File: //etc/httpd/error_log
[Thu Jul 30 11:41:00.445809 2026] [lsapi:notice] [pid 8929:tid 8929] mod_lsapi: version 1.1-92
[Thu Jul 30 11:41:00.449768 2026] [:notice] [pid 642290:tid 642290] [host root@sh00085.hostgator.com] mod_lsapi: Selfstarter 642290 started
[Thu Jul 30 11:41:01.052505 2026] [ssl:warn] [pid 8929:tid 8929] AH01909: localhost:8443:0 server certificate does NOT include an ID which matches the server name
[Thu Jul 30 11:41:01.060103 2026] [qos:notice] [pid 8929:tid 8929] mod_qos(007): calculated MaxClients/MaxRequestWorkers (max connections): 6144, applied limit: 2048 (QS_MaxClients)
[Thu Jul 30 11:41:01.222999 2026] [http2:info] [pid 8929:tid 8929] AH03090: mod_http2 (v2.0.42, feats=CHPRIO+SHA256+INVHD+DWINS, nghttp2 1.69.0), initializing...
[Thu Jul 30 11:41:01.226053 2026] [mpm_event:notice] [pid 8929:tid 8929] AH00489: Apache/2.4.68 (cPanel) OpenSSL/3.5.5 Apache mod_qos/11.76 mod_bwlimited/1.4 mod_fcgid/2.3.9 mod_rbld2.0 configured -- resuming normal operations
[Thu Jul 30 11:41:01.226072 2026] [core:notice] [pid 8929:tid 8929] AH00094: Command line: '/usr/sbin/httpd'
[Thu Jul 30 11:41:02.271201 2026] [http2:info] [pid 642360:tid 642360] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 11:41:02.491053 2026] [core:error] [pid 642360:tid 642539] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:02.491079 2026] [core:error] [pid 642360:tid 642539] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:02.491317 2026] [core:error] [pid 642360:tid 642540] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:02.491339 2026] [core:error] [pid 642360:tid 642540] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:02.513916 2026] [core:error] [pid 642360:tid 642556] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:02.513936 2026] [core:error] [pid 642360:tid 642556] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:02.523304 2026] [security2:error] [pid 642360:tid 642516] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt-npSUkh3e5AhEJOBQfQABqX8"]
[Thu Jul 30 11:41:02.526907 2026] [core:error] [pid 642360:tid 642554] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:02.526929 2026] [core:error] [pid 642360:tid 642554] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:02.529818 2026] [core:error] [pid 642360:tid 642558] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:02.529855 2026] [core:error] [pid 642360:tid 642558] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:02.556877 2026] [security2:error] [pid 642360:tid 642386] [remote 57.141.0.48:45156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Perspective/article/view/1685"] [unique_id "amt-npSUkh3e5AhEJOBQvQAB7Rk"]
[Thu Jul 30 11:41:02.718507 2026] [security2:error] [pid 642360:tid 642576] [client 57.141.0.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-npSUkh3e5AhEJOBQtgAAAeU"]
[Thu Jul 30 11:41:02.783433 2026] [security2:error] [pid 642360:tid 642524] [client 43.166.136.153:38040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.136.166.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Euclid"] [unique_id "amt-npSUkh3e5AhEJOBQowAAAbE"], referer: https://ejournalugj.com/index_php/Euclid
[Thu Jul 30 11:41:03.135633 2026] [security2:error] [pid 642360:tid 642574] [client 57.141.0.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt-npSUkh3e5AhEJOBQsAAAAeM"]
[Thu Jul 30 11:41:04.114743 2026] [security2:error] [pid 642360:tid 642554] [client 181.54.0.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "online-hope.com"] [uri "/index.php"] [unique_id "amt-n5SUkh3e5AhEJOBQ2QAAAc8"], referer: https://online-hope.com
[Thu Jul 30 11:41:04.425000 2026] [security2:error] [pid 642360:tid 642530] [client 2a03:2880:f800:30:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt-npSUkh3e5AhEJOBQxQABtx4"]
[Thu Jul 30 11:41:04.478618 2026] [security2:error] [pid 642360:tid 642525] [client 2a03:2880:f800:1c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt-npSUkh3e5AhEJOBQxgABsh8"]
[Thu Jul 30 11:41:04.622623 2026] [security2:error] [pid 642360:tid 642585] [client 109.236.45.26:49488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.45.236.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "journeywomenscenter.org"] [uri "/xmlrpc.php"] [unique_id "amt-oJSUkh3e5AhEJOBQ8QAAAe4"]
[Thu Jul 30 11:41:04.623294 2026] [security2:error] [pid 642360:tid 642585] [client 109.236.45.26:49488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "journeywomenscenter.org"] [uri "/xmlrpc.php"] [unique_id "amt-oJSUkh3e5AhEJOBQ8QAAAe4"]
[Thu Jul 30 11:41:04.751017 2026] [security2:error] [pid 642360:tid 642597] [client 185.156.175.171:50440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.175.156.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amt-oJSUkh3e5AhEJOBQ8gAAAfo"]
[Thu Jul 30 11:41:04.751130 2026] [security2:error] [pid 642360:tid 642597] [client 185.156.175.171:50440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amt-oJSUkh3e5AhEJOBQ8gAAAfo"]
[Thu Jul 30 11:41:04.989060 2026] [core:error] [pid 642360:tid 642491] [client 158.173.25.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://appliancerepairservice.one/
[Thu Jul 30 11:41:04.989085 2026] [core:error] [pid 642360:tid 642491] [client 158.173.25.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://appliancerepairservice.one/
[Thu Jul 30 11:41:05.432478 2026] [security2:error] [pid 642360:tid 642610] [client 2a03:2880:f800:d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt-npSUkh3e5AhEJOBQxwACByA"]
[Thu Jul 30 11:41:06.196730 2026] [security2:error] [pid 642360:tid 642600] [client 104.210.56.224:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "lucky-strike-shop.com"] [uri "/index.php"] [unique_id "amt-oJSUkh3e5AhEJOBRCAAB_S8"]
[Thu Jul 30 11:41:06.428843 2026] [security2:error] [pid 642360:tid 642616] [client 172.237.109.114:55602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oJSUkh3e5AhEJOBQ_QAAAg0"]
[Thu Jul 30 11:41:06.450599 2026] [security2:error] [pid 642360:tid 642613] [client 172.237.109.114:6488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oJSUkh3e5AhEJOBQ-AAAAgo"]
[Thu Jul 30 11:41:06.507339 2026] [security2:error] [pid 642360:tid 642578] [client 172.237.109.114:37976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oJSUkh3e5AhEJOBRCQAAAec"]
[Thu Jul 30 11:41:06.555291 2026] [security2:error] [pid 642360:tid 642611] [client 172.237.109.114:10415] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oJSUkh3e5AhEJOBQ9wAAAgg"]
[Thu Jul 30 11:41:06.556008 2026] [security2:error] [pid 642360:tid 642493] [client 172.237.109.114:24535] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oJSUkh3e5AhEJOBRBQAAAZI"]
[Thu Jul 30 11:41:06.594913 2026] [security2:error] [pid 642360:tid 642615] [client 172.237.109.114:18197] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oJSUkh3e5AhEJOBQ_AAAAgw"]
[Thu Jul 30 11:41:06.603459 2026] [security2:error] [pid 642360:tid 642492] [client 172.237.109.114:29607] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oJSUkh3e5AhEJOBRAQAAAZE"]
[Thu Jul 30 11:41:06.616282 2026] [security2:error] [pid 642360:tid 642496] [client 172.237.109.114:30333] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oJSUkh3e5AhEJOBQ_gAAAZU"]
[Thu Jul 30 11:41:06.623623 2026] [security2:error] [pid 642360:tid 642511] [client 172.237.109.114:64277] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oJSUkh3e5AhEJOBQ9gAAAaQ"]
[Thu Jul 30 11:41:06.623696 2026] [security2:error] [pid 642360:tid 642614] [client 172.237.109.114:26191] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oJSUkh3e5AhEJOBQ-wAAAgs"]
[Thu Jul 30 11:41:06.628441 2026] [security2:error] [pid 642360:tid 642499] [client 172.237.109.114:60882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oJSUkh3e5AhEJOBRAAAAAZg"]
[Thu Jul 30 11:41:06.650932 2026] [security2:error] [pid 642360:tid 642555] [client 172.237.109.114:11858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oJSUkh3e5AhEJOBRBgAAAdA"]
[Thu Jul 30 11:41:06.661999 2026] [security2:error] [pid 642360:tid 642543] [client 172.237.109.114:65318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oZSUkh3e5AhEJOBRDAAAAcQ"]
[Thu Jul 30 11:41:06.666598 2026] [security2:error] [pid 642360:tid 642540] [client 172.237.109.114:1426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oZSUkh3e5AhEJOBRDQAAAcE"]
[Thu Jul 30 11:41:06.668819 2026] [security2:error] [pid 642360:tid 642542] [client 172.237.109.114:32816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oJSUkh3e5AhEJOBRBwAAAcM"]
[Thu Jul 30 11:41:06.693780 2026] [security2:error] [pid 642360:tid 642524] [client 172.237.109.114:7571] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oJSUkh3e5AhEJOBQ-gAAAbE"]
[Thu Jul 30 11:41:06.775306 2026] [security2:error] [pid 642360:tid 642512] [client 172.237.109.114:53532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oZSUkh3e5AhEJOBREAAAAaU"]
[Thu Jul 30 11:41:06.781836 2026] [security2:error] [pid 642360:tid 642565] [client 172.237.109.114:25893] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oZSUkh3e5AhEJOBRDwAAAdo"]
[Thu Jul 30 11:41:07.233563 2026] [security2:error] [pid 642360:tid 642574] [client 172.237.109.114:26104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oZSUkh3e5AhEJOBRDgAAAeM"]
[Thu Jul 30 11:41:07.258896 2026] [security2:error] [pid 642360:tid 642534] [client 172.237.109.114:45802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oJSUkh3e5AhEJOBRBAAAAbs"]
[Thu Jul 30 11:41:07.342382 2026] [security2:error] [pid 642360:tid 642507] [client 5.161.117.52:10464] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amt-o5SUkh3e5AhEJOBRQQAAAaA"], referer: https://globalmarks.pk/
[Thu Jul 30 11:41:07.439737 2026] [core:notice] [pid 642360:tid 642425] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:41:07.831779 2026] [security2:error] [pid 642360:tid 642430] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt-o5SUkh3e5AhEJOBRUwABo0U"]
[Thu Jul 30 11:41:07.831959 2026] [security2:error] [pid 642360:tid 642510] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt-o5SUkh3e5AhEJOBRUwABo0U"]
[Thu Jul 30 11:41:07.891171 2026] [security2:error] [pid 642360:tid 642533] [client 57.141.0.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt-o5SUkh3e5AhEJOBRRwAAAbo"]
[Thu Jul 30 11:41:08.113389 2026] [security2:error] [pid 642360:tid 642561] [client 176.241.66.87:35317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt-pJSUkh3e5AhEJOBRXQAAAdY"]
[Thu Jul 30 11:41:08.113547 2026] [security2:error] [pid 642360:tid 642561] [client 176.241.66.87:35317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt-pJSUkh3e5AhEJOBRXQAAAdY"]
[Thu Jul 30 11:41:08.580991 2026] [core:notice] [pid 642360:tid 642570] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:41:10.246420 2026] [security2:error] [pid 642360:tid 642455] [remote 57.141.0.68:49244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Konstruksi/FocusandScope"] [unique_id "amt-ppSUkh3e5AhEJOBRjQABzV4"]
[Thu Jul 30 11:41:10.466129 2026] [security2:error] [pid 642360:tid 642532] [client 178.20.44.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt-pZSUkh3e5AhEJOBRdwABuVc"], referer: https://allmontecristi.com/5-important-characteristics-to-identify-an-export-panama-hat/?srsltid=afmbooobpjslvy1dcritpm3oyoloutbopk2q0t238sboel09-jvs0f2z
[Thu Jul 30 11:41:11.263816 2026] [security2:error] [pid 642360:tid 642496] [client 143.198.88.13:62537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.88.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.website-976d73dd.ubp.hmu.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amt-p5SUkh3e5AhEJOBRnwAAAZU"], referer: www.website-88aad310.rja.sfu.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:41:11.489856 2026] [core:error] [pid 642360:tid 642530] [client 143.198.88.13:57839] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.website-88aad310.rja.sfu.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:41:11.489878 2026] [core:error] [pid 642360:tid 642530] [client 143.198.88.13:57839] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.website-88aad310.rja.sfu.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:41:11.719012 2026] [core:error] [pid 642360:tid 642542] [client 143.198.88.13:61900] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.website-88aad310.rja.sfu.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:41:11.719035 2026] [core:error] [pid 642360:tid 642542] [client 143.198.88.13:61900] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.website-88aad310.rja.sfu.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:41:11.974757 2026] [core:error] [pid 642360:tid 642599] [client 143.198.88.13:57622] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.website-88aad310.rja.sfu.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:41:11.974779 2026] [core:error] [pid 642360:tid 642599] [client 143.198.88.13:57622] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.website-88aad310.rja.sfu.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:41:12.216563 2026] [core:error] [pid 642360:tid 642576] [client 143.198.88.13:49169] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.website-88aad310.rja.sfu.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:41:12.216584 2026] [core:error] [pid 642360:tid 642576] [client 143.198.88.13:49169] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.website-88aad310.rja.sfu.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:41:12.300415 2026] [security2:error] [pid 642360:tid 642597] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt-qJSUkh3e5AhEJOBRsAAB-mk"]
[Thu Jul 30 11:41:12.408187 2026] [security2:error] [pid 642360:tid 642491] [client 178.20.44.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt-ppSUkh3e5AhEJOBRmQABkGM"], referer: https://allmontecristi.com/contact/
[Thu Jul 30 11:41:12.415372 2026] [core:notice] [pid 642360:tid 642548] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:41:12.523179 2026] [security2:error] [pid 642360:tid 642541] [client 2a03:2880:f800:3b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt-ppSUkh3e5AhEJOBRmAABwmI"]
[Thu Jul 30 11:41:13.170715 2026] [core:notice] [pid 642360:tid 642472] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:41:13.958035 2026] [security2:error] [pid 642360:tid 642532] [client 1.13.255.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-qZSUkh3e5AhEJOBRzgAAAbk"], referer: https://cnpinyin.com/
[Thu Jul 30 11:41:15.666885 2026] [core:error] [pid 642360:tid 642369] [remote 57.141.0.33:39774] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:15.666919 2026] [core:error] [pid 642360:tid 642369] [remote 57.141.0.33:39774] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:15.878363 2026] [security2:error] [pid 642360:tid 642565] [client 57.141.0.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt-q5SUkh3e5AhEJOBR9QAAAdo"]
[Thu Jul 30 11:41:16.300082 2026] [security2:error] [pid 642360:tid 642549] [client 143.198.88.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aletihadfurnituretransportllc.cc"] [uri "/index.php"] [unique_id "amt-rJSUkh3e5AhEJOBSBQAByg4"], referer: www.website-93bf5d36.fyb.fxy.temporary.site/blog//wp-login.php
[Thu Jul 30 11:41:16.431588 2026] [security2:error] [pid 642360:tid 642535] [client 57.141.0.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt-q5SUkh3e5AhEJOBSAAAAAbw"]
[Thu Jul 30 11:41:16.695677 2026] [security2:error] [pid 642360:tid 642510] [client 213.152.187.230:55074] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amt-rJSUkh3e5AhEJOBSFgAAAaM"]
[Thu Jul 30 11:41:16.695791 2026] [security2:error] [pid 642360:tid 642510] [client 213.152.187.230:55074] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amt-rJSUkh3e5AhEJOBSFgAAAaM"]
[Thu Jul 30 11:41:17.430042 2026] [security2:error] [pid 642360:tid 642506] [client 2a03:2880:f800:1c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt-q5SUkh3e5AhEJOBR_QABnww"]
[Thu Jul 30 11:41:17.508261 2026] [security2:error] [pid 642360:tid 642391] [remote 74.7.241.59:48388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amt-rZSUkh3e5AhEJOBSNAABoR4"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/pixelyoursite/includes
[Thu Jul 30 11:41:18.184238 2026] [core:notice] [pid 642360:tid 642546] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:41:18.376677 2026] [security2:error] [pid 642360:tid 642580] [client 57.141.0.23:49986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amt-rZSUkh3e5AhEJOBSWwAB6Us"], referer: https://igetvape-australia.com/store/?product-page=4&add-to-cart=1049
[Thu Jul 30 11:41:18.533182 2026] [security2:error] [pid 642360:tid 642587] [client 2a03:2880:f800:d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt-rZSUkh3e5AhEJOBSMwAB8AE"]
[Thu Jul 30 11:41:18.652870 2026] [security2:error] [pid 642360:tid 642444] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt-rpSUkh3e5AhEJOBSbQAB11M"]
[Thu Jul 30 11:41:18.653026 2026] [security2:error] [pid 642360:tid 642562] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt-rpSUkh3e5AhEJOBSbQAB11M"]
[Thu Jul 30 11:41:18.747149 2026] [security2:error] [pid 642360:tid 642494] [client 176.241.66.87:53119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt-rpSUkh3e5AhEJOBScgAAAZM"]
[Thu Jul 30 11:41:18.747275 2026] [security2:error] [pid 642360:tid 642494] [client 176.241.66.87:53119] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt-rpSUkh3e5AhEJOBScgAAAZM"]
[Thu Jul 30 11:41:18.832699 2026] [security2:error] [pid 642360:tid 642545] [client 43.172.195.154:36912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.195.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2016/09/26/collection-cachemire-c-et-a/"] [unique_id "amt-rpSUkh3e5AhEJOBSagAAAcY"]
[Thu Jul 30 11:41:18.990299 2026] [fcgid:warn] [pid 642360:tid 642578] (70014)End of file found: [client 157.245.105.107:39920] mod_fcgid: can't get data from http client
[Thu Jul 30 11:41:19.239651 2026] [security2:error] [pid 642360:tid 642550] [client 57.141.0.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt-rpSUkh3e5AhEJOBSbgAAAcs"]
[Thu Jul 30 11:41:19.461221 2026] [core:notice] [pid 642360:tid 642582] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:41:19.466476 2026] [security2:error] [pid 642360:tid 642582] [client 43.172.197.47:58842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2016/09/26/collection-cachemire-c-et-a/"] [unique_id "amt-r5SUkh3e5AhEJOBSggAAAes"], referer: https://carnetdeshopping.com/index.php/2016/09/26/collection-cachemire-c-et-a/
[Thu Jul 30 11:41:20.065859 2026] [security2:error] [pid 642360:tid 642602] [client 213.152.187.230:45272] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amt-sJSUkh3e5AhEJOBSiwAAAf8"]
[Thu Jul 30 11:41:20.065972 2026] [security2:error] [pid 642360:tid 642602] [client 213.152.187.230:45272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amt-sJSUkh3e5AhEJOBSiwAAAf8"]
[Thu Jul 30 11:41:22.932595 2026] [security2:error] [pid 642360:tid 642616] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt-spSUkh3e5AhEJOBStAACDWs"]
[Thu Jul 30 11:41:23.397808 2026] [authz_core:error] [pid 642360:tid 642613] [client 118.194.253.208:58554] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/config.yml
[Thu Jul 30 11:41:23.995169 2026] [security2:error] [pid 642360:tid 642547] [client 185.156.175.171:40066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.175.156.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amt-s5SUkh3e5AhEJOBS0wAAAcg"]
[Thu Jul 30 11:41:23.995264 2026] [security2:error] [pid 642360:tid 642547] [client 185.156.175.171:40066] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amt-s5SUkh3e5AhEJOBS0wAAAcg"]
[Thu Jul 30 11:41:24.236582 2026] [security2:error] [pid 642360:tid 642531] [client 72.27.155.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "online-hope.com"] [uri "/index.php"] [unique_id "amt-s5SUkh3e5AhEJOBSzwAAAbg"], referer: https://online-hope.com
[Thu Jul 30 11:41:24.686559 2026] [core:error] [pid 642360:tid 642496] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:24.686582 2026] [core:error] [pid 642360:tid 642496] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:24.710694 2026] [core:error] [pid 642360:tid 642533] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:24.710714 2026] [core:error] [pid 642360:tid 642533] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:24.723954 2026] [core:error] [pid 642360:tid 642561] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:24.723991 2026] [core:error] [pid 642360:tid 642561] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:25.345516 2026] [security2:error] [pid 642360:tid 642551] [client 74.7.241.192:38182] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "webdisk.mxk.djb.temporary.site"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amt-tZSUkh3e5AhEJOBTBQAAAcw"]
[Thu Jul 30 11:41:25.647821 2026] [security2:error] [pid 642360:tid 642583] [client 2a03:2880:f800:2:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt-tJSUkh3e5AhEJOBS-gAB7Hk"]
[Thu Jul 30 11:41:26.274997 2026] [security2:error] [pid 642360:tid 642583] [client 50.6.43.217:10952] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amt-tpSUkh3e5AhEJOBTHQAAAew"]
[Thu Jul 30 11:41:26.306767 2026] [http2:info] [pid 643253:tid 643253] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 11:41:26.701769 2026] [qos:error] [pid 642360:tid 642593] [client 136.109.111.23:47220] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-tpSUkh3e5AhEJOBTtwAAAfY
[Thu Jul 30 11:41:26.704874 2026] [qos:error] [pid 642360:tid 642528] [client 136.109.111.23:47160] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-tpSUkh3e5AhEJOBTuQAAAbU
[Thu Jul 30 11:41:26.705059 2026] [qos:error] [pid 643253:tid 643461] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-tsjqbtjBYzqM1uYiUwAAAE0
[Thu Jul 30 11:41:26.708202 2026] [qos:error] [pid 642360:tid 642504] [client 136.109.111.23:47498] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-tpSUkh3e5AhEJOBTugAAAZ0
[Thu Jul 30 11:41:26.711084 2026] [qos:error] [pid 642360:tid 642543] [client 136.109.111.23:47850] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-tpSUkh3e5AhEJOBTvAAAAcQ
[Thu Jul 30 11:41:26.712555 2026] [qos:error] [pid 643253:tid 643468] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-tsjqbtjBYzqM1uYiVgAAAFQ
[Thu Jul 30 11:41:26.713604 2026] [qos:error] [pid 643253:tid 643471] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-tsjqbtjBYzqM1uYiWQAAAFc
[Thu Jul 30 11:41:26.713626 2026] [qos:error] [pid 643253:tid 643470] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.112.84, id=amt-tsjqbtjBYzqM1uYiWAAAAFY
[Thu Jul 30 11:41:26.718796 2026] [qos:error] [pid 643253:tid 643480] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-tsjqbtjBYzqM1uYiXAAAAGA
[Thu Jul 30 11:41:26.735890 2026] [qos:error] [pid 642360:tid 642613] [client 136.109.111.23:47532] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-tpSUkh3e5AhEJOBTvgAAAgo
[Thu Jul 30 11:41:26.737149 2026] [autoindex:error] [pid 643253:tid 643482] [client 200.45.130.42:0] AH01276: Cannot serve directory /home2/mbmudite/koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:41:26.745090 2026] [qos:error] [pid 643253:tid 643489] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-tsjqbtjBYzqM1uYiYgAAAGk
[Thu Jul 30 11:41:26.846810 2026] [qos:error] [pid 642360:tid 642594] [client 136.109.111.23:47550] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-tpSUkh3e5AhEJOBTwAAAAfc
[Thu Jul 30 11:41:26.885099 2026] [qos:error] [pid 642360:tid 642504] [client 136.109.111.23:47246] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-tpSUkh3e5AhEJOBTwgAAAZ0
[Thu Jul 30 11:41:26.885407 2026] [qos:error] [pid 642360:tid 642543] [client 136.109.111.23:47374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-tpSUkh3e5AhEJOBTwwAAAcQ
[Thu Jul 30 11:41:26.886657 2026] [qos:error] [pid 642360:tid 642601] [client 136.109.111.23:47236] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-tpSUkh3e5AhEJOBTxAAAAf4
[Thu Jul 30 11:41:26.887384 2026] [qos:error] [pid 643253:tid 643495] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-tsjqbtjBYzqM1uYiZAAAAG8
[Thu Jul 30 11:41:26.950947 2026] [qos:error] [pid 642360:tid 642563] [client 136.109.111.23:47714] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-tpSUkh3e5AhEJOBTxwAAAdg
[Thu Jul 30 11:41:26.952028 2026] [qos:error] [pid 643253:tid 643499] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-tsjqbtjBYzqM1uYiZgAAAHM
[Thu Jul 30 11:41:26.973058 2026] [qos:error] [pid 643253:tid 643465] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-tsjqbtjBYzqM1uYidAAAAFE
[Thu Jul 30 11:41:26.987901 2026] [qos:error] [pid 642360:tid 642568] [client 136.109.111.23:47760] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-tpSUkh3e5AhEJOBTygAAAd0
[Thu Jul 30 11:41:26.990831 2026] [authz_core:error] [pid 642360:tid 642527] [client 118.194.253.208:44398] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/serverless.yml
[Thu Jul 30 11:41:26.991612 2026] [qos:error] [pid 642360:tid 642602] [client 136.109.111.23:47362] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-tpSUkh3e5AhEJOBTzAAAAf8
[Thu Jul 30 11:41:26.992333 2026] [qos:error] [pid 642360:tid 642525] [client 136.109.111.23:47488] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-tpSUkh3e5AhEJOBTzQAAAbI
[Thu Jul 30 11:41:26.993258 2026] [qos:error] [pid 643253:tid 643476] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-tsjqbtjBYzqM1uYifAAAAFw
[Thu Jul 30 11:41:26.993778 2026] [qos:error] [pid 642360:tid 642593] [client 136.109.111.23:47412] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-tpSUkh3e5AhEJOBTzgAAAfY
[Thu Jul 30 11:41:26.997258 2026] [qos:error] [pid 642360:tid 642594] [client 136.109.111.23:47406] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-tpSUkh3e5AhEJOBT0AAAAfc
[Thu Jul 30 11:41:26.998662 2026] [qos:error] [pid 642360:tid 642559] [client 136.109.111.23:47186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-tpSUkh3e5AhEJOBT0gAAAdQ
[Thu Jul 30 11:41:26.998963 2026] [qos:error] [pid 642360:tid 642528] [client 136.109.111.23:47628] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-tpSUkh3e5AhEJOBT0QAAAbU
[Thu Jul 30 11:41:26.999568 2026] [qos:error] [pid 642360:tid 642528] [client 136.109.111.23:47618] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-tpSUkh3e5AhEJOBT0wAAAbU
[Thu Jul 30 11:41:27.003927 2026] [qos:error] [pid 642360:tid 642543] [client 136.109.111.23:47562] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT1AAAAcQ
[Thu Jul 30 11:41:27.005710 2026] [qos:error] [pid 642360:tid 642601] [client 136.109.111.23:47716] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT1QAAAf4
[Thu Jul 30 11:41:27.007471 2026] [qos:error] [pid 643253:tid 643480] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t8jqbtjBYzqM1uYifgAAAGA
[Thu Jul 30 11:41:27.021844 2026] [qos:error] [pid 642360:tid 642563] [client 136.109.111.23:47700] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT1wAAAdg
[Thu Jul 30 11:41:27.025619 2026] [qos:error] [pid 643253:tid 643462] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t8jqbtjBYzqM1uYigAAAAE4
[Thu Jul 30 11:41:27.038301 2026] [qos:error] [pid 642360:tid 642558] [client 136.109.111.23:47498] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT2QAAAdM
[Thu Jul 30 11:41:27.044966 2026] [qos:error] [pid 643253:tid 643491] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t8jqbtjBYzqM1uYihQAAAGs
[Thu Jul 30 11:41:27.114960 2026] [qos:error] [pid 642360:tid 642593] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t5SUkh3e5AhEJOBT3AAAAfY
[Thu Jul 30 11:41:27.125646 2026] [qos:error] [pid 642360:tid 642504] [client 136.109.111.23:47796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT3wAAAZ0
[Thu Jul 30 11:41:27.143912 2026] [qos:error] [pid 643253:tid 643496] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t8jqbtjBYzqM1uYiiQAAAHA
[Thu Jul 30 11:41:27.147550 2026] [qos:error] [pid 642360:tid 642533] [client 136.109.111.23:47532] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT4wAAAbo
[Thu Jul 30 11:41:27.157579 2026] [qos:error] [pid 643253:tid 643500] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t8jqbtjBYzqM1uYiiwAAAHQ
[Thu Jul 30 11:41:27.165535 2026] [qos:error] [pid 642360:tid 642537] [client 136.109.111.23:47594] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT5gAAAb4
[Thu Jul 30 11:41:27.172129 2026] [qos:error] [pid 642360:tid 642558] [client 136.109.111.23:47450] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT5wAAAdM
[Thu Jul 30 11:41:27.201696 2026] [qos:error] [pid 642360:tid 642602] [client 136.109.111.23:47550] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT6QAAAf8
[Thu Jul 30 11:41:27.202052 2026] [qos:error] [pid 642360:tid 642588] [client 136.109.111.23:47306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT6gAAAfE
[Thu Jul 30 11:41:27.224122 2026] [qos:error] [pid 642360:tid 642525] [client 136.109.111.23:47714] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT7AAAAbI
[Thu Jul 30 11:41:27.225746 2026] [qos:error] [pid 642360:tid 642521] [client 136.109.111.23:47318] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT7QAAAa4
[Thu Jul 30 11:41:27.226127 2026] [qos:error] [pid 642360:tid 642593] [client 136.109.111.23:47690] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT7gAAAfY
[Thu Jul 30 11:41:27.227593 2026] [qos:error] [pid 642360:tid 642527] [client 136.109.111.23:47246] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT8AAAAbQ
[Thu Jul 30 11:41:27.227644 2026] [qos:error] [pid 642360:tid 642613] [client 136.109.111.23:47374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT7wAAAgo
[Thu Jul 30 11:41:27.228396 2026] [qos:error] [pid 642360:tid 642504] [client 136.109.111.23:47760] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT8QAAAZ0
[Thu Jul 30 11:41:27.229243 2026] [qos:error] [pid 642360:tid 642559] [client 136.109.111.23:47488] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT8gAAAdQ
[Thu Jul 30 11:41:27.229705 2026] [qos:error] [pid 642360:tid 642543] [client 136.109.111.23:47270] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT8wAAAcQ
[Thu Jul 30 11:41:27.229776 2026] [qos:error] [pid 642360:tid 642601] [client 136.109.111.23:47362] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT9AAAAf4
[Thu Jul 30 11:41:27.230631 2026] [qos:error] [pid 642360:tid 642533] [client 136.109.111.23:47236] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT9QAAAbo
[Thu Jul 30 11:41:27.231480 2026] [qos:error] [pid 642360:tid 642523] [client 136.109.111.23:47344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT9gAAAbA
[Thu Jul 30 11:41:27.235308 2026] [qos:error] [pid 642360:tid 642537] [client 136.109.111.23:47412] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT9wAAAb4
[Thu Jul 30 11:41:27.235789 2026] [qos:error] [pid 642360:tid 642558] [client 136.109.111.23:47580] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT-AAAAdM
[Thu Jul 30 11:41:27.241413 2026] [qos:error] [pid 642360:tid 642528] [client 136.109.111.23:47694] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT-QAAAbU
[Thu Jul 30 11:41:27.244372 2026] [qos:error] [pid 642360:tid 642578] [client 136.109.111.23:47186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT-gAAAec
[Thu Jul 30 11:41:27.248371 2026] [qos:error] [pid 642360:tid 642568] [client 136.109.111.23:47618] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT-wAAAd0
[Thu Jul 30 11:41:27.258628 2026] [qos:error] [pid 642360:tid 642594] [client 136.109.111.23:47406] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT_AAAAfc
[Thu Jul 30 11:41:27.296220 2026] [security2:error] [pid 642360:tid 642520] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tpSUkh3e5AhEJOBTiAAAAa0"]
[Thu Jul 30 11:41:27.324329 2026] [http2:info] [pid 643573:tid 643573] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 11:41:27.346676 2026] [security2:error] [pid 643253:tid 643410] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYiIAAAABo"]
[Thu Jul 30 11:41:27.355364 2026] [security2:error] [pid 643253:tid 643413] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYiHAAAAB0"]
[Thu Jul 30 11:41:27.371440 2026] [qos:error] [pid 642360:tid 642558] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t5SUkh3e5AhEJOBUBAAAAdM
[Thu Jul 30 11:41:27.394427 2026] [qos:error] [pid 642360:tid 642606] [client 136.109.111.23:47796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUCAAAAgM
[Thu Jul 30 11:41:27.395020 2026] [qos:error] [pid 642360:tid 642594] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t5SUkh3e5AhEJOBUCQAAAfc
[Thu Jul 30 11:41:27.441986 2026] [qos:error] [pid 642360:tid 642520] [client 136.109.111.23:47532] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUDAAAAa0
[Thu Jul 30 11:41:27.444350 2026] [core:notice] [pid 643253:tid 643459] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:41:27.445846 2026] [qos:error] [pid 642360:tid 642593] [client 136.109.111.23:47594] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUDgAAAfY
[Thu Jul 30 11:41:27.446052 2026] [qos:error] [pid 642360:tid 642521] [client 136.109.111.23:47524] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUDQAAAa4
[Thu Jul 30 11:41:27.446121 2026] [qos:error] [pid 642360:tid 642522] [client 136.109.111.23:47384] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUDwAAAa8
[Thu Jul 30 11:41:27.446699 2026] [qos:error] [pid 642360:tid 642577] [client 136.109.111.23:47306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUEQAAAeY
[Thu Jul 30 11:41:27.447528 2026] [qos:error] [pid 642360:tid 642612] [client 136.109.111.23:47550] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUEAAAAgk
[Thu Jul 30 11:41:27.448190 2026] [qos:error] [pid 642360:tid 642531] [client 136.109.111.23:47714] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUEgAAAbg
[Thu Jul 30 11:41:27.448832 2026] [qos:error] [pid 642360:tid 642527] [client 136.109.111.23:47690] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUEwAAAbQ
[Thu Jul 30 11:41:27.449717 2026] [qos:error] [pid 643573:tid 643729] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t_xWyxgRnoFKAJ_TJQAAAic
[Thu Jul 30 11:41:27.453804 2026] [qos:error] [pid 642360:tid 642576] [client 136.109.111.23:47246] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUFQAAAeU
[Thu Jul 30 11:41:27.454381 2026] [qos:error] [pid 642360:tid 642576] [client 136.109.111.23:47318] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUFwAAAeU
[Thu Jul 30 11:41:27.454685 2026] [qos:error] [pid 642360:tid 642542] [client 136.109.111.23:47374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUFgAAAcM
[Thu Jul 30 11:41:27.458214 2026] [qos:error] [pid 642360:tid 642601] [client 136.109.111.23:47760] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUGAAAAf4
[Thu Jul 30 11:41:27.458779 2026] [qos:error] [pid 642360:tid 642558] [client 136.109.111.23:47450] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUGQAAAdM
[Thu Jul 30 11:41:27.461519 2026] [qos:error] [pid 642360:tid 642528] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t5SUkh3e5AhEJOBUGgAAAbU
[Thu Jul 30 11:41:27.467609 2026] [qos:error] [pid 642360:tid 642606] [client 136.109.111.23:47236] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUHAAAAgM
[Thu Jul 30 11:41:27.477714 2026] [qos:error] [pid 643573:tid 643718] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t_xWyxgRnoFKAJ_TKAAAAhw
[Thu Jul 30 11:41:27.482812 2026] [qos:error] [pid 642360:tid 642520] [client 136.109.111.23:47362] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUIAAAAa0
[Thu Jul 30 11:41:27.491616 2026] [qos:error] [pid 643573:tid 643727] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t_xWyxgRnoFKAJ_TKgAAAiU
[Thu Jul 30 11:41:27.539153 2026] [qos:error] [pid 643573:tid 643715] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t_xWyxgRnoFKAJ_TKwAAAhk
[Thu Jul 30 11:41:27.612549 2026] [qos:error] [pid 642360:tid 642527] [client 136.109.111.23:47186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUJQAAAbQ
[Thu Jul 30 11:41:27.612623 2026] [qos:error] [pid 642360:tid 642531] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.112.84, id=amt-t5SUkh3e5AhEJOBUJgAAAbg
[Thu Jul 30 11:41:27.619090 2026] [qos:error] [pid 642360:tid 642559] [client 136.109.111.23:47618] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUKAAAAdQ
[Thu Jul 30 11:41:27.622087 2026] [qos:error] [pid 642360:tid 642542] [client 136.109.111.23:47406] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUKgAAAcM
[Thu Jul 30 11:41:27.622355 2026] [qos:error] [pid 642360:tid 642601] [client 136.109.111.23:47852] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUKwAAAf4
[Thu Jul 30 11:41:27.628672 2026] [qos:error] [pid 643253:tid 643488] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t8jqbtjBYzqM1uYilQAAAGg
[Thu Jul 30 11:41:27.628871 2026] [qos:error] [pid 642360:tid 642558] [client 136.109.111.23:47558] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBULAAAAdM
[Thu Jul 30 11:41:27.657531 2026] [qos:error] [pid 642360:tid 642613] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t5SUkh3e5AhEJOBUMAAAAgo
[Thu Jul 30 11:41:27.682837 2026] [qos:error] [pid 642360:tid 642602] [client 136.109.111.23:47796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUNQAAAf8
[Thu Jul 30 11:41:27.682998 2026] [qos:error] [pid 642360:tid 642505] [client 136.109.111.23:47594] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUNAAAAZ4
[Thu Jul 30 11:41:27.684224 2026] [qos:error] [pid 642360:tid 642602] [client 136.109.111.23:47532] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUNgAAAf8
[Thu Jul 30 11:41:27.684623 2026] [qos:error] [pid 642360:tid 642521] [client 136.109.111.23:47384] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUNwAAAa4
[Thu Jul 30 11:41:27.684922 2026] [qos:error] [pid 642360:tid 642527] [client 136.109.111.23:47220] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUOwAAAbQ
[Thu Jul 30 11:41:27.685065 2026] [qos:error] [pid 642360:tid 642577] [client 136.109.111.23:47690] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUOgAAAeY
[Thu Jul 30 11:41:27.685099 2026] [qos:error] [pid 642360:tid 642540] [client 136.109.111.23:47306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUOAAAAcE
[Thu Jul 30 11:41:27.685574 2026] [qos:error] [pid 642360:tid 642593] [client 136.109.111.23:47550] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUOQAAAfY
[Thu Jul 30 11:41:27.686458 2026] [qos:error] [pid 642360:tid 642531] [client 136.109.111.23:47446] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUPAAAAbg
[Thu Jul 30 11:41:27.688072 2026] [qos:error] [pid 642360:tid 642502] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t5SUkh3e5AhEJOBUPQAAAZs
[Thu Jul 30 11:41:27.706698 2026] [qos:error] [pid 642360:tid 642558] [client 136.109.111.23:47714] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUQQAAAdM
[Thu Jul 30 11:41:27.708063 2026] [qos:error] [pid 642360:tid 642558] [client 136.109.111.23:47524] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUQgAAAdM
[Thu Jul 30 11:41:27.711716 2026] [qos:error] [pid 642360:tid 642528] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t5SUkh3e5AhEJOBUQwAAAbU
[Thu Jul 30 11:41:27.713460 2026] [qos:error] [pid 642360:tid 642613] [client 136.109.111.23:47246] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBURAAAAgo
[Thu Jul 30 11:41:27.713651 2026] [qos:error] [pid 642360:tid 642594] [client 136.109.111.23:47374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBURgAAAfc
[Thu Jul 30 11:41:27.720263 2026] [qos:error] [pid 642360:tid 642505] [client 136.109.111.23:47488] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUSAAAAZ4
[Thu Jul 30 11:41:27.721710 2026] [qos:error] [pid 642360:tid 642602] [client 136.109.111.23:47450] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUSQAAAf8
[Thu Jul 30 11:41:27.731735 2026] [qos:error] [pid 643253:tid 643492] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t8jqbtjBYzqM1uYilwAAAGw
[Thu Jul 30 11:41:27.784359 2026] [qos:error] [pid 642360:tid 642540] [client 136.109.111.23:47270] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUTgAAAcE
[Thu Jul 30 11:41:27.794173 2026] [qos:error] [pid 643573:tid 643762] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t_xWyxgRnoFKAJ_TOAAAAkg
[Thu Jul 30 11:41:27.850735 2026] [qos:error] [pid 642360:tid 642520] [client 136.109.111.23:47186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUUgAAAa0
[Thu Jul 30 11:41:27.852666 2026] [qos:error] [pid 642360:tid 642559] [client 136.109.111.23:47344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUUwAAAdQ
[Thu Jul 30 11:41:27.852844 2026] [qos:error] [pid 643573:tid 643759] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t_xWyxgRnoFKAJ_TOQAAAkU
[Thu Jul 30 11:41:27.861859 2026] [qos:error] [pid 642360:tid 642528] [client 136.109.111.23:47618] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUVQAAAbU
[Thu Jul 30 11:41:27.862146 2026] [qos:error] [pid 642360:tid 642601] [client 136.109.111.23:47412] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUVgAAAf4
[Thu Jul 30 11:41:27.865562 2026] [qos:error] [pid 643573:tid 643758] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t_xWyxgRnoFKAJ_TOwAAAkQ
[Thu Jul 30 11:41:27.877457 2026] [qos:error] [pid 642360:tid 642557] [client 136.109.111.23:47406] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUWQAAAdI
[Thu Jul 30 11:41:27.878508 2026] [qos:error] [pid 642360:tid 642613] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t5SUkh3e5AhEJOBUWgAAAgo
[Thu Jul 30 11:41:27.912856 2026] [security2:error] [pid 642360:tid 642560] [client 50.6.43.217:10962] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amt-t5SUkh3e5AhEJOBUXAAAAdU"]
[Thu Jul 30 11:41:27.916304 2026] [qos:error] [pid 642360:tid 642577] [client 136.109.111.23:47594] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUXgAAAeY
[Thu Jul 30 11:41:27.919358 2026] [qos:error] [pid 642360:tid 642531] [client 136.109.111.23:47150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUYAAAAbg
[Thu Jul 30 11:41:27.919805 2026] [qos:error] [pid 642360:tid 642559] [client 136.109.111.23:47562] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUYgAAAdQ
[Thu Jul 30 11:41:27.919814 2026] [qos:error] [pid 642360:tid 642520] [client 136.109.111.23:47558] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUYQAAAa0
[Thu Jul 30 11:41:27.924113 2026] [qos:error] [pid 642360:tid 642612] [client 136.109.111.23:47532] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUYwAAAgk
[Thu Jul 30 11:41:27.924590 2026] [qos:error] [pid 642360:tid 642558] [client 136.109.111.23:47384] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUZAAAAdM
[Thu Jul 30 11:41:27.925381 2026] [qos:error] [pid 642360:tid 642523] [client 136.109.111.23:47306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUZgAAAbA
[Thu Jul 30 11:41:27.925537 2026] [qos:error] [pid 642360:tid 642502] [client 136.109.111.23:47550] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUZQAAAZs
[Thu Jul 30 11:41:27.925632 2026] [qos:error] [pid 643573:tid 643756] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t_xWyxgRnoFKAJ_TPAAAAkI
[Thu Jul 30 11:41:27.926009 2026] [qos:error] [pid 642360:tid 642528] [client 136.109.111.23:47690] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUZwAAAbU
[Thu Jul 30 11:41:27.938241 2026] [qos:error] [pid 642360:tid 642542] [client 136.109.111.23:47832] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUaQAAAcM
[Thu Jul 30 11:41:27.940923 2026] [qos:error] [pid 642360:tid 642578] [client 136.109.111.23:47446] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUagAAAec
[Thu Jul 30 11:41:27.941042 2026] [qos:error] [pid 642360:tid 642606] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t5SUkh3e5AhEJOBUawAAAgM
[Thu Jul 30 11:41:27.951001 2026] [qos:error] [pid 642360:tid 642593] [client 136.109.111.23:47498] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUbQAAAfY
[Thu Jul 30 11:41:27.956049 2026] [qos:error] [pid 643573:tid 643766] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t_xWyxgRnoFKAJ_TPwAAAkw
[Thu Jul 30 11:41:28.217199 2026] [security2:error] [pid 643253:tid 643417] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYiKAAAACE"]
[Thu Jul 30 11:41:28.247432 2026] [security2:error] [pid 642360:tid 642576] [client 57.141.0.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt-t5SUkh3e5AhEJOBUKQAAAeU"]
[Thu Jul 30 11:41:28.277237 2026] [security2:error] [pid 643253:tid 643421] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYiKwAAACU"]
[Thu Jul 30 11:41:28.286683 2026] [security2:error] [pid 643253:tid 643419] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYiKQAAACM"]
[Thu Jul 30 11:41:28.294157 2026] [security2:error] [pid 643253:tid 643411] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYiGwAAABs"]
[Thu Jul 30 11:41:28.374770 2026] [security2:error] [pid 642360:tid 642536] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tpSUkh3e5AhEJOBTlgAAAb0"]
[Thu Jul 30 11:41:28.378464 2026] [security2:error] [pid 643253:tid 643426] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYiMAAAACo"]
[Thu Jul 30 11:41:28.389288 2026] [security2:error] [pid 642360:tid 642597] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tpSUkh3e5AhEJOBTlAAAAfo"]
[Thu Jul 30 11:41:29.311057 2026] [security2:error] [pid 642360:tid 642560] [client 68.221.186.136:22271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.tmb/LA.php"] [unique_id "amt-uZSUkh3e5AhEJOBUjAAAAdU"]
[Thu Jul 30 11:41:29.316730 2026] [security2:error] [pid 643253:tid 643432] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYiOAAAADA"]
[Thu Jul 30 11:41:29.342804 2026] [security2:error] [pid 642360:tid 642499] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tpSUkh3e5AhEJOBToQAAAZg"]
[Thu Jul 30 11:41:29.383557 2026] [security2:error] [pid 643573:tid 643684] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt-ufxWyxgRnoFKAJ_TUAACfWc"]
[Thu Jul 30 11:41:29.383805 2026] [security2:error] [pid 643573:tid 643815] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt-ufxWyxgRnoFKAJ_TUAACfWc"]
[Thu Jul 30 11:41:29.436630 2026] [security2:error] [pid 643573:tid 643813] [client 176.241.66.87:53644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt-ufxWyxgRnoFKAJ_TUwAAAns"]
[Thu Jul 30 11:41:29.436809 2026] [security2:error] [pid 643573:tid 643813] [client 176.241.66.87:53644] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt-ufxWyxgRnoFKAJ_TUwAAAns"]
[Thu Jul 30 11:41:29.579231 2026] [security2:error] [pid 643573:tid 643803] [client 2a03:2880:f800:26:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt-uPxWyxgRnoFKAJ_TRwACcWQ"]
[Thu Jul 30 11:41:30.047280 2026] [security2:error] [pid 642360:tid 642584] [client 68.221.186.136:20272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.tmb/admin.php"] [unique_id "amt-upSUkh3e5AhEJOBUoAAAAe0"]
[Thu Jul 30 11:41:30.241115 2026] [security2:error] [pid 643253:tid 643430] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYiNQAAAC4"]
[Thu Jul 30 11:41:30.297106 2026] [security2:error] [pid 643253:tid 643438] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYiPgAAADY"]
[Thu Jul 30 11:41:30.315796 2026] [security2:error] [pid 643253:tid 643442] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYiPwAAADo"]
[Thu Jul 30 11:41:30.338282 2026] [security2:error] [pid 643253:tid 643452] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYiSAAAAEQ"]
[Thu Jul 30 11:41:30.342208 2026] [security2:error] [pid 643253:tid 643439] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYiPQAAADc"]
[Thu Jul 30 11:41:31.224821 2026] [security2:error] [pid 643253:tid 643436] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYiPAAAADQ"]
[Thu Jul 30 11:41:31.242134 2026] [security2:error] [pid 643573:tid 643802] [client 68.221.186.136:22250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.tmb/class_api.php"] [unique_id "amt-u_xWyxgRnoFKAJ_TYAAAAnA"]
[Thu Jul 30 11:41:31.309187 2026] [security2:error] [pid 643253:tid 643475] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYiewAAAFs"]
[Thu Jul 30 11:41:31.311590 2026] [security2:error] [pid 643253:tid 643510] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYibgAAAH4"]
[Thu Jul 30 11:41:31.312798 2026] [security2:error] [pid 643253:tid 643461] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYicwAAAE0"]
[Thu Jul 30 11:41:31.324035 2026] [security2:error] [pid 643253:tid 643456] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYidwAAAEg"]
[Thu Jul 30 11:41:31.330105 2026] [security2:error] [pid 643253:tid 643445] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYibwAAAD0"]
[Thu Jul 30 11:41:31.337893 2026] [security2:error] [pid 643253:tid 643490] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-t8jqbtjBYzqM1uYigwAAAGo"]
[Thu Jul 30 11:41:31.974882 2026] [security2:error] [pid 643573:tid 643825] [client 68.221.186.136:14602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.tmb/cpabpkyk.php"] [unique_id "amt-u_xWyxgRnoFKAJ_TZgAAAoc"]
[Thu Jul 30 11:41:32.258756 2026] [security2:error] [pid 643253:tid 643509] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYibQAAAH0"]
[Thu Jul 30 11:41:33.060179 2026] [security2:error] [pid 642360:tid 642597] [client 68.221.186.136:14620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.tmb/wp-login.php"] [unique_id "amt-vJSUkh3e5AhEJOBU0wAAAfo"]
[Thu Jul 30 11:41:33.579282 2026] [security2:error] [pid 643573:tid 643764] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt-vfxWyxgRnoFKAJ_TcgACSiQ"]
[Thu Jul 30 11:41:33.620864 2026] [access_compat:error] [pid 643573:tid 643750] [client 157.245.105.107:57702] AH01797: client denied by server configuration: /home1/lomgzjte/public_html/web/server-status
[Thu Jul 30 11:41:33.774452 2026] [security2:error] [pid 643573:tid 643829] [client 66.249.68.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.dapperdangolf.com"] [uri "/index.php"] [unique_id "amt-u_xWyxgRnoFKAJ_TXwACiyA"]
[Thu Jul 30 11:41:33.874527 2026] [security2:error] [pid 643573:tid 643732] [client 68.221.186.136:18153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known//.well-known/owlmailer.php"] [unique_id "amt-vfxWyxgRnoFKAJ_TdAAAAio"]
[Thu Jul 30 11:41:34.122600 2026] [security2:error] [pid 643253:tid 643260] [remote 209.42.18.223:40882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wce.gzj.temporary.site"] [uri "/wp-login.php"] [unique_id "amt-vsjqbtjBYzqM1uYiqQAAAgU"]
[Thu Jul 30 11:41:34.495466 2026] [security2:error] [pid 643573:tid 643753] [client 68.221.186.136:14882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/991176.php"] [unique_id "amt-vvxWyxgRnoFKAJ_TewAAAj8"]
[Thu Jul 30 11:41:34.732394 2026] [security2:error] [pid 642360:tid 642411] [remote 208.122.213.225:60670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.213.122.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daralnaseemdxb.com"] [uri "/wp-login.php"] [unique_id "amt-vpSUkh3e5AhEJOBU7gABmjI"]
[Thu Jul 30 11:41:35.968533 2026] [security2:error] [pid 643573:tid 643782] [client 68.221.186.136:14889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/acme-challenge/adminfuns.php"] [unique_id "amt-v_xWyxgRnoFKAJ_ThwAAAlw"]
[Thu Jul 30 11:41:36.089623 2026] [proxy:error] [pid 642360:tid 642545] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:41:36.089675 2026] [proxy_http:error] [pid 642360:tid 642545] [client 193.47.62.167:45826] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:41:36.090246 2026] [proxy:error] [pid 642360:tid 642545] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:41:36.090292 2026] [proxy_http:error] [pid 642360:tid 642545] [client 193.47.62.167:45826] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:41:37.189467 2026] [core:notice] [pid 642360:tid 642586] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:41:37.918800 2026] [core:notice] [pid 642360:tid 642574] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:41:38.132060 2026] [security2:error] [pid 643573:tid 643729] [client 43.172.194.63:45554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dlr.djb.temporary.site"] [uri "/index.php"] [unique_id "amt-wfxWyxgRnoFKAJ_TmQAAAic"]
[Thu Jul 30 11:41:38.617898 2026] [core:error] [pid 643573:tid 643735] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:38.617923 2026] [core:error] [pid 643573:tid 643735] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:38.620359 2026] [core:error] [pid 642360:tid 642497] [client 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:38.620390 2026] [core:error] [pid 642360:tid 642497] [client 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:38.624035 2026] [core:error] [pid 643573:tid 643762] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:38.624054 2026] [core:error] [pid 643573:tid 643762] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:38.664219 2026] [core:error] [pid 643253:tid 643451] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:38.664242 2026] [core:error] [pid 643253:tid 643451] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:38.664696 2026] [core:error] [pid 643573:tid 643755] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:38.664709 2026] [core:error] [pid 643573:tid 643755] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:38.707131 2026] [security2:error] [pid 642360:tid 642577] [client 68.221.186.136:18574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "amt-wpSUkh3e5AhEJOBVLgAAAeY"]
[Thu Jul 30 11:41:38.940887 2026] [security2:error] [pid 642360:tid 642404] [remote 57.141.0.63:23146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amt-wpSUkh3e5AhEJOBVMQABvis"]
[Thu Jul 30 11:41:39.119079 2026] [security2:error] [pid 643573:tid 643742] [client 57.141.0.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt-wvxWyxgRnoFKAJ_TowAAAjQ"]
[Thu Jul 30 11:41:39.550940 2026] [security2:error] [pid 643573:tid 643797] [client 68.221.186.136:18842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/acme-challenge/classsmtps.php"] [unique_id "amt-w_xWyxgRnoFKAJ_TvQAAAms"]
[Thu Jul 30 11:41:40.037315 2026] [core:notice] [pid 643573:tid 643781] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:41:40.056071 2026] [security2:error] [pid 643573:tid 643769] [client 176.241.66.87:54178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt-xPxWyxgRnoFKAJ_TwgAAAk8"]
[Thu Jul 30 11:41:40.056192 2026] [security2:error] [pid 643573:tid 643769] [client 176.241.66.87:54178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt-xPxWyxgRnoFKAJ_TwgAAAk8"]
[Thu Jul 30 11:41:40.106317 2026] [core:error] [pid 642360:tid 642526] [client 191.96.227.82:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://airevoduct.ltd/
[Thu Jul 30 11:41:40.106347 2026] [core:error] [pid 642360:tid 642526] [client 191.96.227.82:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://airevoduct.ltd/
[Thu Jul 30 11:41:40.247703 2026] [security2:error] [pid 643573:tid 643627] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt-xPxWyxgRnoFKAJ_TxAACXC4"]
[Thu Jul 30 11:41:40.247842 2026] [security2:error] [pid 643573:tid 643782] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt-xPxWyxgRnoFKAJ_TxAACXC4"]
[Thu Jul 30 11:41:40.697595 2026] [security2:error] [pid 643573:tid 643834] [client 68.221.186.136:46731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "amt-xPxWyxgRnoFKAJ_TxQAAApA"]
[Thu Jul 30 11:41:41.018249 2026] [security2:error] [pid 642360:tid 642516] [client 57.141.0.61:50488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amt-xJSUkh3e5AhEJOBVUwABqU8"], referer: https://igetvape-australia.com/product-category/alibarbar-rich-8000-puffs/?add-to-cart=1053
[Thu Jul 30 11:41:41.381254 2026] [security2:error] [pid 643253:tid 643478] [client 68.221.186.136:17656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/acme-challenge/doc.php"] [unique_id "amt-xcjqbtjBYzqM1uYitAAAAF4"]
[Thu Jul 30 11:41:41.621559 2026] [authz_core:error] [pid 642360:tid 642492] [client 157.245.105.107:57788] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.DS_Store
[Thu Jul 30 11:41:42.416351 2026] [authz_core:error] [pid 643573:tid 643711] [client 157.245.105.107:46774] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.env
[Thu Jul 30 11:41:42.547482 2026] [proxy:error] [pid 642360:tid 642593] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:41:42.547535 2026] [proxy_http:error] [pid 642360:tid 642593] [client 44.216.125.112:54490] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:41:42.548106 2026] [proxy:error] [pid 642360:tid 642593] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:41:42.548151 2026] [proxy_http:error] [pid 642360:tid 642593] [client 44.216.125.112:54490] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:41:42.791333 2026] [security2:error] [pid 642360:tid 642494] [client 68.221.186.136:17622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/acme-challenge/fond.php"] [unique_id "amt-xpSUkh3e5AhEJOBVbQAAAZM"]
[Thu Jul 30 11:41:43.491896 2026] [security2:error] [pid 643573:tid 643726] [client 68.221.186.136:17630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "amt-x_xWyxgRnoFKAJ_T3gAAAiQ"]
[Thu Jul 30 11:41:44.179177 2026] [security2:error] [pid 643573:tid 643756] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt-x_xWyxgRnoFKAJ_T4QACQmw"]
[Thu Jul 30 11:41:44.331924 2026] [security2:error] [pid 642360:tid 642505] [client 68.221.186.136:17638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/acme-challenge/license.php"] [unique_id "amt-yJSUkh3e5AhEJOBVgAAAAZ4"]
[Thu Jul 30 11:41:44.884828 2026] [security2:error] [pid 643253:tid 643443] [client 68.221.186.136:20280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/acme-challenge/mariju.php"] [unique_id "amt-yMjqbtjBYzqM1uYitgAAADs"]
[Thu Jul 30 11:41:46.577899 2026] [authz_core:error] [pid 643573:tid 643792] [client 157.245.105.107:46796] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.git
[Thu Jul 30 11:41:46.893151 2026] [proxy:error] [pid 643573:tid 643828] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:41:46.893219 2026] [proxy_http:error] [pid 643573:tid 643828] [client 34.224.175.62:29096] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:41:46.893783 2026] [proxy:error] [pid 643573:tid 643828] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:41:46.893827 2026] [proxy_http:error] [pid 643573:tid 643828] [client 34.224.175.62:29096] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:41:46.977037 2026] [proxy:error] [pid 643573:tid 643831] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:41:46.977131 2026] [proxy_http:error] [pid 643573:tid 643831] [client 32.194.121.99:16370] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:41:46.977974 2026] [proxy:error] [pid 643573:tid 643831] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:41:46.978046 2026] [proxy_http:error] [pid 643573:tid 643831] [client 32.194.121.99:16370] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:41:47.545400 2026] [proxy:error] [pid 642360:tid 642574] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:41:47.545627 2026] [proxy_http:error] [pid 642360:tid 642574] [client 54.87.222.253:46114] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:41:47.546189 2026] [proxy:error] [pid 642360:tid 642574] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:41:47.546232 2026] [proxy_http:error] [pid 642360:tid 642574] [client 54.87.222.253:46114] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:41:47.634535 2026] [proxy:error] [pid 642360:tid 642597] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:41:47.634643 2026] [proxy_http:error] [pid 642360:tid 642597] [client 3.228.112.215:6872] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:41:47.635507 2026] [proxy:error] [pid 642360:tid 642597] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:41:47.635572 2026] [proxy_http:error] [pid 642360:tid 642597] [client 3.228.112.215:6872] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:41:48.194587 2026] [core:notice] [pid 642360:tid 642546] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:41:48.350914 2026] [security2:error] [pid 643573:tid 643752] [client 68.221.186.136:18109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/acme-challenge/moon.php"] [unique_id "amt-zPxWyxgRnoFKAJ_UDgAAAj4"]
[Thu Jul 30 11:41:48.449605 2026] [autoindex:error] [pid 642360:tid 642514] [client 40.77.167.150:0] AH01276: Cannot serve directory /home2/mbmudite/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:41:49.239917 2026] [security2:error] [pid 643253:tid 643417] [client 68.221.186.136:17648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amt-zcjqbtjBYzqM1uYiuwAAACE"]
[Thu Jul 30 11:41:49.387795 2026] [security2:error] [pid 643573:tid 643694] [remote 74.7.241.60:60694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/content/article.php"] [unique_id "amt-zfxWyxgRnoFKAJ_UGwACSXE"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/content/1784122425_Physioth%C3%A9rapie%20%C3%A0%20Domicile.jpg
[Thu Jul 30 11:41:49.973042 2026] [security2:error] [pid 643573:tid 643800] [client 68.221.186.136:18104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "amt-zfxWyxgRnoFKAJ_UIAAAAm4"]
[Thu Jul 30 11:41:50.042671 2026] [security2:error] [pid 642360:tid 642544] [client 213.152.187.230:40786] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amt-zpSUkh3e5AhEJOBV1AAAAcU"]
[Thu Jul 30 11:41:50.042779 2026] [security2:error] [pid 642360:tid 642544] [client 213.152.187.230:40786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amt-zpSUkh3e5AhEJOBV1AAAAcU"]
[Thu Jul 30 11:41:50.789395 2026] [security2:error] [pid 643573:tid 643780] [client 176.241.66.87:54710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt-zvxWyxgRnoFKAJ_UJwAAAlo"]
[Thu Jul 30 11:41:50.789537 2026] [security2:error] [pid 643573:tid 643780] [client 176.241.66.87:54710] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt-zvxWyxgRnoFKAJ_UJwAAAlo"]
[Thu Jul 30 11:41:51.152243 2026] [security2:error] [pid 643573:tid 643697] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt-z_xWyxgRnoFKAJ_UKwACYHQ"]
[Thu Jul 30 11:41:51.152409 2026] [security2:error] [pid 643573:tid 643786] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt-z_xWyxgRnoFKAJ_UKwACYHQ"]
[Thu Jul 30 11:41:51.211817 2026] [security2:error] [pid 643573:tid 643744] [client 68.221.186.136:20249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "amt-z_xWyxgRnoFKAJ_ULQAAAjY"]
[Thu Jul 30 11:41:52.133155 2026] [security2:error] [pid 643573:tid 643791] [client 57.141.0.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt-z_xWyxgRnoFKAJ_UOQAAAmU"]
[Thu Jul 30 11:41:52.588927 2026] [security2:error] [pid 642360:tid 642499] [client 157.245.105.107:40998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.105.245.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.greensparkle.net.lom.gzj.temporary.site"] [uri "/info.php"] [unique_id "amt-0JSUkh3e5AhEJOBV9AAAAZg"]
[Thu Jul 30 11:41:53.546755 2026] [security2:error] [pid 643573:tid 643824] [client 68.221.186.136:20257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/amaxx.php"] [unique_id "amt-0fxWyxgRnoFKAJ_USgAAAoY"]
[Thu Jul 30 11:41:54.612942 2026] [security2:error] [pid 643573:tid 643760] [client 68.221.186.136:18078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/bek.php"] [unique_id "amt-0vxWyxgRnoFKAJ_UWQAAAkY"]
[Thu Jul 30 11:41:54.835287 2026] [security2:error] [pid 643573:tid 643739] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt-0vxWyxgRnoFKAJ_UWwACMXw"]
[Thu Jul 30 11:41:55.399634 2026] [security2:error] [pid 642360:tid 642504] [client 46.232.235.3:47398] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.greensparkle.net"] [uri "/.env"] [unique_id "amt-05SUkh3e5AhEJOBWEAAAAZ0"]
[Thu Jul 30 11:41:56.503690 2026] [security2:error] [pid 643573:tid 643797] [client 68.221.186.136:17238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/caches.php.suspected"] [unique_id "amt-1PxWyxgRnoFKAJ_UeAAAAms"]
[Thu Jul 30 11:41:56.908809 2026] [authz_core:error] [pid 643573:tid 643759] [client 46.232.235.3:35508] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.env
[Thu Jul 30 11:41:56.925999 2026] [authz_core:error] [pid 643573:tid 643720] [client 46.232.235.3:35498] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.env
[Thu Jul 30 11:41:57.446545 2026] [authz_core:error] [pid 643573:tid 643818] [client 157.245.105.107:41036] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.vscode
[Thu Jul 30 11:41:57.503084 2026] [authz_core:error] [pid 642360:tid 642542] [client 46.232.235.3:35522] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.git
[Thu Jul 30 11:41:57.602263 2026] [security2:error] [pid 643573:tid 643826] [client 68.221.186.136:14736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/class.api.php"] [unique_id "amt-1fxWyxgRnoFKAJ_UhAAAAog"]
[Thu Jul 30 11:41:57.701768 2026] [authz_core:error] [pid 642360:tid 642604] [client 46.232.235.3:35536] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.git
[Thu Jul 30 11:41:57.702530 2026] [security2:error] [pid 642360:tid 642604] [client 46.232.235.3:35536] ModSecurity: Warning. Matched phrase "Firefox/7.0" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "403"] [hostname "greensparkle.net"] [uri "/cgi-sys/403.html"] [unique_id "amt-1ZSUkh3e5AhEJOBWLAAAAgE"]
[Thu Jul 30 11:41:58.196511 2026] [security2:error] [pid 643573:tid 643716] [client 68.221.186.136:14730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/cong.php"] [unique_id "amt-1vxWyxgRnoFKAJ_UhQAAAho"]
[Thu Jul 30 11:41:58.944694 2026] [security2:error] [pid 643573:tid 643725] [client 68.221.186.136:17221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/content.php"] [unique_id "amt-1vxWyxgRnoFKAJ_UkgAAAiM"]
[Thu Jul 30 11:41:59.013654 2026] [authz_core:error] [pid 643573:tid 643726] [client 46.232.235.3:35542] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.env
[Thu Jul 30 11:41:59.489682 2026] [security2:error] [pid 643573:tid 643745] [client 118.194.253.208:49476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.greensparkle.net"] [uri "/backup/.env"] [unique_id "amt-1_xWyxgRnoFKAJ_UmAAAAjc"]
[Thu Jul 30 11:41:59.681689 2026] [authz_core:error] [pid 643573:tid 643804] [client 46.232.235.3:35558] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.git
[Thu Jul 30 11:41:59.766851 2026] [security2:error] [pid 642360:tid 642601] [client 68.221.186.136:17228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/cwianpri.php"] [unique_id "amt-15SUkh3e5AhEJOBWRgAAAf4"]
[Thu Jul 30 11:41:59.822962 2026] [security2:error] [pid 643573:tid 643760] [client 118.194.253.208:49476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.greensparkle.net"] [uri "/backups/.env"] [unique_id "amt-1_xWyxgRnoFKAJ_UmgAAAkY"]
[Thu Jul 30 11:42:00.155671 2026] [security2:error] [pid 643573:tid 643816] [client 118.194.253.208:49476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.greensparkle.net"] [uri "/old/.env"] [unique_id "amt-2PxWyxgRnoFKAJ_UngAAAn4"]
[Thu Jul 30 11:42:00.252613 2026] [core:notice] [pid 642360:tid 642421] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:42:00.257167 2026] [security2:error] [pid 642360:tid 642566] [client 191.36.149.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/citationstylelanguage/get/acm-sig-proceedings"] [unique_id "amt-15SUkh3e5AhEJOBWSQAB2zw"]
[Thu Jul 30 11:42:00.487885 2026] [security2:error] [pid 643573:tid 643806] [client 118.194.253.208:49476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.greensparkle.net"] [uri "/temp/.env"] [unique_id "amt-2PxWyxgRnoFKAJ_UpQAAAnQ"]
[Thu Jul 30 11:42:00.506437 2026] [security2:error] [pid 643573:tid 643762] [client 68.221.186.136:20251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/elp.php"] [unique_id "amt-2PxWyxgRnoFKAJ_UpgAAAkg"]
[Thu Jul 30 11:42:00.821300 2026] [security2:error] [pid 643573:tid 643823] [client 118.194.253.208:49476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.greensparkle.net"] [uri "/tmp/.env"] [unique_id "amt-2PxWyxgRnoFKAJ_UqwAAAoU"]
[Thu Jul 30 11:42:01.154273 2026] [authz_core:error] [pid 643573:tid 643720] [client 118.194.253.208:49476] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.streamlit
[Thu Jul 30 11:42:01.270144 2026] [security2:error] [pid 642360:tid 642559] [client 68.221.186.136:20265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/kwggvpup.php"] [unique_id "amt-2ZSUkh3e5AhEJOBWVAAAAdQ"]
[Thu Jul 30 11:42:01.522027 2026] [security2:error] [pid 642360:tid 642579] [client 176.241.66.87:55244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt-2ZSUkh3e5AhEJOBWWAAAAeg"]
[Thu Jul 30 11:42:01.522234 2026] [security2:error] [pid 642360:tid 642579] [client 176.241.66.87:55244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt-2ZSUkh3e5AhEJOBWWAAAAeg"]
[Thu Jul 30 11:42:01.775466 2026] [security2:error] [pid 643573:tid 643727] [client 68.221.186.136:14762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/101d2ae2-f2f3-4977-b35d-b3a0ad74a469.php"] [unique_id "amt-2fxWyxgRnoFKAJ_UvQAAAiU"]
[Thu Jul 30 11:42:02.047315 2026] [security2:error] [pid 642360:tid 642417] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt-2pSUkh3e5AhEJOBWXAACBjg"]
[Thu Jul 30 11:42:02.047476 2026] [security2:error] [pid 642360:tid 642609] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt-2pSUkh3e5AhEJOBWXAACBjg"]
[Thu Jul 30 11:42:02.102931 2026] [core:notice] [pid 643573:tid 643616] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:42:02.622452 2026] [security2:error] [pid 643253:tid 643451] [client 68.221.186.136:20252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/LA.php"] [unique_id "amt-2sjqbtjBYzqM1uYi5wAAAEM"]
[Thu Jul 30 11:42:03.704252 2026] [security2:error] [pid 643573:tid 643619] [remote 72.167.132.114:57990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-login.php"] [unique_id "amt-2_xWyxgRnoFKAJ_UzwACWSY"]
[Thu Jul 30 11:42:03.905777 2026] [security2:error] [pid 643253:tid 643436] [client 68.221.186.136:17222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/Newsupway.php"] [unique_id "amt-28jqbtjBYzqM1uYi7gAAADQ"]
[Thu Jul 30 11:42:04.414839 2026] [core:notice] [pid 643573:tid 643630] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:42:05.066195 2026] [security2:error] [pid 643573:tid 643773] [client 68.221.186.136:18049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/a.php"] [unique_id "amt-3fxWyxgRnoFKAJ_U1gAAAlM"]
[Thu Jul 30 11:42:05.132445 2026] [core:notice] [pid 643573:tid 643631] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:42:05.620447 2026] [security2:error] [pid 643573:tid 643833] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt-3fxWyxgRnoFKAJ_U3gACjzk"]
[Thu Jul 30 11:42:05.929878 2026] [security2:error] [pid 643253:tid 643471] [client 68.221.186.136:18065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "amt-3cjqbtjBYzqM1uYi_AAAAFc"]
[Thu Jul 30 11:42:05.933653 2026] [security2:error] [pid 643573:tid 643775] [client 89.37.95.54:35340] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "lilyinspires.com"] [uri "/wp-comments-post.php"] [unique_id "amt-3fxWyxgRnoFKAJ_U3QAAAlU"]
[Thu Jul 30 11:42:06.049240 2026] [security2:error] [pid 643573:tid 643775] [client 89.37.95.54:35340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "lilyinspires.com"] [uri "/wp-comments-post.php"] [unique_id "amt-3fxWyxgRnoFKAJ_U3QAAAlU"]
[Thu Jul 30 11:42:06.050304 2026] [security2:error] [pid 643573:tid 643775] [client 89.37.95.54:35340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lilyinspires.com"] [uri "/wp-comments-post.php"] [unique_id "amt-3fxWyxgRnoFKAJ_U3QAAAlU"]
[Thu Jul 30 11:42:06.217941 2026] [authz_core:error] [pid 643573:tid 643724] [client 46.232.235.3:54030] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.env
[Thu Jul 30 11:42:06.355277 2026] [authz_core:error] [pid 643253:tid 643456] [client 46.232.235.3:54032] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.env
[Thu Jul 30 11:42:06.687869 2026] [security2:error] [pid 643573:tid 643718] [client 68.221.186.136:17393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/amaxx.php"] [unique_id "amt-3vxWyxgRnoFKAJ_U6QAAAhw"]
[Thu Jul 30 11:42:07.290069 2026] [authz_core:error] [pid 642360:tid 642532] [client 46.232.235.3:54044] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.git
[Thu Jul 30 11:42:07.372840 2026] [authz_core:error] [pid 642360:tid 642581] [client 46.232.235.3:54056] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.git
[Thu Jul 30 11:42:07.833658 2026] [security2:error] [pid 642360:tid 642515] [client 118.194.253.208:59072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.greensparkle.net"] [uri "/index.php"] [unique_id "amt-35SUkh3e5AhEJOBWpwAAAag"]
[Thu Jul 30 11:42:07.833859 2026] [security2:error] [pid 643573:tid 643725] [client 57.141.0.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt-3_xWyxgRnoFKAJ_U-wAAAiM"]
[Thu Jul 30 11:42:08.451008 2026] [core:notice] [pid 643573:tid 643804] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:42:10.102496 2026] [security2:error] [pid 643573:tid 643730] [client 68.221.186.136:14225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/bb.php"] [unique_id "amt-4vxWyxgRnoFKAJ_VJwAAAig"]
[Thu Jul 30 11:42:10.659667 2026] [authz_core:error] [pid 643573:tid 643734] [client 118.194.253.208:59080] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/secrets.yml
[Thu Jul 30 11:42:10.694563 2026] [security2:error] [pid 642360:tid 642497] [client 2a03:2880:f800:35:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt-4ZSUkh3e5AhEJOBWwQABlmE"]
[Thu Jul 30 11:42:10.998867 2026] [authz_core:error] [pid 643573:tid 643796] [client 118.194.253.208:59080] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.secrets
[Thu Jul 30 11:42:11.340554 2026] [authz_core:error] [pid 643573:tid 643782] [client 118.194.253.208:59080] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.env.vault
[Thu Jul 30 11:42:11.472878 2026] [security2:error] [pid 643573:tid 643827] [client 68.221.186.136:17361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/cifcxgxm.php"] [unique_id "amt-4_xWyxgRnoFKAJ_VNQAAAok"]
[Thu Jul 30 11:42:11.682346 2026] [authz_core:error] [pid 643573:tid 643758] [client 118.194.253.208:59080] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.aws
[Thu Jul 30 11:42:12.022901 2026] [authz_core:error] [pid 643573:tid 643830] [client 118.194.253.208:59080] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.aws
[Thu Jul 30 11:42:12.093303 2026] [security2:error] [pid 643573:tid 643740] [client 176.241.66.87:55784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt-5PxWyxgRnoFKAJ_VQAAAAjI"]
[Thu Jul 30 11:42:12.093441 2026] [security2:error] [pid 643573:tid 643740] [client 176.241.66.87:55784] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt-5PxWyxgRnoFKAJ_VQAAAAjI"]
[Thu Jul 30 11:42:12.201885 2026] [security2:error] [pid 643573:tid 643833] [client 213.152.187.230:43960] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amt-5PxWyxgRnoFKAJ_VQQAAAo8"]
[Thu Jul 30 11:42:12.202002 2026] [security2:error] [pid 643573:tid 643833] [client 213.152.187.230:43960] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amt-5PxWyxgRnoFKAJ_VQQAAAo8"]
[Thu Jul 30 11:42:12.349479 2026] [security2:error] [pid 642360:tid 642614] [client 110.249.201.23:20232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.urwru.club"] [uri "/robots.txt"] [unique_id "amt-5JSUkh3e5AhEJOBW2AAAAgs"]
[Thu Jul 30 11:42:12.363240 2026] [authz_core:error] [pid 643573:tid 643800] [client 118.194.253.208:59080] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.docker
[Thu Jul 30 11:42:12.702604 2026] [security2:error] [pid 643573:tid 643822] [client 118.194.253.208:59080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.greensparkle.net"] [uri "/storage/framework/.env"] [unique_id "amt-5PxWyxgRnoFKAJ_VUAAAAoQ"]
[Thu Jul 30 11:42:12.921953 2026] [security2:error] [pid 643573:tid 643661] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt-5PxWyxgRnoFKAJ_VVAACc1A"]
[Thu Jul 30 11:42:12.922164 2026] [security2:error] [pid 643573:tid 643805] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt-5PxWyxgRnoFKAJ_VVAACc1A"]
[Thu Jul 30 11:42:13.042029 2026] [security2:error] [pid 643573:tid 643736] [client 118.194.253.208:59080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.greensparkle.net"] [uri "/laravel/.env"] [unique_id "amt-5fxWyxgRnoFKAJ_VWAAAAi4"]
[Thu Jul 30 11:42:13.317390 2026] [security2:error] [pid 643573:tid 643726] [client 68.221.186.136:29588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/ckyocyyp.php"] [unique_id "amt-5fxWyxgRnoFKAJ_VWgAAAiQ"]
[Thu Jul 30 11:42:14.225160 2026] [security2:error] [pid 642360:tid 642480] [remote 216.73.216.152:52199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amt-5pSUkh3e5AhEJOBW-QABtHc"]
[Thu Jul 30 11:42:14.452414 2026] [security2:error] [pid 643573:tid 643789] [client 68.221.186.136:21198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/classwithtostring.php"] [unique_id "amt-5vxWyxgRnoFKAJ_VYAAAAmM"]
[Thu Jul 30 11:42:15.030847 2026] [security2:error] [pid 643573:tid 643830] [client 68.221.186.136:21217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/content.php"] [unique_id "amt-5_xWyxgRnoFKAJ_VZQAAAow"]
[Thu Jul 30 11:42:15.101031 2026] [authz_core:error] [pid 642360:tid 642525] [client 118.194.253.208:59148] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.gcp
[Thu Jul 30 11:42:15.436646 2026] [authz_core:error] [pid 642360:tid 642565] [client 118.194.253.208:59148] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.gcp
[Thu Jul 30 11:42:15.639922 2026] [security2:error] [pid 643573:tid 643767] [client 68.221.186.136:21223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/content.php.suspected"] [unique_id "amt-5_xWyxgRnoFKAJ_VagAAAk0"]
[Thu Jul 30 11:42:16.126029 2026] [security2:error] [pid 643573:tid 643666] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt-6PxWyxgRnoFKAJ_VbAACjVU"]
[Thu Jul 30 11:42:16.126206 2026] [security2:error] [pid 643573:tid 643831] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt-6PxWyxgRnoFKAJ_VbAACjVU"]
[Thu Jul 30 11:42:16.498372 2026] [security2:error] [pid 643573:tid 643724] [client 68.221.186.136:29678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/doc.php"] [unique_id "amt-6PxWyxgRnoFKAJ_VcAAAAiI"]
[Thu Jul 30 11:42:16.680492 2026] [security2:error] [pid 643573:tid 643800] [client 66.249.64.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.j-nintei.com"] [uri "/index.php"] [unique_id "amt-5_xWyxgRnoFKAJ_VZwAAAm4"]
[Thu Jul 30 11:42:17.645905 2026] [core:notice] [pid 643253:tid 643451] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:42:17.711564 2026] [security2:error] [pid 643573:tid 643733] [client 68.221.186.136:29651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/fond.php"] [unique_id "amt-6fxWyxgRnoFKAJ_VdgAAAis"]
[Thu Jul 30 11:42:18.445008 2026] [security2:error] [pid 643573:tid 643827] [client 68.221.186.136:14536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/gkiliuew.php"] [unique_id "amt-6vxWyxgRnoFKAJ_VegAAAok"]
[Thu Jul 30 11:42:19.451453 2026] [security2:error] [pid 643573:tid 643773] [client 68.221.186.136:19829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/iR7SzrsOUEP.php"] [unique_id "amt-6_xWyxgRnoFKAJ_VgAAAAlM"]
[Thu Jul 30 11:42:20.567599 2026] [security2:error] [pid 643573:tid 643669] [remote 74.7.241.59:58724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amt-7PxWyxgRnoFKAJ_VhwACGlg"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/pixelyoursite/includes
[Thu Jul 30 11:42:20.701213 2026] [security2:error] [pid 643573:tid 643819] [client 68.221.186.136:14528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/ibkejxnu.php"] [unique_id "amt-7PxWyxgRnoFKAJ_ViAAAAoE"]
[Thu Jul 30 11:42:21.121819 2026] [security2:error] [pid 643573:tid 643671] [remote 185.191.171.1:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lifelogstory.com"] [uri "/robots.txt"] [unique_id "amt-7fxWyxgRnoFKAJ_VigACVlo"]
[Thu Jul 30 11:42:21.122019 2026] [security2:error] [pid 643573:tid 643776] [client 185.191.171.1:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lifelogstory.com"] [uri "/robots.txt"] [unique_id "amt-7fxWyxgRnoFKAJ_VigACVlo"]
[Thu Jul 30 11:42:21.453542 2026] [security2:error] [pid 643573:tid 643736] [client 68.221.186.136:29677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/install.php"] [unique_id "amt-7fxWyxgRnoFKAJ_VjAAAAi4"]
[Thu Jul 30 11:42:22.567278 2026] [security2:error] [pid 643573:tid 643815] [client 57.141.0.66:54566] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amt-7vxWyxgRnoFKAJ_VlAACfVs"], referer: https://igetvape-australia.com/store/?product-page=11&add-to-cart=117
[Thu Jul 30 11:42:22.607409 2026] [security2:error] [pid 643573:tid 643675] [remote 47.128.28.107:64228] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/moose-knuckles-jacket-black-10/"] [unique_id "amt-7vxWyxgRnoFKAJ_VlwACbV4"]
[Thu Jul 30 11:42:22.776155 2026] [security2:error] [pid 642360:tid 642553] [client 176.241.66.87:40163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt-7pSUkh3e5AhEJOBXSAAAAc4"]
[Thu Jul 30 11:42:22.776274 2026] [security2:error] [pid 642360:tid 642553] [client 176.241.66.87:40163] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt-7pSUkh3e5AhEJOBXSAAAAc4"]
[Thu Jul 30 11:42:23.017310 2026] [security2:error] [pid 643573:tid 643806] [client 162.19.8.250:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "higherdimensionsii.com"] [uri "/index.php"] [unique_id "amt-7vxWyxgRnoFKAJ_VlQACdFw"]
[Thu Jul 30 11:42:23.241116 2026] [core:notice] [pid 642360:tid 642400] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:42:23.728041 2026] [security2:error] [pid 643573:tid 643738] [client 68.221.186.136:20224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/lang-load-role.php"] [unique_id "amt-7_xWyxgRnoFKAJ_VowAAAjA"]
[Thu Jul 30 11:42:23.886898 2026] [security2:error] [pid 643573:tid 643610] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt-7_xWyxgRnoFKAJ_VpgACWR0"]
[Thu Jul 30 11:42:23.887098 2026] [security2:error] [pid 643573:tid 643779] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt-7_xWyxgRnoFKAJ_VpgACWR0"]
[Thu Jul 30 11:42:23.951265 2026] [security2:error] [pid 643573:tid 643603] [remote 185.191.171.13:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lifelogstory.com"] [uri "/"] [unique_id "amt-7_xWyxgRnoFKAJ_VpwACJBY"]
[Thu Jul 30 11:42:23.951439 2026] [security2:error] [pid 643573:tid 643726] [client 185.191.171.13:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lifelogstory.com"] [uri "/"] [unique_id "amt-7_xWyxgRnoFKAJ_VpwACJBY"]
[Thu Jul 30 11:42:25.659056 2026] [security2:error] [pid 643573:tid 643684] [remote 57.141.0.66:44056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/REFORMASI/issue/archive"] [unique_id "amt-8fxWyxgRnoFKAJ_VvQACOGc"]
[Thu Jul 30 11:42:26.171798 2026] [security2:error] [pid 643573:tid 643618] [remote 85.208.96.194:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lifelogstory.com"] [uri "/sitemap.xml"] [unique_id "amt-8vxWyxgRnoFKAJ_VzAACMSU"]
[Thu Jul 30 11:42:26.172049 2026] [security2:error] [pid 643573:tid 643739] [client 85.208.96.194:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lifelogstory.com"] [uri "/sitemap.xml"] [unique_id "amt-8vxWyxgRnoFKAJ_VzAACMSU"]
[Thu Jul 30 11:42:26.524204 2026] [security2:error] [pid 642360:tid 642526] [client 68.221.186.136:14217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/link.php"] [unique_id "amt-8pSUkh3e5AhEJOBXagAAAbM"]
[Thu Jul 30 11:42:26.745328 2026] [security2:error] [pid 642360:tid 642417] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt-8pSUkh3e5AhEJOBXbAAB1jg"]
[Thu Jul 30 11:42:26.745635 2026] [security2:error] [pid 642360:tid 642561] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt-8pSUkh3e5AhEJOBXbAAB1jg"]
[Thu Jul 30 11:42:26.847479 2026] [security2:error] [pid 643253:tid 643467] [client 172.237.109.114:7652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-8sjqbtjBYzqM1uYjMAAAAFM"]
[Thu Jul 30 11:42:26.847834 2026] [security2:error] [pid 643573:tid 643744] [client 172.237.109.114:31046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-8vxWyxgRnoFKAJ_VxgAAAjY"]
[Thu Jul 30 11:42:26.887723 2026] [security2:error] [pid 643573:tid 643743] [client 172.237.109.114:64374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-8vxWyxgRnoFKAJ_VyQAAAjU"]
[Thu Jul 30 11:42:26.905581 2026] [security2:error] [pid 643573:tid 643833] [client 172.237.109.114:19304] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-8vxWyxgRnoFKAJ_VxwAAAo8"]
[Thu Jul 30 11:42:26.905730 2026] [security2:error] [pid 643573:tid 643835] [client 172.237.109.114:12036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-8vxWyxgRnoFKAJ_VyAAAApE"]
[Thu Jul 30 11:42:26.906789 2026] [security2:error] [pid 643253:tid 643492] [client 172.237.109.114:44511] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-8sjqbtjBYzqM1uYjMgAAAGw"]
[Thu Jul 30 11:42:26.927170 2026] [security2:error] [pid 643253:tid 643484] [client 172.237.109.114:45682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-8sjqbtjBYzqM1uYjMQAAAGQ"]
[Thu Jul 30 11:42:26.930624 2026] [security2:error] [pid 643573:tid 643823] [client 172.237.109.114:6984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-8vxWyxgRnoFKAJ_VygAAAoU"]
[Thu Jul 30 11:42:27.139141 2026] [security2:error] [pid 643573:tid 643597] [remote 213.180.203.123:59738] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "spacexpress.africa"] [uri "/2024/02/27/enhancing-project-management-processes-with-business-consulting/"] [unique_id "amt-8_xWyxgRnoFKAJ_V2wACVxA"]
[Thu Jul 30 11:42:27.167104 2026] [core:notice] [pid 642360:tid 642515] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:42:27.512430 2026] [security2:error] [pid 643253:tid 643446] [client 185.156.175.171:59254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.175.156.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amt-88jqbtjBYzqM1uYjOgAAAD4"]
[Thu Jul 30 11:42:27.512647 2026] [security2:error] [pid 643253:tid 643446] [client 185.156.175.171:59254] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amt-88jqbtjBYzqM1uYjOgAAAD4"]
[Thu Jul 30 11:42:27.700463 2026] [security2:error] [pid 643253:tid 643463] [client 162.19.8.250:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "higherdimensionsii.com"] [uri "/index.php"] [unique_id "amt-8sjqbtjBYzqM1uYjOAAATxQ"]
[Thu Jul 30 11:42:27.788240 2026] [security2:error] [pid 643573:tid 643763] [client 172.237.109.114:32112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-8_xWyxgRnoFKAJ_V2QAAAkk"]
[Thu Jul 30 11:42:27.796491 2026] [security2:error] [pid 643573:tid 643827] [client 172.237.109.114:57885] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-8_xWyxgRnoFKAJ_V2gAAAok"]
[Thu Jul 30 11:42:27.801476 2026] [security2:error] [pid 643573:tid 643736] [client 172.237.109.114:20806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-8_xWyxgRnoFKAJ_V2AAAAi4"]
[Thu Jul 30 11:42:27.801502 2026] [security2:error] [pid 642360:tid 642524] [client 172.237.109.114:27051] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-85SUkh3e5AhEJOBXbwAAAbE"]
[Thu Jul 30 11:42:27.816486 2026] [security2:error] [pid 643573:tid 643723] [client 172.237.109.114:44997] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-8_xWyxgRnoFKAJ_V1wAAAiE"]
[Thu Jul 30 11:42:27.817206 2026] [security2:error] [pid 642360:tid 642516] [client 172.237.109.114:12228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-85SUkh3e5AhEJOBXcAAAAak"]
[Thu Jul 30 11:42:27.837334 2026] [security2:error] [pid 642360:tid 642605] [client 172.237.109.114:65228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-85SUkh3e5AhEJOBXcQAAAgI"]
[Thu Jul 30 11:42:27.843688 2026] [security2:error] [pid 643573:tid 643767] [client 172.237.109.114:58190] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-8_xWyxgRnoFKAJ_V3AAAAk0"]
[Thu Jul 30 11:42:27.969381 2026] [security2:error] [pid 642360:tid 642403] [remote 57.141.0.44:34614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6146521103/feed/rss2/"] [unique_id "amt-85SUkh3e5AhEJOBXgAAB5io"]
[Thu Jul 30 11:42:28.002150 2026] [security2:error] [pid 643573:tid 643807] [client 68.221.186.136:14220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/mar.php"] [unique_id "amt-9PxWyxgRnoFKAJ_V4wAAAnU"]
[Thu Jul 30 11:42:28.308811 2026] [autoindex:error] [pid 643573:tid 643826] [client 143.198.88.13:56054] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_b1080a24/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: www.website-aa1e85b2.kxl.dup.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:42:28.685139 2026] [security2:error] [pid 643573:tid 643731] [client 172.237.109.114:57655] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-9PxWyxgRnoFKAJ_V5wAAAik"]
[Thu Jul 30 11:42:28.685201 2026] [security2:error] [pid 643573:tid 643728] [client 172.237.109.114:24036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-9PxWyxgRnoFKAJ_V5gAAAiY"]
[Thu Jul 30 11:42:28.713860 2026] [security2:error] [pid 643573:tid 643727] [client 172.237.109.114:51884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-9PxWyxgRnoFKAJ_V6AAAAiU"]
[Thu Jul 30 11:42:28.714129 2026] [security2:error] [pid 643253:tid 643495] [client 172.237.109.114:14432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-9MjqbtjBYzqM1uYjPAAAAG8"]
[Thu Jul 30 11:42:29.803700 2026] [security2:error] [pid 643253:tid 643475] [client 2a03:2880:f800:3c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt-9cjqbtjBYzqM1uYjPgAAWxg"]
[Thu Jul 30 11:42:30.142252 2026] [security2:error] [pid 643573:tid 643741] [client 68.221.186.136:20328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "amt-9vxWyxgRnoFKAJ_V_QAAAjM"]
[Thu Jul 30 11:42:30.363616 2026] [security2:error] [pid 642360:tid 642596] [client 57.141.0.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt-9ZSUkh3e5AhEJOBXmgAAAfk"]
[Thu Jul 30 11:42:30.735964 2026] [core:notice] [pid 643573:tid 643837] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:42:30.765961 2026] [security2:error] [pid 643573:tid 643714] [client 64.31.3.126:50668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amt-7_xWyxgRnoFKAJ_VpAAAAkw"], referer: https://globalmarks.pk/2023/08/28/parent-guide-babys-first-tooth-and-what-parents-must-know/#comment-2269
[Thu Jul 30 11:42:30.854731 2026] [security2:error] [pid 642360:tid 642526] [client 68.221.186.136:14222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "amt-9pSUkh3e5AhEJOBXqAAAAbM"]
[Thu Jul 30 11:42:31.050458 2026] [core:notice] [pid 643573:tid 643780] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:42:31.409935 2026] [core:notice] [pid 643253:tid 643280] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:42:31.435068 2026] [security2:error] [pid 643573:tid 643767] [client 68.221.186.136:18911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/plugins.php"] [unique_id "amt-9_xWyxgRnoFKAJ_WCQAAAk0"]
[Thu Jul 30 11:42:31.623972 2026] [security2:error] [pid 643573:tid 643751] [client 2a03:2880:f800:20:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt-9_xWyxgRnoFKAJ_WBwACPWk"]
[Thu Jul 30 11:42:31.856488 2026] [core:notice] [pid 643573:tid 643693] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:42:31.861105 2026] [security2:error] [pid 643573:tid 643759] [client 74.7.230.15:39880] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ejournalugj.com"] [uri "/robots.txt"] [unique_id "amt-9_xWyxgRnoFKAJ_WDAACRXA"]
[Thu Jul 30 11:42:32.635062 2026] [core:notice] [pid 643573:tid 643694] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:42:32.876254 2026] [security2:error] [pid 643573:tid 643825] [client 68.221.186.136:18936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/post.php"] [unique_id "amt--PxWyxgRnoFKAJ_WFwAAAoc"]
[Thu Jul 30 11:42:33.110883 2026] [authz_core:error] [pid 643573:tid 643794] [client 94.154.43.183:26860] AH01630: client denied by server configuration: /home1/jstnyxte/public_html/website_602f6769/.env
[Thu Jul 30 11:42:33.142934 2026] [security2:error] [pid 642360:tid 642592] [client 85.208.98.18:23764] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toscanamall.com"] [uri "/robots.txt"] [unique_id "amt--ZSUkh3e5AhEJOBXvQAAAfU"]
[Thu Jul 30 11:42:33.143057 2026] [security2:error] [pid 642360:tid 642592] [client 85.208.98.18:23764] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.toscanamall.com"] [uri "/robots.txt"] [unique_id "amt--ZSUkh3e5AhEJOBXvQAAAfU"]
[Thu Jul 30 11:42:33.440309 2026] [security2:error] [pid 643573:tid 643784] [client 85.208.98.18:20012] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/category/policiais/"] [unique_id "amt--fxWyxgRnoFKAJ_WIAAAAl4"], referer: https://insurancecouncilinc.com/
[Thu Jul 30 11:42:33.440442 2026] [security2:error] [pid 643573:tid 643784] [client 85.208.98.18:20012] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/category/policiais/"] [unique_id "amt--fxWyxgRnoFKAJ_WIAAAAl4"], referer: https://insurancecouncilinc.com/
[Thu Jul 30 11:42:33.444867 2026] [security2:error] [pid 643573:tid 643757] [client 57.141.0.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-32476423.xnc.nyx.temporary.site"] [uri "/index.php"] [unique_id "amt--PxWyxgRnoFKAJ_WEwAAAkM"]
[Thu Jul 30 11:42:33.554253 2026] [security2:error] [pid 643573:tid 643713] [client 176.241.66.87:40843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt--fxWyxgRnoFKAJ_WIwAAAhc"]
[Thu Jul 30 11:42:33.554393 2026] [security2:error] [pid 643573:tid 643713] [client 176.241.66.87:40843] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt--fxWyxgRnoFKAJ_WIwAAAhc"]
[Thu Jul 30 11:42:33.872761 2026] [security2:error] [pid 643573:tid 643701] [remote 85.208.98.18:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "teknomalay.com"] [uri "/robots.txt"] [unique_id "amt--fxWyxgRnoFKAJ_WJgACI3g"], referer: http://teknomalay.com/robots.txt
[Thu Jul 30 11:42:33.872930 2026] [security2:error] [pid 643573:tid 643725] [client 85.208.98.18:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "teknomalay.com"] [uri "/robots.txt"] [unique_id "amt--fxWyxgRnoFKAJ_WJgACI3g"], referer: http://teknomalay.com/robots.txt
[Thu Jul 30 11:42:33.934914 2026] [security2:error] [pid 643573:tid 643834] [client 68.221.186.136:21162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/shell.php"] [unique_id "amt--fxWyxgRnoFKAJ_WJwAAApA"]
[Thu Jul 30 11:42:34.808704 2026] [security2:error] [pid 642360:tid 642462] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt--pSUkh3e5AhEJOBXygABv2U"]
[Thu Jul 30 11:42:34.808864 2026] [security2:error] [pid 642360:tid 642538] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt--pSUkh3e5AhEJOBXygABv2U"]
[Thu Jul 30 11:42:35.085466 2026] [security2:error] [pid 642360:tid 642500] [client 47.79.228.42:53176] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "mail.womenclothingbox.com"] [uri "/"] [unique_id "amt--5SUkh3e5AhEJOBX8AAAAZk"]
[Thu Jul 30 11:42:35.158459 2026] [security2:error] [pid 642360:tid 642575] [client 47.79.228.42:53176] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "mail.womenclothingbox.com"] [uri "/wp-json/batch/v1"] [unique_id "amt--5SUkh3e5AhEJOBX9QAAAeQ"]
[Thu Jul 30 11:42:35.415814 2026] [security2:error] [pid 643573:tid 643809] [client 207.58.142.67:37617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt--vxWyxgRnoFKAJ_WMAAAAnc"]
[Thu Jul 30 11:42:35.897813 2026] [core:notice] [pid 642360:tid 642505] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:42:36.097925 2026] [security2:error] [pid 643573:tid 643767] [client 68.221.186.136:14113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/ssl.php"] [unique_id "amt-_PxWyxgRnoFKAJ_WPwAAAk0"]
[Thu Jul 30 11:42:36.128003 2026] [security2:error] [pid 642360:tid 642490] [client 207.58.142.67:19888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt-_JSUkh3e5AhEJOBX_wAAAY8"]
[Thu Jul 30 11:42:36.303243 2026] [security2:error] [pid 643573:tid 643703] [remote 52.167.144.204:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/jipkl/article/download/303/310"] [unique_id "amt-_PxWyxgRnoFKAJ_WQwACYHo"]
[Thu Jul 30 11:42:36.856012 2026] [security2:error] [pid 643573:tid 643815] [client 207.58.142.67:7634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt-_PxWyxgRnoFKAJ_WRwAAAn0"]
[Thu Jul 30 11:42:37.009800 2026] [core:error] [pid 642360:tid 642543] [client 66.249.74.5:34855] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:42:37.009827 2026] [core:error] [pid 642360:tid 642543] [client 66.249.74.5:34855] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:42:37.444299 2026] [security2:error] [pid 643573:tid 643698] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt-_fxWyxgRnoFKAJ_WSgACGXU"]
[Thu Jul 30 11:42:37.444470 2026] [security2:error] [pid 643573:tid 643715] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt-_fxWyxgRnoFKAJ_WSgACGXU"]
[Thu Jul 30 11:42:37.558642 2026] [security2:error] [pid 643573:tid 643740] [client 68.221.186.136:20291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/sx.php"] [unique_id "amt-_fxWyxgRnoFKAJ_WSwAAAjI"]
[Thu Jul 30 11:42:37.574243 2026] [security2:error] [pid 643573:tid 643757] [client 207.58.142.67:16126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt-_fxWyxgRnoFKAJ_WTAAAAkM"]
[Thu Jul 30 11:42:38.057606 2026] [security2:error] [pid 642360:tid 642590] [client 2a03:2880:f800:3a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt-_ZSUkh3e5AhEJOBYCgAB8w4"]
[Thu Jul 30 11:42:38.210940 2026] [security2:error] [pid 643573:tid 643819] [client 68.221.186.136:20292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/themes.php"] [unique_id "amt-_vxWyxgRnoFKAJ_WTwAAAoE"]
[Thu Jul 30 11:42:38.292918 2026] [security2:error] [pid 643573:tid 643823] [client 207.58.142.67:23387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt-_vxWyxgRnoFKAJ_WUAAAAoU"]
[Thu Jul 30 11:42:39.004277 2026] [security2:error] [pid 643573:tid 643830] [client 207.58.142.67:28630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt-__xWyxgRnoFKAJ_WVAAAAow"]
[Thu Jul 30 11:42:39.045511 2026] [security2:error] [pid 643573:tid 643708] [remote 52.167.144.212:7225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.aded-rdc.org"] [uri "/planejamento-controle-gestao-convenios/article.php"] [unique_id "amt-__xWyxgRnoFKAJ_WVQACN38"]
[Thu Jul 30 11:42:39.328159 2026] [security2:error] [pid 643573:tid 643755] [client 68.221.186.136:21167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/worksec.php"] [unique_id "amt-__xWyxgRnoFKAJ_WWgAAAkE"]
[Thu Jul 30 11:42:39.739501 2026] [security2:error] [pid 643573:tid 643820] [client 207.58.142.67:21903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt-__xWyxgRnoFKAJ_WYAAAAoI"]
[Thu Jul 30 11:42:39.867671 2026] [security2:error] [pid 643573:tid 643832] [client 68.221.186.136:21136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/wp-admin/install.php"] [unique_id "amt-__xWyxgRnoFKAJ_WYQAAAo4"]
[Thu Jul 30 11:42:40.467779 2026] [security2:error] [pid 643573:tid 643747] [client 207.58.142.67:22071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt_APxWyxgRnoFKAJ_WZwAAAjk"]
[Thu Jul 30 11:42:41.121352 2026] [security2:error] [pid 643573:tid 643834] [client 68.221.186.136:18898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "amt_AfxWyxgRnoFKAJ_WcAAAApA"]
[Thu Jul 30 11:42:41.187500 2026] [security2:error] [pid 643573:tid 643755] [client 207.58.142.67:20976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt_AfxWyxgRnoFKAJ_WcQAAAkE"]
[Thu Jul 30 11:42:41.580320 2026] [security2:error] [pid 643573:tid 643820] [client 74.7.175.180:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.allmontecristi.com"] [uri "/robots.txt"] [unique_id "amt_AfxWyxgRnoFKAJ_WeAAAAoI"]
[Thu Jul 30 11:42:41.580883 2026] [security2:error] [pid 643573:tid 643788] [client 74.7.175.180:35404] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.allmontecristi.com"] [uri "/robots.txt"] [unique_id "amt_AfxWyxgRnoFKAJ_WdgACYnw"]
[Thu Jul 30 11:42:41.659157 2026] [security2:error] [pid 643573:tid 643589] [remote 57.141.0.20:42538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/15975943371/feed/rss2/"] [unique_id "amt_AfxWyxgRnoFKAJ_WeQACcgg"]
[Thu Jul 30 11:42:41.914685 2026] [security2:error] [pid 643573:tid 643805] [client 207.58.142.67:55153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt_AfxWyxgRnoFKAJ_WewAAAnM"]
[Thu Jul 30 11:42:42.619859 2026] [security2:error] [pid 642360:tid 642508] [client 207.58.142.67:48006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt_ApSUkh3e5AhEJOBYkAAAAaE"]
[Thu Jul 30 11:42:42.928600 2026] [authz_core:error] [pid 643573:tid 643834] [client 118.194.253.208:39376] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.hcloud.toml
[Thu Jul 30 11:42:43.249204 2026] [security2:error] [pid 642360:tid 642468] [remote 3.7.204.22:36196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.204.7.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/wp-login.php"] [unique_id "amt_A5SUkh3e5AhEJOBYlQAB4Gs"]
[Thu Jul 30 11:42:43.266256 2026] [authz_core:error] [pid 643573:tid 643716] [client 118.194.253.208:39376] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/hcloud.yml
[Thu Jul 30 11:42:43.335235 2026] [security2:error] [pid 643573:tid 643751] [client 207.58.142.67:65518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt_A_xWyxgRnoFKAJ_WjgAAAj0"]
[Thu Jul 30 11:42:43.344222 2026] [security2:error] [pid 643573:tid 643763] [client 40.77.167.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amt_AvxWyxgRnoFKAJ_WiQAAAkk"]
[Thu Jul 30 11:42:43.388282 2026] [security2:error] [pid 643253:tid 643419] [client 2a03:2880:f800:2b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_AsjqbtjBYzqM1uYjSQAAIxs"]
[Thu Jul 30 11:42:43.719751 2026] [security2:error] [pid 643573:tid 643605] [remote 85.208.98.18:25646] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amt_A_xWyxgRnoFKAJ_WlwACYhg"]
[Thu Jul 30 11:42:43.719930 2026] [security2:error] [pid 643573:tid 643788] [client 85.208.98.18:25646] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amt_A_xWyxgRnoFKAJ_WlwACYhg"]
[Thu Jul 30 11:42:44.047687 2026] [security2:error] [pid 643573:tid 643813] [client 207.58.142.67:40711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt_BPxWyxgRnoFKAJ_WngAAAns"]
[Thu Jul 30 11:42:44.126287 2026] [security2:error] [pid 643573:tid 643805] [client 176.241.66.87:57784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_BPxWyxgRnoFKAJ_WoQAAAnM"]
[Thu Jul 30 11:42:44.126414 2026] [security2:error] [pid 643573:tid 643805] [client 176.241.66.87:57784] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_BPxWyxgRnoFKAJ_WoQAAAnM"]
[Thu Jul 30 11:42:44.281407 2026] [authz_core:error] [pid 643573:tid 643775] [client 118.194.253.208:39376] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.linode-cli
[Thu Jul 30 11:42:44.434855 2026] [security2:error] [pid 643573:tid 643756] [client 57.141.0.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_A_xWyxgRnoFKAJ_WmQAAAkI"]
[Thu Jul 30 11:42:44.470284 2026] [security2:error] [pid 643573:tid 643787] [client 57.141.0.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_A_xWyxgRnoFKAJ_WnAAAAmE"]
[Thu Jul 30 11:42:44.762295 2026] [security2:error] [pid 642360:tid 642561] [client 207.58.142.67:47633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt_BJSUkh3e5AhEJOBYowAAAdY"]
[Thu Jul 30 11:42:44.862921 2026] [security2:error] [pid 642360:tid 642381] [remote 216.73.216.152:37561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amt_BJSUkh3e5AhEJOBYpQACARQ"]
[Thu Jul 30 11:42:45.296278 2026] [authz_core:error] [pid 643573:tid 643806] [client 118.194.253.208:39376] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.vultr-cli.yaml
[Thu Jul 30 11:42:45.466919 2026] [security2:error] [pid 642360:tid 642550] [client 207.58.142.67:23476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt_BZSUkh3e5AhEJOBYsAAAAcs"]
[Thu Jul 30 11:42:45.671355 2026] [security2:error] [pid 643573:tid 643590] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_BfxWyxgRnoFKAJ_WrgACYgk"]
[Thu Jul 30 11:42:45.671557 2026] [security2:error] [pid 643573:tid 643788] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_BfxWyxgRnoFKAJ_WrgACYgk"]
[Thu Jul 30 11:42:46.173693 2026] [security2:error] [pid 643573:tid 643798] [client 207.58.142.67:34477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt_BvxWyxgRnoFKAJ_WtQAAAmw"]
[Thu Jul 30 11:42:46.889232 2026] [security2:error] [pid 643573:tid 643812] [client 207.58.142.67:1853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt_BvxWyxgRnoFKAJ_WvAAAAno"]
[Thu Jul 30 11:42:47.396153 2026] [security2:error] [pid 643573:tid 643609] [remote 85.208.98.18:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "teknomalay.com"] [uri "/category/tutorial/"] [unique_id "amt_B_xWyxgRnoFKAJ_WwAACZBw"]
[Thu Jul 30 11:42:47.396449 2026] [security2:error] [pid 643573:tid 643790] [client 85.208.98.18:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "teknomalay.com"] [uri "/category/tutorial/"] [unique_id "amt_B_xWyxgRnoFKAJ_WwAACZBw"]
[Thu Jul 30 11:42:47.608474 2026] [security2:error] [pid 643573:tid 643713] [client 207.58.142.67:45036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt_B_xWyxgRnoFKAJ_WwwAAAhc"]
[Thu Jul 30 11:42:48.039619 2026] [security2:error] [pid 643573:tid 643600] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_CPxWyxgRnoFKAJ_WyQACexM"]
[Thu Jul 30 11:42:48.039830 2026] [security2:error] [pid 643573:tid 643813] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_CPxWyxgRnoFKAJ_WyQACexM"]
[Thu Jul 30 11:42:48.328366 2026] [security2:error] [pid 643573:tid 643819] [client 207.58.142.67:8246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt_CPxWyxgRnoFKAJ_WzQAAAoE"]
[Thu Jul 30 11:42:48.534334 2026] [security2:error] [pid 642360:tid 642408] [remote 97.74.93.24:56472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-login.php"] [unique_id "amt_CJSUkh3e5AhEJOBYygABpS8"]
[Thu Jul 30 11:42:49.046064 2026] [security2:error] [pid 643573:tid 643718] [client 207.58.142.67:43216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt_CfxWyxgRnoFKAJ_W1gAAAhw"]
[Thu Jul 30 11:42:49.377774 2026] [security2:error] [pid 642360:tid 642435] [remote 216.73.216.152:37561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amt_CZSUkh3e5AhEJOBY2wAB_Uo"]
[Thu Jul 30 11:42:49.962411 2026] [security2:error] [pid 642360:tid 642564] [client 50.116.63.89:59952] ModSecurity: Warning. Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "82"] [id "331030"] [rev "2"] [msg "Atomicorp.com WAF Rules: Suspicious activity detected - HTTP Request Missing a Host Header"] [severity "NOTICE"] [tag "no_ar"] [hostname "sh00085.hostgator.com"] [uri "/"] [unique_id "amt_CZSUkh3e5AhEJOBY6AAAAdk"]
[Thu Jul 30 11:42:50.488851 2026] [security2:error] [pid 642360:tid 642564] [client 50.116.63.89:59952] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "sh00085.hostgator.com"] [uri "/index.cgi"] [unique_id "amt_CZSUkh3e5AhEJOBY6AAAAdk"]
[Thu Jul 30 11:42:50.640060 2026] [security2:error] [pid 643573:tid 643729] [client 172.237.109.114:22348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_CvxWyxgRnoFKAJ_W3wAAAic"]
[Thu Jul 30 11:42:50.732038 2026] [security2:error] [pid 643573:tid 643752] [client 172.237.109.114:6923] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_CvxWyxgRnoFKAJ_W4AAAAj4"]
[Thu Jul 30 11:42:50.732133 2026] [security2:error] [pid 642360:tid 642490] [client 172.237.109.114:7731] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_CpSUkh3e5AhEJOBY6gAAAY8"]
[Thu Jul 30 11:42:50.757304 2026] [security2:error] [pid 642360:tid 642496] [client 172.237.109.114:22426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_CpSUkh3e5AhEJOBY6wAAAZU"]
[Thu Jul 30 11:42:50.791649 2026] [security2:error] [pid 643253:tid 643405] [client 172.237.109.114:45295] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_CsjqbtjBYzqM1uYjTwAAABU"]
[Thu Jul 30 11:42:54.347535 2026] [security2:error] [pid 642360:tid 642546] [client 172.237.109.114:38233] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_DZSUkh3e5AhEJOBZEgAAAcc"]
[Thu Jul 30 11:42:54.347781 2026] [security2:error] [pid 642360:tid 642514] [client 172.237.109.114:49147] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_DZSUkh3e5AhEJOBZEQAAAac"]
[Thu Jul 30 11:42:54.402524 2026] [security2:error] [pid 642360:tid 642601] [client 172.237.109.114:62292] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_DZSUkh3e5AhEJOBZEAAAAf4"]
[Thu Jul 30 11:42:54.489136 2026] [security2:error] [pid 643573:tid 643729] [client 172.237.109.114:9242] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_DfxWyxgRnoFKAJ_W-wAAAic"]
[Thu Jul 30 11:42:54.497736 2026] [security2:error] [pid 643573:tid 643753] [client 172.237.109.114:29630] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_DfxWyxgRnoFKAJ_W-gAAAj8"]
[Thu Jul 30 11:42:54.500414 2026] [security2:error] [pid 643253:tid 643442] [client 172.237.109.114:14105] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_DcjqbtjBYzqM1uYjUgAAADo"]
[Thu Jul 30 11:42:54.506357 2026] [security2:error] [pid 642360:tid 642589] [client 172.237.109.114:16388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_DZSUkh3e5AhEJOBZEwAAAfI"]
[Thu Jul 30 11:42:54.520756 2026] [security2:error] [pid 643253:tid 643449] [client 172.237.109.114:51745] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_DcjqbtjBYzqM1uYjUwAAAEE"]
[Thu Jul 30 11:42:54.521669 2026] [security2:error] [pid 642360:tid 642591] [client 172.237.109.114:31327] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_DZSUkh3e5AhEJOBZFAAAAfQ"]
[Thu Jul 30 11:42:54.524022 2026] [security2:error] [pid 643573:tid 643801] [client 172.237.109.114:18596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_DfxWyxgRnoFKAJ_W_AAAAm8"]
[Thu Jul 30 11:42:54.535524 2026] [security2:error] [pid 642360:tid 642506] [client 172.237.109.114:33243] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_DZSUkh3e5AhEJOBZFQAAAZ8"]
[Thu Jul 30 11:42:54.543027 2026] [security2:error] [pid 643253:tid 643411] [client 172.237.109.114:41534] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_DcjqbtjBYzqM1uYjVQAAABs"]
[Thu Jul 30 11:42:54.558358 2026] [security2:error] [pid 643253:tid 643474] [client 172.237.109.114:42090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_DcjqbtjBYzqM1uYjVAAAAFo"]
[Thu Jul 30 11:42:54.558431 2026] [security2:error] [pid 643253:tid 643451] [client 172.237.109.114:28133] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_DcjqbtjBYzqM1uYjVgAAAEM"]
[Thu Jul 30 11:42:54.563106 2026] [security2:error] [pid 642360:tid 642494] [client 172.237.109.114:56968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_DZSUkh3e5AhEJOBZFgAAAZM"]
[Thu Jul 30 11:42:54.843824 2026] [security2:error] [pid 642360:tid 642532] [client 176.241.66.87:42425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_DpSUkh3e5AhEJOBZJgAAAbk"]
[Thu Jul 30 11:42:54.844008 2026] [security2:error] [pid 642360:tid 642532] [client 176.241.66.87:42425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_DpSUkh3e5AhEJOBZJgAAAbk"]
[Thu Jul 30 11:42:55.118567 2026] [security2:error] [pid 643573:tid 643626] [remote 74.7.241.60:38426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/content/article.php"] [unique_id "amt_D_xWyxgRnoFKAJ_XCQACSy0"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/content/1784122425_Physioth%C3%A9rapie%20%C3%A0%20Domicile.jpg
[Thu Jul 30 11:42:55.204494 2026] [security2:error] [pid 643573:tid 643750] [client 213.152.161.25:34982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amt_D_xWyxgRnoFKAJ_XDAAAAjw"]
[Thu Jul 30 11:42:55.204581 2026] [security2:error] [pid 643573:tid 643750] [client 213.152.161.25:34982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amt_D_xWyxgRnoFKAJ_XDAAAAjw"]
[Thu Jul 30 11:42:55.773466 2026] [security2:error] [pid 643573:tid 643629] [remote 157.55.39.49:46851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.39.55.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.aded-rdc.org"] [uri "/2025/10/08/add.php"] [unique_id "amt_D_xWyxgRnoFKAJ_XEQACeTA"]
[Thu Jul 30 11:42:56.716807 2026] [security2:error] [pid 643573:tid 643616] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_EPxWyxgRnoFKAJ_XGAACKiM"]
[Thu Jul 30 11:42:56.716996 2026] [security2:error] [pid 643573:tid 643732] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_EPxWyxgRnoFKAJ_XGAACKiM"]
[Thu Jul 30 11:42:58.614688 2026] [security2:error] [pid 643573:tid 643631] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_EvxWyxgRnoFKAJ_XJwACjDI"]
[Thu Jul 30 11:42:58.614924 2026] [security2:error] [pid 643573:tid 643830] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_EvxWyxgRnoFKAJ_XJwACjDI"]
[Thu Jul 30 11:42:59.382746 2026] [security2:error] [pid 643253:tid 643287] [remote 216.73.216.152:57448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amt_E8jqbtjBYzqM1uYjZQAATSA"]
[Thu Jul 30 11:43:00.586856 2026] [security2:error] [pid 643573:tid 643641] [remote 94.101.115.105:30416] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.alseermarine.com"] [uri "/.git/config"] [unique_id "amt_FPxWyxgRnoFKAJ_XMQACdDw"], referer: http://alseermarine.ae/.git/config
[Thu Jul 30 11:43:01.607700 2026] [security2:error] [pid 643573:tid 643636] [remote 94.101.115.105:30416] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.alseermarine.com"] [uri "/.git/config"] [unique_id "amt_FfxWyxgRnoFKAJ_XOgACTTc"], referer: https://alseermarine.ae/.git/config
[Thu Jul 30 11:43:02.639849 2026] [core:notice] [pid 643573:tid 643766] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:43:02.676630 2026] [core:notice] [pid 643253:tid 643473] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:43:03.365679 2026] [core:error] [pid 642360:tid 642482] (36)File name too long: [remote 91.192.240.21:20349] AH00036: access to />","sale_flash_html":""},{"attributes":{"attribute_size":"42"},"availability_html":"","backorders_allowed":false,"dimensions":{"length":"","width":"","height":""},"dimensions_html":"N/A","display_price":209.9,"display_regular_price":209.9,"image":{"title":"8765f1ca-scaled-1.jpg","caption":"","url":"https:/kicksity.com/wp-content/uploads/2024/08/8765f1ca-scaled-1.jpg","alt":"8765f1ca-scaled-1.jpg","src":"https:/kicksity.com/wp-content/uploads/2024/08/8765f1ca-scaled-1-600x400.jpg","srcset":"https:/kicksity.com/wp-content/uploads/2024/08/8765f1ca-scaled-1-600x400.jpg failed (filesystem path '/home1/vdbnyxte/public_html/website_3f9373c9/>","sale_flash_html":""},{"attributes":{"attribute_size":"42"},"availability_html":"","backorders_allowed":false,"dimensions":{"length":"","width":"","height":""},"dimensions_html":"N'), referer: https://kicksity.com/product/nike-air-jordan-4-mushroom/
[Thu Jul 30 11:43:04.089972 2026] [core:notice] [pid 643573:tid 643731] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:43:04.384926 2026] [security2:error] [pid 643253:tid 643288] [remote 216.73.216.152:57448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amt_GMjqbtjBYzqM1uYjawAACSE"]
[Thu Jul 30 11:43:04.748511 2026] [core:notice] [pid 643573:tid 643720] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:43:05.458652 2026] [security2:error] [pid 643573:tid 643798] [client 176.241.66.87:43395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_GfxWyxgRnoFKAJ_XegAAAmw"]
[Thu Jul 30 11:43:05.458873 2026] [security2:error] [pid 643573:tid 643798] [client 176.241.66.87:43395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_GfxWyxgRnoFKAJ_XegAAAmw"]
[Thu Jul 30 11:43:06.294576 2026] [security2:error] [pid 643573:tid 643786] [client 172.236.9.101:13938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GPxWyxgRnoFKAJ_XZAAAAmA"]
[Thu Jul 30 11:43:06.297497 2026] [security2:error] [pid 643573:tid 643833] [client 172.236.9.101:62660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GPxWyxgRnoFKAJ_XZgAAAo8"]
[Thu Jul 30 11:43:06.310798 2026] [security2:error] [pid 643573:tid 643756] [client 172.236.9.101:8060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GPxWyxgRnoFKAJ_XYgAAAkI"]
[Thu Jul 30 11:43:06.331192 2026] [security2:error] [pid 643573:tid 643768] [client 172.236.9.101:37259] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GPxWyxgRnoFKAJ_XZQAAAk4"]
[Thu Jul 30 11:43:06.335413 2026] [security2:error] [pid 643573:tid 643789] [client 172.236.9.101:37816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GPxWyxgRnoFKAJ_XZwAAAmM"]
[Thu Jul 30 11:43:06.364255 2026] [security2:error] [pid 642360:tid 642554] [client 172.236.9.101:17111] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GJSUkh3e5AhEJOBZfgAAAc8"]
[Thu Jul 30 11:43:06.386967 2026] [security2:error] [pid 643573:tid 643816] [client 172.236.9.101:28237] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GPxWyxgRnoFKAJ_XawAAAn4"]
[Thu Jul 30 11:43:06.387400 2026] [security2:error] [pid 642360:tid 642505] [client 172.236.9.101:1196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GJSUkh3e5AhEJOBZfQAAAZ4"]
[Thu Jul 30 11:43:06.388540 2026] [security2:error] [pid 642360:tid 642571] [client 172.236.9.101:10568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GJSUkh3e5AhEJOBZfwAAAeA"]
[Thu Jul 30 11:43:06.416376 2026] [security2:error] [pid 642360:tid 642493] [client 172.236.9.101:4317] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GJSUkh3e5AhEJOBZfAAAAZI"]
[Thu Jul 30 11:43:06.426849 2026] [security2:error] [pid 643253:tid 643495] [client 172.236.9.101:10260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GMjqbtjBYzqM1uYjagAAAG8"]
[Thu Jul 30 11:43:06.428554 2026] [security2:error] [pid 643573:tid 643779] [client 172.236.9.101:10279] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GPxWyxgRnoFKAJ_XbwAAAlk"]
[Thu Jul 30 11:43:06.446487 2026] [security2:error] [pid 642360:tid 642508] [client 172.236.9.101:6132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GJSUkh3e5AhEJOBZewAAAaE"]
[Thu Jul 30 11:43:06.448498 2026] [security2:error] [pid 643573:tid 643819] [client 172.236.9.101:1578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GPxWyxgRnoFKAJ_XYwAAAoE"]
[Thu Jul 30 11:43:06.466186 2026] [security2:error] [pid 643573:tid 643813] [client 172.236.9.101:41573] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GPxWyxgRnoFKAJ_XbQAAAns"]
[Thu Jul 30 11:43:06.505349 2026] [security2:error] [pid 643573:tid 643752] [client 172.236.9.101:50359] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GPxWyxgRnoFKAJ_XaQAAAj4"]
[Thu Jul 30 11:43:06.516530 2026] [security2:error] [pid 643573:tid 643762] [client 172.236.9.101:11253] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GPxWyxgRnoFKAJ_XbAAAAkg"]
[Thu Jul 30 11:43:06.528754 2026] [security2:error] [pid 643573:tid 643714] [client 172.236.9.101:36977] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GPxWyxgRnoFKAJ_XagAAAhg"]
[Thu Jul 30 11:43:06.573765 2026] [security2:error] [pid 642360:tid 642544] [client 172.236.9.101:55076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GJSUkh3e5AhEJOBZgAAAAcU"]
[Thu Jul 30 11:43:06.640664 2026] [security2:error] [pid 643573:tid 643736] [client 172.236.9.101:9068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GPxWyxgRnoFKAJ_XbgAAAi4"]
[Thu Jul 30 11:43:07.155345 2026] [security2:error] [pid 643573:tid 643808] [client 185.191.171.19:22042] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2020/10/19/ataque-a-tiros-deixa-duas-pessoas-feridas-no-castelo-branco-em-joao-pessoa/"] [unique_id "amt_G_xWyxgRnoFKAJ_XgwAAAnY"]
[Thu Jul 30 11:43:07.155476 2026] [security2:error] [pid 643573:tid 643808] [client 185.191.171.19:22042] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2020/10/19/ataque-a-tiros-deixa-duas-pessoas-feridas-no-castelo-branco-em-joao-pessoa/"] [unique_id "amt_G_xWyxgRnoFKAJ_XgwAAAnY"]
[Thu Jul 30 11:43:07.631816 2026] [security2:error] [pid 643253:tid 643289] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_G8jqbtjBYzqM1uYjbwAAcSI"]
[Thu Jul 30 11:43:07.632003 2026] [security2:error] [pid 643253:tid 643497] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_G8jqbtjBYzqM1uYjbwAAcSI"]
[Thu Jul 30 11:43:08.759139 2026] [security2:error] [pid 642360:tid 642524] [client 74.208.150.73:59213] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.adviseassociates.com"] [uri "/"] [unique_id "amt_HJSUkh3e5AhEJOBZoQAAAbE"]
[Thu Jul 30 11:43:09.296213 2026] [security2:error] [pid 643573:tid 643637] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_HfxWyxgRnoFKAJ_XkQACOTg"]
[Thu Jul 30 11:43:09.296381 2026] [security2:error] [pid 643573:tid 643747] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_HfxWyxgRnoFKAJ_XkQACOTg"]
[Thu Jul 30 11:43:09.386566 2026] [security2:error] [pid 643253:tid 643290] [remote 216.73.216.152:57448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amt_HcjqbtjBYzqM1uYjcgAAHiM"]
[Thu Jul 30 11:43:10.145709 2026] [core:notice] [pid 642360:tid 642603] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:43:10.188503 2026] [core:error] [pid 643573:tid 643656] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/
[Thu Jul 30 11:43:10.188526 2026] [core:error] [pid 643573:tid 643656] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/
[Thu Jul 30 11:43:10.733125 2026] [core:error] [pid 642360:tid 642365] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/wp/
[Thu Jul 30 11:43:10.733151 2026] [core:error] [pid 642360:tid 642365] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/wp/
[Thu Jul 30 11:43:11.266825 2026] [core:error] [pid 642360:tid 642373] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/wp/
[Thu Jul 30 11:43:11.266848 2026] [core:error] [pid 642360:tid 642373] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/wp/
[Thu Jul 30 11:43:11.799318 2026] [core:error] [pid 643573:tid 643659] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/wordpress/
[Thu Jul 30 11:43:11.799347 2026] [core:error] [pid 643573:tid 643659] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/wordpress/
[Thu Jul 30 11:43:12.372972 2026] [core:error] [pid 643573:tid 643632] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/wordpress/
[Thu Jul 30 11:43:12.373009 2026] [core:error] [pid 643573:tid 643632] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/wordpress/
[Thu Jul 30 11:43:12.736149 2026] [security2:error] [pid 643573:tid 643765] [client 172.236.9.101:45469] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IPxWyxgRnoFKAJ_XqAAAAks"]
[Thu Jul 30 11:43:12.773813 2026] [security2:error] [pid 643573:tid 643777] [client 172.236.9.101:51547] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IPxWyxgRnoFKAJ_XqQAAAlc"]
[Thu Jul 30 11:43:12.853486 2026] [security2:error] [pid 643253:tid 643488] [client 172.236.9.101:35300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IMjqbtjBYzqM1uYjdAAAAGg"]
[Thu Jul 30 11:43:12.918345 2026] [core:error] [pid 643573:tid 643661] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/blog/
[Thu Jul 30 11:43:12.918367 2026] [core:error] [pid 643573:tid 643661] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/blog/
[Thu Jul 30 11:43:13.466230 2026] [core:error] [pid 643573:tid 643662] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/blog/
[Thu Jul 30 11:43:13.466271 2026] [core:error] [pid 643573:tid 643662] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/blog/
[Thu Jul 30 11:43:13.664641 2026] [core:error] [pid 643573:tid 643666] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/old/
[Thu Jul 30 11:43:13.664666 2026] [core:error] [pid 643573:tid 643666] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/old/
[Thu Jul 30 11:43:14.200492 2026] [security2:error] [pid 643253:tid 643428] [client 57.141.0.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_IcjqbtjBYzqM1uYjegAAACw"]
[Thu Jul 30 11:43:14.241528 2026] [core:error] [pid 643573:tid 643669] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/old/
[Thu Jul 30 11:43:14.241566 2026] [core:error] [pid 643573:tid 643669] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/old/
[Thu Jul 30 11:43:14.452235 2026] [core:error] [pid 643573:tid 643671] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/test/
[Thu Jul 30 11:43:14.452268 2026] [core:error] [pid 643573:tid 643671] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/test/
[Thu Jul 30 11:43:14.533673 2026] [security2:error] [pid 643573:tid 643755] [client 172.236.9.101:35549] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IfxWyxgRnoFKAJ_XsgAAAkE"]
[Thu Jul 30 11:43:14.541199 2026] [security2:error] [pid 643573:tid 643739] [client 172.236.9.101:47670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IfxWyxgRnoFKAJ_XswAAAjE"]
[Thu Jul 30 11:43:14.547109 2026] [security2:error] [pid 642360:tid 642538] [client 172.236.9.101:28648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IZSUkh3e5AhEJOBZwQAAAb8"]
[Thu Jul 30 11:43:14.662030 2026] [core:error] [pid 642360:tid 642440] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/test/
[Thu Jul 30 11:43:14.662056 2026] [core:error] [pid 642360:tid 642440] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/test/
[Thu Jul 30 11:43:15.071009 2026] [security2:error] [pid 643573:tid 643668] [remote 216.73.216.152:57391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amt_I_xWyxgRnoFKAJ_XzQACLlc"]
[Thu Jul 30 11:43:15.231066 2026] [security2:error] [pid 642360:tid 642532] [client 172.236.9.101:8763] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IZSUkh3e5AhEJOBZxQAAAbk"]
[Thu Jul 30 11:43:15.236631 2026] [core:error] [pid 643573:tid 643670] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/dev/
[Thu Jul 30 11:43:15.236666 2026] [core:error] [pid 643573:tid 643670] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/dev/
[Thu Jul 30 11:43:15.244102 2026] [security2:error] [pid 643253:tid 643385] [client 172.236.9.101:15723] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IcjqbtjBYzqM1uYjdgAAAAE"]
[Thu Jul 30 11:43:15.248714 2026] [security2:error] [pid 642360:tid 642503] [client 172.236.9.101:49879] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IZSUkh3e5AhEJOBZwwAAAZw"]
[Thu Jul 30 11:43:15.252604 2026] [security2:error] [pid 642360:tid 642528] [client 172.236.9.101:60028] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IZSUkh3e5AhEJOBZyAAAAbU"]
[Thu Jul 30 11:43:15.260794 2026] [security2:error] [pid 643573:tid 643716] [client 172.236.9.101:49114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IfxWyxgRnoFKAJ_XtAAAAho"]
[Thu Jul 30 11:43:15.261155 2026] [security2:error] [pid 642360:tid 642557] [client 172.236.9.101:63132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IZSUkh3e5AhEJOBZyQAAAdI"]
[Thu Jul 30 11:43:15.261456 2026] [security2:error] [pid 642360:tid 642570] [client 172.236.9.101:34216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IZSUkh3e5AhEJOBZxwAAAd8"]
[Thu Jul 30 11:43:15.263643 2026] [security2:error] [pid 642360:tid 642575] [client 172.236.9.101:62264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IZSUkh3e5AhEJOBZxgAAAeQ"]
[Thu Jul 30 11:43:15.272899 2026] [security2:error] [pid 642360:tid 642511] [client 172.236.9.101:32376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IZSUkh3e5AhEJOBZxAAAAaQ"]
[Thu Jul 30 11:43:15.273935 2026] [security2:error] [pid 642360:tid 642500] [client 172.236.9.101:61914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IZSUkh3e5AhEJOBZygAAAZk"]
[Thu Jul 30 11:43:15.277304 2026] [security2:error] [pid 643573:tid 643737] [client 172.236.9.101:25817] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IfxWyxgRnoFKAJ_XtgAAAi8"]
[Thu Jul 30 11:43:15.277306 2026] [security2:error] [pid 643573:tid 643796] [client 172.236.9.101:9926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IfxWyxgRnoFKAJ_XtQAAAmo"]
[Thu Jul 30 11:43:15.278012 2026] [security2:error] [pid 642360:tid 642611] [client 172.236.9.101:9602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IZSUkh3e5AhEJOBZwgAAAgg"]
[Thu Jul 30 11:43:15.289367 2026] [security2:error] [pid 643573:tid 643829] [client 172.236.9.101:6480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IfxWyxgRnoFKAJ_XtwAAAos"]
[Thu Jul 30 11:43:15.442055 2026] [core:error] [pid 643573:tid 643672] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/dev/
[Thu Jul 30 11:43:15.442076 2026] [core:error] [pid 643573:tid 643672] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/dev/
[Thu Jul 30 11:43:15.647386 2026] [core:error] [pid 642360:tid 642417] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/backup/
[Thu Jul 30 11:43:15.647418 2026] [core:error] [pid 642360:tid 642417] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/backup/
[Thu Jul 30 11:43:15.847843 2026] [core:error] [pid 642360:tid 642430] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/backup/
[Thu Jul 30 11:43:15.847872 2026] [core:error] [pid 642360:tid 642430] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/backup/
[Thu Jul 30 11:43:16.046666 2026] [core:error] [pid 642360:tid 642435] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/staging/
[Thu Jul 30 11:43:16.046690 2026] [core:error] [pid 642360:tid 642435] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/staging/
[Thu Jul 30 11:43:16.080844 2026] [security2:error] [pid 642360:tid 642549] [client 176.241.66.87:59426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_JJSUkh3e5AhEJOBZ4AAAAco"]
[Thu Jul 30 11:43:16.080972 2026] [security2:error] [pid 642360:tid 642549] [client 176.241.66.87:59426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_JJSUkh3e5AhEJOBZ4AAAAco"]
[Thu Jul 30 11:43:16.260297 2026] [core:error] [pid 643573:tid 643601] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/staging/
[Thu Jul 30 11:43:16.260329 2026] [core:error] [pid 643573:tid 643601] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/staging/
[Thu Jul 30 11:43:16.712577 2026] [security2:error] [pid 643573:tid 643756] [client 57.141.0.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_JPxWyxgRnoFKAJ_X3gAAAkI"]
[Thu Jul 30 11:43:16.891313 2026] [core:error] [pid 643573:tid 643678] [remote 74.7.228.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:43:16.891338 2026] [core:error] [pid 643573:tid 643678] [remote 74.7.228.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:43:16.891591 2026] [security2:error] [pid 643573:tid 643739] [client 74.7.228.59:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.professionalfurnituremovingcompanyllc.store"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amt_JPxWyxgRnoFKAJ_X5QACMWE"]
[Thu Jul 30 11:43:17.065566 2026] [core:error] [pid 643573:tid 643648] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/
[Thu Jul 30 11:43:17.065592 2026] [core:error] [pid 643573:tid 643648] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/
[Thu Jul 30 11:43:17.699779 2026] [security2:error] [pid 643573:tid 643726] [client 34.231.118.144:3190] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2016/11/L%C3%A9o-400x400.jpg"] [unique_id "amt_JfxWyxgRnoFKAJ_X8wAAAiQ"]
[Thu Jul 30 11:43:17.826219 2026] [security2:error] [pid 642360:tid 642545] [client 74.7.241.136:39236] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-14b4edfb.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amt_JJSUkh3e5AhEJOBZ4QABxi0"]
[Thu Jul 30 11:43:18.544462 2026] [security2:error] [pid 643573:tid 643681] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_JvxWyxgRnoFKAJ_X-QACPWQ"]
[Thu Jul 30 11:43:18.544597 2026] [security2:error] [pid 643573:tid 643751] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_JvxWyxgRnoFKAJ_X-QACPWQ"]
[Thu Jul 30 11:43:18.852628 2026] [security2:error] [pid 643573:tid 643791] [client 74.7.230.49:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.vvr.hfl.temporary.site"] [uri "/index.php"] [unique_id "amt_JvxWyxgRnoFKAJ_X-gAAAmU"]
[Thu Jul 30 11:43:18.853708 2026] [security2:error] [pid 643253:tid 643458] [client 74.7.230.49:47270] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.vvr.hfl.temporary.site"] [uri "/robots.txt"] [unique_id "amt_JsjqbtjBYzqM1uYjfAAASiQ"]
[Thu Jul 30 11:43:19.930952 2026] [security2:error] [pid 643573:tid 643597] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_J_xWyxgRnoFKAJ_YBwACVRA"]
[Thu Jul 30 11:43:19.931171 2026] [security2:error] [pid 643573:tid 643775] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_J_xWyxgRnoFKAJ_YBwACVRA"]
[Thu Jul 30 11:43:20.201896 2026] [core:notice] [pid 643573:tid 643759] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:43:21.783674 2026] [security2:error] [pid 643573:tid 643767] [client 74.7.228.15:44030] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "dhowcruisedinner.com"] [uri "/robots.txt"] [unique_id "amt_KfxWyxgRnoFKAJ_YDwAAAk0"]
[Thu Jul 30 11:43:23.204749 2026] [security2:error] [pid 643573:tid 643739] [client 43.153.96.233:59090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.96.153.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amt_KvxWyxgRnoFKAJ_YGAAAAjE"]
[Thu Jul 30 11:43:24.396355 2026] [security2:error] [pid 643573:tid 643595] [remote 216.73.216.152:57391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amt_LPxWyxgRnoFKAJ_YLgACXw4"]
[Thu Jul 30 11:43:25.339843 2026] [security2:error] [pid 642360:tid 642542] [client 172.236.9.101:9163] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K5SUkh3e5AhEJOBaIQAAAcM"]
[Thu Jul 30 11:43:25.349721 2026] [security2:error] [pid 643573:tid 643792] [client 172.236.9.101:20222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K_xWyxgRnoFKAJ_YIwAAAmY"]
[Thu Jul 30 11:43:25.355261 2026] [security2:error] [pid 643573:tid 643751] [client 172.236.9.101:24336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K_xWyxgRnoFKAJ_YHwAAAj0"]
[Thu Jul 30 11:43:25.355345 2026] [security2:error] [pid 642360:tid 642606] [client 172.236.9.101:6411] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K5SUkh3e5AhEJOBaHwAAAgM"]
[Thu Jul 30 11:43:25.365539 2026] [security2:error] [pid 643573:tid 643768] [client 172.236.9.101:8421] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K_xWyxgRnoFKAJ_YJAAAAk4"]
[Thu Jul 30 11:43:25.365859 2026] [security2:error] [pid 642360:tid 642569] [client 172.236.9.101:27023] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K5SUkh3e5AhEJOBaIAAAAd4"]
[Thu Jul 30 11:43:25.366610 2026] [security2:error] [pid 643573:tid 643711] [client 172.236.9.101:24562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K_xWyxgRnoFKAJ_YHgAAAhU"]
[Thu Jul 30 11:43:25.369855 2026] [security2:error] [pid 642360:tid 642611] [client 172.236.9.101:14189] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K5SUkh3e5AhEJOBaHgAAAgg"]
[Thu Jul 30 11:43:25.390661 2026] [security2:error] [pid 643573:tid 643784] [client 172.236.9.101:39343] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K_xWyxgRnoFKAJ_YIQAAAl4"]
[Thu Jul 30 11:43:25.392178 2026] [security2:error] [pid 643573:tid 643713] [client 172.236.9.101:21925] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K_xWyxgRnoFKAJ_YHQAAAhc"]
[Thu Jul 30 11:43:25.394963 2026] [security2:error] [pid 642360:tid 642500] [client 172.236.9.101:19320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K5SUkh3e5AhEJOBaHQAAAZk"]
[Thu Jul 30 11:43:25.412446 2026] [security2:error] [pid 643573:tid 643801] [client 172.236.9.101:42258] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K_xWyxgRnoFKAJ_YJgAAAm8"]
[Thu Jul 30 11:43:25.414991 2026] [security2:error] [pid 643573:tid 643743] [client 172.236.9.101:55833] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K_xWyxgRnoFKAJ_YKgAAAjU"]
[Thu Jul 30 11:43:25.422053 2026] [security2:error] [pid 643573:tid 643837] [client 172.236.9.101:3859] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K_xWyxgRnoFKAJ_YIgAAApM"]
[Thu Jul 30 11:43:25.437249 2026] [security2:error] [pid 643573:tid 643786] [client 172.236.9.101:18192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K_xWyxgRnoFKAJ_YKAAAAmA"]
[Thu Jul 30 11:43:25.438171 2026] [security2:error] [pid 642360:tid 642543] [client 172.236.9.101:34762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K5SUkh3e5AhEJOBaIwAAAcQ"]
[Thu Jul 30 11:43:25.479666 2026] [security2:error] [pid 643573:tid 643729] [client 172.236.9.101:41989] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K_xWyxgRnoFKAJ_YIAAAAic"]
[Thu Jul 30 11:43:25.496404 2026] [security2:error] [pid 642360:tid 642584] [client 172.236.9.101:46985] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K5SUkh3e5AhEJOBaIgAAAe0"]
[Thu Jul 30 11:43:25.508049 2026] [security2:error] [pid 643573:tid 643727] [client 172.236.9.101:51814] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K_xWyxgRnoFKAJ_YKQAAAiU"]
[Thu Jul 30 11:43:25.523413 2026] [security2:error] [pid 643573:tid 643789] [client 172.236.9.101:12417] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K_xWyxgRnoFKAJ_YJwAAAmM"]
[Thu Jul 30 11:43:25.931647 2026] [security2:error] [pid 643573:tid 643746] [client 57.141.0.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_LfxWyxgRnoFKAJ_YNQAAAjg"]
[Thu Jul 30 11:43:26.701568 2026] [security2:error] [pid 642360:tid 642520] [client 52.167.144.232:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amt_LpSUkh3e5AhEJOBaOgAAAa0"]
[Thu Jul 30 11:43:26.705933 2026] [security2:error] [pid 643573:tid 643738] [client 176.241.66.87:45392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_LvxWyxgRnoFKAJ_YQQAAAjA"]
[Thu Jul 30 11:43:26.706067 2026] [security2:error] [pid 643573:tid 643738] [client 176.241.66.87:45392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_LvxWyxgRnoFKAJ_YQQAAAjA"]
[Thu Jul 30 11:43:26.712501 2026] [core:error] [pid 642360:tid 642449] [remote 74.7.230.55:42834] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:43:26.712518 2026] [core:error] [pid 642360:tid 642449] [remote 74.7.230.55:42834] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:43:26.712714 2026] [security2:error] [pid 642360:tid 642550] [client 74.7.230.55:42834] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "website-55c6e681.wrf.zzt.temporary.site"] [uri "/website_55c6e681/index.php"] [unique_id "amt_LpSUkh3e5AhEJOBaQAABy1g"]
[Thu Jul 30 11:43:27.773493 2026] [security2:error] [pid 643573:tid 643687] [remote 57.141.0.39:39400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amt_L_xWyxgRnoFKAJ_YTQACXmo"]
[Thu Jul 30 11:43:28.756043 2026] [core:notice] [pid 643573:tid 643764] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:43:29.411874 2026] [security2:error] [pid 642360:tid 642476] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_MZSUkh3e5AhEJOBaUAAB_nM"]
[Thu Jul 30 11:43:29.412065 2026] [security2:error] [pid 642360:tid 642601] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_MZSUkh3e5AhEJOBaUAAB_nM"]
[Thu Jul 30 11:43:30.634609 2026] [security2:error] [pid 643573:tid 643697] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_MvxWyxgRnoFKAJ_YbQACZHQ"]
[Thu Jul 30 11:43:30.634773 2026] [security2:error] [pid 643573:tid 643790] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_MvxWyxgRnoFKAJ_YbQACZHQ"]
[Thu Jul 30 11:43:31.307302 2026] [security2:error] [pid 643573:tid 643808] [client 2a03:2880:f800:3f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_MvxWyxgRnoFKAJ_YbAACdm8"]
[Thu Jul 30 11:43:31.307575 2026] [security2:error] [pid 643573:tid 643699] [remote 216.244.66.246:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "spececigarette.com"] [uri "/product-tag/%E0%B8%9A%E0%B8%B8%E0%B8%AB%E0%B8%A3%E0%B8%B5%E0%B9%88/"] [unique_id "amt_M_xWyxgRnoFKAJ_YcwACSXY"]
[Thu Jul 30 11:43:31.307761 2026] [security2:error] [pid 643573:tid 643763] [client 216.244.66.246:0] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "spececigarette.com"] [uri "/product-tag/%E0%B8%9A%E0%B8%B8%E0%B8%AB%E0%B8%A3%E0%B8%B5%E0%B9%88/"] [unique_id "amt_M_xWyxgRnoFKAJ_YcwACSXY"]
[Thu Jul 30 11:43:31.376348 2026] [security2:error] [pid 643573:tid 643779] [client 159.65.49.75:47624] ModSecurity: Warning. Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "82"] [id "331030"] [rev "2"] [msg "Atomicorp.com WAF Rules: Suspicious activity detected - HTTP Request Missing a Host Header"] [severity "NOTICE"] [tag "no_ar"] [hostname "sh00085.hostgator.com"] [uri "/"] [unique_id "amt_M_xWyxgRnoFKAJ_YdAAAAlk"]
[Thu Jul 30 11:43:31.412869 2026] [security2:error] [pid 643573:tid 643786] [client 2a03:2880:f800:2b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_MvxWyxgRnoFKAJ_YbgACYHg"]
[Thu Jul 30 11:43:31.909694 2026] [security2:error] [pid 643573:tid 643779] [client 159.65.49.75:47624] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "sh00085.hostgator.com"] [uri "/index.cgi"] [unique_id "amt_M_xWyxgRnoFKAJ_YdAAAAlk"]
[Thu Jul 30 11:43:32.677141 2026] [security2:error] [pid 643573:tid 643800] [client 172.237.109.114:23715] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_M_xWyxgRnoFKAJ_YeAAAAm4"]
[Thu Jul 30 11:43:32.725321 2026] [security2:error] [pid 643573:tid 643809] [client 172.237.109.114:4910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_M_xWyxgRnoFKAJ_YeQAAAnc"]
[Thu Jul 30 11:43:32.736648 2026] [security2:error] [pid 643573:tid 643833] [client 172.237.109.114:34892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_M_xWyxgRnoFKAJ_YegAAAo8"]
[Thu Jul 30 11:43:32.738329 2026] [security2:error] [pid 643573:tid 643824] [client 172.237.109.114:19867] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_M_xWyxgRnoFKAJ_YewAAAoY"]
[Thu Jul 30 11:43:32.741333 2026] [security2:error] [pid 642360:tid 642570] [client 172.237.109.114:20333] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_M5SUkh3e5AhEJOBaagAAAd8"]
[Thu Jul 30 11:43:32.756057 2026] [security2:error] [pid 642360:tid 642511] [client 172.237.109.114:57005] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_M5SUkh3e5AhEJOBabQAAAaQ"]
[Thu Jul 30 11:43:32.765133 2026] [security2:error] [pid 642360:tid 642575] [client 172.237.109.114:46460] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_M5SUkh3e5AhEJOBabAAAAeQ"]
[Thu Jul 30 11:43:32.780024 2026] [security2:error] [pid 642360:tid 642547] [client 172.237.109.114:1283] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NJSUkh3e5AhEJOBabgAAAcg"]
[Thu Jul 30 11:43:32.782938 2026] [security2:error] [pid 643573:tid 643714] [client 172.237.109.114:12464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NPxWyxgRnoFKAJ_YfQAAAhg"]
[Thu Jul 30 11:43:32.789910 2026] [security2:error] [pid 642360:tid 642528] [client 172.237.109.114:45839] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_M5SUkh3e5AhEJOBaawAAAbU"]
[Thu Jul 30 11:43:32.791196 2026] [security2:error] [pid 643573:tid 643738] [client 172.237.109.114:11934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NPxWyxgRnoFKAJ_YfAAAAjA"]
[Thu Jul 30 11:43:32.793881 2026] [security2:error] [pid 643573:tid 643827] [client 172.237.109.114:1436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NPxWyxgRnoFKAJ_YfgAAAok"]
[Thu Jul 30 11:43:33.767095 2026] [fcgid:warn] [pid 643573:tid 643746] (70014)End of file found: [client 159.65.49.75:47642] mod_fcgid: can't get data from http client
[Thu Jul 30 11:43:34.400417 2026] [security2:error] [pid 643573:tid 643698] [remote 216.73.216.152:57391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amt_NvxWyxgRnoFKAJ_YmQACWnU"]
[Thu Jul 30 11:43:34.603337 2026] [security2:error] [pid 643573:tid 643804] [client 172.236.9.101:54786] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NfxWyxgRnoFKAJ_YiAAAAnI"]
[Thu Jul 30 11:43:34.607225 2026] [security2:error] [pid 643573:tid 643795] [client 172.237.109.114:12695] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NPxWyxgRnoFKAJ_YhAAAAmk"]
[Thu Jul 30 11:43:34.869574 2026] [proxy:error] [pid 643573:tid 643752] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:43:34.869631 2026] [proxy_http:error] [pid 643573:tid 643752] [client 3.228.112.215:35733] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:43:34.870419 2026] [proxy:error] [pid 643573:tid 643752] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:43:34.870470 2026] [proxy_http:error] [pid 643573:tid 643752] [client 3.228.112.215:35733] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:43:35.276652 2026] [security2:error] [pid 643573:tid 643743] [client 172.237.109.114:1045] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NPxWyxgRnoFKAJ_YgwAAAjU"]
[Thu Jul 30 11:43:35.362600 2026] [security2:error] [pid 643573:tid 643741] [client 172.236.9.101:7683] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NfxWyxgRnoFKAJ_YiwAAAjM"]
[Thu Jul 30 11:43:35.404427 2026] [security2:error] [pid 643573:tid 643789] [client 172.236.9.101:42249] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NfxWyxgRnoFKAJ_YigAAAmM"]
[Thu Jul 30 11:43:35.417728 2026] [security2:error] [pid 643573:tid 643784] [client 172.237.109.114:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NfxWyxgRnoFKAJ_YhwAAAl4"]
[Thu Jul 30 11:43:35.438947 2026] [security2:error] [pid 642360:tid 642544] [client 172.237.109.114:62996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NJSUkh3e5AhEJOBadwAAAcU"]
[Thu Jul 30 11:43:35.447725 2026] [security2:error] [pid 642360:tid 642521] [client 172.236.9.101:40040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NZSUkh3e5AhEJOBaewAAAa4"]
[Thu Jul 30 11:43:35.522416 2026] [security2:error] [pid 643573:tid 643835] [client 172.237.109.114:23576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NfxWyxgRnoFKAJ_YhgAAApE"]
[Thu Jul 30 11:43:35.523483 2026] [security2:error] [pid 642360:tid 642606] [client 172.236.9.101:51661] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NZSUkh3e5AhEJOBafQAAAgM"]
[Thu Jul 30 11:43:35.530860 2026] [security2:error] [pid 642360:tid 642567] [client 172.237.109.114:11756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NJSUkh3e5AhEJOBaeAAAAdw"]
[Thu Jul 30 11:43:35.568549 2026] [security2:error] [pid 642360:tid 642542] [client 172.236.9.101:16511] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NZSUkh3e5AhEJOBafAAAAcM"]
[Thu Jul 30 11:43:36.268512 2026] [security2:error] [pid 642360:tid 642604] [client 172.236.9.101:5621] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NZSUkh3e5AhEJOBaegAAAgE"]
[Thu Jul 30 11:43:36.285789 2026] [security2:error] [pid 643573:tid 643832] [client 172.236.9.101:12354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NfxWyxgRnoFKAJ_YjQAAAo4"]
[Thu Jul 30 11:43:36.286189 2026] [security2:error] [pid 643573:tid 643722] [client 172.237.109.114:40439] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NPxWyxgRnoFKAJ_YhQAAAiA"]
[Thu Jul 30 11:43:36.289420 2026] [security2:error] [pid 643253:tid 643435] [client 172.236.9.101:25964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NcjqbtjBYzqM1uYjjQAAADM"]
[Thu Jul 30 11:43:36.306544 2026] [security2:error] [pid 643253:tid 643452] [client 172.236.9.101:3492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NcjqbtjBYzqM1uYjjwAAAEQ"]
[Thu Jul 30 11:43:36.326582 2026] [security2:error] [pid 642360:tid 642526] [client 172.236.9.101:21216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NZSUkh3e5AhEJOBaeQAAAbM"]
[Thu Jul 30 11:43:36.334093 2026] [security2:error] [pid 643253:tid 643502] [client 172.236.9.101:52842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NcjqbtjBYzqM1uYjjgAAAHY"]
[Thu Jul 30 11:43:36.342601 2026] [security2:error] [pid 643573:tid 643797] [client 172.236.9.101:40000] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NfxWyxgRnoFKAJ_YjgAAAms"]
[Thu Jul 30 11:43:36.345510 2026] [security2:error] [pid 643573:tid 643735] [client 172.236.9.101:15583] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NfxWyxgRnoFKAJ_YjwAAAi0"]
[Thu Jul 30 11:43:36.387053 2026] [security2:error] [pid 642360:tid 642611] [client 172.236.9.101:45485] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NZSUkh3e5AhEJOBafwAAAgg"]
[Thu Jul 30 11:43:36.388257 2026] [security2:error] [pid 643573:tid 643718] [client 172.236.9.101:8503] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NfxWyxgRnoFKAJ_YjAAAAhw"]
[Thu Jul 30 11:43:36.406247 2026] [security2:error] [pid 642360:tid 642500] [client 172.236.9.101:51012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NZSUkh3e5AhEJOBagAAAAZk"]
[Thu Jul 30 11:43:36.438567 2026] [security2:error] [pid 643573:tid 643733] [client 172.236.9.101:46096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NfxWyxgRnoFKAJ_YkAAAAis"]
[Thu Jul 30 11:43:36.485343 2026] [security2:error] [pid 643253:tid 643413] [client 172.236.9.101:12562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NcjqbtjBYzqM1uYjkQAAAB0"]
[Thu Jul 30 11:43:36.513303 2026] [security2:error] [pid 643253:tid 643480] [client 172.236.9.101:20468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NcjqbtjBYzqM1uYjkAAAAGA"]
[Thu Jul 30 11:43:36.581356 2026] [security2:error] [pid 643573:tid 643755] [client 172.237.109.114:53894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NfxWyxgRnoFKAJ_YlQAAAkE"]
[Thu Jul 30 11:43:37.244745 2026] [fcgid:warn] [pid 643573:tid 643818] (70014)End of file found: [client 159.65.49.75:47674] mod_fcgid: can't get data from http client
[Thu Jul 30 11:43:37.335924 2026] [security2:error] [pid 643573:tid 643765] [client 176.241.66.87:60512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_OfxWyxgRnoFKAJ_YqwAAAks"]
[Thu Jul 30 11:43:37.336114 2026] [security2:error] [pid 643573:tid 643765] [client 176.241.66.87:60512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_OfxWyxgRnoFKAJ_YqwAAAks"]
[Thu Jul 30 11:43:37.482536 2026] [fcgid:warn] [pid 643573:tid 643796] (70014)End of file found: [client 159.65.49.75:47678] mod_fcgid: can't get data from http client
[Thu Jul 30 11:43:39.339626 2026] [fcgid:warn] [pid 643573:tid 643726] (70014)End of file found: [client 159.65.49.75:47702] mod_fcgid: can't get data from http client
[Thu Jul 30 11:43:39.400174 2026] [security2:error] [pid 643573:tid 643651] [remote 216.73.216.152:57391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amt_O_xWyxgRnoFKAJ_YtwACHUY"]
[Thu Jul 30 11:43:40.235364 2026] [security2:error] [pid 642360:tid 642423] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_PJSUkh3e5AhEJOBavwABxD4"]
[Thu Jul 30 11:43:40.235521 2026] [security2:error] [pid 642360:tid 642543] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_PJSUkh3e5AhEJOBavwABxD4"]
[Thu Jul 30 11:43:41.001332 2026] [security2:error] [pid 643573:tid 643794] [client 185.156.175.171:51530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.175.156.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amt_PfxWyxgRnoFKAJ_YxAAAAmg"]
[Thu Jul 30 11:43:41.001487 2026] [security2:error] [pid 643573:tid 643794] [client 185.156.175.171:51530] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amt_PfxWyxgRnoFKAJ_YxAAAAmg"]
[Thu Jul 30 11:43:41.068274 2026] [autoindex:error] [pid 643573:tid 643789] [client 8.234.138.211:0] AH01276: Cannot serve directory /home2/mbmudite/otbola.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.otbola.click
[Thu Jul 30 11:43:41.199167 2026] [fcgid:warn] [pid 642360:tid 642572] (70014)End of file found: [client 159.65.49.75:56932] mod_fcgid: can't get data from http client
[Thu Jul 30 11:43:41.246765 2026] [core:notice] [pid 643573:tid 643756] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:43:41.278916 2026] [security2:error] [pid 643573:tid 643587] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_PfxWyxgRnoFKAJ_YyAACUgY"]
[Thu Jul 30 11:43:41.279081 2026] [security2:error] [pid 643573:tid 643772] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_PfxWyxgRnoFKAJ_YyAACUgY"]
[Thu Jul 30 11:43:41.289137 2026] [security2:error] [pid 642360:tid 642574] [client 143.198.88.13:59373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.88.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_PZSUkh3e5AhEJOBayQAAAeM"], referer: www.website-c08187ca.rka.jtu.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:43:41.545178 2026] [proxy:error] [pid 643253:tid 643492] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:43:41.545238 2026] [proxy_http:error] [pid 643253:tid 643492] [client 98.87.102.177:33811] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:43:41.545798 2026] [proxy:error] [pid 643253:tid 643492] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:43:41.545841 2026] [proxy_http:error] [pid 643253:tid 643492] [client 98.87.102.177:33811] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:43:41.570284 2026] [proxy:error] [pid 643573:tid 643732] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:43:41.570355 2026] [proxy_http:error] [pid 643573:tid 643732] [client 44.216.125.112:56535] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:43:41.571201 2026] [proxy:error] [pid 643573:tid 643732] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:43:41.571260 2026] [proxy_http:error] [pid 643573:tid 643732] [client 44.216.125.112:56535] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:43:42.255896 2026] [security2:error] [pid 643573:tid 643585] [remote 198.244.242.68:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "saiqon.net"] [uri "/hello-world/"] [unique_id "amt_PvxWyxgRnoFKAJ_Y1QACawQ"]
[Thu Jul 30 11:43:42.256121 2026] [security2:error] [pid 643573:tid 643797] [client 198.244.242.68:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "saiqon.net"] [uri "/hello-world/"] [unique_id "amt_PvxWyxgRnoFKAJ_Y1QACawQ"]
[Thu Jul 30 11:43:42.517727 2026] [security2:error] [pid 643253:tid 643504] [client 143.198.88.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "seven-stars-shop.com"] [uri "/index.php"] [unique_id "amt_PcjqbtjBYzqM1uYjowAAAHg"], referer: www.website-c08187ca.rka.jtu.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:43:42.820386 2026] [security2:error] [pid 642360:tid 642558] [client 172.236.9.101:61676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_PpSUkh3e5AhEJOBa1QAAAdM"]
[Thu Jul 30 11:43:42.832957 2026] [security2:error] [pid 643573:tid 643719] [client 172.236.9.101:27187] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_PvxWyxgRnoFKAJ_Y1AAAAh0"]
[Thu Jul 30 11:43:42.916108 2026] [security2:error] [pid 642360:tid 642567] [client 172.236.9.101:52721] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_PpSUkh3e5AhEJOBa1wAAAdw"]
[Thu Jul 30 11:43:42.924831 2026] [security2:error] [pid 642360:tid 642499] [client 172.236.9.101:55619] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_PpSUkh3e5AhEJOBa1gAAAZg"]
[Thu Jul 30 11:43:42.930843 2026] [security2:error] [pid 643253:tid 643447] [client 172.236.9.101:41373] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_PsjqbtjBYzqM1uYjpAAAAD8"]
[Thu Jul 30 11:43:44.220530 2026] [security2:error] [pid 642360:tid 642545] [client 2a03:2880:f800:16:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_PpSUkh3e5AhEJOBa0AABxjk"]
[Thu Jul 30 11:43:44.392637 2026] [proxy:error] [pid 643573:tid 643751] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:43:44.392731 2026] [proxy_http:error] [pid 643573:tid 643751] [client 74.7.230.26:54014] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:43:44.394099 2026] [proxy:error] [pid 643573:tid 643751] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:43:44.394168 2026] [proxy_http:error] [pid 643573:tid 643751] [client 74.7.230.26:54014] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:43:44.394457 2026] [security2:error] [pid 643573:tid 643751] [client 74.7.230.26:54014] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "cpcontacts.bah.djb.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amt_QPxWyxgRnoFKAJ_Y7AAAAj0"]
[Thu Jul 30 11:43:44.464552 2026] [security2:error] [pid 643573:tid 643816] [client 172.236.9.101:54557] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_P_xWyxgRnoFKAJ_Y3gAAAn4"]
[Thu Jul 30 11:43:44.474641 2026] [security2:error] [pid 643573:tid 643770] [client 172.236.9.101:38414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_P_xWyxgRnoFKAJ_Y4AAAAlA"]
[Thu Jul 30 11:43:44.489868 2026] [security2:error] [pid 643573:tid 643777] [client 172.236.9.101:19826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_P_xWyxgRnoFKAJ_Y3QAAAlc"]
[Thu Jul 30 11:43:44.506122 2026] [security2:error] [pid 643573:tid 643811] [client 172.236.9.101:57648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_P_xWyxgRnoFKAJ_Y3AAAAnk"]
[Thu Jul 30 11:43:44.512863 2026] [security2:error] [pid 643573:tid 643769] [client 172.236.9.101:58791] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_P_xWyxgRnoFKAJ_Y3wAAAk8"]
[Thu Jul 30 11:43:44.581502 2026] [security2:error] [pid 642360:tid 642553] [client 172.236.9.101:18105] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_P5SUkh3e5AhEJOBa4gAAAc4"]
[Thu Jul 30 11:43:44.586764 2026] [security2:error] [pid 643573:tid 643793] [client 172.236.9.101:15787] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_P_xWyxgRnoFKAJ_Y4gAAAmc"]
[Thu Jul 30 11:43:44.603189 2026] [security2:error] [pid 643573:tid 643818] [client 172.236.9.101:60907] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_P_xWyxgRnoFKAJ_Y4wAAAoA"]
[Thu Jul 30 11:43:44.624476 2026] [security2:error] [pid 643253:tid 643393] [client 172.236.9.101:4066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_P8jqbtjBYzqM1uYjpgAAAAk"]
[Thu Jul 30 11:43:44.625036 2026] [security2:error] [pid 642360:tid 642591] [client 172.236.9.101:51945] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_P5SUkh3e5AhEJOBa4wAAAfQ"]
[Thu Jul 30 11:43:44.627950 2026] [security2:error] [pid 643573:tid 643766] [client 172.236.9.101:26209] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_P_xWyxgRnoFKAJ_Y4QAAAkw"]
[Thu Jul 30 11:43:44.638858 2026] [security2:error] [pid 643573:tid 643785] [client 172.236.9.101:14308] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_P_xWyxgRnoFKAJ_Y5QAAAl8"]
[Thu Jul 30 11:43:44.666515 2026] [security2:error] [pid 643573:tid 643743] [client 172.236.9.101:16533] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_P_xWyxgRnoFKAJ_Y5gAAAjU"]
[Thu Jul 30 11:43:44.668063 2026] [security2:error] [pid 643253:tid 643407] [client 172.236.9.101:11853] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_P8jqbtjBYzqM1uYjpwAAABc"]
[Thu Jul 30 11:43:44.668082 2026] [security2:error] [pid 643573:tid 643765] [client 172.236.9.101:31145] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_P_xWyxgRnoFKAJ_Y5AAAAks"]
[Thu Jul 30 11:43:44.763391 2026] [security2:error] [pid 643573:tid 643753] [client 143.198.88.13:59424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "seven-stars-shop.com"] [uri "/index.php"] [unique_id "amt_P_xWyxgRnoFKAJ_Y6QAAAj8"], referer: www.website-c08187ca.rka.jtu.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:43:45.025873 2026] [security2:error] [pid 643573:tid 643622] [remote 216.73.216.152:13381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amt_QfxWyxgRnoFKAJ_Y8gACOCk"]
[Thu Jul 30 11:43:45.728648 2026] [security2:error] [pid 643573:tid 643819] [client 143.198.88.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "seven-stars-shop.com"] [uri "/index.php"] [unique_id "amt_QPxWyxgRnoFKAJ_Y8QAAAoE"], referer: www.website-c08187ca.rka.jtu.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:43:47.019747 2026] [security2:error] [pid 643573:tid 643738] [client 143.198.88.13:59424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "seven-stars-shop.com"] [uri "/index.php"] [unique_id "amt_QvxWyxgRnoFKAJ_Y-wAAAjA"], referer: www.website-c08187ca.rka.jtu.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:43:47.116671 2026] [security2:error] [pid 643573:tid 643743] [client 143.198.88.13:59424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.88.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/blog//xmlrpc.php"] [unique_id "amt_Q_xWyxgRnoFKAJ_ZBAAAAjU"]
[Thu Jul 30 11:43:47.116804 2026] [security2:error] [pid 643573:tid 643743] [client 143.198.88.13:59424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/blog//xmlrpc.php"] [unique_id "amt_Q_xWyxgRnoFKAJ_ZBAAAAjU"]
[Thu Jul 30 11:43:47.494055 2026] [security2:error] [pid 643573:tid 643757] [client 143.198.88.13:51141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.88.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/blog//wp-login.php"] [unique_id "amt_Q_xWyxgRnoFKAJ_ZBQAAAkM"], referer: https://seven-stars-shop.com//blog//wp-login.php
[Thu Jul 30 11:43:47.988882 2026] [security2:error] [pid 643573:tid 643718] [client 176.241.66.87:47313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_Q_xWyxgRnoFKAJ_ZBgAAAhw"]
[Thu Jul 30 11:43:47.989029 2026] [security2:error] [pid 643573:tid 643718] [client 176.241.66.87:47313] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_Q_xWyxgRnoFKAJ_ZBgAAAhw"]
[Thu Jul 30 11:43:48.870796 2026] [security2:error] [pid 643573:tid 643780] [client 172.236.9.101:12230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RPxWyxgRnoFKAJ_ZBwAAAlo"]
[Thu Jul 30 11:43:48.872703 2026] [security2:error] [pid 642360:tid 642492] [client 172.236.9.101:41138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RJSUkh3e5AhEJOBbFgAAAZE"]
[Thu Jul 30 11:43:49.245636 2026] [security2:error] [pid 642360:tid 642577] [client 172.236.9.101:35823] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RJSUkh3e5AhEJOBbFwAAAeY"]
[Thu Jul 30 11:43:49.273625 2026] [security2:error] [pid 642360:tid 642598] [client 172.236.9.101:11892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RJSUkh3e5AhEJOBbGAAAAfs"]
[Thu Jul 30 11:43:49.307897 2026] [security2:error] [pid 643573:tid 643805] [client 172.236.9.101:59506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RPxWyxgRnoFKAJ_ZCAAAAnM"]
[Thu Jul 30 11:43:49.315432 2026] [security2:error] [pid 642360:tid 642603] [client 172.236.9.101:4263] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RJSUkh3e5AhEJOBbGgAAAgA"]
[Thu Jul 30 11:43:49.331588 2026] [security2:error] [pid 642360:tid 642529] [client 172.236.9.101:28738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RJSUkh3e5AhEJOBbGQAAAbY"]
[Thu Jul 30 11:43:49.338006 2026] [security2:error] [pid 642360:tid 642563] [client 172.236.9.101:47421] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RJSUkh3e5AhEJOBbGwAAAdg"]
[Thu Jul 30 11:43:49.344294 2026] [security2:error] [pid 643253:tid 643501] [client 172.236.9.101:63294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RMjqbtjBYzqM1uYjrwAAAHU"]
[Thu Jul 30 11:43:49.361857 2026] [security2:error] [pid 642360:tid 642606] [client 172.236.9.101:2322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RJSUkh3e5AhEJOBbHAAAAgM"]
[Thu Jul 30 11:43:49.406242 2026] [security2:error] [pid 643573:tid 643609] [remote 216.73.216.152:13381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amt_RfxWyxgRnoFKAJ_ZIAACUhw"]
[Thu Jul 30 11:43:49.408129 2026] [security2:error] [pid 642360:tid 642601] [client 127.0.0.1:57226] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amt_RZSUkh3e5AhEJOBbJwAAAf4"]
[Thu Jul 30 11:43:49.408396 2026] [security2:error] [pid 642360:tid 642568] [client 74.7.230.57:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.royalrelaxspa.sbs"] [uri "/robots.txt"] [unique_id "amt_RZSUkh3e5AhEJOBbJgAB3VQ"]
[Thu Jul 30 11:43:50.307730 2026] [security2:error] [pid 642360:tid 642567] [client 172.236.9.101:48545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RZSUkh3e5AhEJOBbJAAAAdw"]
[Thu Jul 30 11:43:50.325930 2026] [security2:error] [pid 643573:tid 643835] [client 172.236.9.101:16775] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RfxWyxgRnoFKAJ_ZGAAAApE"]
[Thu Jul 30 11:43:50.334125 2026] [security2:error] [pid 642360:tid 642499] [client 172.236.9.101:1301] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RZSUkh3e5AhEJOBbJQAAAZg"]
[Thu Jul 30 11:43:50.362190 2026] [security2:error] [pid 643573:tid 643781] [client 172.236.9.101:65289] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RfxWyxgRnoFKAJ_ZGgAAAls"]
[Thu Jul 30 11:43:50.420327 2026] [security2:error] [pid 643573:tid 643789] [client 172.236.9.101:38053] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RfxWyxgRnoFKAJ_ZGQAAAmM"]
[Thu Jul 30 11:43:50.438155 2026] [security2:error] [pid 643573:tid 643775] [client 172.236.9.101:15352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RfxWyxgRnoFKAJ_ZGwAAAlU"]
[Thu Jul 30 11:43:50.440241 2026] [security2:error] [pid 643573:tid 643831] [client 172.236.9.101:65236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RfxWyxgRnoFKAJ_ZHQAAAo0"]
[Thu Jul 30 11:43:50.440453 2026] [security2:error] [pid 643573:tid 643829] [client 172.236.9.101:12130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RfxWyxgRnoFKAJ_ZHAAAAos"]
[Thu Jul 30 11:43:50.458798 2026] [security2:error] [pid 643573:tid 643792] [client 172.236.9.101:36992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RfxWyxgRnoFKAJ_ZHwAAAmY"]
[Thu Jul 30 11:43:50.469267 2026] [security2:error] [pid 643573:tid 643824] [client 172.236.9.101:64774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RfxWyxgRnoFKAJ_ZHgAAAoY"]
[Thu Jul 30 11:43:50.619841 2026] [security2:error] [pid 643573:tid 643598] [remote 152.53.37.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.37.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "madeninsabah.com"] [uri "/xmlrpc.php"] [unique_id "amt_RvxWyxgRnoFKAJ_ZJgACfBE"]
[Thu Jul 30 11:43:50.620048 2026] [security2:error] [pid 643573:tid 643814] [client 152.53.37.129:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "madeninsabah.com"] [uri "/xmlrpc.php"] [unique_id "amt_RvxWyxgRnoFKAJ_ZJgACfBE"]
[Thu Jul 30 11:43:51.205266 2026] [security2:error] [pid 643573:tid 643608] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_R_xWyxgRnoFKAJ_ZKQACTRs"]
[Thu Jul 30 11:43:51.205410 2026] [security2:error] [pid 643573:tid 643767] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_R_xWyxgRnoFKAJ_ZKQACTRs"]
[Thu Jul 30 11:43:51.933580 2026] [security2:error] [pid 643573:tid 643583] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_R_xWyxgRnoFKAJ_ZLAACIwI"]
[Thu Jul 30 11:43:51.933730 2026] [security2:error] [pid 643573:tid 643725] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_R_xWyxgRnoFKAJ_ZLAACIwI"]
[Thu Jul 30 11:43:52.793593 2026] [security2:error] [pid 642360:tid 642456] [remote 40.77.167.70:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/citationstylelanguage/download/bibtex"] [unique_id "amt_SJSUkh3e5AhEJOBbTwABzV8"]
[Thu Jul 30 11:43:52.959334 2026] [security2:error] [pid 643573:tid 643796] [client 57.141.0.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "marlboro-shop.com"] [uri "/index.php"] [unique_id "amt_R_xWyxgRnoFKAJ_ZLgAAAmo"], referer: https://marlboro-shop.com/marlboro-rank/
[Thu Jul 30 11:43:53.317934 2026] [security2:error] [pid 643573:tid 643625] [remote 217.181.86.111:47568] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "deltaedu.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amt_SfxWyxgRnoFKAJ_ZNgACgCw"], referer: https://deltaedu.net/
[Thu Jul 30 11:43:54.408111 2026] [security2:error] [pid 643573:tid 643616] [remote 216.73.216.152:13381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amt_SvxWyxgRnoFKAJ_ZTAACTCM"]
[Thu Jul 30 11:43:55.793159 2026] [security2:error] [pid 643573:tid 643737] [client 57.141.0.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_S_xWyxgRnoFKAJ_ZVgAAAi8"]
[Thu Jul 30 11:43:56.538170 2026] [core:notice] [pid 643573:tid 643810] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:43:57.503636 2026] [security2:error] [pid 643573:tid 643749] [client 172.236.9.101:9067] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TPxWyxgRnoFKAJ_ZYgAAAjs"]
[Thu Jul 30 11:43:57.508859 2026] [core:notice] [pid 643573:tid 643770] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:43:57.546243 2026] [security2:error] [pid 643573:tid 643831] [client 172.236.9.101:47497] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TPxWyxgRnoFKAJ_ZYQAAAo0"]
[Thu Jul 30 11:43:58.231506 2026] [security2:error] [pid 643573:tid 643763] [client 172.236.9.101:61122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TPxWyxgRnoFKAJ_ZYAAAAkk"]
[Thu Jul 30 11:43:58.259903 2026] [security2:error] [pid 643573:tid 643776] [client 172.236.9.101:61955] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TPxWyxgRnoFKAJ_ZYwAAAlY"]
[Thu Jul 30 11:43:58.274094 2026] [security2:error] [pid 642360:tid 642529] [client 172.236.9.101:1599] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TJSUkh3e5AhEJOBbZwAAAbY"]
[Thu Jul 30 11:43:58.280250 2026] [security2:error] [pid 643573:tid 643779] [client 172.236.9.101:13349] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TPxWyxgRnoFKAJ_ZZQAAAlk"]
[Thu Jul 30 11:43:58.280332 2026] [security2:error] [pid 643253:tid 643424] [client 172.236.9.101:14516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TMjqbtjBYzqM1uYjuAAAACg"]
[Thu Jul 30 11:43:58.286535 2026] [security2:error] [pid 643573:tid 643762] [client 172.236.9.101:23794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TPxWyxgRnoFKAJ_ZZAAAAkg"]
[Thu Jul 30 11:43:58.287414 2026] [security2:error] [pid 643573:tid 643804] [client 172.236.9.101:60968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TPxWyxgRnoFKAJ_ZZgAAAnI"]
[Thu Jul 30 11:43:58.287461 2026] [security2:error] [pid 643253:tid 643431] [client 172.236.9.101:1746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TMjqbtjBYzqM1uYjuQAAAC8"]
[Thu Jul 30 11:43:58.295488 2026] [security2:error] [pid 643573:tid 643758] [client 172.236.9.101:19117] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TPxWyxgRnoFKAJ_ZagAAAkQ"]
[Thu Jul 30 11:43:58.298669 2026] [security2:error] [pid 643573:tid 643767] [client 172.236.9.101:38358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TPxWyxgRnoFKAJ_ZaQAAAk0"]
[Thu Jul 30 11:43:58.307509 2026] [security2:error] [pid 643573:tid 643795] [client 172.236.9.101:35932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TPxWyxgRnoFKAJ_ZaAAAAmk"]
[Thu Jul 30 11:43:58.313138 2026] [security2:error] [pid 643573:tid 643748] [client 172.236.9.101:41204] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TPxWyxgRnoFKAJ_ZZwAAAjo"]
[Thu Jul 30 11:43:58.317234 2026] [security2:error] [pid 643253:tid 643418] [client 172.236.9.101:20085] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TMjqbtjBYzqM1uYjtwAAACI"]
[Thu Jul 30 11:43:58.328686 2026] [security2:error] [pid 643573:tid 643764] [client 172.236.9.101:10406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TPxWyxgRnoFKAJ_ZawAAAko"]
[Thu Jul 30 11:43:58.545011 2026] [core:notice] [pid 643573:tid 643730] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:43:58.604660 2026] [security2:error] [pid 643253:tid 643462] [client 172.236.9.101:10620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TcjqbtjBYzqM1uYjvAAAAE4"]
[Thu Jul 30 11:43:58.632795 2026] [security2:error] [pid 643253:tid 643464] [client 176.241.66.87:48243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_TsjqbtjBYzqM1uYjvwAAAFA"]
[Thu Jul 30 11:43:58.633258 2026] [security2:error] [pid 643253:tid 643464] [client 176.241.66.87:48243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_TsjqbtjBYzqM1uYjvwAAAFA"]
[Thu Jul 30 11:43:58.649340 2026] [security2:error] [pid 643253:tid 643455] [client 172.236.9.101:28920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TcjqbtjBYzqM1uYjvQAAAEc"]
[Thu Jul 30 11:43:58.682057 2026] [security2:error] [pid 643573:tid 643836] [client 172.236.9.101:11343] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TfxWyxgRnoFKAJ_ZcwAAApI"]
[Thu Jul 30 11:43:58.712183 2026] [security2:error] [pid 643253:tid 643421] [client 172.236.9.101:62908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TcjqbtjBYzqM1uYjvgAAACU"]
[Thu Jul 30 11:43:58.941489 2026] [security2:error] [pid 642360:tid 642501] [client 57.141.0.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_TpSUkh3e5AhEJOBbdwAAAZo"]
[Thu Jul 30 11:44:00.047544 2026] [security2:error] [pid 643573:tid 643828] [client 78.47.173.76:45656] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amt_UPxWyxgRnoFKAJ_ZkwAAAoo"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 11:44:00.334295 2026] [security2:error] [pid 643573:tid 643642] [remote 74.7.241.60:35984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/content/article.php"] [unique_id "amt_UPxWyxgRnoFKAJ_ZmQACRD0"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/content/1784122425_Physioth%C3%A9rapie%20%C3%A0%20Domicile.jpg
[Thu Jul 30 11:44:00.847461 2026] [core:notice] [pid 643573:tid 643788] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:00.852902 2026] [security2:error] [pid 643573:tid 643788] [client 78.47.173.76:45658] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_UPxWyxgRnoFKAJ_ZnQAAAmI"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 11:44:00.969131 2026] [core:notice] [pid 643573:tid 643780] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:01.481629 2026] [security2:error] [pid 642360:tid 642511] [client 78.47.173.76:45672] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amt_UZSUkh3e5AhEJOBbjgAAAaQ"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 11:44:02.120110 2026] [security2:error] [pid 642360:tid 642470] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_UpSUkh3e5AhEJOBblAAB_G0"]
[Thu Jul 30 11:44:02.120327 2026] [security2:error] [pid 642360:tid 642599] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_UpSUkh3e5AhEJOBblAAB_G0"]
[Thu Jul 30 11:44:02.272686 2026] [security2:error] [pid 642360:tid 642530] [client 143.198.88.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "plumbingplumb.com"] [uri "/index.php"] [unique_id "amt_UpSUkh3e5AhEJOBblQABt3U"], referer: https://chenclean2015.com//blog//wp-login.php
[Thu Jul 30 11:44:02.339358 2026] [security2:error] [pid 643573:tid 643790] [client 172.202.44.182:47271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/chosen.php"] [unique_id "amt_UvxWyxgRnoFKAJ_ZrAAAAmQ"]
[Thu Jul 30 11:44:02.572692 2026] [security2:error] [pid 643573:tid 643654] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_UvxWyxgRnoFKAJ_ZrwACaUk"]
[Thu Jul 30 11:44:02.572845 2026] [security2:error] [pid 643573:tid 643795] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_UvxWyxgRnoFKAJ_ZrwACaUk"]
[Thu Jul 30 11:44:03.238594 2026] [security2:error] [pid 643573:tid 643728] [client 172.202.44.182:22360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/xleet.php"] [unique_id "amt_U_xWyxgRnoFKAJ_ZtwAAAiY"]
[Thu Jul 30 11:44:03.270328 2026] [security2:error] [pid 643573:tid 643837] [client 2a03:2880:f800:c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_UvxWyxgRnoFKAJ_ZpgACk0I"]
[Thu Jul 30 11:44:03.310665 2026] [security2:error] [pid 643573:tid 643733] [client 185.191.171.2:39692] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/robots.txt"] [unique_id "amt_U_xWyxgRnoFKAJ_ZugAAAis"]
[Thu Jul 30 11:44:03.310770 2026] [security2:error] [pid 643573:tid 643733] [client 185.191.171.2:39692] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/robots.txt"] [unique_id "amt_U_xWyxgRnoFKAJ_ZugAAAis"]
[Thu Jul 30 11:44:04.251358 2026] [security2:error] [pid 643573:tid 643725] [client 85.208.96.202:59274] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2021/08/25/bb-libera-r-2-bi-para-recuperacao-de-lavouras-atingidas-por-geada/"] [unique_id "amt_VPxWyxgRnoFKAJ_ZvwAAAiM"]
[Thu Jul 30 11:44:04.251460 2026] [security2:error] [pid 643573:tid 643725] [client 85.208.96.202:59274] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2021/08/25/bb-libera-r-2-bi-para-recuperacao-de-lavouras-atingidas-por-geada/"] [unique_id "amt_VPxWyxgRnoFKAJ_ZvwAAAiM"]
[Thu Jul 30 11:44:04.443421 2026] [core:notice] [pid 642360:tid 642361] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:04.450687 2026] [security2:error] [pid 642360:tid 642525] [client 20.235.75.219:49857] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/camic/article/download/9051/3903"] [unique_id "amt_VJSUkh3e5AhEJOBbowABsgA"]
[Thu Jul 30 11:44:04.781105 2026] [security2:error] [pid 643253:tid 643465] [client 170.64.210.244:46400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "50.6.43.58"] [uri "/.env"] [unique_id "amt_VMjqbtjBYzqM1uYjwwAAAFE"]
[Thu Jul 30 11:44:05.028875 2026] [core:notice] [pid 643573:tid 643632] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:06.203513 2026] [security2:error] [pid 642360:tid 642546] [client 172.202.44.182:60948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/ds.php"] [unique_id "amt_VpSUkh3e5AhEJOBbvAAAAcc"]
[Thu Jul 30 11:44:07.218408 2026] [security2:error] [pid 643573:tid 643743] [client 172.202.44.182:60943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/f5.php"] [unique_id "amt_V_xWyxgRnoFKAJ_Z3gAAAjU"]
[Thu Jul 30 11:44:07.301697 2026] [security2:error] [pid 642360:tid 642559] [client 172.236.9.101:11304] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VZSUkh3e5AhEJOBbqwAAAdQ"]
[Thu Jul 30 11:44:07.344359 2026] [security2:error] [pid 642360:tid 642604] [client 172.236.9.101:47605] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VZSUkh3e5AhEJOBbrAAAAgE"]
[Thu Jul 30 11:44:07.351460 2026] [security2:error] [pid 642360:tid 642615] [client 172.236.9.101:55841] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VZSUkh3e5AhEJOBbrQAAAgw"]
[Thu Jul 30 11:44:07.351666 2026] [security2:error] [pid 643573:tid 643793] [client 172.236.9.101:27992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VfxWyxgRnoFKAJ_ZzAAAAmc"]
[Thu Jul 30 11:44:07.386928 2026] [security2:error] [pid 643573:tid 643813] [client 172.236.9.101:42705] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VfxWyxgRnoFKAJ_ZzwAAAns"]
[Thu Jul 30 11:44:07.393727 2026] [security2:error] [pid 642360:tid 642514] [client 172.236.9.101:33986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VZSUkh3e5AhEJOBbrwAAAac"]
[Thu Jul 30 11:44:07.394573 2026] [security2:error] [pid 643573:tid 643718] [client 172.236.9.101:4889] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VfxWyxgRnoFKAJ_ZzQAAAhw"]
[Thu Jul 30 11:44:07.394973 2026] [security2:error] [pid 642360:tid 642558] [client 172.236.9.101:16169] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VZSUkh3e5AhEJOBbrgAAAdM"]
[Thu Jul 30 11:44:07.395023 2026] [security2:error] [pid 642360:tid 642598] [client 172.236.9.101:41610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VZSUkh3e5AhEJOBbswAAAfs"]
[Thu Jul 30 11:44:07.399549 2026] [security2:error] [pid 642360:tid 642603] [client 172.236.9.101:22226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VZSUkh3e5AhEJOBbtAAAAgA"]
[Thu Jul 30 11:44:07.409017 2026] [security2:error] [pid 643573:tid 643824] [client 172.236.9.101:41877] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VfxWyxgRnoFKAJ_ZzgAAAoY"]
[Thu Jul 30 11:44:07.409734 2026] [security2:error] [pid 643573:tid 643722] [client 172.236.9.101:26792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VfxWyxgRnoFKAJ_Z0QAAAiA"]
[Thu Jul 30 11:44:07.410242 2026] [security2:error] [pid 642360:tid 642563] [client 172.236.9.101:39878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VZSUkh3e5AhEJOBbtwAAAdg"]
[Thu Jul 30 11:44:07.430047 2026] [security2:error] [pid 643573:tid 643782] [client 172.236.9.101:19690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VfxWyxgRnoFKAJ_Z0gAAAlw"]
[Thu Jul 30 11:44:07.434781 2026] [security2:error] [pid 642360:tid 642526] [client 172.236.9.101:11246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VZSUkh3e5AhEJOBbsAAAAbM"]
[Thu Jul 30 11:44:07.452007 2026] [security2:error] [pid 642360:tid 642500] [client 172.236.9.101:55989] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VZSUkh3e5AhEJOBbtgAAAZk"]
[Thu Jul 30 11:44:07.463122 2026] [security2:error] [pid 643253:tid 643416] [client 172.236.9.101:12925] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VcjqbtjBYzqM1uYjxAAAACA"]
[Thu Jul 30 11:44:07.480224 2026] [security2:error] [pid 643573:tid 643819] [client 172.236.9.101:13940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VfxWyxgRnoFKAJ_Z0wAAAoE"]
[Thu Jul 30 11:44:07.482714 2026] [security2:error] [pid 642360:tid 642610] [client 172.236.9.101:28129] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VZSUkh3e5AhEJOBbtQAAAgc"]
[Thu Jul 30 11:44:07.500510 2026] [security2:error] [pid 643573:tid 643814] [client 172.236.9.101:5558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VfxWyxgRnoFKAJ_ZywAAAnw"]
[Thu Jul 30 11:44:08.389648 2026] [security2:error] [pid 643573:tid 643745] [client 172.202.44.182:22397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/god4m.php"] [unique_id "amt_WPxWyxgRnoFKAJ_Z5wAAAjc"]
[Thu Jul 30 11:44:08.855688 2026] [core:notice] [pid 643253:tid 643305] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:09.291682 2026] [security2:error] [pid 643573:tid 643811] [client 176.241.66.87:62122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_WfxWyxgRnoFKAJ_Z8QAAAnk"]
[Thu Jul 30 11:44:09.291801 2026] [security2:error] [pid 643573:tid 643811] [client 176.241.66.87:62122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_WfxWyxgRnoFKAJ_Z8QAAAnk"]
[Thu Jul 30 11:44:09.412040 2026] [security2:error] [pid 643573:tid 643669] [remote 216.73.216.152:13381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amt_WfxWyxgRnoFKAJ_Z8wACg1g"]
[Thu Jul 30 11:44:09.582441 2026] [security2:error] [pid 643573:tid 643819] [client 172.202.44.182:22017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/info.php"] [unique_id "amt_WfxWyxgRnoFKAJ_Z9QAAAoE"]
[Thu Jul 30 11:44:09.843552 2026] [security2:error] [pid 643573:tid 643789] [client 57.141.0.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_WfxWyxgRnoFKAJ_Z7gAAAmM"]
[Thu Jul 30 11:44:11.036053 2026] [security2:error] [pid 643573:tid 643753] [client 172.202.44.182:47233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/.__info.php"] [unique_id "amt_W_xWyxgRnoFKAJ_aAAAAAj8"]
[Thu Jul 30 11:44:11.817990 2026] [core:notice] [pid 643573:tid 643761] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:12.065865 2026] [core:notice] [pid 643573:tid 643763] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:12.191512 2026] [security2:error] [pid 642360:tid 642597] [client 20.215.191.139:49119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/011i.php"] [unique_id "amt_XJSUkh3e5AhEJOBb7gAAAfo"]
[Thu Jul 30 11:44:12.265227 2026] [core:notice] [pid 643573:tid 643812] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:12.265405 2026] [security2:error] [pid 642360:tid 642527] [client 172.202.44.182:60945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/0.php"] [unique_id "amt_XJSUkh3e5AhEJOBb7wAAAbQ"]
[Thu Jul 30 11:44:12.537524 2026] [core:notice] [pid 643573:tid 643731] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:12.731785 2026] [core:notice] [pid 642360:tid 642548] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:12.970265 2026] [core:notice] [pid 643573:tid 643816] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:13.011507 2026] [security2:error] [pid 643573:tid 643756] [client 57.141.0.50:49478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amt_XPxWyxgRnoFKAJ_aCwACQlM"], referer: https://igetvape-australia.com/product-category/alibarbar-rich-8000-puffs/?add-to-cart=1049
[Thu Jul 30 11:44:13.030458 2026] [security2:error] [pid 643573:tid 643751] [client 20.215.191.139:64705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/03a005685d.php"] [unique_id "amt_XfxWyxgRnoFKAJ_aDwAAAj0"]
[Thu Jul 30 11:44:13.119290 2026] [security2:error] [pid 643573:tid 643668] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_XfxWyxgRnoFKAJ_aEAACRVc"]
[Thu Jul 30 11:44:13.119489 2026] [security2:error] [pid 643573:tid 643759] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_XfxWyxgRnoFKAJ_aEAACRVc"]
[Thu Jul 30 11:44:13.189899 2026] [security2:error] [pid 643573:tid 643670] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_XfxWyxgRnoFKAJ_aEQACPlk"]
[Thu Jul 30 11:44:13.190091 2026] [security2:error] [pid 643573:tid 643752] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_XfxWyxgRnoFKAJ_aEQACPlk"]
[Thu Jul 30 11:44:13.222409 2026] [core:notice] [pid 643573:tid 643818] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:13.306344 2026] [security2:error] [pid 643573:tid 643805] [client 57.141.0.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_XPxWyxgRnoFKAJ_aDAAAAnM"]
[Thu Jul 30 11:44:13.476609 2026] [core:notice] [pid 643573:tid 643740] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:13.687263 2026] [core:notice] [pid 643573:tid 643824] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:13.911277 2026] [core:notice] [pid 642360:tid 642615] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:14.157963 2026] [core:notice] [pid 643573:tid 643835] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:14.395542 2026] [core:notice] [pid 643573:tid 643742] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:14.570581 2026] [security2:error] [pid 643573:tid 643667] [remote 173.231.241.109:57246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.241.231.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-aa23bb9f.dlr.djb.temporary.site"] [uri "/wp-login.php"] [unique_id "amt_XvxWyxgRnoFKAJ_aKAACSVY"]
[Thu Jul 30 11:44:14.645728 2026] [core:notice] [pid 643573:tid 643724] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:14.871216 2026] [core:notice] [pid 643573:tid 643831] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:14.966106 2026] [security2:error] [pid 643573:tid 643747] [client 20.215.191.139:49148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/403.php"] [unique_id "amt_XvxWyxgRnoFKAJ_aMQAAAjk"]
[Thu Jul 30 11:44:15.054640 2026] [core:notice] [pid 643573:tid 643756] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:15.136018 2026] [security2:error] [pid 643573:tid 643610] [remote 216.73.216.152:4364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amt_X_xWyxgRnoFKAJ_aNQACWB0"]
[Thu Jul 30 11:44:15.437761 2026] [security2:error] [pid 643573:tid 643773] [client 57.141.0.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_XvxWyxgRnoFKAJ_aLwAAAlM"]
[Thu Jul 30 11:44:15.963578 2026] [security2:error] [pid 643573:tid 643730] [client 20.215.191.139:49146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/404.php"] [unique_id "amt_X_xWyxgRnoFKAJ_aPAAAAig"]
[Thu Jul 30 11:44:16.048203 2026] [core:notice] [pid 643573:tid 643784] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:16.137614 2026] [security2:error] [pid 643573:tid 643710] [client 57.141.0.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_X_xWyxgRnoFKAJ_aOQAAAhQ"]
[Thu Jul 30 11:44:16.565395 2026] [core:notice] [pid 643573:tid 643772] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:16.848193 2026] [security2:error] [pid 642360:tid 642608] [client 47.236.199.168:42352] ModSecurity: Warning. Matched phrase "WebCopier" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "legalsnaps.info"] [uri "/wp-content/uploads/2026/04/ChatGPT-Image-Apr-21-2026-12_09_00-AM.png"] [unique_id "amt_RpSUkh3e5AhEJOBbOAAAAgU"]
[Thu Jul 30 11:44:16.890579 2026] [security2:error] [pid 643573:tid 643677] [remote 188.132.136.190:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.136.132.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "trustedmoversandpackersabudhabi.online"] [uri "/xmlrpc.php"] [unique_id "amt_YPxWyxgRnoFKAJ_aQQACLGA"]
[Thu Jul 30 11:44:16.890799 2026] [security2:error] [pid 643573:tid 643734] [client 188.132.136.190:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "trustedmoversandpackersabudhabi.online"] [uri "/xmlrpc.php"] [unique_id "amt_YPxWyxgRnoFKAJ_aQQACLGA"]
[Thu Jul 30 11:44:17.172109 2026] [core:notice] [pid 643573:tid 643832] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:17.209237 2026] [core:error] [pid 643253:tid 643387] [client 185.247.137.50:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:17.209265 2026] [core:error] [pid 643253:tid 643387] [client 185.247.137.50:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:17.508626 2026] [security2:error] [pid 643573:tid 643737] [client 85.208.96.198:20636] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/06/10/em-apenas-uma-semana-paraiba-registra-mais-de-3-mil-novos-casos-de-dengue-zika-e-chikungunya/"] [unique_id "amt_YfxWyxgRnoFKAJ_aRgAAAi8"]
[Thu Jul 30 11:44:17.508807 2026] [security2:error] [pid 643573:tid 643737] [client 85.208.96.198:20636] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/06/10/em-apenas-uma-semana-paraiba-registra-mais-de-3-mil-novos-casos-de-dengue-zika-e-chikungunya/"] [unique_id "amt_YfxWyxgRnoFKAJ_aRgAAAi8"]
[Thu Jul 30 11:44:17.528331 2026] [security2:error] [pid 643573:tid 643781] [client 20.215.191.139:49108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/aa.php"] [unique_id "amt_YfxWyxgRnoFKAJ_aRwAAAls"]
[Thu Jul 30 11:44:17.796044 2026] [security2:error] [pid 643573:tid 643798] [client 2a03:2880:f800:8:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_YfxWyxgRnoFKAJ_aQgACbBI"]
[Thu Jul 30 11:44:17.923423 2026] [core:notice] [pid 643573:tid 643791] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:18.506638 2026] [core:notice] [pid 643573:tid 643837] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:19.030023 2026] [security2:error] [pid 643573:tid 643733] [client 20.215.191.139:49133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/aafewc0k.php"] [unique_id "amt_Y_xWyxgRnoFKAJ_aWgAAAis"]
[Thu Jul 30 11:44:19.155186 2026] [autoindex:error] [pid 643573:tid 643800] [client 106.219.166.254:3823] AH01276: Cannot serve directory /home1/yqegzjte/hello-pal.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:44:19.258756 2026] [core:notice] [pid 643573:tid 643801] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:19.307268 2026] [security2:error] [pid 643573:tid 643754] [client 129.159.56.14:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.yxe.zzt.temporary.site"] [uri "/.env"] [unique_id "amt_Y_xWyxgRnoFKAJ_aXgAAAkA"]
[Thu Jul 30 11:44:19.423206 2026] [security2:error] [pid 643573:tid 643648] [remote 216.73.216.152:4364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amt_Y_xWyxgRnoFKAJ_aYQACLEM"]
[Thu Jul 30 11:44:19.626637 2026] [security2:error] [pid 643573:tid 643788] [client 2407:d000:1c:9d56:64c4:87bd:6970:5a53:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_Y_xWyxgRnoFKAJ_aWwACYmU"]
[Thu Jul 30 11:44:19.787800 2026] [security2:error] [pid 643253:tid 643487] [client 172.202.44.182:22358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/07.php"] [unique_id "amt_Y8jqbtjBYzqM1uYjzAAAAGc"]
[Thu Jul 30 11:44:19.857457 2026] [security2:error] [pid 643573:tid 643785] [client 176.241.66.87:49916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_Y_xWyxgRnoFKAJ_aYwAAAl8"]
[Thu Jul 30 11:44:19.857612 2026] [security2:error] [pid 643573:tid 643785] [client 176.241.66.87:49916] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_Y_xWyxgRnoFKAJ_aYwAAAl8"]
[Thu Jul 30 11:44:19.877839 2026] [core:notice] [pid 643573:tid 643779] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:21.203592 2026] [security2:error] [pid 643573:tid 643683] [remote 57.141.0.32:32318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amt_ZfxWyxgRnoFKAJ_abQACUWY"]
[Thu Jul 30 11:44:21.319138 2026] [security2:error] [pid 643573:tid 643751] [client 20.215.191.139:65309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/abcd.php"] [unique_id "amt_ZfxWyxgRnoFKAJ_abgAAAj0"]
[Thu Jul 30 11:44:21.961430 2026] [security2:error] [pid 643573:tid 643790] [client 20.215.191.139:49149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/about.php"] [unique_id "amt_ZfxWyxgRnoFKAJ_adwAAAmQ"]
[Thu Jul 30 11:44:22.092452 2026] [core:notice] [pid 643573:tid 643676] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:22.180827 2026] [core:notice] [pid 643573:tid 643813] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:22.241641 2026] [security2:error] [pid 643573:tid 643735] [client 47.128.120.38:26752] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.shorewooddaycare.com"] [uri "/robots.txt"] [unique_id "amt_ZvxWyxgRnoFKAJ_afgAAAi0"]
[Thu Jul 30 11:44:22.435748 2026] [security2:error] [pid 643573:tid 643836] [client 43.173.177.44:40016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.177.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2016/03/21/bijoux-en-perles-de-culture-histoire-d-or/"] [unique_id "amt_ZvxWyxgRnoFKAJ_aggAAApI"]
[Thu Jul 30 11:44:22.717142 2026] [security2:error] [pid 643573:tid 643833] [client 43.172.194.179:39530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.194.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/04/04/shopping-13-pieces-chez-zara/"] [unique_id "amt_ZvxWyxgRnoFKAJ_agwAAAo8"]
[Thu Jul 30 11:44:22.874354 2026] [core:notice] [pid 642360:tid 642499] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:22.879628 2026] [security2:error] [pid 642360:tid 642499] [client 43.173.177.197:33636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2016/03/21/bijoux-en-perles-de-culture-histoire-d-or/"] [unique_id "amt_ZpSUkh3e5AhEJOBcSgAAAZg"], referer: https://carnetdeshopping.com/index.php/2016/03/21/bijoux-en-perles-de-culture-histoire-d-or/
[Thu Jul 30 11:44:22.912519 2026] [security2:error] [pid 643573:tid 643812] [client 172.202.44.182:60950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/dropdown.php"] [unique_id "amt_ZvxWyxgRnoFKAJ_aiwAAAno"]
[Thu Jul 30 11:44:23.162400 2026] [security2:error] [pid 643573:tid 643751] [client 143.198.88.13:59236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.88.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tereashops.com"] [uri "/xmlrpc.php"] [unique_id "amt_Z_xWyxgRnoFKAJ_ajwAAAj0"], referer: www.website-d1827c3b.palatov.com/blog//wp-login.php
[Thu Jul 30 11:44:23.439079 2026] [core:notice] [pid 643573:tid 643824] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:23.451498 2026] [security2:error] [pid 643573:tid 643824] [client 43.173.177.222:46074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/04/04/shopping-13-pieces-chez-zara/"] [unique_id "amt_Z_xWyxgRnoFKAJ_amgAAAoY"], referer: https://carnetdeshopping.com/index.php/2014/04/04/shopping-13-pieces-chez-zara/
[Thu Jul 30 11:44:23.873191 2026] [security2:error] [pid 642360:tid 642449] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_Z5SUkh3e5AhEJOBcWQABuVg"]
[Thu Jul 30 11:44:23.873482 2026] [security2:error] [pid 642360:tid 642532] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_Z5SUkh3e5AhEJOBcWQABuVg"]
[Thu Jul 30 11:44:23.919599 2026] [security2:error] [pid 643253:tid 643510] [client 172.202.44.182:22095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/makeasmtp.php"] [unique_id "amt_Z8jqbtjBYzqM1uYj2gAAAH4"]
[Thu Jul 30 11:44:23.933295 2026] [security2:error] [pid 642360:tid 642368] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_Z5SUkh3e5AhEJOBcWgABzgc"]
[Thu Jul 30 11:44:23.933449 2026] [security2:error] [pid 642360:tid 642553] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_Z5SUkh3e5AhEJOBcWgABzgc"]
[Thu Jul 30 11:44:24.214949 2026] [security2:error] [pid 643253:tid 643482] [client 20.215.191.139:48746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/admin.php"] [unique_id "amt_aMjqbtjBYzqM1uYj2wAAAGI"]
[Thu Jul 30 11:44:24.870337 2026] [security2:error] [pid 642360:tid 642610] [client 143.198.88.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amt_Z5SUkh3e5AhEJOBcVwAAAgc"], referer: www.website-d1827c3b.palatov.com/blog//wp-login.php
[Thu Jul 30 11:44:24.949561 2026] [security2:error] [pid 642360:tid 642566] [client 20.215.191.139:48727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/adminfuns.php"] [unique_id "amt_aJSUkh3e5AhEJOBcYgAAAds"]
[Thu Jul 30 11:44:25.104482 2026] [security2:error] [pid 643573:tid 643614] [remote 216.73.216.152:36964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amt_afxWyxgRnoFKAJ_arwACLyE"]
[Thu Jul 30 11:44:25.161651 2026] [security2:error] [pid 643573:tid 643763] [client 74.7.175.155:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jta.nyx.temporary.site"] [uri "/index.php"] [unique_id "amt_ZvxWyxgRnoFKAJ_aiQAAAkk"]
[Thu Jul 30 11:44:25.162409 2026] [security2:error] [pid 643573:tid 643766] [client 74.7.175.155:42312] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jta.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amt_ZvxWyxgRnoFKAJ_ahwACTGQ"]
[Thu Jul 30 11:44:25.258710 2026] [security2:error] [pid 642360:tid 642598] [client 172.236.9.101:14321] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z5SUkh3e5AhEJOBcUQAAAfs"]
[Thu Jul 30 11:44:25.266595 2026] [security2:error] [pid 643573:tid 643710] [client 172.236.9.101:33856] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z_xWyxgRnoFKAJ_akgAAAhQ"]
[Thu Jul 30 11:44:25.271677 2026] [security2:error] [pid 643573:tid 643723] [client 172.236.9.101:23318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z_xWyxgRnoFKAJ_alAAAAiE"]
[Thu Jul 30 11:44:25.289905 2026] [security2:error] [pid 643573:tid 643785] [client 172.236.9.101:38121] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z_xWyxgRnoFKAJ_alwAAAl8"]
[Thu Jul 30 11:44:25.335357 2026] [security2:error] [pid 643573:tid 643828] [client 172.236.9.101:32303] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z_xWyxgRnoFKAJ_algAAAoo"]
[Thu Jul 30 11:44:25.346704 2026] [security2:error] [pid 642360:tid 642589] [client 172.236.9.101:34219] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z5SUkh3e5AhEJOBcUwAAAfI"]
[Thu Jul 30 11:44:25.354050 2026] [security2:error] [pid 643253:tid 643477] [client 172.236.9.101:1423] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z8jqbtjBYzqM1uYj1gAAAF0"]
[Thu Jul 30 11:44:25.357481 2026] [security2:error] [pid 642360:tid 642512] [client 172.202.44.182:60983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/wp-sigunq.php"] [unique_id "amt_aZSUkh3e5AhEJOBcZQAAAaU"]
[Thu Jul 30 11:44:25.363458 2026] [security2:error] [pid 643573:tid 643779] [client 172.236.9.101:24378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z_xWyxgRnoFKAJ_amAAAAlk"]
[Thu Jul 30 11:44:25.431553 2026] [security2:error] [pid 643573:tid 643778] [client 172.236.9.101:51696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z_xWyxgRnoFKAJ_alQAAAlg"]
[Thu Jul 30 11:44:25.449661 2026] [security2:error] [pid 643253:tid 643491] [client 172.236.9.101:11601] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z8jqbtjBYzqM1uYj1AAAAGs"]
[Thu Jul 30 11:44:25.481368 2026] [security2:error] [pid 643573:tid 643834] [client 172.236.9.101:6074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z_xWyxgRnoFKAJ_akwAAApA"]
[Thu Jul 30 11:44:25.486266 2026] [security2:error] [pid 643253:tid 643472] [client 172.236.9.101:48265] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z8jqbtjBYzqM1uYj1QAAAFg"]
[Thu Jul 30 11:44:25.520455 2026] [security2:error] [pid 642360:tid 642603] [client 172.236.9.101:37078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z5SUkh3e5AhEJOBcUgAAAgA"]
[Thu Jul 30 11:44:25.561530 2026] [security2:error] [pid 643573:tid 643738] [client 172.236.9.101:40278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z_xWyxgRnoFKAJ_akQAAAjA"]
[Thu Jul 30 11:44:25.578869 2026] [security2:error] [pid 643573:tid 643721] [client 172.236.9.101:16056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z_xWyxgRnoFKAJ_akAAAAh8"]
[Thu Jul 30 11:44:25.580360 2026] [security2:error] [pid 643253:tid 643443] [client 172.236.9.101:54126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z8jqbtjBYzqM1uYj0wAAADs"]
[Thu Jul 30 11:44:25.596530 2026] [security2:error] [pid 643573:tid 643762] [client 172.236.9.101:6382] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z_xWyxgRnoFKAJ_amQAAAkg"]
[Thu Jul 30 11:44:25.641158 2026] [security2:error] [pid 643253:tid 643402] [client 172.236.9.101:27079] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z8jqbtjBYzqM1uYj2QAAABI"]
[Thu Jul 30 11:44:25.657944 2026] [security2:error] [pid 643253:tid 643493] [client 172.236.9.101:47680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z8jqbtjBYzqM1uYj2AAAAG0"]
[Thu Jul 30 11:44:25.721599 2026] [security2:error] [pid 643253:tid 643459] [client 172.236.9.101:27758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z8jqbtjBYzqM1uYj1wAAAEs"]
[Thu Jul 30 11:44:26.026045 2026] [proxy:error] [pid 643573:tid 643833] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:44:26.026148 2026] [proxy_http:error] [pid 643573:tid 643833] [client 32.194.121.99:53424] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:44:26.027270 2026] [proxy:error] [pid 643573:tid 643833] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:44:26.027329 2026] [proxy_http:error] [pid 643573:tid 643833] [client 32.194.121.99:53424] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:44:26.413496 2026] [security2:error] [pid 643573:tid 643724] [client 172.202.44.182:22351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/wso112233.php"] [unique_id "amt_avxWyxgRnoFKAJ_azAAAAiI"]
[Thu Jul 30 11:44:26.465263 2026] [security2:error] [pid 643573:tid 643720] [client 20.215.191.139:49097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/albin.php"] [unique_id "amt_avxWyxgRnoFKAJ_azgAAAh4"]
[Thu Jul 30 11:44:26.709169 2026] [core:error] [pid 643253:tid 643446] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:26.709197 2026] [core:error] [pid 643253:tid 643446] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:26.712632 2026] [core:error] [pid 643253:tid 643463] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:26.712652 2026] [core:error] [pid 643253:tid 643463] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:26.719457 2026] [security2:error] [pid 643573:tid 643768] [client 143.198.88.13:64237] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amt_afxWyxgRnoFKAJ_avAAAAk4"], referer: www.website-d1827c3b.palatov.com/blog//wp-login.php
[Thu Jul 30 11:44:26.724048 2026] [core:error] [pid 643253:tid 643445] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:26.724067 2026] [core:error] [pid 643253:tid 643445] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:26.748590 2026] [core:error] [pid 643573:tid 643759] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:26.748619 2026] [core:error] [pid 643573:tid 643759] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:26.760733 2026] [core:error] [pid 642360:tid 642514] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:26.760753 2026] [core:error] [pid 642360:tid 642514] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:27.585958 2026] [security2:error] [pid 642360:tid 642550] [client 172.202.44.182:22083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/alfanew.php"] [unique_id "amt_a5SUkh3e5AhEJOBcfwAAAcs"]
[Thu Jul 30 11:44:27.628536 2026] [security2:error] [pid 643573:tid 643765] [client 20.215.191.139:48767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/amfsqvgv.php"] [unique_id "amt_a_xWyxgRnoFKAJ_a6AAAAks"]
[Thu Jul 30 11:44:27.862246 2026] [security2:error] [pid 643573:tid 643767] [client 143.198.88.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amt_avxWyxgRnoFKAJ_a3wAAAk0"], referer: www.website-d1827c3b.palatov.com/blog//wp-login.php
[Thu Jul 30 11:44:28.210969 2026] [security2:error] [pid 643573:tid 643775] [client 20.215.191.139:48735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/ant.php"] [unique_id "amt_bPxWyxgRnoFKAJ_a8wAAAlU"]
[Thu Jul 30 11:44:28.315739 2026] [security2:error] [pid 642360:tid 642611] [client 94.154.43.183:29500] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "saifalkhaleejest.com"] [uri "/.env"] [unique_id "amt_bJSUkh3e5AhEJOBchAAAAgg"]
[Thu Jul 30 11:44:28.613747 2026] [security2:error] [pid 643573:tid 643764] [client 172.202.44.182:60982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/fw.php"] [unique_id "amt_bPxWyxgRnoFKAJ_a9wAAAko"]
[Thu Jul 30 11:44:28.790350 2026] [security2:error] [pid 643573:tid 643741] [client 2a03:2880:f800:2:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lucky-strike-shop.com"] [uri "/index.php"] [unique_id "amt_a_xWyxgRnoFKAJ_a6QACMw0"]
[Thu Jul 30 11:44:29.029089 2026] [security2:error] [pid 643573:tid 643782] [client 20.215.191.139:48946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/appreciators.php"] [unique_id "amt_bfxWyxgRnoFKAJ_a_gAAAlw"]
[Thu Jul 30 11:44:29.436288 2026] [security2:error] [pid 643573:tid 643694] [remote 216.73.216.152:36964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amt_bfxWyxgRnoFKAJ_bAwACd3E"]
[Thu Jul 30 11:44:29.606274 2026] [security2:error] [pid 643573:tid 643789] [client 34.182.188.145:64435] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seven-stars-shop.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amt_bfxWyxgRnoFKAJ_bBwAAAmM"]
[Thu Jul 30 11:44:29.778191 2026] [security2:error] [pid 643573:tid 643778] [client 143.198.88.13:64237] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amt_bPxWyxgRnoFKAJ_a_QAAAlg"], referer: www.website-d1827c3b.palatov.com/blog//wp-login.php
[Thu Jul 30 11:44:29.897813 2026] [security2:error] [pid 643573:tid 643736] [client 143.198.88.13:64237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.88.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tereashops.com"] [uri "/blog//xmlrpc.php"] [unique_id "amt_bfxWyxgRnoFKAJ_bDAAAAi4"]
[Thu Jul 30 11:44:29.897966 2026] [security2:error] [pid 643573:tid 643736] [client 143.198.88.13:64237] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tereashops.com"] [uri "/blog//xmlrpc.php"] [unique_id "amt_bfxWyxgRnoFKAJ_bDAAAAi4"]
[Thu Jul 30 11:44:30.388002 2026] [security2:error] [pid 643573:tid 643815] [client 143.198.88.13:53819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.88.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tereashops.com"] [uri "/blog//wp-login.php"] [unique_id "amt_bvxWyxgRnoFKAJ_bFAAAAn0"], referer: https://tereashops.com//blog//wp-login.php
[Thu Jul 30 11:44:30.578623 2026] [security2:error] [pid 643573:tid 643752] [client 34.182.188.145:64874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.188.182.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_bvxWyxgRnoFKAJ_bFQAAAj4"]
[Thu Jul 30 11:44:30.598925 2026] [security2:error] [pid 643573:tid 643795] [client 176.241.66.87:50715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_bvxWyxgRnoFKAJ_bFgAAAmk"]
[Thu Jul 30 11:44:30.599090 2026] [security2:error] [pid 643573:tid 643795] [client 176.241.66.87:50715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_bvxWyxgRnoFKAJ_bFgAAAmk"]
[Thu Jul 30 11:44:30.681353 2026] [security2:error] [pid 643573:tid 643714] [client 20.215.191.139:64287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/archive.php"] [unique_id "amt_bvxWyxgRnoFKAJ_bFwAAAhg"]
[Thu Jul 30 11:44:30.735605 2026] [security2:error] [pid 643573:tid 643700] [remote 57.141.0.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amt_bvxWyxgRnoFKAJ_bGAACenc"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=nylon,plastic,polyester,silicon,steel,wood&filter_size=large&filter_brand=desigual&unfilter=1
[Thu Jul 30 11:44:31.082782 2026] [security2:error] [pid 643573:tid 643692] [remote 52.167.144.18:13612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/jurnaltuturan/article/download/8922/3577"] [unique_id "amt_bvxWyxgRnoFKAJ_bGgACIW8"]
[Thu Jul 30 11:44:31.251697 2026] [security2:error] [pid 643573:tid 643699] [remote 57.141.0.11:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amt_b_xWyxgRnoFKAJ_bHQACKXY"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=nylon,plastic,polyester,silicon,steel,wood&filter_size=large&filter_brand=desigual&unfilter=1
[Thu Jul 30 11:44:33.112337 2026] [security2:error] [pid 643573:tid 643832] [client 143.198.88.13:64040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.88.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.website-dc09cfb9.jud.zzt.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amt_cfxWyxgRnoFKAJ_bKgAAAo4"], referer: https://www.website-d7a8aca5.vwn.lxf.temporary.site//blog//wp-login.php
[Thu Jul 30 11:44:33.244988 2026] [security2:error] [pid 642360:tid 642564] [client 2a03:2880:f800:3b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_b5SUkh3e5AhEJOBcowAB2XY"]
[Thu Jul 30 11:44:33.499686 2026] [security2:error] [pid 643573:tid 643714] [client 20.91.199.21:12259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/geju.php"] [unique_id "amt_cfxWyxgRnoFKAJ_bMgAAAhg"]
[Thu Jul 30 11:44:33.808403 2026] [core:error] [pid 643253:tid 643486] [client 143.198.88.13:60072] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.website-d7a8aca5.vwn.lxf.temporary.site//blog//wp-login.php
[Thu Jul 30 11:44:33.808429 2026] [core:error] [pid 643253:tid 643486] [client 143.198.88.13:60072] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.website-d7a8aca5.vwn.lxf.temporary.site//blog//wp-login.php
[Thu Jul 30 11:44:34.031645 2026] [core:error] [pid 642360:tid 642616] [client 143.198.88.13:58281] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.website-d7a8aca5.vwn.lxf.temporary.site//blog//wp-login.php
[Thu Jul 30 11:44:34.031675 2026] [core:error] [pid 642360:tid 642616] [client 143.198.88.13:58281] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.website-d7a8aca5.vwn.lxf.temporary.site//blog//wp-login.php
[Thu Jul 30 11:44:34.278438 2026] [core:error] [pid 643573:tid 643789] [client 143.198.88.13:58431] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.website-d7a8aca5.vwn.lxf.temporary.site//blog//wp-login.php
[Thu Jul 30 11:44:34.278461 2026] [core:error] [pid 643573:tid 643789] [client 143.198.88.13:58431] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.website-d7a8aca5.vwn.lxf.temporary.site//blog//wp-login.php
[Thu Jul 30 11:44:34.331991 2026] [security2:error] [pid 643573:tid 643732] [client 57.141.0.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_cfxWyxgRnoFKAJ_bNQAAAio"]
[Thu Jul 30 11:44:34.437405 2026] [security2:error] [pid 643573:tid 643698] [remote 216.73.216.152:36964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amt_cvxWyxgRnoFKAJ_bQAACcHU"]
[Thu Jul 30 11:44:34.482614 2026] [core:error] [pid 643573:tid 643796] [client 143.198.88.13:62841] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.website-d7a8aca5.vwn.lxf.temporary.site//blog//wp-login.php
[Thu Jul 30 11:44:34.482637 2026] [core:error] [pid 643573:tid 643796] [client 143.198.88.13:62841] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.website-d7a8aca5.vwn.lxf.temporary.site//blog//wp-login.php
[Thu Jul 30 11:44:34.509139 2026] [security2:error] [pid 643573:tid 643708] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_cvxWyxgRnoFKAJ_bQgACN38"]
[Thu Jul 30 11:44:34.509348 2026] [security2:error] [pid 643573:tid 643745] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_cvxWyxgRnoFKAJ_bQgACN38"]
[Thu Jul 30 11:44:34.757956 2026] [security2:error] [pid 643573:tid 643707] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_cvxWyxgRnoFKAJ_bQwACLH4"]
[Thu Jul 30 11:44:34.758122 2026] [security2:error] [pid 643573:tid 643734] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_cvxWyxgRnoFKAJ_bQwACLH4"]
[Thu Jul 30 11:44:35.638102 2026] [security2:error] [pid 643573:tid 643649] [remote 40.77.167.247:36904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/edunomic/article/download/9127/3948"] [unique_id "amt_c_xWyxgRnoFKAJ_bUgACe0Q"]
[Thu Jul 30 11:44:36.203459 2026] [security2:error] [pid 642360:tid 642609] [client 172.202.44.182:22080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/wp-login.php"] [unique_id "amt_c5SUkh3e5AhEJOBcuwAAAgY"]
[Thu Jul 30 11:44:36.658618 2026] [security2:error] [pid 643573:tid 643740] [client 34.182.188.145:55256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.188.182.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_dPxWyxgRnoFKAJ_bWwAAAjI"]
[Thu Jul 30 11:44:36.658729 2026] [security2:error] [pid 643573:tid 643740] [client 34.182.188.145:55256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_dPxWyxgRnoFKAJ_bWwAAAjI"]
[Thu Jul 30 11:44:36.666053 2026] [core:notice] [pid 643573:tid 643792] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:36.780123 2026] [security2:error] [pid 643253:tid 643489] [client 20.91.199.21:14998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/plugins/about.php"] [unique_id "amt_dMjqbtjBYzqM1uYj7AAAAGk"]
[Thu Jul 30 11:44:36.796025 2026] [security2:error] [pid 643253:tid 643401] [client 143.198.88.13:64154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.88.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_dMjqbtjBYzqM1uYj7QAAABE"], referer: www.website-dbe2688a.snappyhomeoffers.com/blog//wp-login.php
[Thu Jul 30 11:44:37.168825 2026] [security2:error] [pid 643573:tid 643765] [client 172.202.44.182:61014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/simple.php"] [unique_id "amt_dfxWyxgRnoFKAJ_bYAAAAks"]
[Thu Jul 30 11:44:38.003468 2026] [security2:error] [pid 643253:tid 643400] [client 172.202.44.182:47244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/classsmtps.php"] [unique_id "amt_dsjqbtjBYzqM1uYj8AAAABA"]
[Thu Jul 30 11:44:38.155055 2026] [security2:error] [pid 643573:tid 643751] [client 143.198.88.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amt_dfxWyxgRnoFKAJ_bYgAAAj0"], referer: www.website-dbe2688a.snappyhomeoffers.com/blog//wp-login.php
[Thu Jul 30 11:44:38.424696 2026] [security2:error] [pid 643573:tid 643734] [client 2a03:2880:f800:34:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_dfxWyxgRnoFKAJ_bXwACLAg"]
[Thu Jul 30 11:44:38.449630 2026] [security2:error] [pid 643573:tid 643585] [remote 57.141.0.12:21084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amt_dvxWyxgRnoFKAJ_bcgACIQQ"]
[Thu Jul 30 11:44:38.577200 2026] [core:error] [pid 643253:tid 643458] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:38.577225 2026] [core:error] [pid 643253:tid 643458] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:38.585131 2026] [core:error] [pid 643573:tid 643725] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:38.585165 2026] [core:error] [pid 643573:tid 643725] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:38.595201 2026] [core:error] [pid 643253:tid 643431] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:38.595232 2026] [core:error] [pid 643253:tid 643431] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:38.596238 2026] [core:error] [pid 643253:tid 643418] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:38.596262 2026] [core:error] [pid 643253:tid 643418] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:38.597163 2026] [core:error] [pid 643253:tid 643395] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:38.597184 2026] [core:error] [pid 643253:tid 643395] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:38.629730 2026] [security2:error] [pid 643573:tid 643745] [client 2a03:2880:f800:28:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_dfxWyxgRnoFKAJ_bYwACN3w"]
[Thu Jul 30 11:44:38.838213 2026] [security2:error] [pid 643573:tid 643768] [client 20.91.199.21:45286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp.php"] [unique_id "amt_dvxWyxgRnoFKAJ_biAAAAk4"]
[Thu Jul 30 11:44:39.250701 2026] [security2:error] [pid 643573:tid 643796] [client 172.202.44.182:60935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/wp-blog-header.php"] [unique_id "amt_d_xWyxgRnoFKAJ_bkAAAAmo"]
[Thu Jul 30 11:44:39.439290 2026] [security2:error] [pid 643573:tid 643605] [remote 216.73.216.152:36964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amt_d_xWyxgRnoFKAJ_bkQACexg"]
[Thu Jul 30 11:44:39.717855 2026] [proxy:error] [pid 643573:tid 643743] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:44:39.717958 2026] [proxy_http:error] [pid 643573:tid 643743] [client 32.194.121.99:2406] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:44:39.718757 2026] [security2:error] [pid 642360:tid 642617] [client 143.198.88.13:60799] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amt_dpSUkh3e5AhEJOBczAAAAg4"], referer: www.website-dbe2688a.snappyhomeoffers.com/blog//wp-login.php
[Thu Jul 30 11:44:39.718834 2026] [proxy:error] [pid 643573:tid 643743] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:44:39.718893 2026] [proxy_http:error] [pid 643573:tid 643743] [client 32.194.121.99:2406] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:44:39.724306 2026] [proxy:error] [pid 643573:tid 643797] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:44:39.724369 2026] [proxy_http:error] [pid 643573:tid 643797] [client 34.224.175.62:47937] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:44:39.724920 2026] [proxy:error] [pid 643573:tid 643797] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:44:39.724963 2026] [proxy_http:error] [pid 643573:tid 643797] [client 34.224.175.62:47937] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:44:39.800311 2026] [security2:error] [pid 643253:tid 643511] [client 20.91.199.21:45482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/aaa.php"] [unique_id "amt_d8jqbtjBYzqM1uYj_AAAAH8"]
[Thu Jul 30 11:44:40.469486 2026] [security2:error] [pid 643253:tid 643429] [client 172.202.44.182:22338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/wp-trackback.php"] [unique_id "amt_eMjqbtjBYzqM1uYj_gAAAC0"]
[Thu Jul 30 11:44:40.537925 2026] [security2:error] [pid 643573:tid 643715] [client 2a03:2880:f800:1b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_d_xWyxgRnoFKAJ_bigACGUg"]
[Thu Jul 30 11:44:40.640541 2026] [security2:error] [pid 643253:tid 643416] [client 20.91.199.21:3998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/hoot.php"] [unique_id "amt_eMjqbtjBYzqM1uYj_wAAACA"]
[Thu Jul 30 11:44:40.773737 2026] [security2:error] [pid 643253:tid 643465] [client 143.198.88.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amt_d8jqbtjBYzqM1uYj_QAAAFE"], referer: www.website-dbe2688a.snappyhomeoffers.com/blog//wp-login.php
[Thu Jul 30 11:44:41.207216 2026] [security2:error] [pid 643573:tid 643770] [client 176.241.66.87:51419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_efxWyxgRnoFKAJ_brAAAAlA"]
[Thu Jul 30 11:44:41.207402 2026] [security2:error] [pid 643573:tid 643770] [client 176.241.66.87:51419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_efxWyxgRnoFKAJ_brAAAAlA"]
[Thu Jul 30 11:44:41.470670 2026] [security2:error] [pid 643573:tid 643736] [client 20.91.199.21:3968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/about.php"] [unique_id "amt_efxWyxgRnoFKAJ_brwAAAi4"]
[Thu Jul 30 11:44:41.940284 2026] [security2:error] [pid 643573:tid 643719] [client 20.215.191.139:64272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/as.php"] [unique_id "amt_efxWyxgRnoFKAJ_bsgAAAh0"]
[Thu Jul 30 11:44:42.218352 2026] [security2:error] [pid 643573:tid 643780] [client 172.202.44.182:60953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/wp-signup.php"] [unique_id "amt_evxWyxgRnoFKAJ_bswAAAlo"]
[Thu Jul 30 11:44:42.246510 2026] [security2:error] [pid 643253:tid 643481] [client 172.236.9.101:9601] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/privatekey.key"] [unique_id "amt_esjqbtjBYzqM1uYkAgAAAGE"]
[Thu Jul 30 11:44:42.274579 2026] [security2:error] [pid 643573:tid 643735] [client 20.91.199.21:5698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/admin.php"] [unique_id "amt_evxWyxgRnoFKAJ_buAAAAi0"]
[Thu Jul 30 11:44:42.291706 2026] [security2:error] [pid 643573:tid 643822] [client 172.236.9.101:64365] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/id_dsa"] [unique_id "amt_evxWyxgRnoFKAJ_buQAAAoQ"]
[Thu Jul 30 11:44:42.292165 2026] [security2:error] [pid 642360:tid 642563] [client 172.236.9.101:9638] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/key.pem"] [unique_id "amt_epSUkh3e5AhEJOBc6wAAAdg"]
[Thu Jul 30 11:44:42.294821 2026] [security2:error] [pid 642360:tid 642578] [client 172.236.9.101:59518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/id_rsa"] [unique_id "amt_epSUkh3e5AhEJOBc7AAAAec"]
[Thu Jul 30 11:44:42.410036 2026] [security2:error] [pid 642360:tid 642534] [client 143.198.88.13:60799] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amt_eZSUkh3e5AhEJOBc4AAAAbs"], referer: www.website-dbe2688a.snappyhomeoffers.com/blog//wp-login.php
[Thu Jul 30 11:44:42.489331 2026] [security2:error] [pid 642360:tid 642591] [client 143.198.88.13:60799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.88.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/blog//xmlrpc.php"] [unique_id "amt_epSUkh3e5AhEJOBc7gAAAfQ"]
[Thu Jul 30 11:44:42.489538 2026] [security2:error] [pid 642360:tid 642591] [client 143.198.88.13:60799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kool-shop.com"] [uri "/blog//xmlrpc.php"] [unique_id "amt_epSUkh3e5AhEJOBc7gAAAfQ"]
[Thu Jul 30 11:44:42.858091 2026] [security2:error] [pid 643573:tid 643712] [client 143.198.88.13:64839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.88.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/blog//wp-login.php"] [unique_id "amt_evxWyxgRnoFKAJ_bwgAAAhY"], referer: https://kool-shop.com//blog//wp-login.php
[Thu Jul 30 11:44:42.930518 2026] [security2:error] [pid 642360:tid 642587] [client 172.236.9.101:61473] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_epSUkh3e5AhEJOBc5QAAAfA"]
[Thu Jul 30 11:44:42.936251 2026] [security2:error] [pid 643573:tid 643743] [client 172.236.9.101:45935] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_evxWyxgRnoFKAJ_btgAAAjU"]
[Thu Jul 30 11:44:42.941733 2026] [security2:error] [pid 643573:tid 643774] [client 172.236.9.101:11996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_evxWyxgRnoFKAJ_buwAAAlQ"]
[Thu Jul 30 11:44:42.949070 2026] [security2:error] [pid 643253:tid 643387] [client 172.236.9.101:63630] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_esjqbtjBYzqM1uYkAwAAAAM"]
[Thu Jul 30 11:44:42.963243 2026] [security2:error] [pid 642360:tid 642529] [client 172.236.9.101:41134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_epSUkh3e5AhEJOBc5gAAAbY"]
[Thu Jul 30 11:44:42.982659 2026] [security2:error] [pid 643573:tid 643754] [client 172.236.9.101:47520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_evxWyxgRnoFKAJ_btwAAAkA"]
[Thu Jul 30 11:44:42.983946 2026] [security2:error] [pid 643573:tid 643756] [client 172.236.9.101:47985] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_evxWyxgRnoFKAJ_bugAAAkI"]
[Thu Jul 30 11:44:42.986781 2026] [security2:error] [pid 642360:tid 642615] [client 172.236.9.101:6338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_epSUkh3e5AhEJOBc6AAAAgw"]
[Thu Jul 30 11:44:43.088396 2026] [security2:error] [pid 642360:tid 642536] [client 172.202.44.182:22107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/wp-comments-post.php"] [unique_id "amt_e5SUkh3e5AhEJOBc8gAAAb0"]
[Thu Jul 30 11:44:43.265439 2026] [security2:error] [pid 643573:tid 643753] [client 57.141.0.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_evxWyxgRnoFKAJ_bvwAAAj8"]
[Thu Jul 30 11:44:43.277307 2026] [security2:error] [pid 642360:tid 642508] [client 172.236.9.101:32444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.ssh/id_dsa"] [unique_id "amt_e5SUkh3e5AhEJOBc9AAAAaE"]
[Thu Jul 30 11:44:43.277334 2026] [security2:error] [pid 643573:tid 643724] [client 172.236.9.101:14087] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.ssh/id_rsa"] [unique_id "amt_e_xWyxgRnoFKAJ_bygAAAiI"]
[Thu Jul 30 11:44:43.674809 2026] [core:error] [pid 643573:tid 643609] [remote 94.154.43.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:43.674844 2026] [core:error] [pid 643573:tid 643609] [remote 94.154.43.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:43.708517 2026] [core:error] [pid 642360:tid 642412] [remote 94.154.43.187:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:43.708564 2026] [core:error] [pid 642360:tid 642412] [remote 94.154.43.187:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:43.783919 2026] [security2:error] [pid 643573:tid 643715] [client 172.236.9.101:46297] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_e_xWyxgRnoFKAJ_bxwAAAhk"]
[Thu Jul 30 11:44:43.796669 2026] [security2:error] [pid 642360:tid 642571] [client 172.236.9.101:64113] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_e5SUkh3e5AhEJOBc9gAAAeA"]
[Thu Jul 30 11:44:43.813098 2026] [security2:error] [pid 643573:tid 643744] [client 172.236.9.101:18374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_e_xWyxgRnoFKAJ_byQAAAjY"]
[Thu Jul 30 11:44:43.818268 2026] [security2:error] [pid 642360:tid 642570] [client 172.236.9.101:33813] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_e5SUkh3e5AhEJOBc9QAAAd8"]
[Thu Jul 30 11:44:43.829054 2026] [security2:error] [pid 643573:tid 643817] [client 172.236.9.101:22024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_e_xWyxgRnoFKAJ_bxgAAAn8"]
[Thu Jul 30 11:44:43.841780 2026] [security2:error] [pid 643573:tid 643788] [client 172.236.9.101:60034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_e_xWyxgRnoFKAJ_bywAAAmI"]
[Thu Jul 30 11:44:44.219847 2026] [security2:error] [pid 643573:tid 643710] [client 172.202.44.182:61023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/wp-mail.php"] [unique_id "amt_fPxWyxgRnoFKAJ_b1AAAAhQ"]
[Thu Jul 30 11:44:45.071996 2026] [security2:error] [pid 643573:tid 643608] [remote 216.73.216.152:20905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amt_ffxWyxgRnoFKAJ_b2gACUhs"]
[Thu Jul 30 11:44:45.106578 2026] [security2:error] [pid 642360:tid 642514] [client 2a03:2880:f800:3:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "spececigarette.com"] [uri "/wp-login.php"] [unique_id "amt_fJSUkh3e5AhEJOBdBgABpzs"]
[Thu Jul 30 11:44:45.214351 2026] [security2:error] [pid 642360:tid 642406] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_fZSUkh3e5AhEJOBdCwACBi0"]
[Thu Jul 30 11:44:45.214531 2026] [security2:error] [pid 642360:tid 642609] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_fZSUkh3e5AhEJOBdCwACBi0"]
[Thu Jul 30 11:44:45.261241 2026] [security2:error] [pid 643573:tid 643757] [client 172.202.44.182:60959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/wp-activate.php"] [unique_id "amt_ffxWyxgRnoFKAJ_b2wAAAkM"]
[Thu Jul 30 11:44:45.574133 2026] [security2:error] [pid 643573:tid 643588] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_ffxWyxgRnoFKAJ_b4AACMgc"]
[Thu Jul 30 11:44:45.574265 2026] [security2:error] [pid 643573:tid 643740] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_ffxWyxgRnoFKAJ_b4AACMgc"]
[Thu Jul 30 11:44:46.237680 2026] [security2:error] [pid 642360:tid 642415] [remote 47.128.125.43:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "fantasynamelist.com"] [uri "/robots.txt"] [unique_id "amt_fpSUkh3e5AhEJOBdEQAB4TY"]
[Thu Jul 30 11:44:46.538566 2026] [security2:error] [pid 643253:tid 643434] [client 20.215.191.139:63956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/atomlib.php"] [unique_id "amt_fsjqbtjBYzqM1uYkHAAAADI"]
[Thu Jul 30 11:44:46.562931 2026] [security2:error] [pid 643573:tid 643725] [client 2a03:2880:f800:29:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_ffxWyxgRnoFKAJ_b3AACIwI"]
[Thu Jul 30 11:44:47.098214 2026] [security2:error] [pid 643573:tid 643801] [client 172.202.44.182:22120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/post.php"] [unique_id "amt_f_xWyxgRnoFKAJ_b7QAAAm8"]
[Thu Jul 30 11:44:47.422399 2026] [security2:error] [pid 643573:tid 643755] [client 20.91.199.21:18122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/plugins/admin.php"] [unique_id "amt_f_xWyxgRnoFKAJ_b8gAAAkE"]
[Thu Jul 30 11:44:47.436834 2026] [security2:error] [pid 643573:tid 643793] [client 20.215.191.139:64326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/autoload_classmap.php"] [unique_id "amt_f_xWyxgRnoFKAJ_b8wAAAmc"]
[Thu Jul 30 11:44:48.078231 2026] [security2:error] [pid 643573:tid 643753] [client 20.91.199.21:15037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/db-cache.php"] [unique_id "amt_gPxWyxgRnoFKAJ_b-wAAAj8"]
[Thu Jul 30 11:44:48.657414 2026] [security2:error] [pid 643573:tid 643761] [client 172.202.44.182:61032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/wp-2019.php"] [unique_id "amt_gPxWyxgRnoFKAJ_cAwAAAkc"]
[Thu Jul 30 11:44:48.916320 2026] [security2:error] [pid 643573:tid 643817] [client 20.91.199.21:13846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/themes/twentyeleven/functions.php"] [unique_id "amt_gPxWyxgRnoFKAJ_cBgAAAn8"]
[Thu Jul 30 11:44:48.917294 2026] [security2:error] [pid 643573:tid 643813] [client 20.215.191.139:64355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/bb.php"] [unique_id "amt_gPxWyxgRnoFKAJ_cBwAAAns"]
[Thu Jul 30 11:44:49.277713 2026] [security2:error] [pid 643253:tid 643494] [client 220.124.216.164:44476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/wp-login.php"] [unique_id "amt_gMjqbtjBYzqM1uYkHQAAAG4"]
[Thu Jul 30 11:44:49.449145 2026] [security2:error] [pid 643573:tid 643626] [remote 216.73.216.152:20905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amt_gfxWyxgRnoFKAJ_cDgACcS0"]
[Thu Jul 30 11:44:49.607750 2026] [security2:error] [pid 643573:tid 643784] [client 20.215.191.139:48338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/bnm.php"] [unique_id "amt_gfxWyxgRnoFKAJ_cEgAAAl4"]
[Thu Jul 30 11:44:49.764576 2026] [security2:error] [pid 643573:tid 643772] [client 44.248.244.184:38574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.shorewooddaycare.com"] [uri "/"] [unique_id "amt_gfxWyxgRnoFKAJ_cFgAAAlI"]
[Thu Jul 30 11:44:50.290475 2026] [security2:error] [pid 643573:tid 643827] [client 172.202.44.182:60980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/hoot.php"] [unique_id "amt_gvxWyxgRnoFKAJ_cHAAAAok"]
[Thu Jul 30 11:44:50.340273 2026] [security2:error] [pid 643573:tid 643837] [client 20.215.191.139:64329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/bootstrap.php"] [unique_id "amt_gvxWyxgRnoFKAJ_cHQAAApM"]
[Thu Jul 30 11:44:50.539328 2026] [security2:error] [pid 643573:tid 643820] [client 44.248.244.184:35936] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.shorewooddaycare.com"] [uri "/index.html"] [unique_id "amt_gvxWyxgRnoFKAJ_cHwAAAoI"], referer: http://www.shorewooddaycare.com/
[Thu Jul 30 11:44:50.986080 2026] [security2:error] [pid 642360:tid 642604] [client 20.215.191.139:63941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/buy.php"] [unique_id "amt_gpSUkh3e5AhEJOBdLQAAAgE"]
[Thu Jul 30 11:44:51.350456 2026] [security2:error] [pid 643573:tid 643729] [client 172.202.44.182:61050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/log.php"] [unique_id "amt_g_xWyxgRnoFKAJ_cJwAAAic"]
[Thu Jul 30 11:44:51.359281 2026] [security2:error] [pid 643573:tid 643749] [client 2a03:2880:f800:17:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_gfxWyxgRnoFKAJ_cFwACOyM"]
[Thu Jul 30 11:44:51.455783 2026] [security2:error] [pid 643573:tid 643710] [client 82.181.86.116:57276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/wp-login.php"] [unique_id "amt_gvxWyxgRnoFKAJ_cHgAAAlM"]
[Thu Jul 30 11:44:51.525884 2026] [security2:error] [pid 643253:tid 643409] [client 213.152.161.25:46194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amt_g8jqbtjBYzqM1uYkHgAAABk"]
[Thu Jul 30 11:44:51.526030 2026] [security2:error] [pid 643253:tid 643409] [client 213.152.161.25:46194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amt_g8jqbtjBYzqM1uYkHgAAABk"]
[Thu Jul 30 11:44:51.601096 2026] [security2:error] [pid 643573:tid 643817] [client 118.193.33.19:55498] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "sh00085.hostgator.com"] [uri "/index.cgi"] [unique_id "amt_g_xWyxgRnoFKAJ_cJAAAAn8"]
[Thu Jul 30 11:44:51.761686 2026] [security2:error] [pid 642360:tid 642563] [client 20.91.199.21:45408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/themes/oceanwp/functions.php"] [unique_id "amt_g5SUkh3e5AhEJOBdNAAAAdg"]
[Thu Jul 30 11:44:51.854288 2026] [security2:error] [pid 643573:tid 643738] [client 176.241.66.87:52192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_g_xWyxgRnoFKAJ_cKgAAAjA"]
[Thu Jul 30 11:44:51.854390 2026] [security2:error] [pid 643573:tid 643738] [client 176.241.66.87:52192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_g_xWyxgRnoFKAJ_cKgAAAjA"]
[Thu Jul 30 11:44:52.081126 2026] [fcgid:warn] [pid 642360:tid 642587] (70014)End of file found: [client 118.193.33.19:59062] mod_fcgid: can't get data from http client
[Thu Jul 30 11:44:52.303252 2026] [fcgid:warn] [pid 642360:tid 642554] (70014)End of file found: [client 118.193.33.19:59092] mod_fcgid: can't get data from http client
[Thu Jul 30 11:44:52.532922 2026] [fcgid:warn] [pid 643573:tid 643734] (70014)End of file found: [client 118.193.33.19:59146] mod_fcgid: can't get data from http client
[Thu Jul 30 11:44:53.333345 2026] [security2:error] [pid 643253:tid 643473] [client 172.202.44.182:60960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/bak.php"] [unique_id "amt_hcjqbtjBYzqM1uYkKAAAAFk"]
[Thu Jul 30 11:44:53.374463 2026] [core:error] [pid 643253:tid 643468] [client 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:53.374486 2026] [core:error] [pid 643253:tid 643468] [client 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:53.413882 2026] [core:error] [pid 643573:tid 643811] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:53.413901 2026] [core:error] [pid 643573:tid 643811] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:53.425571 2026] [core:error] [pid 643573:tid 643798] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:53.425595 2026] [core:error] [pid 643573:tid 643798] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:53.441840 2026] [core:error] [pid 642360:tid 642603] [client 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:53.441858 2026] [core:error] [pid 642360:tid 642603] [client 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:53.442821 2026] [core:error] [pid 643573:tid 643788] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:53.442836 2026] [core:error] [pid 643573:tid 643788] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:53.479844 2026] [security2:error] [pid 643573:tid 643781] [client 179.43.134.114:42010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.134.43.179.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrecoveryserviceabudhabillc.site"] [uri "/wp-login.php"] [unique_id "amt_hfxWyxgRnoFKAJ_cMQAAAls"]
[Thu Jul 30 11:44:53.803559 2026] [security2:error] [pid 643573:tid 643768] [client 20.91.199.21:11660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/themes/twentythirteen/functions.php"] [unique_id "amt_hfxWyxgRnoFKAJ_cQQAAAk4"]
[Thu Jul 30 11:44:54.074394 2026] [security2:error] [pid 643573:tid 643801] [client 20.215.191.139:64283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/chosen.php"] [unique_id "amt_hvxWyxgRnoFKAJ_cRwAAAm8"]
[Thu Jul 30 11:44:54.269759 2026] [core:error] [pid 642360:tid 642612] [client 179.43.134.114:42020] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:54.269786 2026] [core:error] [pid 642360:tid 642612] [client 179.43.134.114:42020] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:54.344634 2026] [security2:error] [pid 643573:tid 643822] [client 59.0.218.253:34118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/wp-login.php"] [unique_id "amt_hfxWyxgRnoFKAJ_cQAAAAi4"]
[Thu Jul 30 11:44:54.448919 2026] [security2:error] [pid 643573:tid 643630] [remote 216.73.216.152:20905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amt_hvxWyxgRnoFKAJ_cTQACYDE"]
[Thu Jul 30 11:44:54.948078 2026] [security2:error] [pid 642360:tid 642584] [client 20.215.191.139:64373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/class-wp-image.php"] [unique_id "amt_hpSUkh3e5AhEJOBdUwAAAe0"]
[Thu Jul 30 11:44:55.789930 2026] [security2:error] [pid 643573:tid 643744] [client 20.215.191.139:48325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/classsmtps.php"] [unique_id "amt_h_xWyxgRnoFKAJ_cXAAAAjY"]
[Thu Jul 30 11:44:55.828332 2026] [security2:error] [pid 642360:tid 642380] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_h5SUkh3e5AhEJOBdVwABvxM"]
[Thu Jul 30 11:44:55.828555 2026] [security2:error] [pid 642360:tid 642538] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_h5SUkh3e5AhEJOBdVwABvxM"]
[Thu Jul 30 11:44:56.282802 2026] [security2:error] [pid 643253:tid 643392] [client 57.141.0.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_h8jqbtjBYzqM1uYkLgAAAAg"]
[Thu Jul 30 11:44:56.379584 2026] [security2:error] [pid 643573:tid 643769] [client 20.91.199.21:45511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/themes/kadence/functions.php"] [unique_id "amt_iPxWyxgRnoFKAJ_cYAAAAk8"]
[Thu Jul 30 11:44:56.484062 2026] [security2:error] [pid 643573:tid 643721] [client 20.215.191.139:63953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/classwithtostring.php"] [unique_id "amt_iPxWyxgRnoFKAJ_cYQAAAh8"]
[Thu Jul 30 11:44:56.519854 2026] [security2:error] [pid 643573:tid 643643] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_iPxWyxgRnoFKAJ_cZAACHT4"]
[Thu Jul 30 11:44:56.520045 2026] [security2:error] [pid 643573:tid 643719] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_iPxWyxgRnoFKAJ_cZAACHT4"]
[Thu Jul 30 11:44:56.540581 2026] [security2:error] [pid 643573:tid 643817] [client 85.240.122.127:34716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/wp-login.php"] [unique_id "amt_h_xWyxgRnoFKAJ_cWgAAAmw"]
[Thu Jul 30 11:44:56.945478 2026] [proxy:error] [pid 643573:tid 643749] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:44:56.945529 2026] [proxy_http:error] [pid 643573:tid 643749] [client 195.96.139.95:51419] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:44:56.946094 2026] [proxy:error] [pid 643573:tid 643749] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:44:56.946139 2026] [proxy_http:error] [pid 643573:tid 643749] [client 195.96.139.95:51419] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:44:58.076740 2026] [security2:error] [pid 643573:tid 643765] [client 114.119.132.101:46849] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "deltaedu.net"] [uri "/low-tution-fee"] [unique_id "amt_ivxWyxgRnoFKAJ_ccgAAAks"], referer: https://deltaedu.net/
[Thu Jul 30 11:44:58.359199 2026] [security2:error] [pid 643573:tid 643811] [client 172.236.9.101:30107] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/backup.sql"] [unique_id "amt_ivxWyxgRnoFKAJ_cdQAAAnk"]
[Thu Jul 30 11:44:58.361148 2026] [security2:error] [pid 642360:tid 642562] [client 172.236.9.101:56461] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/dump.sql"] [unique_id "amt_ipSUkh3e5AhEJOBdbQAAAdc"]
[Thu Jul 30 11:44:58.368246 2026] [security2:error] [pid 642360:tid 642577] [client 172.236.9.101:52720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/alseermarine.com:443.sql"] [unique_id "amt_ipSUkh3e5AhEJOBdbgAAAeY"]
[Thu Jul 30 11:44:58.368727 2026] [security2:error] [pid 642360:tid 642579] [client 172.236.9.101:38920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/backups/database.sql"] [unique_id "amt_ipSUkh3e5AhEJOBdbwAAAeg"]
[Thu Jul 30 11:44:58.375103 2026] [security2:error] [pid 643573:tid 643770] [client 172.236.9.101:7701] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/database.sql"] [unique_id "amt_ivxWyxgRnoFKAJ_cdgAAAlA"]
[Thu Jul 30 11:44:58.377639 2026] [security2:error] [pid 643573:tid 643785] [client 172.236.9.101:50002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/mysql.sql"] [unique_id "amt_ivxWyxgRnoFKAJ_cdwAAAl8"]
[Thu Jul 30 11:44:58.384571 2026] [security2:error] [pid 643573:tid 643714] [client 172.236.9.101:55161] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/alseermarine.com:443.sql"] [unique_id "amt_ivxWyxgRnoFKAJ_ceAAAAhg"]
[Thu Jul 30 11:44:58.404415 2026] [security2:error] [pid 642360:tid 642533] [client 172.236.9.101:57424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/wp-content/database.sql"] [unique_id "amt_ipSUkh3e5AhEJOBdcQAAAbo"]
[Thu Jul 30 11:44:58.404416 2026] [security2:error] [pid 642360:tid 642614] [client 172.236.9.101:30781] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/database.sql"] [unique_id "amt_ipSUkh3e5AhEJOBdcAAAAgs"]
[Thu Jul 30 11:44:58.404796 2026] [security2:error] [pid 643573:tid 643790] [client 172.236.9.101:17610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/backup.sql"] [unique_id "amt_ivxWyxgRnoFKAJ_ceQAAAmQ"]
[Thu Jul 30 11:44:58.430401 2026] [security2:error] [pid 643573:tid 643799] [client 172.236.9.101:41969] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/db.sql"] [unique_id "amt_ivxWyxgRnoFKAJ_cegAAAm0"]
[Thu Jul 30 11:44:58.430491 2026] [security2:error] [pid 643573:tid 643761] [client 172.236.9.101:34940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/dump.sql"] [unique_id "amt_ivxWyxgRnoFKAJ_cewAAAkc"]
[Thu Jul 30 11:44:58.628567 2026] [security2:error] [pid 642360:tid 642593] [client 20.91.199.21:45673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/themes/twentytwenty/functions.php"] [unique_id "amt_ipSUkh3e5AhEJOBddAAAAfY"]
[Thu Jul 30 11:44:58.797785 2026] [security2:error] [pid 643573:tid 643782] [client 172.202.44.182:61013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/content.php"] [unique_id "amt_ivxWyxgRnoFKAJ_cfwAAAlw"]
[Thu Jul 30 11:44:59.876716 2026] [security2:error] [pid 643573:tid 643726] [client 20.91.199.21:3453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/content.php"] [unique_id "amt_i_xWyxgRnoFKAJ_chgAAAiQ"]
[Thu Jul 30 11:44:59.901501 2026] [security2:error] [pid 642360:tid 642490] [client 172.202.44.182:21993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/upfile.php"] [unique_id "amt_i5SUkh3e5AhEJOBdfwAAAY8"]
[Thu Jul 30 11:45:00.055726 2026] [security2:error] [pid 642360:tid 642468] [remote 216.73.216.152:51864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amt_jJSUkh3e5AhEJOBdgAAB8Gs"]
[Thu Jul 30 11:45:00.827191 2026] [security2:error] [pid 643573:tid 643806] [client 172.202.44.182:60930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/bypass.php"] [unique_id "amt_jPxWyxgRnoFKAJ_ckAAAAnQ"]
[Thu Jul 30 11:45:01.240539 2026] [security2:error] [pid 643573:tid 643779] [client 85.208.96.204:59560] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2020/11/14/doria-pode-sofrer-impeachment-por-cheque-em-branco-a-china/"] [unique_id "amt_jfxWyxgRnoFKAJ_ckgAAAlk"]
[Thu Jul 30 11:45:01.240704 2026] [security2:error] [pid 643573:tid 643779] [client 85.208.96.204:59560] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2020/11/14/doria-pode-sofrer-impeachment-por-cheque-em-branco-a-china/"] [unique_id "amt_jfxWyxgRnoFKAJ_ckgAAAlk"]
[Thu Jul 30 11:45:01.392234 2026] [fcgid:warn] [pid 643573:tid 643729] (70014)End of file found: [client 118.193.33.19:57190] mod_fcgid: can't get data from http client
[Thu Jul 30 11:45:01.631012 2026] [security2:error] [pid 642360:tid 642470] [remote 74.7.241.60:53570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/article.php"] [unique_id "amt_jZSUkh3e5AhEJOBdjgAB1m0"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/bootstrap.bundle.min.js
[Thu Jul 30 11:45:02.236097 2026] [security2:error] [pid 642360:tid 642547] [client 20.215.191.139:64334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/config.php"] [unique_id "amt_jpSUkh3e5AhEJOBdkwAAAcg"]
[Thu Jul 30 11:45:02.264018 2026] [security2:error] [pid 643573:tid 643727] [client 172.202.44.182:60977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/updates.php"] [unique_id "amt_jvxWyxgRnoFKAJ_cmgAAAiU"]
[Thu Jul 30 11:45:02.470582 2026] [security2:error] [pid 643573:tid 643646] [remote 57.141.0.16:25002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/589953950/feed/rss2/"] [unique_id "amt_jvxWyxgRnoFKAJ_clwACZ0E"]
[Thu Jul 30 11:45:02.544093 2026] [security2:error] [pid 643573:tid 643828] [client 176.241.66.87:52870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_jvxWyxgRnoFKAJ_cnQAAAoo"]
[Thu Jul 30 11:45:02.544334 2026] [security2:error] [pid 643573:tid 643828] [client 176.241.66.87:52870] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_jvxWyxgRnoFKAJ_cnQAAAoo"]
[Thu Jul 30 11:45:02.895668 2026] [security2:error] [pid 642360:tid 642607] [client 20.91.199.21:6969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/plugins/not/includes/about.php"] [unique_id "amt_jpSUkh3e5AhEJOBdnAAAAgQ"]
[Thu Jul 30 11:45:03.226698 2026] [core:notice] [pid 643573:tid 643820] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:03.503055 2026] [security2:error] [pid 643573:tid 643720] [client 57.141.0.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_jvxWyxgRnoFKAJ_cngAAAh4"]
[Thu Jul 30 11:45:03.811199 2026] [security2:error] [pid 642360:tid 642541] [client 20.215.191.139:64336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/core.php"] [unique_id "amt_j5SUkh3e5AhEJOBdpAAAAcI"]
[Thu Jul 30 11:45:04.023206 2026] [security2:error] [pid 643253:tid 643509] [client 2407:d000:1c:9d56:64c4:87bd:6970:5a53:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_j8jqbtjBYzqM1uYkNAAAfVo"]
[Thu Jul 30 11:45:04.271896 2026] [security2:error] [pid 643573:tid 643757] [client 172.202.44.182:21955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/xmrlpc.php"] [unique_id "amt_kPxWyxgRnoFKAJ_cqwAAAkM"]
[Thu Jul 30 11:45:04.276476 2026] [core:notice] [pid 642360:tid 642527] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:05.154824 2026] [security2:error] [pid 643573:tid 643760] [client 20.91.199.21:14110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/plugins/simple/simple.php"] [unique_id "amt_kfxWyxgRnoFKAJ_csgAAAkY"]
[Thu Jul 30 11:45:06.260552 2026] [security2:error] [pid 643573:tid 643799] [client 20.91.199.21:16286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/plugins/wp-theme-editor/include.php"] [unique_id "amt_kvxWyxgRnoFKAJ_cvAAAAm0"]
[Thu Jul 30 11:45:06.422117 2026] [security2:error] [pid 643573:tid 643637] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_kvxWyxgRnoFKAJ_cvQACdjg"]
[Thu Jul 30 11:45:06.422331 2026] [security2:error] [pid 643573:tid 643808] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_kvxWyxgRnoFKAJ_cvQACdjg"]
[Thu Jul 30 11:45:06.627767 2026] [security2:error] [pid 643573:tid 643730] [client 20.215.191.139:48340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/css.php"] [unique_id "amt_kvxWyxgRnoFKAJ_cwgAAAig"]
[Thu Jul 30 11:45:07.349538 2026] [security2:error] [pid 643573:tid 643835] [client 172.202.44.182:61045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/ae.php"] [unique_id "amt_k_xWyxgRnoFKAJ_cxwAAApE"]
[Thu Jul 30 11:45:07.486430 2026] [security2:error] [pid 642360:tid 642437] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_k5SUkh3e5AhEJOBdzgABm0w"]
[Thu Jul 30 11:45:07.486631 2026] [security2:error] [pid 642360:tid 642502] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_k5SUkh3e5AhEJOBdzgABm0w"]
[Thu Jul 30 11:45:07.516681 2026] [security2:error] [pid 642360:tid 642490] [client 20.91.199.21:13925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/themes/aahana/json.php"] [unique_id "amt_k5SUkh3e5AhEJOBdzwAAAY8"]
[Thu Jul 30 11:45:07.568741 2026] [security2:error] [pid 643573:tid 643771] [client 103.215.74.26:46190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-login.php"] [unique_id "amt_k_xWyxgRnoFKAJ_cxgAAAlE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:45:07.577638 2026] [security2:error] [pid 643573:tid 643789] [client 20.215.191.139:48353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/database.php"] [unique_id "amt_k_xWyxgRnoFKAJ_cyQAAAmM"]
[Thu Jul 30 11:45:07.763929 2026] [security2:error] [pid 643573:tid 643807] [client 57.141.0.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt_k_xWyxgRnoFKAJ_cywAAAnU"]
[Thu Jul 30 11:45:08.105359 2026] [core:error] [pid 643573:tid 643657] [remote 216.73.216.19:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:45:08.105392 2026] [core:error] [pid 643573:tid 643657] [remote 216.73.216.19:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:45:08.230434 2026] [core:notice] [pid 643573:tid 643809] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:08.256684 2026] [security2:error] [pid 642360:tid 642547] [client 20.91.199.21:45539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/plugins/awesome-coming-soon/come.php"] [unique_id "amt_lJSUkh3e5AhEJOBd1wAAAcg"]
[Thu Jul 30 11:45:08.331683 2026] [security2:error] [pid 642360:tid 642496] [client 103.215.74.26:46198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/blog/wp-login.php"] [unique_id "amt_lJSUkh3e5AhEJOBd2AAAAZU"], referer: https://carnetdeshopping.com/blog/
[Thu Jul 30 11:45:08.593639 2026] [security2:error] [pid 643573:tid 643717] [client 172.202.44.182:21961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/moon.php"] [unique_id "amt_lPxWyxgRnoFKAJ_c2gAAAhs"]
[Thu Jul 30 11:45:08.610366 2026] [core:notice] [pid 642360:tid 642573] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:08.638386 2026] [security2:error] [pid 643573:tid 643824] [client 20.215.191.139:48370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/db.php"] [unique_id "amt_lPxWyxgRnoFKAJ_c2wAAAoY"]
[Thu Jul 30 11:45:08.715090 2026] [security2:error] [pid 643573:tid 643776] [client 20.104.18.253:30831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/011i.php"] [unique_id "amt_lPxWyxgRnoFKAJ_c3AAAAlY"]
[Thu Jul 30 11:45:09.096872 2026] [security2:error] [pid 643573:tid 643744] [client 103.215.74.26:46208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wordpress/wp-login.php"] [unique_id "amt_lfxWyxgRnoFKAJ_c4QAAAjY"], referer: https://carnetdeshopping.com/wordpress/
[Thu Jul 30 11:45:09.566399 2026] [security2:error] [pid 642360:tid 642609] [client 74.7.228.16:58582] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.hoki188win.com"] [uri "/robots.txt"] [unique_id "amt_lZSUkh3e5AhEJOBd4AACBkc"]
[Thu Jul 30 11:45:09.851169 2026] [security2:error] [pid 642360:tid 642515] [client 103.215.74.26:46216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp/wp-login.php"] [unique_id "amt_lZSUkh3e5AhEJOBd5QAAAag"], referer: https://carnetdeshopping.com/wp/
[Thu Jul 30 11:45:09.863269 2026] [security2:error] [pid 643573:tid 643760] [client 20.104.18.253:23335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/03a005685d.php"] [unique_id "amt_lfxWyxgRnoFKAJ_c6gAAAkY"]
[Thu Jul 30 11:45:09.892372 2026] [security2:error] [pid 643573:tid 643756] [client 20.215.191.139:48361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/default.php"] [unique_id "amt_lfxWyxgRnoFKAJ_c6wAAAkI"]
[Thu Jul 30 11:45:10.605174 2026] [security2:error] [pid 642360:tid 642550] [client 103.215.74.26:46232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/cms/wp-login.php"] [unique_id "amt_lpSUkh3e5AhEJOBd6wAAAcs"], referer: https://carnetdeshopping.com/cms/
[Thu Jul 30 11:45:10.635257 2026] [security2:error] [pid 642360:tid 642525] [client 74.7.228.58:42028] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.pkfprogroup.com"] [uri "/cgi-sys/404.html"] [unique_id "amt_lpSUkh3e5AhEJOBd7QABsk8"]
[Thu Jul 30 11:45:10.715713 2026] [security2:error] [pid 642360:tid 642509] [client 20.215.191.139:64333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/dropdown.php"] [unique_id "amt_lpSUkh3e5AhEJOBd9AAAAaI"]
[Thu Jul 30 11:45:11.094059 2026] [security2:error] [pid 643253:tid 643498] [client 20.104.18.253:28411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/403.php"] [unique_id "amt_l8jqbtjBYzqM1uYkNQAAAHI"]
[Thu Jul 30 11:45:11.341753 2026] [security2:error] [pid 643253:tid 643499] [client 103.215.74.26:46242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/site/wp-login.php"] [unique_id "amt_l8jqbtjBYzqM1uYkNwAAAHM"], referer: https://carnetdeshopping.com/site/
[Thu Jul 30 11:45:11.903317 2026] [core:notice] [pid 643573:tid 643786] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:11.939380 2026] [security2:error] [pid 643573:tid 643735] [client 20.104.18.253:22926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/404.php"] [unique_id "amt_l_xWyxgRnoFKAJ_c9AAAAi0"]
[Thu Jul 30 11:45:12.097214 2026] [security2:error] [pid 642360:tid 642559] [client 103.215.74.26:46254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/main/wp-login.php"] [unique_id "amt_mJSUkh3e5AhEJOBeAwAAAdQ"], referer: https://carnetdeshopping.com/main/
[Thu Jul 30 11:45:12.473999 2026] [security2:error] [pid 643573:tid 643780] [client 20.91.199.21:3877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/plugins/wp-conflg.php"] [unique_id "amt_mPxWyxgRnoFKAJ_c-gAAAlo"]
[Thu Jul 30 11:45:12.666785 2026] [security2:error] [pid 643573:tid 643744] [client 172.237.109.114:33023] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_mPxWyxgRnoFKAJ_c9QAAAjY"]
[Thu Jul 30 11:45:12.701789 2026] [core:notice] [pid 642360:tid 642531] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:12.743136 2026] [security2:error] [pid 643573:tid 643712] [client 172.237.109.114:14255] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_mPxWyxgRnoFKAJ_c9gAAAhY"]
[Thu Jul 30 11:45:12.762066 2026] [security2:error] [pid 643573:tid 643713] [client 172.237.109.114:26176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_mPxWyxgRnoFKAJ_c9wAAAhc"]
[Thu Jul 30 11:45:12.769036 2026] [security2:error] [pid 642360:tid 642555] [client 172.237.109.114:21389] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_mJSUkh3e5AhEJOBeBAAAAdA"]
[Thu Jul 30 11:45:12.793885 2026] [security2:error] [pid 642360:tid 642563] [client 172.237.109.114:36712] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_mJSUkh3e5AhEJOBeBQAAAdg"]
[Thu Jul 30 11:45:12.848531 2026] [security2:error] [pid 642360:tid 642566] [client 103.215.74.26:46268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/new/wp-login.php"] [unique_id "amt_mJSUkh3e5AhEJOBeEQAAAds"], referer: https://carnetdeshopping.com/new/
[Thu Jul 30 11:45:12.890203 2026] [security2:error] [pid 643573:tid 643791] [client 172.202.44.182:36692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/blog.php"] [unique_id "amt_mPxWyxgRnoFKAJ_c_AAAAmU"]
[Thu Jul 30 11:45:13.003999 2026] [security2:error] [pid 642360:tid 642536] [client 176.241.66.87:65386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_mZSUkh3e5AhEJOBeEwAAAb0"]
[Thu Jul 30 11:45:13.004188 2026] [security2:error] [pid 642360:tid 642536] [client 176.241.66.87:65386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_mZSUkh3e5AhEJOBeEwAAAb0"]
[Thu Jul 30 11:45:13.418962 2026] [security2:error] [pid 643573:tid 643720] [client 103.215.74.26:29848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-login.php"] [unique_id "amt_mfxWyxgRnoFKAJ_dAgAAAh4"], referer: http://carnetdeshopping.com/
[Thu Jul 30 11:45:13.542267 2026] [security2:error] [pid 643573:tid 643714] [client 20.104.18.253:55834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/aa.php"] [unique_id "amt_mfxWyxgRnoFKAJ_dBQAAAhg"]
[Thu Jul 30 11:45:13.892843 2026] [security2:error] [pid 643573:tid 643729] [client 103.215.74.26:29850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/blog/wp-login.php"] [unique_id "amt_mfxWyxgRnoFKAJ_dCwAAAic"], referer: http://carnetdeshopping.com/blog/
[Thu Jul 30 11:45:13.893012 2026] [security2:error] [pid 643573:tid 643779] [client 172.202.44.182:60993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/ini.php"] [unique_id "amt_mfxWyxgRnoFKAJ_dDAAAAlk"]
[Thu Jul 30 11:45:14.382920 2026] [security2:error] [pid 643573:tid 643830] [client 103.215.74.26:29856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wordpress/wp-login.php"] [unique_id "amt_mvxWyxgRnoFKAJ_dEQAAAow"], referer: http://carnetdeshopping.com/wordpress/
[Thu Jul 30 11:45:14.935468 2026] [security2:error] [pid 642360:tid 642602] [client 103.215.74.26:29858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp/wp-login.php"] [unique_id "amt_mpSUkh3e5AhEJOBeJgAAAf8"], referer: http://carnetdeshopping.com/wp/
[Thu Jul 30 11:45:15.380068 2026] [security2:error] [pid 643573:tid 643823] [client 57.141.0.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_mvxWyxgRnoFKAJ_dFwAAAoU"]
[Thu Jul 30 11:45:15.426070 2026] [security2:error] [pid 642360:tid 642595] [client 103.215.74.26:29862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/cms/wp-login.php"] [unique_id "amt_m5SUkh3e5AhEJOBeLQAAAfg"], referer: http://carnetdeshopping.com/cms/
[Thu Jul 30 11:45:15.515402 2026] [security2:error] [pid 643573:tid 643743] [client 20.104.18.253:32005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/aafewc0k.php"] [unique_id "amt_m_xWyxgRnoFKAJ_dIAAAAjU"]
[Thu Jul 30 11:45:15.949379 2026] [security2:error] [pid 642360:tid 642516] [client 172.202.44.182:61002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/admin-ajax.php"] [unique_id "amt_m5SUkh3e5AhEJOBeMwAAAak"]
[Thu Jul 30 11:45:15.957731 2026] [security2:error] [pid 643573:tid 643723] [client 103.215.74.26:29878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/site/wp-login.php"] [unique_id "amt_m_xWyxgRnoFKAJ_dJQAAAiE"], referer: http://carnetdeshopping.com/site/
[Thu Jul 30 11:45:16.271231 2026] [security2:error] [pid 643573:tid 643829] [client 20.104.18.253:28381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/abcd.php"] [unique_id "amt_nPxWyxgRnoFKAJ_dKQAAAos"]
[Thu Jul 30 11:45:16.387324 2026] [security2:error] [pid 643253:tid 643464] [client 172.236.9.101:16888] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.env.old"] [unique_id "amt_nMjqbtjBYzqM1uYkPwAAAFA"]
[Thu Jul 30 11:45:16.431594 2026] [security2:error] [pid 643253:tid 643391] [client 172.236.9.101:21719] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.env"] [unique_id "amt_nMjqbtjBYzqM1uYkQQAAAAc"]
[Thu Jul 30 11:45:16.469040 2026] [security2:error] [pid 642360:tid 642517] [client 103.215.74.26:29894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/main/wp-login.php"] [unique_id "amt_nJSUkh3e5AhEJOBePAAAAao"], referer: http://carnetdeshopping.com/main/
[Thu Jul 30 11:45:16.988243 2026] [security2:error] [pid 643253:tid 643394] [client 103.215.74.26:29900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/new/wp-login.php"] [unique_id "amt_nMjqbtjBYzqM1uYkQwAAAAo"], referer: http://carnetdeshopping.com/new/
[Thu Jul 30 11:45:17.061459 2026] [security2:error] [pid 643573:tid 643671] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_nfxWyxgRnoFKAJ_dNAACJFo"]
[Thu Jul 30 11:45:17.061664 2026] [security2:error] [pid 643573:tid 643726] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_nfxWyxgRnoFKAJ_dNAACJFo"]
[Thu Jul 30 11:45:17.215831 2026] [security2:error] [pid 643573:tid 643733] [client 172.236.9.101:20436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_nPxWyxgRnoFKAJ_dKwAAAis"]
[Thu Jul 30 11:45:17.216914 2026] [security2:error] [pid 643573:tid 643792] [client 172.236.9.101:23086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_nPxWyxgRnoFKAJ_dKgAAAmY"]
[Thu Jul 30 11:45:17.277180 2026] [security2:error] [pid 643253:tid 643431] [client 172.236.9.101:12495] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_nMjqbtjBYzqM1uYkOwAAAC8"]
[Thu Jul 30 11:45:17.288784 2026] [security2:error] [pid 643253:tid 643406] [client 172.236.9.101:1660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_nMjqbtjBYzqM1uYkPAAAABY"]
[Thu Jul 30 11:45:17.319469 2026] [security2:error] [pid 643253:tid 643418] [client 172.236.9.101:38822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_nMjqbtjBYzqM1uYkPQAAACI"]
[Thu Jul 30 11:45:17.319498 2026] [security2:error] [pid 643253:tid 643462] [client 172.236.9.101:52197] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_nMjqbtjBYzqM1uYkPgAAAE4"]
[Thu Jul 30 11:45:17.322704 2026] [security2:error] [pid 643573:tid 643718] [client 172.236.9.101:33072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_nPxWyxgRnoFKAJ_dLAAAAhw"]
[Thu Jul 30 11:45:17.333107 2026] [security2:error] [pid 643253:tid 643395] [client 172.236.9.101:34193] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_nMjqbtjBYzqM1uYkQAAAAAs"]
[Thu Jul 30 11:45:17.348213 2026] [security2:error] [pid 642360:tid 642579] [client 172.236.9.101:49846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_nJSUkh3e5AhEJOBeOwAAAeg"]
[Thu Jul 30 11:45:17.350881 2026] [security2:error] [pid 643573:tid 643737] [client 172.236.9.101:33014] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_nPxWyxgRnoFKAJ_dLQAAAi8"]
[Thu Jul 30 11:45:17.530953 2026] [security2:error] [pid 642360:tid 642527] [client 20.104.18.253:23354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/about.php"] [unique_id "amt_nZSUkh3e5AhEJOBeRAAAAbQ"]
[Thu Jul 30 11:45:17.710857 2026] [core:notice] [pid 642360:tid 642613] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:18.135892 2026] [security2:error] [pid 642360:tid 642600] [client 172.202.44.182:47293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/akc.php"] [unique_id "amt_npSUkh3e5AhEJOBeTgAAAf0"]
[Thu Jul 30 11:45:18.512656 2026] [security2:error] [pid 643573:tid 643644] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_nvxWyxgRnoFKAJ_dRQACcz8"]
[Thu Jul 30 11:45:18.512828 2026] [security2:error] [pid 643573:tid 643805] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_nvxWyxgRnoFKAJ_dRQACcz8"]
[Thu Jul 30 11:45:19.007708 2026] [security2:error] [pid 642360:tid 642566] [client 57.141.0.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_npSUkh3e5AhEJOBeUQAAAds"]
[Thu Jul 30 11:45:19.400440 2026] [security2:error] [pid 642360:tid 642526] [client 172.202.44.182:61009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/akcc.php"] [unique_id "amt_n5SUkh3e5AhEJOBeXgAAAbM"]
[Thu Jul 30 11:45:19.508213 2026] [security2:error] [pid 643573:tid 643761] [client 20.104.18.253:22912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/admin.php"] [unique_id "amt_n_xWyxgRnoFKAJ_dTwAAAkc"]
[Thu Jul 30 11:45:19.826470 2026] [core:notice] [pid 643573:tid 643794] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:21.289154 2026] [security2:error] [pid 642360:tid 642574] [client 20.91.199.21:45690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-includes/Requests/about.php"] [unique_id "amt_oZSUkh3e5AhEJOBedQAAAeM"]
[Thu Jul 30 11:45:21.648749 2026] [security2:error] [pid 642360:tid 642495] [client 20.104.18.253:43187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/adminfuns.php"] [unique_id "amt_oZSUkh3e5AhEJOBeegAAAZQ"]
[Thu Jul 30 11:45:21.687396 2026] [security2:error] [pid 642360:tid 642597] [client 74.7.175.171:37396] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cpanel.gbv.gzj.temporary.site"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amt_oZSUkh3e5AhEJOBeewAAAfo"]
[Thu Jul 30 11:45:21.886587 2026] [core:notice] [pid 642360:tid 642494] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:22.343863 2026] [security2:error] [pid 643573:tid 643715] [client 20.215.191.139:48343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/edit.php"] [unique_id "amt_ovxWyxgRnoFKAJ_dZAAAAhk"]
[Thu Jul 30 11:45:22.403334 2026] [security2:error] [pid 643573:tid 643786] [client 172.236.9.101:61296] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "alseermarine.com"] [uri "/WEB_VMS/LEVEL15/"] [unique_id "amt_ovxWyxgRnoFKAJ_dZQAAAmA"]
[Thu Jul 30 11:45:22.721053 2026] [core:notice] [pid 643253:tid 643444] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:23.179786 2026] [security2:error] [pid 643573:tid 643748] [client 20.104.18.253:35618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/albin.php"] [unique_id "amt_o_xWyxgRnoFKAJ_daQAAAjo"]
[Thu Jul 30 11:45:23.447496 2026] [security2:error] [pid 643573:tid 643828] [client 20.215.191.139:64352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/f35.php"] [unique_id "amt_o_xWyxgRnoFKAJ_dbAAAAoo"]
[Thu Jul 30 11:45:23.655610 2026] [security2:error] [pid 643573:tid 643745] [client 176.241.66.87:54315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_o_xWyxgRnoFKAJ_dbQAAAjc"]
[Thu Jul 30 11:45:23.655755 2026] [security2:error] [pid 643573:tid 643745] [client 176.241.66.87:54315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_o_xWyxgRnoFKAJ_dbQAAAjc"]
[Thu Jul 30 11:45:23.851153 2026] [security2:error] [pid 642360:tid 642570] [client 103.215.74.26:25470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-login.php"] [unique_id "amt_o5SUkh3e5AhEJOBeogAAAd8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:45:24.363650 2026] [security2:error] [pid 642360:tid 642569] [client 20.104.18.253:35634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/amfsqvgv.php"] [unique_id "amt_pJSUkh3e5AhEJOBeqgAAAd4"]
[Thu Jul 30 11:45:24.601057 2026] [core:notice] [pid 642360:tid 642511] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:24.709119 2026] [security2:error] [pid 643573:tid 643770] [client 20.215.191.139:64377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/f7.php"] [unique_id "amt_pPxWyxgRnoFKAJ_dcQAAAlA"]
[Thu Jul 30 11:45:25.084173 2026] [security2:error] [pid 643573:tid 643806] [client 43.173.181.31:42124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.181.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/tag/toulouse-2/"] [unique_id "amt_pPxWyxgRnoFKAJ_dcwAAAnQ"]
[Thu Jul 30 11:45:25.094070 2026] [security2:error] [pid 642360:tid 642538] [client 172.202.44.182:36718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/asasx.php"] [unique_id "amt_pZSUkh3e5AhEJOBetAAAAb8"]
[Thu Jul 30 11:45:25.147694 2026] [core:notice] [pid 643573:tid 643754] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:25.152465 2026] [security2:error] [pid 643573:tid 643754] [client 43.173.175.106:38848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/typography/"] [unique_id "amt_pPxWyxgRnoFKAJ_ddAAAAkA"]
[Thu Jul 30 11:45:25.160969 2026] [security2:error] [pid 642360:tid 642475] [remote 47.128.96.19:31020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.96.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/4514"] [unique_id "amt_pJSUkh3e5AhEJOBesQAB-HI"]
[Thu Jul 30 11:45:25.234262 2026] [core:notice] [pid 642360:tid 642459] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:25.239645 2026] [security2:error] [pid 642360:tid 642592] [client 47.128.96.19:31020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/4514"] [unique_id "amt_pZSUkh3e5AhEJOBetgAB9WI"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:45:25.402436 2026] [core:notice] [pid 642360:tid 642480] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:25.497241 2026] [core:notice] [pid 642360:tid 642482] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:25.561883 2026] [core:notice] [pid 642360:tid 642382] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:25.655074 2026] [security2:error] [pid 643573:tid 643809] [client 20.104.18.253:30360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/ant.php"] [unique_id "amt_pfxWyxgRnoFKAJ_dfgAAAnc"]
[Thu Jul 30 11:45:25.838215 2026] [core:notice] [pid 643573:tid 643735] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:25.843512 2026] [security2:error] [pid 643573:tid 643735] [client 43.173.175.113:56080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/tag/toulouse-2/"] [unique_id "amt_pfxWyxgRnoFKAJ_dgwAAAi0"], referer: https://carnetdeshopping.com/index.php/tag/toulouse-2/
[Thu Jul 30 11:45:26.279891 2026] [core:error] [pid 643573:tid 643603] [remote 74.7.230.40:37448] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:45:26.279913 2026] [core:error] [pid 643573:tid 643603] [remote 74.7.230.40:37448] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:45:26.280118 2026] [security2:error] [pid 643573:tid 643746] [client 74.7.230.40:37448] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "website-a94f61be.jst.nyx.temporary.site"] [uri "/website_a94f61be/index.php"] [unique_id "amt_pvxWyxgRnoFKAJ_dhgACOBY"]
[Thu Jul 30 11:45:26.616451 2026] [core:notice] [pid 642360:tid 642494] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:26.809623 2026] [security2:error] [pid 643573:tid 643718] [client 20.104.18.253:36188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/appreciators.php"] [unique_id "amt_pvxWyxgRnoFKAJ_diQAAAhw"]
[Thu Jul 30 11:45:27.708722 2026] [security2:error] [pid 643573:tid 643617] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_p_xWyxgRnoFKAJ_dnAACTCQ"]
[Thu Jul 30 11:45:27.708897 2026] [security2:error] [pid 643573:tid 643766] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_p_xWyxgRnoFKAJ_dnAACTCQ"]
[Thu Jul 30 11:45:27.866015 2026] [core:error] [pid 642360:tid 642600] [client 158.173.25.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://appliancerepairservice.one/
[Thu Jul 30 11:45:27.866039 2026] [core:error] [pid 642360:tid 642600] [client 158.173.25.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://appliancerepairservice.one/
[Thu Jul 30 11:45:28.591639 2026] [security2:error] [pid 643573:tid 643721] [client 57.141.0.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_p_xWyxgRnoFKAJ_doQAAAh8"]
[Thu Jul 30 11:45:28.665139 2026] [core:notice] [pid 643253:tid 643442] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:29.451564 2026] [security2:error] [pid 643573:tid 643597] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_qfxWyxgRnoFKAJ_dsAACRhA"]
[Thu Jul 30 11:45:29.451821 2026] [security2:error] [pid 643573:tid 643760] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_qfxWyxgRnoFKAJ_dsAACRhA"]
[Thu Jul 30 11:45:29.941549 2026] [security2:error] [pid 642360:tid 642534] [client 20.91.199.21:3305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-includes/style-engine/about.php"] [unique_id "amt_qZSUkh3e5AhEJOBe8AAAAbs"]
[Thu Jul 30 11:45:30.287319 2026] [security2:error] [pid 642360:tid 642566] [client 172.236.9.101:48771] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qJSUkh3e5AhEJOBe2wAAAds"]
[Thu Jul 30 11:45:30.290848 2026] [security2:error] [pid 642360:tid 642528] [client 172.236.9.101:62600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qJSUkh3e5AhEJOBe1wAAAbU"]
[Thu Jul 30 11:45:30.310192 2026] [security2:error] [pid 642360:tid 642616] [client 172.236.9.101:49842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qJSUkh3e5AhEJOBe4QAAAg0"]
[Thu Jul 30 11:45:30.343182 2026] [security2:error] [pid 642360:tid 642561] [client 172.236.9.101:46760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qJSUkh3e5AhEJOBe3AAAAdY"]
[Thu Jul 30 11:45:30.347601 2026] [security2:error] [pid 642360:tid 642588] [client 172.236.9.101:60052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qJSUkh3e5AhEJOBe2QAAAfE"]
[Thu Jul 30 11:45:30.370771 2026] [security2:error] [pid 643573:tid 643829] [client 172.236.9.101:7954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qPxWyxgRnoFKAJ_dpgAAAos"]
[Thu Jul 30 11:45:30.374153 2026] [security2:error] [pid 642360:tid 642564] [client 172.236.9.101:8635] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qJSUkh3e5AhEJOBe2gAAAdk"]
[Thu Jul 30 11:45:30.412275 2026] [security2:error] [pid 643253:tid 643479] [client 172.236.9.101:8686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qMjqbtjBYzqM1uYkSwAAAF8"]
[Thu Jul 30 11:45:30.415143 2026] [security2:error] [pid 643573:tid 643801] [client 172.236.9.101:27161] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qPxWyxgRnoFKAJ_dpwAAAm8"]
[Thu Jul 30 11:45:30.437005 2026] [security2:error] [pid 642360:tid 642578] [client 172.236.9.101:27532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qJSUkh3e5AhEJOBe2AAAAec"]
[Thu Jul 30 11:45:30.449797 2026] [security2:error] [pid 642360:tid 642529] [client 172.236.9.101:27610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qJSUkh3e5AhEJOBe3wAAAbY"]
[Thu Jul 30 11:45:30.457123 2026] [security2:error] [pid 642360:tid 642580] [client 172.236.9.101:13558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qJSUkh3e5AhEJOBe4AAAAek"]
[Thu Jul 30 11:45:30.457248 2026] [security2:error] [pid 642360:tid 642596] [client 172.236.9.101:61840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qJSUkh3e5AhEJOBe3QAAAfk"]
[Thu Jul 30 11:45:30.469424 2026] [security2:error] [pid 643253:tid 643481] [client 172.236.9.101:13132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qMjqbtjBYzqM1uYkSgAAAGE"]
[Thu Jul 30 11:45:30.472673 2026] [security2:error] [pid 642360:tid 642570] [client 172.236.9.101:53403] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qJSUkh3e5AhEJOBe3gAAAd8"]
[Thu Jul 30 11:45:30.482231 2026] [security2:error] [pid 643253:tid 643398] [client 172.236.9.101:46143] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qMjqbtjBYzqM1uYkSAAAAA4"]
[Thu Jul 30 11:45:30.497082 2026] [security2:error] [pid 643573:tid 643735] [client 172.236.9.101:54903] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qPxWyxgRnoFKAJ_dqAAAAi0"]
[Thu Jul 30 11:45:30.497089 2026] [security2:error] [pid 642360:tid 642594] [client 172.236.9.101:25754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qJSUkh3e5AhEJOBe4gAAAfc"]
[Thu Jul 30 11:45:30.509693 2026] [security2:error] [pid 643253:tid 643396] [client 172.236.9.101:10760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qMjqbtjBYzqM1uYkSQAAAAw"]
[Thu Jul 30 11:45:30.545466 2026] [security2:error] [pid 642360:tid 642543] [client 172.236.9.101:42099] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qJSUkh3e5AhEJOBe4wAAAcQ"]
[Thu Jul 30 11:45:30.739091 2026] [core:notice] [pid 643253:tid 643397] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:30.757491 2026] [security2:error] [pid 642360:tid 642574] [client 20.91.199.21:45516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-includes/rest-api/about.php"] [unique_id "amt_qpSUkh3e5AhEJOBe-AAAAeM"]
[Thu Jul 30 11:45:31.406140 2026] [security2:error] [pid 643573:tid 643737] [client 74.7.175.167:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-137a15f9.brx.dtn.temporary.site"] [uri "/index.php"] [unique_id "amt_qfxWyxgRnoFKAJ_dtQAAAi8"]
[Thu Jul 30 11:45:31.406954 2026] [security2:error] [pid 643573:tid 643765] [client 74.7.175.167:38586] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-137a15f9.brx.dtn.temporary.site"] [uri "/robots.txt"] [unique_id "amt_qfxWyxgRnoFKAJ_dswACSyU"]
[Thu Jul 30 11:45:31.665958 2026] [security2:error] [pid 643573:tid 643717] [client 20.104.18.253:30372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/archive.php"] [unique_id "amt_q_xWyxgRnoFKAJ_dvwAAAhs"]
[Thu Jul 30 11:45:32.433148 2026] [security2:error] [pid 643253:tid 643417] [client 20.104.18.253:50286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/as.php"] [unique_id "amt_rMjqbtjBYzqM1uYkVAAAACE"]
[Thu Jul 30 11:45:32.700926 2026] [core:notice] [pid 643253:tid 643485] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:32.877534 2026] [security2:error] [pid 643573:tid 643779] [client 131.226.102.36:43714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "hris.rgserve.ph"] [uri "/login.php"] [unique_id "amt_rPxWyxgRnoFKAJ_dwgACWS4"]
[Thu Jul 30 11:45:32.965011 2026] [security2:error] [pid 643573:tid 643774] [client 172.202.44.182:56338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/axx.php"] [unique_id "amt_rPxWyxgRnoFKAJ_dyQAAAlQ"]
[Thu Jul 30 11:45:33.376862 2026] [security2:error] [pid 643573:tid 643720] [client 104.28.90.40:17227] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jesus.claims"] [uri "/index.php"] [unique_id "amt_rPxWyxgRnoFKAJ_dwQACHiA"]
[Thu Jul 30 11:45:33.459133 2026] [security2:error] [pid 643573:tid 643787] [client 74.7.241.179:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "guardian-heir.com"] [uri "/index.php"] [unique_id "amt_rfxWyxgRnoFKAJ_dzQACYWs"]
[Thu Jul 30 11:45:33.952300 2026] [security2:error] [pid 642360:tid 642583] [client 20.91.199.21:22691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amt_rZSUkh3e5AhEJOBfGAAAAew"]
[Thu Jul 30 11:45:34.045480 2026] [security2:error] [pid 643573:tid 643819] [client 57.141.0.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_rfxWyxgRnoFKAJ_d0AAAAoE"]
[Thu Jul 30 11:45:34.261013 2026] [security2:error] [pid 642360:tid 642532] [client 176.241.66.87:55291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_rpSUkh3e5AhEJOBfHwAAAbk"]
[Thu Jul 30 11:45:34.261144 2026] [security2:error] [pid 642360:tid 642532] [client 176.241.66.87:55291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_rpSUkh3e5AhEJOBfHwAAAbk"]
[Thu Jul 30 11:45:34.593283 2026] [security2:error] [pid 643573:tid 643777] [client 172.202.44.182:37704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/berax.php"] [unique_id "amt_rvxWyxgRnoFKAJ_d2wAAAlc"]
[Thu Jul 30 11:45:34.696517 2026] [core:notice] [pid 643573:tid 643785] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:34.787119 2026] [security2:error] [pid 643573:tid 643818] [client 20.104.18.253:36211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/atomlib.php"] [unique_id "amt_rvxWyxgRnoFKAJ_d4AAAAoA"]
[Thu Jul 30 11:45:35.807969 2026] [security2:error] [pid 642360:tid 642586] [client 172.236.9.101:49485] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_r5SUkh3e5AhEJOBfKQAAAe8"]
[Thu Jul 30 11:45:35.809525 2026] [security2:error] [pid 642360:tid 642511] [client 172.236.9.101:53199] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_r5SUkh3e5AhEJOBfKgAAAaQ"]
[Thu Jul 30 11:45:35.854992 2026] [security2:error] [pid 643253:tid 643507] [client 172.202.44.182:50257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/build.php"] [unique_id "amt_r8jqbtjBYzqM1uYkWAAAAHs"]
[Thu Jul 30 11:45:35.893567 2026] [security2:error] [pid 643253:tid 643443] [client 172.236.9.101:16320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_r8jqbtjBYzqM1uYkVgAAADs"]
[Thu Jul 30 11:45:36.140548 2026] [security2:error] [pid 642360:tid 642588] [client 20.91.199.21:22718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/banners/about.php"] [unique_id "amt_sJSUkh3e5AhEJOBfMgAAAfE"]
[Thu Jul 30 11:45:36.650601 2026] [core:notice] [pid 643573:tid 643783] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:36.912772 2026] [security2:error] [pid 643573:tid 643799] [client 20.91.199.21:12641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/about.php"] [unique_id "amt_sPxWyxgRnoFKAJ_eYAAAAm0"]
[Thu Jul 30 11:45:37.736382 2026] [security2:error] [pid 643573:tid 643817] [client 20.91.199.21:3451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/.well-known/about.php"] [unique_id "amt_sfxWyxgRnoFKAJ_ebQAAAn8"]
[Thu Jul 30 11:45:37.834577 2026] [security2:error] [pid 643573:tid 643774] [client 172.236.9.101:6070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_sfxWyxgRnoFKAJ_eZgAAAlQ"]
[Thu Jul 30 11:45:37.838048 2026] [security2:error] [pid 643573:tid 643803] [client 172.236.9.101:44978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_sfxWyxgRnoFKAJ_eZQAAAnE"]
[Thu Jul 30 11:45:37.854572 2026] [security2:error] [pid 643573:tid 643728] [client 172.236.9.101:3344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_sfxWyxgRnoFKAJ_eZwAAAiY"]
[Thu Jul 30 11:45:37.943385 2026] [security2:error] [pid 642360:tid 642539] [client 172.236.9.101:63667] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_sZSUkh3e5AhEJOBfPAAAAcA"]
[Thu Jul 30 11:45:37.943895 2026] [security2:error] [pid 643573:tid 643721] [client 172.236.9.101:31489] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_sfxWyxgRnoFKAJ_eaAAAAh8"]
[Thu Jul 30 11:45:37.949559 2026] [security2:error] [pid 642360:tid 642601] [client 172.236.9.101:15682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_sZSUkh3e5AhEJOBfOwAAAf4"]
[Thu Jul 30 11:45:37.951516 2026] [security2:error] [pid 643573:tid 643776] [client 172.236.9.101:32055] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_sfxWyxgRnoFKAJ_eaQAAAlY"]
[Thu Jul 30 11:45:37.952081 2026] [security2:error] [pid 642360:tid 642493] [client 172.236.9.101:51658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_sZSUkh3e5AhEJOBfPQAAAZI"]
[Thu Jul 30 11:45:38.004896 2026] [security2:error] [pid 643573:tid 643835] [client 172.236.9.101:47041] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_sfxWyxgRnoFKAJ_eagAAApE"]
[Thu Jul 30 11:45:38.387161 2026] [security2:error] [pid 643573:tid 643688] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_svxWyxgRnoFKAJ_edgACfGs"]
[Thu Jul 30 11:45:38.387404 2026] [security2:error] [pid 643573:tid 643814] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_svxWyxgRnoFKAJ_edgACfGs"]
[Thu Jul 30 11:45:38.392693 2026] [security2:error] [pid 642360:tid 642541] [client 20.104.18.253:28423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/autoload_classmap.php"] [unique_id "amt_spSUkh3e5AhEJOBfTAAAAcI"]
[Thu Jul 30 11:45:38.433057 2026] [security2:error] [pid 643253:tid 643470] [client 20.91.199.21:3402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-includes/Text/about.php"] [unique_id "amt_ssjqbtjBYzqM1uYkWQAAAFY"]
[Thu Jul 30 11:45:38.656713 2026] [security2:error] [pid 643573:tid 643711] [client 119.73.97.132:31164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amt_svxWyxgRnoFKAJ_edQACFSA"], referer: https://www.urwru.club/emm-elevate/
[Thu Jul 30 11:45:38.672552 2026] [security2:error] [pid 643573:tid 643710] [client 172.202.44.182:36710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/buy.php"] [unique_id "amt_svxWyxgRnoFKAJ_eeQAAAhQ"]
[Thu Jul 30 11:45:38.759374 2026] [core:notice] [pid 642360:tid 642558] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:38.836764 2026] [security2:error] [pid 642360:tid 642584] [client 172.236.9.101:58532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_spSUkh3e5AhEJOBfRwAAAe0"]
[Thu Jul 30 11:45:38.836897 2026] [security2:error] [pid 643573:tid 643816] [client 172.236.9.101:49244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_svxWyxgRnoFKAJ_edAAAAn4"]
[Thu Jul 30 11:45:38.843761 2026] [security2:error] [pid 642360:tid 642606] [client 172.236.9.101:10002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_spSUkh3e5AhEJOBfSAAAAgM"]
[Thu Jul 30 11:45:38.848449 2026] [security2:error] [pid 643573:tid 643792] [client 172.236.9.101:32203] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_svxWyxgRnoFKAJ_ecwAAAmY"]
[Thu Jul 30 11:45:38.866906 2026] [security2:error] [pid 642360:tid 642565] [client 172.236.9.101:8031] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_spSUkh3e5AhEJOBfRgAAAdo"]
[Thu Jul 30 11:45:38.875252 2026] [security2:error] [pid 642360:tid 642491] [client 172.236.9.101:31101] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_spSUkh3e5AhEJOBfSQAAAZA"]
[Thu Jul 30 11:45:38.893255 2026] [security2:error] [pid 642360:tid 642546] [client 172.236.9.101:9753] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_spSUkh3e5AhEJOBfSgAAAcc"]
[Thu Jul 30 11:45:38.893269 2026] [security2:error] [pid 642360:tid 642581] [client 172.236.9.101:51323] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_spSUkh3e5AhEJOBfSwAAAeo"]
[Thu Jul 30 11:45:38.957431 2026] [proxy:error] [pid 643573:tid 643739] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:45:38.957485 2026] [proxy_http:error] [pid 643573:tid 643739] [client 185.247.137.152:33131] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:45:38.958055 2026] [proxy:error] [pid 643573:tid 643739] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:45:38.958099 2026] [proxy_http:error] [pid 643573:tid 643739] [client 185.247.137.152:33131] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:45:39.417470 2026] [security2:error] [pid 643573:tid 643781] [client 119.73.97.132:31164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amt_s_xWyxgRnoFKAJ_ehgACW24"], referer: https://www.urwru.club/emm-elevate/
[Thu Jul 30 11:45:40.022801 2026] [security2:error] [pid 643573:tid 643715] [client 172.202.44.182:37721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/checkbox.php"] [unique_id "amt_tPxWyxgRnoFKAJ_emAAAAhk"]
[Thu Jul 30 11:45:40.247090 2026] [security2:error] [pid 643573:tid 643720] [client 20.91.199.21:4873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-includes/ID3/about.php"] [unique_id "amt_tPxWyxgRnoFKAJ_emQAAAh4"]
[Thu Jul 30 11:45:40.348510 2026] [security2:error] [pid 642360:tid 642401] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_tJSUkh3e5AhEJOBfZAAB0Cg"]
[Thu Jul 30 11:45:40.348664 2026] [security2:error] [pid 642360:tid 642555] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_tJSUkh3e5AhEJOBfZAAB0Cg"]
[Thu Jul 30 11:45:40.806170 2026] [security2:error] [pid 643573:tid 643730] [client 103.215.74.26:63446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php"] [unique_id "amt_tPxWyxgRnoFKAJ_erAAAAig"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:45:40.966531 2026] [security2:error] [pid 643573:tid 643742] [client 172.202.44.182:36696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/cong.php"] [unique_id "amt_tPxWyxgRnoFKAJ_erQAAAjQ"]
[Thu Jul 30 11:45:40.981942 2026] [security2:error] [pid 643573:tid 643710] [client 57.141.0.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_tPxWyxgRnoFKAJ_eowAAAhQ"]
[Thu Jul 30 11:45:41.179383 2026] [security2:error] [pid 643573:tid 643803] [client 74.7.230.1:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.nfi.nyx.temporary.site"] [uri "/index.php"] [unique_id "amt_s_xWyxgRnoFKAJ_elgAAAnE"]
[Thu Jul 30 11:45:41.179418 2026] [security2:error] [pid 643573:tid 643803] [client 74.7.230.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.nfi.nyx.temporary.site"] [uri "/index.php"] [unique_id "amt_s_xWyxgRnoFKAJ_elgAAAnE"]
[Thu Jul 30 11:45:41.180231 2026] [security2:error] [pid 643573:tid 643751] [client 74.7.230.1:44604] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.nfi.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amt_s_xWyxgRnoFKAJ_elAACPXM"]
[Thu Jul 30 11:45:41.531262 2026] [core:notice] [pid 643573:tid 643757] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:41.843103 2026] [security2:error] [pid 642360:tid 642605] [client 20.104.18.253:52425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/bb.php"] [unique_id "amt_tZSUkh3e5AhEJOBfcwAAAgI"]
[Thu Jul 30 11:45:41.972373 2026] [security2:error] [pid 643573:tid 643776] [client 74.7.230.1:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "nfi.nyx.temporary.site"] [uri "/index.php"] [unique_id "amt_tfxWyxgRnoFKAJ_euQAAAlY"], referer: https://www.nfi.nyx.temporary.site/robots.txt
[Thu Jul 30 11:45:41.973269 2026] [security2:error] [pid 643253:tid 643508] [client 74.7.230.1:44614] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "nfi.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amt_tcjqbtjBYzqM1uYkYgAAfF8"], referer: https://www.nfi.nyx.temporary.site/robots.txt
[Thu Jul 30 11:45:42.315422 2026] [security2:error] [pid 642360:tid 642585] [client 20.91.199.21:3242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/img/about.php"] [unique_id "amt_tpSUkh3e5AhEJOBfdwAAAe4"]
[Thu Jul 30 11:45:42.470541 2026] [security2:error] [pid 642360:tid 642586] [client 172.202.44.182:56343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/file4.php"] [unique_id "amt_tpSUkh3e5AhEJOBfegAAAe8"]
[Thu Jul 30 11:45:42.491084 2026] [security2:error] [pid 643573:tid 643743] [client 2a03:2880:f800:2b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_tfxWyxgRnoFKAJ_etQACNQo"]
[Thu Jul 30 11:45:42.851990 2026] [proxy:error] [pid 643573:tid 643773] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:45:42.852096 2026] [proxy_http:error] [pid 643573:tid 643773] [client 74.7.175.131:33634] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:45:42.853425 2026] [proxy:error] [pid 643573:tid 643773] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:45:42.853497 2026] [proxy_http:error] [pid 643573:tid 643773] [client 74.7.175.131:33634] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:45:42.853654 2026] [security2:error] [pid 643573:tid 643773] [client 74.7.175.131:33634] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "cpcalendars.mxk.djb.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amt_tvxWyxgRnoFKAJ_fBwAAAlM"]
[Thu Jul 30 11:45:43.243211 2026] [security2:error] [pid 642360:tid 642521] [client 20.91.199.21:22322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/languages/about.php"] [unique_id "amt_t5SUkh3e5AhEJOBfgAAAAa4"]
[Thu Jul 30 11:45:43.455131 2026] [security2:error] [pid 643573:tid 643737] [client 20.104.18.253:49702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/bnm.php"] [unique_id "amt_t_xWyxgRnoFKAJ_fEAAAAi8"]
[Thu Jul 30 11:45:43.548444 2026] [security2:error] [pid 643573:tid 643830] [client 172.202.44.182:36695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/flower.php"] [unique_id "amt_t_xWyxgRnoFKAJ_fEQAAAow"]
[Thu Jul 30 11:45:43.599113 2026] [core:notice] [pid 643573:tid 643778] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:43.603652 2026] [security2:error] [pid 643573:tid 643778] [client 103.215.74.26:48574] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_t_xWyxgRnoFKAJ_fEgAAAlg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:45:43.663447 2026] [security2:error] [pid 642360:tid 642524] [client 57.141.0.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_t5SUkh3e5AhEJOBffwAAAbE"]
[Thu Jul 30 11:45:44.354603 2026] [core:notice] [pid 643573:tid 643720] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:44.355512 2026] [security2:error] [pid 643573:tid 643802] [client 2407:d000:1c:9d56:64c4:87bd:6970:5a53:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_t_xWyxgRnoFKAJ_fGAACcB0"]
[Thu Jul 30 11:45:44.360355 2026] [security2:error] [pid 643573:tid 643720] [client 103.215.74.26:48584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_uPxWyxgRnoFKAJ_fJQAAAh4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:45:44.630828 2026] [security2:error] [pid 643573:tid 643740] [client 20.91.199.21:14108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-includes/customize/about.php"] [unique_id "amt_uPxWyxgRnoFKAJ_fJgAAAjI"]
[Thu Jul 30 11:45:44.645178 2026] [security2:error] [pid 643253:tid 643408] [client 172.237.109.114:23220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_uMjqbtjBYzqM1uYkZwAAABg"]
[Thu Jul 30 11:45:45.042130 2026] [security2:error] [pid 643573:tid 643718] [client 176.241.66.87:50654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_ufxWyxgRnoFKAJ_fKgAAAhw"]
[Thu Jul 30 11:45:45.042253 2026] [security2:error] [pid 643573:tid 643718] [client 176.241.66.87:50654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_ufxWyxgRnoFKAJ_fKgAAAhw"]
[Thu Jul 30 11:45:45.075787 2026] [core:notice] [pid 643573:tid 643712] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:45.079903 2026] [security2:error] [pid 643573:tid 643712] [client 103.215.74.26:48592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_ufxWyxgRnoFKAJ_fKwAAAhY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:45:45.106448 2026] [core:notice] [pid 643573:tid 643738] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:45.574456 2026] [security2:error] [pid 643573:tid 643827] [client 172.237.109.114:51751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_ufxWyxgRnoFKAJ_fLAAAAok"]
[Thu Jul 30 11:45:45.596043 2026] [security2:error] [pid 643573:tid 643727] [client 172.237.109.114:1543] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_ufxWyxgRnoFKAJ_fLgAAAiU"]
[Thu Jul 30 11:45:45.680204 2026] [security2:error] [pid 642360:tid 642590] [client 20.104.18.253:28449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/bootstrap.php"] [unique_id "amt_uZSUkh3e5AhEJOBfjgAAAfM"]
[Thu Jul 30 11:45:45.695785 2026] [core:notice] [pid 643573:tid 643734] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:45.721568 2026] [security2:error] [pid 642360:tid 642516] [client 172.237.109.114:21390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_uZSUkh3e5AhEJOBfigAAAak"]
[Thu Jul 30 11:45:45.724624 2026] [security2:error] [pid 643573:tid 643710] [client 172.237.109.114:46395] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_ufxWyxgRnoFKAJ_fLwAAAhQ"]
[Thu Jul 30 11:45:45.803931 2026] [core:notice] [pid 643573:tid 643770] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:45.808515 2026] [security2:error] [pid 643573:tid 643770] [client 103.215.74.26:48596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_ufxWyxgRnoFKAJ_fOgAAAlA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:45:46.020310 2026] [security2:error] [pid 643573:tid 643748] [client 85.208.96.198:52718] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/06/28/tjpb-mantem-validade-de-ato-do-tce-que-julgou-irregular-contratacao-de-escritorio-de-advocacia/"] [unique_id "amt_uvxWyxgRnoFKAJ_fPQAAAjo"]
[Thu Jul 30 11:45:46.020434 2026] [security2:error] [pid 643573:tid 643748] [client 85.208.96.198:52718] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/06/28/tjpb-mantem-validade-de-ato-do-tce-que-julgou-irregular-contratacao-de-escritorio-de-advocacia/"] [unique_id "amt_uvxWyxgRnoFKAJ_fPQAAAjo"]
[Thu Jul 30 11:45:46.530611 2026] [core:notice] [pid 642360:tid 642491] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:46.534538 2026] [security2:error] [pid 642360:tid 642491] [client 103.215.74.26:48606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_upSUkh3e5AhEJOBflQAAAZA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:45:46.659479 2026] [security2:error] [pid 642360:tid 642581] [client 20.104.18.253:40996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/buy.php"] [unique_id "amt_upSUkh3e5AhEJOBflgAAAeo"]
[Thu Jul 30 11:45:47.247392 2026] [core:notice] [pid 643573:tid 643780] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:47.251375 2026] [security2:error] [pid 643573:tid 643780] [client 103.215.74.26:48622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_u_xWyxgRnoFKAJ_fSAAAAlo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:45:47.975065 2026] [security2:error] [pid 642360:tid 642615] [client 20.91.199.21:14133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-includes.bak/html-api/about.php"] [unique_id "amt_u5SUkh3e5AhEJOBfpQAAAgw"]
[Thu Jul 30 11:45:47.989956 2026] [autoindex:error] [pid 643573:tid 643807] [client 143.198.88.13:63581] AH01276: Cannot serve directory /home2/tvsnyxte/public_html/website_f8c1eb2c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: www.website-f723eabb.ikn.mzi.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:45:48.028902 2026] [core:notice] [pid 642360:tid 642522] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:48.034048 2026] [security2:error] [pid 642360:tid 642522] [client 103.215.74.26:48624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_vJSUkh3e5AhEJOBfqAAAAa8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:45:48.055500 2026] [security2:error] [pid 643573:tid 643812] [client 20.104.18.253:43021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/chosen.php"] [unique_id "amt_vPxWyxgRnoFKAJ_fTwAAAno"]
[Thu Jul 30 11:45:48.616096 2026] [security2:error] [pid 643573:tid 643712] [client 172.202.44.182:50244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/form.php"] [unique_id "amt_vPxWyxgRnoFKAJ_fUwAAAhY"]
[Thu Jul 30 11:45:48.832843 2026] [core:notice] [pid 643253:tid 643498] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:48.837819 2026] [security2:error] [pid 643253:tid 643498] [client 103.215.74.26:48634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_vMjqbtjBYzqM1uYkbgAAAHI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:45:49.009461 2026] [security2:error] [pid 643573:tid 643796] [client 20.104.18.253:38710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/class-wp-image.php"] [unique_id "amt_vfxWyxgRnoFKAJ_fVgAAAmo"]
[Thu Jul 30 11:45:49.042507 2026] [security2:error] [pid 643573:tid 643682] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_vfxWyxgRnoFKAJ_fWAACZmU"]
[Thu Jul 30 11:45:49.042663 2026] [security2:error] [pid 643573:tid 643792] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_vfxWyxgRnoFKAJ_fWAACZmU"]
[Thu Jul 30 11:45:49.127407 2026] [security2:error] [pid 642360:tid 642559] [client 193.47.62.167:37476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.besthomemovingcompanysharjah.boutique"] [uri "/index.php"] [unique_id "amt_upSUkh3e5AhEJOBfmAAAAdQ"]
[Thu Jul 30 11:45:49.149091 2026] [security2:error] [pid 643573:tid 643730] [client 57.141.0.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_vPxWyxgRnoFKAJ_fUgAAAig"]
[Thu Jul 30 11:45:49.542270 2026] [security2:error] [pid 643573:tid 643804] [client 172.202.44.182:36687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/gecko.php"] [unique_id "amt_vfxWyxgRnoFKAJ_fWgAAAnI"]
[Thu Jul 30 11:45:49.548988 2026] [core:notice] [pid 643573:tid 643830] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:49.553161 2026] [security2:error] [pid 643573:tid 643830] [client 103.215.74.26:48650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_vfxWyxgRnoFKAJ_fWwAAAow"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:45:49.761101 2026] [core:notice] [pid 643573:tid 643715] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:50.020689 2026] [security2:error] [pid 643573:tid 643748] [client 20.104.18.253:45575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/classsmtps.php"] [unique_id "amt_vvxWyxgRnoFKAJ_fZAAAAjo"]
[Thu Jul 30 11:45:50.299996 2026] [core:notice] [pid 643573:tid 643802] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:50.308210 2026] [security2:error] [pid 643573:tid 643802] [client 103.215.74.26:48666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_vvxWyxgRnoFKAJ_fcwAAAnA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:45:50.519196 2026] [security2:error] [pid 643573:tid 643790] [client 20.91.199.21:16295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-includes/widgets/about.php"] [unique_id "amt_vvxWyxgRnoFKAJ_fdQAAAmQ"]
[Thu Jul 30 11:45:50.683738 2026] [security2:error] [pid 643253:tid 643419] [client 172.202.44.182:37724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/kyami.php"] [unique_id "amt_vsjqbtjBYzqM1uYkdQAAACM"]
[Thu Jul 30 11:45:50.687687 2026] [core:notice] [pid 643573:tid 643738] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:50.792652 2026] [security2:error] [pid 642360:tid 642572] [client 20.104.18.253:54412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/classwithtostring.php"] [unique_id "amt_vpSUkh3e5AhEJOBfwgAAAeE"]
[Thu Jul 30 11:45:51.056201 2026] [core:notice] [pid 642360:tid 642552] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:51.061156 2026] [security2:error] [pid 642360:tid 642552] [client 103.215.74.26:48668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_v5SUkh3e5AhEJOBfxQAAAc0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:45:51.208281 2026] [security2:error] [pid 642360:tid 642487] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_v5SUkh3e5AhEJOBfxwABv34"]
[Thu Jul 30 11:45:51.208448 2026] [security2:error] [pid 642360:tid 642538] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_v5SUkh3e5AhEJOBfxwABv34"]
[Thu Jul 30 11:45:51.822784 2026] [core:notice] [pid 642360:tid 642592] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:51.827269 2026] [security2:error] [pid 642360:tid 642592] [client 103.215.74.26:48674] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_v5SUkh3e5AhEJOBfzAAAAfU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:45:51.870904 2026] [security2:error] [pid 643573:tid 643730] [client 172.202.44.182:37706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/manager.php"] [unique_id "amt_v_xWyxgRnoFKAJ_fhAAAAig"]
[Thu Jul 30 11:45:51.879600 2026] [security2:error] [pid 643573:tid 643797] [client 127.0.0.1:35310] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amt_v_xWyxgRnoFKAJ_fgwAAAms"]
[Thu Jul 30 11:45:51.879620 2026] [security2:error] [pid 643573:tid 643830] [client 127.0.0.1:35302] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amt_v_xWyxgRnoFKAJ_fgQAAAow"]
[Thu Jul 30 11:45:51.879661 2026] [security2:error] [pid 643573:tid 643723] [client 74.7.230.4:37624] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.xff.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amt_v_xWyxgRnoFKAJ_fggACIWc"]
[Thu Jul 30 11:45:51.879777 2026] [security2:error] [pid 643573:tid 643778] [client 74.7.228.45:45062] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.pse.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amt_v_xWyxgRnoFKAJ_fgAACWCE"]
[Thu Jul 30 11:45:52.031953 2026] [security2:error] [pid 643253:tid 643455] [client 20.91.199.21:15389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-includes/IXR/about.php"] [unique_id "amt_wMjqbtjBYzqM1uYkdwAAAEc"]
[Thu Jul 30 11:45:52.256992 2026] [security2:error] [pid 643573:tid 643758] [client 172.236.9.101:12230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vvxWyxgRnoFKAJ_fZwAAAkQ"]
[Thu Jul 30 11:45:52.324666 2026] [security2:error] [pid 643573:tid 643736] [client 172.236.9.101:17717] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vvxWyxgRnoFKAJ_faAAAAi4"]
[Thu Jul 30 11:45:52.333171 2026] [security2:error] [pid 643573:tid 643811] [client 172.236.9.101:58083] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vvxWyxgRnoFKAJ_fawAAAnk"]
[Thu Jul 30 11:45:52.336204 2026] [security2:error] [pid 643253:tid 643458] [client 172.236.9.101:5334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vsjqbtjBYzqM1uYkcAAAAEo"]
[Thu Jul 30 11:45:52.342510 2026] [security2:error] [pid 643573:tid 643721] [client 172.236.9.101:31214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vvxWyxgRnoFKAJ_fagAAAh8"]
[Thu Jul 30 11:45:52.345804 2026] [security2:error] [pid 643573:tid 643824] [client 172.236.9.101:30444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vvxWyxgRnoFKAJ_faQAAAoY"]
[Thu Jul 30 11:45:52.356737 2026] [security2:error] [pid 642360:tid 642582] [client 172.236.9.101:33001] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vpSUkh3e5AhEJOBfugAAAes"]
[Thu Jul 30 11:45:52.362075 2026] [security2:error] [pid 643573:tid 643735] [client 172.236.9.101:42601] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vvxWyxgRnoFKAJ_fbAAAAi0"]
[Thu Jul 30 11:45:52.362965 2026] [security2:error] [pid 643253:tid 643441] [client 172.236.9.101:44579] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vsjqbtjBYzqM1uYkcQAAADk"]
[Thu Jul 30 11:45:52.385334 2026] [security2:error] [pid 643573:tid 643791] [client 172.236.9.101:28536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vvxWyxgRnoFKAJ_fbQAAAmU"]
[Thu Jul 30 11:45:52.402495 2026] [security2:error] [pid 642360:tid 642534] [client 172.236.9.101:37129] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vpSUkh3e5AhEJOBfuQAAAbs"]
[Thu Jul 30 11:45:52.412755 2026] [security2:error] [pid 643253:tid 643464] [client 172.236.9.101:4281] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vsjqbtjBYzqM1uYkdAAAAFA"]
[Thu Jul 30 11:45:52.413992 2026] [security2:error] [pid 642360:tid 642528] [client 172.236.9.101:31317] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vpSUkh3e5AhEJOBfuwAAAbU"]
[Thu Jul 30 11:45:52.422548 2026] [security2:error] [pid 643253:tid 643430] [client 172.236.9.101:60662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vsjqbtjBYzqM1uYkcgAAAC4"]
[Thu Jul 30 11:45:52.438873 2026] [security2:error] [pid 643573:tid 643772] [client 172.236.9.101:1634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vvxWyxgRnoFKAJ_fbwAAAlI"]
[Thu Jul 30 11:45:52.444059 2026] [security2:error] [pid 643253:tid 643422] [client 172.236.9.101:55461] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vsjqbtjBYzqM1uYkcwAAACY"]
[Thu Jul 30 11:45:52.444944 2026] [security2:error] [pid 643573:tid 643743] [client 172.236.9.101:54571] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vvxWyxgRnoFKAJ_fcQAAAjU"]
[Thu Jul 30 11:45:52.448042 2026] [security2:error] [pid 643573:tid 643725] [client 172.236.9.101:52075] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vvxWyxgRnoFKAJ_fcAAAAiM"]
[Thu Jul 30 11:45:52.462500 2026] [security2:error] [pid 643573:tid 643788] [client 172.236.9.101:56135] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vvxWyxgRnoFKAJ_fbgAAAmI"]
[Thu Jul 30 11:45:52.480355 2026] [security2:error] [pid 643573:tid 643739] [client 172.236.9.101:33105] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vvxWyxgRnoFKAJ_fcgAAAjE"]
[Thu Jul 30 11:45:52.554768 2026] [core:notice] [pid 643573:tid 643724] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:52.559147 2026] [security2:error] [pid 643573:tid 643724] [client 103.215.74.26:48688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_wPxWyxgRnoFKAJ_fjAAAAiI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:45:52.856451 2026] [security2:error] [pid 643573:tid 643740] [client 172.202.44.182:37718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/mari.php"] [unique_id "amt_wPxWyxgRnoFKAJ_flAAAAjI"]
[Thu Jul 30 11:45:53.145998 2026] [security2:error] [pid 643573:tid 643710] [client 20.104.18.253:28420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/config.php"] [unique_id "amt_wfxWyxgRnoFKAJ_flwAAAhQ"]
[Thu Jul 30 11:45:53.249391 2026] [security2:error] [pid 642360:tid 642574] [client 57.141.0.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_wJSUkh3e5AhEJOBf0QAAAeM"]
[Thu Jul 30 11:45:53.287672 2026] [core:notice] [pid 643573:tid 643796] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:53.293130 2026] [security2:error] [pid 643573:tid 643796] [client 103.215.74.26:17556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_wfxWyxgRnoFKAJ_fmQAAAmo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:45:53.884105 2026] [security2:error] [pid 643573:tid 643801] [client 20.91.199.21:12666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-admin/js/about.php"] [unique_id "amt_wfxWyxgRnoFKAJ_fpAAAAm8"]
[Thu Jul 30 11:45:54.021007 2026] [core:notice] [pid 643573:tid 643805] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:54.025384 2026] [security2:error] [pid 643573:tid 643805] [client 103.215.74.26:17558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_wvxWyxgRnoFKAJ_fpQAAAnM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:45:54.683700 2026] [security2:error] [pid 643573:tid 643836] [client 20.91.199.21:4888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amt_wvxWyxgRnoFKAJ_frwAAApI"]
[Thu Jul 30 11:45:55.132809 2026] [security2:error] [pid 643573:tid 643740] [client 20.104.18.253:43060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/core.php"] [unique_id "amt_w_xWyxgRnoFKAJ_ftAAAAjI"]
[Thu Jul 30 11:45:55.504140 2026] [security2:error] [pid 643573:tid 643775] [client 176.241.66.87:57592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_w_xWyxgRnoFKAJ_ftgAAAlU"]
[Thu Jul 30 11:45:55.504315 2026] [security2:error] [pid 643573:tid 643775] [client 176.241.66.87:57592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_w_xWyxgRnoFKAJ_ftgAAAlU"]
[Thu Jul 30 11:45:56.245065 2026] [security2:error] [pid 643573:tid 643779] [client 20.91.199.21:45633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-includes/pomo/about.php"] [unique_id "amt_xPxWyxgRnoFKAJ_fvgAAAlk"]
[Thu Jul 30 11:45:56.408534 2026] [security2:error] [pid 643573:tid 643757] [client 172.202.44.182:56982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/nc4.php"] [unique_id "amt_xPxWyxgRnoFKAJ_fvwAAAkM"]
[Thu Jul 30 11:45:57.444955 2026] [security2:error] [pid 642360:tid 642553] [client 143.198.88.13:57171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.88.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.website-fbcbfb4b.brx.dtn.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amt_xZSUkh3e5AhEJOBf8wAAAc4"], referer: www.website-e2d5057b.ogv.ajs.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:45:57.656515 2026] [core:error] [pid 643573:tid 643730] [client 143.198.88.13:50012] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.website-e2d5057b.ogv.ajs.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:45:57.656541 2026] [core:error] [pid 643573:tid 643730] [client 143.198.88.13:50012] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.website-e2d5057b.ogv.ajs.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:45:57.968911 2026] [security2:error] [pid 643573:tid 643686] [remote 57.141.0.43:49874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/7399102667/feed/rss2/"] [unique_id "amt_xfxWyxgRnoFKAJ_fzwACJGk"]
[Thu Jul 30 11:45:58.298617 2026] [security2:error] [pid 643573:tid 643820] [client 20.104.18.253:49724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/css.php"] [unique_id "amt_xvxWyxgRnoFKAJ_f0gAAAoI"]
[Thu Jul 30 11:45:58.415951 2026] [security2:error] [pid 643573:tid 643740] [client 57.141.0.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_xfxWyxgRnoFKAJ_fzgAAAjI"]
[Thu Jul 30 11:45:58.703670 2026] [security2:error] [pid 643573:tid 643833] [client 154.57.218.68:44579] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amt_xvxWyxgRnoFKAJ_f1AACjyc"], referer: https://trello.com/
[Thu Jul 30 11:45:58.775318 2026] [security2:error] [pid 643573:tid 643771] [client 172.236.9.101:26680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_xvxWyxgRnoFKAJ_f0QAAAlE"]
[Thu Jul 30 11:45:58.917395 2026] [core:error] [pid 643573:tid 643779] [client 143.198.88.13:51607] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.website-e2d5057b.ogv.ajs.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:45:58.917422 2026] [core:error] [pid 643573:tid 643779] [client 143.198.88.13:51607] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.website-e2d5057b.ogv.ajs.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:45:58.972445 2026] [cgid:error] [pid 643573:tid 643725] [client 172.202.44.182:57010] AH01264: stderr from /home1/khwnyxte/alshateeintl.com/cgi-bin: script not found or unable to stat
[Thu Jul 30 11:45:59.620737 2026] [security2:error] [pid 643573:tid 643752] [client 20.91.199.21:14130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-includes/block-patterns/about.php"] [unique_id "amt_x_xWyxgRnoFKAJ_f5QAAAj4"]
[Thu Jul 30 11:45:59.630307 2026] [security2:error] [pid 643573:tid 643747] [client 20.104.18.253:39353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/database.php"] [unique_id "amt_x_xWyxgRnoFKAJ_f5gAAAjk"]
[Thu Jul 30 11:45:59.745522 2026] [security2:error] [pid 642360:tid 642361] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_x5SUkh3e5AhEJOBgBwAB2wA"]
[Thu Jul 30 11:45:59.745753 2026] [security2:error] [pid 642360:tid 642566] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_x5SUkh3e5AhEJOBgBwAB2wA"]
[Thu Jul 30 11:45:59.758694 2026] [security2:error] [pid 643573:tid 643791] [client 172.236.9.101:5531] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_x_xWyxgRnoFKAJ_f3gAAAmU"]
[Thu Jul 30 11:45:59.766685 2026] [core:notice] [pid 643253:tid 643416] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:59.771961 2026] [security2:error] [pid 643253:tid 643416] [client 103.215.74.26:17568] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_x8jqbtjBYzqM1uYkfQAAACA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:45:59.778400 2026] [security2:error] [pid 642360:tid 642505] [client 172.236.9.101:39152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_x5SUkh3e5AhEJOBgBAAAAZ4"]
[Thu Jul 30 11:45:59.882891 2026] [security2:error] [pid 642360:tid 642519] [client 172.236.9.101:60195] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_x5SUkh3e5AhEJOBgBQAAAaw"]
[Thu Jul 30 11:45:59.892029 2026] [security2:error] [pid 643253:tid 643429] [client 172.236.9.101:58317] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_x8jqbtjBYzqM1uYkfAAAAC0"]
[Thu Jul 30 11:45:59.916361 2026] [security2:error] [pid 643573:tid 643825] [client 172.236.9.101:19926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_x_xWyxgRnoFKAJ_f3wAAAoc"]
[Thu Jul 30 11:46:00.213694 2026] [core:error] [pid 643573:tid 643770] [client 143.198.88.13:49520] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.website-e2d5057b.ogv.ajs.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:46:00.213719 2026] [core:error] [pid 643573:tid 643770] [client 143.198.88.13:49520] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.website-e2d5057b.ogv.ajs.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:46:00.491757 2026] [core:error] [pid 643253:tid 643389] [client 143.198.88.13:50407] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.website-e2d5057b.ogv.ajs.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:46:00.491788 2026] [core:error] [pid 643253:tid 643389] [client 143.198.88.13:50407] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.website-e2d5057b.ogv.ajs.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:46:00.492820 2026] [core:notice] [pid 643573:tid 643728] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:00.506236 2026] [security2:error] [pid 643573:tid 643728] [client 103.215.74.26:17576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_yPxWyxgRnoFKAJ_f-AAAAiY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:00.553755 2026] [core:error] [pid 642360:tid 642390] [remote 74.7.241.162:53854] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:46:00.553785 2026] [core:error] [pid 642360:tid 642390] [remote 74.7.241.162:53854] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:46:00.554202 2026] [security2:error] [pid 642360:tid 642578] [client 74.7.241.162:53854] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "mail.bisbeetour.com"] [uri "/index.php"] [unique_id "amt_yJSUkh3e5AhEJOBgEwAB5x0"]
[Thu Jul 30 11:46:01.236609 2026] [core:notice] [pid 643573:tid 643724] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:01.245919 2026] [security2:error] [pid 643573:tid 643724] [client 103.215.74.26:17584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_yfxWyxgRnoFKAJ_f_gAAAiI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:01.293794 2026] [security2:error] [pid 643573:tid 643746] [client 2a03:2880:f800:23:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_x_xWyxgRnoFKAJ_f4QACOHI"]
[Thu Jul 30 11:46:01.465951 2026] [security2:error] [pid 642360:tid 642586] [client 172.236.9.101:45933] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_yJSUkh3e5AhEJOBgDAAAAe8"]
[Thu Jul 30 11:46:01.471845 2026] [security2:error] [pid 643573:tid 643784] [client 172.236.9.101:10914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_yPxWyxgRnoFKAJ_f8QAAAl4"]
[Thu Jul 30 11:46:01.537407 2026] [security2:error] [pid 643573:tid 643816] [client 172.236.9.101:23726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_yPxWyxgRnoFKAJ_f7QAAAn4"]
[Thu Jul 30 11:46:01.571352 2026] [security2:error] [pid 643573:tid 643774] [client 172.236.9.101:10514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_yPxWyxgRnoFKAJ_f7gAAAlQ"]
[Thu Jul 30 11:46:01.631561 2026] [security2:error] [pid 642360:tid 642594] [client 172.236.9.101:43278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_yJSUkh3e5AhEJOBgEQAAAfc"]
[Thu Jul 30 11:46:01.632625 2026] [security2:error] [pid 643573:tid 643715] [client 172.236.9.101:21590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_yPxWyxgRnoFKAJ_f8gAAAhk"]
[Thu Jul 30 11:46:01.633939 2026] [security2:error] [pid 643573:tid 643766] [client 172.236.9.101:5249] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_yPxWyxgRnoFKAJ_f9AAAAkw"]
[Thu Jul 30 11:46:01.649437 2026] [security2:error] [pid 642360:tid 642552] [client 172.236.9.101:55274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_yJSUkh3e5AhEJOBgEgAAAc0"]
[Thu Jul 30 11:46:01.649647 2026] [security2:error] [pid 642360:tid 642572] [client 172.236.9.101:65444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_yJSUkh3e5AhEJOBgDQAAAeE"]
[Thu Jul 30 11:46:01.652685 2026] [security2:error] [pid 643573:tid 643726] [client 172.236.9.101:23677] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_yPxWyxgRnoFKAJ_f8AAAAiQ"]
[Thu Jul 30 11:46:01.653220 2026] [security2:error] [pid 642360:tid 642513] [client 172.236.9.101:54409] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_yJSUkh3e5AhEJOBgDwAAAaY"]
[Thu Jul 30 11:46:01.663308 2026] [security2:error] [pid 643573:tid 643831] [client 172.236.9.101:2829] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_yPxWyxgRnoFKAJ_f8wAAAo0"]
[Thu Jul 30 11:46:01.670739 2026] [security2:error] [pid 642360:tid 642529] [client 172.236.9.101:27792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_yJSUkh3e5AhEJOBgEAAAAbY"]
[Thu Jul 30 11:46:01.675305 2026] [security2:error] [pid 643253:tid 643438] [client 172.236.9.101:15319] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_yMjqbtjBYzqM1uYkfgAAADY"]
[Thu Jul 30 11:46:01.981310 2026] [core:notice] [pid 643253:tid 643439] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:01.986264 2026] [security2:error] [pid 643253:tid 643439] [client 103.215.74.26:17592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_ycjqbtjBYzqM1uYkggAAADc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:02.152956 2026] [security2:error] [pid 643573:tid 643697] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_yvxWyxgRnoFKAJ_gBQACYXQ"]
[Thu Jul 30 11:46:02.153165 2026] [security2:error] [pid 643573:tid 643787] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_yvxWyxgRnoFKAJ_gBQACYXQ"]
[Thu Jul 30 11:46:02.319076 2026] [security2:error] [pid 643573:tid 643825] [client 57.141.0.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_yfxWyxgRnoFKAJ_gAgAAAoc"]
[Thu Jul 30 11:46:02.656386 2026] [security2:error] [pid 643573:tid 643736] [client 62.102.148.185:42078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amt_yvxWyxgRnoFKAJ_gBgAAAi4"]
[Thu Jul 30 11:46:02.656574 2026] [security2:error] [pid 643573:tid 643736] [client 62.102.148.185:42078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amt_yvxWyxgRnoFKAJ_gBgAAAi4"]
[Thu Jul 30 11:46:02.730263 2026] [core:notice] [pid 642360:tid 642533] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:02.735645 2026] [security2:error] [pid 642360:tid 642533] [client 103.215.74.26:17600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_ypSUkh3e5AhEJOBgMAAAAbo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:02.820014 2026] [core:notice] [pid 643573:tid 643720] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:02.938424 2026] [security2:error] [pid 642360:tid 642426] [remote 74.7.241.60:43616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/article.php"] [unique_id "amt_ypSUkh3e5AhEJOBgMgABkUE"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/bootstrap.bundle.min.js
[Thu Jul 30 11:46:03.048534 2026] [security2:error] [pid 643573:tid 643815] [client 20.104.18.253:43048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/db.php"] [unique_id "amt_y_xWyxgRnoFKAJ_gDgAAAn0"]
[Thu Jul 30 11:46:03.286571 2026] [security2:error] [pid 643573:tid 643708] [remote 57.141.0.12:52864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/24984966950/feed/rss2/"] [unique_id "amt_y_xWyxgRnoFKAJ_gEAACc38"]
[Thu Jul 30 11:46:03.301142 2026] [core:notice] [pid 643573:tid 643802] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:03.405793 2026] [core:notice] [pid 643573:tid 643793] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:03.520160 2026] [core:notice] [pid 643253:tid 643425] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:03.524417 2026] [security2:error] [pid 643253:tid 643425] [client 103.215.74.26:26990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_y8jqbtjBYzqM1uYkhAAAACk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:05.012557 2026] [security2:error] [pid 642360:tid 642526] [client 20.104.18.253:43063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/default.php"] [unique_id "amt_zZSUkh3e5AhEJOBgQAAAAbM"]
[Thu Jul 30 11:46:06.109874 2026] [security2:error] [pid 643573:tid 643784] [client 114.119.134.220:48965] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "thdinfinity.com"] [uri "/healthcareg/physical-therapy-assistant-schools-alabama"] [unique_id "amt_zvxWyxgRnoFKAJ_gMQAAAl4"], referer: https://thdinfinity.com/healthcareg/physical-therapy-assistant-schools-alabama
[Thu Jul 30 11:46:06.170004 2026] [security2:error] [pid 642360:tid 642607] [client 176.241.66.87:58783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_zpSUkh3e5AhEJOBgTwAAAgQ"]
[Thu Jul 30 11:46:06.170131 2026] [security2:error] [pid 642360:tid 642607] [client 176.241.66.87:58783] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_zpSUkh3e5AhEJOBgTwAAAgQ"]
[Thu Jul 30 11:46:06.782369 2026] [security2:error] [pid 643573:tid 643734] [client 172.236.9.101:6740] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_zvxWyxgRnoFKAJ_gMwAAAiw"]
[Thu Jul 30 11:46:06.782970 2026] [security2:error] [pid 643573:tid 643808] [client 172.236.9.101:27373] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_zvxWyxgRnoFKAJ_gMgAAAnY"]
[Thu Jul 30 11:46:06.840075 2026] [security2:error] [pid 643573:tid 643809] [client 172.236.9.101:61376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_zvxWyxgRnoFKAJ_gNAAAAnc"]
[Thu Jul 30 11:46:06.851139 2026] [security2:error] [pid 642360:tid 642609] [client 172.236.9.101:24208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_zpSUkh3e5AhEJOBgUAAAAgY"]
[Thu Jul 30 11:46:06.896359 2026] [security2:error] [pid 643573:tid 643813] [client 172.236.9.101:3108] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_zvxWyxgRnoFKAJ_gNQAAAns"]
[Thu Jul 30 11:46:06.984943 2026] [security2:error] [pid 643573:tid 643780] [client 143.198.88.13:57337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.88.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.website-ff6a65b0.vdb.nyx.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amt_zvxWyxgRnoFKAJ_gPAAAAlo"], referer: https://china2026.icsa.org//blog//wp-login.php
[Thu Jul 30 11:46:07.226877 2026] [core:error] [pid 643573:tid 643833] [client 143.198.88.13:55708] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://china2026.icsa.org//blog//wp-login.php
[Thu Jul 30 11:46:07.226901 2026] [core:error] [pid 643573:tid 643833] [client 143.198.88.13:55708] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://china2026.icsa.org//blog//wp-login.php
[Thu Jul 30 11:46:07.462741 2026] [core:error] [pid 643253:tid 643452] [client 143.198.88.13:55636] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://china2026.icsa.org//blog//wp-login.php
[Thu Jul 30 11:46:07.462774 2026] [core:error] [pid 643253:tid 643452] [client 143.198.88.13:55636] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://china2026.icsa.org//blog//wp-login.php
[Thu Jul 30 11:46:07.673026 2026] [core:error] [pid 642360:tid 642582] [client 143.198.88.13:58778] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://china2026.icsa.org//blog//wp-login.php
[Thu Jul 30 11:46:07.673059 2026] [core:error] [pid 642360:tid 642582] [client 143.198.88.13:58778] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://china2026.icsa.org//blog//wp-login.php
[Thu Jul 30 11:46:07.913559 2026] [core:error] [pid 642360:tid 642499] [client 143.198.88.13:53319] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://china2026.icsa.org//blog//wp-login.php
[Thu Jul 30 11:46:07.913582 2026] [core:error] [pid 642360:tid 642499] [client 143.198.88.13:53319] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://china2026.icsa.org//blog//wp-login.php
[Thu Jul 30 11:46:08.778076 2026] [security2:error] [pid 643573:tid 643592] [remote 97.74.93.24:37518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-login.php"] [unique_id "amt_0PxWyxgRnoFKAJ_gWQACfgs"]
[Thu Jul 30 11:46:09.179032 2026] [security2:error] [pid 643573:tid 643778] [client 74.7.244.62:35990] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.dqy.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amt_0fxWyxgRnoFKAJ_gWgAAAlg"]
[Thu Jul 30 11:46:09.236949 2026] [core:notice] [pid 643573:tid 643729] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:09.243539 2026] [security2:error] [pid 643573:tid 643729] [client 103.215.74.26:27002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_0fxWyxgRnoFKAJ_gXQAAAic"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:09.403337 2026] [security2:error] [pid 643573:tid 643795] [client 20.91.199.21:4926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/updraft/about.php"] [unique_id "amt_0fxWyxgRnoFKAJ_gXgAAAmk"]
[Thu Jul 30 11:46:09.424881 2026] [security2:error] [pid 643573:tid 643724] [client 172.236.9.101:28006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_0PxWyxgRnoFKAJ_gSgAAAiI"]
[Thu Jul 30 11:46:09.453724 2026] [security2:error] [pid 642360:tid 642539] [client 172.236.9.101:10316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_0JSUkh3e5AhEJOBgaAAAAcA"]
[Thu Jul 30 11:46:09.464639 2026] [security2:error] [pid 642360:tid 642509] [client 172.236.9.101:1271] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_0JSUkh3e5AhEJOBgaQAAAaI"]
[Thu Jul 30 11:46:09.466861 2026] [security2:error] [pid 642360:tid 642504] [client 172.236.9.101:33625] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_0JSUkh3e5AhEJOBgagAAAZ0"]
[Thu Jul 30 11:46:09.514622 2026] [security2:error] [pid 643573:tid 643734] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "heir-holdings.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "amt_0fxWyxgRnoFKAJ_gYQAAAiw"]
[Thu Jul 30 11:46:09.540566 2026] [security2:error] [pid 642360:tid 642541] [client 172.236.9.101:15089] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_0JSUkh3e5AhEJOBgawAAAcI"]
[Thu Jul 30 11:46:09.571427 2026] [security2:error] [pid 642360:tid 642597] [client 172.236.9.101:35040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_0JSUkh3e5AhEJOBgbAAAAfo"]
[Thu Jul 30 11:46:09.577588 2026] [security2:error] [pid 642360:tid 642614] [client 172.236.9.101:55630] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_0JSUkh3e5AhEJOBgbQAAAgs"]
[Thu Jul 30 11:46:09.580625 2026] [security2:error] [pid 643573:tid 643732] [client 172.236.9.101:1137] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_0PxWyxgRnoFKAJ_gSwAAAio"]
[Thu Jul 30 11:46:09.589297 2026] [security2:error] [pid 643573:tid 643719] [client 172.236.9.101:7621] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_0PxWyxgRnoFKAJ_gTQAAAh0"]
[Thu Jul 30 11:46:09.593356 2026] [security2:error] [pid 642360:tid 642495] [client 172.236.9.101:20263] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_0JSUkh3e5AhEJOBgbgAAAZQ"]
[Thu Jul 30 11:46:09.596524 2026] [security2:error] [pid 643573:tid 643746] [client 172.236.9.101:12307] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_0PxWyxgRnoFKAJ_gTwAAAjg"]
[Thu Jul 30 11:46:09.598305 2026] [security2:error] [pid 643573:tid 643769] [client 172.236.9.101:31773] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_0PxWyxgRnoFKAJ_gTAAAAk8"]
[Thu Jul 30 11:46:09.598718 2026] [security2:error] [pid 642360:tid 642558] [client 172.236.9.101:7639] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_0JSUkh3e5AhEJOBgbwAAAdM"]
[Thu Jul 30 11:46:09.605699 2026] [security2:error] [pid 643573:tid 643818] [client 172.236.9.101:24716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_0PxWyxgRnoFKAJ_gTgAAAoA"]
[Thu Jul 30 11:46:09.618550 2026] [security2:error] [pid 643253:tid 643479] [client 172.236.9.101:39271] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_0MjqbtjBYzqM1uYkigAAAF8"]
[Thu Jul 30 11:46:09.984838 2026] [core:notice] [pid 643253:tid 643482] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:09.989047 2026] [security2:error] [pid 643253:tid 643482] [client 103.215.74.26:27016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_0cjqbtjBYzqM1uYkjgAAAGI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:10.426601 2026] [security2:error] [pid 643253:tid 643353] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_0sjqbtjBYzqM1uYkkQAAe2I"]
[Thu Jul 30 11:46:10.426762 2026] [security2:error] [pid 643253:tid 643507] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_0sjqbtjBYzqM1uYkkQAAe2I"]
[Thu Jul 30 11:46:10.754903 2026] [core:notice] [pid 642360:tid 642571] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:10.759108 2026] [security2:error] [pid 642360:tid 642571] [client 103.215.74.26:27018] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_0pSUkh3e5AhEJOBgjgAAAeA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:10.862808 2026] [security2:error] [pid 642360:tid 642611] [client 20.104.18.253:39354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/dropdown.php"] [unique_id "amt_0pSUkh3e5AhEJOBgkAAAAgg"]
[Thu Jul 30 11:46:11.216136 2026] [security2:error] [pid 643573:tid 643725] [client 57.141.0.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_0vxWyxgRnoFKAJ_gaQAAAiM"]
[Thu Jul 30 11:46:11.365811 2026] [security2:error] [pid 642360:tid 642493] [client 66.249.73.98:37889] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amt_0JSUkh3e5AhEJOBgcAAAAZI"]
[Thu Jul 30 11:46:11.420398 2026] [security2:error] [pid 642360:tid 642600] [client 20.91.199.21:15405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "amt_05SUkh3e5AhEJOBglwAAAf0"]
[Thu Jul 30 11:46:11.498570 2026] [core:notice] [pid 643573:tid 643727] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:11.506358 2026] [security2:error] [pid 643573:tid 643727] [client 103.215.74.26:27022] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_0_xWyxgRnoFKAJ_gewAAAiU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:11.605009 2026] [security2:error] [pid 642360:tid 642505] [client 74.7.230.43:33494] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.google-search.org.meg.gzj.temporary.site"] [uri "/robots.txt"] [unique_id "amt_05SUkh3e5AhEJOBgmAABnlo"]
[Thu Jul 30 11:46:11.851841 2026] [core:notice] [pid 642360:tid 642561] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:11.900106 2026] [security2:error] [pid 643573:tid 643834] [client 20.104.18.253:49138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/edit.php"] [unique_id "amt_0_xWyxgRnoFKAJ_ggQAAApA"]
[Thu Jul 30 11:46:11.988764 2026] [security2:error] [pid 643573:tid 643732] [client 20.91.199.21:3252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/themes/about.php"] [unique_id "amt_0_xWyxgRnoFKAJ_gggAAAio"]
[Thu Jul 30 11:46:12.240925 2026] [core:notice] [pid 643573:tid 643728] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:12.247583 2026] [security2:error] [pid 643573:tid 643728] [client 103.215.74.26:27036] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_1PxWyxgRnoFKAJ_ggwAAAiY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:12.791500 2026] [security2:error] [pid 643573:tid 643625] [remote 92.222.104.212:21940] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "kayomanis.com"] [uri "/menu-grid/"] [unique_id "amt_1PxWyxgRnoFKAJ_gkQACciw"]
[Thu Jul 30 11:46:12.791714 2026] [security2:error] [pid 643573:tid 643804] [client 92.222.104.212:21940] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kayomanis.com"] [uri "/menu-grid/"] [unique_id "amt_1PxWyxgRnoFKAJ_gkQACciw"]
[Thu Jul 30 11:46:12.801050 2026] [security2:error] [pid 642360:tid 642596] [client 172.236.9.101:3074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1JSUkh3e5AhEJOBgoQAAAfk"]
[Thu Jul 30 11:46:12.812782 2026] [security2:error] [pid 643573:tid 643748] [client 172.236.9.101:11116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1PxWyxgRnoFKAJ_ghQAAAjo"]
[Thu Jul 30 11:46:12.844209 2026] [security2:error] [pid 643573:tid 643762] [client 172.236.9.101:11941] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1PxWyxgRnoFKAJ_ghAAAAkg"]
[Thu Jul 30 11:46:12.898469 2026] [security2:error] [pid 643573:tid 643800] [client 172.236.9.101:18775] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1PxWyxgRnoFKAJ_ghgAAAm4"]
[Thu Jul 30 11:46:12.918175 2026] [security2:error] [pid 643573:tid 643832] [client 172.236.9.101:51255] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1PxWyxgRnoFKAJ_ghwAAAo4"]
[Thu Jul 30 11:46:12.929238 2026] [security2:error] [pid 643573:tid 643801] [client 172.236.9.101:55321] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1PxWyxgRnoFKAJ_giAAAAm8"]
[Thu Jul 30 11:46:12.966223 2026] [security2:error] [pid 643573:tid 643634] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_1PxWyxgRnoFKAJ_glAACgTU"]
[Thu Jul 30 11:46:12.966386 2026] [security2:error] [pid 643573:tid 643819] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_1PxWyxgRnoFKAJ_glAACgTU"]
[Thu Jul 30 11:46:12.972618 2026] [core:notice] [pid 643573:tid 643765] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:12.976773 2026] [security2:error] [pid 643573:tid 643765] [client 103.215.74.26:27038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_1PxWyxgRnoFKAJ_glQAAAks"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:12.986471 2026] [security2:error] [pid 643253:tid 643409] [client 20.104.18.253:30912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/f35.php"] [unique_id "amt_1MjqbtjBYzqM1uYklgAAABk"]
[Thu Jul 30 11:46:13.443006 2026] [security2:error] [pid 643573:tid 643812] [client 20.91.199.21:4865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-admin/includes/about.php"] [unique_id "amt_1fxWyxgRnoFKAJ_gmwAAAno"]
[Thu Jul 30 11:46:13.778590 2026] [security2:error] [pid 643253:tid 643468] [client 20.104.18.253:61987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/f7.php"] [unique_id "amt_1cjqbtjBYzqM1uYkmgAAAFQ"]
[Thu Jul 30 11:46:13.778753 2026] [security2:error] [pid 643573:tid 643718] [client 172.236.9.101:59342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1fxWyxgRnoFKAJ_gmQAAAhw"]
[Thu Jul 30 11:46:13.796501 2026] [security2:error] [pid 643253:tid 643471] [client 172.236.9.101:26662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1cjqbtjBYzqM1uYkmAAAAFc"]
[Thu Jul 30 11:46:13.799131 2026] [security2:error] [pid 643573:tid 643731] [client 172.236.9.101:38982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1fxWyxgRnoFKAJ_gmgAAAik"]
[Thu Jul 30 11:46:13.801436 2026] [security2:error] [pid 642360:tid 642617] [client 172.236.9.101:44920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1ZSUkh3e5AhEJOBgqwAAAg4"]
[Thu Jul 30 11:46:14.166265 2026] [security2:error] [pid 642360:tid 642584] [client 20.91.199.21:41047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/images/about.php"] [unique_id "amt_1pSUkh3e5AhEJOBguAAAAe0"]
[Thu Jul 30 11:46:14.352894 2026] [security2:error] [pid 642360:tid 642537] [client 57.141.0.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_1ZSUkh3e5AhEJOBgsgAAAb4"]
[Thu Jul 30 11:46:14.615768 2026] [core:notice] [pid 642360:tid 642529] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:14.838868 2026] [security2:error] [pid 643573:tid 643721] [client 172.236.9.101:19885] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1vxWyxgRnoFKAJ_goAAAAh8"]
[Thu Jul 30 11:46:14.850035 2026] [security2:error] [pid 643573:tid 643817] [client 172.236.9.101:48957] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1vxWyxgRnoFKAJ_gowAAAn8"]
[Thu Jul 30 11:46:14.870858 2026] [security2:error] [pid 643573:tid 643769] [client 172.236.9.101:45360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1vxWyxgRnoFKAJ_gpAAAAk8"]
[Thu Jul 30 11:46:14.872732 2026] [security2:error] [pid 643573:tid 643786] [client 172.236.9.101:49721] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1vxWyxgRnoFKAJ_goQAAAmA"]
[Thu Jul 30 11:46:14.875092 2026] [security2:error] [pid 643573:tid 643734] [client 172.236.9.101:23508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1vxWyxgRnoFKAJ_gnwAAAiw"]
[Thu Jul 30 11:46:14.875454 2026] [security2:error] [pid 643573:tid 643747] [client 172.236.9.101:8745] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1vxWyxgRnoFKAJ_gogAAAjk"]
[Thu Jul 30 11:46:15.226854 2026] [security2:error] [pid 643573:tid 643824] [client 172.236.9.101:4407] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1vxWyxgRnoFKAJ_gpgAAAoY"]
[Thu Jul 30 11:46:15.231483 2026] [security2:error] [pid 643573:tid 643818] [client 172.236.9.101:26071] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1vxWyxgRnoFKAJ_gpQAAAoA"]
[Thu Jul 30 11:46:15.232731 2026] [security2:error] [pid 643573:tid 643719] [client 172.236.9.101:47949] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1vxWyxgRnoFKAJ_gqAAAAh0"]
[Thu Jul 30 11:46:15.235521 2026] [security2:error] [pid 643573:tid 643758] [client 172.236.9.101:3042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1vxWyxgRnoFKAJ_gpwAAAkQ"]
[Thu Jul 30 11:46:15.375150 2026] [security2:error] [pid 643573:tid 643835] [client 20.91.199.21:15402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/blogs.dir/about.php"] [unique_id "amt_1_xWyxgRnoFKAJ_gsAAAApE"]
[Thu Jul 30 11:46:16.669473 2026] [security2:error] [pid 643573:tid 643751] [client 57.141.0.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_2PxWyxgRnoFKAJ_gtwAAAj0"]
[Thu Jul 30 11:46:16.801255 2026] [security2:error] [pid 643573:tid 643816] [client 176.241.66.87:52286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_2PxWyxgRnoFKAJ_gvgAAAn4"]
[Thu Jul 30 11:46:16.801395 2026] [security2:error] [pid 643573:tid 643816] [client 176.241.66.87:52286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_2PxWyxgRnoFKAJ_gvgAAAn4"]
[Thu Jul 30 11:46:17.673096 2026] [core:notice] [pid 643573:tid 643633] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:17.677007 2026] [security2:error] [pid 643573:tid 643728] [client 66.249.74.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/download/30/33/62"] [unique_id "amt_2fxWyxgRnoFKAJ_gxQACJjQ"]
[Thu Jul 30 11:46:18.832026 2026] [core:notice] [pid 642360:tid 642538] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:18.839693 2026] [security2:error] [pid 642360:tid 642538] [client 103.215.74.26:50870] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "767"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_2pSUkh3e5AhEJOBg5wAAAb8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:19.058717 2026] [security2:error] [pid 643573:tid 643723] [client 20.91.199.21:17889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-includes/images/about.php"] [unique_id "amt_2_xWyxgRnoFKAJ_g0wAAAiE"]
[Thu Jul 30 11:46:19.158890 2026] [security2:error] [pid 643573:tid 643824] [client 2407:d000:1c:9d56:64c4:87bd:6970:5a53:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_2vxWyxgRnoFKAJ_g0QAChjo"]
[Thu Jul 30 11:46:19.603049 2026] [core:notice] [pid 643573:tid 643823] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:19.609767 2026] [security2:error] [pid 643573:tid 643823] [client 103.215.74.26:50884] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_2_xWyxgRnoFKAJ_g2AAAAoU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:20.188436 2026] [security2:error] [pid 642360:tid 642590] [client 57.141.0.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt_25SUkh3e5AhEJOBg9wAAAfM"]
[Thu Jul 30 11:46:20.354743 2026] [core:notice] [pid 643573:tid 643778] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:20.358795 2026] [security2:error] [pid 643573:tid 643778] [client 103.215.74.26:50886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "780"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_3PxWyxgRnoFKAJ_g4QAAAlg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:20.855427 2026] [security2:error] [pid 643573:tid 643737] [client 20.91.199.21:5279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-includes/about.php"] [unique_id "amt_3PxWyxgRnoFKAJ_g7gAAAi8"]
[Thu Jul 30 11:46:21.060533 2026] [security2:error] [pid 643573:tid 643646] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_3fxWyxgRnoFKAJ_g7wACdUE"]
[Thu Jul 30 11:46:21.060702 2026] [security2:error] [pid 643573:tid 643807] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_3fxWyxgRnoFKAJ_g7wACdUE"]
[Thu Jul 30 11:46:21.094957 2026] [core:notice] [pid 642360:tid 642614] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:21.098958 2026] [security2:error] [pid 642360:tid 642614] [client 103.215.74.26:50890] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_3ZSUkh3e5AhEJOBhBwAAAgs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:21.843894 2026] [core:notice] [pid 643573:tid 643752] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:21.849017 2026] [security2:error] [pid 643573:tid 643752] [client 103.215.74.26:50906] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_3fxWyxgRnoFKAJ_hAQAAAj4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:21.892787 2026] [security2:error] [pid 643253:tid 643501] [client 20.91.199.21:5357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/cgi-bin/about.php"] [unique_id "amt_3cjqbtjBYzqM1uYkpgAAAHU"]
[Thu Jul 30 11:46:22.441445 2026] [security2:error] [pid 643573:tid 643773] [client 172.236.9.101:1924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3fxWyxgRnoFKAJ_g8wAAAlM"]
[Thu Jul 30 11:46:22.518658 2026] [security2:error] [pid 642360:tid 642507] [client 172.236.9.101:19046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3ZSUkh3e5AhEJOBhDAAAAaA"]
[Thu Jul 30 11:46:22.579428 2026] [core:notice] [pid 643573:tid 643725] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:22.584392 2026] [security2:error] [pid 643573:tid 643725] [client 103.215.74.26:50916] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_3vxWyxgRnoFKAJ_hDAAAAiM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:22.614175 2026] [security2:error] [pid 642360:tid 642493] [client 116.204.97.72:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt_3pSUkh3e5AhEJOBhIgAAAZI"]
[Thu Jul 30 11:46:23.248418 2026] [security2:error] [pid 643573:tid 643738] [client 172.236.9.101:56153] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3fxWyxgRnoFKAJ_g_AAAAjA"]
[Thu Jul 30 11:46:23.259245 2026] [security2:error] [pid 643573:tid 643719] [client 172.236.9.101:35642] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3fxWyxgRnoFKAJ_g-QAAAh0"]
[Thu Jul 30 11:46:23.261300 2026] [security2:error] [pid 643573:tid 643818] [client 172.236.9.101:22691] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3fxWyxgRnoFKAJ_g9wAAAoA"]
[Thu Jul 30 11:46:23.264603 2026] [security2:error] [pid 643573:tid 643745] [client 172.236.9.101:32960] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3fxWyxgRnoFKAJ_g-gAAAjc"]
[Thu Jul 30 11:46:23.271213 2026] [security2:error] [pid 643573:tid 643786] [client 172.236.9.101:31225] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3fxWyxgRnoFKAJ_g9gAAAmA"]
[Thu Jul 30 11:46:23.272381 2026] [security2:error] [pid 643573:tid 643741] [client 172.236.9.101:42166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3fxWyxgRnoFKAJ_g9QAAAjM"]
[Thu Jul 30 11:46:23.292396 2026] [security2:error] [pid 643573:tid 643832] [client 172.236.9.101:39467] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3fxWyxgRnoFKAJ_g-wAAAo4"]
[Thu Jul 30 11:46:23.295176 2026] [security2:error] [pid 643573:tid 643779] [client 172.236.9.101:33872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3fxWyxgRnoFKAJ_g9AAAAlk"]
[Thu Jul 30 11:46:23.328391 2026] [core:notice] [pid 643573:tid 643814] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:23.328998 2026] [security2:error] [pid 643573:tid 643758] [client 172.236.9.101:28960] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3fxWyxgRnoFKAJ_g-AAAAkQ"]
[Thu Jul 30 11:46:23.332416 2026] [security2:error] [pid 643253:tid 643432] [client 172.236.9.101:2354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3cjqbtjBYzqM1uYkowAAADA"]
[Thu Jul 30 11:46:23.340140 2026] [security2:error] [pid 643573:tid 643814] [client 103.215.74.26:40566] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_3_xWyxgRnoFKAJ_hFgAAAnw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:23.363803 2026] [security2:error] [pid 643573:tid 643803] [client 172.236.9.101:24879] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3fxWyxgRnoFKAJ_g_gAAAnE"]
[Thu Jul 30 11:46:23.410232 2026] [security2:error] [pid 643573:tid 643835] [client 172.236.9.101:10873] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3fxWyxgRnoFKAJ_g_QAAApE"]
[Thu Jul 30 11:46:23.667503 2026] [core:notice] [pid 643573:tid 643757] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:23.687956 2026] [security2:error] [pid 642360:tid 642372] [remote 47.128.27.31:53344] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/nike-victori-one-slide-2/"] [unique_id "amt_35SUkh3e5AhEJOBhLwABuws"]
[Thu Jul 30 11:46:23.882589 2026] [security2:error] [pid 643253:tid 643483] [client 57.141.0.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_38jqbtjBYzqM1uYkrwAAAGM"]
[Thu Jul 30 11:46:23.896805 2026] [security2:error] [pid 643573:tid 643703] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_3_xWyxgRnoFKAJ_hGgACc3o"]
[Thu Jul 30 11:46:23.896921 2026] [security2:error] [pid 643573:tid 643805] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_3_xWyxgRnoFKAJ_hGgACc3o"]
[Thu Jul 30 11:46:24.069921 2026] [core:notice] [pid 642360:tid 642542] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:24.075190 2026] [security2:error] [pid 642360:tid 642542] [client 103.215.74.26:40582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_4JSUkh3e5AhEJOBhMwAAAcM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:24.111139 2026] [core:notice] [pid 642360:tid 642611] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:24.388096 2026] [core:notice] [pid 643573:tid 643793] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:24.438461 2026] [security2:error] [pid 642360:tid 642508] [client 172.236.9.101:5643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3pSUkh3e5AhEJOBhGgAAAaE"]
[Thu Jul 30 11:46:24.445837 2026] [security2:error] [pid 643253:tid 643496] [client 172.236.9.101:42939] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3sjqbtjBYzqM1uYkqAAAAHA"]
[Thu Jul 30 11:46:24.446766 2026] [security2:error] [pid 643573:tid 643794] [client 172.236.9.101:49692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3vxWyxgRnoFKAJ_hBgAAAmg"]
[Thu Jul 30 11:46:24.463694 2026] [security2:error] [pid 642360:tid 642608] [client 172.236.9.101:11798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3pSUkh3e5AhEJOBhIQAAAgU"]
[Thu Jul 30 11:46:24.481738 2026] [security2:error] [pid 643253:tid 643401] [client 172.236.9.101:56242] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3sjqbtjBYzqM1uYkpwAAABE"]
[Thu Jul 30 11:46:24.498269 2026] [security2:error] [pid 642360:tid 642602] [client 172.236.9.101:47896] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3pSUkh3e5AhEJOBhGwAAAf8"]
[Thu Jul 30 11:46:24.603751 2026] [security2:error] [pid 643253:tid 643390] [client 172.236.9.101:36301] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3sjqbtjBYzqM1uYkqgAAAAY"]
[Thu Jul 30 11:46:24.622898 2026] [security2:error] [pid 643573:tid 643718] [client 172.236.9.101:3040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3vxWyxgRnoFKAJ_hBQAAAhw"]
[Thu Jul 30 11:46:24.633005 2026] [security2:error] [pid 642360:tid 642559] [client 172.236.9.101:19319] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3pSUkh3e5AhEJOBhIwAAAdQ"]
[Thu Jul 30 11:46:24.638097 2026] [security2:error] [pid 643253:tid 643509] [client 172.236.9.101:19260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3sjqbtjBYzqM1uYkqQAAAH0"]
[Thu Jul 30 11:46:24.639019 2026] [security2:error] [pid 643573:tid 643722] [client 172.236.9.101:1158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3vxWyxgRnoFKAJ_hCAAAAiA"]
[Thu Jul 30 11:46:24.645830 2026] [security2:error] [pid 643253:tid 643506] [client 172.236.9.101:42268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3sjqbtjBYzqM1uYkqwAAAHo"]
[Thu Jul 30 11:46:24.646855 2026] [security2:error] [pid 642360:tid 642549] [client 172.236.9.101:45611] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3pSUkh3e5AhEJOBhHwAAAco"]
[Thu Jul 30 11:46:24.649451 2026] [security2:error] [pid 643573:tid 643727] [client 172.236.9.101:60277] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3vxWyxgRnoFKAJ_hCgAAAiU"]
[Thu Jul 30 11:46:24.650084 2026] [security2:error] [pid 643573:tid 643750] [client 172.236.9.101:25464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3vxWyxgRnoFKAJ_hCQAAAjw"]
[Thu Jul 30 11:46:24.669951 2026] [security2:error] [pid 642360:tid 642523] [client 172.236.9.101:46549] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3pSUkh3e5AhEJOBhJQAAAbA"]
[Thu Jul 30 11:46:25.241800 2026] [security2:error] [pid 643253:tid 643400] [client 172.236.9.101:28925] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3sjqbtjBYzqM1uYkrAAAABA"]
[Thu Jul 30 11:46:25.252562 2026] [security2:error] [pid 643573:tid 643751] [client 172.236.9.101:19711] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3vxWyxgRnoFKAJ_hCwAAAj0"]
[Thu Jul 30 11:46:25.280492 2026] [security2:error] [pid 642360:tid 642531] [client 172.236.9.101:53194] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3pSUkh3e5AhEJOBhJAAAAbg"]
[Thu Jul 30 11:46:25.939021 2026] [core:error] [pid 643573:tid 643742] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:46:25.939043 2026] [core:error] [pid 643573:tid 643742] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:46:25.940132 2026] [core:error] [pid 643573:tid 643720] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:46:25.940155 2026] [core:error] [pid 643573:tid 643720] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:46:26.004097 2026] [core:error] [pid 643573:tid 643833] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:46:26.004123 2026] [core:error] [pid 643573:tid 643833] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:46:26.769624 2026] [security2:error] [pid 642360:tid 642615] [client 20.91.199.21:3765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/gallery/about.php"] [unique_id "amt_4pSUkh3e5AhEJOBhTwAAAgw"]
[Thu Jul 30 11:46:27.322081 2026] [security2:error] [pid 643573:tid 643817] [client 176.241.66.87:60680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_4_xWyxgRnoFKAJ_hNAAAAn8"]
[Thu Jul 30 11:46:27.322233 2026] [security2:error] [pid 643573:tid 643817] [client 176.241.66.87:60680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_4_xWyxgRnoFKAJ_hNAAAAn8"]
[Thu Jul 30 11:46:27.495649 2026] [security2:error] [pid 642360:tid 642423] [remote 41.210.146.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amt_4pSUkh3e5AhEJOBhUwABjz4"], referer: https://flixon.net/lost-password/
[Thu Jul 30 11:46:28.326556 2026] [security2:error] [pid 643573:tid 643800] [client 57.129.81.227:39140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.81.129.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/board.php"] [unique_id "amt_5PxWyxgRnoFKAJ_hPQAAAm4"]
[Thu Jul 30 11:46:28.493865 2026] [security2:error] [pid 643573:tid 643791] [client 141.94.76.134:38800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.76.94.141.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/board.php"] [unique_id "amt_5PxWyxgRnoFKAJ_hQgAAAmU"]
[Thu Jul 30 11:46:29.245143 2026] [security2:error] [pid 643573:tid 643782] [client 145.239.83.37:42402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.83.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/board.php"] [unique_id "amt_5fxWyxgRnoFKAJ_hVQAAAlw"]
[Thu Jul 30 11:46:29.523296 2026] [security2:error] [pid 643573:tid 643808] [client 217.182.77.22:41252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.77.182.217.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/board.php"] [unique_id "amt_5fxWyxgRnoFKAJ_hZwAAAnY"]
[Thu Jul 30 11:46:29.539570 2026] [security2:error] [pid 643573:tid 643751] [client 172.237.109.114:43499] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_5PxWyxgRnoFKAJ_hUgAAAj0"]
[Thu Jul 30 11:46:29.548393 2026] [security2:error] [pid 643573:tid 643830] [client 172.237.109.114:40858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_5PxWyxgRnoFKAJ_hUwAAAow"]
[Thu Jul 30 11:46:29.582040 2026] [security2:error] [pid 643573:tid 643732] [client 57.129.81.224:52166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.81.129.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/board.php"] [unique_id "amt_5fxWyxgRnoFKAJ_haAAAAio"]
[Thu Jul 30 11:46:29.601765 2026] [security2:error] [pid 643573:tid 643725] [client 172.237.109.114:21453] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_5PxWyxgRnoFKAJ_hVAAAAiM"]
[Thu Jul 30 11:46:29.604772 2026] [security2:error] [pid 643573:tid 643795] [client 172.237.109.114:9134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_5fxWyxgRnoFKAJ_hVgAAAmk"]
[Thu Jul 30 11:46:29.644958 2026] [security2:error] [pid 642360:tid 642612] [client 172.237.109.114:20980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_5ZSUkh3e5AhEJOBhYwAAAgk"]
[Thu Jul 30 11:46:29.717729 2026] [security2:error] [pid 643573:tid 643731] [client 57.141.0.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_5fxWyxgRnoFKAJ_hZgAAAik"]
[Thu Jul 30 11:46:29.945773 2026] [core:notice] [pid 643573:tid 643797] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:29.952693 2026] [security2:error] [pid 643573:tid 643797] [client 103.215.74.26:40584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_5fxWyxgRnoFKAJ_hawAAAms"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:30.038018 2026] [security2:error] [pid 643573:tid 643818] [client 213.32.68.81:52994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.68.32.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/board.php"] [unique_id "amt_5vxWyxgRnoFKAJ_hbAAAAoA"]
[Thu Jul 30 11:46:30.682273 2026] [core:notice] [pid 643573:tid 643769] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:30.687646 2026] [security2:error] [pid 643573:tid 643769] [client 103.215.74.26:40598] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_5vxWyxgRnoFKAJ_hdQAAAk8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:30.827137 2026] [security2:error] [pid 643253:tid 643360] [remote 185.95.156.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.156.95.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mskabir.com"] [uri "/wp-login.php"] [unique_id "amt_5sjqbtjBYzqM1uYkwQAAA2k"]
[Thu Jul 30 11:46:31.410535 2026] [core:notice] [pid 643253:tid 643435] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:31.417823 2026] [security2:error] [pid 643253:tid 643435] [client 103.215.74.26:40602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_58jqbtjBYzqM1uYkxAAAADM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:31.680630 2026] [security2:error] [pid 642360:tid 642416] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_55SUkh3e5AhEJOBhegABrjc"]
[Thu Jul 30 11:46:31.680864 2026] [security2:error] [pid 642360:tid 642521] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_55SUkh3e5AhEJOBhegABrjc"]
[Thu Jul 30 11:46:31.769598 2026] [security2:error] [pid 643573:tid 643824] [client 172.236.9.101:25820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_5_xWyxgRnoFKAJ_hfgAAAoY"]
[Thu Jul 30 11:46:31.801782 2026] [security2:error] [pid 643573:tid 643780] [client 172.236.9.101:21279] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_5_xWyxgRnoFKAJ_hfwAAAlo"]
[Thu Jul 30 11:46:31.801782 2026] [security2:error] [pid 642360:tid 642543] [client 172.236.9.101:8439] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_55SUkh3e5AhEJOBhdwAAAcQ"]
[Thu Jul 30 11:46:31.823461 2026] [security2:error] [pid 642360:tid 642524] [client 172.236.9.101:37314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_55SUkh3e5AhEJOBheAAAAbE"]
[Thu Jul 30 11:46:32.122849 2026] [security2:error] [pid 642360:tid 642552] [client 20.91.199.21:18454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-includes/blocks/about.php"] [unique_id "amt_6JSUkh3e5AhEJOBhfwAAAc0"]
[Thu Jul 30 11:46:32.157126 2026] [core:notice] [pid 643573:tid 643756] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:32.161490 2026] [security2:error] [pid 643573:tid 643756] [client 103.215.74.26:40604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_6PxWyxgRnoFKAJ_hiQAAAkI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:32.882960 2026] [security2:error] [pid 643573:tid 643789] [client 112.86.225.178:45704] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/category/colunistas/ramalho-leite/"] [unique_id "amt_6PxWyxgRnoFKAJ_hmQAAAmM"]
[Thu Jul 30 11:46:32.883071 2026] [security2:error] [pid 643573:tid 643789] [client 112.86.225.178:45704] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/category/colunistas/ramalho-leite/"] [unique_id "amt_6PxWyxgRnoFKAJ_hmQAAAmM"]
[Thu Jul 30 11:46:32.888609 2026] [core:notice] [pid 643253:tid 643510] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:32.893945 2026] [security2:error] [pid 643253:tid 643510] [client 103.215.74.26:40612] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_6MjqbtjBYzqM1uYkywAAAH4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:33.441898 2026] [security2:error] [pid 642360:tid 642608] [client 172.236.9.101:10193] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_6JSUkh3e5AhEJOBhggAAAgU"]
[Thu Jul 30 11:46:33.476371 2026] [security2:error] [pid 643253:tid 643451] [client 172.236.9.101:19826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_6MjqbtjBYzqM1uYkxQAAAEM"]
[Thu Jul 30 11:46:33.490173 2026] [security2:error] [pid 643573:tid 643810] [client 172.236.9.101:40376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_6PxWyxgRnoFKAJ_hjQAAAng"]
[Thu Jul 30 11:46:33.507448 2026] [security2:error] [pid 643573:tid 643754] [client 172.236.9.101:37700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_6PxWyxgRnoFKAJ_hjAAAAkA"]
[Thu Jul 30 11:46:33.551115 2026] [security2:error] [pid 642360:tid 642602] [client 172.236.9.101:30561] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_6JSUkh3e5AhEJOBhgwAAAf8"]
[Thu Jul 30 11:46:33.572628 2026] [security2:error] [pid 643573:tid 643768] [client 172.236.9.101:21881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_6PxWyxgRnoFKAJ_hiwAAAk4"]
[Thu Jul 30 11:46:33.576412 2026] [security2:error] [pid 642360:tid 642586] [client 172.236.9.101:43547] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_6JSUkh3e5AhEJOBhhAAAAe8"]
[Thu Jul 30 11:46:33.582774 2026] [security2:error] [pid 643573:tid 643724] [client 172.236.9.101:1970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_6PxWyxgRnoFKAJ_hkgAAAiI"]
[Thu Jul 30 11:46:33.590239 2026] [security2:error] [pid 643573:tid 643809] [client 172.236.9.101:47323] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_6PxWyxgRnoFKAJ_hkAAAAnc"]
[Thu Jul 30 11:46:33.601382 2026] [security2:error] [pid 642360:tid 642574] [client 172.236.9.101:1447] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_6JSUkh3e5AhEJOBhhQAAAeM"]
[Thu Jul 30 11:46:33.602267 2026] [security2:error] [pid 643253:tid 643398] [client 172.236.9.101:60306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_6MjqbtjBYzqM1uYkxgAAAA4"]
[Thu Jul 30 11:46:33.603081 2026] [security2:error] [pid 643573:tid 643782] [client 172.236.9.101:2542] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_6PxWyxgRnoFKAJ_hlAAAAlw"]
[Thu Jul 30 11:46:33.607406 2026] [core:notice] [pid 642360:tid 642531] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:33.607677 2026] [security2:error] [pid 643573:tid 643816] [client 172.236.9.101:55538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_6PxWyxgRnoFKAJ_hjwAAAn4"]
[Thu Jul 30 11:46:33.608349 2026] [security2:error] [pid 643573:tid 643775] [client 172.236.9.101:35674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_6PxWyxgRnoFKAJ_hkwAAAlU"]
[Thu Jul 30 11:46:33.614523 2026] [security2:error] [pid 643573:tid 643813] [client 172.236.9.101:43680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_6PxWyxgRnoFKAJ_hkQAAAns"]
[Thu Jul 30 11:46:33.615425 2026] [security2:error] [pid 642360:tid 642531] [client 103.215.74.26:32938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_6ZSUkh3e5AhEJOBhkwAAAbg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:33.620659 2026] [security2:error] [pid 643573:tid 643822] [client 172.236.9.101:58756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_6PxWyxgRnoFKAJ_hjgAAAoQ"]
[Thu Jul 30 11:46:34.098394 2026] [security2:error] [pid 643573:tid 643784] [client 20.91.199.21:16334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-admin/css/about.php"] [unique_id "amt_6vxWyxgRnoFKAJ_hoQAAAl4"]
[Thu Jul 30 11:46:34.529701 2026] [security2:error] [pid 642360:tid 642541] [client 2a03:2880:f800:2f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_6ZSUkh3e5AhEJOBhlQABwh4"]
[Thu Jul 30 11:46:34.617500 2026] [security2:error] [pid 643253:tid 643472] [client 2a03:2880:f800:41:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_6cjqbtjBYzqM1uYkzgAAWG8"]
[Thu Jul 30 11:46:34.826009 2026] [security2:error] [pid 643573:tid 643686] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_6vxWyxgRnoFKAJ_hqgACk2k"]
[Thu Jul 30 11:46:34.826131 2026] [security2:error] [pid 643573:tid 643837] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_6vxWyxgRnoFKAJ_hqgACk2k"]
[Thu Jul 30 11:46:35.492183 2026] [security2:error] [pid 642360:tid 642451] [remote 57.141.0.25:57114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6164509415/feed/rss2/"] [unique_id "amt_65SUkh3e5AhEJOBhogABq1o"]
[Thu Jul 30 11:46:35.886424 2026] [security2:error] [pid 643253:tid 643484] [client 20.91.199.21:6934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-admin/images/about.php"] [unique_id "amt_68jqbtjBYzqM1uYk0gAAAGQ"]
[Thu Jul 30 11:46:36.821211 2026] [security2:error] [pid 643573:tid 643728] [client 20.91.199.21:12203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/.well-known/pki-validation/cloud.php"] [unique_id "amt_7PxWyxgRnoFKAJ_htgAAAiY"]
[Thu Jul 30 11:46:37.864059 2026] [security2:error] [pid 643573:tid 643822] [client 172.236.9.101:14388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_7fxWyxgRnoFKAJ_hugAAAoQ"]
[Thu Jul 30 11:46:38.073359 2026] [security2:error] [pid 643573:tid 643715] [client 176.241.66.87:61630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_7vxWyxgRnoFKAJ_hvgAAAhk"]
[Thu Jul 30 11:46:38.073491 2026] [security2:error] [pid 643573:tid 643715] [client 176.241.66.87:61630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_7vxWyxgRnoFKAJ_hvgAAAhk"]
[Thu Jul 30 11:46:38.353857 2026] [security2:error] [pid 642360:tid 642566] [client 74.7.228.27:60314] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ssl.zzt.temporary.site"] [uri "/robots.txt"] [unique_id "amt_7pSUkh3e5AhEJOBhvQAAAds"]
[Thu Jul 30 11:46:38.919458 2026] [security2:error] [pid 643573:tid 643824] [client 172.236.9.101:19026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_7vxWyxgRnoFKAJ_hwgAAAoY"]
[Thu Jul 30 11:46:38.924539 2026] [security2:error] [pid 643573:tid 643831] [client 172.236.9.101:30778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_7vxWyxgRnoFKAJ_hwAAAAo0"]
[Thu Jul 30 11:46:38.973721 2026] [security2:error] [pid 643573:tid 643769] [client 20.91.199.21:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/.well-known/acme-challenge/cloud.php"] [unique_id "amt_7vxWyxgRnoFKAJ_hxwAAAk8"]
[Thu Jul 30 11:46:38.993750 2026] [security2:error] [pid 643253:tid 643445] [client 172.236.9.101:3544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_7sjqbtjBYzqM1uYk0wAAAD0"]
[Thu Jul 30 11:46:38.994152 2026] [security2:error] [pid 643573:tid 643780] [client 172.236.9.101:3978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_7vxWyxgRnoFKAJ_hwQAAAlo"]
[Thu Jul 30 11:46:39.027249 2026] [security2:error] [pid 643573:tid 643796] [client 172.236.9.101:37115] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_7vxWyxgRnoFKAJ_hxAAAAmo"]
[Thu Jul 30 11:46:39.027249 2026] [security2:error] [pid 643573:tid 643752] [client 172.236.9.101:12249] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_7vxWyxgRnoFKAJ_hwwAAAj4"]
[Thu Jul 30 11:46:39.042023 2026] [security2:error] [pid 643573:tid 643726] [client 172.236.9.101:2117] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_7vxWyxgRnoFKAJ_hxQAAAiQ"]
[Thu Jul 30 11:46:39.244593 2026] [security2:error] [pid 643573:tid 643698] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amt_7_xWyxgRnoFKAJ_hygACJ3U"]
[Thu Jul 30 11:46:39.244800 2026] [security2:error] [pid 643573:tid 643729] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amt_7_xWyxgRnoFKAJ_hygACJ3U"]
[Thu Jul 30 11:46:39.354234 2026] [core:notice] [pid 642360:tid 642601] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:39.358543 2026] [security2:error] [pid 642360:tid 642601] [client 103.215.74.26:32942] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_75SUkh3e5AhEJOBhygAAAf4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:40.043158 2026] [security2:error] [pid 643573:tid 643624] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amt_8PxWyxgRnoFKAJ_h0AACLis"]
[Thu Jul 30 11:46:40.043358 2026] [security2:error] [pid 643573:tid 643736] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amt_8PxWyxgRnoFKAJ_h0AACLis"]
[Thu Jul 30 11:46:40.076095 2026] [core:notice] [pid 643253:tid 643427] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:40.081025 2026] [security2:error] [pid 643253:tid 643427] [client 103.215.74.26:32944] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_8MjqbtjBYzqM1uYk1QAAACs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:40.315720 2026] [security2:error] [pid 643573:tid 643702] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/xstelth.php"] [unique_id "amt_8PxWyxgRnoFKAJ_h0wACeHk"]
[Thu Jul 30 11:46:40.315960 2026] [security2:error] [pid 643573:tid 643810] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/xstelth.php"] [unique_id "amt_8PxWyxgRnoFKAJ_h0wACeHk"]
[Thu Jul 30 11:46:40.571564 2026] [security2:error] [pid 643573:tid 643695] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/584062352875874akp.php"] [unique_id "amt_8PxWyxgRnoFKAJ_h1QACQ3I"]
[Thu Jul 30 11:46:40.571734 2026] [security2:error] [pid 643573:tid 643757] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/584062352875874akp.php"] [unique_id "amt_8PxWyxgRnoFKAJ_h1QACQ3I"]
[Thu Jul 30 11:46:40.835397 2026] [core:notice] [pid 643573:tid 643809] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:40.839795 2026] [security2:error] [pid 643573:tid 643809] [client 103.215.74.26:32958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_8PxWyxgRnoFKAJ_h2AAAAnc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:40.909043 2026] [security2:error] [pid 643573:tid 643697] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/newfile.php"] [unique_id "amt_8PxWyxgRnoFKAJ_h2QACe3Q"]
[Thu Jul 30 11:46:40.909337 2026] [security2:error] [pid 643573:tid 643813] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/newfile.php"] [unique_id "amt_8PxWyxgRnoFKAJ_h2QACe3Q"]
[Thu Jul 30 11:46:41.024851 2026] [security2:error] [pid 643573:tid 643724] [client 66.249.74.74:36694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "supreme-hydraulics.com"] [uri "/index.php"] [unique_id "amt_8PxWyxgRnoFKAJ_h1wAAAiI"], referer: https://supreme-hydraulics.com/
[Thu Jul 30 11:46:41.195027 2026] [security2:error] [pid 643573:tid 643690] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/tBEZGQz.php"] [unique_id "amt_8fxWyxgRnoFKAJ_h3AACYW0"]
[Thu Jul 30 11:46:41.195193 2026] [security2:error] [pid 643573:tid 643787] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/tBEZGQz.php"] [unique_id "amt_8fxWyxgRnoFKAJ_h3AACYW0"]
[Thu Jul 30 11:46:41.212741 2026] [core:notice] [pid 643253:tid 643369] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:41.343853 2026] [security2:error] [pid 643573:tid 643828] [client 74.7.228.6:50106] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.ege.nyx.temporary.site"] [uri "/index.php"] [unique_id "amt_7_xWyxgRnoFKAJ_hywACiic"]
[Thu Jul 30 11:46:41.343882 2026] [security2:error] [pid 643573:tid 643828] [client 74.7.228.6:50106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ege.nyx.temporary.site"] [uri "/index.php"] [unique_id "amt_7_xWyxgRnoFKAJ_hywACiic"]
[Thu Jul 30 11:46:41.468462 2026] [security2:error] [pid 643573:tid 643740] [client 66.249.74.74:43533] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "supreme-hydraulics.com"] [uri "/index.php"] [unique_id "amt_8fxWyxgRnoFKAJ_h3QAAAjI"], referer: https://supreme-hydraulics.com/
[Thu Jul 30 11:46:41.587484 2026] [core:notice] [pid 642360:tid 642513] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:41.592005 2026] [security2:error] [pid 642360:tid 642513] [client 103.215.74.26:32974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_8ZSUkh3e5AhEJOBh5gAAAaY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:41.755608 2026] [security2:error] [pid 643573:tid 643807] [client 66.249.74.74:36694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "supreme-hydraulics.com"] [uri "/index.php"] [unique_id "amt_8fxWyxgRnoFKAJ_h4AAAAnU"], referer: https://supreme-hydraulics.com/
[Thu Jul 30 11:46:42.179442 2026] [security2:error] [pid 643573:tid 643675] [remote 190.6.176.90:49116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.176.6.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-login.php"] [unique_id "amt_8vxWyxgRnoFKAJ_h5gACc14"]
[Thu Jul 30 11:46:42.321569 2026] [security2:error] [pid 643573:tid 643704] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_8vxWyxgRnoFKAJ_h7QACens"]
[Thu Jul 30 11:46:42.321771 2026] [security2:error] [pid 643573:tid 643812] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_8vxWyxgRnoFKAJ_h7QACens"]
[Thu Jul 30 11:46:42.331597 2026] [core:notice] [pid 642360:tid 642529] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:42.335862 2026] [security2:error] [pid 642360:tid 642529] [client 103.215.74.26:32988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_8pSUkh3e5AhEJOBh7wAAAbY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:42.586667 2026] [security2:error] [pid 643573:tid 643714] [client 74.7.228.6:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "medaxco.com"] [uri "/index.php"] [unique_id "amt_8vxWyxgRnoFKAJ_h6QACGHc"], referer: https://www.ege.nyx.temporary.site/robots.txt
[Thu Jul 30 11:46:42.717097 2026] [security2:error] [pid 643573:tid 643711] [client 20.104.16.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_8fxWyxgRnoFKAJ_h3wACFXA"]
[Thu Jul 30 11:46:42.717143 2026] [security2:error] [pid 643573:tid 643711] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_8fxWyxgRnoFKAJ_h3wACFXA"]
[Thu Jul 30 11:46:42.734548 2026] [security2:error] [pid 642360:tid 642549] [client 20.91.199.21:5271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-admin/network/cloud.php"] [unique_id "amt_8pSUkh3e5AhEJOBh8wAAAco"]
[Thu Jul 30 11:46:42.743494 2026] [security2:error] [pid 643253:tid 643501] [client 57.141.0.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_8sjqbtjBYzqM1uYk2QAAAHU"]
[Thu Jul 30 11:46:43.071489 2026] [core:notice] [pid 643573:tid 643769] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:43.075424 2026] [security2:error] [pid 643573:tid 643769] [client 103.215.74.26:38796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_8_xWyxgRnoFKAJ_h9AAAAk8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:43.232589 2026] [security2:error] [pid 643573:tid 643707] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/drykl.php"] [unique_id "amt_8_xWyxgRnoFKAJ_h9gACRn4"]
[Thu Jul 30 11:46:43.232803 2026] [security2:error] [pid 643573:tid 643760] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/drykl.php"] [unique_id "amt_8_xWyxgRnoFKAJ_h9gACRn4"]
[Thu Jul 30 11:46:43.513345 2026] [security2:error] [pid 643573:tid 643701] [remote 194.116.184.179:17681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.184.116.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.gyj.djb.temporary.site"] [uri "/wp-login.php"] [unique_id "amt_8_xWyxgRnoFKAJ_h9wACWng"]
[Thu Jul 30 11:46:43.604112 2026] [autoindex:error] [pid 643573:tid 643706] [remote 20.104.16.169:0] AH01276: Cannot serve directory /home2/xncnyxte/public_html/website_32476423/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:46:43.604950 2026] [security2:error] [pid 643573:tid 643742] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "allmontecristi.com"] [uri "/cgi-sys/403.html"] [unique_id "amt_8_xWyxgRnoFKAJ_h-wACNH0"]
[Thu Jul 30 11:46:43.815937 2026] [core:notice] [pid 643573:tid 643732] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:43.819962 2026] [security2:error] [pid 643573:tid 643732] [client 103.215.74.26:38810] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_8_xWyxgRnoFKAJ_iAAAAAio"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:43.863803 2026] [security2:error] [pid 643573:tid 643788] [client 20.91.199.21:8644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/cloud.php"] [unique_id "amt_8_xWyxgRnoFKAJ_iAQAAAmI"]
[Thu Jul 30 11:46:43.905774 2026] [security2:error] [pid 643573:tid 643593] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/ls.php"] [unique_id "amt_8_xWyxgRnoFKAJ_iAgACKAw"]
[Thu Jul 30 11:46:43.905930 2026] [security2:error] [pid 643573:tid 643730] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/ls.php"] [unique_id "amt_8_xWyxgRnoFKAJ_iAgACKAw"]
[Thu Jul 30 11:46:44.126671 2026] [security2:error] [pid 643573:tid 643756] [client 54.87.112.51:24778] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amt_8vxWyxgRnoFKAJ_h8wAAAkI"], referer: https://globalmarks.pk/
[Thu Jul 30 11:46:44.227870 2026] [security2:error] [pid 643573:tid 643699] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/dx.php"] [unique_id "amt_9PxWyxgRnoFKAJ_iCAACf3Y"]
[Thu Jul 30 11:46:44.228116 2026] [security2:error] [pid 643573:tid 643817] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/dx.php"] [unique_id "amt_9PxWyxgRnoFKAJ_iCAACf3Y"]
[Thu Jul 30 11:46:44.537540 2026] [security2:error] [pid 643573:tid 643809] [client 20.91.199.21:3944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/cgi-bin/cloud.php"] [unique_id "amt_9PxWyxgRnoFKAJ_iCgAAAnc"]
[Thu Jul 30 11:46:44.544469 2026] [core:notice] [pid 643573:tid 643816] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:44.545961 2026] [security2:error] [pid 643573:tid 643589] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/mac.php"] [unique_id "amt_9PxWyxgRnoFKAJ_iDAACSQg"]
[Thu Jul 30 11:46:44.546116 2026] [security2:error] [pid 643573:tid 643763] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/mac.php"] [unique_id "amt_9PxWyxgRnoFKAJ_iDAACSQg"]
[Thu Jul 30 11:46:44.548824 2026] [security2:error] [pid 643573:tid 643816] [client 103.215.74.26:38826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_9PxWyxgRnoFKAJ_iCwAAAn4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:44.857411 2026] [security2:error] [pid 643573:tid 643585] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/485.php"] [unique_id "amt_9PxWyxgRnoFKAJ_iDgACggQ"]
[Thu Jul 30 11:46:44.857669 2026] [security2:error] [pid 643573:tid 643820] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/485.php"] [unique_id "amt_9PxWyxgRnoFKAJ_iDgACggQ"]
[Thu Jul 30 11:46:45.143150 2026] [security2:error] [pid 643573:tid 643586] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/gelio1.php"] [unique_id "amt_9fxWyxgRnoFKAJ_iDwACIQU"]
[Thu Jul 30 11:46:45.143376 2026] [security2:error] [pid 643573:tid 643723] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/gelio1.php"] [unique_id "amt_9fxWyxgRnoFKAJ_iDwACIQU"]
[Thu Jul 30 11:46:45.311649 2026] [core:notice] [pid 642360:tid 642566] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:45.318273 2026] [security2:error] [pid 642360:tid 642566] [client 103.215.74.26:38836] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_9ZSUkh3e5AhEJOBiEAAAAds"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:45.441512 2026] [security2:error] [pid 643573:tid 643651] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/lp6.php"] [unique_id "amt_9fxWyxgRnoFKAJ_iEwACgUY"]
[Thu Jul 30 11:46:45.441753 2026] [security2:error] [pid 643573:tid 643819] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/lp6.php"] [unique_id "amt_9fxWyxgRnoFKAJ_iEwACgUY"]
[Thu Jul 30 11:46:45.737157 2026] [security2:error] [pid 643573:tid 643622] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_9fxWyxgRnoFKAJ_iGAACQSk"]
[Thu Jul 30 11:46:45.737297 2026] [security2:error] [pid 643573:tid 643755] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_9fxWyxgRnoFKAJ_iGAACQSk"]
[Thu Jul 30 11:46:45.751244 2026] [security2:error] [pid 643573:tid 643587] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "amt_9fxWyxgRnoFKAJ_iGQACegY"]
[Thu Jul 30 11:46:45.751410 2026] [security2:error] [pid 643573:tid 643812] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "amt_9fxWyxgRnoFKAJ_iGQACegY"]
[Thu Jul 30 11:46:45.794927 2026] [security2:error] [pid 643573:tid 643727] [client 139.28.219.70:49260] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alseermarine.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amt_9fxWyxgRnoFKAJ_iGgAAAiU"]
[Thu Jul 30 11:46:46.044137 2026] [core:notice] [pid 643573:tid 643806] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:46.051734 2026] [security2:error] [pid 643573:tid 643806] [client 103.215.74.26:38842] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_9vxWyxgRnoFKAJ_iHgAAAnQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:46.061292 2026] [autoindex:error] [pid 643573:tid 643596] [remote 20.104.16.169:0] AH01276: Cannot serve directory /home2/xncnyxte/public_html/website_32476423/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:46:46.062135 2026] [security2:error] [pid 643573:tid 643737] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "allmontecristi.com"] [uri "/cgi-sys/403.html"] [unique_id "amt_9vxWyxgRnoFKAJ_iHwACLw8"]
[Thu Jul 30 11:46:46.279642 2026] [core:notice] [pid 643573:tid 643752] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:46.325059 2026] [security2:error] [pid 643573:tid 643796] [client 139.28.219.70:49270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/xmlrpc.php"] [unique_id "amt_9vxWyxgRnoFKAJ_iIwAAAmo"]
[Thu Jul 30 11:46:46.346727 2026] [security2:error] [pid 643573:tid 643623] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/w3llscc.php"] [unique_id "amt_9vxWyxgRnoFKAJ_iJAACaSo"]
[Thu Jul 30 11:46:46.346870 2026] [security2:error] [pid 643573:tid 643795] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/w3llscc.php"] [unique_id "amt_9vxWyxgRnoFKAJ_iJAACaSo"]
[Thu Jul 30 11:46:46.648107 2026] [security2:error] [pid 643573:tid 643600] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/miru3.php"] [unique_id "amt_9vxWyxgRnoFKAJ_iJwACYxM"]
[Thu Jul 30 11:46:46.648293 2026] [security2:error] [pid 643573:tid 643789] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/miru3.php"] [unique_id "amt_9vxWyxgRnoFKAJ_iJwACYxM"]
[Thu Jul 30 11:46:46.774388 2026] [core:notice] [pid 643573:tid 643771] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:46.778670 2026] [security2:error] [pid 643573:tid 643771] [client 103.215.74.26:38854] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_9vxWyxgRnoFKAJ_iKQAAAlE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:46.941409 2026] [core:notice] [pid 642360:tid 642398] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:46.956877 2026] [security2:error] [pid 643573:tid 643745] [client 139.28.219.70:49274] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alseermarine.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amt_9vxWyxgRnoFKAJ_iKwAAAjc"]
[Thu Jul 30 11:46:46.957084 2026] [security2:error] [pid 643573:tid 643608] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/autoload_classmap.php"] [unique_id "amt_9vxWyxgRnoFKAJ_iKgACXRs"]
[Thu Jul 30 11:46:46.957203 2026] [security2:error] [pid 643573:tid 643783] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/autoload_classmap.php"] [unique_id "amt_9vxWyxgRnoFKAJ_iKgACXRs"]
[Thu Jul 30 11:46:47.301414 2026] [security2:error] [pid 643573:tid 643756] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "allmontecristi.com"] [uri "/wp-content/index.php"] [unique_id "amt_9_xWyxgRnoFKAJ_iLgACQgk"]
[Thu Jul 30 11:46:47.511183 2026] [core:notice] [pid 643573:tid 643815] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:47.516228 2026] [security2:error] [pid 643573:tid 643815] [client 103.215.74.26:38860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "767"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_9_xWyxgRnoFKAJ_iMAAAAn0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:47.520311 2026] [security2:error] [pid 643573:tid 643739] [client 139.28.219.70:49290] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alseermarine.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amt_9_xWyxgRnoFKAJ_iMQAAAjE"]
[Thu Jul 30 11:46:47.634606 2026] [security2:error] [pid 643573:tid 643629] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-content/themes/index.php"] [unique_id "amt_9_xWyxgRnoFKAJ_iMwACezA"]
[Thu Jul 30 11:46:47.634809 2026] [security2:error] [pid 643573:tid 643813] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/wp-content/themes/index.php"] [unique_id "amt_9_xWyxgRnoFKAJ_iMwACezA"]
[Thu Jul 30 11:46:47.665716 2026] [security2:error] [pid 643573:tid 643778] [client 20.91.199.21:3763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/updates.php"] [unique_id "amt_9_xWyxgRnoFKAJ_iNAAAAlg"]
[Thu Jul 30 11:46:47.891176 2026] [security2:error] [pid 643573:tid 643616] [remote 208.122.213.225:53446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.213.122.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/wp-login.php"] [unique_id "amt_9_xWyxgRnoFKAJ_iNgACgCM"]
[Thu Jul 30 11:46:47.942591 2026] [security2:error] [pid 643573:tid 643605] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/av.php"] [unique_id "amt_9_xWyxgRnoFKAJ_iNwACMhg"]
[Thu Jul 30 11:46:47.942805 2026] [security2:error] [pid 643573:tid 643740] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/av.php"] [unique_id "amt_9_xWyxgRnoFKAJ_iNwACMhg"]
[Thu Jul 30 11:46:48.052813 2026] [security2:error] [pid 643573:tid 643748] [client 139.28.219.70:49304] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alseermarine.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amt_-PxWyxgRnoFKAJ_iOgAAAjo"]
[Thu Jul 30 11:46:48.238511 2026] [core:notice] [pid 643573:tid 643801] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:48.246148 2026] [security2:error] [pid 643573:tid 643801] [client 103.215.74.26:38866] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_-PxWyxgRnoFKAJ_iPgAAAm8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:48.272874 2026] [autoindex:error] [pid 643573:tid 643621] [remote 20.104.16.169:0] AH01276: Cannot serve directory /home2/xncnyxte/public_html/website_32476423/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:46:48.273661 2026] [security2:error] [pid 643573:tid 643715] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "allmontecristi.com"] [uri "/cgi-sys/403.html"] [unique_id "amt_-PxWyxgRnoFKAJ_iPwACGSg"]
[Thu Jul 30 11:46:48.578473 2026] [security2:error] [pid 643573:tid 643762] [client 139.28.219.70:49308] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alseermarine.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amt_-PxWyxgRnoFKAJ_iQQAAAkg"]
[Thu Jul 30 11:46:48.734544 2026] [security2:error] [pid 643573:tid 643827] [client 213.152.161.240:32890] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amt_-PxWyxgRnoFKAJ_iRAAAAok"]
[Thu Jul 30 11:46:48.734662 2026] [security2:error] [pid 643573:tid 643827] [client 213.152.161.240:32890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amt_-PxWyxgRnoFKAJ_iRAAAAok"]
[Thu Jul 30 11:46:48.846714 2026] [security2:error] [pid 642360:tid 642540] [client 176.241.66.87:62551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_-JSUkh3e5AhEJOBiMAAAAcE"]
[Thu Jul 30 11:46:48.846866 2026] [security2:error] [pid 642360:tid 642540] [client 176.241.66.87:62551] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_-JSUkh3e5AhEJOBiMAAAAcE"]
[Thu Jul 30 11:46:48.959867 2026] [core:notice] [pid 643573:tid 643718] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:48.964137 2026] [security2:error] [pid 643573:tid 643718] [client 103.215.74.26:38868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "780"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_-PxWyxgRnoFKAJ_iRgAAAhw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:49.213426 2026] [security2:error] [pid 643573:tid 643791] [client 20.104.16.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_-PxWyxgRnoFKAJ_iQgACZS8"]
[Thu Jul 30 11:46:49.213455 2026] [security2:error] [pid 643573:tid 643791] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_-PxWyxgRnoFKAJ_iQgACZS8"]
[Thu Jul 30 11:46:49.348889 2026] [security2:error] [pid 643573:tid 643711] [client 139.28.219.70:49322] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alseermarine.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amt_-fxWyxgRnoFKAJ_iSAAAAhU"]
[Thu Jul 30 11:46:49.693563 2026] [core:notice] [pid 642360:tid 642544] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:49.697665 2026] [security2:error] [pid 642360:tid 642544] [client 103.215.74.26:38872] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_-ZSUkh3e5AhEJOBiOQAAAcU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:49.763740 2026] [security2:error] [pid 643573:tid 643615] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/tiny.php"] [unique_id "amt_-fxWyxgRnoFKAJ_iTQACjiI"]
[Thu Jul 30 11:46:49.763927 2026] [security2:error] [pid 643573:tid 643832] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/tiny.php"] [unique_id "amt_-fxWyxgRnoFKAJ_iTQACjiI"]
[Thu Jul 30 11:46:50.001741 2026] [security2:error] [pid 643573:tid 643833] [client 139.28.219.70:49328] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alseermarine.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amt_-vxWyxgRnoFKAJ_iTwAAAo8"]
[Thu Jul 30 11:46:50.061663 2026] [security2:error] [pid 643573:tid 643609] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amt_-vxWyxgRnoFKAJ_iUAACKBw"]
[Thu Jul 30 11:46:50.061836 2026] [security2:error] [pid 643573:tid 643730] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amt_-vxWyxgRnoFKAJ_iUAACKBw"]
[Thu Jul 30 11:46:50.358692 2026] [security2:error] [pid 643573:tid 643604] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/zrrhj.php"] [unique_id "amt_-vxWyxgRnoFKAJ_iVgACKxc"]
[Thu Jul 30 11:46:50.358885 2026] [security2:error] [pid 643573:tid 643733] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/zrrhj.php"] [unique_id "amt_-vxWyxgRnoFKAJ_iVgACKxc"]
[Thu Jul 30 11:46:50.419314 2026] [core:notice] [pid 643573:tid 643761] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:50.423401 2026] [security2:error] [pid 643573:tid 643761] [client 103.215.74.26:38888] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_-vxWyxgRnoFKAJ_iVwAAAkc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:50.519847 2026] [security2:error] [pid 643573:tid 643815] [client 139.28.219.70:49344] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alseermarine.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amt_-vxWyxgRnoFKAJ_iWQAAAn0"]
[Thu Jul 30 11:46:50.690885 2026] [security2:error] [pid 643573:tid 643612] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amt_-vxWyxgRnoFKAJ_iWgACOh8"]
[Thu Jul 30 11:46:50.691129 2026] [security2:error] [pid 643573:tid 643748] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amt_-vxWyxgRnoFKAJ_iWgACOh8"]
[Thu Jul 30 11:46:50.748461 2026] [security2:error] [pid 642360:tid 642529] [client 172.236.9.101:7694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-pSUkh3e5AhEJOBiPQAAAbY"]
[Thu Jul 30 11:46:50.800059 2026] [security2:error] [pid 643573:tid 643782] [client 172.236.9.101:28831] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-vxWyxgRnoFKAJ_iVAAAAlw"]
[Thu Jul 30 11:46:50.866635 2026] [security2:error] [pid 643573:tid 643739] [client 172.236.9.101:65287] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-vxWyxgRnoFKAJ_iUwAAAjE"]
[Thu Jul 30 11:46:50.985689 2026] [security2:error] [pid 643573:tid 643588] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wpgum.php"] [unique_id "amt_-vxWyxgRnoFKAJ_iYAACiAc"]
[Thu Jul 30 11:46:50.985883 2026] [security2:error] [pid 643573:tid 643826] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/wpgum.php"] [unique_id "amt_-vxWyxgRnoFKAJ_iYAACiAc"]
[Thu Jul 30 11:46:50.995095 2026] [security2:error] [pid 643573:tid 643625] [remote 52.167.144.219:56963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/Edunomic/article/download/6852/public/journals/11/journalThumbnail_id_ID.jpg"] [unique_id "amt_-vxWyxgRnoFKAJ_iYQACFCw"]
[Thu Jul 30 11:46:51.043437 2026] [security2:error] [pid 643573:tid 643779] [client 139.28.219.70:39766] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alseermarine.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amt_-_xWyxgRnoFKAJ_iYwAAAlk"]
[Thu Jul 30 11:46:51.148426 2026] [core:notice] [pid 643573:tid 643834] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:51.155471 2026] [security2:error] [pid 643573:tid 643834] [client 103.215.74.26:38902] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_-_xWyxgRnoFKAJ_iZQAAApA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:51.286511 2026] [security2:error] [pid 643573:tid 643607] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/ywwbf.php"] [unique_id "amt_-_xWyxgRnoFKAJ_ibAAChho"]
[Thu Jul 30 11:46:51.286824 2026] [security2:error] [pid 643573:tid 643824] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/ywwbf.php"] [unique_id "amt_-_xWyxgRnoFKAJ_ibAAChho"]
[Thu Jul 30 11:46:51.611846 2026] [security2:error] [pid 643573:tid 643630] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/xoldj.php"] [unique_id "amt_-_xWyxgRnoFKAJ_ibwACaTE"]
[Thu Jul 30 11:46:51.612181 2026] [security2:error] [pid 643573:tid 643795] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/xoldj.php"] [unique_id "amt_-_xWyxgRnoFKAJ_ibwACaTE"]
[Thu Jul 30 11:46:51.650922 2026] [security2:error] [pid 643573:tid 643830] [client 139.28.219.70:39774] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alseermarine.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amt_-_xWyxgRnoFKAJ_icAAAAow"]
[Thu Jul 30 11:46:51.896893 2026] [security2:error] [pid 643573:tid 643631] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/f35.php"] [unique_id "amt_-_xWyxgRnoFKAJ_icgACYDI"]
[Thu Jul 30 11:46:51.897127 2026] [security2:error] [pid 643573:tid 643786] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/f35.php"] [unique_id "amt_-_xWyxgRnoFKAJ_icgACYDI"]
[Thu Jul 30 11:46:52.043934 2026] [security2:error] [pid 643573:tid 643800] [client 20.91.199.21:3950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/css/cloud.php"] [unique_id "amt__PxWyxgRnoFKAJ_icwAAAm4"]
[Thu Jul 30 11:46:52.409021 2026] [security2:error] [pid 643253:tid 643469] [client 139.28.219.70:39780] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alseermarine.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amt__MjqbtjBYzqM1uYk3QAAAFU"]
[Thu Jul 30 11:46:52.537751 2026] [security2:error] [pid 643573:tid 643770] [client 172.236.9.101:14221] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-_xWyxgRnoFKAJ_iZwAAAlA"]
[Thu Jul 30 11:46:52.538863 2026] [security2:error] [pid 643573:tid 643718] [client 172.236.9.101:9125] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-_xWyxgRnoFKAJ_iaAAAAhw"]
[Thu Jul 30 11:46:52.546927 2026] [security2:error] [pid 642360:tid 642490] [client 172.236.9.101:58683] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-5SUkh3e5AhEJOBiSAAAAY8"]
[Thu Jul 30 11:46:52.572926 2026] [security2:error] [pid 643573:tid 643773] [client 172.236.9.101:15722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-_xWyxgRnoFKAJ_iaQAAAlM"]
[Thu Jul 30 11:46:52.755443 2026] [security2:error] [pid 643573:tid 643809] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mgr3.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "amt__PxWyxgRnoFKAJ_ifAAAAnc"]
[Thu Jul 30 11:46:52.931395 2026] [security2:error] [pid 643573:tid 643777] [client 139.28.219.70:39796] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alseermarine.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amt__PxWyxgRnoFKAJ_ifgAAAlc"]
[Thu Jul 30 11:46:52.932260 2026] [core:notice] [pid 642360:tid 642425] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:52.936293 2026] [security2:error] [pid 643573:tid 643645] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt__PxWyxgRnoFKAJ_ifwACikA"]
[Thu Jul 30 11:46:52.936434 2026] [security2:error] [pid 643573:tid 643828] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt__PxWyxgRnoFKAJ_ifwACikA"]
[Thu Jul 30 11:46:52.999367 2026] [security2:error] [pid 643573:tid 643638] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/gk.php"] [unique_id "amt__PxWyxgRnoFKAJ_igAACMjk"]
[Thu Jul 30 11:46:52.999577 2026] [security2:error] [pid 643573:tid 643740] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/gk.php"] [unique_id "amt__PxWyxgRnoFKAJ_igAACMjk"]
[Thu Jul 30 11:46:53.228682 2026] [security2:error] [pid 643573:tid 643806] [client 172.236.9.101:19997] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-_xWyxgRnoFKAJ_iagAAAnQ"]
[Thu Jul 30 11:46:53.231414 2026] [security2:error] [pid 642360:tid 642589] [client 172.236.9.101:47716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-5SUkh3e5AhEJOBiRwAAAfI"]
[Thu Jul 30 11:46:53.231795 2026] [security2:error] [pid 642360:tid 642530] [client 172.236.9.101:64164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-5SUkh3e5AhEJOBiTAAAAbc"]
[Thu Jul 30 11:46:53.231898 2026] [security2:error] [pid 642360:tid 642558] [client 172.236.9.101:60377] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-5SUkh3e5AhEJOBiSQAAAdM"]
[Thu Jul 30 11:46:53.232855 2026] [security2:error] [pid 642360:tid 642571] [client 172.236.9.101:60326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-5SUkh3e5AhEJOBiSwAAAeA"]
[Thu Jul 30 11:46:53.235947 2026] [security2:error] [pid 642360:tid 642536] [client 172.236.9.101:15255] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-5SUkh3e5AhEJOBiTgAAAb0"]
[Thu Jul 30 11:46:53.241914 2026] [security2:error] [pid 642360:tid 642569] [client 172.236.9.101:1070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-5SUkh3e5AhEJOBiTwAAAd4"]
[Thu Jul 30 11:46:53.253882 2026] [security2:error] [pid 643573:tid 643837] [client 172.236.9.101:58508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-_xWyxgRnoFKAJ_iawAAApM"]
[Thu Jul 30 11:46:53.254148 2026] [security2:error] [pid 642360:tid 642556] [client 172.236.9.101:30976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-5SUkh3e5AhEJOBiSgAAAdE"]
[Thu Jul 30 11:46:53.267320 2026] [security2:error] [pid 642360:tid 642526] [client 172.236.9.101:17284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-5SUkh3e5AhEJOBiTQAAAbM"]
[Thu Jul 30 11:46:53.282147 2026] [security2:error] [pid 643573:tid 643744] [client 172.236.9.101:57513] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-_xWyxgRnoFKAJ_ibQAAAjY"]
[Thu Jul 30 11:46:53.294217 2026] [security2:error] [pid 643573:tid 643747] [client 172.236.9.101:16436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-_xWyxgRnoFKAJ_ibgAAAjk"]
[Thu Jul 30 11:46:53.297849 2026] [security2:error] [pid 643253:tid 643432] [client 172.236.9.101:12593] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-8jqbtjBYzqM1uYk2gAAADA"]
[Thu Jul 30 11:46:53.299155 2026] [security2:error] [pid 643573:tid 643641] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/584062352875874akp.php"] [unique_id "amt__fxWyxgRnoFKAJ_ihAACbzw"]
[Thu Jul 30 11:46:53.299386 2026] [security2:error] [pid 643573:tid 643801] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/584062352875874akp.php"] [unique_id "amt__fxWyxgRnoFKAJ_ihAACbzw"]
[Thu Jul 30 11:46:53.601970 2026] [security2:error] [pid 643573:tid 643633] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wper3.php"] [unique_id "amt__fxWyxgRnoFKAJ_ihwACIDQ"]
[Thu Jul 30 11:46:53.602186 2026] [security2:error] [pid 643573:tid 643722] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/wper3.php"] [unique_id "amt__fxWyxgRnoFKAJ_ihwACIDQ"]
[Thu Jul 30 11:46:53.906039 2026] [security2:error] [pid 643573:tid 643650] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/bthil.php"] [unique_id "amt__fxWyxgRnoFKAJ_ijQACTUU"]
[Thu Jul 30 11:46:53.906252 2026] [security2:error] [pid 643573:tid 643767] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/bthil.php"] [unique_id "amt__fxWyxgRnoFKAJ_ijQACTUU"]
[Thu Jul 30 11:46:54.210087 2026] [security2:error] [pid 643573:tid 643647] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wyzer1.php"] [unique_id "amt__vxWyxgRnoFKAJ_ikwACdkI"]
[Thu Jul 30 11:46:54.210261 2026] [security2:error] [pid 643573:tid 643808] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/wyzer1.php"] [unique_id "amt__vxWyxgRnoFKAJ_ikwACdkI"]
[Thu Jul 30 11:46:54.492996 2026] [security2:error] [pid 643573:tid 643751] [client 20.91.199.21:3912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-admin/user/cloud.php"] [unique_id "amt__vxWyxgRnoFKAJ_ilQAAAj0"]
[Thu Jul 30 11:46:54.494210 2026] [security2:error] [pid 643573:tid 643581] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/mh.php"] [unique_id "amt__vxWyxgRnoFKAJ_ilgACMAA"]
[Thu Jul 30 11:46:54.494343 2026] [security2:error] [pid 643573:tid 643738] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/mh.php"] [unique_id "amt__vxWyxgRnoFKAJ_ilgACMAA"]
[Thu Jul 30 11:46:54.796569 2026] [security2:error] [pid 643573:tid 643652] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amt__vxWyxgRnoFKAJ_ilwACa0c"]
[Thu Jul 30 11:46:54.796860 2026] [security2:error] [pid 643573:tid 643797] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amt__vxWyxgRnoFKAJ_ilwACa0c"]
[Thu Jul 30 11:46:55.105813 2026] [security2:error] [pid 643573:tid 643658] [remote 20.104.16.169:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "allmontecristi.com"] [uri "/1.php"] [unique_id "amt___xWyxgRnoFKAJ_ioAACg00"]
[Thu Jul 30 11:46:55.105940 2026] [security2:error] [pid 643573:tid 643658] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/1.php"] [unique_id "amt___xWyxgRnoFKAJ_ioAACg00"]
[Thu Jul 30 11:46:55.106120 2026] [security2:error] [pid 643573:tid 643821] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/1.php"] [unique_id "amt___xWyxgRnoFKAJ_ioAACg00"]
[Thu Jul 30 11:46:55.391242 2026] [security2:error] [pid 643573:tid 643661] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/chosen.php"] [unique_id "amt___xWyxgRnoFKAJ_iowACJlA"]
[Thu Jul 30 11:46:55.391407 2026] [security2:error] [pid 643573:tid 643728] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/chosen.php"] [unique_id "amt___xWyxgRnoFKAJ_iowACJlA"]
[Thu Jul 30 11:46:55.676669 2026] [security2:error] [pid 643573:tid 643668] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/sd.php"] [unique_id "amt___xWyxgRnoFKAJ_iqAACU1c"]
[Thu Jul 30 11:46:55.676845 2026] [security2:error] [pid 643573:tid 643773] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/sd.php"] [unique_id "amt___xWyxgRnoFKAJ_iqAACU1c"]
[Thu Jul 30 11:46:55.814887 2026] [security2:error] [pid 643573:tid 643718] [client 20.91.199.21:22285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/img/cloud.php"] [unique_id "amt___xWyxgRnoFKAJ_iqQAAAhw"]
[Thu Jul 30 11:46:55.993747 2026] [security2:error] [pid 643573:tid 643671] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/z60.php"] [unique_id "amt___xWyxgRnoFKAJ_irAACfVo"]
[Thu Jul 30 11:46:55.993957 2026] [security2:error] [pid 643573:tid 643815] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/z60.php"] [unique_id "amt___xWyxgRnoFKAJ_irAACfVo"]
[Thu Jul 30 11:46:56.286714 2026] [security2:error] [pid 643573:tid 643632] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/home.php"] [unique_id "amuAAPxWyxgRnoFKAJ_isAACgjM"]
[Thu Jul 30 11:46:56.286990 2026] [security2:error] [pid 643573:tid 643820] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/home.php"] [unique_id "amuAAPxWyxgRnoFKAJ_isAACgjM"]
[Thu Jul 30 11:46:56.536491 2026] [security2:error] [pid 643253:tid 643458] [client 20.91.199.21:3745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "amuAAMjqbtjBYzqM1uYk4QAAAEo"]
[Thu Jul 30 11:46:56.574411 2026] [security2:error] [pid 643573:tid 643644] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/ws58.php"] [unique_id "amuAAPxWyxgRnoFKAJ_isQACZj8"]
[Thu Jul 30 11:46:56.574568 2026] [security2:error] [pid 643573:tid 643792] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/ws58.php"] [unique_id "amuAAPxWyxgRnoFKAJ_isQACZj8"]
[Thu Jul 30 11:46:56.655400 2026] [security2:error] [pid 642360:tid 642427] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAAJSUkh3e5AhEJOBifAAB10I"]
[Thu Jul 30 11:46:56.655588 2026] [security2:error] [pid 642360:tid 642562] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAAJSUkh3e5AhEJOBifAAB10I"]
[Thu Jul 30 11:46:56.733388 2026] [security2:error] [pid 642360:tid 642568] [client 57.141.0.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuAAJSUkh3e5AhEJOBidgAAAd0"]
[Thu Jul 30 11:46:56.858478 2026] [security2:error] [pid 643573:tid 643591] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/gulu.php"] [unique_id "amuAAPxWyxgRnoFKAJ_iswACOQo"]
[Thu Jul 30 11:46:56.858634 2026] [security2:error] [pid 643573:tid 643747] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/gulu.php"] [unique_id "amuAAPxWyxgRnoFKAJ_iswACOQo"]
[Thu Jul 30 11:46:56.884340 2026] [core:notice] [pid 642360:tid 642591] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:56.888761 2026] [security2:error] [pid 642360:tid 642591] [client 103.215.74.26:30272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAAJSUkh3e5AhEJOBigAAAAfQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:57.144585 2026] [security2:error] [pid 643573:tid 643619] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuAAfxWyxgRnoFKAJ_itgACXiY"]
[Thu Jul 30 11:46:57.144760 2026] [security2:error] [pid 643573:tid 643784] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuAAfxWyxgRnoFKAJ_itgACXiY"]
[Thu Jul 30 11:46:57.436126 2026] [security2:error] [pid 643573:tid 643666] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wpls.php"] [unique_id "amuAAfxWyxgRnoFKAJ_iuAACSFU"]
[Thu Jul 30 11:46:57.436274 2026] [security2:error] [pid 643573:tid 643762] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/wpls.php"] [unique_id "amuAAfxWyxgRnoFKAJ_iuAACSFU"]
[Thu Jul 30 11:46:57.615125 2026] [core:notice] [pid 643573:tid 643812] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:57.618960 2026] [security2:error] [pid 643573:tid 643812] [client 103.215.74.26:30278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAAfxWyxgRnoFKAJ_iuwAAAno"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:57.703751 2026] [security2:error] [pid 642360:tid 642587] [client 57.141.0.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuAAZSUkh3e5AhEJOBihQAAAfA"]
[Thu Jul 30 11:46:57.738995 2026] [security2:error] [pid 643573:tid 643660] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/php.php"] [unique_id "amuAAfxWyxgRnoFKAJ_ivAACbE8"]
[Thu Jul 30 11:46:57.739198 2026] [security2:error] [pid 643573:tid 643798] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/php.php"] [unique_id "amuAAfxWyxgRnoFKAJ_ivAACbE8"]
[Thu Jul 30 11:46:57.920581 2026] [core:notice] [pid 643573:tid 643713] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:58.059459 2026] [security2:error] [pid 643573:tid 643672] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/100.php"] [unique_id "amuAAvxWyxgRnoFKAJ_ivwACZVs"]
[Thu Jul 30 11:46:58.059655 2026] [security2:error] [pid 643573:tid 643791] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/100.php"] [unique_id "amuAAvxWyxgRnoFKAJ_ivwACZVs"]
[Thu Jul 30 11:46:58.168882 2026] [security2:error] [pid 643573:tid 643757] [client 20.91.199.21:17896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-admin/images/cloud.php"] [unique_id "amuAAvxWyxgRnoFKAJ_iwAAAAkM"]
[Thu Jul 30 11:46:58.348723 2026] [security2:error] [pid 643573:tid 643664] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/BDKR28WP.php"] [unique_id "amuAAvxWyxgRnoFKAJ_iwwACeVM"]
[Thu Jul 30 11:46:58.348896 2026] [security2:error] [pid 643573:tid 643811] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/BDKR28WP.php"] [unique_id "amuAAvxWyxgRnoFKAJ_iwwACeVM"]
[Thu Jul 30 11:46:58.352149 2026] [core:notice] [pid 643573:tid 643746] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:58.356363 2026] [security2:error] [pid 643573:tid 643746] [client 103.215.74.26:30290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAAvxWyxgRnoFKAJ_ixAAAAjg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:59.016830 2026] [security2:error] [pid 643573:tid 643610] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/browse.php"] [unique_id "amuAA_xWyxgRnoFKAJ_iywACgx0"]
[Thu Jul 30 11:46:59.017090 2026] [security2:error] [pid 643573:tid 643821] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/browse.php"] [unique_id "amuAA_xWyxgRnoFKAJ_iywACgx0"]
[Thu Jul 30 11:46:59.079393 2026] [core:notice] [pid 643573:tid 643797] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:59.084359 2026] [security2:error] [pid 643573:tid 643797] [client 103.215.74.26:30304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAA_xWyxgRnoFKAJ_izAAAAms"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:59.306910 2026] [security2:error] [pid 643573:tid 643584] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-good.php"] [unique_id "amuAA_xWyxgRnoFKAJ_i0QACLgM"]
[Thu Jul 30 11:46:59.307115 2026] [security2:error] [pid 643573:tid 643736] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/wp-good.php"] [unique_id "amuAA_xWyxgRnoFKAJ_i0QACLgM"]
[Thu Jul 30 11:46:59.377161 2026] [security2:error] [pid 643573:tid 643836] [client 176.241.66.87:63423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAA_xWyxgRnoFKAJ_i0gAAApI"]
[Thu Jul 30 11:46:59.377308 2026] [security2:error] [pid 643573:tid 643836] [client 176.241.66.87:63423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAA_xWyxgRnoFKAJ_i0gAAApI"]
[Thu Jul 30 11:46:59.523083 2026] [security2:error] [pid 642360:tid 642575] [client 57.141.0.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuAApSUkh3e5AhEJOBikgAAAeQ"]
[Thu Jul 30 11:46:59.575847 2026] [security2:error] [pid 642360:tid 642547] [client 50.6.43.217:51330] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuAApSUkh3e5AhEJOBijQAAAcg"]
[Thu Jul 30 11:46:59.611244 2026] [security2:error] [pid 643573:tid 643599] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/8573.php"] [unique_id "amuAA_xWyxgRnoFKAJ_i1AACixI"]
[Thu Jul 30 11:46:59.611433 2026] [security2:error] [pid 643573:tid 643829] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/8573.php"] [unique_id "amuAA_xWyxgRnoFKAJ_i1AACixI"]
[Thu Jul 30 11:46:59.779882 2026] [security2:error] [pid 643573:tid 643764] [client 57.141.0.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuAA_xWyxgRnoFKAJ_izwAAAko"]
[Thu Jul 30 11:46:59.947880 2026] [security2:error] [pid 643573:tid 643682] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-admin/install.php"] [unique_id "amuAA_xWyxgRnoFKAJ_i2QACfmU"]
[Thu Jul 30 11:46:59.948092 2026] [security2:error] [pid 643573:tid 643816] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/wp-admin/install.php"] [unique_id "amuAA_xWyxgRnoFKAJ_i2QACfmU"]
[Thu Jul 30 11:47:00.240467 2026] [security2:error] [pid 642360:tid 642599] [client 20.91.199.21:4864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/avaa.php"] [unique_id "amuABJSUkh3e5AhEJOBingAAAfw"]
[Thu Jul 30 11:47:00.276102 2026] [security2:error] [pid 643573:tid 643680] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/classwithtostring.php"] [unique_id "amuABPxWyxgRnoFKAJ_i2wACZ2M"]
[Thu Jul 30 11:47:00.276272 2026] [security2:error] [pid 643573:tid 643793] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/classwithtostring.php"] [unique_id "amuABPxWyxgRnoFKAJ_i2wACZ2M"]
[Thu Jul 30 11:47:00.382838 2026] [security2:error] [pid 642360:tid 642561] [client 50.6.43.217:51346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuAA5SUkh3e5AhEJOBimQAAAdY"]
[Thu Jul 30 11:47:00.577556 2026] [security2:error] [pid 643573:tid 643603] [remote 97.74.93.24:45906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/wp-login.php"] [unique_id "amuABPxWyxgRnoFKAJ_i3gACVxY"]
[Thu Jul 30 11:47:00.587168 2026] [security2:error] [pid 643573:tid 643614] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/ohct.php"] [unique_id "amuABPxWyxgRnoFKAJ_i3wACOyE"]
[Thu Jul 30 11:47:00.587347 2026] [security2:error] [pid 643573:tid 643749] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/ohct.php"] [unique_id "amuABPxWyxgRnoFKAJ_i3wACOyE"]
[Thu Jul 30 11:47:00.907418 2026] [security2:error] [pid 643573:tid 643677] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/bless.php"] [unique_id "amuABPxWyxgRnoFKAJ_i4gACiWA"]
[Thu Jul 30 11:47:00.907633 2026] [security2:error] [pid 643573:tid 643827] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/bless.php"] [unique_id "amuABPxWyxgRnoFKAJ_i4gACiWA"]
[Thu Jul 30 11:47:00.978456 2026] [security2:error] [pid 643573:tid 643721] [client 2a03:2880:f800:24:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuAA_xWyxgRnoFKAJ_i1QACHxQ"]
[Thu Jul 30 11:47:01.218880 2026] [security2:error] [pid 643573:tid 643681] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/about.php"] [unique_id "amuABfxWyxgRnoFKAJ_i5gACRWQ"]
[Thu Jul 30 11:47:01.219122 2026] [security2:error] [pid 643573:tid 643759] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/about.php"] [unique_id "amuABfxWyxgRnoFKAJ_i5gACRWQ"]
[Thu Jul 30 11:47:01.379265 2026] [security2:error] [pid 643573:tid 643711] [client 20.91.199.21:4871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/images/cloud.php"] [unique_id "amuABfxWyxgRnoFKAJ_i6AAAAhU"]
[Thu Jul 30 11:47:01.538561 2026] [security2:error] [pid 643573:tid 643662] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuABfxWyxgRnoFKAJ_i7AACg1E"]
[Thu Jul 30 11:47:01.538715 2026] [security2:error] [pid 643573:tid 643821] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuABfxWyxgRnoFKAJ_i7AACg1E"]
[Thu Jul 30 11:47:01.888289 2026] [security2:error] [pid 643573:tid 643617] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/ta0ol.php"] [unique_id "amuABfxWyxgRnoFKAJ_i7wACYyQ"]
[Thu Jul 30 11:47:01.888452 2026] [security2:error] [pid 643573:tid 643789] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/ta0ol.php"] [unique_id "amuABfxWyxgRnoFKAJ_i7wACYyQ"]
[Thu Jul 30 11:47:02.185989 2026] [security2:error] [pid 643573:tid 643627] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/sa.php7"] [unique_id "amuABvxWyxgRnoFKAJ_i8gACSS4"]
[Thu Jul 30 11:47:02.186223 2026] [security2:error] [pid 643573:tid 643763] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/sa.php7"] [unique_id "amuABvxWyxgRnoFKAJ_i8gACSS4"]
[Thu Jul 30 11:47:02.269587 2026] [security2:error] [pid 643253:tid 643509] [client 20.91.199.21:16290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-admin/js/widgets/cloud.php"] [unique_id "amuABsjqbtjBYzqM1uYk5gAAAH0"]
[Thu Jul 30 11:47:02.488379 2026] [security2:error] [pid 643573:tid 643582] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-class.php"] [unique_id "amuABvxWyxgRnoFKAJ_i-AACIQE"]
[Thu Jul 30 11:47:02.488543 2026] [security2:error] [pid 643573:tid 643723] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/wp-class.php"] [unique_id "amuABvxWyxgRnoFKAJ_i-AACIQE"]
[Thu Jul 30 11:47:02.529632 2026] [security2:error] [pid 643573:tid 643597] [remote 57.141.0.55:28228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/407345907/feed/rss2/"] [unique_id "amuABvxWyxgRnoFKAJ_i-gACghA"]
[Thu Jul 30 11:47:02.649678 2026] [core:notice] [pid 643573:tid 643802] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:02.789315 2026] [security2:error] [pid 643573:tid 643613] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/8.php"] [unique_id "amuABvxWyxgRnoFKAJ_i_gACWSA"]
[Thu Jul 30 11:47:02.789540 2026] [security2:error] [pid 643573:tid 643779] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/8.php"] [unique_id "amuABvxWyxgRnoFKAJ_i_gACWSA"]
[Thu Jul 30 11:47:03.112570 2026] [security2:error] [pid 643573:tid 643595] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/bootstrap.php"] [unique_id "amuAB_xWyxgRnoFKAJ_jAQACPg4"]
[Thu Jul 30 11:47:03.112746 2026] [security2:error] [pid 643573:tid 643752] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/bootstrap.php"] [unique_id "amuAB_xWyxgRnoFKAJ_jAQACPg4"]
[Thu Jul 30 11:47:03.397866 2026] [security2:error] [pid 643573:tid 643686] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-blog-header.php"] [unique_id "amuAB_xWyxgRnoFKAJ_jBAACHWk"]
[Thu Jul 30 11:47:03.398064 2026] [security2:error] [pid 643573:tid 643719] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/wp-blog-header.php"] [unique_id "amuAB_xWyxgRnoFKAJ_jBAACHWk"]
[Thu Jul 30 11:47:03.546046 2026] [security2:error] [pid 643573:tid 643687] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAB_xWyxgRnoFKAJ_jBgACM2o"]
[Thu Jul 30 11:47:03.546253 2026] [security2:error] [pid 643573:tid 643741] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAB_xWyxgRnoFKAJ_jBgACM2o"]
[Thu Jul 30 11:47:03.702288 2026] [security2:error] [pid 643573:tid 643694] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/aa.php"] [unique_id "amuAB_xWyxgRnoFKAJ_jDAACQnE"]
[Thu Jul 30 11:47:03.702492 2026] [security2:error] [pid 643573:tid 643756] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/aa.php"] [unique_id "amuAB_xWyxgRnoFKAJ_jDAACQnE"]
[Thu Jul 30 11:47:03.819730 2026] [security2:error] [pid 643573:tid 643755] [client 20.91.199.21:45188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-includes/Requests/Text/admin.php"] [unique_id "amuAB_xWyxgRnoFKAJ_jDQAAAkE"]
[Thu Jul 30 11:47:03.967412 2026] [security2:error] [pid 642360:tid 642449] [remote 74.7.241.60:42596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/article.php"] [unique_id "amuAB5SUkh3e5AhEJOBiugAB6lg"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/bootstrap.bundle.min.js
[Thu Jul 30 11:47:04.004223 2026] [security2:error] [pid 643573:tid 643698] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/tx79.php"] [unique_id "amuACPxWyxgRnoFKAJ_jDgACi3U"]
[Thu Jul 30 11:47:04.004391 2026] [security2:error] [pid 643573:tid 643829] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/tx79.php"] [unique_id "amuACPxWyxgRnoFKAJ_jDgACi3U"]
[Thu Jul 30 11:47:04.327658 2026] [security2:error] [pid 643573:tid 643624] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/motu.php"] [unique_id "amuACPxWyxgRnoFKAJ_jEwACiis"]
[Thu Jul 30 11:47:04.327823 2026] [security2:error] [pid 643573:tid 643828] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/motu.php"] [unique_id "amuACPxWyxgRnoFKAJ_jEwACiis"]
[Thu Jul 30 11:47:04.632782 2026] [security2:error] [pid 643573:tid 643702] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-head.php"] [unique_id "amuACPxWyxgRnoFKAJ_jFQACVHk"]
[Thu Jul 30 11:47:04.632991 2026] [security2:error] [pid 643573:tid 643774] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/wp-head.php"] [unique_id "amuACPxWyxgRnoFKAJ_jFQACVHk"]
[Thu Jul 30 11:47:04.875172 2026] [core:notice] [pid 643253:tid 643421] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:04.879937 2026] [security2:error] [pid 643253:tid 643421] [client 103.215.74.26:23440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuACMjqbtjBYzqM1uYk5wAAACU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:05.040811 2026] [security2:error] [pid 643573:tid 643594] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuACfxWyxgRnoFKAJ_jGAACFA0"]
[Thu Jul 30 11:47:05.041080 2026] [security2:error] [pid 643573:tid 643710] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuACfxWyxgRnoFKAJ_jGAACFA0"]
[Thu Jul 30 11:47:05.341560 2026] [security2:error] [pid 643573:tid 643675] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/60856e3a4findex.php"] [unique_id "amuACfxWyxgRnoFKAJ_jHwACiV4"]
[Thu Jul 30 11:47:05.341723 2026] [security2:error] [pid 643573:tid 643827] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/60856e3a4findex.php"] [unique_id "amuACfxWyxgRnoFKAJ_jHwACiV4"]
[Thu Jul 30 11:47:05.421472 2026] [security2:error] [pid 643573:tid 643807] [client 20.91.199.21:3234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "amuACfxWyxgRnoFKAJ_jIQAAAnU"]
[Thu Jul 30 11:47:05.605675 2026] [security2:error] [pid 643573:tid 643685] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-the.php"] [unique_id "amuACfxWyxgRnoFKAJ_jJAACNGg"]
[Thu Jul 30 11:47:05.605874 2026] [security2:error] [pid 643573:tid 643742] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/wp-the.php"] [unique_id "amuACfxWyxgRnoFKAJ_jJAACNGg"]
[Thu Jul 30 11:47:05.609102 2026] [core:notice] [pid 643573:tid 643776] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:05.614072 2026] [security2:error] [pid 643573:tid 643776] [client 103.215.74.26:23444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuACfxWyxgRnoFKAJ_jJQAAAlY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:05.665542 2026] [autoindex:error] [pid 643573:tid 643719] [client 43.157.20.63:52436] AH01276: Cannot serve directory /home1/uixgzjte/public_html/chicago-mfg.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:47:05.886460 2026] [security2:error] [pid 643573:tid 643693] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp.php"] [unique_id "amuACfxWyxgRnoFKAJ_jLAACKHA"]
[Thu Jul 30 11:47:05.886614 2026] [security2:error] [pid 643573:tid 643730] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/wp.php"] [unique_id "amuACfxWyxgRnoFKAJ_jLAACKHA"]
[Thu Jul 30 11:47:06.089704 2026] [security2:error] [pid 643573:tid 643746] [client 2a03:2880:f800:3f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuACfxWyxgRnoFKAJ_jIgACOHs"]
[Thu Jul 30 11:47:06.147377 2026] [security2:error] [pid 643573:tid 643692] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/users.php"] [unique_id "amuACvxWyxgRnoFKAJ_jLQACYG8"]
[Thu Jul 30 11:47:06.147620 2026] [security2:error] [pid 643573:tid 643786] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/users.php"] [unique_id "amuACvxWyxgRnoFKAJ_jLQACYG8"]
[Thu Jul 30 11:47:06.354898 2026] [core:notice] [pid 643573:tid 643789] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:06.359291 2026] [security2:error] [pid 643573:tid 643789] [client 103.215.74.26:23452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuACvxWyxgRnoFKAJ_jMgAAAmM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:06.430958 2026] [security2:error] [pid 643573:tid 643701] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/tinysd.php"] [unique_id "amuACvxWyxgRnoFKAJ_jNAACfXg"]
[Thu Jul 30 11:47:06.431126 2026] [security2:error] [pid 643573:tid 643815] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/tinysd.php"] [unique_id "amuACvxWyxgRnoFKAJ_jNAACfXg"]
[Thu Jul 30 11:47:06.719631 2026] [security2:error] [pid 643573:tid 643706] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/ws78.php"] [unique_id "amuACvxWyxgRnoFKAJ_jNgACNn0"]
[Thu Jul 30 11:47:06.719772 2026] [security2:error] [pid 643573:tid 643744] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/ws78.php"] [unique_id "amuACvxWyxgRnoFKAJ_jNgACNn0"]
[Thu Jul 30 11:47:06.991928 2026] [security2:error] [pid 643573:tid 643649] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/elp.php"] [unique_id "amuACvxWyxgRnoFKAJ_jOAACXEQ"]
[Thu Jul 30 11:47:06.992146 2026] [security2:error] [pid 643573:tid 643782] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/elp.php"] [unique_id "amuACvxWyxgRnoFKAJ_jOAACXEQ"]
[Thu Jul 30 11:47:07.085139 2026] [core:notice] [pid 643573:tid 643739] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:07.089831 2026] [security2:error] [pid 643573:tid 643739] [client 103.215.74.26:23454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAC_xWyxgRnoFKAJ_jOQAAAjE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:07.283892 2026] [security2:error] [pid 643573:tid 643696] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/atomlib.php"] [unique_id "amuAC_xWyxgRnoFKAJ_jPQACjXM"]
[Thu Jul 30 11:47:07.284218 2026] [security2:error] [pid 643573:tid 643831] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/atomlib.php"] [unique_id "amuAC_xWyxgRnoFKAJ_jPQACjXM"]
[Thu Jul 30 11:47:07.527138 2026] [security2:error] [pid 643573:tid 643699] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAC_xWyxgRnoFKAJ_jPwACdXY"]
[Thu Jul 30 11:47:07.527318 2026] [security2:error] [pid 643573:tid 643807] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAC_xWyxgRnoFKAJ_jPwACdXY"]
[Thu Jul 30 11:47:07.575163 2026] [security2:error] [pid 643573:tid 643589] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wyzer3.php"] [unique_id "amuAC_xWyxgRnoFKAJ_jQAACHwg"]
[Thu Jul 30 11:47:07.575343 2026] [security2:error] [pid 643573:tid 643721] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/wyzer3.php"] [unique_id "amuAC_xWyxgRnoFKAJ_jQAACHwg"]
[Thu Jul 30 11:47:07.647781 2026] [core:error] [pid 643253:tid 643370] [remote 74.7.244.56:54136] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:47:07.647810 2026] [core:error] [pid 643253:tid 643370] [remote 74.7.244.56:54136] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:47:07.648002 2026] [security2:error] [pid 643253:tid 643399] [client 74.7.244.56:54136] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.website-d7e4058d.xdi.djb.temporary.site"] [uri "/website_d7e4058d/index.php"] [unique_id "amuAC8jqbtjBYzqM1uYk6QAAD3M"]
[Thu Jul 30 11:47:07.794612 2026] [core:notice] [pid 643573:tid 643785] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:07.822691 2026] [core:notice] [pid 643573:tid 643811] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:07.824669 2026] [security2:error] [pid 643573:tid 643825] [client 172.236.9.101:48305] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAC_xWyxgRnoFKAJ_jPAAAAoc"]
[Thu Jul 30 11:47:07.825424 2026] [security2:error] [pid 642360:tid 642551] [client 172.236.9.101:12038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAC5SUkh3e5AhEJOBi1QAAAcw"]
[Thu Jul 30 11:47:07.826008 2026] [security2:error] [pid 642360:tid 642582] [client 172.236.9.101:26530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAC5SUkh3e5AhEJOBi1AAAAes"]
[Thu Jul 30 11:47:07.827502 2026] [security2:error] [pid 643573:tid 643811] [client 103.215.74.26:23456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAC_xWyxgRnoFKAJ_jQwAAAnk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:07.845539 2026] [security2:error] [pid 643573:tid 643585] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/max.php"] [unique_id "amuAC_xWyxgRnoFKAJ_jRAACRQQ"]
[Thu Jul 30 11:47:07.845691 2026] [security2:error] [pid 643573:tid 643759] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/max.php"] [unique_id "amuAC_xWyxgRnoFKAJ_jRAACRQQ"]
[Thu Jul 30 11:47:08.120567 2026] [security2:error] [pid 643573:tid 643586] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/ftde.php"] [unique_id "amuADPxWyxgRnoFKAJ_jRwACHQU"]
[Thu Jul 30 11:47:08.120838 2026] [security2:error] [pid 643573:tid 643719] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/ftde.php"] [unique_id "amuADPxWyxgRnoFKAJ_jRwACHQU"]
[Thu Jul 30 11:47:08.345701 2026] [core:notice] [pid 643573:tid 643736] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:08.564880 2026] [core:notice] [pid 642360:tid 642554] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:08.572617 2026] [security2:error] [pid 642360:tid 642554] [client 103.215.74.26:23458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuADJSUkh3e5AhEJOBi4AAAAc8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:08.793881 2026] [security2:error] [pid 643573:tid 643771] [client 172.236.9.101:44577] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuADPxWyxgRnoFKAJ_jSAAAAlE"]
[Thu Jul 30 11:47:08.825304 2026] [security2:error] [pid 642360:tid 642607] [client 172.236.9.101:49529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuADJSUkh3e5AhEJOBi3gAAAgQ"]
[Thu Jul 30 11:47:08.836134 2026] [security2:error] [pid 643573:tid 643741] [client 172.236.9.101:13805] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuADPxWyxgRnoFKAJ_jSQAAAjM"]
[Thu Jul 30 11:47:08.864542 2026] [security2:error] [pid 643573:tid 643745] [client 172.236.9.101:26851] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuADPxWyxgRnoFKAJ_jSgAAAjc"]
[Thu Jul 30 11:47:08.914329 2026] [security2:error] [pid 643573:tid 643783] [client 172.236.9.101:24865] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuADPxWyxgRnoFKAJ_jTAAAAl0"]
[Thu Jul 30 11:47:08.921417 2026] [security2:error] [pid 643573:tid 643821] [client 172.236.9.101:65397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuADPxWyxgRnoFKAJ_jSwAAAoM"]
[Thu Jul 30 11:47:08.922272 2026] [security2:error] [pid 643573:tid 643835] [client 172.236.9.101:38776] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuADPxWyxgRnoFKAJ_jTgAAApE"]
[Thu Jul 30 11:47:08.939660 2026] [security2:error] [pid 643573:tid 643788] [client 172.236.9.101:5614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuADPxWyxgRnoFKAJ_jTQAAAmI"]
[Thu Jul 30 11:47:08.944714 2026] [security2:error] [pid 643573:tid 643786] [client 20.91.199.21:3878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-admin/includes/cloud.php"] [unique_id "amuADPxWyxgRnoFKAJ_jVQAAAmA"]
[Thu Jul 30 11:47:09.290802 2026] [security2:error] [pid 643573:tid 643744] [client 172.236.9.101:34618] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/ssl/private/alseermarine.com_key.pem"] [unique_id "amuADfxWyxgRnoFKAJ_jXQAAAjY"]
[Thu Jul 30 11:47:09.292653 2026] [core:notice] [pid 642360:tid 642535] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:09.302050 2026] [security2:error] [pid 642360:tid 642535] [client 103.215.74.26:23466] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuADZSUkh3e5AhEJOBi6QAAAbw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:09.828579 2026] [security2:error] [pid 643573:tid 643793] [client 172.236.9.101:18283] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuADfxWyxgRnoFKAJ_jWAAAAmc"]
[Thu Jul 30 11:47:09.840739 2026] [security2:error] [pid 643573:tid 643772] [client 172.236.9.101:6631] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuADfxWyxgRnoFKAJ_jWQAAAlI"]
[Thu Jul 30 11:47:09.847553 2026] [security2:error] [pid 643573:tid 643748] [client 172.236.9.101:35087] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuADfxWyxgRnoFKAJ_jVwAAAjo"]
[Thu Jul 30 11:47:09.847638 2026] [security2:error] [pid 643573:tid 643820] [client 172.236.9.101:11812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuADfxWyxgRnoFKAJ_jWwAAAoI"]
[Thu Jul 30 11:47:09.854828 2026] [security2:error] [pid 643573:tid 643806] [client 172.236.9.101:22263] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuADfxWyxgRnoFKAJ_jWgAAAnQ"]
[Thu Jul 30 11:47:09.870811 2026] [security2:error] [pid 642360:tid 642585] [client 172.236.9.101:19118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuADZSUkh3e5AhEJOBi6AAAAe4"]
[Thu Jul 30 11:47:09.872521 2026] [security2:error] [pid 643573:tid 643775] [client 172.236.9.101:12574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuADfxWyxgRnoFKAJ_jXAAAAlU"]
[Thu Jul 30 11:47:09.881784 2026] [security2:error] [pid 643573:tid 643747] [client 172.236.9.101:59906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuADfxWyxgRnoFKAJ_jXgAAAjk"]
[Thu Jul 30 11:47:10.021459 2026] [core:notice] [pid 643573:tid 643716] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:10.026670 2026] [security2:error] [pid 643573:tid 643716] [client 103.215.74.26:23470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuADvxWyxgRnoFKAJ_jZgAAAho"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:10.168708 2026] [security2:error] [pid 643573:tid 643798] [client 176.241.66.87:55020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuADvxWyxgRnoFKAJ_jaQAAAmw"]
[Thu Jul 30 11:47:10.168866 2026] [security2:error] [pid 643573:tid 643798] [client 176.241.66.87:55020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuADvxWyxgRnoFKAJ_jaQAAAmw"]
[Thu Jul 30 11:47:10.602742 2026] [security2:error] [pid 642360:tid 642530] [client 20.91.199.21:15900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-admin/css/colors/blue/cloud.php"] [unique_id "amuADpSUkh3e5AhEJOBi8gAAAbc"]
[Thu Jul 30 11:47:10.751693 2026] [core:notice] [pid 643573:tid 643779] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:10.757120 2026] [security2:error] [pid 643573:tid 643779] [client 103.215.74.26:23480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuADvxWyxgRnoFKAJ_jcQAAAlk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:10.771270 2026] [security2:error] [pid 642360:tid 642536] [client 2a03:2880:f800:32:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuADpSUkh3e5AhEJOBi7gABvWw"]
[Thu Jul 30 11:47:11.282176 2026] [security2:error] [pid 643573:tid 643821] [client 20.91.199.21:4868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-admin/cloud.php"] [unique_id "amuAD_xWyxgRnoFKAJ_jcwAAAoM"]
[Thu Jul 30 11:47:11.493095 2026] [core:notice] [pid 643573:tid 643732] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:11.497198 2026] [security2:error] [pid 643573:tid 643732] [client 103.215.74.26:23492] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAD_xWyxgRnoFKAJ_jeQAAAio"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:12.201549 2026] [security2:error] [pid 643573:tid 643623] [remote 57.141.0.9:63170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/85694478356/feed/rss2/"] [unique_id "amuAEPxWyxgRnoFKAJ_jgAACOSo"]
[Thu Jul 30 11:47:12.210737 2026] [security2:error] [pid 643573:tid 643827] [client 47.128.48.248:39884] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.hmhs.ph"] [uri "/robots.txt"] [unique_id "amuAEPxWyxgRnoFKAJ_jgQAAAok"]
[Thu Jul 30 11:47:12.215949 2026] [core:notice] [pid 643573:tid 643799] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:12.219943 2026] [security2:error] [pid 643573:tid 643799] [client 103.215.74.26:23494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAEPxWyxgRnoFKAJ_jggAAAm0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:12.869535 2026] [core:notice] [pid 643573:tid 643756] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:12.968546 2026] [core:notice] [pid 643573:tid 643726] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:12.973043 2026] [security2:error] [pid 643573:tid 643726] [client 103.215.74.26:23504] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAEPxWyxgRnoFKAJ_jiwAAAiQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:13.456429 2026] [security2:error] [pid 643573:tid 643736] [client 57.141.0.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuAEPxWyxgRnoFKAJ_jiAAAAi4"]
[Thu Jul 30 11:47:13.721857 2026] [core:notice] [pid 643573:tid 643778] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:13.728410 2026] [security2:error] [pid 643573:tid 643778] [client 103.215.74.26:4630] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAEfxWyxgRnoFKAJ_jjgAAAlg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:14.211897 2026] [security2:error] [pid 643573:tid 643608] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAEvxWyxgRnoFKAJ_jkgACihs"]
[Thu Jul 30 11:47:14.212108 2026] [security2:error] [pid 643573:tid 643828] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAEvxWyxgRnoFKAJ_jkgACihs"]
[Thu Jul 30 11:47:14.468055 2026] [security2:error] [pid 642360:tid 642503] [client 68.221.186.136:42574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/json.php"] [unique_id "amuAEpSUkh3e5AhEJOBjEQAAAZw"]
[Thu Jul 30 11:47:14.473116 2026] [core:notice] [pid 643573:tid 643815] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:14.479712 2026] [security2:error] [pid 643573:tid 643815] [client 103.215.74.26:4642] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAEvxWyxgRnoFKAJ_jlQAAAn0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:14.601240 2026] [security2:error] [pid 643573:tid 643837] [client 20.91.199.21:3708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/updates.php"] [unique_id "amuAEvxWyxgRnoFKAJ_jmAAAApM"]
[Thu Jul 30 11:47:15.229770 2026] [core:notice] [pid 643573:tid 643793] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:15.233807 2026] [security2:error] [pid 643573:tid 643793] [client 103.215.74.26:4650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAE_xWyxgRnoFKAJ_jnQAAAmc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:15.335705 2026] [security2:error] [pid 642360:tid 642602] [client 68.221.186.136:44356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/mini.php"] [unique_id "amuAE5SUkh3e5AhEJOBjGgAAAf8"]
[Thu Jul 30 11:47:15.407966 2026] [security2:error] [pid 642360:tid 642544] [client 20.91.199.21:6913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/libraries/legacy/updates.php"] [unique_id "amuAE5SUkh3e5AhEJOBjGwAAAcU"]
[Thu Jul 30 11:47:15.543119 2026] [security2:error] [pid 643573:tid 643777] [client 2a03:2880:f800:6:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuAEvxWyxgRnoFKAJ_jmgACVzA"]
[Thu Jul 30 11:47:15.974303 2026] [core:notice] [pid 643573:tid 643827] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:15.981180 2026] [security2:error] [pid 643573:tid 643827] [client 103.215.74.26:4652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "766"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAE_xWyxgRnoFKAJ_jpgAAAok"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:16.426390 2026] [security2:error] [pid 643573:tid 643780] [client 68.221.186.136:44126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/chosen.php"] [unique_id "amuAFPxWyxgRnoFKAJ_jrgAAAlo"]
[Thu Jul 30 11:47:16.710560 2026] [core:notice] [pid 643573:tid 643730] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:16.717347 2026] [security2:error] [pid 643573:tid 643730] [client 103.215.74.26:4658] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAFPxWyxgRnoFKAJ_jsQAAAig"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:16.801559 2026] [security2:error] [pid 642360:tid 642424] [remote 208.122.213.225:40632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.213.122.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp-login.php"] [unique_id "amuAFJSUkh3e5AhEJOBjJgAB2D8"]
[Thu Jul 30 11:47:17.464043 2026] [core:notice] [pid 643573:tid 643809] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:17.468761 2026] [security2:error] [pid 643573:tid 643809] [client 103.215.74.26:4660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "779"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAFfxWyxgRnoFKAJ_juAAAAnc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:17.877234 2026] [core:notice] [pid 643573:tid 643784] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:18.201832 2026] [core:notice] [pid 642360:tid 642589] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:18.207191 2026] [security2:error] [pid 642360:tid 642589] [client 103.215.74.26:4672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAFpSUkh3e5AhEJOBjNAAAAfI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:18.295157 2026] [security2:error] [pid 643253:tid 643474] [client 34.91.115.13:49152] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.alseermarine.com"] [uri "/"] [unique_id "amuAFsjqbtjBYzqM1uYk9AAAAFo"], referer: https://alseermarine.ae/
[Thu Jul 30 11:47:18.295244 2026] [security2:error] [pid 643253:tid 643474] [client 34.91.115.13:49152] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.alseermarine.com"] [uri "/"] [unique_id "amuAFsjqbtjBYzqM1uYk9AAAAFo"], referer: https://alseermarine.ae/
[Thu Jul 30 11:47:18.504727 2026] [security2:error] [pid 642360:tid 642432] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAFpSUkh3e5AhEJOBjNwABqEc"]
[Thu Jul 30 11:47:18.504931 2026] [security2:error] [pid 642360:tid 642515] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAFpSUkh3e5AhEJOBjNwABqEc"]
[Thu Jul 30 11:47:18.959516 2026] [core:notice] [pid 643573:tid 643713] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:18.963751 2026] [security2:error] [pid 643573:tid 643713] [client 103.215.74.26:4678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAFvxWyxgRnoFKAJ_jxwAAAhc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:19.491148 2026] [security2:error] [pid 643573:tid 643724] [client 20.91.199.21:5341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/libraries/phpmailer/updates.php"] [unique_id "amuAF_xWyxgRnoFKAJ_jzQAAAiI"]
[Thu Jul 30 11:47:19.682568 2026] [core:notice] [pid 643573:tid 643754] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:19.686618 2026] [security2:error] [pid 643573:tid 643754] [client 103.215.74.26:4690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "761"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAF_xWyxgRnoFKAJ_j0AAAAkA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:20.179137 2026] [security2:error] [pid 643573:tid 643816] [client 198.54.128.138:34936] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuAGPxWyxgRnoFKAJ_j1AAAAn4"]
[Thu Jul 30 11:47:20.179296 2026] [security2:error] [pid 643573:tid 643816] [client 198.54.128.138:34936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuAGPxWyxgRnoFKAJ_j1AAAAn4"]
[Thu Jul 30 11:47:20.278779 2026] [core:notice] [pid 643573:tid 643818] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:20.434478 2026] [security2:error] [pid 643573:tid 643722] [client 127.0.0.1:18536] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuAGPxWyxgRnoFKAJ_j2wAAAiA"]
[Thu Jul 30 11:47:20.434503 2026] [security2:error] [pid 643573:tid 643822] [client 127.0.0.1:18534] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.qpsuae.com"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuAGPxWyxgRnoFKAJ_j2gAAAoQ"]
[Thu Jul 30 11:47:20.434614 2026] [security2:error] [pid 642360:tid 642499] [client 74.7.228.50:40764] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.qpsuae.com"] [uri "/robots.txt"] [unique_id "amuAGJSUkh3e5AhEJOBjSAABmEo"]
[Thu Jul 30 11:47:20.436608 2026] [core:notice] [pid 643573:tid 643723] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:20.440989 2026] [security2:error] [pid 643573:tid 643723] [client 103.215.74.26:4700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAGPxWyxgRnoFKAJ_j3AAAAiE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:20.765675 2026] [security2:error] [pid 643253:tid 643435] [client 176.241.66.87:65487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAGMjqbtjBYzqM1uYk9QAAADM"]
[Thu Jul 30 11:47:20.765824 2026] [security2:error] [pid 643253:tid 643435] [client 176.241.66.87:65487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAGMjqbtjBYzqM1uYk9QAAADM"]
[Thu Jul 30 11:47:20.944795 2026] [core:notice] [pid 643573:tid 643799] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:21.161962 2026] [security2:error] [pid 642360:tid 642601] [client 152.232.72.98:48987] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "saifalkhaleejest.com"] [uri "/xmlrpc.php"] [unique_id "amuAGJSUkh3e5AhEJOBjTgAAAf4"]
[Thu Jul 30 11:47:21.162114 2026] [security2:error] [pid 642360:tid 642601] [client 152.232.72.98:48987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "saifalkhaleejest.com"] [uri "/xmlrpc.php"] [unique_id "amuAGJSUkh3e5AhEJOBjTgAAAf4"]
[Thu Jul 30 11:47:21.166210 2026] [core:notice] [pid 643573:tid 643769] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:21.170116 2026] [security2:error] [pid 643573:tid 643769] [client 103.215.74.26:4706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAGfxWyxgRnoFKAJ_j6gAAAk8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:21.171224 2026] [security2:error] [pid 643573:tid 643791] [client 103.253.27.196:61055] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ejournalugj.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuAGfxWyxgRnoFKAJ_j6wAAAmU"]
[Thu Jul 30 11:47:21.410947 2026] [security2:error] [pid 643573:tid 643710] [client 68.221.186.136:45302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/kj.php"] [unique_id "amuAGfxWyxgRnoFKAJ_j7gAAAhQ"]
[Thu Jul 30 11:47:21.417647 2026] [security2:error] [pid 643573:tid 643759] [client 20.91.199.21:3935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/libraries/vendor/updates.php"] [unique_id "amuAGfxWyxgRnoFKAJ_j7wAAAkU"]
[Thu Jul 30 11:47:22.039811 2026] [core:notice] [pid 642360:tid 642503] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:22.046044 2026] [security2:error] [pid 642360:tid 642503] [client 103.253.27.196:61120] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/xmlrpc.php"] [unique_id "amuAGZSUkh3e5AhEJOBjVwAAAZw"]
[Thu Jul 30 11:47:22.079634 2026] [security2:error] [pid 643573:tid 643768] [client 68.221.186.136:44961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/wp-files.php"] [unique_id "amuAGvxWyxgRnoFKAJ_j9gAAAk4"]
[Thu Jul 30 11:47:22.259003 2026] [core:notice] [pid 642360:tid 642597] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:22.286077 2026] [lsapi:error] [pid 643573:tid 643674] [remote 41.210.167.242:0] [host flixon.net] Error receiving response: ReceiveResponse: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1009; user ID 1009), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://flixon.net/video/keeper-vj-junior/
[Thu Jul 30 11:47:22.624252 2026] [security2:error] [pid 642360:tid 642610] [client 103.253.27.196:61120] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ejournalugj.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuAGpSUkh3e5AhEJOBjZAAAAgc"]
[Thu Jul 30 11:47:22.822032 2026] [security2:error] [pid 643253:tid 643480] [client 152.232.72.98:38532] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "saifalkhaleejest.com"] [uri "/xmlrpc.php"] [unique_id "amuAGsjqbtjBYzqM1uYk-wAAAGA"]
[Thu Jul 30 11:47:22.886846 2026] [core:notice] [pid 642360:tid 642541] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:23.049880 2026] [security2:error] [pid 643253:tid 643480] [client 152.232.72.98:38532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "saifalkhaleejest.com"] [uri "/xmlrpc.php"] [unique_id "amuAGsjqbtjBYzqM1uYk-wAAAGA"]
[Thu Jul 30 11:47:23.076124 2026] [security2:error] [pid 642360:tid 642613] [client 103.253.27.196:61215] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ejournalugj.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuAG5SUkh3e5AhEJOBjbQAAAgo"]
[Thu Jul 30 11:47:23.236559 2026] [security2:error] [pid 643573:tid 643749] [client 57.141.0.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuAGvxWyxgRnoFKAJ_j-gAAAjs"]
[Thu Jul 30 11:47:23.424267 2026] [security2:error] [pid 643573:tid 643820] [client 103.253.27.196:61233] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ejournalugj.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuAG_xWyxgRnoFKAJ_kBAAAAoI"]
[Thu Jul 30 11:47:23.728810 2026] [security2:error] [pid 643573:tid 643822] [client 116.172.248.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "marlboro-shop.com"] [uri "/index.php"] [unique_id "amuAGvxWyxgRnoFKAJ_j_gAAAoQ"]
[Thu Jul 30 11:47:24.029207 2026] [security2:error] [pid 643253:tid 643443] [client 103.253.27.196:61251] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ejournalugj.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuAHMjqbtjBYzqM1uYk_QAAADs"]
[Thu Jul 30 11:47:24.040545 2026] [security2:error] [pid 643573:tid 643744] [client 68.221.186.136:43027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/wp-setup.php"] [unique_id "amuAHPxWyxgRnoFKAJ_kEwAAAjY"]
[Thu Jul 30 11:47:24.203392 2026] [security2:error] [pid 643253:tid 643402] [client 103.253.27.196:61275] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ejournalugj.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuAHMjqbtjBYzqM1uYk_wAAABI"]
[Thu Jul 30 11:47:24.232324 2026] [security2:error] [pid 643573:tid 643731] [client 5.255.231.124:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuAHPxWyxgRnoFKAJ_kFgAAAik"]
[Thu Jul 30 11:47:24.235066 2026] [security2:error] [pid 643573:tid 643812] [client 57.141.0.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuAG_xWyxgRnoFKAJ_kCgAAAno"]
[Thu Jul 30 11:47:24.405947 2026] [security2:error] [pid 643573:tid 643783] [client 103.253.27.196:61285] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ejournalugj.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuAHPxWyxgRnoFKAJ_kGAAAAl0"]
[Thu Jul 30 11:47:24.427213 2026] [security2:error] [pid 643573:tid 643722] [client 20.91.199.21:17915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/alfa-rex.php7"] [unique_id "amuAHPxWyxgRnoFKAJ_kGQAAAiA"]
[Thu Jul 30 11:47:24.479804 2026] [security2:error] [pid 643253:tid 643398] [client 152.232.72.98:53927] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "saifalkhaleejest.com"] [uri "/xmlrpc.php"] [unique_id "amuAHMjqbtjBYzqM1uYlAAAAAA4"]
[Thu Jul 30 11:47:24.705320 2026] [security2:error] [pid 643253:tid 643398] [client 152.232.72.98:53927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "saifalkhaleejest.com"] [uri "/xmlrpc.php"] [unique_id "amuAHMjqbtjBYzqM1uYlAAAAAA4"]
[Thu Jul 30 11:47:24.753674 2026] [security2:error] [pid 643573:tid 643815] [client 103.253.27.196:61303] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ejournalugj.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuAHPxWyxgRnoFKAJ_kIAAAAn0"]
[Thu Jul 30 11:47:24.791320 2026] [security2:error] [pid 642360:tid 642585] [client 62.102.148.185:55518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marlboro-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAHJSUkh3e5AhEJOBjewAAAe4"]
[Thu Jul 30 11:47:24.791447 2026] [security2:error] [pid 642360:tid 642585] [client 62.102.148.185:55518] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marlboro-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAHJSUkh3e5AhEJOBjewAAAe4"]
[Thu Jul 30 11:47:24.868149 2026] [security2:error] [pid 642360:tid 642419] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAHJSUkh3e5AhEJOBjfAABszo"]
[Thu Jul 30 11:47:24.868365 2026] [security2:error] [pid 642360:tid 642526] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAHJSUkh3e5AhEJOBjfAABszo"]
[Thu Jul 30 11:47:25.088401 2026] [security2:error] [pid 642360:tid 642519] [client 103.253.27.196:61316] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ejournalugj.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuAHZSUkh3e5AhEJOBjgAAAAaw"]
[Thu Jul 30 11:47:25.496011 2026] [security2:error] [pid 643573:tid 643721] [client 103.253.27.196:61343] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ejournalugj.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuAHfxWyxgRnoFKAJ_kIwAAAh8"]
[Thu Jul 30 11:47:25.876567 2026] [security2:error] [pid 643573:tid 643795] [client 103.253.27.196:61363] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ejournalugj.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuAHfxWyxgRnoFKAJ_kKQAAAmk"]
[Thu Jul 30 11:47:26.001427 2026] [core:notice] [pid 642360:tid 642454] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:26.239175 2026] [security2:error] [pid 643573:tid 643810] [client 103.253.27.196:61378] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ejournalugj.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuAHvxWyxgRnoFKAJ_kLgAAAng"]
[Thu Jul 30 11:47:26.358028 2026] [security2:error] [pid 643253:tid 643493] [client 152.232.72.98:57810] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "saifalkhaleejest.com"] [uri "/xmlrpc.php"] [unique_id "amuAHsjqbtjBYzqM1uYlAQAAAG0"]
[Thu Jul 30 11:47:26.586138 2026] [security2:error] [pid 643253:tid 643493] [client 152.232.72.98:57810] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "saifalkhaleejest.com"] [uri "/xmlrpc.php"] [unique_id "amuAHsjqbtjBYzqM1uYlAQAAAG0"]
[Thu Jul 30 11:47:26.604138 2026] [security2:error] [pid 642360:tid 642502] [client 103.253.27.196:61401] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ejournalugj.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuAHpSUkh3e5AhEJOBjiQAAAZs"]
[Thu Jul 30 11:47:26.891283 2026] [core:notice] [pid 643573:tid 643771] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:26.895223 2026] [security2:error] [pid 643573:tid 643771] [client 103.215.74.26:39658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAHvxWyxgRnoFKAJ_kNwAAAlE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:26.985438 2026] [security2:error] [pid 642360:tid 642499] [client 103.253.27.196:61421] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ejournalugj.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuAHpSUkh3e5AhEJOBjjgAAAZg"]
[Thu Jul 30 11:47:27.394933 2026] [security2:error] [pid 643253:tid 643409] [client 103.253.27.196:61439] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ejournalugj.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuAH8jqbtjBYzqM1uYlBAAAABk"]
[Thu Jul 30 11:47:27.456189 2026] [security2:error] [pid 643573:tid 643789] [client 20.91.199.21:3879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/alfanew.php"] [unique_id "amuAH_xWyxgRnoFKAJ_kOgAAAmM"]
[Thu Jul 30 11:47:27.617567 2026] [core:notice] [pid 643573:tid 643740] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:27.622972 2026] [security2:error] [pid 643573:tid 643740] [client 103.215.74.26:39674] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAH_xWyxgRnoFKAJ_kPgAAAjI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:28.189308 2026] [security2:error] [pid 643253:tid 643447] [client 153.0.81.232:57412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "marlboro-shop.com"] [uri "/index.php"] [unique_id "amuAHsjqbtjBYzqM1uYlAgAAAFY"]
[Thu Jul 30 11:47:28.207244 2026] [security2:error] [pid 643573:tid 643806] [client 20.91.199.21:3873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/plugins/Cache/Cache.php"] [unique_id "amuAIPxWyxgRnoFKAJ_kRQAAAnQ"]
[Thu Jul 30 11:47:28.230364 2026] [security2:error] [pid 642360:tid 642533] [client 68.221.186.136:44358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/defaults.php"] [unique_id "amuAIJSUkh3e5AhEJOBjlwAAAbo"]
[Thu Jul 30 11:47:28.354423 2026] [core:notice] [pid 643573:tid 643769] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:28.362000 2026] [security2:error] [pid 643573:tid 643769] [client 103.215.74.26:39678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAIPxWyxgRnoFKAJ_kSQAAAk8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:28.477394 2026] [security2:error] [pid 642360:tid 642457] [remote 57.141.0.50:42940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuAIJSUkh3e5AhEJOBjnAABx2A"]
[Thu Jul 30 11:47:28.491365 2026] [security2:error] [pid 643573:tid 643747] [client 152.232.72.98:49795] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "saifalkhaleejest.com"] [uri "/xmlrpc.php"] [unique_id "amuAIPxWyxgRnoFKAJ_kSwAAAjk"]
[Thu Jul 30 11:47:28.719026 2026] [security2:error] [pid 643573:tid 643747] [client 152.232.72.98:49795] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "saifalkhaleejest.com"] [uri "/xmlrpc.php"] [unique_id "amuAIPxWyxgRnoFKAJ_kSwAAAjk"]
[Thu Jul 30 11:47:28.888654 2026] [security2:error] [pid 643573:tid 643768] [client 20.91.199.21:6947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-admin/js/widgets/about.php7"] [unique_id "amuAIPxWyxgRnoFKAJ_kZgAAAk4"]
[Thu Jul 30 11:47:29.112605 2026] [core:notice] [pid 643573:tid 643764] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:29.117124 2026] [security2:error] [pid 643573:tid 643764] [client 103.215.74.26:39680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAIfxWyxgRnoFKAJ_kbgAAAko"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:29.338891 2026] [security2:error] [pid 643573:tid 643765] [client 68.221.186.136:26708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/gtc.php"] [unique_id "amuAIfxWyxgRnoFKAJ_kcQAAAks"]
[Thu Jul 30 11:47:29.357208 2026] [security2:error] [pid 643573:tid 643735] [client 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAIPxWyxgRnoFKAJ_kVwACLVA"]
[Thu Jul 30 11:47:29.384121 2026] [security2:error] [pid 642360:tid 642446] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAIZSUkh3e5AhEJOBjogACB1U"]
[Thu Jul 30 11:47:29.384282 2026] [security2:error] [pid 642360:tid 642610] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAIZSUkh3e5AhEJOBjogACB1U"]
[Thu Jul 30 11:47:29.418740 2026] [security2:error] [pid 643573:tid 643584] [remote 57.141.0.36:42448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Signal/issue/view/571"] [unique_id "amuAIfxWyxgRnoFKAJ_kcgACFwM"]
[Thu Jul 30 11:47:29.537022 2026] [security2:error] [pid 642360:tid 642587] [client 20.91.199.21:3653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-p.php7"] [unique_id "amuAIZSUkh3e5AhEJOBjpQAAAfA"]
[Thu Jul 30 11:47:29.844709 2026] [core:notice] [pid 643573:tid 643715] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:29.849311 2026] [security2:error] [pid 643573:tid 643715] [client 103.215.74.26:39696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAIfxWyxgRnoFKAJ_kfQAAAhk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:30.582314 2026] [core:notice] [pid 643573:tid 643790] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:30.586638 2026] [security2:error] [pid 643573:tid 643790] [client 103.215.74.26:39698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAIvxWyxgRnoFKAJ_kgQAAAmQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:31.304938 2026] [core:notice] [pid 643573:tid 643811] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:31.309507 2026] [security2:error] [pid 643573:tid 643811] [client 103.215.74.26:39702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAI_xWyxgRnoFKAJ_khgAAAnk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:31.349470 2026] [security2:error] [pid 643573:tid 643793] [client 176.241.66.87:1931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAI_xWyxgRnoFKAJ_khwAAAmc"]
[Thu Jul 30 11:47:31.349615 2026] [security2:error] [pid 643573:tid 643793] [client 176.241.66.87:1931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAI_xWyxgRnoFKAJ_khwAAAmc"]
[Thu Jul 30 11:47:31.701692 2026] [security2:error] [pid 643573:tid 643741] [client 68.221.186.136:42599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/import.php"] [unique_id "amuAI_xWyxgRnoFKAJ_kigAAAjM"]
[Thu Jul 30 11:47:34.511804 2026] [security2:error] [pid 643573:tid 643771] [client 20.91.199.21:4905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-admin/repeater.php"] [unique_id "amuAJvxWyxgRnoFKAJ_koQAAAlE"]
[Thu Jul 30 11:47:35.451363 2026] [security2:error] [pid 643573:tid 643677] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAJ_xWyxgRnoFKAJ_ktwACKGA"]
[Thu Jul 30 11:47:35.451543 2026] [security2:error] [pid 643573:tid 643730] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAJ_xWyxgRnoFKAJ_ktwACKGA"]
[Thu Jul 30 11:47:35.942737 2026] [security2:error] [pid 642360:tid 642611] [client 2a03:2880:f800:29:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuAJ5SUkh3e5AhEJOBj0wACCHE"]
[Thu Jul 30 11:47:36.270367 2026] [core:notice] [pid 643253:tid 643407] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:36.337157 2026] [security2:error] [pid 643573:tid 643791] [client 20.91.199.21:13646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-includes/repeater.php"] [unique_id "amuAKPxWyxgRnoFKAJ_kxwAAAmU"]
[Thu Jul 30 11:47:36.563189 2026] [security2:error] [pid 642360:tid 642523] [client 57.141.0.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuAJ5SUkh3e5AhEJOBj2QAAAbA"]
[Thu Jul 30 11:47:37.025269 2026] [core:notice] [pid 642360:tid 642561] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:37.029876 2026] [security2:error] [pid 642360:tid 642561] [client 103.215.74.26:42712] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAKZSUkh3e5AhEJOBj5QAAAdY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:37.701458 2026] [security2:error] [pid 643253:tid 643486] [client 20.91.199.21:41085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/repeater.php"] [unique_id "amuAKcjqbtjBYzqM1uYlDgAAAGY"]
[Thu Jul 30 11:47:37.789617 2026] [core:notice] [pid 642360:tid 642610] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:37.793906 2026] [security2:error] [pid 642360:tid 642610] [client 103.215.74.26:42716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAKZSUkh3e5AhEJOBj8wAAAgc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:37.916959 2026] [security2:error] [pid 643573:tid 643711] [client 57.141.0.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuAKfxWyxgRnoFKAJ_k0AAAAhU"]
[Thu Jul 30 11:47:38.186073 2026] [security2:error] [pid 643573:tid 643742] [client 68.221.186.136:44371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/lufix.php"] [unique_id "amuAKvxWyxgRnoFKAJ_k2wAAAjQ"]
[Thu Jul 30 11:47:38.395156 2026] [security2:error] [pid 643573:tid 643787] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aaapropertiesph.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "amuAKvxWyxgRnoFKAJ_k3gAAAmE"]
[Thu Jul 30 11:47:38.522615 2026] [core:notice] [pid 642360:tid 642510] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:38.527356 2026] [security2:error] [pid 642360:tid 642510] [client 103.215.74.26:42724] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAKpSUkh3e5AhEJOBj_AAAAaM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:38.567215 2026] [core:notice] [pid 643573:tid 643698] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:39.098564 2026] [security2:error] [pid 643573:tid 643831] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aaapropertiesph.com"] [uri "/media/system/js/core.js"] [unique_id "amuAK_xWyxgRnoFKAJ_k5wAAAo0"]
[Thu Jul 30 11:47:39.175922 2026] [core:notice] [pid 643573:tid 643702] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:39.236570 2026] [security2:error] [pid 643573:tid 643747] [client 103.156.16.241:50373] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuAKvxWyxgRnoFKAJ_k4QAAAjk"]
[Thu Jul 30 11:47:39.260870 2026] [core:notice] [pid 643573:tid 643727] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:39.264878 2026] [security2:error] [pid 643573:tid 643727] [client 103.215.74.26:42730] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAK_xWyxgRnoFKAJ_k6gAAAiU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:39.956514 2026] [security2:error] [pid 643573:tid 643764] [client 57.141.0.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuAK_xWyxgRnoFKAJ_k7gAAAko"]
[Thu Jul 30 11:47:39.980049 2026] [core:notice] [pid 643573:tid 643735] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:39.983931 2026] [security2:error] [pid 643573:tid 643735] [client 103.215.74.26:42734] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "752"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAK_xWyxgRnoFKAJ_k9AAAAi0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:40.389584 2026] [security2:error] [pid 643573:tid 643827] [client 68.221.186.136:26948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/Geforce.php"] [unique_id "amuALPxWyxgRnoFKAJ_k-AAAAok"]
[Thu Jul 30 11:47:40.548287 2026] [security2:error] [pid 643573:tid 643697] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuALPxWyxgRnoFKAJ_k_AACWXQ"]
[Thu Jul 30 11:47:40.548449 2026] [security2:error] [pid 643573:tid 643779] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuALPxWyxgRnoFKAJ_k_AACWXQ"]
[Thu Jul 30 11:47:40.719223 2026] [core:notice] [pid 643573:tid 643713] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:40.723162 2026] [security2:error] [pid 643573:tid 643713] [client 103.215.74.26:42742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuALPxWyxgRnoFKAJ_k_QAAAhc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:41.448036 2026] [core:notice] [pid 643573:tid 643789] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:41.452506 2026] [security2:error] [pid 643573:tid 643789] [client 103.215.74.26:42744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuALfxWyxgRnoFKAJ_lCQAAAmM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:41.944261 2026] [security2:error] [pid 643573:tid 643813] [client 176.241.66.87:2788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuALfxWyxgRnoFKAJ_lEgAAAns"]
[Thu Jul 30 11:47:41.944393 2026] [security2:error] [pid 643573:tid 643813] [client 176.241.66.87:2788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuALfxWyxgRnoFKAJ_lEgAAAns"]
[Thu Jul 30 11:47:42.025530 2026] [core:notice] [pid 643573:tid 643830] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:42.190519 2026] [core:notice] [pid 643573:tid 643811] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:42.198400 2026] [security2:error] [pid 643573:tid 643811] [client 103.215.74.26:42754] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuALvxWyxgRnoFKAJ_lIAAAAnk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:42.274718 2026] [autoindex:error] [pid 643573:tid 643743] [client 185.247.137.125:0] AH01276: Cannot serve directory /home2/mbmudite/otbola.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.otbola.click:2086
[Thu Jul 30 11:47:42.596047 2026] [security2:error] [pid 643573:tid 643729] [client 180.163.29.217:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "marlboro-shop.com"] [uri "/index.php"] [unique_id "amuALfxWyxgRnoFKAJ_lDAAAAic"]
[Thu Jul 30 11:47:42.924805 2026] [core:notice] [pid 643573:tid 643714] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:42.932438 2026] [security2:error] [pid 643573:tid 643714] [client 103.215.74.26:42756] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuALvxWyxgRnoFKAJ_lJQAAAhg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:43.580936 2026] [proxy:error] [pid 643573:tid 643762] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:47:43.581023 2026] [proxy_http:error] [pid 643573:tid 643762] [client 44.216.125.112:12225] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:47:43.581594 2026] [proxy:error] [pid 643573:tid 643762] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:47:43.581638 2026] [proxy_http:error] [pid 643573:tid 643762] [client 44.216.125.112:12225] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:47:43.582657 2026] [autoindex:error] [pid 642360:tid 642577] [client 18.211.55.47:12735] AH01276: Cannot serve directory /home2/tvsnyxte/public_html/website_f8c1eb2c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:47:43.633334 2026] [autoindex:error] [pid 642360:tid 642586] [client 44.216.125.112:65052] AH01276: Cannot serve directory /home2/tvsnyxte/public_html/website_f8c1eb2c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:47:43.638251 2026] [autoindex:error] [pid 643573:tid 643740] [client 18.211.55.47:35560] AH01276: Cannot serve directory /home2/tvsnyxte/public_html/website_f8c1eb2c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:47:43.646718 2026] [proxy:error] [pid 643573:tid 643804] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:47:43.646793 2026] [proxy_http:error] [pid 643573:tid 643804] [client 18.211.55.47:63268] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:47:43.647371 2026] [proxy:error] [pid 643573:tid 643804] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:47:43.647417 2026] [proxy_http:error] [pid 643573:tid 643804] [client 18.211.55.47:63268] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:47:43.657535 2026] [core:notice] [pid 643573:tid 643790] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:43.661404 2026] [security2:error] [pid 643573:tid 643790] [client 103.215.74.26:19608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAL_xWyxgRnoFKAJ_lNAAAAmQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:43.996725 2026] [security2:error] [pid 643573:tid 643707] [remote 95.108.213.147:50408] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "spacexpress.africa"] [uri "/2024/02/27/enhancing-project-management-processes-with-business-consulting/"] [unique_id "amuAL_xWyxgRnoFKAJ_lOQACcX4"]
[Thu Jul 30 11:47:44.395374 2026] [core:notice] [pid 643573:tid 643716] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:44.399627 2026] [security2:error] [pid 643573:tid 643716] [client 103.215.74.26:19624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "768"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAMPxWyxgRnoFKAJ_lPgAAAho"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:44.438161 2026] [security2:error] [pid 643573:tid 643785] [client 68.221.186.136:43885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/a4.php"] [unique_id "amuAMPxWyxgRnoFKAJ_lPwAAAl8"]
[Thu Jul 30 11:47:45.133424 2026] [core:notice] [pid 643573:tid 643801] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:45.140783 2026] [security2:error] [pid 643573:tid 643801] [client 103.215.74.26:19634] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAMfxWyxgRnoFKAJ_lSQAAAm8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:45.239615 2026] [security2:error] [pid 643573:tid 643750] [client 68.221.186.136:27863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/011i.php"] [unique_id "amuAMfxWyxgRnoFKAJ_lSwAAAjw"]
[Thu Jul 30 11:47:45.871286 2026] [core:notice] [pid 643573:tid 643730] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:45.875349 2026] [security2:error] [pid 643573:tid 643730] [client 103.215.74.26:19644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "781"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAMfxWyxgRnoFKAJ_lUgAAAig"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:46.015223 2026] [security2:error] [pid 643573:tid 643705] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAMvxWyxgRnoFKAJ_lVwACXXw"]
[Thu Jul 30 11:47:46.015382 2026] [security2:error] [pid 643573:tid 643783] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAMvxWyxgRnoFKAJ_lVwACXXw"]
[Thu Jul 30 11:47:46.339130 2026] [security2:error] [pid 643573:tid 643797] [client 68.221.186.136:43494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/accueil.php"] [unique_id "amuAMvxWyxgRnoFKAJ_lWwAAAms"]
[Thu Jul 30 11:47:46.572460 2026] [security2:error] [pid 643573:tid 643802] [client 68.221.186.136:41254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/03a005685d.php"] [unique_id "amuAMvxWyxgRnoFKAJ_lXwAAAnA"]
[Thu Jul 30 11:47:46.609109 2026] [core:notice] [pid 643573:tid 643712] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:46.613255 2026] [security2:error] [pid 643573:tid 643712] [client 103.215.74.26:19646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAMvxWyxgRnoFKAJ_lYAAAAhY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:46.889723 2026] [security2:error] [pid 643573:tid 643772] [client 68.221.186.136:43066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/dashboard.php"] [unique_id "amuAMvxWyxgRnoFKAJ_lZwAAAlI"]
[Thu Jul 30 11:47:47.338131 2026] [core:notice] [pid 643573:tid 643819] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:47.342242 2026] [security2:error] [pid 643573:tid 643819] [client 103.215.74.26:19650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAM_xWyxgRnoFKAJ_lcQAAAoE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:47.674621 2026] [security2:error] [pid 642360:tid 642528] [client 68.221.186.136:44183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/radio.php"] [unique_id "amuAM5SUkh3e5AhEJOBkYAAAAbU"]
[Thu Jul 30 11:47:47.947356 2026] [security2:error] [pid 643573:tid 643747] [client 103.156.16.241:50373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuAKvxWyxgRnoFKAJ_k4QAAAjk"]
[Thu Jul 30 11:47:47.947419 2026] [security2:error] [pid 643573:tid 643747] [client 103.156.16.241:50373] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuAKvxWyxgRnoFKAJ_k4QAAAjk"]
[Thu Jul 30 11:47:48.058659 2026] [core:notice] [pid 642360:tid 642499] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:48.066938 2026] [security2:error] [pid 642360:tid 642499] [client 103.215.74.26:19664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuANJSUkh3e5AhEJOBkZQAAAZg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:48.265354 2026] [security2:error] [pid 643573:tid 643712] [client 68.221.186.136:44989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/wpsml-sys.php"] [unique_id "amuANPxWyxgRnoFKAJ_leQAAAhY"]
[Thu Jul 30 11:47:48.339209 2026] [security2:error] [pid 643573:tid 643815] [client 68.221.186.136:41238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/403.php"] [unique_id "amuANPxWyxgRnoFKAJ_lewAAAn0"]
[Thu Jul 30 11:47:48.437913 2026] [security2:error] [pid 643573:tid 643808] [client 2a03:2880:f800:39:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuAM_xWyxgRnoFKAJ_ldQACdhM"]
[Thu Jul 30 11:47:48.784355 2026] [security2:error] [pid 643253:tid 643432] [client 103.156.16.241:50586] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuANMjqbtjBYzqM1uYlFwAAADA"]
[Thu Jul 30 11:47:48.796065 2026] [core:notice] [pid 643573:tid 643792] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:48.803572 2026] [security2:error] [pid 643573:tid 643792] [client 103.215.74.26:19680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuANPxWyxgRnoFKAJ_lhQAAAmY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:48.815479 2026] [security2:error] [pid 643573:tid 643739] [client 57.141.0.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuANPxWyxgRnoFKAJ_lggAAAjE"]
[Thu Jul 30 11:47:48.940659 2026] [security2:error] [pid 643573:tid 643830] [client 68.221.186.136:41220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/404.php"] [unique_id "amuANPxWyxgRnoFKAJ_lhgAAAow"]
[Thu Jul 30 11:47:49.156439 2026] [security2:error] [pid 642360:tid 642584] [client 2a03:2880:f800:3e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuANJSUkh3e5AhEJOBkaAAB7S0"]
[Thu Jul 30 11:47:49.371007 2026] [security2:error] [pid 642360:tid 642566] [client 68.221.186.136:42580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/02.php"] [unique_id "amuANZSUkh3e5AhEJOBkdAAAAds"]
[Thu Jul 30 11:47:49.530372 2026] [core:notice] [pid 642360:tid 642577] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:49.536741 2026] [security2:error] [pid 642360:tid 642577] [client 103.215.74.26:19692] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuANZSUkh3e5AhEJOBkdQAAAeY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:49.641826 2026] [security2:error] [pid 643253:tid 643432] [client 103.156.16.241:50586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuANMjqbtjBYzqM1uYlFwAAADA"]
[Thu Jul 30 11:47:50.120479 2026] [security2:error] [pid 643573:tid 643758] [client 68.221.186.136:41229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/aa.php"] [unique_id "amuANvxWyxgRnoFKAJ_ljgAAAkQ"]
[Thu Jul 30 11:47:50.154785 2026] [security2:error] [pid 642360:tid 642587] [client 185.191.171.1:49266] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/03/17/carioca-flamengo-sai-da-frente-do-vasco-na-busca-de-vaga-para-a-final/"] [unique_id "amuANpSUkh3e5AhEJOBkfAAAAfA"]
[Thu Jul 30 11:47:50.154942 2026] [security2:error] [pid 642360:tid 642587] [client 185.191.171.1:49266] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/03/17/carioca-flamengo-sai-da-frente-do-vasco-na-busca-de-vaga-para-a-final/"] [unique_id "amuANpSUkh3e5AhEJOBkfAAAAfA"]
[Thu Jul 30 11:47:50.263400 2026] [core:notice] [pid 643573:tid 643725] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:50.269350 2026] [security2:error] [pid 643573:tid 643725] [client 103.215.74.26:19698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuANvxWyxgRnoFKAJ_lkAAAAiM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:50.768570 2026] [autoindex:error] [pid 643573:tid 643813] [client 207.175.47.108:61346] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_b1080a24/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:47:50.844265 2026] [security2:error] [pid 642360:tid 642518] [client 68.221.186.136:25309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/infos.php"] [unique_id "amuANpSUkh3e5AhEJOBkggAAAas"]
[Thu Jul 30 11:47:51.027042 2026] [core:notice] [pid 643573:tid 643744] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:51.031583 2026] [security2:error] [pid 643573:tid 643744] [client 103.215.74.26:19714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAN_xWyxgRnoFKAJ_lmgAAAjY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:51.298186 2026] [security2:error] [pid 643573:tid 643728] [client 68.221.186.136:41226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/aafewc0k.php"] [unique_id "amuAN_xWyxgRnoFKAJ_lnAAAAiY"]
[Thu Jul 30 11:47:51.360062 2026] [security2:error] [pid 643573:tid 643590] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAN_xWyxgRnoFKAJ_lngACbgk"]
[Thu Jul 30 11:47:51.360248 2026] [security2:error] [pid 643573:tid 643800] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAN_xWyxgRnoFKAJ_lngACbgk"]
[Thu Jul 30 11:47:51.725516 2026] [security2:error] [pid 642360:tid 642610] [client 68.221.186.136:44552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/updates.php"] [unique_id "amuAN5SUkh3e5AhEJOBkhwAAAgc"]
[Thu Jul 30 11:47:51.760465 2026] [core:notice] [pid 643573:tid 643810] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:51.764936 2026] [security2:error] [pid 643573:tid 643810] [client 103.215.74.26:19728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAN_xWyxgRnoFKAJ_loQAAAng"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:51.932412 2026] [security2:error] [pid 643573:tid 643820] [client 103.156.16.241:50632] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuAN_xWyxgRnoFKAJ_lowAAAoI"]
[Thu Jul 30 11:47:52.092575 2026] [security2:error] [pid 642360:tid 642547] [client 68.221.186.136:41237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/abcd.php"] [unique_id "amuAOJSUkh3e5AhEJOBkjgAAAcg"]
[Thu Jul 30 11:47:52.557382 2026] [security2:error] [pid 643253:tid 643454] [client 68.221.186.136:44572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/user.php"] [unique_id "amuAOMjqbtjBYzqM1uYlGgAAAEY"]
[Thu Jul 30 11:47:52.590063 2026] [security2:error] [pid 643253:tid 643458] [client 176.241.66.87:3587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAOMjqbtjBYzqM1uYlGwAAAEo"]
[Thu Jul 30 11:47:52.590193 2026] [security2:error] [pid 643253:tid 643458] [client 176.241.66.87:3587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAOMjqbtjBYzqM1uYlGwAAAEo"]
[Thu Jul 30 11:47:52.812200 2026] [security2:error] [pid 643573:tid 643820] [client 103.156.16.241:50632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuAN_xWyxgRnoFKAJ_lowAAAoI"]
[Thu Jul 30 11:47:52.928262 2026] [security2:error] [pid 642360:tid 642589] [client 68.221.186.136:41260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/about.php"] [unique_id "amuAOJSUkh3e5AhEJOBklgAAAfI"]
[Thu Jul 30 11:47:52.933775 2026] [security2:error] [pid 643573:tid 643740] [client 14.116.236.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "online-hope.com"] [uri "/index.php"] [unique_id "amuAOPxWyxgRnoFKAJ_lqwAAAjI"]
[Thu Jul 30 11:47:54.053038 2026] [security2:error] [pid 643573:tid 643598] [remote 5.161.62.209:7544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.otbola.click.mbm.udi.temporary.site"] [uri "/.env"] [unique_id "amuAOvxWyxgRnoFKAJ_lswACIBE"]
[Thu Jul 30 11:47:54.357184 2026] [security2:error] [pid 643573:tid 643765] [client 5.161.62.209:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.otbola.click"] [uri "/.env"] [unique_id "amuAOvxWyxgRnoFKAJ_luAAAAks"]
[Thu Jul 30 11:47:54.910543 2026] [security2:error] [pid 643573:tid 643740] [client 68.221.186.136:41268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/admin.php"] [unique_id "amuAOvxWyxgRnoFKAJ_lvgAAAjI"]
[Thu Jul 30 11:47:55.100400 2026] [security2:error] [pid 643573:tid 643785] [client 47.128.21.167:21790] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lark-shop.com"] [uri "/robots.txt"] [unique_id "amuAO_xWyxgRnoFKAJ_lwAAAAl8"]
[Thu Jul 30 11:47:55.441809 2026] [security2:error] [pid 643573:tid 643829] [client 103.156.16.241:50714] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuAO_xWyxgRnoFKAJ_lxAAAAos"]
[Thu Jul 30 11:47:55.636770 2026] [security2:error] [pid 643573:tid 643714] [client 68.221.186.136:43042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/admin-ajax.php"] [unique_id "amuAO_xWyxgRnoFKAJ_lxwAAAhg"]
[Thu Jul 30 11:47:55.994330 2026] [security2:error] [pid 643573:tid 643720] [client 68.221.186.136:41232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/adminfuns.php"] [unique_id "amuAO_xWyxgRnoFKAJ_lzQAAAh4"]
[Thu Jul 30 11:47:56.648192 2026] [security2:error] [pid 642360:tid 642442] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAPJSUkh3e5AhEJOBkuwAB_1E"]
[Thu Jul 30 11:47:56.648343 2026] [security2:error] [pid 642360:tid 642602] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAPJSUkh3e5AhEJOBkuwAB_1E"]
[Thu Jul 30 11:47:56.926522 2026] [security2:error] [pid 642360:tid 642497] [client 68.221.186.136:41279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/albin.php"] [unique_id "amuAPJSUkh3e5AhEJOBkvQAAAZY"]
[Thu Jul 30 11:47:56.929540 2026] [security2:error] [pid 643573:tid 643773] [client 62.102.148.185:43902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuAPPxWyxgRnoFKAJ_l3gAAAlM"]
[Thu Jul 30 11:47:56.929613 2026] [security2:error] [pid 643573:tid 643773] [client 62.102.148.185:43902] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuAPPxWyxgRnoFKAJ_l3gAAAlM"]
[Thu Jul 30 11:47:57.011648 2026] [security2:error] [pid 642360:tid 642574] [client 68.221.186.136:44173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/alfa.php"] [unique_id "amuAPZSUkh3e5AhEJOBkvgAAAeM"]
[Thu Jul 30 11:47:57.509031 2026] [core:notice] [pid 643573:tid 643714] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:57.513205 2026] [security2:error] [pid 643573:tid 643714] [client 103.215.74.26:17126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAPfxWyxgRnoFKAJ_l5gAAAhg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:57.828370 2026] [proxy:error] [pid 643573:tid 643738] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:47:57.828425 2026] [proxy_http:error] [pid 643573:tid 643738] [client 68.221.186.136:44575] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:47:57.828994 2026] [proxy:error] [pid 643573:tid 643738] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:47:57.829041 2026] [proxy_http:error] [pid 643573:tid 643738] [client 68.221.186.136:44575] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:47:58.221402 2026] [security2:error] [pid 642360:tid 642576] [client 68.221.186.136:41240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/amfsqvgv.php"] [unique_id "amuAPpSUkh3e5AhEJOBkygAAAeU"]
[Thu Jul 30 11:47:58.270069 2026] [core:notice] [pid 643573:tid 643750] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:58.274726 2026] [security2:error] [pid 643573:tid 643750] [client 103.215.74.26:17128] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAPvxWyxgRnoFKAJ_l9wAAAjw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:58.459883 2026] [security2:error] [pid 643573:tid 643773] [client 23.23.104.107:1429] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2016/11/captura-de-tela-2016-10-24-090123.png"] [unique_id "amuAPvxWyxgRnoFKAJ_mAQAAAlM"]
[Thu Jul 30 11:47:59.227820 2026] [core:notice] [pid 643573:tid 643720] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:59.415012 2026] [core:notice] [pid 643573:tid 643712] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:59.471238 2026] [security2:error] [pid 642360:tid 642603] [client 68.221.186.136:46563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/hehe.php"] [unique_id "amuAP5SUkh3e5AhEJOBkzwAAAgA"]
[Thu Jul 30 11:48:00.206081 2026] [security2:error] [pid 642360:tid 642495] [client 57.141.0.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "magicmooncorp.com"] [uri "/index.php"] [unique_id "amuAPZSUkh3e5AhEJOBkxAAAAZQ"]
[Thu Jul 30 11:48:00.658571 2026] [security2:error] [pid 642360:tid 642532] [client 68.221.186.136:41269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/ant.php"] [unique_id "amuAQJSUkh3e5AhEJOBk2gAAAbk"]
[Thu Jul 30 11:48:00.881003 2026] [security2:error] [pid 643573:tid 643731] [client 172.236.9.101:5334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAQPxWyxgRnoFKAJ_mIgAAAik"]
[Thu Jul 30 11:48:00.882247 2026] [security2:error] [pid 643573:tid 643835] [client 172.236.9.101:64121] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAQPxWyxgRnoFKAJ_mJQAAApE"]
[Thu Jul 30 11:48:00.895158 2026] [security2:error] [pid 643573:tid 643737] [client 172.236.9.101:5912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAQPxWyxgRnoFKAJ_mJAAAAi8"]
[Thu Jul 30 11:48:00.924604 2026] [security2:error] [pid 643573:tid 643759] [client 172.236.9.101:53623] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAQPxWyxgRnoFKAJ_mIwAAAkU"]
[Thu Jul 30 11:48:00.929933 2026] [security2:error] [pid 643573:tid 643794] [client 172.236.9.101:7924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAQPxWyxgRnoFKAJ_mKAAAAmg"]
[Thu Jul 30 11:48:01.224657 2026] [security2:error] [pid 643573:tid 643763] [client 68.221.186.136:25337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/rk2.php"] [unique_id "amuAQfxWyxgRnoFKAJ_mMgAAAkk"]
[Thu Jul 30 11:48:01.262110 2026] [security2:error] [pid 643573:tid 643829] [client 103.156.16.241:50714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuAO_xWyxgRnoFKAJ_lxAAAAos"]
[Thu Jul 30 11:48:01.262165 2026] [security2:error] [pid 643573:tid 643829] [client 103.156.16.241:50714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuAO_xWyxgRnoFKAJ_lxAAAAos"]
[Thu Jul 30 11:48:01.839924 2026] [fcgid:warn] [pid 643573:tid 643826] (70014)End of file found: [client 66.132.195.44:42672] mod_fcgid: can't get data from http client
[Thu Jul 30 11:48:01.850950 2026] [security2:error] [pid 642360:tid 642600] [client 68.221.186.136:43923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/setup-config.php"] [unique_id "amuAQZSUkh3e5AhEJOBk4gAAAf0"]
[Thu Jul 30 11:48:01.860049 2026] [security2:error] [pid 643573:tid 643795] [client 54.235.125.129:53521] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2016/11/instagram-pode-incluir-transmissao-ao-vivo-no-app.jpg"] [unique_id "amuAQfxWyxgRnoFKAJ_mOAAAAmk"]
[Thu Jul 30 11:48:02.296211 2026] [security2:error] [pid 643253:tid 643381] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAQsjqbtjBYzqM1uYlMAAARH4"]
[Thu Jul 30 11:48:02.296376 2026] [security2:error] [pid 643253:tid 643452] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAQsjqbtjBYzqM1uYlMAAARH4"]
[Thu Jul 30 11:48:03.116678 2026] [security2:error] [pid 642360:tid 642528] [client 176.241.66.87:4399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAQ5SUkh3e5AhEJOBk8QAAAbU"]
[Thu Jul 30 11:48:03.116821 2026] [security2:error] [pid 642360:tid 642528] [client 176.241.66.87:4399] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAQ5SUkh3e5AhEJOBk8QAAAbU"]
[Thu Jul 30 11:48:03.336685 2026] [security2:error] [pid 643573:tid 643733] [client 213.152.186.19:54948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAQ_xWyxgRnoFKAJ_mTQAAAis"]
[Thu Jul 30 11:48:03.336796 2026] [security2:error] [pid 643573:tid 643733] [client 213.152.186.19:54948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAQ_xWyxgRnoFKAJ_mTQAAAis"]
[Thu Jul 30 11:48:03.756172 2026] [security2:error] [pid 643573:tid 643716] [client 172.236.9.101:11786] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAQ_xWyxgRnoFKAJ_mSAAAAho"]
[Thu Jul 30 11:48:03.756222 2026] [security2:error] [pid 643573:tid 643739] [client 172.236.9.101:39373] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAQ_xWyxgRnoFKAJ_mRwAAAjE"]
[Thu Jul 30 11:48:03.757342 2026] [security2:error] [pid 643573:tid 643803] [client 172.236.9.101:38529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAQ_xWyxgRnoFKAJ_mSQAAAnE"]
[Thu Jul 30 11:48:04.113171 2026] [core:notice] [pid 643573:tid 643800] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:04.117609 2026] [security2:error] [pid 643573:tid 643800] [client 103.215.74.26:51772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuARPxWyxgRnoFKAJ_mWQAAAm4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:04.159448 2026] [security2:error] [pid 642360:tid 642516] [client 103.156.16.241:50928] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuARJSUkh3e5AhEJOBk9wAAAak"]
[Thu Jul 30 11:48:04.796907 2026] [security2:error] [pid 643253:tid 643397] [client 172.236.9.101:19239] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuARMjqbtjBYzqM1uYlMwAAAA0"]
[Thu Jul 30 11:48:04.811204 2026] [security2:error] [pid 642360:tid 642533] [client 172.236.9.101:2033] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuARJSUkh3e5AhEJOBk-AAAAbo"]
[Thu Jul 30 11:48:04.841664 2026] [security2:error] [pid 643253:tid 643413] [client 68.221.186.136:42941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/a7.php"] [unique_id "amuARMjqbtjBYzqM1uYlNAAAAB0"]
[Thu Jul 30 11:48:04.842618 2026] [core:notice] [pid 642360:tid 642494] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:04.847290 2026] [security2:error] [pid 642360:tid 642494] [client 103.215.74.26:51780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuARJSUkh3e5AhEJOBk-wAAAZM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:04.944526 2026] [security2:error] [pid 643253:tid 643417] [client 62.102.148.185:56666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuARMjqbtjBYzqM1uYlNQAAACE"]
[Thu Jul 30 11:48:04.944684 2026] [security2:error] [pid 643253:tid 643417] [client 62.102.148.185:56666] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuARMjqbtjBYzqM1uYlNQAAACE"]
[Thu Jul 30 11:48:05.095074 2026] [security2:error] [pid 642360:tid 642516] [client 103.156.16.241:50928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuARJSUkh3e5AhEJOBk9wAAAak"]
[Thu Jul 30 11:48:05.530347 2026] [security2:error] [pid 643573:tid 643812] [client 68.221.186.136:44214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/f7.php"] [unique_id "amuARfxWyxgRnoFKAJ_mbgAAAno"]
[Thu Jul 30 11:48:05.563015 2026] [core:notice] [pid 643573:tid 643827] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:05.571506 2026] [security2:error] [pid 643573:tid 643827] [client 103.215.74.26:51790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuARfxWyxgRnoFKAJ_mbwAAAok"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:06.207749 2026] [security2:error] [pid 643573:tid 643834] [client 103.156.16.241:50996] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuARvxWyxgRnoFKAJ_mfAAAApA"]
[Thu Jul 30 11:48:06.234521 2026] [core:notice] [pid 643573:tid 643836] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:06.238185 2026] [security2:error] [pid 643573:tid 643836] [client 168.197.25.44:23516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/signal/article/view/9507"] [unique_id "amuARfxWyxgRnoFKAJ_mdwAAApI"]
[Thu Jul 30 11:48:06.295355 2026] [core:notice] [pid 643573:tid 643725] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:06.299859 2026] [security2:error] [pid 643573:tid 643725] [client 103.215.74.26:51802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuARvxWyxgRnoFKAJ_mfQAAAiM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:06.986994 2026] [security2:error] [pid 643573:tid 643611] [remote 57.141.0.67:59480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6113126855/feed/rss2/"] [unique_id "amuARvxWyxgRnoFKAJ_miQACeR4"]
[Thu Jul 30 11:48:07.004583 2026] [security2:error] [pid 643573:tid 643658] [remote 74.7.241.60:44572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/article.php"] [unique_id "amuAR_xWyxgRnoFKAJ_migACUk0"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/bootstrap.bundle.min.js
[Thu Jul 30 11:48:07.037439 2026] [core:notice] [pid 643573:tid 643636] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:07.045174 2026] [core:notice] [pid 643573:tid 643739] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:07.049350 2026] [security2:error] [pid 643573:tid 643739] [client 103.215.74.26:51816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAR_xWyxgRnoFKAJ_mjAAAAjE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:07.066086 2026] [security2:error] [pid 643573:tid 643834] [client 103.156.16.241:50996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuARvxWyxgRnoFKAJ_mfAAAApA"]
[Thu Jul 30 11:48:07.275817 2026] [security2:error] [pid 643573:tid 643656] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAR_xWyxgRnoFKAJ_mjwACdUs"]
[Thu Jul 30 11:48:07.276023 2026] [security2:error] [pid 643573:tid 643807] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAR_xWyxgRnoFKAJ_mjwACdUs"]
[Thu Jul 30 11:48:07.559331 2026] [security2:error] [pid 643573:tid 643763] [client 68.221.186.136:43963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/nw.php"] [unique_id "amuAR_xWyxgRnoFKAJ_mkQAAAkk"]
[Thu Jul 30 11:48:07.625176 2026] [core:notice] [pid 643573:tid 643654] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:07.807747 2026] [core:notice] [pid 643573:tid 643742] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:07.812494 2026] [security2:error] [pid 643573:tid 643742] [client 103.215.74.26:51830] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAR_xWyxgRnoFKAJ_mmwAAAjQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:08.312970 2026] [security2:error] [pid 643573:tid 643722] [client 2a03:2880:f800:1b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuAR_xWyxgRnoFKAJ_mlQACIEw"]
[Thu Jul 30 11:48:08.337465 2026] [security2:error] [pid 643573:tid 643813] [client 68.221.186.136:43942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/ova.php"] [unique_id "amuASPxWyxgRnoFKAJ_mpwAAAns"]
[Thu Jul 30 11:48:08.532192 2026] [core:notice] [pid 642360:tid 642514] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:08.536207 2026] [security2:error] [pid 642360:tid 642514] [client 103.215.74.26:51836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuASJSUkh3e5AhEJOBlGwAAAac"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:08.642863 2026] [security2:error] [pid 643573:tid 643837] [client 57.141.0.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuASPxWyxgRnoFKAJ_mogAAApM"]
[Thu Jul 30 11:48:08.914164 2026] [security2:error] [pid 643573:tid 643781] [client 103.156.16.241:51064] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuASPxWyxgRnoFKAJ_mqwAAAls"]
[Thu Jul 30 11:48:09.189308 2026] [fcgid:warn] [pid 643253:tid 643493] (70014)End of file found: [client 66.132.195.44:60822] mod_fcgid: can't get data from http client
[Thu Jul 30 11:48:09.258513 2026] [core:notice] [pid 643573:tid 643732] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:09.263449 2026] [security2:error] [pid 643573:tid 643732] [client 103.215.74.26:51844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "741"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuASfxWyxgRnoFKAJ_msgAAAio"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:09.731525 2026] [security2:error] [pid 643573:tid 643711] [client 74.7.244.4:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-788fb95f.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuASfxWyxgRnoFKAJ_msQAAAhU"]
[Thu Jul 30 11:48:09.732459 2026] [security2:error] [pid 643253:tid 643507] [client 74.7.244.4:33706] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-788fb95f.glb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuAScjqbtjBYzqM1uYlOQAAewE"]
[Thu Jul 30 11:48:09.754191 2026] [security2:error] [pid 643573:tid 643781] [client 103.156.16.241:51064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuASPxWyxgRnoFKAJ_mqwAAAls"]
[Thu Jul 30 11:48:09.846371 2026] [security2:error] [pid 643573:tid 643715] [client 198.54.128.138:48876] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "marlboro-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuASfxWyxgRnoFKAJ_muQAAAhk"]
[Thu Jul 30 11:48:09.846472 2026] [security2:error] [pid 643573:tid 643715] [client 198.54.128.138:48876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "marlboro-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuASfxWyxgRnoFKAJ_muQAAAhk"]
[Thu Jul 30 11:48:09.896340 2026] [security2:error] [pid 643573:tid 643741] [client 68.221.186.136:25315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/robots.php"] [unique_id "amuASfxWyxgRnoFKAJ_mugAAAjM"]
[Thu Jul 30 11:48:10.002483 2026] [core:notice] [pid 643573:tid 643748] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:10.007617 2026] [security2:error] [pid 643573:tid 643748] [client 103.215.74.26:51850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuASvxWyxgRnoFKAJ_muwAAAjo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:10.372783 2026] [core:notice] [pid 643573:tid 643789] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:10.530413 2026] [security2:error] [pid 643573:tid 643813] [client 68.221.186.136:44592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/alf.php"] [unique_id "amuASvxWyxgRnoFKAJ_mwgAAAns"]
[Thu Jul 30 11:48:10.734839 2026] [core:notice] [pid 643573:tid 643793] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:10.741670 2026] [security2:error] [pid 643573:tid 643793] [client 103.215.74.26:51866] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuASvxWyxgRnoFKAJ_mxQAAAmc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:10.867094 2026] [security2:error] [pid 643573:tid 643820] [client 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuASvxWyxgRnoFKAJ_mwQACgj8"]
[Thu Jul 30 11:48:10.877811 2026] [security2:error] [pid 642360:tid 642525] [client 103.156.16.241:51133] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuASpSUkh3e5AhEJOBlMAAAAbI"]
[Thu Jul 30 11:48:11.194257 2026] [core:error] [pid 643253:tid 643494] [client 74.7.244.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:48:11.194291 2026] [core:error] [pid 643253:tid 643494] [client 74.7.244.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:48:11.194458 2026] [security2:error] [pid 643253:tid 643494] [client 74.7.244.14:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.ahm.djb.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/index.php"] [unique_id "amuAS8jqbtjBYzqM1uYlPQAAAG4"]
[Thu Jul 30 11:48:11.195119 2026] [security2:error] [pid 643253:tid 643472] [client 74.7.244.14:52954] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.ahm.djb.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "amuAS8jqbtjBYzqM1uYlPAAAWAI"]
[Thu Jul 30 11:48:11.469000 2026] [core:notice] [pid 642360:tid 642594] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:11.476124 2026] [security2:error] [pid 642360:tid 642594] [client 103.215.74.26:51870] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAS5SUkh3e5AhEJOBlOgAAAfc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:12.795165 2026] [security2:error] [pid 643573:tid 643733] [client 68.221.186.136:27869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/appreciators.php"] [unique_id "amuATPxWyxgRnoFKAJ_m6gAAAis"]
[Thu Jul 30 11:48:12.964945 2026] [core:notice] [pid 643573:tid 643813] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:12.968943 2026] [security2:error] [pid 642360:tid 642527] [client 68.221.186.136:44167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/feedback.php"] [unique_id "amuATJSUkh3e5AhEJOBlRAAAAbQ"]
[Thu Jul 30 11:48:13.174468 2026] [security2:error] [pid 643573:tid 643662] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuATfxWyxgRnoFKAJ_m7QACdFE"]
[Thu Jul 30 11:48:13.174674 2026] [security2:error] [pid 643573:tid 643806] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuATfxWyxgRnoFKAJ_m7QACdFE"]
[Thu Jul 30 11:48:13.610869 2026] [security2:error] [pid 643253:tid 643409] [client 176.241.66.87:5186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuATcjqbtjBYzqM1uYlPgAAABk"]
[Thu Jul 30 11:48:13.611021 2026] [security2:error] [pid 643253:tid 643409] [client 176.241.66.87:5186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuATcjqbtjBYzqM1uYlPgAAABk"]
[Thu Jul 30 11:48:13.726604 2026] [security2:error] [pid 643573:tid 643723] [client 68.221.186.136:41275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/archive.php"] [unique_id "amuATfxWyxgRnoFKAJ_m8wAAAiE"]
[Thu Jul 30 11:48:14.293326 2026] [security2:error] [pid 643573:tid 643836] [client 44.223.232.55:60346] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/arquivos/noticias/150/956b6156835979bdf1fbd69e57a7eeed.jpg"] [unique_id "amuATvxWyxgRnoFKAJ_m9wAAApI"]
[Thu Jul 30 11:48:14.330640 2026] [security2:error] [pid 643573:tid 643763] [client 68.221.186.136:46589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/gettest.php"] [unique_id "amuATvxWyxgRnoFKAJ_m-AAAAkk"]
[Thu Jul 30 11:48:15.051304 2026] [security2:error] [pid 643573:tid 643826] [client 43.134.91.35:59178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.91.134.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/JGST"] [unique_id "amuAT_xWyxgRnoFKAJ_m_QAAAog"], referer: https://ejournalugj.com/index_php/JGST
[Thu Jul 30 11:48:15.374311 2026] [security2:error] [pid 643573:tid 643783] [client 68.221.186.136:46551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/maint.php"] [unique_id "amuAT_xWyxgRnoFKAJ_nDgAAAl0"]
[Thu Jul 30 11:48:15.573831 2026] [security2:error] [pid 643573:tid 643835] [client 66.249.68.67:48012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nobleinternationals.com"] [uri "/index.php/favicon.ico"] [unique_id "amuAT_xWyxgRnoFKAJ_nEAAAApE"]
[Thu Jul 30 11:48:15.865019 2026] [security2:error] [pid 643573:tid 643800] [client 172.236.9.101:45744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAT_xWyxgRnoFKAJ_nBQAAAm4"]
[Thu Jul 30 11:48:15.898185 2026] [security2:error] [pid 643573:tid 643736] [client 172.236.9.101:7591] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAT_xWyxgRnoFKAJ_nBwAAAi4"]
[Thu Jul 30 11:48:15.913712 2026] [security2:error] [pid 643573:tid 643774] [client 172.236.9.101:1685] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAT_xWyxgRnoFKAJ_nBgAAAlQ"]
[Thu Jul 30 11:48:15.975592 2026] [security2:error] [pid 643573:tid 643806] [client 172.236.9.101:5788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAT_xWyxgRnoFKAJ_nCQAAAnQ"]
[Thu Jul 30 11:48:15.984924 2026] [security2:error] [pid 643573:tid 643805] [client 172.236.9.101:60806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAT_xWyxgRnoFKAJ_nCAAAAnM"]
[Thu Jul 30 11:48:16.229883 2026] [security2:error] [pid 643573:tid 643784] [client 64.127.138.130:11823] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuAT_xWyxgRnoFKAJ_nAgACXhA"]
[Thu Jul 30 11:48:16.346605 2026] [security2:error] [pid 643573:tid 643683] [remote 64.127.138.130:11823] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuAT_xWyxgRnoFKAJ_nAQACXmY"]
[Thu Jul 30 11:48:16.413045 2026] [security2:error] [pid 642360:tid 642525] [client 103.156.16.241:51133] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuASpSUkh3e5AhEJOBlMAAAAbI"]
[Thu Jul 30 11:48:16.413123 2026] [security2:error] [pid 642360:tid 642525] [client 103.156.16.241:51133] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuASpSUkh3e5AhEJOBlMAAAAbI"]
[Thu Jul 30 11:48:16.613557 2026] [security2:error] [pid 643573:tid 643784] [client 64.127.138.130:11823] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuAT_xWyxgRnoFKAJ_nAwACXi4"]
[Thu Jul 30 11:48:16.869289 2026] [security2:error] [pid 642360:tid 642522] [client 68.221.186.136:25280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/files.php"] [unique_id "amuAUJSUkh3e5AhEJOBlXwAAAa8"]
[Thu Jul 30 11:48:16.886571 2026] [security2:error] [pid 642360:tid 642494] [client 68.221.186.136:41266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/as.php"] [unique_id "amuAUJSUkh3e5AhEJOBlYAAAAZM"]
[Thu Jul 30 11:48:17.260712 2026] [core:notice] [pid 642360:tid 642514] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:17.264939 2026] [security2:error] [pid 642360:tid 642514] [client 103.215.74.26:32150] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAUZSUkh3e5AhEJOBlagAAAac"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:17.409469 2026] [security2:error] [pid 643573:tid 643729] [client 64.127.138.130:11160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuAUPxWyxgRnoFKAJ_nHwACJw4"]
[Thu Jul 30 11:48:17.547374 2026] [security2:error] [pid 642360:tid 642490] [client 103.156.16.241:51317] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuAUZSUkh3e5AhEJOBlawAAAY8"]
[Thu Jul 30 11:48:17.620368 2026] [security2:error] [pid 643573:tid 643793] [client 68.221.186.136:41259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/atomlib.php"] [unique_id "amuAUfxWyxgRnoFKAJ_nKQAAAmc"]
[Thu Jul 30 11:48:17.901028 2026] [security2:error] [pid 643573:tid 643698] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAUfxWyxgRnoFKAJ_nKgACgnU"]
[Thu Jul 30 11:48:17.901320 2026] [security2:error] [pid 643573:tid 643820] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAUfxWyxgRnoFKAJ_nKgACgnU"]
[Thu Jul 30 11:48:17.983315 2026] [core:notice] [pid 642360:tid 642554] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:17.989882 2026] [security2:error] [pid 642360:tid 642554] [client 103.215.74.26:32160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAUZSUkh3e5AhEJOBlcgAAAc8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:18.167604 2026] [security2:error] [pid 643253:tid 643508] [client 68.221.186.136:41278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/autoload_classmap.php"] [unique_id "amuAUsjqbtjBYzqM1uYlRgAAAHw"]
[Thu Jul 30 11:48:18.333704 2026] [security2:error] [pid 643573:tid 643785] [client 68.221.186.136:44549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/gecko.php"] [unique_id "amuAUvxWyxgRnoFKAJ_nLwAAAl8"]
[Thu Jul 30 11:48:18.403251 2026] [security2:error] [pid 642360:tid 642490] [client 103.156.16.241:51317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuAUZSUkh3e5AhEJOBlawAAAY8"]
[Thu Jul 30 11:48:18.718780 2026] [core:notice] [pid 643573:tid 643762] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:18.726422 2026] [security2:error] [pid 643573:tid 643762] [client 103.215.74.26:32176] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAUvxWyxgRnoFKAJ_nMwAAAkg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:18.901323 2026] [security2:error] [pid 642360:tid 642592] [client 68.221.186.136:26454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/zwso.php"] [unique_id "amuAUpSUkh3e5AhEJOBlfQAAAfU"]
[Thu Jul 30 11:48:18.962726 2026] [security2:error] [pid 642360:tid 642538] [client 68.221.186.136:41219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/bb.php"] [unique_id "amuAUpSUkh3e5AhEJOBlfgAAAb8"]
[Thu Jul 30 11:48:19.036137 2026] [security2:error] [pid 643573:tid 643770] [client 64.127.138.130:11160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuAUvxWyxgRnoFKAJ_nLAACUHE"]
[Thu Jul 30 11:48:19.055068 2026] [security2:error] [pid 642360:tid 642575] [client 57.141.0.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuAUpSUkh3e5AhEJOBldgAAAeQ"]
[Thu Jul 30 11:48:19.466089 2026] [core:notice] [pid 643573:tid 643721] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:19.470336 2026] [security2:error] [pid 643573:tid 643721] [client 103.215.74.26:32192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "773"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAU_xWyxgRnoFKAJ_nOgAAAh8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:19.500701 2026] [security2:error] [pid 642360:tid 642548] [client 103.156.16.241:51372] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuAU5SUkh3e5AhEJOBlhQAAAck"]
[Thu Jul 30 11:48:19.742667 2026] [security2:error] [pid 643573:tid 643715] [client 68.221.186.136:41272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/bnm.php"] [unique_id "amuAU_xWyxgRnoFKAJ_nOwAAAhk"]
[Thu Jul 30 11:48:19.791404 2026] [security2:error] [pid 643573:tid 643737] [client 172.236.9.101:17092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAU_xWyxgRnoFKAJ_nOAAAAi8"]
[Thu Jul 30 11:48:19.864103 2026] [security2:error] [pid 642360:tid 642508] [client 57.141.0.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuAU5SUkh3e5AhEJOBlgQAAAaE"]
[Thu Jul 30 11:48:19.943106 2026] [security2:error] [pid 643573:tid 643799] [client 114.119.149.78:25599] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bisbeewalk.com"] [uri "/images/Bisbee_jflatspanfromtun.jpg"] [unique_id "amuAU_xWyxgRnoFKAJ_nPQAAAm0"], referer: https://bisbeewalk.com/images/Bisbee_jflatspanfromtun.jpg
[Thu Jul 30 11:48:20.189816 2026] [core:notice] [pid 643573:tid 643731] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:20.193828 2026] [security2:error] [pid 643573:tid 643731] [client 103.215.74.26:32206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAVPxWyxgRnoFKAJ_nPgAAAik"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:20.363178 2026] [security2:error] [pid 642360:tid 642548] [client 103.156.16.241:51372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuAU5SUkh3e5AhEJOBlhQAAAck"]
[Thu Jul 30 11:48:20.542882 2026] [security2:error] [pid 642360:tid 642608] [client 68.221.186.136:41218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/bootstrap.php"] [unique_id "amuAVJSUkh3e5AhEJOBllAAAAgU"]
[Thu Jul 30 11:48:20.793505 2026] [security2:error] [pid 643573:tid 643806] [client 172.236.9.101:43355] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAVPxWyxgRnoFKAJ_nPwAAAnQ"]
[Thu Jul 30 11:48:20.846508 2026] [security2:error] [pid 643573:tid 643805] [client 172.236.9.101:40128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAVPxWyxgRnoFKAJ_nQAAAAnM"]
[Thu Jul 30 11:48:20.888475 2026] [security2:error] [pid 643573:tid 643822] [client 172.236.9.101:38132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAVPxWyxgRnoFKAJ_nQQAAAoQ"]
[Thu Jul 30 11:48:20.912752 2026] [security2:error] [pid 643573:tid 643767] [client 172.236.9.101:27428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAVPxWyxgRnoFKAJ_nQgAAAk0"]
[Thu Jul 30 11:48:20.924111 2026] [core:notice] [pid 643573:tid 643775] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:20.932151 2026] [security2:error] [pid 643573:tid 643775] [client 103.215.74.26:32222] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAVPxWyxgRnoFKAJ_nRwAAAlU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:21.408661 2026] [security2:error] [pid 642360:tid 642419] [remote 190.92.174.190:37100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "emmelevate.club"] [uri "/wp-login.php"] [unique_id "amuAVZSUkh3e5AhEJOBlnQAB8Do"]
[Thu Jul 30 11:48:21.667387 2026] [core:notice] [pid 642360:tid 642504] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:21.671508 2026] [security2:error] [pid 642360:tid 642504] [client 103.215.74.26:32224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAVZSUkh3e5AhEJOBloQAAAZ0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:22.403596 2026] [core:notice] [pid 642360:tid 642539] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:22.409947 2026] [security2:error] [pid 642360:tid 642539] [client 103.215.74.26:32232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "745"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAVpSUkh3e5AhEJOBlpwAAAcA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:22.482391 2026] [security2:error] [pid 642360:tid 642593] [client 68.221.186.136:46583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/13.php"] [unique_id "amuAVpSUkh3e5AhEJOBlqQAAAfY"]
[Thu Jul 30 11:48:22.639267 2026] [security2:error] [pid 643253:tid 643505] [client 172.237.109.114:22355] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAVsjqbtjBYzqM1uYlSgAAAHk"]
[Thu Jul 30 11:48:22.690806 2026] [security2:error] [pid 643573:tid 643812] [client 172.237.109.114:47058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAVvxWyxgRnoFKAJ_nTAAAAno"]
[Thu Jul 30 11:48:22.722924 2026] [security2:error] [pid 643253:tid 643475] [client 172.237.109.114:30313] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAVsjqbtjBYzqM1uYlSwAAAFs"]
[Thu Jul 30 11:48:22.763610 2026] [security2:error] [pid 643573:tid 643779] [client 172.237.109.114:61857] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAVvxWyxgRnoFKAJ_nTQAAAlk"]
[Thu Jul 30 11:48:22.822673 2026] [security2:error] [pid 642360:tid 642563] [client 172.237.109.114:58081] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAVpSUkh3e5AhEJOBlpgAAAdg"]
[Thu Jul 30 11:48:22.860534 2026] [security2:error] [pid 643573:tid 643793] [client 172.237.109.114:35879] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAVvxWyxgRnoFKAJ_nTgAAAmc"]
[Thu Jul 30 11:48:23.297735 2026] [security2:error] [pid 643573:tid 643828] [client 172.236.9.101:15376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAVvxWyxgRnoFKAJ_nUwAAAoo"]
[Thu Jul 30 11:48:23.303396 2026] [security2:error] [pid 643573:tid 643778] [client 172.236.9.101:31340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAVvxWyxgRnoFKAJ_nTwAAAlg"]
[Thu Jul 30 11:48:23.304160 2026] [security2:error] [pid 643573:tid 643827] [client 172.236.9.101:50152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAVvxWyxgRnoFKAJ_nUAAAAok"]
[Thu Jul 30 11:48:23.325505 2026] [security2:error] [pid 643573:tid 643769] [client 172.236.9.101:35888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAVvxWyxgRnoFKAJ_nUgAAAk8"]
[Thu Jul 30 11:48:23.348604 2026] [security2:error] [pid 643573:tid 643733] [client 172.236.9.101:22658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAVvxWyxgRnoFKAJ_nUQAAAis"]
[Thu Jul 30 11:48:23.382770 2026] [security2:error] [pid 642360:tid 642541] [client 68.221.186.136:41251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/buy.php"] [unique_id "amuAV5SUkh3e5AhEJOBlswAAAcI"]
[Thu Jul 30 11:48:23.477324 2026] [core:notice] [pid 643253:tid 643433] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:23.589133 2026] [security2:error] [pid 643573:tid 643773] [client 68.221.186.136:25325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/ava.php"] [unique_id "amuAV_xWyxgRnoFKAJ_nZQAAAlM"]
[Thu Jul 30 11:48:24.057713 2026] [core:notice] [pid 643253:tid 643448] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:24.088861 2026] [security2:error] [pid 643573:tid 643690] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAWPxWyxgRnoFKAJ_naAACVW0"]
[Thu Jul 30 11:48:24.088999 2026] [security2:error] [pid 643573:tid 643775] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAWPxWyxgRnoFKAJ_naAACVW0"]
[Thu Jul 30 11:48:24.317764 2026] [security2:error] [pid 643573:tid 643712] [client 176.241.66.87:59252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAWPxWyxgRnoFKAJ_nawAAAhY"]
[Thu Jul 30 11:48:24.318028 2026] [security2:error] [pid 643573:tid 643712] [client 176.241.66.87:59252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAWPxWyxgRnoFKAJ_nawAAAhY"]
[Thu Jul 30 11:48:24.434150 2026] [security2:error] [pid 643573:tid 643772] [client 172.237.109.114:32604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAV_xWyxgRnoFKAJ_nXgAAAlI"]
[Thu Jul 30 11:48:24.445444 2026] [security2:error] [pid 643573:tid 643720] [client 172.237.109.114:35746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAV_xWyxgRnoFKAJ_nXwAAAh4"]
[Thu Jul 30 11:48:24.482228 2026] [security2:error] [pid 642360:tid 642495] [client 172.237.109.114:1612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAV5SUkh3e5AhEJOBlrwAAAZQ"]
[Thu Jul 30 11:48:24.484734 2026] [security2:error] [pid 643253:tid 643427] [client 172.237.109.114:55498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAV8jqbtjBYzqM1uYlTAAAACs"]
[Thu Jul 30 11:48:24.485048 2026] [security2:error] [pid 643573:tid 643783] [client 172.237.109.114:61019] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAV_xWyxgRnoFKAJ_nWgAAAl0"]
[Thu Jul 30 11:48:24.499455 2026] [security2:error] [pid 643573:tid 643739] [client 172.237.109.114:12895] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAV_xWyxgRnoFKAJ_nXQAAAjE"]
[Thu Jul 30 11:48:24.530833 2026] [security2:error] [pid 643573:tid 643809] [client 172.237.109.114:50896] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAV_xWyxgRnoFKAJ_nYQAAAnc"]
[Thu Jul 30 11:48:24.530893 2026] [security2:error] [pid 643573:tid 643798] [client 172.237.109.114:9987] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAV_xWyxgRnoFKAJ_nYwAAAmw"]
[Thu Jul 30 11:48:24.557529 2026] [security2:error] [pid 642360:tid 642510] [client 172.237.109.114:53864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAV5SUkh3e5AhEJOBlsAAAAaM"]
[Thu Jul 30 11:48:24.562556 2026] [security2:error] [pid 642360:tid 642565] [client 172.237.109.114:21942] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAV5SUkh3e5AhEJOBlsgAAAdo"]
[Thu Jul 30 11:48:24.562556 2026] [security2:error] [pid 643253:tid 643486] [client 172.237.109.114:43371] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAV8jqbtjBYzqM1uYlTQAAAGY"]
[Thu Jul 30 11:48:24.567253 2026] [security2:error] [pid 643573:tid 643781] [client 172.237.109.114:14077] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAV_xWyxgRnoFKAJ_nYAAAAls"]
[Thu Jul 30 11:48:24.583785 2026] [security2:error] [pid 643573:tid 643835] [client 172.237.109.114:30257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAV_xWyxgRnoFKAJ_nYgAAApE"]
[Thu Jul 30 11:48:24.590258 2026] [security2:error] [pid 642360:tid 642616] [client 172.237.109.114:14012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAV5SUkh3e5AhEJOBlsQAAAg0"]
[Thu Jul 30 11:48:25.233400 2026] [security2:error] [pid 643573:tid 643785] [client 68.221.186.136:27843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/chosen.php"] [unique_id "amuAWfxWyxgRnoFKAJ_negAAAl8"]
[Thu Jul 30 11:48:25.314160 2026] [security2:error] [pid 643573:tid 643718] [client 68.221.186.136:44573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/main.php"] [unique_id "amuAWfxWyxgRnoFKAJ_newAAAhw"]
[Thu Jul 30 11:48:26.296218 2026] [security2:error] [pid 643573:tid 643801] [client 57.141.0.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuAWfxWyxgRnoFKAJ_ngAAAAm8"]
[Thu Jul 30 11:48:26.460610 2026] [security2:error] [pid 642360:tid 642567] [client 68.221.186.136:41273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/class-wp-image.php"] [unique_id "amuAWpSUkh3e5AhEJOBlzgAAAdw"]
[Thu Jul 30 11:48:26.753633 2026] [security2:error] [pid 643573:tid 643827] [client 172.236.9.101:28407] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAWvxWyxgRnoFKAJ_nhQAAAok"]
[Thu Jul 30 11:48:26.760161 2026] [security2:error] [pid 643573:tid 643769] [client 172.236.9.101:41726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAWvxWyxgRnoFKAJ_nhgAAAk8"]
[Thu Jul 30 11:48:26.764877 2026] [security2:error] [pid 642360:tid 642542] [client 172.236.9.101:63289] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAWpSUkh3e5AhEJOBlzAAAAcM"]
[Thu Jul 30 11:48:26.766283 2026] [security2:error] [pid 642360:tid 642528] [client 172.236.9.101:16462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAWpSUkh3e5AhEJOBlywAAAbU"]
[Thu Jul 30 11:48:26.917061 2026] [security2:error] [pid 642360:tid 642491] [client 172.236.9.101:59150] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAWpSUkh3e5AhEJOBlzQAAAZA"]
[Thu Jul 30 11:48:27.531366 2026] [security2:error] [pid 643253:tid 643412] [client 68.221.186.136:45702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/wp-file.php"] [unique_id "amuAW8jqbtjBYzqM1uYlVAAAABw"]
[Thu Jul 30 11:48:27.775124 2026] [security2:error] [pid 643573:tid 643829] [client 50.6.43.217:47428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuAWvxWyxgRnoFKAJ_njgAAAos"]
[Thu Jul 30 11:48:28.125137 2026] [security2:error] [pid 643573:tid 643739] [client 57.141.0.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuAW_xWyxgRnoFKAJ_nmAAAAjE"]
[Thu Jul 30 11:48:28.172748 2026] [security2:error] [pid 643573:tid 643795] [client 68.221.186.136:41246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/classsmtps.php"] [unique_id "amuAXPxWyxgRnoFKAJ_nogAAAmk"]
[Thu Jul 30 11:48:28.194610 2026] [security2:error] [pid 643573:tid 643820] [client 68.221.186.136:45246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/wp-signin.php"] [unique_id "amuAXPxWyxgRnoFKAJ_npAAAAoI"]
[Thu Jul 30 11:48:28.257253 2026] [core:notice] [pid 643573:tid 643814] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:28.261159 2026] [security2:error] [pid 643573:tid 643814] [client 103.215.74.26:34406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "737"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAXPxWyxgRnoFKAJ_nqwAAAnw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:28.587853 2026] [security2:error] [pid 643573:tid 643622] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAXPxWyxgRnoFKAJ_nrQACdik"]
[Thu Jul 30 11:48:28.588060 2026] [security2:error] [pid 643573:tid 643808] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAXPxWyxgRnoFKAJ_nrQACdik"]
[Thu Jul 30 11:48:28.589454 2026] [security2:error] [pid 643573:tid 643750] [client 50.6.43.217:47450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuAW_xWyxgRnoFKAJ_nnAAAAjw"]
[Thu Jul 30 11:48:28.906306 2026] [security2:error] [pid 643573:tid 643759] [client 68.221.186.136:27877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/classwithtostring.php"] [unique_id "amuAXPxWyxgRnoFKAJ_ntAAAAkU"]
[Thu Jul 30 11:48:29.020720 2026] [core:notice] [pid 643573:tid 643794] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:29.024853 2026] [security2:error] [pid 643573:tid 643794] [client 103.215.74.26:34408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "745"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAXfxWyxgRnoFKAJ_ntQAAAmg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:29.754405 2026] [core:notice] [pid 643573:tid 643767] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:29.758385 2026] [security2:error] [pid 643573:tid 643767] [client 103.215.74.26:34414] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAXfxWyxgRnoFKAJ_nuwAAAk0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:30.118061 2026] [security2:error] [pid 643573:tid 643722] [client 68.221.186.136:27845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/config.php"] [unique_id "amuAXvxWyxgRnoFKAJ_nvgAAAiA"]
[Thu Jul 30 11:48:30.493841 2026] [core:notice] [pid 643573:tid 643788] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:30.500734 2026] [security2:error] [pid 643573:tid 643788] [client 103.215.74.26:34430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAXvxWyxgRnoFKAJ_nxQAAAmI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:30.753115 2026] [security2:error] [pid 643573:tid 643729] [client 172.236.9.101:17360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAXvxWyxgRnoFKAJ_nwAAAAic"]
[Thu Jul 30 11:48:30.757208 2026] [security2:error] [pid 643573:tid 643728] [client 172.236.9.101:50274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAXvxWyxgRnoFKAJ_nvwAAAiY"]
[Thu Jul 30 11:48:30.826303 2026] [security2:error] [pid 643573:tid 643811] [client 172.236.9.101:4244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAXvxWyxgRnoFKAJ_nwgAAAnk"]
[Thu Jul 30 11:48:30.829692 2026] [security2:error] [pid 643253:tid 643464] [client 172.236.9.101:5920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAXsjqbtjBYzqM1uYlVwAAAFA"]
[Thu Jul 30 11:48:30.833816 2026] [security2:error] [pid 643573:tid 643754] [client 172.236.9.101:18624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAXvxWyxgRnoFKAJ_nwQAAAkA"]
[Thu Jul 30 11:48:30.843015 2026] [security2:error] [pid 643573:tid 643751] [client 68.221.186.136:27870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/core.php"] [unique_id "amuAXvxWyxgRnoFKAJ_nxgAAAj0"]
[Thu Jul 30 11:48:30.952122 2026] [security2:error] [pid 643573:tid 643799] [client 68.221.186.136:45733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/simi.php"] [unique_id "amuAXvxWyxgRnoFKAJ_nywAAAm0"]
[Thu Jul 30 11:48:31.241861 2026] [core:notice] [pid 643573:tid 643755] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:31.246488 2026] [security2:error] [pid 643573:tid 643755] [client 103.215.74.26:34438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAX_xWyxgRnoFKAJ_nzQAAAkE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:31.979369 2026] [core:notice] [pid 642360:tid 642505] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:31.984389 2026] [security2:error] [pid 642360:tid 642505] [client 103.215.74.26:34448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAX5SUkh3e5AhEJOBl9wAAAZ4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:31.989469 2026] [security2:error] [pid 642360:tid 642555] [client 68.221.186.136:27846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/css.php"] [unique_id "amuAX5SUkh3e5AhEJOBl-AAAAdA"]
[Thu Jul 30 11:48:31.995049 2026] [security2:error] [pid 643573:tid 643741] [client 68.221.186.136:44186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/wp-conf.php"] [unique_id "amuAX_xWyxgRnoFKAJ_n0QAAAjM"]
[Thu Jul 30 11:48:32.699505 2026] [core:notice] [pid 642360:tid 642532] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:32.703538 2026] [security2:error] [pid 642360:tid 642532] [client 103.215.74.26:34464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAYJSUkh3e5AhEJOBl_gAAAbk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:32.977824 2026] [security2:error] [pid 642360:tid 642588] [client 68.221.186.136:41233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/database.php"] [unique_id "amuAYJSUkh3e5AhEJOBmAQAAAfE"]
[Thu Jul 30 11:48:33.534806 2026] [security2:error] [pid 643573:tid 643827] [client 68.221.186.136:41241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/db.php"] [unique_id "amuAYfxWyxgRnoFKAJ_n3QAAAok"]
[Thu Jul 30 11:48:34.086040 2026] [core:notice] [pid 643573:tid 643787] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:34.307219 2026] [security2:error] [pid 643573:tid 643759] [client 68.221.186.136:46535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/WZGHHra0r3.php"] [unique_id "amuAYvxWyxgRnoFKAJ_n5QAAAkU"]
[Thu Jul 30 11:48:34.458740 2026] [security2:error] [pid 643573:tid 643744] [client 68.221.186.136:27859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/default.php"] [unique_id "amuAYvxWyxgRnoFKAJ_n5gAAAjY"]
[Thu Jul 30 11:48:34.745318 2026] [security2:error] [pid 642360:tid 642558] [client 172.236.9.101:12439] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAYpSUkh3e5AhEJOBmCgAAAdM"]
[Thu Jul 30 11:48:34.750650 2026] [security2:error] [pid 642360:tid 642556] [client 172.236.9.101:19579] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAYpSUkh3e5AhEJOBmCwAAAdE"]
[Thu Jul 30 11:48:34.843680 2026] [security2:error] [pid 642360:tid 642536] [client 172.236.9.101:60455] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAYpSUkh3e5AhEJOBmDAAAAb0"]
[Thu Jul 30 11:48:34.844460 2026] [security2:error] [pid 643573:tid 643722] [client 172.236.9.101:59809] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAYvxWyxgRnoFKAJ_n5AAAAiA"]
[Thu Jul 30 11:48:34.920784 2026] [security2:error] [pid 643253:tid 643496] [client 176.241.66.87:59802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAYsjqbtjBYzqM1uYlWgAAAHA"]
[Thu Jul 30 11:48:34.920909 2026] [security2:error] [pid 643253:tid 643496] [client 176.241.66.87:59802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAYsjqbtjBYzqM1uYlWgAAAHA"]
[Thu Jul 30 11:48:34.944645 2026] [security2:error] [pid 643573:tid 643651] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAYvxWyxgRnoFKAJ_n6AACGkY"]
[Thu Jul 30 11:48:34.944805 2026] [security2:error] [pid 643573:tid 643716] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAYvxWyxgRnoFKAJ_n6AACGkY"]
[Thu Jul 30 11:48:35.746380 2026] [security2:error] [pid 643573:tid 643779] [client 172.236.9.101:18497] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAY_xWyxgRnoFKAJ_n7gAAAlk"]
[Thu Jul 30 11:48:36.515245 2026] [security2:error] [pid 643573:tid 643733] [client 20.203.148.31:43052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/011i.php"] [unique_id "amuAZPxWyxgRnoFKAJ_n-gAAAis"]
[Thu Jul 30 11:48:37.005380 2026] [security2:error] [pid 642360:tid 642617] [client 198.54.128.138:60082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuAZJSUkh3e5AhEJOBmIgAAAg4"]
[Thu Jul 30 11:48:37.005488 2026] [security2:error] [pid 642360:tid 642617] [client 198.54.128.138:60082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuAZJSUkh3e5AhEJOBmIgAAAg4"]
[Thu Jul 30 11:48:37.315693 2026] [security2:error] [pid 642360:tid 642601] [client 20.203.148.31:48275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/03a005685d.php"] [unique_id "amuAZZSUkh3e5AhEJOBmKAAAAf4"]
[Thu Jul 30 11:48:37.844522 2026] [security2:error] [pid 643573:tid 643590] [remote 97.74.93.24:36774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/wp-login.php"] [unique_id "amuAZfxWyxgRnoFKAJ_oAAACJAk"]
[Thu Jul 30 11:48:37.899302 2026] [security2:error] [pid 642360:tid 642575] [client 68.221.186.136:41244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/dropdown.php"] [unique_id "amuAZZSUkh3e5AhEJOBmMAAAAeQ"]
[Thu Jul 30 11:48:38.489686 2026] [security2:error] [pid 643573:tid 643829] [client 68.221.186.136:27860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/edit.php"] [unique_id "amuAZvxWyxgRnoFKAJ_oBQAAAos"]
[Thu Jul 30 11:48:38.490015 2026] [core:notice] [pid 643573:tid 643725] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:38.494382 2026] [security2:error] [pid 643573:tid 643725] [client 103.215.74.26:10110] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAZvxWyxgRnoFKAJ_oBAAAAiM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:39.185382 2026] [security2:error] [pid 643573:tid 643768] [client 68.221.186.136:26461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/bala.php"] [unique_id "amuAZ_xWyxgRnoFKAJ_oCQAAAk4"]
[Thu Jul 30 11:48:39.215284 2026] [security2:error] [pid 643573:tid 643616] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAZ_xWyxgRnoFKAJ_oCgACPyM"]
[Thu Jul 30 11:48:39.215431 2026] [security2:error] [pid 643573:tid 643753] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAZ_xWyxgRnoFKAJ_oCgACPyM"]
[Thu Jul 30 11:48:39.229313 2026] [core:notice] [pid 642360:tid 642603] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:39.233678 2026] [security2:error] [pid 642360:tid 642603] [client 103.215.74.26:10120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAZ5SUkh3e5AhEJOBmPwAAAgA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:39.374739 2026] [security2:error] [pid 643253:tid 643418] [client 68.221.186.136:41277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/f35.php"] [unique_id "amuAZ8jqbtjBYzqM1uYlWwAAACI"]
[Thu Jul 30 11:48:39.395877 2026] [security2:error] [pid 642360:tid 642573] [client 66.249.65.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuAZpSUkh3e5AhEJOBmPgAAAeI"]
[Thu Jul 30 11:48:39.409183 2026] [core:notice] [pid 643573:tid 643815] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:39.959587 2026] [core:notice] [pid 643253:tid 643462] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:39.963983 2026] [security2:error] [pid 643253:tid 643462] [client 103.215.74.26:10128] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAZ8jqbtjBYzqM1uYlXQAAAE4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:40.303218 2026] [security2:error] [pid 643573:tid 643783] [client 20.203.148.31:36638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/403.php"] [unique_id "amuAaPxWyxgRnoFKAJ_oEAAAAl0"]
[Thu Jul 30 11:48:40.365156 2026] [security2:error] [pid 643573:tid 643747] [client 213.152.161.240:42042] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuAaPxWyxgRnoFKAJ_oDwAAAjk"]
[Thu Jul 30 11:48:40.365307 2026] [security2:error] [pid 643573:tid 643747] [client 213.152.161.240:42042] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuAaPxWyxgRnoFKAJ_oDwAAAjk"]
[Thu Jul 30 11:48:40.696808 2026] [core:notice] [pid 643253:tid 643400] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:40.701391 2026] [security2:error] [pid 643253:tid 643400] [client 103.215.74.26:10130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAaMjqbtjBYzqM1uYlXgAAABA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:40.816956 2026] [security2:error] [pid 642360:tid 642588] [client 20.203.148.31:43061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/404.php"] [unique_id "amuAaJSUkh3e5AhEJOBmTAAAAfE"]
[Thu Jul 30 11:48:40.961072 2026] [security2:error] [pid 643573:tid 643803] [client 68.221.186.136:27356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/f7.php"] [unique_id "amuAaPxWyxgRnoFKAJ_oGAAAAnE"]
[Thu Jul 30 11:48:40.962375 2026] [security2:error] [pid 642360:tid 642564] [client 68.221.186.136:45567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/bk.php"] [unique_id "amuAaJSUkh3e5AhEJOBmUQAAAdk"]
[Thu Jul 30 11:48:41.460143 2026] [core:notice] [pid 642360:tid 642578] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:41.464666 2026] [security2:error] [pid 642360:tid 642578] [client 103.215.74.26:10134] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAaZSUkh3e5AhEJOBmVgAAAec"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:42.201091 2026] [core:notice] [pid 643573:tid 643806] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:42.205461 2026] [security2:error] [pid 643573:tid 643806] [client 103.215.74.26:10162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAavxWyxgRnoFKAJ_oIQAAAnQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:42.408418 2026] [security2:error] [pid 643573:tid 643605] [remote 57.141.0.24:22632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amuAavxWyxgRnoFKAJ_oJwACHRg"]
[Thu Jul 30 11:48:42.620744 2026] [security2:error] [pid 643573:tid 643788] [client 20.203.148.31:43886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/aa.php"] [unique_id "amuAavxWyxgRnoFKAJ_oLQAAAmI"]
[Thu Jul 30 11:48:42.794806 2026] [security2:error] [pid 643573:tid 643830] [client 74.7.241.129:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-f3494d1e.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuAavxWyxgRnoFKAJ_oJAAAAow"]
[Thu Jul 30 11:48:42.795527 2026] [security2:error] [pid 643573:tid 643726] [client 74.7.241.129:37854] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-f3494d1e.glb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuAavxWyxgRnoFKAJ_oIgACJCg"]
[Thu Jul 30 11:48:42.914243 2026] [security2:error] [pid 643573:tid 643814] [client 207.58.142.67:4437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/index.php"] [unique_id "amuAavxWyxgRnoFKAJ_oLgAAAnw"]
[Thu Jul 30 11:48:42.944822 2026] [core:notice] [pid 643573:tid 643822] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:42.949427 2026] [security2:error] [pid 643573:tid 643822] [client 103.215.74.26:10170] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAavxWyxgRnoFKAJ_oLwAAAoQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:42.992632 2026] [security2:error] [pid 643573:tid 643723] [client 68.221.186.136:45530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/ahax.php"] [unique_id "amuAavxWyxgRnoFKAJ_oMAAAAiE"]
[Thu Jul 30 11:48:43.296790 2026] [security2:error] [pid 642360:tid 642509] [client 20.203.148.31:43260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/aafewc0k.php"] [unique_id "amuAa5SUkh3e5AhEJOBmYwAAAaI"]
[Thu Jul 30 11:48:43.682919 2026] [core:notice] [pid 642360:tid 642546] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:43.687309 2026] [security2:error] [pid 642360:tid 642546] [client 103.215.74.26:41498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAa5SUkh3e5AhEJOBmaQAAAcc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:44.414911 2026] [core:notice] [pid 643573:tid 643823] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:44.419229 2026] [security2:error] [pid 643573:tid 643823] [client 103.215.74.26:41500] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAbPxWyxgRnoFKAJ_oOAAAAoU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:44.948149 2026] [security2:error] [pid 643573:tid 643775] [client 20.203.148.31:43847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/abcd.php"] [unique_id "amuAbPxWyxgRnoFKAJ_oPAAAAlU"]
[Thu Jul 30 11:48:45.140292 2026] [core:notice] [pid 643573:tid 643749] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:45.144394 2026] [security2:error] [pid 643573:tid 643749] [client 103.215.74.26:41510] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAbfxWyxgRnoFKAJ_oRAAAAjs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:45.155382 2026] [security2:error] [pid 643573:tid 643800] [client 57.141.0.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuAbPxWyxgRnoFKAJ_oPwAAAm4"]
[Thu Jul 30 11:48:45.641101 2026] [security2:error] [pid 643253:tid 643386] [client 20.203.148.31:37249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/about.php"] [unique_id "amuAbcjqbtjBYzqM1uYlYQAAAAI"]
[Thu Jul 30 11:48:45.690807 2026] [security2:error] [pid 643573:tid 643751] [client 176.241.66.87:60358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAbfxWyxgRnoFKAJ_oSAAAAj0"]
[Thu Jul 30 11:48:45.690956 2026] [security2:error] [pid 643573:tid 643751] [client 176.241.66.87:60358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAbfxWyxgRnoFKAJ_oSAAAAj0"]
[Thu Jul 30 11:48:45.761224 2026] [security2:error] [pid 643573:tid 643729] [client 172.236.9.101:52176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAbfxWyxgRnoFKAJ_oRQAAAic"]
[Thu Jul 30 11:48:45.821337 2026] [security2:error] [pid 642360:tid 642597] [client 172.236.9.101:48133] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAbZSUkh3e5AhEJOBmdQAAAfo"]
[Thu Jul 30 11:48:45.822648 2026] [security2:error] [pid 643573:tid 643604] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAbfxWyxgRnoFKAJ_oSQACUBc"]
[Thu Jul 30 11:48:45.822813 2026] [security2:error] [pid 643573:tid 643770] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAbfxWyxgRnoFKAJ_oSQACUBc"]
[Thu Jul 30 11:48:45.866564 2026] [security2:error] [pid 643573:tid 643788] [client 172.236.9.101:45899] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAbfxWyxgRnoFKAJ_oRgAAAmI"]
[Thu Jul 30 11:48:45.873318 2026] [core:notice] [pid 642360:tid 642498] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:45.877369 2026] [security2:error] [pid 642360:tid 642498] [client 103.215.74.26:41518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "746"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAbZSUkh3e5AhEJOBmfAAAAZc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:46.135723 2026] [security2:error] [pid 643573:tid 643758] [client 207.58.142.67:58811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/index.php"] [unique_id "amuAbvxWyxgRnoFKAJ_oTQAAAkQ"]
[Thu Jul 30 11:48:46.195268 2026] [security2:error] [pid 643573:tid 643743] [client 20.203.148.31:43202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/admin.php"] [unique_id "amuAbvxWyxgRnoFKAJ_oUAAAAjU"]
[Thu Jul 30 11:48:46.856560 2026] [security2:error] [pid 643573:tid 643831] [client 207.58.142.67:1270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/index.php"] [unique_id "amuAbvxWyxgRnoFKAJ_oUwAAAo0"]
[Thu Jul 30 11:48:47.312223 2026] [security2:error] [pid 643573:tid 643724] [client 20.203.148.31:43857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/adminfuns.php"] [unique_id "amuAb_xWyxgRnoFKAJ_oWgAAAiI"]
[Thu Jul 30 11:48:47.559791 2026] [security2:error] [pid 642360:tid 642555] [client 57.141.0.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuAb5SUkh3e5AhEJOBmjAAAAdA"]
[Thu Jul 30 11:48:47.578220 2026] [security2:error] [pid 643573:tid 643753] [client 207.58.142.67:49255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/index.php"] [unique_id "amuAb_xWyxgRnoFKAJ_oXgAAAj8"]
[Thu Jul 30 11:48:47.600240 2026] [security2:error] [pid 642360:tid 642418] [remote 40.77.167.30:23421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/anwendungen/braille-pruefung/aboutf.php"] [unique_id "amuAb5SUkh3e5AhEJOBmkAABrDk"]
[Thu Jul 30 11:48:47.784752 2026] [security2:error] [pid 643573:tid 643806] [client 172.236.9.101:11349] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAb_xWyxgRnoFKAJ_oVwAAAnQ"]
[Thu Jul 30 11:48:47.841667 2026] [security2:error] [pid 643573:tid 643826] [client 172.236.9.101:54168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAb_xWyxgRnoFKAJ_oWAAAAog"]
[Thu Jul 30 11:48:47.848661 2026] [security2:error] [pid 642360:tid 642580] [client 172.236.9.101:31523] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAb5SUkh3e5AhEJOBmiQAAAek"]
[Thu Jul 30 11:48:47.869008 2026] [security2:error] [pid 643573:tid 643798] [client 172.236.9.101:17283] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAb_xWyxgRnoFKAJ_oWQAAAmw"]
[Thu Jul 30 11:48:47.940152 2026] [security2:error] [pid 643253:tid 643429] [client 172.236.9.101:16268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAb8jqbtjBYzqM1uYlYgAAAC0"]
[Thu Jul 30 11:48:47.956498 2026] [security2:error] [pid 642360:tid 642599] [client 172.236.9.101:3435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAb5SUkh3e5AhEJOBmigAAAfw"]
[Thu Jul 30 11:48:47.957945 2026] [security2:error] [pid 642360:tid 642549] [client 172.236.9.101:13075] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAb5SUkh3e5AhEJOBmiwAAAco"]
[Thu Jul 30 11:48:48.288070 2026] [security2:error] [pid 643573:tid 643801] [client 207.58.142.67:36012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/nxproof.php.json"] [unique_id "amuAcPxWyxgRnoFKAJ_oYwAAAm8"]
[Thu Jul 30 11:48:49.001832 2026] [security2:error] [pid 643573:tid 643728] [client 207.58.142.67:2188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/index.php"] [unique_id "amuAcfxWyxgRnoFKAJ_ocAAAAiY"]
[Thu Jul 30 11:48:49.124111 2026] [security2:error] [pid 643573:tid 643816] [client 57.141.0.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuAcPxWyxgRnoFKAJ_oZwAAAn4"]
[Thu Jul 30 11:48:49.710350 2026] [security2:error] [pid 643573:tid 643770] [client 207.58.142.67:61784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/templates/shaper_helixultimate/layout/nxproof.php.json"] [unique_id "amuAcfxWyxgRnoFKAJ_odQAAAlA"]
[Thu Jul 30 11:48:49.816439 2026] [security2:error] [pid 643573:tid 643824] [client 20.203.148.31:43222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/albin.php"] [unique_id "amuAcfxWyxgRnoFKAJ_odwAAAoY"]
[Thu Jul 30 11:48:49.884011 2026] [security2:error] [pid 643573:tid 643625] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAcfxWyxgRnoFKAJ_oewACOSw"]
[Thu Jul 30 11:48:49.884202 2026] [security2:error] [pid 643573:tid 643747] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAcfxWyxgRnoFKAJ_oewACOSw"]
[Thu Jul 30 11:48:50.282598 2026] [security2:error] [pid 643573:tid 643588] [remote 152.228.213.32:56516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/wp-login.php"] [unique_id "amuAcvxWyxgRnoFKAJ_ogQACaAc"]
[Thu Jul 30 11:48:51.120324 2026] [security2:error] [pid 643573:tid 643772] [client 20.203.148.31:43841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/amfsqvgv.php"] [unique_id "amuAc_xWyxgRnoFKAJ_ojQAAAlI"]
[Thu Jul 30 11:48:51.598473 2026] [core:notice] [pid 643253:tid 643384] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:51.602718 2026] [security2:error] [pid 643253:tid 643384] [client 103.215.74.26:41532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAc8jqbtjBYzqM1uYlZQAAAAA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:52.342448 2026] [core:notice] [pid 643573:tid 643736] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:52.347828 2026] [security2:error] [pid 643573:tid 643736] [client 103.215.74.26:41536] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAdPxWyxgRnoFKAJ_okwAAAi4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:52.879459 2026] [security2:error] [pid 643573:tid 643640] [remote 74.7.241.59:33702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuAdPxWyxgRnoFKAJ_olgACjTs"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/pixelyoursite/includes
[Thu Jul 30 11:48:53.078758 2026] [core:notice] [pid 642360:tid 642542] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:53.085453 2026] [security2:error] [pid 642360:tid 642542] [client 103.215.74.26:4474] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAdZSUkh3e5AhEJOBmuwAAAcM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:53.778768 2026] [security2:error] [pid 643573:tid 643762] [client 57.141.0.52:36506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "happyspree.app"] [uri "/index.php"] [unique_id "amuAdfxWyxgRnoFKAJ_omQACSDw"]
[Thu Jul 30 11:48:53.813235 2026] [security2:error] [pid 643573:tid 643798] [client 20.203.148.31:48293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/ant.php"] [unique_id "amuAdfxWyxgRnoFKAJ_omwAAAmw"]
[Thu Jul 30 11:48:54.122002 2026] [core:notice] [pid 643573:tid 643750] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:54.128686 2026] [security2:error] [pid 643573:tid 643750] [client 103.215.74.26:4504] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAdvxWyxgRnoFKAJ_onwAAAjw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:54.853493 2026] [core:notice] [pid 642360:tid 642613] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:54.858732 2026] [security2:error] [pid 642360:tid 642613] [client 103.215.74.26:4526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAdpSUkh3e5AhEJOBmygAAAgo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:55.236156 2026] [security2:error] [pid 643573:tid 643789] [client 57.141.0.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuAdvxWyxgRnoFKAJ_opQAAAmM"]
[Thu Jul 30 11:48:55.311665 2026] [security2:error] [pid 643573:tid 643768] [client 20.203.148.31:43217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/appreciators.php"] [unique_id "amuAd_xWyxgRnoFKAJ_orQAAAk4"]
[Thu Jul 30 11:48:56.032927 2026] [security2:error] [pid 643573:tid 643758] [client 20.203.148.31:43030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/archive.php"] [unique_id "amuAePxWyxgRnoFKAJ_otgAAAkQ"]
[Thu Jul 30 11:48:56.204218 2026] [autoindex:error] [pid 642360:tid 642582] [client 169.58.39.192:50066] AH01276: Cannot serve directory /home2/evkgplte/public_html/website_178d2f94/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Thu Jul 30 11:48:56.249998 2026] [security2:error] [pid 643573:tid 643788] [client 176.241.66.87:60908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAePxWyxgRnoFKAJ_ouQAAAmI"]
[Thu Jul 30 11:48:56.250136 2026] [security2:error] [pid 643573:tid 643788] [client 176.241.66.87:60908] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAePxWyxgRnoFKAJ_ouQAAAmI"]
[Thu Jul 30 11:48:56.294696 2026] [security2:error] [pid 642360:tid 642547] [client 172.236.9.101:42735] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/certificates/alseermarine.com_privkey.pem"] [unique_id "amuAeJSUkh3e5AhEJOBm1wAAAcg"]
[Thu Jul 30 11:48:56.788924 2026] [security2:error] [pid 643573:tid 643637] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAePxWyxgRnoFKAJ_owQACcjg"]
[Thu Jul 30 11:48:56.789202 2026] [security2:error] [pid 643573:tid 643804] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAePxWyxgRnoFKAJ_owQACcjg"]
[Thu Jul 30 11:48:56.823701 2026] [security2:error] [pid 643573:tid 643809] [client 172.236.9.101:24955] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAePxWyxgRnoFKAJ_ouAAAAnc"]
[Thu Jul 30 11:48:56.920176 2026] [security2:error] [pid 642360:tid 642539] [client 172.236.9.101:14719] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAeJSUkh3e5AhEJOBm1QAAAcA"]
[Thu Jul 30 11:48:56.922739 2026] [security2:error] [pid 643573:tid 643827] [client 172.236.9.101:29847] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAePxWyxgRnoFKAJ_ouwAAAok"]
[Thu Jul 30 11:48:56.925004 2026] [security2:error] [pid 642360:tid 642563] [client 172.236.9.101:4336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAeJSUkh3e5AhEJOBm1AAAAdg"]
[Thu Jul 30 11:48:56.928081 2026] [security2:error] [pid 642360:tid 642541] [client 172.236.9.101:37822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAeJSUkh3e5AhEJOBm1gAAAcI"]
[Thu Jul 30 11:48:56.978185 2026] [security2:error] [pid 643573:tid 643784] [client 172.236.9.101:46671] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAePxWyxgRnoFKAJ_ougAAAl4"]
[Thu Jul 30 11:48:57.141804 2026] [security2:error] [pid 642360:tid 642515] [client 20.203.148.31:43216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/as.php"] [unique_id "amuAeZSUkh3e5AhEJOBm3wAAAag"]
[Thu Jul 30 11:48:57.205824 2026] [security2:error] [pid 643573:tid 643797] [client 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAePxWyxgRnoFKAJ_owAACazo"]
[Thu Jul 30 11:48:58.801889 2026] [security2:error] [pid 643573:tid 643806] [client 167.88.167.87:53364] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "alseermarine.com"] [uri "/"] [unique_id "amuAevxWyxgRnoFKAJ_o2QAAAnQ"]
[Thu Jul 30 11:49:00.363091 2026] [core:error] [pid 643573:tid 643754] [client 158.173.25.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://appliancerepairservice.one/
[Thu Jul 30 11:49:00.363116 2026] [core:error] [pid 643573:tid 643754] [client 158.173.25.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://appliancerepairservice.one/
[Thu Jul 30 11:49:00.504413 2026] [security2:error] [pid 643573:tid 643703] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAfPxWyxgRnoFKAJ_o4QACiXo"]
[Thu Jul 30 11:49:00.504578 2026] [security2:error] [pid 643573:tid 643827] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAfPxWyxgRnoFKAJ_o4QACiXo"]
[Thu Jul 30 11:49:00.584481 2026] [core:notice] [pid 642360:tid 642566] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:00.588795 2026] [security2:error] [pid 642360:tid 642566] [client 103.215.74.26:4574] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "762"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAfJSUkh3e5AhEJOBnAwAAAds"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:00.687554 2026] [security2:error] [pid 643573:tid 643830] [client 41.210.146.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuAfPxWyxgRnoFKAJ_o4AACjEc"], referer: https://flixon.net/lost-password/
[Thu Jul 30 11:49:01.318950 2026] [core:notice] [pid 642360:tid 642553] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:01.326582 2026] [security2:error] [pid 642360:tid 642553] [client 103.215.74.26:4588] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAfZSUkh3e5AhEJOBnCgAAAc4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:02.051276 2026] [core:notice] [pid 643573:tid 643794] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:02.055249 2026] [security2:error] [pid 643573:tid 643794] [client 103.215.74.26:4592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "775"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAfvxWyxgRnoFKAJ_o7QAAAmg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:02.773820 2026] [core:notice] [pid 643573:tid 643739] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:02.777732 2026] [security2:error] [pid 643573:tid 643739] [client 103.215.74.26:4608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "745"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAfvxWyxgRnoFKAJ_o8wAAAjE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:03.498869 2026] [security2:error] [pid 643573:tid 643619] [remote 57.141.0.49:42754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuAf_xWyxgRnoFKAJ_o_AACOiY"]
[Thu Jul 30 11:49:03.556497 2026] [core:notice] [pid 643573:tid 643802] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:03.563223 2026] [security2:error] [pid 643573:tid 643802] [client 103.215.74.26:42914] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAf_xWyxgRnoFKAJ_o_gAAAnA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:03.653021 2026] [core:notice] [pid 643573:tid 643672] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:03.967935 2026] [security2:error] [pid 643573:tid 643830] [client 66.249.66.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuAf_xWyxgRnoFKAJ_o-QACjFI"]
[Thu Jul 30 11:49:04.292515 2026] [core:notice] [pid 643573:tid 643794] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:04.296578 2026] [security2:error] [pid 643573:tid 643794] [client 103.215.74.26:42918] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAgPxWyxgRnoFKAJ_pAwAAAmg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:05.050204 2026] [core:notice] [pid 643573:tid 643779] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:05.054556 2026] [security2:error] [pid 643573:tid 643779] [client 103.215.74.26:42920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAgfxWyxgRnoFKAJ_pEgAAAlk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:05.785315 2026] [core:notice] [pid 642360:tid 642502] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:05.789413 2026] [security2:error] [pid 642360:tid 642502] [client 103.215.74.26:42922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAgZSUkh3e5AhEJOBnNQAAAZs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:06.517488 2026] [core:notice] [pid 643253:tid 643403] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:06.522618 2026] [security2:error] [pid 643253:tid 643403] [client 103.215.74.26:42926] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAgsjqbtjBYzqM1uYlbgAAABM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:06.831918 2026] [security2:error] [pid 643573:tid 643715] [client 176.241.66.87:3925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAgvxWyxgRnoFKAJ_pJgAAAhk"]
[Thu Jul 30 11:49:06.832070 2026] [security2:error] [pid 643573:tid 643715] [client 176.241.66.87:3925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAgvxWyxgRnoFKAJ_pJgAAAhk"]
[Thu Jul 30 11:49:07.256693 2026] [core:notice] [pid 643573:tid 643733] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:07.261254 2026] [security2:error] [pid 643573:tid 643733] [client 103.215.74.26:42940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAg_xWyxgRnoFKAJ_pKAAAAis"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:07.301662 2026] [security2:error] [pid 642360:tid 642611] [client 3.77.67.4:63402] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuAg5SUkh3e5AhEJOBnPQAAAgg"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 11:49:07.640783 2026] [security2:error] [pid 643253:tid 643267] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAg8jqbtjBYzqM1uYlbwAADAw"]
[Thu Jul 30 11:49:07.640945 2026] [security2:error] [pid 643253:tid 643396] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAg8jqbtjBYzqM1uYlbwAADAw"]
[Thu Jul 30 11:49:07.933243 2026] [core:notice] [pid 643573:tid 643762] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:07.937621 2026] [security2:error] [pid 643573:tid 643762] [client 3.77.67.4:34044] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAg_xWyxgRnoFKAJ_pLgAAAkg"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 11:49:07.984609 2026] [core:notice] [pid 643573:tid 643829] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:07.989242 2026] [security2:error] [pid 643573:tid 643829] [client 103.215.74.26:42942] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAg_xWyxgRnoFKAJ_pLwAAAos"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:08.497725 2026] [security2:error] [pid 643573:tid 643781] [client 3.77.67.4:34048] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuAhPxWyxgRnoFKAJ_pNAAAAls"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 11:49:08.732156 2026] [core:notice] [pid 643573:tid 643774] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:08.736535 2026] [security2:error] [pid 643573:tid 643774] [client 103.215.74.26:42948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAhPxWyxgRnoFKAJ_pNgAAAlQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:09.070554 2026] [core:notice] [pid 643573:tid 643755] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:09.477771 2026] [core:notice] [pid 643573:tid 643712] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:09.482341 2026] [security2:error] [pid 643573:tid 643712] [client 103.215.74.26:42950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAhfxWyxgRnoFKAJ_pPQAAAhY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:10.142028 2026] [core:notice] [pid 643573:tid 643676] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:10.246302 2026] [core:notice] [pid 643573:tid 643758] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:10.250701 2026] [security2:error] [pid 643573:tid 643758] [client 103.215.74.26:42958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAhvxWyxgRnoFKAJ_pSAAAAkQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:10.890906 2026] [security2:error] [pid 643253:tid 643417] [client 157.148.43.126:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "online-hope.com"] [uri "/index.php"] [unique_id "amuAhsjqbtjBYzqM1uYlcQAAACE"]
[Thu Jul 30 11:49:11.171005 2026] [security2:error] [pid 643573:tid 643597] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAh_xWyxgRnoFKAJ_pVwACUxA"]
[Thu Jul 30 11:49:11.171204 2026] [security2:error] [pid 643573:tid 643773] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAh_xWyxgRnoFKAJ_pVwACUxA"]
[Thu Jul 30 11:49:11.248571 2026] [core:error] [pid 642360:tid 642396] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/
[Thu Jul 30 11:49:11.248593 2026] [core:error] [pid 642360:tid 642396] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/
[Thu Jul 30 11:49:11.297639 2026] [security2:error] [pid 643573:tid 643683] [remote 74.7.241.60:47638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/article.php"] [unique_id "amuAh_xWyxgRnoFKAJ_pWgACXmY"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/bootstrap.bundle.min.js
[Thu Jul 30 11:49:11.402108 2026] [security2:error] [pid 642360:tid 642493] [client 74.7.228.3:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.alpha518.com"] [uri "/cgi-sys/404.html"] [unique_id "amuAh5SUkh3e5AhEJOBnYgABkgo"]
[Thu Jul 30 11:49:11.454529 2026] [security2:error] [pid 643573:tid 643808] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuAh_xWyxgRnoFKAJ_pWwAAAnY"]
[Thu Jul 30 11:49:11.454645 2026] [security2:error] [pid 643573:tid 643808] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuAh_xWyxgRnoFKAJ_pWwAAAnY"]
[Thu Jul 30 11:49:11.483383 2026] [core:error] [pid 642360:tid 642426] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/
[Thu Jul 30 11:49:11.483401 2026] [core:error] [pid 642360:tid 642426] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/
[Thu Jul 30 11:49:12.023745 2026] [security2:error] [pid 643573:tid 643730] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuAiPxWyxgRnoFKAJ_pZgAAAig"]
[Thu Jul 30 11:49:12.023859 2026] [security2:error] [pid 643573:tid 643730] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuAiPxWyxgRnoFKAJ_pZgAAAig"]
[Thu Jul 30 11:49:12.568299 2026] [security2:error] [pid 643573:tid 643755] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/xstelth.php"] [unique_id "amuAiPxWyxgRnoFKAJ_pawAAAkE"]
[Thu Jul 30 11:49:12.568441 2026] [security2:error] [pid 643573:tid 643755] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/xstelth.php"] [unique_id "amuAiPxWyxgRnoFKAJ_pawAAAkE"]
[Thu Jul 30 11:49:13.079380 2026] [security2:error] [pid 643573:tid 643806] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/584062352875874akp.php"] [unique_id "amuAifxWyxgRnoFKAJ_pcQAAAnQ"]
[Thu Jul 30 11:49:13.079497 2026] [security2:error] [pid 643573:tid 643806] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/584062352875874akp.php"] [unique_id "amuAifxWyxgRnoFKAJ_pcQAAAnQ"]
[Thu Jul 30 11:49:13.587930 2026] [security2:error] [pid 643573:tid 643756] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/newfile.php"] [unique_id "amuAifxWyxgRnoFKAJ_pdAAAAkI"]
[Thu Jul 30 11:49:13.588090 2026] [security2:error] [pid 643573:tid 643756] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/newfile.php"] [unique_id "amuAifxWyxgRnoFKAJ_pdAAAAkI"]
[Thu Jul 30 11:49:14.003142 2026] [security2:error] [pid 642360:tid 642440] [remote 195.26.253.119:52454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.253.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.lld.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuAipSUkh3e5AhEJOBndgABpE8"]
[Thu Jul 30 11:49:14.144580 2026] [security2:error] [pid 643573:tid 643719] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/tBEZGQz.php"] [unique_id "amuAivxWyxgRnoFKAJ_pdQAAAh0"]
[Thu Jul 30 11:49:14.144756 2026] [security2:error] [pid 643573:tid 643719] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/tBEZGQz.php"] [unique_id "amuAivxWyxgRnoFKAJ_pdQAAAh0"]
[Thu Jul 30 11:49:14.719425 2026] [proxy:error] [pid 643573:tid 643718] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:49:14.719498 2026] [proxy_http:error] [pid 643573:tid 643718] [client 172.202.95.21:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:49:14.720059 2026] [proxy:error] [pid 643573:tid 643718] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:49:14.720104 2026] [proxy_http:error] [pid 643573:tid 643718] [client 172.202.95.21:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:49:14.720201 2026] [security2:error] [pid 643573:tid 643718] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuAivxWyxgRnoFKAJ_pewAAAhw"]
[Thu Jul 30 11:49:15.246211 2026] [security2:error] [pid 643573:tid 643806] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/drykl.php"] [unique_id "amuAi_xWyxgRnoFKAJ_phgAAAnQ"]
[Thu Jul 30 11:49:15.246327 2026] [security2:error] [pid 643573:tid 643806] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/drykl.php"] [unique_id "amuAi_xWyxgRnoFKAJ_phgAAAnQ"]
[Thu Jul 30 11:49:15.768646 2026] [proxy:error] [pid 643573:tid 643802] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:49:15.768722 2026] [proxy_http:error] [pid 643573:tid 643802] [client 172.202.95.21:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:49:15.769313 2026] [proxy:error] [pid 643573:tid 643802] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:49:15.769359 2026] [proxy_http:error] [pid 643573:tid 643802] [client 172.202.95.21:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:49:15.769445 2026] [security2:error] [pid 643573:tid 643802] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuAi_xWyxgRnoFKAJ_pjQAAAnA"]
[Thu Jul 30 11:49:15.984094 2026] [core:notice] [pid 643573:tid 643803] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:15.988550 2026] [security2:error] [pid 643573:tid 643803] [client 103.215.74.26:6148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAi_xWyxgRnoFKAJ_pkwAAAnE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:16.441505 2026] [security2:error] [pid 643573:tid 643790] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/ls.php"] [unique_id "amuAjPxWyxgRnoFKAJ_pzAAAAmQ"]
[Thu Jul 30 11:49:16.441640 2026] [security2:error] [pid 643573:tid 643790] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/ls.php"] [unique_id "amuAjPxWyxgRnoFKAJ_pzAAAAmQ"]
[Thu Jul 30 11:49:17.018116 2026] [security2:error] [pid 643573:tid 643786] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/dx.php"] [unique_id "amuAjfxWyxgRnoFKAJ_p0QAAAmA"]
[Thu Jul 30 11:49:17.018228 2026] [security2:error] [pid 643573:tid 643786] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/dx.php"] [unique_id "amuAjfxWyxgRnoFKAJ_p0QAAAmA"]
[Thu Jul 30 11:49:17.450107 2026] [security2:error] [pid 642360:tid 642577] [client 176.241.66.87:62000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAjZSUkh3e5AhEJOBnlAAAAeY"]
[Thu Jul 30 11:49:17.450261 2026] [security2:error] [pid 642360:tid 642577] [client 176.241.66.87:62000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAjZSUkh3e5AhEJOBnlAAAAeY"]
[Thu Jul 30 11:49:17.559261 2026] [security2:error] [pid 642360:tid 642561] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/mac.php"] [unique_id "amuAjZSUkh3e5AhEJOBnlQAAAdY"]
[Thu Jul 30 11:49:17.559385 2026] [security2:error] [pid 642360:tid 642561] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/mac.php"] [unique_id "amuAjZSUkh3e5AhEJOBnlQAAAdY"]
[Thu Jul 30 11:49:18.036307 2026] [security2:error] [pid 643573:tid 643818] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/485.php"] [unique_id "amuAjvxWyxgRnoFKAJ_p2gAAAoA"]
[Thu Jul 30 11:49:18.036412 2026] [security2:error] [pid 643573:tid 643818] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/485.php"] [unique_id "amuAjvxWyxgRnoFKAJ_p2gAAAoA"]
[Thu Jul 30 11:49:18.221655 2026] [security2:error] [pid 643573:tid 643836] [client 198.54.128.138:41566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuAjvxWyxgRnoFKAJ_p3AAAApI"]
[Thu Jul 30 11:49:18.221773 2026] [security2:error] [pid 643573:tid 643836] [client 198.54.128.138:41566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuAjvxWyxgRnoFKAJ_p3AAAApI"]
[Thu Jul 30 11:49:18.452465 2026] [security2:error] [pid 643573:tid 643659] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAjvxWyxgRnoFKAJ_p4AACZk4"]
[Thu Jul 30 11:49:18.452646 2026] [security2:error] [pid 643573:tid 643792] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAjvxWyxgRnoFKAJ_p4AACZk4"]
[Thu Jul 30 11:49:18.474232 2026] [security2:error] [pid 643573:tid 643830] [client 85.208.96.211:10560] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/11/25/brasil-governo-federal-remaneja-r-5876-milhoes-para-passaportes-e-carros-pipa/"] [unique_id "amuAjvxWyxgRnoFKAJ_p4QAAAow"]
[Thu Jul 30 11:49:18.474363 2026] [security2:error] [pid 643573:tid 643830] [client 85.208.96.211:10560] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/11/25/brasil-governo-federal-remaneja-r-5876-milhoes-para-passaportes-e-carros-pipa/"] [unique_id "amuAjvxWyxgRnoFKAJ_p4QAAAow"]
[Thu Jul 30 11:49:18.559903 2026] [security2:error] [pid 642360:tid 642602] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/gelio1.php"] [unique_id "amuAjpSUkh3e5AhEJOBnnAAAAf8"]
[Thu Jul 30 11:49:18.560001 2026] [security2:error] [pid 642360:tid 642602] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/gelio1.php"] [unique_id "amuAjpSUkh3e5AhEJOBnnAAAAf8"]
[Thu Jul 30 11:49:19.052930 2026] [security2:error] [pid 642360:tid 642529] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/lp6.php"] [unique_id "amuAj5SUkh3e5AhEJOBnoAAAAbY"]
[Thu Jul 30 11:49:19.053065 2026] [security2:error] [pid 642360:tid 642529] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/lp6.php"] [unique_id "amuAj5SUkh3e5AhEJOBnoAAAAbY"]
[Thu Jul 30 11:49:19.223558 2026] [core:notice] [pid 643573:tid 643801] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:19.552505 2026] [security2:error] [pid 643573:tid 643743] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuAj_xWyxgRnoFKAJ_p8gAAAjU"]
[Thu Jul 30 11:49:19.552615 2026] [security2:error] [pid 643573:tid 643743] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuAj_xWyxgRnoFKAJ_p8gAAAjU"]
[Thu Jul 30 11:49:21.077714 2026] [proxy:error] [pid 643573:tid 643711] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:49:21.077789 2026] [proxy_http:error] [pid 643573:tid 643711] [client 172.202.95.21:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:49:21.078401 2026] [proxy:error] [pid 643573:tid 643711] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:49:21.078448 2026] [proxy_http:error] [pid 643573:tid 643711] [client 172.202.95.21:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:49:21.078539 2026] [security2:error] [pid 643573:tid 643711] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuAkfxWyxgRnoFKAJ_qCwAAAhU"]
[Thu Jul 30 11:49:21.581543 2026] [security2:error] [pid 643573:tid 643803] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/w3llscc.php"] [unique_id "amuAkfxWyxgRnoFKAJ_qFAAAAnE"]
[Thu Jul 30 11:49:21.581658 2026] [security2:error] [pid 643573:tid 643803] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/w3llscc.php"] [unique_id "amuAkfxWyxgRnoFKAJ_qFAAAAnE"]
[Thu Jul 30 11:49:21.710430 2026] [core:notice] [pid 643573:tid 643716] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:21.714442 2026] [security2:error] [pid 643573:tid 643716] [client 103.215.74.26:6150] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAkfxWyxgRnoFKAJ_qFwAAAho"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:21.715170 2026] [core:error] [pid 643573:tid 643757] [client 74.7.244.60:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:21.715197 2026] [core:error] [pid 643573:tid 643757] [client 74.7.244.60:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:21.715347 2026] [security2:error] [pid 643573:tid 643757] [client 74.7.244.60:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.smoke-tfhk.com"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "amuAkfxWyxgRnoFKAJ_qGAAAAkM"]
[Thu Jul 30 11:49:21.715897 2026] [security2:error] [pid 643573:tid 643825] [client 74.7.244.60:40394] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.smoke-tfhk.com"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuAkfxWyxgRnoFKAJ_qFgACh1k"]
[Thu Jul 30 11:49:21.861051 2026] [security2:error] [pid 643573:tid 643663] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAkfxWyxgRnoFKAJ_qGQACO1I"]
[Thu Jul 30 11:49:21.861254 2026] [security2:error] [pid 643573:tid 643749] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAkfxWyxgRnoFKAJ_qGQACO1I"]
[Thu Jul 30 11:49:21.958595 2026] [security2:error] [pid 643573:tid 643732] [client 74.7.175.154:33102] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.arabian-tours.com"] [uri "/cgi-sys/404.html"] [unique_id "amuAkfxWyxgRnoFKAJ_qGwACKlM"]
[Thu Jul 30 11:49:22.098167 2026] [security2:error] [pid 643573:tid 643744] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/miru3.php"] [unique_id "amuAkvxWyxgRnoFKAJ_qHwAAAjY"]
[Thu Jul 30 11:49:22.098283 2026] [security2:error] [pid 643573:tid 643744] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/miru3.php"] [unique_id "amuAkvxWyxgRnoFKAJ_qHwAAAjY"]
[Thu Jul 30 11:49:22.444074 2026] [core:notice] [pid 643573:tid 643722] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:22.449524 2026] [security2:error] [pid 643573:tid 643722] [client 103.215.74.26:6164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAkvxWyxgRnoFKAJ_qIgAAAiA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:22.578919 2026] [security2:error] [pid 643573:tid 643824] [client 52.5.242.243:50929] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "radiojelli.com"] [uri "/img/articles/68/famous-men-classified-by-myers-briggs-type-6.jpg"] [unique_id "amuAkvxWyxgRnoFKAJ_qJgAAAoY"]
[Thu Jul 30 11:49:22.599470 2026] [security2:error] [pid 643573:tid 643791] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/autoload_classmap.php"] [unique_id "amuAkvxWyxgRnoFKAJ_qJwAAAmU"]
[Thu Jul 30 11:49:22.599563 2026] [security2:error] [pid 643573:tid 643791] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/autoload_classmap.php"] [unique_id "amuAkvxWyxgRnoFKAJ_qJwAAAmU"]
[Thu Jul 30 11:49:22.870430 2026] [core:notice] [pid 643573:tid 643771] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:23.090241 2026] [proxy:error] [pid 643573:tid 643796] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:49:23.090319 2026] [proxy_http:error] [pid 643573:tid 643796] [client 172.202.95.21:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:49:23.090866 2026] [proxy:error] [pid 643573:tid 643796] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:49:23.090908 2026] [proxy_http:error] [pid 643573:tid 643796] [client 172.202.95.21:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:49:23.091016 2026] [security2:error] [pid 643573:tid 643796] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuAk_xWyxgRnoFKAJ_qMAAAAmo"]
[Thu Jul 30 11:49:23.179858 2026] [core:notice] [pid 643573:tid 643820] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:23.184141 2026] [security2:error] [pid 643573:tid 643820] [client 103.215.74.26:4530] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAk_xWyxgRnoFKAJ_qMgAAAoI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:23.591475 2026] [security2:error] [pid 643573:tid 643774] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-content/themes/index.php"] [unique_id "amuAk_xWyxgRnoFKAJ_qNgAAAlQ"]
[Thu Jul 30 11:49:23.591587 2026] [security2:error] [pid 643573:tid 643774] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-content/themes/index.php"] [unique_id "amuAk_xWyxgRnoFKAJ_qNgAAAlQ"]
[Thu Jul 30 11:49:23.937472 2026] [core:notice] [pid 643573:tid 643768] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:23.941580 2026] [security2:error] [pid 643573:tid 643768] [client 103.215.74.26:4538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAk_xWyxgRnoFKAJ_qOwAAAk4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:24.091288 2026] [security2:error] [pid 643573:tid 643727] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/av.php"] [unique_id "amuAlPxWyxgRnoFKAJ_qPAAAAiU"]
[Thu Jul 30 11:49:24.091390 2026] [security2:error] [pid 643573:tid 643727] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/av.php"] [unique_id "amuAlPxWyxgRnoFKAJ_qPAAAAiU"]
[Thu Jul 30 11:49:24.599908 2026] [proxy:error] [pid 643573:tid 643715] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:49:24.599995 2026] [proxy_http:error] [pid 643573:tid 643715] [client 172.202.95.21:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:49:24.600550 2026] [proxy:error] [pid 643573:tid 643715] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:49:24.600592 2026] [proxy_http:error] [pid 643573:tid 643715] [client 172.202.95.21:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:49:24.600678 2026] [security2:error] [pid 643573:tid 643715] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuAlPxWyxgRnoFKAJ_qPwAAAhk"]
[Thu Jul 30 11:49:24.661405 2026] [core:notice] [pid 642360:tid 642556] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:24.666452 2026] [security2:error] [pid 642360:tid 642556] [client 103.215.74.26:4546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "746"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAlJSUkh3e5AhEJOBnxwAAAdE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:25.106907 2026] [proxy:error] [pid 643573:tid 643792] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:49:25.107009 2026] [proxy_http:error] [pid 643573:tid 643792] [client 172.202.95.21:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:49:25.107814 2026] [proxy:error] [pid 643573:tid 643792] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:49:25.107865 2026] [proxy_http:error] [pid 643573:tid 643792] [client 172.202.95.21:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:49:25.107973 2026] [security2:error] [pid 643573:tid 643792] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuAlfxWyxgRnoFKAJ_qRQAAAmY"]
[Thu Jul 30 11:49:25.390995 2026] [core:notice] [pid 642360:tid 642538] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:25.395099 2026] [security2:error] [pid 642360:tid 642538] [client 103.215.74.26:4552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAlZSUkh3e5AhEJOBnzAAAAb8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:25.606307 2026] [security2:error] [pid 642360:tid 642517] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/tiny.php"] [unique_id "amuAlZSUkh3e5AhEJOBnzQAAAao"]
[Thu Jul 30 11:49:25.606469 2026] [security2:error] [pid 642360:tid 642517] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/tiny.php"] [unique_id "amuAlZSUkh3e5AhEJOBnzQAAAao"]
[Thu Jul 30 11:49:26.132750 2026] [security2:error] [pid 643573:tid 643808] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuAlvxWyxgRnoFKAJ_qUgAAAnY"]
[Thu Jul 30 11:49:26.132861 2026] [security2:error] [pid 643573:tid 643808] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuAlvxWyxgRnoFKAJ_qUgAAAnY"]
[Thu Jul 30 11:49:26.216849 2026] [security2:error] [pid 643573:tid 643768] [client 57.141.0.4:40468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuAlfxWyxgRnoFKAJ_qTwACTms"], referer: https://igetvape-australia.com/product/iget-one-blackberry-ice/
[Thu Jul 30 11:49:26.281999 2026] [core:notice] [pid 643573:tid 643835] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:26.678739 2026] [security2:error] [pid 642360:tid 642546] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/zrrhj.php"] [unique_id "amuAlpSUkh3e5AhEJOBn2AAAAcc"]
[Thu Jul 30 11:49:26.678886 2026] [security2:error] [pid 642360:tid 642546] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/zrrhj.php"] [unique_id "amuAlpSUkh3e5AhEJOBn2AAAAcc"]
[Thu Jul 30 11:49:27.223995 2026] [security2:error] [pid 643573:tid 643744] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuAl_xWyxgRnoFKAJ_qXwAAAjY"]
[Thu Jul 30 11:49:27.224124 2026] [security2:error] [pid 643573:tid 643744] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuAl_xWyxgRnoFKAJ_qXwAAAjY"]
[Thu Jul 30 11:49:27.816570 2026] [security2:error] [pid 643573:tid 643837] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wpgum.php"] [unique_id "amuAl_xWyxgRnoFKAJ_qZQAAApM"]
[Thu Jul 30 11:49:27.816685 2026] [security2:error] [pid 643573:tid 643837] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wpgum.php"] [unique_id "amuAl_xWyxgRnoFKAJ_qZQAAApM"]
[Thu Jul 30 11:49:27.940927 2026] [core:notice] [pid 643573:tid 643687] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:27.945468 2026] [security2:error] [pid 643573:tid 643784] [client 23.124.173.168:37513] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/4514"] [unique_id "amuAl_xWyxgRnoFKAJ_qYgACXmo"]
[Thu Jul 30 11:49:28.061548 2026] [security2:error] [pid 643573:tid 643726] [client 176.241.66.87:62550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAmPxWyxgRnoFKAJ_qaQAAAiQ"]
[Thu Jul 30 11:49:28.061694 2026] [security2:error] [pid 643573:tid 643726] [client 176.241.66.87:62550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAmPxWyxgRnoFKAJ_qaQAAAiQ"]
[Thu Jul 30 11:49:28.378501 2026] [security2:error] [pid 643573:tid 643735] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/ywwbf.php"] [unique_id "amuAmPxWyxgRnoFKAJ_qbwAAAi0"]
[Thu Jul 30 11:49:28.378607 2026] [security2:error] [pid 643573:tid 643735] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/ywwbf.php"] [unique_id "amuAmPxWyxgRnoFKAJ_qbwAAAi0"]
[Thu Jul 30 11:49:28.680637 2026] [core:notice] [pid 643573:tid 643695] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:28.931786 2026] [security2:error] [pid 643573:tid 643792] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/xoldj.php"] [unique_id "amuAmPxWyxgRnoFKAJ_qcwAAAmY"]
[Thu Jul 30 11:49:28.931934 2026] [security2:error] [pid 643573:tid 643792] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/xoldj.php"] [unique_id "amuAmPxWyxgRnoFKAJ_qcwAAAmY"]
[Thu Jul 30 11:49:28.964016 2026] [core:error] [pid 642360:tid 642481] [remote 216.73.217.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:28.964042 2026] [core:error] [pid 642360:tid 642481] [remote 216.73.217.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:29.459802 2026] [security2:error] [pid 643573:tid 643731] [client 47.128.26.97:23772] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "shop-kent.com"] [uri "/robots.txt"] [unique_id "amuAmfxWyxgRnoFKAJ_qegAAAik"]
[Thu Jul 30 11:49:29.502590 2026] [security2:error] [pid 642360:tid 642506] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/f35.php"] [unique_id "amuAmZSUkh3e5AhEJOBn7AAAAZ8"]
[Thu Jul 30 11:49:29.502694 2026] [security2:error] [pid 642360:tid 642506] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/f35.php"] [unique_id "amuAmZSUkh3e5AhEJOBn7AAAAZ8"]
[Thu Jul 30 11:49:29.650325 2026] [core:error] [pid 643573:tid 643826] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:29.650346 2026] [core:error] [pid 643573:tid 643826] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:29.672851 2026] [core:error] [pid 643573:tid 643727] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:29.672874 2026] [core:error] [pid 643573:tid 643727] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:29.675265 2026] [core:error] [pid 642360:tid 642507] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:29.675291 2026] [core:error] [pid 642360:tid 642507] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:29.676512 2026] [core:error] [pid 642360:tid 642582] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:29.676527 2026] [core:error] [pid 642360:tid 642582] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:29.678153 2026] [core:error] [pid 643573:tid 643801] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:29.678168 2026] [core:error] [pid 643573:tid 643801] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:30.016018 2026] [security2:error] [pid 643573:tid 643827] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/gk.php"] [unique_id "amuAmvxWyxgRnoFKAJ_qjAAAAok"]
[Thu Jul 30 11:49:30.016127 2026] [security2:error] [pid 643573:tid 643827] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/gk.php"] [unique_id "amuAmvxWyxgRnoFKAJ_qjAAAAok"]
[Thu Jul 30 11:49:30.394469 2026] [security2:error] [pid 643573:tid 643704] [remote 159.75.55.41:42184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.55.75.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ylw.gpl.temporary.site"] [uri "/wp-login.php"] [unique_id "amuAmvxWyxgRnoFKAJ_qkQACQHs"]
[Thu Jul 30 11:49:30.568848 2026] [security2:error] [pid 643573:tid 643825] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/584062352875874akp.php"] [unique_id "amuAmvxWyxgRnoFKAJ_qkgAAAoc"]
[Thu Jul 30 11:49:30.569018 2026] [security2:error] [pid 643573:tid 643825] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/584062352875874akp.php"] [unique_id "amuAmvxWyxgRnoFKAJ_qkgAAAoc"]
[Thu Jul 30 11:49:30.613317 2026] [security2:error] [pid 642360:tid 642568] [client 74.7.228.11:52408] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.website-97076a0a.jst.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuAmZSUkh3e5AhEJOBn-wAB3Xo"]
[Thu Jul 30 11:49:30.613352 2026] [security2:error] [pid 642360:tid 642568] [client 74.7.228.11:52408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.website-97076a0a.jst.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuAmZSUkh3e5AhEJOBn-wAB3Xo"]
[Thu Jul 30 11:49:31.104031 2026] [core:notice] [pid 642360:tid 642541] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.108587 2026] [security2:error] [pid 642360:tid 642541] [client 103.215.74.26:4566] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAm5SUkh3e5AhEJOBoAwAAAcI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:31.162816 2026] [core:notice] [pid 643573:tid 643675] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.163939 2026] [security2:error] [pid 643573:tid 643801] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wper3.php"] [unique_id "amuAm_xWyxgRnoFKAJ_qqgAAAm8"]
[Thu Jul 30 11:49:31.164060 2026] [security2:error] [pid 643573:tid 643801] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wper3.php"] [unique_id "amuAm_xWyxgRnoFKAJ_qqgAAAm8"]
[Thu Jul 30 11:49:31.167207 2026] [security2:error] [pid 643573:tid 643811] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/index_php/index/---call---/page/page/css-name-stylesheet.css"] [unique_id "amuAmvxWyxgRnoFKAJ_qngACeV4"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.172167 2026] [core:notice] [pid 643573:tid 643700] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.173338 2026] [core:notice] [pid 643573:tid 643693] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.174264 2026] [core:notice] [pid 643573:tid 643685] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.176597 2026] [core:notice] [pid 643573:tid 643701] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.176707 2026] [security2:error] [pid 643573:tid 643811] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/11/journalThumbnail_id_ID.jpg"] [unique_id "amuAmvxWyxgRnoFKAJ_qmgACeXc"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.176867 2026] [security2:error] [pid 643573:tid 643811] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/site/pageHeaderTitleImage_id_ID.jpg"] [unique_id "amuAmvxWyxgRnoFKAJ_qnQACeXA"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.178206 2026] [core:notice] [pid 643573:tid 643589] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.180436 2026] [security2:error] [pid 643573:tid 643811] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/index_php/index/---call---/page/page/css-name-font.css"] [unique_id "amuAmvxWyxgRnoFKAJ_qmwACeWg"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.181025 2026] [security2:error] [pid 643573:tid 643811] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/lib/pkp/styles/fontawesome/fontawesome_v-3.3.0.17.css"] [unique_id "amuAmvxWyxgRnoFKAJ_qnAACeXg"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.182451 2026] [security2:error] [pid 643573:tid 643811] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/17/journalThumbnail_en_US.png"] [unique_id "amuAmvxWyxgRnoFKAJ_qnwACeQg"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.263236 2026] [core:notice] [pid 643573:tid 643592] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.263308 2026] [core:notice] [pid 643573:tid 643590] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.263403 2026] [core:notice] [pid 643573:tid 643596] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.263411 2026] [core:notice] [pid 643573:tid 643615] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.263450 2026] [core:notice] [pid 643573:tid 643699] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.263545 2026] [core:notice] [pid 643573:tid 643587] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.263551 2026] [core:notice] [pid 643573:tid 643586] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.263607 2026] [core:notice] [pid 643573:tid 643583] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.263680 2026] [core:notice] [pid 643573:tid 643623] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.263776 2026] [core:notice] [pid 643573:tid 643651] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.264159 2026] [core:notice] [pid 643573:tid 643696] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.264296 2026] [core:notice] [pid 643573:tid 643585] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.267069 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/32/journalThumbnail_id_ID.jpg"] [unique_id "amuAm_xWyxgRnoFKAJ_qrAACTgs"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.267944 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/20/journalThumbnail_en_US.jpg"] [unique_id "amuAm_xWyxgRnoFKAJ_qtQACTgk"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.268639 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/44/journalThumbnail_id_ID.png"] [unique_id "amuAm_xWyxgRnoFKAJ_qrgACTg8"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.269059 2026] [core:notice] [pid 643573:tid 643592] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.269638 2026] [core:notice] [pid 643573:tid 643616] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.269731 2026] [core:notice] [pid 643573:tid 643649] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.269786 2026] [core:notice] [pid 643573:tid 643590] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.269834 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/site/images/apranolo/Crossref_Logo_Stacked_RGB_SMALL.png"] [unique_id "amuAm_xWyxgRnoFKAJ_qrQACTiI"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.270204 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/22/journalThumbnail_en_US.jpg"] [unique_id "amuAm_xWyxgRnoFKAJ_qsAACTnY"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.270296 2026] [core:notice] [pid 643573:tid 643596] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.270322 2026] [core:notice] [pid 643573:tid 643684] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.270583 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/39/journalThumbnail_en_US.png"] [unique_id "amuAm_xWyxgRnoFKAJ_qsQACTgY"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.270637 2026] [core:notice] [pid 643573:tid 643600] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.270700 2026] [core:notice] [pid 643573:tid 643628] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.270868 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/8/journalThumbnail_id_ID.jpg"] [unique_id "amuAm_xWyxgRnoFKAJ_qsgACTgI"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.270932 2026] [core:notice] [pid 643573:tid 643598] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.271079 2026] [core:notice] [pid 643573:tid 643705] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.271335 2026] [core:notice] [pid 643573:tid 643626] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.271354 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/24/journalThumbnail_id_ID.jpg"] [unique_id "amuAm_xWyxgRnoFKAJ_qtgACTgU"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.271565 2026] [core:notice] [pid 643573:tid 643699] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.271708 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/7/journalThumbnail_id_ID.png"] [unique_id "amuAm_xWyxgRnoFKAJ_qtwACTkY"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.272096 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/19/journalThumbnail_id_ID.jpg"] [unique_id "amuAm_xWyxgRnoFKAJ_qswACTnM"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.272347 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/10/journalThumbnail_id_ID.jpg"] [unique_id "amuAm_xWyxgRnoFKAJ_qtAACTgQ"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.272734 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/33/journalThumbnail_id_ID.jpg"] [unique_id "amuAm_xWyxgRnoFKAJ_qrwACTio"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.274558 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/14/journalThumbnail_id_ID.jpg"] [unique_id "amuAm_xWyxgRnoFKAJ_quQACTgk"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.275080 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/3/journalThumbnail_en_US.jpg"] [unique_id "amuAm_xWyxgRnoFKAJ_quwACTiM"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.275392 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/4/journalThumbnail_id_ID.jpg"] [unique_id "amuAm_xWyxgRnoFKAJ_qvgACTmc"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.275823 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/2/journalThumbnail_id_ID.png"] [unique_id "amuAm_xWyxgRnoFKAJ_qwQACThE"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.276098 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/templates/images/ojs_brand.png"] [unique_id "amuAm_xWyxgRnoFKAJ_qwwACTnw"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.276412 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/29/journalThumbnail_id_ID.jpg"] [unique_id "amuAm_xWyxgRnoFKAJ_qugACTkQ"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.276739 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/21/journalThumbnail_id_ID.jpg"] [unique_id "amuAm_xWyxgRnoFKAJ_quAACTgs"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.277006 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/1/journalThumbnail_id_ID.jpg"] [unique_id "amuAm_xWyxgRnoFKAJ_qwAACTg8"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.277321 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/35/journalThumbnail_id_ID.jpg"] [unique_id "amuAm_xWyxgRnoFKAJ_qvQACTi8"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.277657 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/25/journalThumbnail_id_ID.jpg"] [unique_id "amuAm_xWyxgRnoFKAJ_qvwACTi0"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.277901 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/13/journalThumbnail_id_ID.jpg"] [unique_id "amuAm_xWyxgRnoFKAJ_qwgACTnY"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.278201 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/6/journalThumbnail_en_US.jpg"] [unique_id "amuAm_xWyxgRnoFKAJ_qvAACThM"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.420789 2026] [security2:error] [pid 643573:tid 643724] [client 74.7.228.11:52416] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-97076a0a.jst.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuAm_xWyxgRnoFKAJ_qxwACIig"], referer: https://www.website-97076a0a.jst.nyx.temporary.site/robots.txt
[Thu Jul 30 11:49:31.836008 2026] [core:notice] [pid 643253:tid 643507] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.843304 2026] [security2:error] [pid 643253:tid 643507] [client 103.215.74.26:4578] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAm8jqbtjBYzqM1uYldgAAAHs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:32.554994 2026] [security2:error] [pid 642360:tid 642382] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAnJSUkh3e5AhEJOBoEQABpxU"]
[Thu Jul 30 11:49:32.555150 2026] [security2:error] [pid 642360:tid 642514] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAnJSUkh3e5AhEJOBoEQABpxU"]
[Thu Jul 30 11:49:32.576912 2026] [core:notice] [pid 643573:tid 643741] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:32.583879 2026] [security2:error] [pid 643573:tid 643741] [client 103.215.74.26:4590] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAnPxWyxgRnoFKAJ_q0wAAAjM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:32.750866 2026] [security2:error] [pid 643573:tid 643739] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/bthil.php"] [unique_id "amuAnPxWyxgRnoFKAJ_q2gAAAjE"]
[Thu Jul 30 11:49:32.751003 2026] [security2:error] [pid 643573:tid 643739] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/bthil.php"] [unique_id "amuAnPxWyxgRnoFKAJ_q2gAAAjE"]
[Thu Jul 30 11:49:32.838993 2026] [security2:error] [pid 642360:tid 642592] [client 41.210.146.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuAnJSUkh3e5AhEJOBoDgAB9Xc"], referer: https://flixon.net/lost-password/?ur-lp-error=invalid&message=Invalid%20username%20or%20email.
[Thu Jul 30 11:49:33.271897 2026] [security2:error] [pid 643573:tid 643784] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wyzer1.php"] [unique_id "amuAnfxWyxgRnoFKAJ_q4AAAAl4"]
[Thu Jul 30 11:49:33.272023 2026] [security2:error] [pid 643573:tid 643784] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wyzer1.php"] [unique_id "amuAnfxWyxgRnoFKAJ_q4AAAAl4"]
[Thu Jul 30 11:49:33.309257 2026] [core:notice] [pid 642360:tid 642579] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:33.313174 2026] [security2:error] [pid 642360:tid 642579] [client 103.215.74.26:37956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAnZSUkh3e5AhEJOBoFgAAAeg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:33.778570 2026] [security2:error] [pid 642360:tid 642505] [client 157.230.39.183:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuAnZSUkh3e5AhEJOBoGQAAAZ4"]
[Thu Jul 30 11:49:33.785786 2026] [security2:error] [pid 643573:tid 643740] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/mh.php"] [unique_id "amuAnfxWyxgRnoFKAJ_q6QAAAjI"]
[Thu Jul 30 11:49:33.785886 2026] [security2:error] [pid 643573:tid 643740] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/mh.php"] [unique_id "amuAnfxWyxgRnoFKAJ_q6QAAAjI"]
[Thu Jul 30 11:49:34.033500 2026] [core:notice] [pid 643573:tid 643782] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:34.037354 2026] [security2:error] [pid 643573:tid 643782] [client 103.215.74.26:37962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "762"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAnvxWyxgRnoFKAJ_q7gAAAlw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:34.279887 2026] [security2:error] [pid 643573:tid 643803] [client 39.46.2.208:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuAnvxWyxgRnoFKAJ_q9AAAAnE"]
[Thu Jul 30 11:49:34.340830 2026] [security2:error] [pid 643573:tid 643823] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuAnvxWyxgRnoFKAJ_q-QAAAoU"]
[Thu Jul 30 11:49:34.340929 2026] [security2:error] [pid 643573:tid 643823] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuAnvxWyxgRnoFKAJ_q-QAAAoU"]
[Thu Jul 30 11:49:34.718165 2026] [security2:error] [pid 643573:tid 643749] [client 138.199.40.165:35894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuAnvxWyxgRnoFKAJ_q-gACO0U"], referer: https://www.urwru.club/fitness-coaching/
[Thu Jul 30 11:49:34.763857 2026] [security2:error] [pid 643573:tid 643761] [client 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAnvxWyxgRnoFKAJ_q9gACRwc"]
[Thu Jul 30 11:49:34.776525 2026] [core:notice] [pid 642360:tid 642516] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:34.783323 2026] [security2:error] [pid 642360:tid 642516] [client 103.215.74.26:37972] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAnpSUkh3e5AhEJOBoJAAAAak"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:34.830015 2026] [security2:error] [pid 643573:tid 643745] [client 190.104.114.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuAnvxWyxgRnoFKAJ_q_wAAAjc"]
[Thu Jul 30 11:49:34.922897 2026] [security2:error] [pid 643253:tid 643409] [client 172.202.95.21:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/1.php"] [unique_id "amuAnsjqbtjBYzqM1uYlegAAABk"]
[Thu Jul 30 11:49:34.923028 2026] [security2:error] [pid 643253:tid 643409] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/1.php"] [unique_id "amuAnsjqbtjBYzqM1uYlegAAABk"]
[Thu Jul 30 11:49:34.923145 2026] [security2:error] [pid 643253:tid 643409] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/1.php"] [unique_id "amuAnsjqbtjBYzqM1uYlegAAABk"]
[Thu Jul 30 11:49:35.282624 2026] [security2:error] [pid 643573:tid 643770] [client 139.180.187.227:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuAn_xWyxgRnoFKAJ_rCAAAAlA"]
[Thu Jul 30 11:49:35.500525 2026] [security2:error] [pid 642360:tid 642503] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/chosen.php"] [unique_id "amuAn5SUkh3e5AhEJOBoMQAAAZw"]
[Thu Jul 30 11:49:35.500636 2026] [security2:error] [pid 642360:tid 642503] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/chosen.php"] [unique_id "amuAn5SUkh3e5AhEJOBoMQAAAZw"]
[Thu Jul 30 11:49:35.515346 2026] [core:notice] [pid 643573:tid 643806] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:35.519561 2026] [security2:error] [pid 643573:tid 643806] [client 103.215.74.26:37988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "775"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAn_xWyxgRnoFKAJ_rEgAAAnQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:35.554695 2026] [security2:error] [pid 643573:tid 643764] [client 168.144.47.0:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuAn_xWyxgRnoFKAJ_rDwAAAko"]
[Thu Jul 30 11:49:35.866428 2026] [security2:error] [pid 643253:tid 643461] [client 102.129.223.92:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuAnsjqbtjBYzqM1uYleQAATQ8"], referer: http://allmontecristi.com
[Thu Jul 30 11:49:36.044315 2026] [security2:error] [pid 643573:tid 643774] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/sd.php"] [unique_id "amuAoPxWyxgRnoFKAJ_rJgAAAlQ"]
[Thu Jul 30 11:49:36.044419 2026] [security2:error] [pid 643573:tid 643774] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/sd.php"] [unique_id "amuAoPxWyxgRnoFKAJ_rJgAAAlQ"]
[Thu Jul 30 11:49:36.242787 2026] [core:notice] [pid 643573:tid 643833] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:36.246744 2026] [security2:error] [pid 643573:tid 643833] [client 103.215.74.26:37996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAoPxWyxgRnoFKAJ_rKQAAAo8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:36.380110 2026] [security2:error] [pid 643573:tid 643718] [client 14.231.251.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuAoPxWyxgRnoFKAJ_rKwAAAhw"]
[Thu Jul 30 11:49:36.591906 2026] [security2:error] [pid 643573:tid 643727] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/z60.php"] [unique_id "amuAoPxWyxgRnoFKAJ_rPQAAAiU"]
[Thu Jul 30 11:49:36.592020 2026] [security2:error] [pid 643573:tid 643727] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/z60.php"] [unique_id "amuAoPxWyxgRnoFKAJ_rPQAAAiU"]
[Thu Jul 30 11:49:36.716108 2026] [security2:error] [pid 642360:tid 642377] [remote 20.54.134.42:2424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.134.54.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-login.php"] [unique_id "amuAoJSUkh3e5AhEJOBoPAAB0BA"]
[Thu Jul 30 11:49:36.718887 2026] [security2:error] [pid 643573:tid 643770] [client 45.165.62.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuAoPxWyxgRnoFKAJ_rQAAAAlA"]
[Thu Jul 30 11:49:37.008284 2026] [core:notice] [pid 643573:tid 643834] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:37.012254 2026] [security2:error] [pid 643573:tid 643834] [client 103.215.74.26:38006] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAofxWyxgRnoFKAJ_rRwAAApA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:37.138653 2026] [security2:error] [pid 643573:tid 643767] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/home.php"] [unique_id "amuAofxWyxgRnoFKAJ_rUAAAAk0"]
[Thu Jul 30 11:49:37.138773 2026] [security2:error] [pid 643573:tid 643767] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/home.php"] [unique_id "amuAofxWyxgRnoFKAJ_rUAAAAk0"]
[Thu Jul 30 11:49:37.666494 2026] [security2:error] [pid 643573:tid 643810] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/ws58.php"] [unique_id "amuAofxWyxgRnoFKAJ_rXAAAAng"]
[Thu Jul 30 11:49:37.666662 2026] [security2:error] [pid 643573:tid 643810] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/ws58.php"] [unique_id "amuAofxWyxgRnoFKAJ_rXAAAAng"]
[Thu Jul 30 11:49:37.735782 2026] [core:notice] [pid 643573:tid 643804] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:37.739772 2026] [security2:error] [pid 643573:tid 643804] [client 103.215.74.26:38018] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAofxWyxgRnoFKAJ_rXQAAAnI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:38.163387 2026] [security2:error] [pid 643573:tid 643835] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/gulu.php"] [unique_id "amuAovxWyxgRnoFKAJ_rYwAAApE"]
[Thu Jul 30 11:49:38.163563 2026] [security2:error] [pid 643573:tid 643835] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/gulu.php"] [unique_id "amuAovxWyxgRnoFKAJ_rYwAAApE"]
[Thu Jul 30 11:49:38.467159 2026] [core:notice] [pid 643573:tid 643765] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:38.472576 2026] [security2:error] [pid 643573:tid 643765] [client 103.215.74.26:38024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAovxWyxgRnoFKAJ_rbQAAAks"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:38.692448 2026] [security2:error] [pid 642360:tid 642514] [client 176.241.66.87:63100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAopSUkh3e5AhEJOBoVAAAAac"]
[Thu Jul 30 11:49:38.692636 2026] [security2:error] [pid 642360:tid 642514] [client 176.241.66.87:63100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAopSUkh3e5AhEJOBoVAAAAac"]
[Thu Jul 30 11:49:38.698533 2026] [security2:error] [pid 643573:tid 643819] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuAovxWyxgRnoFKAJ_rcQAAAoE"]
[Thu Jul 30 11:49:38.698646 2026] [security2:error] [pid 643573:tid 643819] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuAovxWyxgRnoFKAJ_rcQAAAoE"]
[Thu Jul 30 11:49:39.186885 2026] [security2:error] [pid 643573:tid 643792] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wpls.php"] [unique_id "amuAo_xWyxgRnoFKAJ_reAAAAmY"]
[Thu Jul 30 11:49:39.187072 2026] [security2:error] [pid 643573:tid 643792] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wpls.php"] [unique_id "amuAo_xWyxgRnoFKAJ_reAAAAmY"]
[Thu Jul 30 11:49:39.201786 2026] [core:notice] [pid 643573:tid 643797] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:39.206591 2026] [security2:error] [pid 643573:tid 643797] [client 103.215.74.26:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAo_xWyxgRnoFKAJ_reQAAAms"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:39.563849 2026] [security2:error] [pid 642360:tid 642517] [client 57.141.0.2:56070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuAo5SUkh3e5AhEJOBoWAABqh8"], referer: https://igetvape-australia.com/store/?product-page=10&add-to-cart=108
[Thu Jul 30 11:49:39.702166 2026] [security2:error] [pid 643573:tid 643810] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/php.php"] [unique_id "amuAo_xWyxgRnoFKAJ_rggAAAng"]
[Thu Jul 30 11:49:39.702309 2026] [security2:error] [pid 643573:tid 643810] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/php.php"] [unique_id "amuAo_xWyxgRnoFKAJ_rggAAAng"]
[Thu Jul 30 11:49:39.756094 2026] [security2:error] [pid 642360:tid 642611] [client 216.73.217.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.collectgabon.com"] [uri "/index.php"] [unique_id "amuAo5SUkh3e5AhEJOBoawACCEc"]
[Thu Jul 30 11:49:39.962046 2026] [core:notice] [pid 643253:tid 643499] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:39.966505 2026] [security2:error] [pid 643253:tid 643499] [client 103.215.74.26:38040] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAo8jqbtjBYzqM1uYljAAAAHM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:40.257909 2026] [security2:error] [pid 642360:tid 642603] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/100.php"] [unique_id "amuApJSUkh3e5AhEJOBodgAAAgA"]
[Thu Jul 30 11:49:40.258027 2026] [security2:error] [pid 642360:tid 642603] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/100.php"] [unique_id "amuApJSUkh3e5AhEJOBodgAAAgA"]
[Thu Jul 30 11:49:40.696184 2026] [core:notice] [pid 643573:tid 643742] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:40.704406 2026] [security2:error] [pid 643573:tid 643742] [client 103.215.74.26:38042] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuApPxWyxgRnoFKAJ_rmgAAAjQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:40.785195 2026] [security2:error] [pid 643573:tid 643809] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/BDKR28WP.php"] [unique_id "amuApPxWyxgRnoFKAJ_rmwAAAnc"]
[Thu Jul 30 11:49:40.785299 2026] [security2:error] [pid 643573:tid 643809] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/BDKR28WP.php"] [unique_id "amuApPxWyxgRnoFKAJ_rmwAAAnc"]
[Thu Jul 30 11:49:40.879839 2026] [core:error] [pid 643573:tid 643644] [remote 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:40.879870 2026] [core:error] [pid 643573:tid 643644] [remote 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:40.963165 2026] [core:error] [pid 643573:tid 643591] [remote 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:40.963186 2026] [core:error] [pid 643573:tid 643591] [remote 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:41.152901 2026] [core:error] [pid 643573:tid 643619] [remote 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:41.152921 2026] [core:error] [pid 643573:tid 643619] [remote 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:41.170451 2026] [security2:error] [pid 642360:tid 642610] [client 68.67.112.24:28093] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "kicksity.com"] [uri "/robots.txt"] [unique_id "amuApZSUkh3e5AhEJOBogAAAAgc"]
[Thu Jul 30 11:49:41.501694 2026] [security2:error] [pid 643573:tid 643817] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/browse.php"] [unique_id "amuApfxWyxgRnoFKAJ_rsQAAAn8"]
[Thu Jul 30 11:49:41.501773 2026] [security2:error] [pid 643573:tid 643817] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/browse.php"] [unique_id "amuApfxWyxgRnoFKAJ_rsQAAAn8"]
[Thu Jul 30 11:49:42.050348 2026] [security2:error] [pid 643253:tid 643462] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-good.php"] [unique_id "amuApsjqbtjBYzqM1uYlkwAAAE4"]
[Thu Jul 30 11:49:42.050452 2026] [security2:error] [pid 643253:tid 643462] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-good.php"] [unique_id "amuApsjqbtjBYzqM1uYlkwAAAE4"]
[Thu Jul 30 11:49:42.306513 2026] [core:error] [pid 643573:tid 643666] [remote 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:42.306544 2026] [core:error] [pid 643573:tid 643666] [remote 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:42.586014 2026] [security2:error] [pid 643573:tid 643789] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/8573.php"] [unique_id "amuApvxWyxgRnoFKAJ_r9AAAAmM"]
[Thu Jul 30 11:49:42.586110 2026] [security2:error] [pid 643573:tid 643789] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/8573.php"] [unique_id "amuApvxWyxgRnoFKAJ_r9AAAAmM"]
[Thu Jul 30 11:49:42.684878 2026] [core:error] [pid 643573:tid 643661] [remote 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:42.684898 2026] [core:error] [pid 643573:tid 643661] [remote 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:43.150062 2026] [security2:error] [pid 642360:tid 642544] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-admin/install.php"] [unique_id "amuAp5SUkh3e5AhEJOBorAAAAcU"]
[Thu Jul 30 11:49:43.150168 2026] [security2:error] [pid 642360:tid 642544] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-admin/install.php"] [unique_id "amuAp5SUkh3e5AhEJOBorAAAAcU"]
[Thu Jul 30 11:49:43.219326 2026] [security2:error] [pid 643573:tid 643673] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAp_xWyxgRnoFKAJ_sEgACVFw"]
[Thu Jul 30 11:49:43.219558 2026] [security2:error] [pid 643573:tid 643774] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAp_xWyxgRnoFKAJ_sEgACVFw"]
[Thu Jul 30 11:49:43.268398 2026] [core:error] [pid 643573:tid 643584] [remote 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:43.268425 2026] [core:error] [pid 643573:tid 643584] [remote 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:43.589430 2026] [security2:error] [pid 643573:tid 643648] [remote 65.181.116.253:42460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.116.181.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/wp-login.php"] [unique_id "amuAp_xWyxgRnoFKAJ_sGQACPUM"]
[Thu Jul 30 11:49:43.713628 2026] [security2:error] [pid 643573:tid 643724] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/classwithtostring.php"] [unique_id "amuAp_xWyxgRnoFKAJ_sHAAAAiI"]
[Thu Jul 30 11:49:43.713776 2026] [security2:error] [pid 643573:tid 643724] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/classwithtostring.php"] [unique_id "amuAp_xWyxgRnoFKAJ_sHAAAAiI"]
[Thu Jul 30 11:49:44.147677 2026] [security2:error] [pid 643573:tid 643731] [client 121.229.156.36:38436] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/adidas-samba-xlg-11/"] [unique_id "amuAqPxWyxgRnoFKAJ_sJAAAAik"]
[Thu Jul 30 11:49:44.147784 2026] [security2:error] [pid 643573:tid 643731] [client 121.229.156.36:38436] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/product/adidas-samba-xlg-11/"] [unique_id "amuAqPxWyxgRnoFKAJ_sJAAAAik"]
[Thu Jul 30 11:49:44.273023 2026] [security2:error] [pid 643573:tid 643732] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/ohct.php"] [unique_id "amuAqPxWyxgRnoFKAJ_sKAAAAio"]
[Thu Jul 30 11:49:44.273125 2026] [security2:error] [pid 643573:tid 643732] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/ohct.php"] [unique_id "amuAqPxWyxgRnoFKAJ_sKAAAAio"]
[Thu Jul 30 11:49:44.615009 2026] [security2:error] [pid 643573:tid 643793] [client 74.7.175.133:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.azureskyfilms.com"] [uri "/robots.txt"] [unique_id "amuAqPxWyxgRnoFKAJ_sLQAAAmc"]
[Thu Jul 30 11:49:44.615633 2026] [security2:error] [pid 643573:tid 643829] [client 74.7.175.133:38852] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.azureskyfilms.com"] [uri "/robots.txt"] [unique_id "amuAqPxWyxgRnoFKAJ_sKwACixY"]
[Thu Jul 30 11:49:44.697370 2026] [core:error] [pid 643573:tid 643617] (36)File name too long: [remote 104.200.74.237:56678] AH00036: access to />","sale_flash_html":""},{"attributes":{"attribute_pa_size":"40"},"availability_html":"","backorders_allowed":false,"dimensions":{"length":"","width":"","height":""},"dimensions_html":"N/A","display_price":209,"display_regular_price":209,"image":{"title":"cae69bf9.jpeg","caption":"","url":"https:/kicksity.com/wp-content/uploads/2024/11/cae69bf9.jpeg","alt":"cae69bf9.jpeg","src":"https:/kicksity.com/wp-content/uploads/2024/11/cae69bf9-600x400.jpeg","srcset":"https:/kicksity.com/wp-content/uploads/2024/11/cae69bf9-600x400.jpeg failed (filesystem path '/home1/vdbnyxte/public_html/website_3f9373c9/>","sale_flash_html":""},{"attributes":{"attribute_pa_size":"40"},"availability_html":"","backorders_allowed":false,"dimensions":{"length":"","width":"","height":""},"dimensions_html":"N'), referer: https://kicksity.com/product/ro-sneaker-black-2/
[Thu Jul 30 11:49:44.806305 2026] [security2:error] [pid 643573:tid 643735] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/bless.php"] [unique_id "amuAqPxWyxgRnoFKAJ_sNQAAAi0"]
[Thu Jul 30 11:49:44.806411 2026] [security2:error] [pid 643573:tid 643735] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/bless.php"] [unique_id "amuAqPxWyxgRnoFKAJ_sNQAAAi0"]
[Thu Jul 30 11:49:45.349957 2026] [security2:error] [pid 643573:tid 643724] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/about.php"] [unique_id "amuAqfxWyxgRnoFKAJ_sSwAAAiI"]
[Thu Jul 30 11:49:45.350103 2026] [security2:error] [pid 643573:tid 643724] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/about.php"] [unique_id "amuAqfxWyxgRnoFKAJ_sSwAAAiI"]
[Thu Jul 30 11:49:45.875531 2026] [security2:error] [pid 643573:tid 643787] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuAqfxWyxgRnoFKAJ_sYAAAAmE"]
[Thu Jul 30 11:49:45.875625 2026] [security2:error] [pid 643573:tid 643787] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuAqfxWyxgRnoFKAJ_sYAAAAmE"]
[Thu Jul 30 11:49:45.972647 2026] [security2:error] [pid 642360:tid 642500] [client 172.237.109.114:48562] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/wp-content/database.sql"] [unique_id "amuAqZSUkh3e5AhEJOBo0AAAAZk"]
[Thu Jul 30 11:49:45.977165 2026] [security2:error] [pid 643573:tid 643775] [client 172.237.109.114:44988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/database.sql"] [unique_id "amuAqfxWyxgRnoFKAJ_sZgAAAlU"]
[Thu Jul 30 11:49:45.977209 2026] [security2:error] [pid 643573:tid 643829] [client 172.237.109.114:31246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/database.sql"] [unique_id "amuAqfxWyxgRnoFKAJ_sZQAAAos"]
[Thu Jul 30 11:49:45.977303 2026] [security2:error] [pid 643573:tid 643803] [client 172.237.109.114:62824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/backup.sql"] [unique_id "amuAqfxWyxgRnoFKAJ_sZAAAAnE"]
[Thu Jul 30 11:49:45.990088 2026] [security2:error] [pid 643573:tid 643747] [client 172.237.109.114:52073] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/alseermarine.com:80.sql"] [unique_id "amuAqfxWyxgRnoFKAJ_sZwAAAjk"]
[Thu Jul 30 11:49:45.990256 2026] [security2:error] [pid 643573:tid 643819] [client 172.237.109.114:40140] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/dump.sql"] [unique_id "amuAqfxWyxgRnoFKAJ_saAAAAoE"]
[Thu Jul 30 11:49:45.991281 2026] [security2:error] [pid 643573:tid 643796] [client 172.237.109.114:64552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/backups/database.sql"] [unique_id "amuAqfxWyxgRnoFKAJ_saQAAAmo"]
[Thu Jul 30 11:49:45.991792 2026] [security2:error] [pid 643253:tid 643503] [client 172.237.109.114:15840] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/mysql.sql"] [unique_id "amuAqcjqbtjBYzqM1uYlnQAAAHc"]
[Thu Jul 30 11:49:45.992111 2026] [security2:error] [pid 643573:tid 643777] [client 172.237.109.114:22003] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/backup.sql"] [unique_id "amuAqfxWyxgRnoFKAJ_sagAAAlc"]
[Thu Jul 30 11:49:46.010287 2026] [security2:error] [pid 643573:tid 643798] [client 172.237.109.114:1345] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/alseermarine.com:80.sql"] [unique_id "amuAqvxWyxgRnoFKAJ_sbAAAAmw"]
[Thu Jul 30 11:49:46.010361 2026] [security2:error] [pid 643573:tid 643834] [client 172.237.109.114:13444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/dump.sql"] [unique_id "amuAqvxWyxgRnoFKAJ_sbQAAApA"]
[Thu Jul 30 11:49:46.010392 2026] [security2:error] [pid 642360:tid 642559] [client 172.237.109.114:32753] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/db.sql"] [unique_id "amuAqpSUkh3e5AhEJOBo0gAAAdQ"]
[Thu Jul 30 11:49:46.420520 2026] [security2:error] [pid 643253:tid 643442] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/ta0ol.php"] [unique_id "amuAqsjqbtjBYzqM1uYlngAAADo"]
[Thu Jul 30 11:49:46.420604 2026] [security2:error] [pid 643253:tid 643442] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/ta0ol.php"] [unique_id "amuAqsjqbtjBYzqM1uYlngAAADo"]
[Thu Jul 30 11:49:46.428172 2026] [core:notice] [pid 643573:tid 643820] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:46.433355 2026] [security2:error] [pid 643573:tid 643820] [client 103.215.74.26:21346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAqvxWyxgRnoFKAJ_sdgAAAoI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:46.988450 2026] [security2:error] [pid 643573:tid 643804] [client 74.7.241.174:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.ztk.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuAqfxWyxgRnoFKAJ_sVAAAAnI"]
[Thu Jul 30 11:49:46.988765 2026] [security2:error] [pid 643253:tid 643425] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/sa.php7"] [unique_id "amuAqsjqbtjBYzqM1uYloAAAACk"]
[Thu Jul 30 11:49:46.988874 2026] [security2:error] [pid 643253:tid 643425] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/sa.php7"] [unique_id "amuAqsjqbtjBYzqM1uYloAAAACk"]
[Thu Jul 30 11:49:46.989185 2026] [security2:error] [pid 643573:tid 643764] [client 74.7.241.174:33326] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.ztk.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuAqfxWyxgRnoFKAJ_sUgACShA"]
[Thu Jul 30 11:49:47.554226 2026] [security2:error] [pid 643573:tid 643757] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-class.php"] [unique_id "amuAq_xWyxgRnoFKAJ_sfwAAAkM"]
[Thu Jul 30 11:49:47.554336 2026] [security2:error] [pid 643573:tid 643757] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-class.php"] [unique_id "amuAq_xWyxgRnoFKAJ_sfwAAAkM"]
[Thu Jul 30 11:49:47.736494 2026] [security2:error] [pid 643573:tid 643829] [client 103.97.165.206:61168] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "happyspree.app"] [uri "/"] [unique_id "amuAq_xWyxgRnoFKAJ_sgQAAAos"]
[Thu Jul 30 11:49:47.973783 2026] [security2:error] [pid 642360:tid 642598] [client 185.191.171.2:54734] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2024/02/28/bolsonaro-passa-por-exames-e-equipe-medica-discute-realizacao-de-nova-cirurgia-no-abdomen/"] [unique_id "amuAq5SUkh3e5AhEJOBo6wAAAfs"]
[Thu Jul 30 11:49:47.973938 2026] [security2:error] [pid 642360:tid 642598] [client 185.191.171.2:54734] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2024/02/28/bolsonaro-passa-por-exames-e-equipe-medica-discute-realizacao-de-nova-cirurgia-no-abdomen/"] [unique_id "amuAq5SUkh3e5AhEJOBo6wAAAfs"]
[Thu Jul 30 11:49:48.108926 2026] [security2:error] [pid 643573:tid 643760] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/8.php"] [unique_id "amuArPxWyxgRnoFKAJ_siAAAAkY"]
[Thu Jul 30 11:49:48.109018 2026] [security2:error] [pid 643573:tid 643760] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/8.php"] [unique_id "amuArPxWyxgRnoFKAJ_siAAAAkY"]
[Thu Jul 30 11:49:48.672931 2026] [security2:error] [pid 643573:tid 643833] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/bootstrap.php"] [unique_id "amuArPxWyxgRnoFKAJ_sjwAAAo8"]
[Thu Jul 30 11:49:48.673060 2026] [security2:error] [pid 643573:tid 643833] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/bootstrap.php"] [unique_id "amuArPxWyxgRnoFKAJ_sjwAAAo8"]
[Thu Jul 30 11:49:49.164166 2026] [security2:error] [pid 643573:tid 643815] [client 173.252.87.113:34510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuArPxWyxgRnoFKAJ_siQAAAn0"]
[Thu Jul 30 11:49:49.464484 2026] [security2:error] [pid 643573:tid 643822] [client 176.241.66.87:10735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuArfxWyxgRnoFKAJ_smAAAAoQ"]
[Thu Jul 30 11:49:49.464602 2026] [security2:error] [pid 643573:tid 643822] [client 176.241.66.87:10735] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuArfxWyxgRnoFKAJ_smAAAAoQ"]
[Thu Jul 30 11:49:49.472640 2026] [security2:error] [pid 642360:tid 642585] [client 57.141.0.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuArJSUkh3e5AhEJOBo8wAAAe4"]
[Thu Jul 30 11:49:49.788945 2026] [security2:error] [pid 642360:tid 642612] [client 173.252.87.38:61140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuArZSUkh3e5AhEJOBo-wAAAgk"]
[Thu Jul 30 11:49:50.022385 2026] [security2:error] [pid 642360:tid 642520] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-blog-header.php"] [unique_id "amuArpSUkh3e5AhEJOBo_QAAAa0"]
[Thu Jul 30 11:49:50.022490 2026] [security2:error] [pid 642360:tid 642520] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-blog-header.php"] [unique_id "amuArpSUkh3e5AhEJOBo_QAAAa0"]
[Thu Jul 30 11:49:50.512702 2026] [security2:error] [pid 643573:tid 643831] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/aa.php"] [unique_id "amuArvxWyxgRnoFKAJ_sowAAAo0"]
[Thu Jul 30 11:49:50.512783 2026] [security2:error] [pid 643573:tid 643831] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/aa.php"] [unique_id "amuArvxWyxgRnoFKAJ_sowAAAo0"]
[Thu Jul 30 11:49:51.048453 2026] [security2:error] [pid 643573:tid 643810] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/tx79.php"] [unique_id "amuAr_xWyxgRnoFKAJ_sqwAAAng"]
[Thu Jul 30 11:49:51.048547 2026] [security2:error] [pid 643573:tid 643810] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/tx79.php"] [unique_id "amuAr_xWyxgRnoFKAJ_sqwAAAng"]
[Thu Jul 30 11:49:51.485993 2026] [security2:error] [pid 643573:tid 643800] [client 200.66.118.215:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuAr_xWyxgRnoFKAJ_ssQAAAm4"]
[Thu Jul 30 11:49:51.604786 2026] [security2:error] [pid 643253:tid 643481] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/motu.php"] [unique_id "amuAr8jqbtjBYzqM1uYlpAAAAGE"]
[Thu Jul 30 11:49:51.604904 2026] [security2:error] [pid 643253:tid 643481] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/motu.php"] [unique_id "amuAr8jqbtjBYzqM1uYlpAAAAGE"]
[Thu Jul 30 11:49:52.163770 2026] [core:notice] [pid 643253:tid 643413] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:52.165868 2026] [proxy:error] [pid 643573:tid 643826] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:49:52.165952 2026] [proxy_http:error] [pid 643573:tid 643826] [client 52.4.19.39:38508] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:49:52.166575 2026] [proxy:error] [pid 643573:tid 643826] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:49:52.166622 2026] [proxy_http:error] [pid 643573:tid 643826] [client 52.4.19.39:38508] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:49:52.168339 2026] [security2:error] [pid 643253:tid 643413] [client 103.215.74.26:21350] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAsMjqbtjBYzqM1uYlpQAAAB0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:52.196156 2026] [security2:error] [pid 643573:tid 643802] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-head.php"] [unique_id "amuAsPxWyxgRnoFKAJ_swQAAAnA"]
[Thu Jul 30 11:49:52.196246 2026] [security2:error] [pid 643573:tid 643802] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-head.php"] [unique_id "amuAsPxWyxgRnoFKAJ_swQAAAnA"]
[Thu Jul 30 11:49:52.201205 2026] [proxy:error] [pid 643253:tid 643482] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:49:52.201306 2026] [proxy_http:error] [pid 643253:tid 643482] [client 52.4.19.39:26207] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:49:52.202102 2026] [proxy:error] [pid 643253:tid 643482] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:49:52.202155 2026] [proxy_http:error] [pid 643253:tid 643482] [client 52.4.19.39:26207] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:49:52.707688 2026] [security2:error] [pid 642360:tid 642505] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuAsJSUkh3e5AhEJOBpEwAAAZ4"]
[Thu Jul 30 11:49:52.707821 2026] [security2:error] [pid 642360:tid 642505] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuAsJSUkh3e5AhEJOBpEwAAAZ4"]
[Thu Jul 30 11:49:52.897346 2026] [core:notice] [pid 643573:tid 643741] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:52.901670 2026] [security2:error] [pid 643573:tid 643741] [client 103.215.74.26:21362] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAsPxWyxgRnoFKAJ_sxwAAAjM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:52.982802 2026] [security2:error] [pid 642360:tid 642463] [remote 40.77.167.70:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/download/258/257"] [unique_id "amuAsJSUkh3e5AhEJOBpFwABuWY"]
[Thu Jul 30 11:49:53.222677 2026] [security2:error] [pid 642360:tid 642581] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/60856e3a4findex.php"] [unique_id "amuAsZSUkh3e5AhEJOBpGwAAAeo"]
[Thu Jul 30 11:49:53.222798 2026] [security2:error] [pid 642360:tid 642581] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/60856e3a4findex.php"] [unique_id "amuAsZSUkh3e5AhEJOBpGwAAAeo"]
[Thu Jul 30 11:49:53.579115 2026] [core:notice] [pid 643573:tid 643618] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:53.623456 2026] [core:notice] [pid 643253:tid 643477] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:53.630540 2026] [security2:error] [pid 643253:tid 643477] [client 103.215.74.26:11248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAscjqbtjBYzqM1uYlpwAAAF0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:53.721469 2026] [security2:error] [pid 643573:tid 643810] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-the.php"] [unique_id "amuAsfxWyxgRnoFKAJ_szgAAAng"]
[Thu Jul 30 11:49:53.721577 2026] [security2:error] [pid 643573:tid 643810] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-the.php"] [unique_id "amuAsfxWyxgRnoFKAJ_szgAAAng"]
[Thu Jul 30 11:49:53.754073 2026] [security2:error] [pid 643573:tid 643798] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "imailearninghub.com"] [uri "/media/system/js/core.js"] [unique_id "amuAsfxWyxgRnoFKAJ_szwAAAmw"]
[Thu Jul 30 11:49:54.280048 2026] [security2:error] [pid 643573:tid 643772] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp.php"] [unique_id "amuAsvxWyxgRnoFKAJ_s1QAAAlI"]
[Thu Jul 30 11:49:54.280157 2026] [security2:error] [pid 643573:tid 643772] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp.php"] [unique_id "amuAsvxWyxgRnoFKAJ_s1QAAAlI"]
[Thu Jul 30 11:49:54.354058 2026] [core:notice] [pid 642360:tid 642562] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:54.359551 2026] [security2:error] [pid 642360:tid 642562] [client 103.215.74.26:11260] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAspSUkh3e5AhEJOBpKwAAAdc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:54.794176 2026] [security2:error] [pid 643573:tid 643721] [client 20.100.187.246:16872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/--wp-lgj.php"] [unique_id "amuAsvxWyxgRnoFKAJ_s4QAAAh8"]
[Thu Jul 30 11:49:54.884066 2026] [security2:error] [pid 642360:tid 642575] [client 2a03:2880:f800:5:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuAspSUkh3e5AhEJOBpKQAB5G8"]
[Thu Jul 30 11:49:55.029064 2026] [security2:error] [pid 643573:tid 643794] [client 57.141.0.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuAsvxWyxgRnoFKAJ_s4gAAAmg"]
[Thu Jul 30 11:49:55.067296 2026] [core:notice] [pid 642360:tid 642512] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:55.072685 2026] [security2:error] [pid 642360:tid 642512] [client 103.215.74.26:11276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAs5SUkh3e5AhEJOBpOAAAAaU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:55.311045 2026] [security2:error] [pid 642360:tid 642547] [client 213.152.161.240:57458] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuAs5SUkh3e5AhEJOBpNwAAAcg"]
[Thu Jul 30 11:49:55.311133 2026] [security2:error] [pid 642360:tid 642547] [client 213.152.161.240:57458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuAs5SUkh3e5AhEJOBpNwAAAcg"]
[Thu Jul 30 11:49:55.609074 2026] [core:notice] [pid 643573:tid 643707] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:55.803644 2026] [core:notice] [pid 643573:tid 643752] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:55.808048 2026] [security2:error] [pid 643573:tid 643752] [client 103.215.74.26:11282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAs_xWyxgRnoFKAJ_s-AAAAj4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:56.541758 2026] [core:notice] [pid 642360:tid 642536] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:56.546738 2026] [security2:error] [pid 642360:tid 642536] [client 103.215.74.26:11292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAtJSUkh3e5AhEJOBpSgAAAb0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:57.208827 2026] [security2:error] [pid 642360:tid 642524] [client 57.141.0.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuAtZSUkh3e5AhEJOBpTgAAAbE"]
[Thu Jul 30 11:49:59.484905 2026] [security2:error] [pid 643573:tid 643723] [client 20.100.187.246:7774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/.well-known/autoload_classmap.php"] [unique_id "amuAt_xWyxgRnoFKAJ_tIgAAAiE"]
[Thu Jul 30 11:50:00.095400 2026] [security2:error] [pid 643573:tid 643782] [client 176.241.66.87:11317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAuPxWyxgRnoFKAJ_tJgAAAlw"]
[Thu Jul 30 11:50:00.095544 2026] [security2:error] [pid 643573:tid 643782] [client 176.241.66.87:11317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAuPxWyxgRnoFKAJ_tJgAAAlw"]
[Thu Jul 30 11:50:01.397844 2026] [security2:error] [pid 643573:tid 643792] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/users.php"] [unique_id "amuAufxWyxgRnoFKAJ_tPAAAAmY"]
[Thu Jul 30 11:50:01.397993 2026] [security2:error] [pid 643573:tid 643792] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/users.php"] [unique_id "amuAufxWyxgRnoFKAJ_tPAAAAmY"]
[Thu Jul 30 11:50:01.422027 2026] [core:error] [pid 643573:tid 643583] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/wp/
[Thu Jul 30 11:50:01.422050 2026] [core:error] [pid 643573:tid 643583] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/wp/
[Thu Jul 30 11:50:01.422880 2026] [security2:error] [pid 642360:tid 642575] [client 198.54.128.138:50756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuAuZSUkh3e5AhEJOBpdwAAAeQ"]
[Thu Jul 30 11:50:01.422959 2026] [security2:error] [pid 642360:tid 642575] [client 198.54.128.138:50756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuAuZSUkh3e5AhEJOBpdwAAAeQ"]
[Thu Jul 30 11:50:01.673233 2026] [security2:error] [pid 643573:tid 643766] [client 20.100.187.246:16888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/.well-known/flower.php"] [unique_id "amuAufxWyxgRnoFKAJ_tQgAAAkw"]
[Thu Jul 30 11:50:01.737838 2026] [security2:error] [pid 643573:tid 643724] [client 52.22.64.232:7283] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/arquivos/noticias/1455/xdc0ccf5f4bd9e8c2a4674ee92378cf27.jpg.pagespeed.ic.PXGK_Uz8yM.webp"] [unique_id "amuAufxWyxgRnoFKAJ_tQwAAAiI"]
[Thu Jul 30 11:50:01.979194 2026] [core:error] [pid 642360:tid 642379] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/wp/
[Thu Jul 30 11:50:01.979223 2026] [core:error] [pid 642360:tid 642379] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/wp/
[Thu Jul 30 11:50:02.192891 2026] [core:error] [pid 642360:tid 642479] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/wordpress/
[Thu Jul 30 11:50:02.192913 2026] [core:error] [pid 642360:tid 642479] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/wordpress/
[Thu Jul 30 11:50:02.282519 2026] [core:notice] [pid 642360:tid 642610] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:02.289465 2026] [security2:error] [pid 642360:tid 642610] [client 103.215.74.26:11300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAupSUkh3e5AhEJOBphwAAAgc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:02.754505 2026] [core:error] [pid 643573:tid 643696] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/wordpress/
[Thu Jul 30 11:50:02.754532 2026] [core:error] [pid 643573:tid 643696] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/wordpress/
[Thu Jul 30 11:50:02.931787 2026] [core:notice] [pid 643573:tid 643731] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:03.014537 2026] [core:notice] [pid 643253:tid 643447] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:03.019533 2026] [security2:error] [pid 643253:tid 643447] [client 103.215.74.26:47912] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "745"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAu8jqbtjBYzqM1uYlrwAAAD8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:03.114361 2026] [security2:error] [pid 643573:tid 643775] [client 20.100.187.246:15334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/.well-known/xleet.php"] [unique_id "amuAu_xWyxgRnoFKAJ_tVgAAAlU"]
[Thu Jul 30 11:50:03.256687 2026] [core:notice] [pid 643573:tid 643791] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:03.319198 2026] [core:error] [pid 642360:tid 642396] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/blog/
[Thu Jul 30 11:50:03.319223 2026] [core:error] [pid 642360:tid 642396] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/blog/
[Thu Jul 30 11:50:03.548830 2026] [core:error] [pid 642360:tid 642371] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/blog/
[Thu Jul 30 11:50:03.548874 2026] [core:error] [pid 642360:tid 642371] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/blog/
[Thu Jul 30 11:50:03.763243 2026] [core:notice] [pid 642360:tid 642601] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:03.768099 2026] [security2:error] [pid 642360:tid 642601] [client 103.215.74.26:47920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAu5SUkh3e5AhEJOBpqAAAAf4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:03.795191 2026] [security2:error] [pid 642360:tid 642608] [client 57.141.0.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuAu5SUkh3e5AhEJOBpnwAAAgU"]
[Thu Jul 30 11:50:04.056724 2026] [security2:error] [pid 642360:tid 642574] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/tinysd.php"] [unique_id "amuAvJSUkh3e5AhEJOBpsAAAAeM"]
[Thu Jul 30 11:50:04.056844 2026] [security2:error] [pid 642360:tid 642574] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/tinysd.php"] [unique_id "amuAvJSUkh3e5AhEJOBpsAAAAeM"]
[Thu Jul 30 11:50:04.114006 2026] [core:error] [pid 642360:tid 642421] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/old/
[Thu Jul 30 11:50:04.114034 2026] [core:error] [pid 642360:tid 642421] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/old/
[Thu Jul 30 11:50:04.501137 2026] [core:notice] [pid 643573:tid 643832] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:04.505586 2026] [security2:error] [pid 643573:tid 643832] [client 103.215.74.26:47922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAvPxWyxgRnoFKAJ_tbgAAAo4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:04.554821 2026] [security2:error] [pid 642360:tid 642617] [client 20.100.187.246:21005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/.well-known/acme-challenge/flower.php"] [unique_id "amuAvJSUkh3e5AhEJOBptwAAAg4"]
[Thu Jul 30 11:50:04.700708 2026] [core:error] [pid 643253:tid 643274] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/old/
[Thu Jul 30 11:50:04.700730 2026] [core:error] [pid 643253:tid 643274] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/old/
[Thu Jul 30 11:50:04.919207 2026] [core:error] [pid 643573:tid 643628] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/test/
[Thu Jul 30 11:50:04.919227 2026] [core:error] [pid 643573:tid 643628] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/test/
[Thu Jul 30 11:50:05.138104 2026] [core:error] [pid 643573:tid 643634] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/test/
[Thu Jul 30 11:50:05.138131 2026] [core:error] [pid 643573:tid 643634] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/test/
[Thu Jul 30 11:50:05.355366 2026] [core:error] [pid 642360:tid 642408] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/dev/
[Thu Jul 30 11:50:05.355386 2026] [core:error] [pid 642360:tid 642408] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/dev/
[Thu Jul 30 11:50:05.583494 2026] [core:error] [pid 642360:tid 642417] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/dev/
[Thu Jul 30 11:50:05.583514 2026] [core:error] [pid 642360:tid 642417] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/dev/
[Thu Jul 30 11:50:05.645221 2026] [security2:error] [pid 643573:tid 643710] [client 52.167.144.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuAu_xWyxgRnoFKAJ_tXgAAAhQ"]
[Thu Jul 30 11:50:05.733541 2026] [security2:error] [pid 643573:tid 643788] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/ws78.php"] [unique_id "amuAvfxWyxgRnoFKAJ_trQAAAmI"]
[Thu Jul 30 11:50:05.733664 2026] [security2:error] [pid 643573:tid 643788] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/ws78.php"] [unique_id "amuAvfxWyxgRnoFKAJ_trQAAAmI"]
[Thu Jul 30 11:50:05.795056 2026] [core:error] [pid 643573:tid 643647] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/backup/
[Thu Jul 30 11:50:05.795084 2026] [core:error] [pid 643573:tid 643647] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/backup/
[Thu Jul 30 11:50:06.011055 2026] [core:error] [pid 643573:tid 643604] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/backup/
[Thu Jul 30 11:50:06.011083 2026] [core:error] [pid 643573:tid 643604] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/backup/
[Thu Jul 30 11:50:06.223869 2026] [core:error] [pid 643573:tid 643674] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/staging/
[Thu Jul 30 11:50:06.223896 2026] [core:error] [pid 643573:tid 643674] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/staging/
[Thu Jul 30 11:50:06.281893 2026] [security2:error] [pid 643573:tid 643726] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/elp.php"] [unique_id "amuAvvxWyxgRnoFKAJ_twwAAAiQ"]
[Thu Jul 30 11:50:06.282003 2026] [security2:error] [pid 643573:tid 643726] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/elp.php"] [unique_id "amuAvvxWyxgRnoFKAJ_twwAAAiQ"]
[Thu Jul 30 11:50:06.434430 2026] [core:error] [pid 642360:tid 642418] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/staging/
[Thu Jul 30 11:50:06.434450 2026] [core:error] [pid 642360:tid 642418] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/staging/
[Thu Jul 30 11:50:06.607443 2026] [core:error] [pid 643573:tid 643821] [client 35.221.246.130:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:06.607464 2026] [core:error] [pid 643573:tid 643821] [client 35.221.246.130:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:06.607557 2026] [security2:error] [pid 643573:tid 643821] [client 35.221.246.130:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "webdisk.theregentsbarber.com.au"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "amuAvvxWyxgRnoFKAJ_tzgAAAoM"]
[Thu Jul 30 11:50:06.608102 2026] [security2:error] [pid 643573:tid 643793] [client 35.221.246.130:37732] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "webdisk.theregentsbarber.com.au"] [uri "/___proxy_subdomain_webdisk/.git/config"] [unique_id "amuAvvxWyxgRnoFKAJ_tywAAAmc"]
[Thu Jul 30 11:50:06.853605 2026] [security2:error] [pid 643573:tid 643775] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/atomlib.php"] [unique_id "amuAvvxWyxgRnoFKAJ_t2wAAAlU"]
[Thu Jul 30 11:50:06.853700 2026] [security2:error] [pid 643573:tid 643775] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/atomlib.php"] [unique_id "amuAvvxWyxgRnoFKAJ_t2wAAAlU"]
[Thu Jul 30 11:50:06.976659 2026] [core:error] [pid 643573:tid 643637] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/
[Thu Jul 30 11:50:06.976681 2026] [core:error] [pid 643573:tid 643637] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/
[Thu Jul 30 11:50:07.018171 2026] [security2:error] [pid 642360:tid 642558] [client 216.244.66.250:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "embassyofspaininpakistan.info"] [uri "/robots.txt"] [unique_id "amuAv5SUkh3e5AhEJOBpzwAAAdM"]
[Thu Jul 30 11:50:07.018298 2026] [security2:error] [pid 642360:tid 642558] [client 216.244.66.250:0] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "embassyofspaininpakistan.info"] [uri "/robots.txt"] [unique_id "amuAv5SUkh3e5AhEJOBpzwAAAdM"]
[Thu Jul 30 11:50:07.196256 2026] [core:error] [pid 642360:tid 642425] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/
[Thu Jul 30 11:50:07.196294 2026] [core:error] [pid 642360:tid 642425] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/
[Thu Jul 30 11:50:07.257031 2026] [security2:error] [pid 643573:tid 643794] [client 52.167.144.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuAvvxWyxgRnoFKAJ_t3gAAAmg"]
[Thu Jul 30 11:50:07.264861 2026] [core:error] [pid 643573:tid 643751] [client 35.221.246.130:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:07.264881 2026] [core:error] [pid 643573:tid 643751] [client 35.221.246.130:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:07.264996 2026] [security2:error] [pid 643573:tid 643751] [client 35.221.246.130:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "webmail.theregentsbarber.com.au"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amuAv_xWyxgRnoFKAJ_t5wAAAj0"]
[Thu Jul 30 11:50:07.266865 2026] [security2:error] [pid 642360:tid 642595] [client 35.221.246.130:37738] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "webmail.theregentsbarber.com.au"] [uri "/___proxy_subdomain_webmail/.git/config"] [unique_id "amuAv5SUkh3e5AhEJOBp1gAAAfg"]
[Thu Jul 30 11:50:07.274480 2026] [core:error] [pid 643573:tid 643810] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:07.274498 2026] [core:error] [pid 643573:tid 643810] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:07.274604 2026] [core:error] [pid 643573:tid 643712] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:07.274626 2026] [core:error] [pid 643573:tid 643712] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:07.282072 2026] [security2:error] [pid 642360:tid 642428] [remote 52.238.199.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afropakmedical.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "amuAv5SUkh3e5AhEJOBp2AABxEM"]
[Thu Jul 30 11:50:07.313057 2026] [core:error] [pid 643573:tid 643783] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:07.313077 2026] [core:error] [pid 643573:tid 643783] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:07.313423 2026] [core:error] [pid 643573:tid 643722] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:07.313433 2026] [core:error] [pid 643573:tid 643722] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:07.313484 2026] [core:error] [pid 642360:tid 642500] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:07.313500 2026] [core:error] [pid 642360:tid 642500] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:07.444482 2026] [security2:error] [pid 643573:tid 643782] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wyzer3.php"] [unique_id "amuAv_xWyxgRnoFKAJ_t_AAAAlw"]
[Thu Jul 30 11:50:07.444590 2026] [security2:error] [pid 643573:tid 643782] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wyzer3.php"] [unique_id "amuAv_xWyxgRnoFKAJ_t_AAAAlw"]
[Thu Jul 30 11:50:07.980368 2026] [core:error] [pid 642360:tid 642586] [client 35.221.246.130:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:07.980397 2026] [core:error] [pid 642360:tid 642586] [client 35.221.246.130:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:07.980561 2026] [security2:error] [pid 642360:tid 642586] [client 35.221.246.130:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.theregentsbarber.com.au"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amuAv5SUkh3e5AhEJOBp5QAAAe8"]
[Thu Jul 30 11:50:07.981257 2026] [security2:error] [pid 643573:tid 643730] [client 35.221.246.130:37756] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.theregentsbarber.com.au"] [uri "/___proxy_subdomain_cpanel/.git/config"] [unique_id "amuAv_xWyxgRnoFKAJ_uEQAAAig"]
[Thu Jul 30 11:50:07.984160 2026] [security2:error] [pid 642360:tid 642527] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/max.php"] [unique_id "amuAv5SUkh3e5AhEJOBp5gAAAbQ"]
[Thu Jul 30 11:50:07.984247 2026] [security2:error] [pid 642360:tid 642527] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/max.php"] [unique_id "amuAv5SUkh3e5AhEJOBp5gAAAbQ"]
[Thu Jul 30 11:50:08.039005 2026] [security2:error] [pid 643573:tid 643720] [client 57.141.0.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuAv_xWyxgRnoFKAJ_t-wAAAh4"]
[Thu Jul 30 11:50:08.251233 2026] [security2:error] [pid 643573:tid 643725] [client 52.167.144.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuAv_xWyxgRnoFKAJ_uDwAAAiM"]
[Thu Jul 30 11:50:08.413471 2026] [security2:error] [pid 643573:tid 643611] [remote 45.252.248.45:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.248.252.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thesounddepot.com"] [uri "/wp-login.php"] [unique_id "amuAwPxWyxgRnoFKAJ_uHQACiB4"]
[Thu Jul 30 11:50:08.559282 2026] [security2:error] [pid 643573:tid 643793] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/ftde.php"] [unique_id "amuAwPxWyxgRnoFKAJ_uHgAAAmc"]
[Thu Jul 30 11:50:08.559400 2026] [security2:error] [pid 643573:tid 643793] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/ftde.php"] [unique_id "amuAwPxWyxgRnoFKAJ_uHgAAAmc"]
[Thu Jul 30 11:50:08.635703 2026] [security2:error] [pid 643573:tid 643715] [client 20.100.187.246:7781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/.well-known/acme-challenge/xleet.php"] [unique_id "amuAwPxWyxgRnoFKAJ_uHwAAAhk"]
[Thu Jul 30 11:50:08.699498 2026] [security2:error] [pid 642360:tid 642532] [client 35.221.246.130:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.theregentsbarber.com.au"] [uri "/index.php"] [unique_id "amuAv5SUkh3e5AhEJOBp4gAAAbk"]
[Thu Jul 30 11:50:08.699525 2026] [security2:error] [pid 642360:tid 642532] [client 35.221.246.130:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.theregentsbarber.com.au"] [uri "/index.php"] [unique_id "amuAv5SUkh3e5AhEJOBp4gAAAbk"]
[Thu Jul 30 11:50:08.700170 2026] [security2:error] [pid 642360:tid 642556] [client 35.221.246.130:37748] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.theregentsbarber.com.au"] [uri "/.git/config"] [unique_id "amuAv5SUkh3e5AhEJOBp4AAAAdE"]
[Thu Jul 30 11:50:08.768648 2026] [core:notice] [pid 643573:tid 643827] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:08.802141 2026] [security2:error] [pid 643573:tid 643754] [client 35.221.246.130:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.theregentsbarber.com.au"] [uri "/index.php"] [unique_id "amuAvvxWyxgRnoFKAJ_t2gAAAkA"]
[Thu Jul 30 11:50:08.802176 2026] [security2:error] [pid 643573:tid 643754] [client 35.221.246.130:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.theregentsbarber.com.au"] [uri "/index.php"] [unique_id "amuAvvxWyxgRnoFKAJ_t2gAAAkA"]
[Thu Jul 30 11:50:08.803003 2026] [security2:error] [pid 643573:tid 643759] [client 35.221.246.130:37720] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.theregentsbarber.com.au"] [uri "/.git/config"] [unique_id "amuAvvxWyxgRnoFKAJ_t2AAAAkU"]
[Thu Jul 30 11:50:09.109387 2026] [security2:error] [pid 643573:tid 643796] [client 35.221.246.130:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-d54872a1.ear.djb.temporary.site"] [uri "/index.php"] [unique_id "amuAvvxWyxgRnoFKAJ_t0wAAAmo"]
[Thu Jul 30 11:50:09.109421 2026] [security2:error] [pid 643573:tid 643796] [client 35.221.246.130:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.website-d54872a1.ear.djb.temporary.site"] [uri "/index.php"] [unique_id "amuAvvxWyxgRnoFKAJ_t0wAAAmo"]
[Thu Jul 30 11:50:09.110023 2026] [security2:error] [pid 642360:tid 642539] [client 35.221.246.130:37706] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.website-d54872a1.ear.djb.temporary.site"] [uri "/.git/config"] [unique_id "amuAvpSUkh3e5AhEJOBpzgAAAcA"]
[Thu Jul 30 11:50:09.713660 2026] [security2:error] [pid 643573:tid 643725] [client 20.100.187.246:14873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amuAwfxWyxgRnoFKAJ_uNwAAAiM"]
[Thu Jul 30 11:50:10.142833 2026] [security2:error] [pid 642360:tid 642576] [client 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAwZSUkh3e5AhEJOBp_AAB5TA"]
[Thu Jul 30 11:50:10.312152 2026] [core:notice] [pid 643573:tid 643752] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:10.318764 2026] [security2:error] [pid 643573:tid 643752] [client 103.215.74.26:47924] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAwvxWyxgRnoFKAJ_uRQAAAj4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:10.753595 2026] [security2:error] [pid 643573:tid 643775] [client 176.241.66.87:64760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAwvxWyxgRnoFKAJ_uUAAAAlU"]
[Thu Jul 30 11:50:10.753703 2026] [security2:error] [pid 643573:tid 643775] [client 176.241.66.87:64760] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAwvxWyxgRnoFKAJ_uUAAAAlU"]
[Thu Jul 30 11:50:10.920421 2026] [security2:error] [pid 643573:tid 643788] [client 20.100.187.246:20994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/.well-known/pki-validation/autoload_classmap.php"] [unique_id "amuAwvxWyxgRnoFKAJ_uVQAAAmI"]
[Thu Jul 30 11:50:10.997226 2026] [core:notice] [pid 643573:tid 643805] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:11.063461 2026] [core:notice] [pid 643573:tid 643758] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:11.070962 2026] [security2:error] [pid 643573:tid 643758] [client 103.215.74.26:47936] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAw_xWyxgRnoFKAJ_uVwAAAkQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:11.814004 2026] [core:notice] [pid 642360:tid 642551] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:11.817880 2026] [security2:error] [pid 642360:tid 642551] [client 103.215.74.26:47952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAw5SUkh3e5AhEJOBqCwAAAcw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:12.417539 2026] [core:error] [pid 643573:tid 643731] [client 74.7.241.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:12.417563 2026] [core:error] [pid 643573:tid 643731] [client 74.7.241.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:12.417704 2026] [security2:error] [pid 643573:tid 643731] [client 74.7.241.152:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.hvacairductscleaners.us"] [uri "/website_141a2c45/index.php"] [unique_id "amuAxPxWyxgRnoFKAJ_uagAAAik"]
[Thu Jul 30 11:50:12.418902 2026] [security2:error] [pid 643573:tid 643759] [client 74.7.241.152:42592] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.hvacairductscleaners.us"] [uri "/robots.txt"] [unique_id "amuAxPxWyxgRnoFKAJ_uaAACRUw"]
[Thu Jul 30 11:50:12.437454 2026] [security2:error] [pid 643253:tid 643275] [remote 74.7.241.60:41884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/article.php"] [unique_id "amuAxMjqbtjBYzqM1uYlwQAAUBQ"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/bootstrap.bundle.min.js
[Thu Jul 30 11:50:13.843132 2026] [security2:error] [pid 643573:tid 643803] [client 20.100.187.246:14894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/.well-known/pki-validation/flower.php"] [unique_id "amuAxfxWyxgRnoFKAJ_ueAAAAnE"]
[Thu Jul 30 11:50:14.302621 2026] [proxy:error] [pid 643253:tid 643454] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:50:14.302696 2026] [proxy_http:error] [pid 643253:tid 643454] [client 74.7.241.156:52084] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:50:14.303266 2026] [proxy:error] [pid 643253:tid 643454] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:50:14.303317 2026] [proxy_http:error] [pid 643253:tid 643454] [client 74.7.241.156:52084] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:50:14.303447 2026] [security2:error] [pid 643253:tid 643454] [client 74.7.241.156:52084] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "cpcontacts.qse.gzj.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuAxsjqbtjBYzqM1uYlwwAAAEY"]
[Thu Jul 30 11:50:15.631852 2026] [security2:error] [pid 643573:tid 643653] [remote 173.231.241.109:51516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.241.231.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ldk.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuAx_xWyxgRnoFKAJ_uhgACikg"]
[Thu Jul 30 11:50:16.716436 2026] [core:error] [pid 642360:tid 642531] [client 162.19.8.250:49518] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:16.716468 2026] [core:error] [pid 642360:tid 642531] [client 162.19.8.250:49518] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:17.551277 2026] [core:notice] [pid 643573:tid 643815] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:17.555341 2026] [security2:error] [pid 643573:tid 643815] [client 103.215.74.26:34376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "761"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAyfxWyxgRnoFKAJ_ulQAAAn0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:17.642465 2026] [core:error] [pid 643573:tid 643726] [client 162.19.8.250:49534] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:17.642485 2026] [core:error] [pid 643573:tid 643726] [client 162.19.8.250:49534] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:17.655747 2026] [core:notice] [pid 643573:tid 643669] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:18.310962 2026] [core:notice] [pid 643573:tid 643792] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:18.317097 2026] [security2:error] [pid 643573:tid 643792] [client 103.215.74.26:34378] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAyvxWyxgRnoFKAJ_unwAAAmY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:18.413245 2026] [core:error] [pid 643573:tid 643824] [client 162.19.8.250:49550] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:18.413267 2026] [core:error] [pid 643573:tid 643824] [client 162.19.8.250:49550] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:18.945814 2026] [core:error] [pid 643573:tid 643732] [client 162.19.8.250:49564] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:18.945841 2026] [core:error] [pid 643573:tid 643732] [client 162.19.8.250:49564] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:19.063340 2026] [core:notice] [pid 643573:tid 643793] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:19.067296 2026] [security2:error] [pid 643573:tid 643793] [client 103.215.74.26:34380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "774"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAy_xWyxgRnoFKAJ_uqQAAAmc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:19.437321 2026] [core:notice] [pid 643573:tid 643672] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:19.559167 2026] [core:error] [pid 642360:tid 642565] [client 162.19.8.250:49580] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:19.559194 2026] [core:error] [pid 642360:tid 642565] [client 162.19.8.250:49580] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:19.826762 2026] [core:notice] [pid 643573:tid 643752] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:19.831352 2026] [security2:error] [pid 643573:tid 643752] [client 103.215.74.26:34386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "746"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAy_xWyxgRnoFKAJ_usAAAAj4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:20.150648 2026] [core:error] [pid 643573:tid 643765] [client 162.19.8.250:49596] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:20.150671 2026] [core:error] [pid 643573:tid 643765] [client 162.19.8.250:49596] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:20.215464 2026] [security2:error] [pid 643573:tid 643749] [client 103.216.116.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuAzPxWyxgRnoFKAJ_usgAAAjs"], referer: https://cnpinyin.com/register
[Thu Jul 30 11:50:20.579219 2026] [core:notice] [pid 643573:tid 643731] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:20.583937 2026] [security2:error] [pid 643573:tid 643731] [client 103.215.74.26:34388] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAzPxWyxgRnoFKAJ_uuAAAAik"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:20.714731 2026] [core:error] [pid 642360:tid 642612] [client 162.19.8.250:49612] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:20.714751 2026] [core:error] [pid 642360:tid 642612] [client 162.19.8.250:49612] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:20.997902 2026] [security2:error] [pid 643573:tid 643717] [client 20.100.187.246:21116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/.well-known/pki-validation/xleet.php"] [unique_id "amuAzPxWyxgRnoFKAJ_uvwAAAhs"]
[Thu Jul 30 11:50:21.207621 2026] [core:error] [pid 643573:tid 643833] [client 162.19.8.250:49626] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:21.207651 2026] [core:error] [pid 643573:tid 643833] [client 162.19.8.250:49626] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:21.318886 2026] [core:notice] [pid 643573:tid 643756] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:21.322738 2026] [security2:error] [pid 643573:tid 643756] [client 103.215.74.26:34394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "756"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAzfxWyxgRnoFKAJ_uwgAAAkI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:21.357487 2026] [security2:error] [pid 643573:tid 643809] [client 176.241.66.87:65312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAzfxWyxgRnoFKAJ_uxgAAAnc"]
[Thu Jul 30 11:50:21.357643 2026] [security2:error] [pid 643573:tid 643809] [client 176.241.66.87:65312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAzfxWyxgRnoFKAJ_uxgAAAnc"]
[Thu Jul 30 11:50:21.676512 2026] [core:error] [pid 643573:tid 643721] [client 162.19.8.250:49634] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:21.676542 2026] [core:error] [pid 643573:tid 643721] [client 162.19.8.250:49634] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:22.072249 2026] [core:notice] [pid 642360:tid 642500] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:22.076773 2026] [security2:error] [pid 642360:tid 642500] [client 103.215.74.26:34402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAzpSUkh3e5AhEJOBqXAAAAZk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:22.251212 2026] [core:error] [pid 643573:tid 643819] [client 162.19.8.250:49640] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:22.251242 2026] [core:error] [pid 643573:tid 643819] [client 162.19.8.250:49640] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:22.340317 2026] [security2:error] [pid 643573:tid 643725] [client 20.100.187.246:7736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/.wp-cli/autoload_classmap.php"] [unique_id "amuAzvxWyxgRnoFKAJ_u0QAAAiM"]
[Thu Jul 30 11:50:22.776515 2026] [core:error] [pid 643253:tid 643465] [client 162.19.8.250:49646] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:22.776546 2026] [core:error] [pid 643253:tid 643465] [client 162.19.8.250:49646] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:22.827730 2026] [core:notice] [pid 643573:tid 643818] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:22.831950 2026] [security2:error] [pid 643573:tid 643818] [client 103.215.74.26:34414] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "745"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAzvxWyxgRnoFKAJ_u1gAAAoA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:22.972874 2026] [security2:error] [pid 643573:tid 643723] [client 20.100.187.246:7831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/.wp-cli/flower.php"] [unique_id "amuAzvxWyxgRnoFKAJ_u2gAAAiE"]
[Thu Jul 30 11:50:23.167497 2026] [core:error] [pid 643573:tid 643726] [client 162.19.8.250:49656] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:23.167518 2026] [core:error] [pid 643573:tid 643726] [client 162.19.8.250:49656] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:23.598431 2026] [core:notice] [pid 643573:tid 643745] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:23.602656 2026] [security2:error] [pid 643573:tid 643745] [client 103.215.74.26:19864] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "745"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAz_xWyxgRnoFKAJ_u5AAAAjc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:23.775497 2026] [core:error] [pid 643573:tid 643804] [client 162.19.8.250:49670] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:23.775524 2026] [core:error] [pid 643573:tid 643804] [client 162.19.8.250:49670] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:23.985426 2026] [security2:error] [pid 643573:tid 643665] [remote 47.128.28.112:33292] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/nike-aj1-air-jordan-1-low-christmas-white-red/"] [unique_id "amuAz_xWyxgRnoFKAJ_u6QACe1Q"]
[Thu Jul 30 11:50:24.199527 2026] [core:error] [pid 643253:tid 643439] [client 162.19.8.250:49676] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:24.199558 2026] [core:error] [pid 643253:tid 643439] [client 162.19.8.250:49676] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:24.364730 2026] [core:notice] [pid 643573:tid 643750] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:24.369063 2026] [security2:error] [pid 643573:tid 643750] [client 103.215.74.26:19880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA0PxWyxgRnoFKAJ_u7AAAAjw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:24.715558 2026] [core:notice] [pid 643573:tid 643660] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:24.782991 2026] [core:error] [pid 643573:tid 643818] [client 162.19.8.250:49684] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:24.783012 2026] [core:error] [pid 643573:tid 643818] [client 162.19.8.250:49684] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:24.795320 2026] [security2:error] [pid 643573:tid 643760] [client 20.100.187.246:29298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/.wp-cli/xleet.php"] [unique_id "amuA0PxWyxgRnoFKAJ_u9QAAAkY"]
[Thu Jul 30 11:50:25.084738 2026] [core:notice] [pid 643573:tid 643795] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:25.089093 2026] [security2:error] [pid 643573:tid 643795] [client 103.215.74.26:19890] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA0fxWyxgRnoFKAJ_u-AAAAmk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:25.545900 2026] [security2:error] [pid 643573:tid 643823] [client 20.100.187.246:7697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amuA0fxWyxgRnoFKAJ_u-gAAAoU"]
[Thu Jul 30 11:50:25.811602 2026] [core:notice] [pid 643573:tid 643810] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:25.815913 2026] [security2:error] [pid 643573:tid 643810] [client 103.215.74.26:19894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA0fxWyxgRnoFKAJ_u_wAAAng"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:26.217601 2026] [security2:error] [pid 643573:tid 643762] [client 20.100.187.246:7729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-admin/network/flower.php"] [unique_id "amuA0vxWyxgRnoFKAJ_vBQAAAkg"]
[Thu Jul 30 11:50:26.405833 2026] [core:error] [pid 643573:tid 643715] [client 162.19.8.250:58352] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:26.405857 2026] [core:error] [pid 643573:tid 643715] [client 162.19.8.250:58352] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:26.552198 2026] [core:notice] [pid 643253:tid 643474] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:26.556707 2026] [security2:error] [pid 643253:tid 643474] [client 103.215.74.26:19898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA0sjqbtjBYzqM1uYl0wAAAFo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:26.800860 2026] [core:error] [pid 642360:tid 642518] [client 162.19.8.250:58368] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:26.800882 2026] [core:error] [pid 642360:tid 642518] [client 162.19.8.250:58368] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:26.900691 2026] [security2:error] [pid 643573:tid 643800] [client 20.100.187.246:14389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-admin/network/xleet.php/wp-content/flower.php"] [unique_id "amuA0vxWyxgRnoFKAJ_vCAAAAm4"]
[Thu Jul 30 11:50:27.301645 2026] [core:error] [pid 643253:tid 643502] [client 162.19.8.250:58384] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:27.301668 2026] [core:error] [pid 643253:tid 643502] [client 162.19.8.250:58384] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:27.305703 2026] [core:notice] [pid 643573:tid 643769] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:27.310016 2026] [security2:error] [pid 643573:tid 643769] [client 103.215.74.26:19908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA0_xWyxgRnoFKAJ_vDgAAAk8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:27.564684 2026] [security2:error] [pid 643573:tid 643743] [client 20.100.187.246:12644] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.lilyinspires.com"] [uri "/1.php"] [unique_id "amuA0_xWyxgRnoFKAJ_vDwAAAjU"]
[Thu Jul 30 11:50:27.564824 2026] [security2:error] [pid 643573:tid 643743] [client 20.100.187.246:12644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/1.php"] [unique_id "amuA0_xWyxgRnoFKAJ_vDwAAAjU"]
[Thu Jul 30 11:50:27.713020 2026] [core:error] [pid 643573:tid 643760] [client 162.19.8.250:58398] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:27.713042 2026] [core:error] [pid 643573:tid 643760] [client 162.19.8.250:58398] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:28.035171 2026] [core:notice] [pid 643573:tid 643716] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:28.039581 2026] [security2:error] [pid 643573:tid 643716] [client 103.215.74.26:19920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA1PxWyxgRnoFKAJ_vFgAAAho"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:28.117730 2026] [security2:error] [pid 643573:tid 643747] [client 74.7.228.57:53842] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.ooj.hfl.temporary.site"] [uri "/index.php"] [unique_id "amuA0_xWyxgRnoFKAJ_vFAACOR0"]
[Thu Jul 30 11:50:28.713153 2026] [security2:error] [pid 643573:tid 643766] [client 20.100.187.246:29259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/admin.php"] [unique_id "amuA1PxWyxgRnoFKAJ_vHQAAAkw"]
[Thu Jul 30 11:50:29.526639 2026] [security2:error] [pid 643573:tid 643800] [client 20.100.187.246:7680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/as.php"] [unique_id "amuA1fxWyxgRnoFKAJ_vJwAAAm4"]
[Thu Jul 30 11:50:31.077621 2026] [security2:error] [pid 643573:tid 643720] [client 20.100.187.246:19549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/autoload_classmap.php"] [unique_id "amuA1_xWyxgRnoFKAJ_vNQAAAh4"]
[Thu Jul 30 11:50:31.341337 2026] [autoindex:error] [pid 643253:tid 643417] [client 43.135.145.73:53826] AH01276: Cannot serve directory /home2/dovdtnte/public_html/rodneyleesmith/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:50:31.536343 2026] [security2:error] [pid 643573:tid 643776] [client 66.249.64.73:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.skilledfurnituremoversuae.com"] [uri "/index.php"] [unique_id "amuA1fxWyxgRnoFKAJ_vJQAAAlY"]
[Thu Jul 30 11:50:31.986139 2026] [security2:error] [pid 643573:tid 643755] [client 176.241.66.87:13167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuA1_xWyxgRnoFKAJ_vPgAAAkE"]
[Thu Jul 30 11:50:31.986269 2026] [security2:error] [pid 643573:tid 643755] [client 176.241.66.87:13167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuA1_xWyxgRnoFKAJ_vPgAAAkE"]
[Thu Jul 30 11:50:33.773966 2026] [core:notice] [pid 643573:tid 643764] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:33.778400 2026] [security2:error] [pid 643573:tid 643764] [client 103.215.74.26:5832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA2fxWyxgRnoFKAJ_vSQAAAko"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:33.952153 2026] [core:error] [pid 643573:tid 643662] [remote 216.73.216.82:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:33.952175 2026] [core:error] [pid 643573:tid 643662] [remote 216.73.216.82:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:34.478951 2026] [security2:error] [pid 643573:tid 643711] [client 20.100.187.246:13313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/back.php"] [unique_id "amuA2vxWyxgRnoFKAJ_vUQAAAhU"]
[Thu Jul 30 11:50:35.486685 2026] [security2:error] [pid 643573:tid 643772] [client 20.100.187.246:13353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/c/autoload_classmap.php"] [unique_id "amuA2_xWyxgRnoFKAJ_vZQAAAlI"]
[Thu Jul 30 11:50:36.401312 2026] [security2:error] [pid 643253:tid 643508] [client 127.0.0.1:13056] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuA3MjqbtjBYzqM1uYl6AAAAHw"]
[Thu Jul 30 11:50:36.402368 2026] [security2:error] [pid 642360:tid 642593] [client 74.7.228.62:44578] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.qmv.zzt.temporary.site"] [uri "/robots.txt"] [unique_id "amuA3JSUkh3e5AhEJOBq1wAAAfY"]
[Thu Jul 30 11:50:36.535739 2026] [security2:error] [pid 643573:tid 643820] [client 172.237.109.114:14406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA2_xWyxgRnoFKAJ_vVwAAAoI"]
[Thu Jul 30 11:50:37.182376 2026] [core:notice] [pid 643573:tid 643718] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:37.219449 2026] [security2:error] [pid 642360:tid 642509] [client 172.237.109.114:42514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA25SUkh3e5AhEJOBqxQAAAaI"]
[Thu Jul 30 11:50:37.225960 2026] [security2:error] [pid 642360:tid 642590] [client 172.237.109.114:9546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA25SUkh3e5AhEJOBqwgAAAfM"]
[Thu Jul 30 11:50:37.228672 2026] [security2:error] [pid 643573:tid 643800] [client 172.237.109.114:35766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA2_xWyxgRnoFKAJ_vWwAAAm4"]
[Thu Jul 30 11:50:37.253016 2026] [security2:error] [pid 643573:tid 643817] [client 172.237.109.114:60726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA2_xWyxgRnoFKAJ_vXQAAAn8"]
[Thu Jul 30 11:50:37.255277 2026] [security2:error] [pid 643573:tid 643754] [client 172.237.109.114:63104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA2_xWyxgRnoFKAJ_vWgAAAkA"]
[Thu Jul 30 11:50:37.266235 2026] [security2:error] [pid 642360:tid 642614] [client 172.237.109.114:58275] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA25SUkh3e5AhEJOBqyQAAAgs"]
[Thu Jul 30 11:50:37.290561 2026] [security2:error] [pid 642360:tid 642542] [client 172.237.109.114:19998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA25SUkh3e5AhEJOBqygAAAcM"]
[Thu Jul 30 11:50:37.302735 2026] [security2:error] [pid 643573:tid 643827] [client 172.237.109.114:41738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA2_xWyxgRnoFKAJ_vWAAAAok"]
[Thu Jul 30 11:50:37.310692 2026] [security2:error] [pid 642360:tid 642560] [client 172.237.109.114:38131] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA25SUkh3e5AhEJOBqxwAAAdU"]
[Thu Jul 30 11:50:37.331049 2026] [security2:error] [pid 643573:tid 643803] [client 172.237.109.114:45642] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA2_xWyxgRnoFKAJ_vWQAAAnE"]
[Thu Jul 30 11:50:37.331628 2026] [security2:error] [pid 643573:tid 643773] [client 172.237.109.114:4834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA2_xWyxgRnoFKAJ_vYAAAAlM"]
[Thu Jul 30 11:50:37.339936 2026] [security2:error] [pid 643573:tid 643750] [client 172.237.109.114:40932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA2_xWyxgRnoFKAJ_vYwAAAjw"]
[Thu Jul 30 11:50:37.343196 2026] [security2:error] [pid 643253:tid 643447] [client 172.237.109.114:36517] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA28jqbtjBYzqM1uYl4wAAAD8"]
[Thu Jul 30 11:50:37.350920 2026] [security2:error] [pid 642360:tid 642577] [client 172.237.109.114:31979] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA25SUkh3e5AhEJOBqyAAAAeY"]
[Thu Jul 30 11:50:37.357204 2026] [security2:error] [pid 642360:tid 642611] [client 172.237.109.114:30203] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA25SUkh3e5AhEJOBqwwAAAgg"]
[Thu Jul 30 11:50:37.392436 2026] [security2:error] [pid 643573:tid 643729] [client 172.237.109.114:45415] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA2_xWyxgRnoFKAJ_vXgAAAic"]
[Thu Jul 30 11:50:37.392527 2026] [security2:error] [pid 642360:tid 642550] [client 172.237.109.114:30844] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA25SUkh3e5AhEJOBqywAAAcs"]
[Thu Jul 30 11:50:37.406268 2026] [security2:error] [pid 643573:tid 643789] [client 172.237.109.114:25015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA2_xWyxgRnoFKAJ_vZAAAAmM"]
[Thu Jul 30 11:50:37.417939 2026] [security2:error] [pid 643253:tid 643470] [client 172.237.109.114:7425] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA28jqbtjBYzqM1uYl4gAAAFY"]
[Thu Jul 30 11:50:37.997814 2026] [security2:error] [pid 643253:tid 643393] [client 20.100.187.246:12642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/c/flower.php"] [unique_id "amuA3cjqbtjBYzqM1uYl6wAAAAk"]
[Thu Jul 30 11:50:38.927378 2026] [security2:error] [pid 643573:tid 643788] [client 20.100.187.246:12615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/c/xleet.php"] [unique_id "amuA3vxWyxgRnoFKAJ_vhwAAAmI"]
[Thu Jul 30 11:50:39.275801 2026] [security2:error] [pid 643573:tid 643829] [client 172.237.109.114:6474] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3fxWyxgRnoFKAJ_vdgAAAos"]
[Thu Jul 30 11:50:39.309547 2026] [security2:error] [pid 643573:tid 643711] [client 172.237.109.114:26727] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3fxWyxgRnoFKAJ_vcQAAAhU"]
[Thu Jul 30 11:50:39.309626 2026] [security2:error] [pid 643573:tid 643724] [client 172.237.109.114:53130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3fxWyxgRnoFKAJ_vdQAAAiI"]
[Thu Jul 30 11:50:39.312946 2026] [security2:error] [pid 642360:tid 642507] [client 172.237.109.114:47388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3ZSUkh3e5AhEJOBq3wAAAaA"]
[Thu Jul 30 11:50:39.315152 2026] [security2:error] [pid 642360:tid 642603] [client 172.237.109.114:45681] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3ZSUkh3e5AhEJOBq4AAAAgA"]
[Thu Jul 30 11:50:39.328699 2026] [security2:error] [pid 643573:tid 643797] [client 172.237.109.114:64947] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3fxWyxgRnoFKAJ_veAAAAms"]
[Thu Jul 30 11:50:39.339370 2026] [security2:error] [pid 643253:tid 643423] [client 172.237.109.114:14625] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3cjqbtjBYzqM1uYl6gAAACc"]
[Thu Jul 30 11:50:39.344403 2026] [security2:error] [pid 643573:tid 643802] [client 172.237.109.114:7824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3fxWyxgRnoFKAJ_vegAAAnA"]
[Thu Jul 30 11:50:39.348298 2026] [security2:error] [pid 642360:tid 642512] [client 172.237.109.114:9820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3ZSUkh3e5AhEJOBq4wAAAaU"]
[Thu Jul 30 11:50:39.364354 2026] [security2:error] [pid 643573:tid 643755] [client 172.237.109.114:17269] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3fxWyxgRnoFKAJ_vcwAAAkE"]
[Thu Jul 30 11:50:39.364949 2026] [security2:error] [pid 643573:tid 643784] [client 172.237.109.114:54214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3fxWyxgRnoFKAJ_veQAAAl4"]
[Thu Jul 30 11:50:39.373443 2026] [security2:error] [pid 643573:tid 643819] [client 172.237.109.114:63931] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3fxWyxgRnoFKAJ_vewAAAoE"]
[Thu Jul 30 11:50:39.379385 2026] [security2:error] [pid 642360:tid 642563] [client 172.237.109.114:29249] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3ZSUkh3e5AhEJOBq3QAAAdg"]
[Thu Jul 30 11:50:39.399482 2026] [security2:error] [pid 643573:tid 643811] [client 172.237.109.114:38727] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3fxWyxgRnoFKAJ_vcgAAAnk"]
[Thu Jul 30 11:50:39.405080 2026] [security2:error] [pid 642360:tid 642522] [client 172.237.109.114:6124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3ZSUkh3e5AhEJOBq3gAAAa8"]
[Thu Jul 30 11:50:39.412496 2026] [security2:error] [pid 643573:tid 643821] [client 172.237.109.114:42556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3fxWyxgRnoFKAJ_vdAAAAoM"]
[Thu Jul 30 11:50:39.521883 2026] [core:notice] [pid 643253:tid 643408] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:39.529325 2026] [security2:error] [pid 643253:tid 643408] [client 103.215.74.26:5862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA38jqbtjBYzqM1uYl8AAAABg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:39.539838 2026] [security2:error] [pid 642360:tid 642580] [client 172.237.109.114:2991] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3pSUkh3e5AhEJOBq6AAAAek"]
[Thu Jul 30 11:50:39.555482 2026] [security2:error] [pid 642360:tid 642520] [client 172.237.109.114:7903] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3pSUkh3e5AhEJOBq6gAAAa0"]
[Thu Jul 30 11:50:39.558546 2026] [security2:error] [pid 643573:tid 643775] [client 172.237.109.114:7802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3vxWyxgRnoFKAJ_vggAAAlU"]
[Thu Jul 30 11:50:39.583470 2026] [security2:error] [pid 642360:tid 642610] [client 172.237.109.114:26425] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3pSUkh3e5AhEJOBq6QAAAgc"]
[Thu Jul 30 11:50:39.650388 2026] [security2:error] [pid 643253:tid 643488] [client 20.100.187.246:19540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/classwithtostring.php"] [unique_id "amuA38jqbtjBYzqM1uYl8QAAAGg"]
[Thu Jul 30 11:50:39.695695 2026] [lsapi:error] [pid 643573:tid 643689] [remote 102.209.111.62:0] [host flixon.net] Error receiving response: ReceiveResponse: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1009; user ID 1009), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://flixon.net/video/teen-lust-vj-emmy/
[Thu Jul 30 11:50:39.799727 2026] [security2:error] [pid 643573:tid 643756] [client 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuA3_xWyxgRnoFKAJ_viwACQmI"]
[Thu Jul 30 11:50:39.952387 2026] [security2:error] [pid 643573:tid 643815] [client 213.152.186.19:33486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuA3_xWyxgRnoFKAJ_vkAAAAn0"]
[Thu Jul 30 11:50:39.952534 2026] [security2:error] [pid 643573:tid 643815] [client 213.152.186.19:33486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuA3_xWyxgRnoFKAJ_vkAAAAn0"]
[Thu Jul 30 11:50:39.975315 2026] [security2:error] [pid 642360:tid 642543] [client 57.141.0.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuA35SUkh3e5AhEJOBq9AAAAcQ"]
[Thu Jul 30 11:50:40.282946 2026] [core:notice] [pid 643573:tid 643757] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:40.287255 2026] [security2:error] [pid 643573:tid 643757] [client 103.215.74.26:5870] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA4PxWyxgRnoFKAJ_vlwAAAkM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:40.492149 2026] [security2:error] [pid 643573:tid 643807] [client 20.100.187.246:36453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/content.php"] [unique_id "amuA4PxWyxgRnoFKAJ_vmAAAAnU"]
[Thu Jul 30 11:50:41.050542 2026] [core:notice] [pid 642360:tid 642559] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:41.057072 2026] [security2:error] [pid 642360:tid 642559] [client 103.215.74.26:5884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "745"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA4ZSUkh3e5AhEJOBrBQAAAdQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:41.473153 2026] [security2:error] [pid 643573:tid 643712] [client 20.100.187.246:18004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/doc.php"] [unique_id "amuA4fxWyxgRnoFKAJ_vnAAAAhY"]
[Thu Jul 30 11:50:41.793758 2026] [core:notice] [pid 643573:tid 643776] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:41.797472 2026] [security2:error] [pid 643573:tid 643776] [client 103.215.74.26:5900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA4fxWyxgRnoFKAJ_vnwAAAlY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:42.529898 2026] [core:notice] [pid 643573:tid 643786] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:42.533924 2026] [security2:error] [pid 643573:tid 643786] [client 103.215.74.26:5912] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA4vxWyxgRnoFKAJ_vpQAAAmA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:42.771067 2026] [security2:error] [pid 643573:tid 643728] [client 176.241.66.87:13855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuA4vxWyxgRnoFKAJ_vqgAAAiY"]
[Thu Jul 30 11:50:42.771202 2026] [security2:error] [pid 643573:tid 643728] [client 176.241.66.87:13855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuA4vxWyxgRnoFKAJ_vqgAAAiY"]
[Thu Jul 30 11:50:43.244880 2026] [security2:error] [pid 642360:tid 642496] [client 74.7.228.56:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "www.odk.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amuA45SUkh3e5AhEJOBrEwAAAZU"]
[Thu Jul 30 11:50:43.245376 2026] [security2:error] [pid 643573:tid 643796] [client 74.7.228.56:52742] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "www.odk.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amuA4_xWyxgRnoFKAJ_vrgAAAmo"]
[Thu Jul 30 11:50:43.306345 2026] [core:notice] [pid 643573:tid 643785] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:43.310594 2026] [security2:error] [pid 643573:tid 643785] [client 103.215.74.26:24554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA4_xWyxgRnoFKAJ_vsAAAAl8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:43.501688 2026] [security2:error] [pid 643573:tid 643763] [client 74.7.228.56:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.odk.udi.temporary.site"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "amuA4_xWyxgRnoFKAJ_vswAAAkk"], referer: https://www.odk.udi.temporary.site/robots.txt
[Thu Jul 30 11:50:43.502214 2026] [security2:error] [pid 643573:tid 643780] [client 74.7.228.56:52742] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.odk.udi.temporary.site"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "amuA4_xWyxgRnoFKAJ_vsQAAAlo"], referer: https://www.odk.udi.temporary.site/robots.txt
[Thu Jul 30 11:50:44.065931 2026] [core:notice] [pid 643573:tid 643720] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:44.072735 2026] [security2:error] [pid 643573:tid 643720] [client 103.215.74.26:24564] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA5PxWyxgRnoFKAJ_vugAAAh4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:44.155552 2026] [security2:error] [pid 643573:tid 643751] [client 20.91.199.21:47586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/json.php"] [unique_id "amuA5PxWyxgRnoFKAJ_vvAAAAj0"]
[Thu Jul 30 11:50:44.472693 2026] [core:notice] [pid 643573:tid 643788] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:44.476238 2026] [security2:error] [pid 643573:tid 643788] [client 66.249.79.1:52381] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/camic/issue/archive"] [unique_id "amuA5PxWyxgRnoFKAJ_vvgAAAmI"]
[Thu Jul 30 11:50:44.790494 2026] [core:notice] [pid 643253:tid 643394] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:44.797150 2026] [security2:error] [pid 643253:tid 643394] [client 103.215.74.26:24574] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA5MjqbtjBYzqM1uYl9AAAAAo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:44.809890 2026] [core:error] [pid 642360:tid 642453] [remote 74.7.230.55:34116] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:44.809915 2026] [core:error] [pid 642360:tid 642453] [remote 74.7.230.55:34116] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:44.810064 2026] [security2:error] [pid 642360:tid 642568] [client 74.7.230.55:34116] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "albayanfurnituremovers.cc"] [uri "/index.php"] [unique_id "amuA5JSUkh3e5AhEJOBrJAAB3Vw"]
[Thu Jul 30 11:50:44.866403 2026] [security2:error] [pid 643253:tid 643483] [client 20.100.187.246:12174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/dropdown.php"] [unique_id "amuA5MjqbtjBYzqM1uYl9QAAAGM"]
[Thu Jul 30 11:50:45.229081 2026] [security2:error] [pid 643253:tid 643430] [client 127.0.0.1:38766] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuA5cjqbtjBYzqM1uYl9wAAAC4"]
[Thu Jul 30 11:50:45.229143 2026] [security2:error] [pid 643253:tid 643432] [client 74.7.244.44:37928] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.ege.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuA5cjqbtjBYzqM1uYl9gAAMCE"]
[Thu Jul 30 11:50:45.378546 2026] [core:notice] [pid 643253:tid 643289] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:45.535679 2026] [core:notice] [pid 643253:tid 643422] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:45.541214 2026] [security2:error] [pid 643253:tid 643422] [client 103.215.74.26:24588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "745"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA5cjqbtjBYzqM1uYl-QAAACY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:45.618737 2026] [security2:error] [pid 643573:tid 643810] [client 172.237.109.114:14165] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA5fxWyxgRnoFKAJ_vxwAAAng"]
[Thu Jul 30 11:50:45.627259 2026] [security2:error] [pid 643573:tid 643730] [client 172.237.109.114:58169] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA5fxWyxgRnoFKAJ_vyAAAAig"]
[Thu Jul 30 11:50:45.671964 2026] [security2:error] [pid 643573:tid 643714] [client 172.237.109.114:1872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA5fxWyxgRnoFKAJ_vyQAAAhg"]
[Thu Jul 30 11:50:45.688972 2026] [security2:error] [pid 643573:tid 643776] [client 172.237.109.114:28595] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA5fxWyxgRnoFKAJ_vygAAAlY"]
[Thu Jul 30 11:50:45.744854 2026] [security2:error] [pid 643573:tid 643745] [client 172.237.109.114:34844] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA5fxWyxgRnoFKAJ_vywAAAjc"]
[Thu Jul 30 11:50:45.772921 2026] [security2:error] [pid 643573:tid 643836] [client 172.237.109.114:38078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA5fxWyxgRnoFKAJ_vzAAAApI"]
[Thu Jul 30 11:50:45.914404 2026] [security2:error] [pid 642360:tid 642547] [client 20.91.199.21:47598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/mini.php"] [unique_id "amuA5ZSUkh3e5AhEJOBrMQAAAcg"]
[Thu Jul 30 11:50:46.311516 2026] [core:notice] [pid 643573:tid 643781] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:46.315530 2026] [security2:error] [pid 643573:tid 643781] [client 103.215.74.26:24594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "763"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA5vxWyxgRnoFKAJ_v0wAAAls"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:46.411802 2026] [core:notice] [pid 643573:tid 643697] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:46.414915 2026] [security2:error] [pid 643573:tid 643715] [client 20.100.187.246:12181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/ee.php"] [unique_id "amuA5vxWyxgRnoFKAJ_v2gAAAhk"]
[Thu Jul 30 11:50:46.748769 2026] [security2:error] [pid 642360:tid 642522] [client 20.91.199.21:47555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/chosen.php"] [unique_id "amuA5pSUkh3e5AhEJOBrNgAAAa8"]
[Thu Jul 30 11:50:46.874809 2026] [core:notice] [pid 643573:tid 643622] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:46.878521 2026] [security2:error] [pid 643573:tid 643734] [client 66.249.74.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/view/303/310"] [unique_id "amuA5vxWyxgRnoFKAJ_v4QACLCk"]
[Thu Jul 30 11:50:47.067101 2026] [core:notice] [pid 642360:tid 642511] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:47.073814 2026] [security2:error] [pid 642360:tid 642511] [client 103.215.74.26:24608] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA55SUkh3e5AhEJOBrPAAAAaQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:47.173280 2026] [security2:error] [pid 642360:tid 642534] [client 20.100.187.246:18046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/flower.php"] [unique_id "amuA55SUkh3e5AhEJOBrRQAAAbs"]
[Thu Jul 30 11:50:47.694088 2026] [security2:error] [pid 642360:tid 642605] [client 172.237.109.114:51732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA55SUkh3e5AhEJOBrPgAAAgI"]
[Thu Jul 30 11:50:47.704173 2026] [security2:error] [pid 642360:tid 642508] [client 172.237.109.114:59596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA55SUkh3e5AhEJOBrQQAAAaE"]
[Thu Jul 30 11:50:47.705031 2026] [security2:error] [pid 642360:tid 642535] [client 172.237.109.114:6066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA55SUkh3e5AhEJOBrPwAAAbw"]
[Thu Jul 30 11:50:47.732752 2026] [security2:error] [pid 642360:tid 642491] [client 172.237.109.114:15436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA55SUkh3e5AhEJOBrPQAAAZA"]
[Thu Jul 30 11:50:47.794987 2026] [security2:error] [pid 643573:tid 643835] [client 172.237.109.114:65194] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA5_xWyxgRnoFKAJ_v5QAAApE"]
[Thu Jul 30 11:50:47.800085 2026] [security2:error] [pid 643573:tid 643823] [client 172.237.109.114:41354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA5_xWyxgRnoFKAJ_v5AAAAoU"]
[Thu Jul 30 11:50:47.808482 2026] [core:notice] [pid 643253:tid 643395] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:47.813863 2026] [security2:error] [pid 643253:tid 643395] [client 103.215.74.26:24618] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "776"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA58jqbtjBYzqM1uYl_wAAAAs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:47.816197 2026] [security2:error] [pid 642360:tid 642516] [client 172.237.109.114:62543] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA55SUkh3e5AhEJOBrQgAAAak"]
[Thu Jul 30 11:50:47.819906 2026] [security2:error] [pid 643573:tid 643766] [client 20.100.187.246:12624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/gecko-new.php"] [unique_id "amuA5_xWyxgRnoFKAJ_v8wAAAkw"]
[Thu Jul 30 11:50:47.838618 2026] [security2:error] [pid 643573:tid 643751] [client 172.237.109.114:52953] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA5_xWyxgRnoFKAJ_v5gAAAj0"]
[Thu Jul 30 11:50:47.862365 2026] [security2:error] [pid 642360:tid 642609] [client 172.237.109.114:34562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA55SUkh3e5AhEJOBrRAAAAgY"]
[Thu Jul 30 11:50:47.870246 2026] [security2:error] [pid 642360:tid 642606] [client 172.237.109.114:57002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA55SUkh3e5AhEJOBrQwAAAgM"]
[Thu Jul 30 11:50:47.884426 2026] [security2:error] [pid 643573:tid 643820] [client 172.237.109.114:6933] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA5_xWyxgRnoFKAJ_v5wAAAoI"]
[Thu Jul 30 11:50:48.549761 2026] [core:notice] [pid 642360:tid 642604] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:48.558043 2026] [security2:error] [pid 642360:tid 642604] [client 103.215.74.26:24622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "738"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA6JSUkh3e5AhEJOBrWgAAAgE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:48.678709 2026] [security2:error] [pid 643573:tid 643825] [client 172.237.109.114:26919] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA6PxWyxgRnoFKAJ_v-gAAAoc"]
[Thu Jul 30 11:50:48.680093 2026] [security2:error] [pid 643573:tid 643800] [client 172.237.109.114:31001] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA6PxWyxgRnoFKAJ_v-QAAAm4"]
[Thu Jul 30 11:50:48.680124 2026] [security2:error] [pid 643573:tid 643794] [client 172.237.109.114:17128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA6PxWyxgRnoFKAJ_v-AAAAmg"]
[Thu Jul 30 11:50:49.298809 2026] [core:notice] [pid 643573:tid 643777] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:49.303234 2026] [security2:error] [pid 643573:tid 643777] [client 103.215.74.26:24636] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA6fxWyxgRnoFKAJ_wAQAAAlc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:49.733928 2026] [security2:error] [pid 643573:tid 643832] [client 100.29.107.38:13963] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.shorewooddaycare.com"] [uri "/"] [unique_id "amuA6fxWyxgRnoFKAJ_wBQAAAo4"]
[Thu Jul 30 11:50:49.860161 2026] [security2:error] [pid 643573:tid 643837] [client 20.100.187.246:36465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/m.php"] [unique_id "amuA6fxWyxgRnoFKAJ_wBgAAApM"]
[Thu Jul 30 11:50:50.026276 2026] [core:notice] [pid 643573:tid 643717] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:50.030494 2026] [security2:error] [pid 643573:tid 643717] [client 103.215.74.26:24650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA6vxWyxgRnoFKAJ_wCQAAAhs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:50.627426 2026] [security2:error] [pid 643573:tid 643784] [client 20.91.199.21:47590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/kj.php"] [unique_id "amuA6vxWyxgRnoFKAJ_wDgAAAl4"]
[Thu Jul 30 11:50:50.645916 2026] [security2:error] [pid 642360:tid 642597] [client 20.100.187.246:28612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/mah/autoload_classmap.php"] [unique_id "amuA6pSUkh3e5AhEJOBrbgAAAfo"]
[Thu Jul 30 11:50:50.716523 2026] [core:notice] [pid 643573:tid 643747] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:50.754461 2026] [core:notice] [pid 643573:tid 643732] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:50.759853 2026] [security2:error] [pid 643573:tid 643732] [client 103.215.74.26:24664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA6vxWyxgRnoFKAJ_wEAAAAio"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:51.564951 2026] [security2:error] [pid 642360:tid 642530] [client 20.100.187.246:29253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/mah/flower.php"] [unique_id "amuA65SUkh3e5AhEJOBrdgAAAbc"]
[Thu Jul 30 11:50:52.450670 2026] [security2:error] [pid 642360:tid 642480] [remote 57.141.0.35:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuA7JSUkh3e5AhEJOBrgAABwXc"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_brand=vitra&filter_materials=carbon,denim,polyester,plastic,linen,wood,nylon&orderby=date&rating=5&tax_product_cat=furniture&min_price=200&max_price=300&unfilter=1
[Thu Jul 30 11:50:52.540452 2026] [security2:error] [pid 643573:tid 643778] [client 20.100.187.246:36450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/mah/xleet.php"] [unique_id "amuA7PxWyxgRnoFKAJ_wHgAAAlg"]
[Thu Jul 30 11:50:53.130769 2026] [security2:error] [pid 643573:tid 643587] [remote 57.141.0.56:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuA7fxWyxgRnoFKAJ_wJAACZwY"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_brand=vitra&filter_materials=carbon,denim,polyester,plastic,linen,wood,nylon&orderby=date&rating=5&tax_product_cat=furniture&min_price=200&max_price=300&unfilter=1
[Thu Jul 30 11:50:53.236624 2026] [security2:error] [pid 643573:tid 643835] [client 20.100.187.246:7693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/mini.php"] [unique_id "amuA7fxWyxgRnoFKAJ_wJwAAApE"]
[Thu Jul 30 11:50:53.425885 2026] [security2:error] [pid 643573:tid 643751] [client 176.241.66.87:14515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuA7fxWyxgRnoFKAJ_wKAAAAj0"]
[Thu Jul 30 11:50:53.426098 2026] [security2:error] [pid 643573:tid 643751] [client 176.241.66.87:14515] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuA7fxWyxgRnoFKAJ_wKAAAAj0"]
[Thu Jul 30 11:50:53.962863 2026] [security2:error] [pid 643573:tid 643586] [remote 110.249.201.164:12068] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "shop-kent.com"] [uri "/product/kent-2/"] [unique_id "amuA7fxWyxgRnoFKAJ_wLwACUgU"]
[Thu Jul 30 11:50:54.285864 2026] [security2:error] [pid 642360:tid 642607] [client 57.141.0.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuA7ZSUkh3e5AhEJOBrigAAAgQ"]
[Thu Jul 30 11:50:55.303198 2026] [core:error] [pid 643253:tid 643387] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:55.303229 2026] [core:error] [pid 643253:tid 643387] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:55.335319 2026] [autoindex:error] [pid 642360:tid 642519] [client 52.4.19.39:10739] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_a59f0c15/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:50:55.339330 2026] [core:error] [pid 643573:tid 643771] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:55.339348 2026] [core:error] [pid 643573:tid 643771] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:55.369554 2026] [core:error] [pid 642360:tid 642560] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:55.369576 2026] [core:error] [pid 642360:tid 642560] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:56.333680 2026] [security2:error] [pid 642360:tid 642583] [client 20.91.199.21:47591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/wp-files.php"] [unique_id "amuA8JSUkh3e5AhEJOBrqgAAAew"]
[Thu Jul 30 11:50:56.529023 2026] [core:notice] [pid 642360:tid 642615] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:56.532942 2026] [security2:error] [pid 642360:tid 642615] [client 103.215.74.26:10474] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "737"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA8JSUkh3e5AhEJOBrrgAAAgw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:56.598880 2026] [security2:error] [pid 643573:tid 643811] [client 2a03:2880:f800:32:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuA7_xWyxgRnoFKAJ_wUAACeQQ"]
[Thu Jul 30 11:50:56.975334 2026] [security2:error] [pid 643573:tid 643772] [client 35.221.246.130:60744] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.eaw.nyx.temporary.site"] [uri "/___proxy_subdomain_webmail/.git/config"] [unique_id "amuA8PxWyxgRnoFKAJ_wWgAAAlI"]
[Thu Jul 30 11:50:56.986724 2026] [security2:error] [pid 642360:tid 642612] [client 35.221.246.130:60722] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.eaw.nyx.temporary.site"] [uri "/___proxy_subdomain_cpanel/.git/config"] [unique_id "amuA8JSUkh3e5AhEJOBrswAAAgk"]
[Thu Jul 30 11:50:57.015810 2026] [security2:error] [pid 643573:tid 643741] [client 35.221.246.130:60720] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "advancedvisiondxb.com"] [uri "/index.cgi"] [unique_id "amuA8fxWyxgRnoFKAJ_wXAAAAjM"]
[Thu Jul 30 11:50:57.065505 2026] [security2:error] [pid 642360:tid 642499] [client 35.221.246.130:60728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.eaw.nyx.temporary.site"] [uri "/___proxy_subdomain_webdisk/.git/config"] [unique_id "amuA8ZSUkh3e5AhEJOBrtAAAAZg"]
[Thu Jul 30 11:50:57.274572 2026] [core:notice] [pid 643573:tid 643779] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:57.278617 2026] [security2:error] [pid 643573:tid 643779] [client 103.215.74.26:10490] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "737"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA8fxWyxgRnoFKAJ_wXwAAAlk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:57.403830 2026] [security2:error] [pid 643573:tid 643740] [client 35.221.246.130:60748] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "www.eaw.nyx.temporary.site"] [uri "/index.cgi"] [unique_id "amuA8fxWyxgRnoFKAJ_wYgAAAjI"]
[Thu Jul 30 11:50:57.815847 2026] [security2:error] [pid 643573:tid 643794] [client 20.100.187.246:36435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/moon.php"] [unique_id "amuA8fxWyxgRnoFKAJ_wcQAAAmg"]
[Thu Jul 30 11:50:57.882894 2026] [core:notice] [pid 643573:tid 643723] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:58.017477 2026] [security2:error] [pid 643573:tid 643746] [client 35.221.246.130:60718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.eaw.nyx.temporary.site"] [uri "/index.cgi"] [unique_id "amuA8fxWyxgRnoFKAJ_wXQAAAjg"]
[Thu Jul 30 11:50:59.532305 2026] [security2:error] [pid 642360:tid 642516] [client 20.100.187.246:7695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/new.php"] [unique_id "amuA85SUkh3e5AhEJOBrzQAAAak"]
[Thu Jul 30 11:51:00.487027 2026] [core:notice] [pid 643573:tid 643762] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:00.539679 2026] [security2:error] [pid 642360:tid 642517] [client 57.141.0.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuA85SUkh3e5AhEJOBr0QAAAao"]
[Thu Jul 30 11:51:01.413042 2026] [security2:error] [pid 643573:tid 643770] [client 20.100.187.246:21083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/radio.php"] [unique_id "amuA9fxWyxgRnoFKAJ_wlAAAAlA"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Thu Jul 30 11:51:02.591679 2026] [security2:error] [pid 643573:tid 643814] [client 20.91.199.21:46994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/wp-setup.php"] [unique_id "amuA9vxWyxgRnoFKAJ_woQAAAnw"]
[Thu Jul 30 11:51:02.831187 2026] [core:notice] [pid 642360:tid 642416] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:03.073110 2026] [core:notice] [pid 643573:tid 643778] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:03.077463 2026] [security2:error] [pid 643573:tid 643778] [client 103.215.74.26:51586] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA9_xWyxgRnoFKAJ_wowAAAlg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:03.578235 2026] [security2:error] [pid 642360:tid 642614] [client 20.100.187.246:16864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/s.php"] [unique_id "amuA95SUkh3e5AhEJOBr7wAAAgs"]
[Thu Jul 30 11:51:03.698474 2026] [security2:error] [pid 642360:tid 642612] [client 213.152.161.240:51338] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuA95SUkh3e5AhEJOBr9AAAAgk"]
[Thu Jul 30 11:51:03.698590 2026] [security2:error] [pid 642360:tid 642612] [client 213.152.161.240:51338] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuA95SUkh3e5AhEJOBr9AAAAgk"]
[Thu Jul 30 11:51:03.825435 2026] [core:notice] [pid 643573:tid 643784] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:03.829786 2026] [security2:error] [pid 643573:tid 643784] [client 103.215.74.26:51600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA9_xWyxgRnoFKAJ_wpwAAAl4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:04.009782 2026] [security2:error] [pid 643573:tid 643755] [client 176.241.66.87:51156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuA-PxWyxgRnoFKAJ_wqgAAAkE"]
[Thu Jul 30 11:51:04.009923 2026] [security2:error] [pid 643573:tid 643755] [client 176.241.66.87:51156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuA-PxWyxgRnoFKAJ_wqgAAAkE"]
[Thu Jul 30 11:51:04.559479 2026] [core:notice] [pid 643573:tid 643821] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:04.564100 2026] [security2:error] [pid 643573:tid 643821] [client 103.215.74.26:51616] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA-PxWyxgRnoFKAJ_wrwAAAoM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:04.747917 2026] [security2:error] [pid 643573:tid 643822] [client 20.100.187.246:29309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/sim.php"] [unique_id "amuA-PxWyxgRnoFKAJ_wsQAAAoQ"]
[Thu Jul 30 11:51:04.824088 2026] [security2:error] [pid 642360:tid 642505] [client 20.91.199.21:47585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/defaults.php"] [unique_id "amuA-JSUkh3e5AhEJOBsBQAAAZ4"]
[Thu Jul 30 11:51:05.320814 2026] [core:notice] [pid 643573:tid 643749] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:05.325371 2026] [security2:error] [pid 643573:tid 643749] [client 103.215.74.26:51618] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA-fxWyxgRnoFKAJ_wtQAAAjs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:05.576183 2026] [security2:error] [pid 643573:tid 643772] [client 20.100.187.246:16890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/text.php"] [unique_id "amuA-fxWyxgRnoFKAJ_wtgAAAlI"]
[Thu Jul 30 11:51:06.088266 2026] [core:notice] [pid 642360:tid 642513] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:06.092752 2026] [security2:error] [pid 642360:tid 642513] [client 103.215.74.26:51620] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA-pSUkh3e5AhEJOBsEQAAAaY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:06.245580 2026] [security2:error] [pid 643573:tid 643764] [client 20.100.187.246:29251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/user.php"] [unique_id "amuA-vxWyxgRnoFKAJ_wugAAAko"]
[Thu Jul 30 11:51:06.830670 2026] [core:notice] [pid 642360:tid 642617] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:06.834908 2026] [security2:error] [pid 642360:tid 642617] [client 103.215.74.26:51636] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA-pSUkh3e5AhEJOBsFwAAAg4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:07.254997 2026] [autoindex:error] [pid 643253:tid 643459] [client 34.233.129.35:32025] AH01276: Cannot serve directory /home2/tvsnyxte/public_html/website_f8c1eb2c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:51:07.261908 2026] [proxy:error] [pid 642360:tid 642607] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:51:07.261956 2026] [proxy_http:error] [pid 642360:tid 642607] [client 34.233.129.35:27555] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:51:07.262524 2026] [proxy:error] [pid 642360:tid 642607] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:51:07.262569 2026] [proxy_http:error] [pid 642360:tid 642607] [client 34.233.129.35:27555] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:51:07.271180 2026] [autoindex:error] [pid 643573:tid 643819] [client 34.233.129.35:14724] AH01276: Cannot serve directory /home2/tvsnyxte/public_html/website_f8c1eb2c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:51:07.273144 2026] [security2:error] [pid 643573:tid 643812] [client 85.208.96.202:29910] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2023/01/30/ufpb-seleciona-alunos-para-residencia-medica-com-bolsa-de-r-41-mil/"] [unique_id "amuA-_xWyxgRnoFKAJ_wxAAAAno"]
[Thu Jul 30 11:51:07.273305 2026] [security2:error] [pid 643573:tid 643812] [client 85.208.96.202:29910] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2023/01/30/ufpb-seleciona-alunos-para-residencia-medica-com-bolsa-de-r-41-mil/"] [unique_id "amuA-_xWyxgRnoFKAJ_wxAAAAno"]
[Thu Jul 30 11:51:07.287411 2026] [proxy:error] [pid 642360:tid 642562] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:51:07.287477 2026] [proxy_http:error] [pid 642360:tid 642562] [client 34.233.129.35:15676] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:51:07.288243 2026] [proxy:error] [pid 642360:tid 642562] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:51:07.288307 2026] [proxy_http:error] [pid 642360:tid 642562] [client 34.233.129.35:15676] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:51:07.292005 2026] [autoindex:error] [pid 643573:tid 643833] [client 32.194.121.99:27085] AH01276: Cannot serve directory /home2/tvsnyxte/public_html/website_f8c1eb2c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:51:07.592023 2026] [core:notice] [pid 642360:tid 642613] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:07.596471 2026] [security2:error] [pid 642360:tid 642613] [client 103.215.74.26:51638] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA-5SUkh3e5AhEJOBsIAAAAgo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:08.374491 2026] [core:notice] [pid 642360:tid 642518] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:08.380343 2026] [security2:error] [pid 642360:tid 642518] [client 103.215.74.26:51654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA_JSUkh3e5AhEJOBsJwAAAas"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:09.016627 2026] [security2:error] [pid 643573:tid 643765] [client 20.100.187.246:7739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/webadmin.php"] [unique_id "amuA_fxWyxgRnoFKAJ_w0QAAAks"]
[Thu Jul 30 11:51:09.106242 2026] [core:notice] [pid 643573:tid 643721] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:09.110462 2026] [security2:error] [pid 643573:tid 643721] [client 103.215.74.26:51664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA_fxWyxgRnoFKAJ_w1AAAAh8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:09.302491 2026] [security2:error] [pid 643573:tid 643785] [client 49.232.81.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuA_fxWyxgRnoFKAJ_w2AAAAl8"], referer: http://cnpinyin.com/dict?search=%e5%8a%b3%e5%8a%a8%e5%8a%9b
[Thu Jul 30 11:51:10.194757 2026] [security2:error] [pid 642360:tid 642615] [client 20.100.187.246:56965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wordpress/wp-content/plugins/xcvbx/autoload_classmap.php"] [unique_id "amuA_pSUkh3e5AhEJOBsOQAAAgw"]
[Thu Jul 30 11:51:11.194209 2026] [security2:error] [pid 643573:tid 643804] [client 20.91.199.21:47597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/gtc.php"] [unique_id "amuA__xWyxgRnoFKAJ_w7QAAAnI"]
[Thu Jul 30 11:51:11.896188 2026] [proxy:error] [pid 643573:tid 643774] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:51:11.896268 2026] [proxy_http:error] [pid 643573:tid 643774] [client 193.47.62.167:40980] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:51:11.896850 2026] [proxy:error] [pid 643573:tid 643774] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:51:11.896893 2026] [proxy_http:error] [pid 643573:tid 643774] [client 193.47.62.167:40980] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:51:12.766239 2026] [security2:error] [pid 643573:tid 643710] [client 20.100.187.246:14872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wordpress/wp-content/plugins/xcvbx/flower.php"] [unique_id "amuBAPxWyxgRnoFKAJ_w-AAAAhQ"]
[Thu Jul 30 11:51:12.806408 2026] [security2:error] [pid 642360:tid 642595] [client 2a03:2880:f800:29:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBAJSUkh3e5AhEJOBsTAAB-A0"]
[Thu Jul 30 11:51:13.179937 2026] [security2:error] [pid 643573:tid 643611] [remote 74.7.241.60:55662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/article.php"] [unique_id "amuBAfxWyxgRnoFKAJ_w-gACKR4"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/bootstrap.bundle.min.js
[Thu Jul 30 11:51:13.792725 2026] [security2:error] [pid 643573:tid 643716] [client 20.100.187.246:7765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wordpress/wp-content/plugins/xcvbx/xleet.php"] [unique_id "amuBAfxWyxgRnoFKAJ_xAAAAAho"]
[Thu Jul 30 11:51:13.914359 2026] [security2:error] [pid 643573:tid 643803] [client 20.91.199.21:47556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/import.php"] [unique_id "amuBAfxWyxgRnoFKAJ_xAQAAAnE"]
[Thu Jul 30 11:51:14.579007 2026] [security2:error] [pid 642360:tid 642596] [client 20.100.187.246:21053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wordpress/wp-content/themes/as/autoload_classmap.php"] [unique_id "amuBApSUkh3e5AhEJOBsXgAAAfk"]
[Thu Jul 30 11:51:14.728725 2026] [security2:error] [pid 643573:tid 643824] [client 176.241.66.87:51704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBAvxWyxgRnoFKAJ_xDAAAAoY"]
[Thu Jul 30 11:51:14.728832 2026] [security2:error] [pid 643573:tid 643824] [client 176.241.66.87:51704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBAvxWyxgRnoFKAJ_xDAAAAoY"]
[Thu Jul 30 11:51:14.900370 2026] [core:notice] [pid 642360:tid 642503] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:14.904393 2026] [security2:error] [pid 642360:tid 642503] [client 103.215.74.26:23898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "737"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBApSUkh3e5AhEJOBsYgAAAZw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:14.984188 2026] [security2:error] [pid 642360:tid 642501] [client 20.91.199.21:46991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/lufix.php"] [unique_id "amuBApSUkh3e5AhEJOBsYwAAAZo"]
[Thu Jul 30 11:51:15.573317 2026] [security2:error] [pid 642360:tid 642566] [client 20.91.199.21:47005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/Geforce.php"] [unique_id "amuBA5SUkh3e5AhEJOBsaAAAAds"]
[Thu Jul 30 11:51:15.650602 2026] [core:notice] [pid 642360:tid 642569] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:15.656878 2026] [security2:error] [pid 642360:tid 642569] [client 103.215.74.26:23906] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBA5SUkh3e5AhEJOBsaQAAAd4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:16.125824 2026] [core:notice] [pid 643573:tid 643738] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:16.270875 2026] [security2:error] [pid 643573:tid 643775] [client 2a03:2880:f800:16:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBA_xWyxgRnoFKAJ_xDwACVUk"]
[Thu Jul 30 11:51:16.393804 2026] [core:notice] [pid 643573:tid 643721] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:16.395670 2026] [security2:error] [pid 642360:tid 642590] [client 20.91.199.21:47588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/a4.php"] [unique_id "amuBBJSUkh3e5AhEJOBscQAAAfM"]
[Thu Jul 30 11:51:16.397713 2026] [security2:error] [pid 643573:tid 643721] [client 103.215.74.26:23910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "736"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBBPxWyxgRnoFKAJ_xIAAAAh8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:17.119510 2026] [core:notice] [pid 643573:tid 643763] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:17.123804 2026] [security2:error] [pid 643573:tid 643763] [client 103.215.74.26:23920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBBfxWyxgRnoFKAJ_xIgAAAkk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:17.228596 2026] [security2:error] [pid 642360:tid 642495] [client 20.100.187.246:11583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wordpress/wp-content/themes/as/flower.php"] [unique_id "amuBBZSUkh3e5AhEJOBseQAAAZQ"]
[Thu Jul 30 11:51:17.314333 2026] [security2:error] [pid 643573:tid 643764] [client 5.255.119.161:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lxw.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuBBfxWyxgRnoFKAJ_xJQAAAko"]
[Thu Jul 30 11:51:17.930792 2026] [security2:error] [pid 643573:tid 643783] [client 5.255.119.161:56862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lxw.gpl.temporary.site"] [uri "/.env"] [unique_id "amuBBfxWyxgRnoFKAJ_xKwAAAl0"]
[Thu Jul 30 11:51:18.177105 2026] [security2:error] [pid 643573:tid 643829] [client 20.100.187.246:11552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wordpress/wp-content/themes/as/xleet.php"] [unique_id "amuBBvxWyxgRnoFKAJ_xMAAAAos"]
[Thu Jul 30 11:51:18.794436 2026] [security2:error] [pid 643573:tid 643718] [client 5.255.119.161:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lxw.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuBBvxWyxgRnoFKAJ_xNwAAAhw"]
[Thu Jul 30 11:51:19.128686 2026] [security2:error] [pid 642360:tid 642612] [client 5.255.119.161:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lxw.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuBB5SUkh3e5AhEJOBsgwAAAgk"]
[Thu Jul 30 11:51:19.196600 2026] [security2:error] [pid 643573:tid 643837] [client 5.255.119.161:50606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lxw.gpl.temporary.site"] [uri "/api/.env"] [unique_id "amuBB_xWyxgRnoFKAJ_xPgAAApM"]
[Thu Jul 30 11:51:19.204610 2026] [security2:error] [pid 643573:tid 643824] [client 5.255.119.161:50602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lxw.gpl.temporary.site"] [uri "/backend/.env"] [unique_id "amuBB_xWyxgRnoFKAJ_xRgAAAoY"]
[Thu Jul 30 11:51:19.314156 2026] [security2:error] [pid 643573:tid 643826] [client 5.255.119.161:50612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lxw.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuBB_xWyxgRnoFKAJ_xPwAAAog"]
[Thu Jul 30 11:51:19.318697 2026] [security2:error] [pid 643573:tid 643714] [client 5.255.119.161:50616] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lxw.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuBB_xWyxgRnoFKAJ_xRQAAAhg"]
[Thu Jul 30 11:51:19.350582 2026] [security2:error] [pid 643573:tid 643815] [client 5.255.119.161:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lxw.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuBB_xWyxgRnoFKAJ_xSQAAAn0"]
[Thu Jul 30 11:51:19.350922 2026] [security2:error] [pid 643573:tid 643774] [client 5.255.119.161:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lxw.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuBB_xWyxgRnoFKAJ_xSgAAAlQ"]
[Thu Jul 30 11:51:19.351408 2026] [security2:error] [pid 643573:tid 643791] [client 5.255.119.161:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lxw.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuBB_xWyxgRnoFKAJ_xSAAAAmU"]
[Thu Jul 30 11:51:19.382901 2026] [security2:error] [pid 642360:tid 642507] [client 5.255.119.161:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lxw.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuBB5SUkh3e5AhEJOBshQAAAaA"]
[Thu Jul 30 11:51:19.417016 2026] [security2:error] [pid 643573:tid 643745] [client 20.100.187.246:15353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "amuBB_xWyxgRnoFKAJ_xTQAAAjc"]
[Thu Jul 30 11:51:20.013922 2026] [security2:error] [pid 643573:tid 643735] [client 74.7.244.56:53128] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ghm.hmu.temporary.site"] [uri "/robots.txt"] [unique_id "amuBCPxWyxgRnoFKAJ_xUwAAAi0"]
[Thu Jul 30 11:51:20.079496 2026] [core:error] [pid 643253:tid 643407] [client 74.7.175.172:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:51:20.079518 2026] [core:error] [pid 643253:tid 643407] [client 74.7.175.172:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:51:20.079638 2026] [security2:error] [pid 643253:tid 643407] [client 74.7.175.172:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.ste.nyx.temporary.site"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amuBCMjqbtjBYzqM1uYmIgAAABc"]
[Thu Jul 30 11:51:20.080305 2026] [security2:error] [pid 643253:tid 643445] [client 74.7.175.172:51804] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.ste.nyx.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuBCMjqbtjBYzqM1uYmIQAAPTE"]
[Thu Jul 30 11:51:20.624062 2026] [security2:error] [pid 643573:tid 643742] [client 20.100.187.246:21731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-admin/css/colors/autoload_classmap.php"] [unique_id "amuBCPxWyxgRnoFKAJ_xWQAAAjQ"]
[Thu Jul 30 11:51:21.835025 2026] [security2:error] [pid 643253:tid 643475] [client 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuBCcjqbtjBYzqM1uYmJAAAWzM"]
[Thu Jul 30 11:51:21.866758 2026] [security2:error] [pid 642360:tid 642491] [client 20.91.199.21:46986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/accueil.php"] [unique_id "amuBCZSUkh3e5AhEJOBslwAAAZA"]
[Thu Jul 30 11:51:22.074195 2026] [security2:error] [pid 643573:tid 643809] [client 20.100.187.246:17173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-admin/css/colors/flower.php"] [unique_id "amuBCvxWyxgRnoFKAJ_xaAAAAnc"]
[Thu Jul 30 11:51:22.464822 2026] [security2:error] [pid 643573:tid 643754] [client 2a03:2880:f800:27:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBCfxWyxgRnoFKAJ_xYwACQFk"]
[Thu Jul 30 11:51:22.961622 2026] [core:notice] [pid 643573:tid 643760] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:22.968791 2026] [security2:error] [pid 643573:tid 643760] [client 103.215.74.26:23926] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBCvxWyxgRnoFKAJ_xaQAAAkY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:23.722490 2026] [core:notice] [pid 642360:tid 642556] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:23.729013 2026] [security2:error] [pid 642360:tid 642556] [client 103.215.74.26:62454] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBC5SUkh3e5AhEJOBsqgAAAdE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:23.851451 2026] [security2:error] [pid 643573:tid 643714] [client 66.249.70.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "flixon.net"] [uri "/wp-login.php"] [unique_id "amuBCvxWyxgRnoFKAJ_xagACGFU"]
[Thu Jul 30 11:51:24.199513 2026] [security2:error] [pid 642360:tid 642544] [client 20.91.199.21:47573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/dashboard.php"] [unique_id "amuBDJSUkh3e5AhEJOBssgAAAcU"]
[Thu Jul 30 11:51:24.444849 2026] [core:notice] [pid 643573:tid 643763] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:24.448861 2026] [security2:error] [pid 643573:tid 643763] [client 103.215.74.26:62460] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "737"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBDPxWyxgRnoFKAJ_xdwAAAkk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:25.182660 2026] [core:notice] [pid 643573:tid 643808] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:25.189540 2026] [security2:error] [pid 643573:tid 643808] [client 103.215.74.26:62472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBDfxWyxgRnoFKAJ_xfQAAAnY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:25.307002 2026] [security2:error] [pid 643573:tid 643770] [client 2a03:2880:f800:35:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBDPxWyxgRnoFKAJ_xeQACUFA"]
[Thu Jul 30 11:51:25.317131 2026] [security2:error] [pid 643573:tid 643753] [client 176.241.66.87:52264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBDfxWyxgRnoFKAJ_xfgAAAj8"]
[Thu Jul 30 11:51:25.317254 2026] [security2:error] [pid 643573:tid 643753] [client 176.241.66.87:52264] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBDfxWyxgRnoFKAJ_xfgAAAj8"]
[Thu Jul 30 11:51:25.681437 2026] [security2:error] [pid 643573:tid 643797] [client 20.91.199.21:46989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/radio.php"] [unique_id "amuBDfxWyxgRnoFKAJ_xgQAAAms"]
[Thu Jul 30 11:51:25.772776 2026] [security2:error] [pid 643573:tid 643673] [remote 95.108.213.181:58094] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "spacexpress.africa"] [uri "/tag/business/"] [unique_id "amuBDfxWyxgRnoFKAJ_xggACalw"]
[Thu Jul 30 11:51:25.784348 2026] [proxy:error] [pid 643573:tid 643610] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:51:25.784395 2026] [proxy_http:error] [pid 643573:tid 643610] [remote 216.73.217.9:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:51:25.784954 2026] [proxy:error] [pid 643573:tid 643610] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:51:25.785017 2026] [proxy_http:error] [pid 643573:tid 643610] [remote 216.73.217.9:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:51:25.926034 2026] [core:notice] [pid 643573:tid 643828] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:25.933785 2026] [security2:error] [pid 643573:tid 643828] [client 103.215.74.26:62488] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBDfxWyxgRnoFKAJ_xhQAAAoo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:26.520636 2026] [security2:error] [pid 642360:tid 642496] [client 20.100.187.246:17209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-admin/css/colors/xleet.php"] [unique_id "amuBDpSUkh3e5AhEJOBszAAAAZU"]
[Thu Jul 30 11:51:26.657595 2026] [core:notice] [pid 643573:tid 643816] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:26.661658 2026] [security2:error] [pid 643573:tid 643816] [client 103.215.74.26:62502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "768"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBDvxWyxgRnoFKAJ_xjgAAAn4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:26.668661 2026] [security2:error] [pid 642360:tid 642546] [client 20.91.199.21:47612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/wpsml-sys.php"] [unique_id "amuBDpSUkh3e5AhEJOBszwAAAcc"]
[Thu Jul 30 11:51:26.748804 2026] [core:notice] [pid 643573:tid 643831] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:27.409299 2026] [core:notice] [pid 643573:tid 643807] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:27.414047 2026] [security2:error] [pid 643573:tid 643807] [client 103.215.74.26:62512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBD_xWyxgRnoFKAJ_xkwAAAnU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:27.548285 2026] [security2:error] [pid 643573:tid 643817] [client 20.91.199.21:46981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/02.php"] [unique_id "amuBD_xWyxgRnoFKAJ_xlAAAAn8"]
[Thu Jul 30 11:51:28.152118 2026] [core:notice] [pid 643573:tid 643780] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:28.156063 2026] [security2:error] [pid 643573:tid 643780] [client 103.215.74.26:62522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBEPxWyxgRnoFKAJ_xmwAAAlo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:28.399655 2026] [security2:error] [pid 643573:tid 643776] [client 20.91.199.21:46985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/infos.php"] [unique_id "amuBEPxWyxgRnoFKAJ_xoAAAAlY"]
[Thu Jul 30 11:51:28.920533 2026] [core:notice] [pid 643573:tid 643824] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:28.924506 2026] [security2:error] [pid 643573:tid 643824] [client 103.215.74.26:62532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBEPxWyxgRnoFKAJ_xpgAAAoY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:30.266633 2026] [security2:error] [pid 642360:tid 642416] [remote 57.141.0.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuBEpSUkh3e5AhEJOBs8wABuTc"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_brand=nike&filter_materials=aluminum,denim,lycra,nylon,polyester,steel&filter_size=extra-extra-large&max_price=125&min_price=75&orderby=menu_order&rating=5&status=instock&unfilter=1
[Thu Jul 30 11:51:30.273894 2026] [security2:error] [pid 642360:tid 642411] [remote 57.141.0.65:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuBEpSUkh3e5AhEJOBs9AAB4zI"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_brand=nike&filter_materials=aluminum,denim,lycra,nylon,polyester,steel&filter_size=extra-extra-large&max_price=125&min_price=75&orderby=menu_order&rating=5&status=instock&unfilter=1
[Thu Jul 30 11:51:31.219960 2026] [security2:error] [pid 642360:tid 642510] [client 20.91.199.21:47595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/updates.php"] [unique_id "amuBE5SUkh3e5AhEJOBs_QAAAaM"]
[Thu Jul 30 11:51:31.291341 2026] [core:notice] [pid 643573:tid 643802] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:34.676157 2026] [security2:error] [pid 642360:tid 642511] [client 57.141.0.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuBFpSUkh3e5AhEJOBtGAAAAaQ"]
[Thu Jul 30 11:51:34.751675 2026] [core:notice] [pid 642360:tid 642538] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:34.755824 2026] [security2:error] [pid 642360:tid 642538] [client 103.215.74.26:59776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBFpSUkh3e5AhEJOBtIAAAAb8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:35.091178 2026] [security2:error] [pid 642360:tid 642564] [client 20.91.199.21:46992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/user.php"] [unique_id "amuBF5SUkh3e5AhEJOBtJQAAAdk"]
[Thu Jul 30 11:51:35.483352 2026] [core:notice] [pid 643573:tid 643760] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:35.487322 2026] [security2:error] [pid 643573:tid 643760] [client 103.215.74.26:59792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBF_xWyxgRnoFKAJ_x5AAAAkY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:35.932566 2026] [security2:error] [pid 643573:tid 643824] [client 176.241.66.87:52822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBF_xWyxgRnoFKAJ_x5gAAAoY"]
[Thu Jul 30 11:51:35.932696 2026] [security2:error] [pid 643573:tid 643824] [client 176.241.66.87:52822] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBF_xWyxgRnoFKAJ_x5gAAAoY"]
[Thu Jul 30 11:51:36.211090 2026] [core:notice] [pid 643573:tid 643757] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:36.215087 2026] [security2:error] [pid 643573:tid 643757] [client 103.215.74.26:59798] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBGPxWyxgRnoFKAJ_x6AAAAkM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:36.936177 2026] [core:notice] [pid 642360:tid 642560] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:36.940249 2026] [security2:error] [pid 642360:tid 642560] [client 103.215.74.26:59814] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBGJSUkh3e5AhEJOBtNwAAAdU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:37.498305 2026] [security2:error] [pid 643573:tid 643744] [client 20.91.199.21:47036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/admin-ajax.php"] [unique_id "amuBGfxWyxgRnoFKAJ_x8AAAAjY"]
[Thu Jul 30 11:51:37.582627 2026] [security2:error] [pid 643573:tid 643782] [client 20.100.187.246:20660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-admin/flower.php"] [unique_id "amuBGfxWyxgRnoFKAJ_x8QAAAlw"]
[Thu Jul 30 11:51:37.664860 2026] [core:notice] [pid 643573:tid 643807] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:37.668741 2026] [security2:error] [pid 643573:tid 643807] [client 103.215.74.26:59828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "765"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBGfxWyxgRnoFKAJ_x8gAAAnU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:38.401484 2026] [core:notice] [pid 642360:tid 642554] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:38.405814 2026] [security2:error] [pid 642360:tid 642554] [client 103.215.74.26:59834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBGpSUkh3e5AhEJOBtRQAAAc8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:38.672859 2026] [security2:error] [pid 643573:tid 643831] [client 20.91.199.21:47581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/alfa.php"] [unique_id "amuBGvxWyxgRnoFKAJ_x9wAAAo0"]
[Thu Jul 30 11:51:39.119326 2026] [core:notice] [pid 643573:tid 643784] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:39.123320 2026] [security2:error] [pid 643573:tid 643784] [client 103.215.74.26:59844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBG_xWyxgRnoFKAJ_x-gAAAl4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:39.271463 2026] [security2:error] [pid 643253:tid 643384] [client 20.100.187.246:8192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-admin/maint/autoload_classmap.php"] [unique_id "amuBG8jqbtjBYzqM1uYmQwAAAAA"]
[Thu Jul 30 11:51:39.837290 2026] [core:notice] [pid 643253:tid 643320] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:39.846498 2026] [core:notice] [pid 643573:tid 643802] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:39.850420 2026] [security2:error] [pid 643573:tid 643802] [client 103.215.74.26:59848] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBG_xWyxgRnoFKAJ_yCQAAAnA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:39.918120 2026] [security2:error] [pid 643573:tid 643752] [client 20.100.187.246:8218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-admin/maint/flower.php"] [unique_id "amuBG_xWyxgRnoFKAJ_yCgAAAj4"]
[Thu Jul 30 11:51:40.585476 2026] [core:notice] [pid 643253:tid 643410] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:40.590310 2026] [security2:error] [pid 643253:tid 643410] [client 103.215.74.26:59858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBHMjqbtjBYzqM1uYmRwAAABo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:41.147338 2026] [security2:error] [pid 642360:tid 642543] [client 20.100.187.246:36487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-admin/maint/xleet.php"] [unique_id "amuBHZSUkh3e5AhEJOBtXgAAAcQ"]
[Thu Jul 30 11:51:41.334878 2026] [core:notice] [pid 643573:tid 643743] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:41.339055 2026] [security2:error] [pid 643573:tid 643743] [client 103.215.74.26:59874] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBHfxWyxgRnoFKAJ_yEAAAAjU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:41.722576 2026] [core:notice] [pid 643573:tid 643781] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:42.078349 2026] [core:notice] [pid 643573:tid 643761] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:42.082939 2026] [security2:error] [pid 643573:tid 643761] [client 103.215.74.26:59888] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBHvxWyxgRnoFKAJ_yGwAAAkc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:42.479630 2026] [security2:error] [pid 643573:tid 643727] [client 57.141.0.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuBHfxWyxgRnoFKAJ_yGAAAAiU"]
[Thu Jul 30 11:51:42.775415 2026] [core:error] [pid 643573:tid 643627] [remote 32.193.37.124:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:51:42.775441 2026] [core:error] [pid 643573:tid 643627] [remote 32.193.37.124:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:51:42.814652 2026] [core:notice] [pid 642360:tid 642531] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:42.818958 2026] [security2:error] [pid 642360:tid 642531] [client 103.215.74.26:59894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBHpSUkh3e5AhEJOBtcAAAAbg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:42.838456 2026] [security2:error] [pid 643573:tid 643792] [client 20.91.199.21:46995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/hehe.php"] [unique_id "amuBHvxWyxgRnoFKAJ_yIQAAAmY"]
[Thu Jul 30 11:51:42.893759 2026] [security2:error] [pid 643573:tid 643775] [client 20.100.187.246:8086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amuBHvxWyxgRnoFKAJ_yIgAAAlU"]
[Thu Jul 30 11:51:43.458696 2026] [core:notice] [pid 643573:tid 643697] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:43.546425 2026] [core:notice] [pid 643573:tid 643820] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:43.550887 2026] [security2:error] [pid 643573:tid 643820] [client 103.215.74.26:44104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBH_xWyxgRnoFKAJ_yNQAAAoI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:43.891879 2026] [security2:error] [pid 643573:tid 643747] [client 20.100.187.246:8008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-admin/network/flower.php"] [unique_id "amuBH_xWyxgRnoFKAJ_yPwAAAjk"]
[Thu Jul 30 11:51:44.281316 2026] [core:notice] [pid 643573:tid 643823] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:44.285660 2026] [security2:error] [pid 643573:tid 643823] [client 103.215.74.26:44110] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBIPxWyxgRnoFKAJ_yRQAAAoU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:44.523543 2026] [security2:error] [pid 642360:tid 642494] [client 20.91.199.21:47613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/rk2.php"] [unique_id "amuBIJSUkh3e5AhEJOBtfQAAAZM"]
[Thu Jul 30 11:51:44.809610 2026] [ssl:error] [pid 643573:tid 643719] [client 199.45.154.140:54636] AH02032: Hostname sh00085.hostgator.com (default host as no SNI was provided) and hostname mail.kendarikomputer.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Thu Jul 30 11:51:44.990815 2026] [security2:error] [pid 643573:tid 643822] [client 57.141.0.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuBIPxWyxgRnoFKAJ_ySAAAAoQ"]
[Thu Jul 30 11:51:45.027897 2026] [core:notice] [pid 643253:tid 643481] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:45.032679 2026] [security2:error] [pid 643253:tid 643481] [client 103.215.74.26:44120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBIcjqbtjBYzqM1uYmTQAAAGE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:45.751382 2026] [security2:error] [pid 643573:tid 643758] [client 20.91.199.21:47608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/setup-config.php"] [unique_id "amuBIfxWyxgRnoFKAJ_yVwAAAkQ"]
[Thu Jul 30 11:51:45.808983 2026] [core:notice] [pid 643573:tid 643806] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:45.813294 2026] [security2:error] [pid 643573:tid 643806] [client 103.215.74.26:44132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBIfxWyxgRnoFKAJ_yWQAAAnQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:46.010444 2026] [security2:error] [pid 642360:tid 642568] [client 20.100.187.246:8078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-admin/network/xleet.php"] [unique_id "amuBIpSUkh3e5AhEJOBtiQAAAd0"]
[Thu Jul 30 11:51:46.071049 2026] [core:notice] [pid 642360:tid 642510] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:46.444743 2026] [security2:error] [pid 643573:tid 643786] [client 20.91.199.21:47609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/a7.php"] [unique_id "amuBIvxWyxgRnoFKAJ_yYwAAAmA"]
[Thu Jul 30 11:51:46.532593 2026] [core:notice] [pid 643573:tid 643718] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:46.537020 2026] [security2:error] [pid 643573:tid 643718] [client 103.215.74.26:44136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBIvxWyxgRnoFKAJ_yZwAAAhw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:46.599871 2026] [security2:error] [pid 643573:tid 643836] [client 176.241.66.87:17781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBIvxWyxgRnoFKAJ_ybAAAApI"]
[Thu Jul 30 11:51:46.599989 2026] [security2:error] [pid 643573:tid 643836] [client 176.241.66.87:17781] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBIvxWyxgRnoFKAJ_ybAAAApI"]
[Thu Jul 30 11:51:46.767552 2026] [security2:error] [pid 643573:tid 643742] [client 20.100.187.246:58926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/json.php"] [unique_id "amuBIvxWyxgRnoFKAJ_yfgAAAjQ"]
[Thu Jul 30 11:51:46.857338 2026] [proxy:error] [pid 643573:tid 643626] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:51:46.857394 2026] [proxy_http:error] [pid 643573:tid 643626] [remote 74.7.228.16:40956] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:51:46.857958 2026] [proxy:error] [pid 643573:tid 643626] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:51:46.858015 2026] [proxy_http:error] [pid 643573:tid 643626] [remote 74.7.228.16:40956] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:51:47.218185 2026] [security2:error] [pid 643573:tid 643834] [client 20.91.199.21:47564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/f7.php"] [unique_id "amuBI_xWyxgRnoFKAJ_yigAAApA"]
[Thu Jul 30 11:51:47.257141 2026] [core:notice] [pid 642360:tid 642571] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:47.261126 2026] [security2:error] [pid 642360:tid 642571] [client 103.215.74.26:44146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBI5SUkh3e5AhEJOBtkgAAAeA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:47.282569 2026] [core:notice] [pid 643573:tid 643714] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:47.284746 2026] [security2:error] [pid 643573:tid 643714] [client 144.76.23.169:56324] ModSecurity: Warning. Matched phrase "Trendiction" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.nordeste1.com"] [uri "/robots.txt"] [unique_id "amuBI_xWyxgRnoFKAJ_yiwAAAhg"]
[Thu Jul 30 11:51:47.666496 2026] [security2:error] [pid 643573:tid 643748] [client 217.181.88.32:28574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "deltaedu.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuBI_xWyxgRnoFKAJ_yjgACOjw"], referer: https://deltaedu.net/wp-admin/admin-ajax.php?action=tnp&na=s
[Thu Jul 30 11:51:48.038531 2026] [core:notice] [pid 642360:tid 642496] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:48.042697 2026] [security2:error] [pid 642360:tid 642496] [client 103.215.74.26:44152] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "756"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBJJSUkh3e5AhEJOBtmAAAAZU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:48.151789 2026] [security2:error] [pid 643573:tid 643760] [client 20.100.187.246:8104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-admin/user/autoload_classmap.php"] [unique_id "amuBJPxWyxgRnoFKAJ_ylgAAAkY"]
[Thu Jul 30 11:51:48.771244 2026] [core:notice] [pid 643573:tid 643800] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:48.775342 2026] [security2:error] [pid 643573:tid 643800] [client 103.215.74.26:44160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBJPxWyxgRnoFKAJ_yrQAAAm4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:49.410775 2026] [security2:error] [pid 643573:tid 643771] [client 20.91.199.21:47559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/nw.php"] [unique_id "amuBJfxWyxgRnoFKAJ_ytAAAAlE"]
[Thu Jul 30 11:51:49.488628 2026] [core:notice] [pid 643573:tid 643765] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:49.493052 2026] [security2:error] [pid 643573:tid 643765] [client 103.215.74.26:44162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBJfxWyxgRnoFKAJ_ytgAAAks"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:49.561231 2026] [security2:error] [pid 643573:tid 643715] [client 20.100.187.246:29096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-admin/user/flower.php"] [unique_id "amuBJfxWyxgRnoFKAJ_ytwAAAhk"]
[Thu Jul 30 11:51:50.214469 2026] [core:notice] [pid 642360:tid 642609] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:50.221089 2026] [security2:error] [pid 642360:tid 642609] [client 103.215.74.26:44164] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBJpSUkh3e5AhEJOBtqgAAAgY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:50.466784 2026] [security2:error] [pid 642360:tid 642610] [client 20.100.187.246:33733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/mini.php"] [unique_id "amuBJpSUkh3e5AhEJOBtsQAAAgc"]
[Thu Jul 30 11:51:50.494480 2026] [core:notice] [pid 642360:tid 642521] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:50.496795 2026] [security2:error] [pid 642360:tid 642521] [client 144.76.23.169:47678] ModSecurity: Warning. Matched phrase "Trendiction" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.nordeste1.com"] [uri "/feed/"] [unique_id "amuBJpSUkh3e5AhEJOBtsgAAAa4"]
[Thu Jul 30 11:51:50.616329 2026] [security2:error] [pid 642360:tid 642516] [client 2a03:2880:f800:5:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBJZSUkh3e5AhEJOBtqQABqSU"]
[Thu Jul 30 11:51:50.642761 2026] [security2:error] [pid 642360:tid 642520] [client 20.91.199.21:47208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/ova.php"] [unique_id "amuBJpSUkh3e5AhEJOBttAAAAa0"]
[Thu Jul 30 11:51:50.720552 2026] [security2:error] [pid 642360:tid 642531] [client 20.100.187.246:29110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-admin/user/xleet.php"] [unique_id "amuBJpSUkh3e5AhEJOBttQAAAbg"]
[Thu Jul 30 11:51:50.721766 2026] [security2:error] [pid 643573:tid 643799] [client 178.156.189.249:7000] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuBJfxWyxgRnoFKAJ_ytQAAAm0"], referer: https://globalmarks.pk/
[Thu Jul 30 11:51:50.992726 2026] [core:notice] [pid 642360:tid 642517] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:50.999674 2026] [security2:error] [pid 642360:tid 642517] [client 103.215.74.26:44170] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBJpSUkh3e5AhEJOBtuQAAAao"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:51.721480 2026] [core:notice] [pid 643573:tid 643797] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:51.725501 2026] [security2:error] [pid 643573:tid 643797] [client 103.215.74.26:44180] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBJ_xWyxgRnoFKAJ_yygAAAms"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:51.800187 2026] [core:notice] [pid 643573:tid 643668] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:51.803839 2026] [security2:error] [pid 643573:tid 643796] [client 66.249.65.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/download/223/241"] [unique_id "amuBJ_xWyxgRnoFKAJ_yyQACalc"]
[Thu Jul 30 11:51:51.991416 2026] [security2:error] [pid 643573:tid 643717] [client 20.91.199.21:47605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/robots.php"] [unique_id "amuBJ_xWyxgRnoFKAJ_yzQAAAhs"]
[Thu Jul 30 11:51:52.450969 2026] [core:notice] [pid 643573:tid 643732] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:52.454943 2026] [security2:error] [pid 643573:tid 643732] [client 103.215.74.26:44194] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "772"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBKPxWyxgRnoFKAJ_y0AAAAio"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:52.780736 2026] [core:notice] [pid 643573:tid 643807] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:52.877860 2026] [security2:error] [pid 643573:tid 643817] [client 74.7.244.3:34442] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.arabiandubaisafari.com.khw.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuBKPxWyxgRnoFKAJ_y0gACf0k"]
[Thu Jul 30 11:51:53.177011 2026] [core:notice] [pid 643573:tid 643750] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:53.184940 2026] [security2:error] [pid 643573:tid 643750] [client 103.215.74.26:17946] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBKfxWyxgRnoFKAJ_y1wAAAjw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:53.203797 2026] [security2:error] [pid 643573:tid 643771] [client 20.91.199.21:47001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/alf.php"] [unique_id "amuBKfxWyxgRnoFKAJ_y2AAAAlE"]
[Thu Jul 30 11:51:53.307177 2026] [security2:error] [pid 642360:tid 642526] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "madeninsabah.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "amuBKZSUkh3e5AhEJOBtzQAAAbM"]
[Thu Jul 30 11:51:53.331093 2026] [security2:error] [pid 643573:tid 643793] [client 20.100.187.246:11872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-admin/xleet.php"] [unique_id "amuBKfxWyxgRnoFKAJ_y3AAAAmc"]
[Thu Jul 30 11:51:53.830350 2026] [proxy:error] [pid 643573:tid 643632] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:51:53.830429 2026] [proxy_http:error] [pid 643573:tid 643632] [remote 74.7.228.34:59616] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:51:53.831258 2026] [proxy:error] [pid 643573:tid 643632] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:51:53.831327 2026] [proxy_http:error] [pid 643573:tid 643632] [remote 74.7.228.34:59616] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:51:53.845066 2026] [core:error] [pid 643573:tid 643794] [client 74.7.244.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:51:53.845093 2026] [core:error] [pid 643573:tid 643794] [client 74.7.244.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:51:53.845250 2026] [security2:error] [pid 643573:tid 643794] [client 74.7.244.51:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.yaz.gzj.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/index.php"] [unique_id "amuBKfxWyxgRnoFKAJ_y4AAAAmg"]
[Thu Jul 30 11:51:53.845835 2026] [security2:error] [pid 642360:tid 642541] [client 74.7.244.51:60296] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.yaz.gzj.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "amuBKZSUkh3e5AhEJOBt0wABwiQ"]
[Thu Jul 30 11:51:53.900349 2026] [security2:error] [pid 643253:tid 643398] [client 20.91.199.21:46980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/feedback.php"] [unique_id "amuBKcjqbtjBYzqM1uYmUgAAAA4"]
[Thu Jul 30 11:51:53.911930 2026] [core:notice] [pid 643253:tid 643493] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:53.913448 2026] [security2:error] [pid 643573:tid 643829] [client 52.23.112.144:27225] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2016/11/cerveja-faz-bem-saude-web.jpg"] [unique_id "amuBKfxWyxgRnoFKAJ_y4QAAAos"]
[Thu Jul 30 11:51:53.915890 2026] [security2:error] [pid 643253:tid 643493] [client 103.215.74.26:17948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "785"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBKcjqbtjBYzqM1uYmUwAAAG0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:53.945333 2026] [security2:error] [pid 642360:tid 642514] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "madeninsabah.com"] [uri "/media/system/js/core.js"] [unique_id "amuBKZSUkh3e5AhEJOBt1gAAAac"]
[Thu Jul 30 11:51:54.291824 2026] [security2:error] [pid 642360:tid 642606] [client 119.73.97.132:30215] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/wp-login.php"] [unique_id "amuBJ5SUkh3e5AhEJOBtvgACA0w"], referer: https://www.urwru.club/wp-login.php?redirect_to=https%3A%2F%2Fwww.urwru.club%2Fwp-admin%2F&reauth=1
[Thu Jul 30 11:51:54.381134 2026] [core:notice] [pid 642360:tid 642571] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:54.474242 2026] [security2:error] [pid 642360:tid 642567] [client 20.100.187.246:64912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/chosen.php"] [unique_id "amuBKpSUkh3e5AhEJOBt3AAAAdw"]
[Thu Jul 30 11:51:54.651421 2026] [core:notice] [pid 643253:tid 643326] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:54.874380 2026] [core:notice] [pid 643573:tid 643767] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:55.478191 2026] [core:error] [pid 643573:tid 643823] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:51:55.478212 2026] [core:error] [pid 643573:tid 643823] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:51:56.711353 2026] [security2:error] [pid 642360:tid 642450] [remote 57.141.0.34:20702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/logika/about/submissions"] [unique_id "amuBLJSUkh3e5AhEJOBuDwABwVk"]
[Thu Jul 30 11:51:56.969788 2026] [security2:error] [pid 643253:tid 643504] [client 20.100.187.246:29100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-config-sample.php"] [unique_id "amuBLMjqbtjBYzqM1uYmXgAAAHg"]
[Thu Jul 30 11:51:57.302699 2026] [security2:error] [pid 643573:tid 643815] [client 176.241.66.87:18427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBLfxWyxgRnoFKAJ_y-wAAAn0"]
[Thu Jul 30 11:51:57.302842 2026] [security2:error] [pid 643573:tid 643815] [client 176.241.66.87:18427] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBLfxWyxgRnoFKAJ_y-wAAAn0"]
[Thu Jul 30 11:51:59.495088 2026] [security2:error] [pid 643573:tid 643788] [client 20.91.199.21:47025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/gettest.php"] [unique_id "amuBL_xWyxgRnoFKAJ_zDAAAAmI"]
[Thu Jul 30 11:51:59.638050 2026] [core:notice] [pid 642360:tid 642589] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:59.642110 2026] [security2:error] [pid 642360:tid 642589] [client 103.215.74.26:17956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBL5SUkh3e5AhEJOBueQAAAfI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:00.359647 2026] [core:notice] [pid 643573:tid 643729] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:00.363771 2026] [security2:error] [pid 643573:tid 643729] [client 103.215.74.26:17960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBMPxWyxgRnoFKAJ_zEwAAAic"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:01.089611 2026] [core:notice] [pid 643573:tid 643803] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:01.093668 2026] [security2:error] [pid 643573:tid 643803] [client 103.215.74.26:17974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "765"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBMfxWyxgRnoFKAJ_zGAAAAnE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:01.404971 2026] [security2:error] [pid 643573:tid 643765] [client 20.91.199.21:47583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/maint.php"] [unique_id "amuBMfxWyxgRnoFKAJ_zHQAAAks"]
[Thu Jul 30 11:52:01.490247 2026] [security2:error] [pid 643573:tid 643714] [client 47.128.35.78:28718] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "deltaedu.net"] [uri "/robots.txt"] [unique_id "amuBMfxWyxgRnoFKAJ_zIAAAAhg"]
[Thu Jul 30 11:52:01.817917 2026] [core:notice] [pid 643573:tid 643711] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:01.823443 2026] [security2:error] [pid 643573:tid 643711] [client 103.215.74.26:17978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBMfxWyxgRnoFKAJ_zJgAAAhU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:02.401595 2026] [security2:error] [pid 642360:tid 642393] [remote 52.238.199.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afropakmedical.com"] [uri "/.well-known/file.php"] [unique_id "amuBMpSUkh3e5AhEJOBukgACCSA"]
[Thu Jul 30 11:52:02.553632 2026] [core:notice] [pid 643573:tid 643754] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:02.557573 2026] [security2:error] [pid 643573:tid 643754] [client 103.215.74.26:17988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBMvxWyxgRnoFKAJ_zLAAAAkA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:02.621355 2026] [security2:error] [pid 643573:tid 643767] [client 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuBMvxWyxgRnoFKAJ_zKQACTRY"]
[Thu Jul 30 11:52:03.143789 2026] [security2:error] [pid 642360:tid 642592] [client 20.91.199.21:47572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/files.php"] [unique_id "amuBM5SUkh3e5AhEJOBumwAAAfU"]
[Thu Jul 30 11:52:03.199288 2026] [security2:error] [pid 643573:tid 643601] [remote 52.238.199.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afropakmedical.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "amuBM_xWyxgRnoFKAJ_zOgACJxQ"]
[Thu Jul 30 11:52:04.107850 2026] [security2:error] [pid 643573:tid 643686] [remote 52.238.199.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afropakmedical.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "amuBNPxWyxgRnoFKAJ_zRgACbWk"]
[Thu Jul 30 11:52:04.760702 2026] [security2:error] [pid 643573:tid 643735] [client 20.91.199.21:46852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/gecko.php"] [unique_id "amuBNPxWyxgRnoFKAJ_zTgAAAi0"]
[Thu Jul 30 11:52:04.777576 2026] [security2:error] [pid 643573:tid 643753] [client 57.141.0.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuBNPxWyxgRnoFKAJ_zSQAAAj8"]
[Thu Jul 30 11:52:05.080498 2026] [core:notice] [pid 643573:tid 643704] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:05.273507 2026] [core:error] [pid 643573:tid 643782] [client 66.249.73.202:45521] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:05.273542 2026] [core:error] [pid 643573:tid 643782] [client 66.249.73.202:45521] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:06.028083 2026] [core:notice] [pid 642360:tid 642416] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:06.050959 2026] [security2:error] [pid 642360:tid 642525] [client 20.91.199.21:46866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/zwso.php"] [unique_id "amuBNpSUkh3e5AhEJOBuugAAAbI"]
[Thu Jul 30 11:52:06.337926 2026] [core:error] [pid 643573:tid 643773] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:06.337950 2026] [core:error] [pid 643573:tid 643773] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:06.343136 2026] [core:error] [pid 643573:tid 643766] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:06.343152 2026] [core:error] [pid 643573:tid 643766] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:06.345097 2026] [core:error] [pid 643573:tid 643780] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:06.345116 2026] [core:error] [pid 643573:tid 643780] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:06.379036 2026] [core:error] [pid 643573:tid 643833] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:06.379058 2026] [core:error] [pid 643573:tid 643833] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:06.400936 2026] [core:error] [pid 643573:tid 643724] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:06.400960 2026] [core:error] [pid 643573:tid 643724] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:06.542668 2026] [core:notice] [pid 642360:tid 642577] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:07.960140 2026] [security2:error] [pid 643573:tid 643805] [client 176.241.66.87:19069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBN_xWyxgRnoFKAJ_zggAAAnM"]
[Thu Jul 30 11:52:07.960285 2026] [security2:error] [pid 643573:tid 643805] [client 176.241.66.87:19069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBN_xWyxgRnoFKAJ_zggAAAnM"]
[Thu Jul 30 11:52:08.342655 2026] [core:notice] [pid 643573:tid 643726] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:08.347414 2026] [security2:error] [pid 643573:tid 643726] [client 103.215.74.26:51264] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBOPxWyxgRnoFKAJ_zhgAAAiQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:09.069569 2026] [core:notice] [pid 643573:tid 643830] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:09.073597 2026] [security2:error] [pid 643573:tid 643830] [client 103.215.74.26:51268] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBOfxWyxgRnoFKAJ_zigAAAow"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:11.039556 2026] [security2:error] [pid 643573:tid 643832] [client 52.167.144.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cnpinyin.com"] [uri "/index.php"] [unique_id "amuBOvxWyxgRnoFKAJ_zlwAAAo4"]
[Thu Jul 30 11:52:12.368118 2026] [security2:error] [pid 643573:tid 643726] [client 20.91.199.21:46862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/13.php"] [unique_id "amuBPPxWyxgRnoFKAJ_zngAAAiQ"]
[Thu Jul 30 11:52:13.127025 2026] [security2:error] [pid 643573:tid 643833] [client 57.141.0.46:60662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuBPPxWyxgRnoFKAJ_zoQACj0Y"], referer: https://igetvape-australia.com/product-tag/alibarbar-ingot-quadruple-berry-9000-puffs/
[Thu Jul 30 11:52:13.276287 2026] [autoindex:error] [pid 642360:tid 642603] [client 54.87.222.253:50431] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_a59f0c15/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:52:13.293446 2026] [core:error] [pid 643573:tid 643823] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:13.293464 2026] [core:error] [pid 643573:tid 643823] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:13.294770 2026] [core:error] [pid 642360:tid 642549] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:13.294784 2026] [core:error] [pid 642360:tid 642549] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:13.298252 2026] [core:error] [pid 643573:tid 643788] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:13.298280 2026] [core:error] [pid 643573:tid 643788] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:14.117870 2026] [security2:error] [pid 642360:tid 642508] [client 20.91.199.21:47072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/ava.php"] [unique_id "amuBPpSUkh3e5AhEJOBvGgAAAaE"]
[Thu Jul 30 11:52:14.501191 2026] [core:notice] [pid 643253:tid 643333] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:14.815225 2026] [core:notice] [pid 642360:tid 642528] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:14.819499 2026] [security2:error] [pid 642360:tid 642528] [client 103.215.74.26:63186] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBPpSUkh3e5AhEJOBvJAAAAbU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:14.952469 2026] [security2:error] [pid 642360:tid 642497] [client 20.91.199.21:47056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/main.php"] [unique_id "amuBPpSUkh3e5AhEJOBvJQAAAZY"]
[Thu Jul 30 11:52:15.439338 2026] [core:notice] [pid 642360:tid 642394] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:15.539683 2026] [core:notice] [pid 643573:tid 643736] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:15.544137 2026] [security2:error] [pid 643573:tid 643736] [client 103.215.74.26:63188] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBP_xWyxgRnoFKAJ_zvAAAAi4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:15.744380 2026] [security2:error] [pid 642360:tid 642601] [client 2a03:2880:f800:42:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBP5SUkh3e5AhEJOBvJgAB_nc"]
[Thu Jul 30 11:52:15.865537 2026] [proxy:error] [pid 643573:tid 643748] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:52:15.865615 2026] [proxy_http:error] [pid 643573:tid 643748] [client 85.204.70.98:1105] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:52:15.866215 2026] [proxy:error] [pid 643573:tid 643748] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:52:15.866259 2026] [proxy_http:error] [pid 643573:tid 643748] [client 85.204.70.98:1105] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:52:16.123960 2026] [proxy:error] [pid 643573:tid 643758] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:52:16.124074 2026] [proxy_http:error] [pid 643573:tid 643758] [client 85.204.70.98:44316] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:52:16.124892 2026] [proxy:error] [pid 643573:tid 643758] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:52:16.124944 2026] [proxy_http:error] [pid 643573:tid 643758] [client 85.204.70.98:44316] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:52:16.262601 2026] [core:notice] [pid 643573:tid 643773] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:16.266840 2026] [security2:error] [pid 643573:tid 643773] [client 103.215.74.26:63204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBQPxWyxgRnoFKAJ_zyAAAAlM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:16.387629 2026] [security2:error] [pid 643573:tid 643774] [client 85.204.70.98:44318] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sua.nyx.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuBQPxWyxgRnoFKAJ_zywAAAlQ"]
[Thu Jul 30 11:52:16.568900 2026] [security2:error] [pid 642360:tid 642376] [remote 216.73.216.152:46162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuBQJSUkh3e5AhEJOBvMwAB9g8"]
[Thu Jul 30 11:52:16.657778 2026] [security2:error] [pid 642360:tid 642590] [client 85.204.70.98:44322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.sua.nyx.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuBQJSUkh3e5AhEJOBvNAAAAfM"]
[Thu Jul 30 11:52:16.863114 2026] [security2:error] [pid 643573:tid 643747] [client 82.221.131.86:57484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.131.221.82.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "store.carnetdeshopping.com"] [uri "/index.php"] [unique_id "amuBQPxWyxgRnoFKAJ_zzAAAAjk"]
[Thu Jul 30 11:52:16.865925 2026] [security2:error] [pid 643573:tid 643830] [client 20.91.199.21:47040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/wp-file.php"] [unique_id "amuBQPxWyxgRnoFKAJ_zzQAAAow"]
[Thu Jul 30 11:52:16.927596 2026] [proxy:error] [pid 643573:tid 643754] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:52:16.927678 2026] [proxy_http:error] [pid 643573:tid 643754] [client 85.204.70.98:44334] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:52:16.928256 2026] [proxy:error] [pid 643573:tid 643754] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:52:16.928311 2026] [proxy_http:error] [pid 643573:tid 643754] [client 85.204.70.98:44334] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:52:16.990672 2026] [core:notice] [pid 642360:tid 642490] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:16.995174 2026] [security2:error] [pid 642360:tid 642490] [client 103.215.74.26:63220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBQJSUkh3e5AhEJOBvOwAAAY8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:17.193694 2026] [security2:error] [pid 642360:tid 642568] [client 85.204.70.98:26610] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sua.nyx.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuBQZSUkh3e5AhEJOBvPAAAAd0"]
[Thu Jul 30 11:52:17.458237 2026] [security2:error] [pid 642360:tid 642577] [client 85.204.70.98:44352] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sua.nyx.temporary.site"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuBQZSUkh3e5AhEJOBvQwAAAeY"]
[Thu Jul 30 11:52:17.636339 2026] [security2:error] [pid 643573:tid 643735] [client 20.91.199.21:47102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/wp-signin.php"] [unique_id "amuBQfxWyxgRnoFKAJ_z0AAAAi0"]
[Thu Jul 30 11:52:17.730733 2026] [core:notice] [pid 643573:tid 643723] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:17.735256 2026] [security2:error] [pid 643573:tid 643723] [client 103.215.74.26:63232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBQfxWyxgRnoFKAJ_z0QAAAiE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:17.746643 2026] [security2:error] [pid 643573:tid 643791] [client 85.204.70.98:44356] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sua.nyx.temporary.site"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuBQfxWyxgRnoFKAJ_z0gAAAmU"]
[Thu Jul 30 11:52:17.948058 2026] [core:notice] [pid 642360:tid 642514] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:17.997624 2026] [security2:error] [pid 643573:tid 643742] [client 85.204.70.98:44366] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sua.nyx.temporary.site"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuBQfxWyxgRnoFKAJ_z1gAAAjQ"]
[Thu Jul 30 11:52:18.258179 2026] [security2:error] [pid 643573:tid 643769] [client 85.204.70.98:44368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sua.nyx.temporary.site"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuBQvxWyxgRnoFKAJ_z1wAAAk8"]
[Thu Jul 30 11:52:18.280679 2026] [security2:error] [pid 643573:tid 643716] [client 20.91.199.21:47099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/simi.php"] [unique_id "amuBQvxWyxgRnoFKAJ_z2AAAAho"]
[Thu Jul 30 11:52:18.379601 2026] [security2:error] [pid 643573:tid 643592] [remote 74.7.241.60:52566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/article.php"] [unique_id "amuBQvxWyxgRnoFKAJ_z2QACPAs"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/bootstrap.bundle.min.js
[Thu Jul 30 11:52:18.487780 2026] [core:notice] [pid 642360:tid 642547] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:18.492264 2026] [security2:error] [pid 642360:tid 642547] [client 103.215.74.26:63248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBQpSUkh3e5AhEJOBvTgAAAcg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:18.611058 2026] [security2:error] [pid 643573:tid 643837] [client 176.241.66.87:19739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBQvxWyxgRnoFKAJ_z4QAAApM"]
[Thu Jul 30 11:52:18.611205 2026] [security2:error] [pid 643573:tid 643837] [client 176.241.66.87:19739] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBQvxWyxgRnoFKAJ_z4QAAApM"]
[Thu Jul 30 11:52:18.692737 2026] [core:notice] [pid 642360:tid 642426] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:18.760325 2026] [core:error] [pid 643253:tid 643496] [client 74.7.230.52:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:18.760354 2026] [core:error] [pid 643253:tid 643496] [client 74.7.230.52:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:18.760472 2026] [security2:error] [pid 643253:tid 643496] [client 74.7.230.52:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.clm.udi.temporary.site"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "amuBQsjqbtjBYzqM1uYmbgAAAHA"]
[Thu Jul 30 11:52:18.761026 2026] [security2:error] [pid 643573:tid 643761] [client 74.7.230.52:50944] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.clm.udi.temporary.site"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuBQvxWyxgRnoFKAJ_z4gACRxM"]
[Thu Jul 30 11:52:19.245237 2026] [core:notice] [pid 643573:tid 643790] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:19.249669 2026] [security2:error] [pid 643573:tid 643790] [client 103.215.74.26:63250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBQ_xWyxgRnoFKAJ_z5wAAAmQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:19.418444 2026] [security2:error] [pid 643573:tid 643770] [client 20.91.199.21:46848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/wp-conf.php"] [unique_id "amuBQ_xWyxgRnoFKAJ_z6AAAAlA"]
[Thu Jul 30 11:52:19.577365 2026] [security2:error] [pid 643573:tid 643804] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ciunews.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "amuBQ_xWyxgRnoFKAJ_z7AAAAnI"]
[Thu Jul 30 11:52:19.988005 2026] [core:notice] [pid 642360:tid 642557] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:19.995197 2026] [security2:error] [pid 642360:tid 642557] [client 103.215.74.26:63260] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBQ5SUkh3e5AhEJOBvWAAAAdI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:20.257367 2026] [security2:error] [pid 642360:tid 642575] [client 172.234.80.100:60166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/wp-login.php"] [unique_id "amuBP5SUkh3e5AhEJOBvLQAAAfQ"]
[Thu Jul 30 11:52:20.561104 2026] [security2:error] [pid 643573:tid 643762] [client 20.91.199.21:47093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/WZGHHra0r3.php"] [unique_id "amuBRPxWyxgRnoFKAJ_z9QAAAkg"]
[Thu Jul 30 11:52:20.716229 2026] [core:notice] [pid 643573:tid 643835] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:20.720279 2026] [security2:error] [pid 643573:tid 643835] [client 103.215.74.26:63266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBRPxWyxgRnoFKAJ_z-QAAApE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:21.494808 2026] [core:notice] [pid 643573:tid 643783] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:21.498844 2026] [security2:error] [pid 643573:tid 643783] [client 103.215.74.26:63280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "756"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBRfxWyxgRnoFKAJ_z_QAAAl0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:22.224567 2026] [core:notice] [pid 643573:tid 643775] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:22.228418 2026] [security2:error] [pid 643573:tid 643775] [client 103.215.74.26:63286] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBRvxWyxgRnoFKAJ_0BAAAAlU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:22.960590 2026] [core:notice] [pid 642360:tid 642582] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:22.965406 2026] [security2:error] [pid 642360:tid 642582] [client 103.215.74.26:63298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBRpSUkh3e5AhEJOBvcwAAAes"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:23.415552 2026] [security2:error] [pid 642360:tid 642511] [client 20.91.199.21:47062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/bala.php"] [unique_id "amuBR5SUkh3e5AhEJOBveAAAAaQ"]
[Thu Jul 30 11:52:23.690550 2026] [core:notice] [pid 643573:tid 643831] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:23.697314 2026] [security2:error] [pid 643573:tid 643831] [client 103.215.74.26:36412] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBR_xWyxgRnoFKAJ_0EQAAAo0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:24.228621 2026] [security2:error] [pid 643573:tid 643810] [client 171.25.193.39:60834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.193.25.171.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "store.carnetdeshopping.com"] [uri "/index.php"] [unique_id "amuBSPxWyxgRnoFKAJ_0GgAAAng"]
[Thu Jul 30 11:52:24.420409 2026] [core:notice] [pid 643573:tid 643723] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:24.427513 2026] [security2:error] [pid 643573:tid 643723] [client 103.215.74.26:36422] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBSPxWyxgRnoFKAJ_0IwAAAiE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:24.643704 2026] [security2:error] [pid 643573:tid 643767] [client 57.141.0.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuBSPxWyxgRnoFKAJ_0FAAAAk0"]
[Thu Jul 30 11:52:25.157551 2026] [core:notice] [pid 642360:tid 642514] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:25.161524 2026] [security2:error] [pid 642360:tid 642514] [client 103.215.74.26:36426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBSZSUkh3e5AhEJOBvigAAAac"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:25.325903 2026] [security2:error] [pid 643573:tid 643796] [client 20.91.199.21:47391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/bk.php"] [unique_id "amuBSfxWyxgRnoFKAJ_0LgAAAmo"]
[Thu Jul 30 11:52:25.395603 2026] [core:notice] [pid 643573:tid 643739] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:25.783834 2026] [security2:error] [pid 643253:tid 643498] [client 57.141.0.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuBScjqbtjBYzqM1uYmcQAAAHI"]
[Thu Jul 30 11:52:25.892747 2026] [core:notice] [pid 643573:tid 643772] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:25.896676 2026] [security2:error] [pid 643573:tid 643772] [client 103.215.74.26:36442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "772"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBSfxWyxgRnoFKAJ_0NQAAAlI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:26.325042 2026] [security2:error] [pid 642360:tid 642507] [client 127.0.0.1:52190] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuBSpSUkh3e5AhEJOBvlgAAAaA"]
[Thu Jul 30 11:52:26.325055 2026] [security2:error] [pid 643573:tid 643819] [client 127.0.0.1:52174] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.fiyan.co"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuBSvxWyxgRnoFKAJ_0OAAAAoE"]
[Thu Jul 30 11:52:26.325283 2026] [security2:error] [pid 643573:tid 643718] [client 74.7.230.38:55446] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.fiyan.co"] [uri "/robots.txt"] [unique_id "amuBSvxWyxgRnoFKAJ_0NwACHEs"]
[Thu Jul 30 11:52:26.635070 2026] [core:notice] [pid 642360:tid 642545] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:26.642149 2026] [security2:error] [pid 642360:tid 642545] [client 103.215.74.26:36472] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBSpSUkh3e5AhEJOBvmwAAAcY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:27.395672 2026] [core:notice] [pid 643573:tid 643737] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:27.400077 2026] [security2:error] [pid 643573:tid 643737] [client 103.215.74.26:36478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "785"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBS_xWyxgRnoFKAJ_0UAAAAi8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:27.420100 2026] [security2:error] [pid 643573:tid 643818] [client 68.221.186.136:46224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/json.php"] [unique_id "amuBS_xWyxgRnoFKAJ_0UgAAAoA"]
[Thu Jul 30 11:52:27.532077 2026] [security2:error] [pid 643573:tid 643834] [client 20.91.199.21:47379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/ahax.php"] [unique_id "amuBS_xWyxgRnoFKAJ_0VwAAApA"]
[Thu Jul 30 11:52:27.589245 2026] [core:notice] [pid 643573:tid 643816] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:28.115829 2026] [core:notice] [pid 643573:tid 643713] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:28.120600 2026] [security2:error] [pid 643573:tid 643713] [client 103.215.74.26:36498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBTPxWyxgRnoFKAJ_0XwAAAhc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:28.601411 2026] [security2:error] [pid 643253:tid 643399] [client 45.137.70.158:41826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.70.137.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "store.carnetdeshopping.com"] [uri "/index.php"] [unique_id "amuBTMjqbtjBYzqM1uYmdAAAAA8"]
[Thu Jul 30 11:52:28.852726 2026] [core:notice] [pid 643573:tid 643754] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:28.856682 2026] [security2:error] [pid 643573:tid 643754] [client 103.215.74.26:36502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBTPxWyxgRnoFKAJ_0aAAAAkA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:29.430697 2026] [security2:error] [pid 643573:tid 643781] [client 176.241.66.87:55640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBTfxWyxgRnoFKAJ_0bwAAAls"]
[Thu Jul 30 11:52:29.430845 2026] [security2:error] [pid 643573:tid 643781] [client 176.241.66.87:55640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBTfxWyxgRnoFKAJ_0bwAAAls"]
[Thu Jul 30 11:52:29.574175 2026] [core:notice] [pid 643573:tid 643721] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:29.578027 2026] [security2:error] [pid 643573:tid 643721] [client 103.215.74.26:36518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "764"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBTfxWyxgRnoFKAJ_0cwAAAh8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:29.766878 2026] [security2:error] [pid 643573:tid 643807] [client 185.100.85.24:3096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.85.100.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "store.carnetdeshopping.com"] [uri "/index.php"] [unique_id "amuBTfxWyxgRnoFKAJ_0cAAAAnU"]
[Thu Jul 30 11:52:30.145293 2026] [security2:error] [pid 643573:tid 643761] [client 198.54.128.138:43206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuBTvxWyxgRnoFKAJ_0eQAAAkc"]
[Thu Jul 30 11:52:30.145396 2026] [security2:error] [pid 643573:tid 643761] [client 198.54.128.138:43206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuBTvxWyxgRnoFKAJ_0eQAAAkc"]
[Thu Jul 30 11:52:30.303324 2026] [core:notice] [pid 643573:tid 643837] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:30.307876 2026] [security2:error] [pid 643573:tid 643837] [client 103.215.74.26:36534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBTvxWyxgRnoFKAJ_0egAAApM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:31.031382 2026] [core:notice] [pid 643573:tid 643786] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:31.036190 2026] [security2:error] [pid 643573:tid 643786] [client 103.215.74.26:36540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBT_xWyxgRnoFKAJ_0ggAAAmA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:31.100901 2026] [security2:error] [pid 643573:tid 643670] [remote 185.61.152.44:49698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.152.61.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-login.php"] [unique_id "amuBT_xWyxgRnoFKAJ_0gwACiFk"]
[Thu Jul 30 11:52:31.429300 2026] [security2:error] [pid 642360:tid 642588] [client 43.173.173.214:42268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.173.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/05/28/bruxelles-quartier-europeen-et-parcours-bd/"] [unique_id "amuBT5SUkh3e5AhEJOBvvwAAAfE"]
[Thu Jul 30 11:52:31.466944 2026] [security2:error] [pid 642360:tid 642511] [client 185.100.87.166:52396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.87.100.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "store.carnetdeshopping.com"] [uri "/index.php"] [unique_id "amuBT5SUkh3e5AhEJOBvwAAAAaQ"]
[Thu Jul 30 11:52:31.469015 2026] [security2:error] [pid 642360:tid 642593] [client 62.102.148.185:49850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuBT5SUkh3e5AhEJOBvwQAAAfY"]
[Thu Jul 30 11:52:31.469122 2026] [security2:error] [pid 642360:tid 642593] [client 62.102.148.185:49850] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuBT5SUkh3e5AhEJOBvwQAAAfY"]
[Thu Jul 30 11:52:31.604889 2026] [security2:error] [pid 643573:tid 643787] [client 68.221.186.136:46239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/mini.php"] [unique_id "amuBT_xWyxgRnoFKAJ_0iAAAAmE"]
[Thu Jul 30 11:52:31.755518 2026] [core:notice] [pid 643253:tid 643444] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:31.759477 2026] [security2:error] [pid 643253:tid 643444] [client 103.215.74.26:36552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBT8jqbtjBYzqM1uYmeQAAADw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:32.023778 2026] [core:notice] [pid 643253:tid 643384] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:32.064557 2026] [core:notice] [pid 643573:tid 643833] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:32.310691 2026] [core:notice] [pid 643573:tid 643741] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:32.315851 2026] [security2:error] [pid 643573:tid 643741] [client 43.173.173.62:35924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/05/28/bruxelles-quartier-europeen-et-parcours-bd/"] [unique_id "amuBUPxWyxgRnoFKAJ_0jwAAAjM"], referer: https://carnetdeshopping.com/index.php/2013/05/28/bruxelles-quartier-europeen-et-parcours-bd/
[Thu Jul 30 11:52:32.323315 2026] [security2:error] [pid 643253:tid 643511] [client 57.141.0.46:46858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuBUMjqbtjBYzqM1uYmewAAf1E"]
[Thu Jul 30 11:52:32.363078 2026] [core:notice] [pid 643573:tid 643762] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:32.486485 2026] [security2:error] [pid 643573:tid 643777] [client 68.221.186.136:26613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/chosen.php"] [unique_id "amuBUPxWyxgRnoFKAJ_0kQAAAlc"]
[Thu Jul 30 11:52:32.490805 2026] [core:notice] [pid 643573:tid 643756] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:32.498688 2026] [security2:error] [pid 643573:tid 643756] [client 103.215.74.26:36558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBUPxWyxgRnoFKAJ_0kgAAAkI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:33.230834 2026] [core:notice] [pid 643573:tid 643745] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:33.234967 2026] [security2:error] [pid 643573:tid 643745] [client 103.215.74.26:45548] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBUfxWyxgRnoFKAJ_0mwAAAjc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:33.370696 2026] [security2:error] [pid 643573:tid 643763] [client 68.221.186.136:26576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/kj.php"] [unique_id "amuBUfxWyxgRnoFKAJ_0nQAAAkk"]
[Thu Jul 30 11:52:33.614330 2026] [security2:error] [pid 643573:tid 643820] [client 2a03:2880:f800:28:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBUPxWyxgRnoFKAJ_0lgACglw"]
[Thu Jul 30 11:52:33.956172 2026] [core:notice] [pid 643573:tid 643808] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:33.960268 2026] [security2:error] [pid 643573:tid 643808] [client 103.215.74.26:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBUfxWyxgRnoFKAJ_0pAAAAnY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:34.201553 2026] [security2:error] [pid 643573:tid 643809] [client 68.221.186.136:44162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-files.php"] [unique_id "amuBUvxWyxgRnoFKAJ_0pwAAAnc"]
[Thu Jul 30 11:52:34.682016 2026] [core:notice] [pid 643573:tid 643788] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:34.686385 2026] [security2:error] [pid 643573:tid 643788] [client 103.215.74.26:45560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBUvxWyxgRnoFKAJ_0qwAAAmI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:34.720577 2026] [core:notice] [pid 643573:tid 643819] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:35.021354 2026] [security2:error] [pid 643573:tid 643828] [client 68.221.186.136:25283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-setup.php"] [unique_id "amuBU_xWyxgRnoFKAJ_0sQAAAoo"]
[Thu Jul 30 11:52:35.406220 2026] [core:notice] [pid 643573:tid 643791] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:35.410612 2026] [security2:error] [pid 643573:tid 643791] [client 103.215.74.26:45574] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBU_xWyxgRnoFKAJ_0ugAAAmU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:36.147178 2026] [core:notice] [pid 643573:tid 643715] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:36.151545 2026] [security2:error] [pid 643573:tid 643715] [client 103.215.74.26:45584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBVPxWyxgRnoFKAJ_0vwAAAhk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:36.156234 2026] [security2:error] [pid 643573:tid 643759] [client 68.221.186.136:42617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/defaults.php"] [unique_id "amuBVPxWyxgRnoFKAJ_0wAAAAkU"]
[Thu Jul 30 11:52:36.673029 2026] [security2:error] [pid 642360:tid 642513] [client 85.208.96.203:46320] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2023/01/04/inscricoes-em-processo-seletivo-da-rede-municipal-de-ensino-de-dona-ines-pb-terminam-nesta-quarta-4/"] [unique_id "amuBVJSUkh3e5AhEJOBwCQAAAaY"]
[Thu Jul 30 11:52:36.673154 2026] [security2:error] [pid 642360:tid 642513] [client 85.208.96.203:46320] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2023/01/04/inscricoes-em-processo-seletivo-da-rede-municipal-de-ensino-de-dona-ines-pb-terminam-nesta-quarta-4/"] [unique_id "amuBVJSUkh3e5AhEJOBwCQAAAaY"]
[Thu Jul 30 11:52:36.879760 2026] [core:notice] [pid 643573:tid 643778] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:36.884099 2026] [security2:error] [pid 643573:tid 643778] [client 103.215.74.26:45594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBVPxWyxgRnoFKAJ_0yAAAAlg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:37.272179 2026] [security2:error] [pid 643573:tid 643775] [client 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuBVPxWyxgRnoFKAJ_0xwACVWQ"]
[Thu Jul 30 11:52:37.308707 2026] [security2:error] [pid 643573:tid 643796] [client 68.221.186.136:44220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/gtc.php"] [unique_id "amuBVfxWyxgRnoFKAJ_0zAAAAmo"]
[Thu Jul 30 11:52:38.264793 2026] [security2:error] [pid 642360:tid 642498] [client 45.84.107.74:51149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.107.84.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "store.carnetdeshopping.com"] [uri "/index.php"] [unique_id "amuBVpSUkh3e5AhEJOBwGAAAAZc"]
[Thu Jul 30 11:52:40.056912 2026] [security2:error] [pid 643573:tid 643727] [client 176.241.66.87:21099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBWPxWyxgRnoFKAJ_06QAAAiU"]
[Thu Jul 30 11:52:40.057089 2026] [security2:error] [pid 643573:tid 643727] [client 176.241.66.87:21099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBWPxWyxgRnoFKAJ_06QAAAiU"]
[Thu Jul 30 11:52:41.354803 2026] [security2:error] [pid 642360:tid 642540] [client 2a03:2880:f800:13:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBWJSUkh3e5AhEJOBwXAABwV4"]
[Thu Jul 30 11:52:41.557284 2026] [security2:error] [pid 643573:tid 643770] [client 68.221.186.136:43037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/import.php"] [unique_id "amuBWfxWyxgRnoFKAJ_07wAAAlA"]
[Thu Jul 30 11:52:41.579175 2026] [security2:error] [pid 643573:tid 643688] [remote 216.73.216.152:5618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuBWfxWyxgRnoFKAJ_08AACY2s"]
[Thu Jul 30 11:52:42.605771 2026] [core:notice] [pid 643573:tid 643760] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:42.610115 2026] [security2:error] [pid 643573:tid 643760] [client 103.215.74.26:45604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBWvxWyxgRnoFKAJ_09wAAAkY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:42.647334 2026] [security2:error] [pid 642360:tid 642566] [client 68.221.186.136:25336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/lufix.php"] [unique_id "amuBWpSUkh3e5AhEJOBwbwAAAds"]
[Thu Jul 30 11:52:43.330013 2026] [core:notice] [pid 642360:tid 642613] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:43.334384 2026] [security2:error] [pid 642360:tid 642613] [client 103.215.74.26:43464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBW5SUkh3e5AhEJOBwdAAAAgo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:43.422715 2026] [core:notice] [pid 642360:tid 642464] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:43.496577 2026] [security2:error] [pid 643573:tid 643716] [client 68.221.186.136:26595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/Geforce.php"] [unique_id "amuBW_xWyxgRnoFKAJ_0_AAAAho"]
[Thu Jul 30 11:52:43.818648 2026] [security2:error] [pid 643573:tid 643724] [client 216.244.66.250:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "embassyofspaininpakistan.info"] [uri "/"] [unique_id "amuBW_xWyxgRnoFKAJ_0_wAAAiI"]
[Thu Jul 30 11:52:43.818762 2026] [security2:error] [pid 643573:tid 643724] [client 216.244.66.250:0] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "embassyofspaininpakistan.info"] [uri "/"] [unique_id "amuBW_xWyxgRnoFKAJ_0_wAAAiI"]
[Thu Jul 30 11:52:43.893038 2026] [core:notice] [pid 643573:tid 643796] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:43.903419 2026] [core:error] [pid 643573:tid 643796] [client 66.249.65.196:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:43.903583 2026] [security2:error] [pid 643573:tid 643796] [client 66.249.65.196:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/view/112/109.html.html.html.html.html.html.html.html.html.html"] [unique_id "amuBW_xWyxgRnoFKAJ_0_gAAAmo"]
[Thu Jul 30 11:52:44.062289 2026] [core:notice] [pid 643573:tid 643726] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:44.066069 2026] [security2:error] [pid 643573:tid 643726] [client 103.215.74.26:43480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBXPxWyxgRnoFKAJ_1AAAAAiQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:44.476233 2026] [core:notice] [pid 643573:tid 643689] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:44.479814 2026] [core:notice] [pid 643573:tid 643627] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:44.791568 2026] [core:notice] [pid 643573:tid 643718] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:44.797125 2026] [security2:error] [pid 643573:tid 643718] [client 103.215.74.26:43496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBXPxWyxgRnoFKAJ_1BwAAAhw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:45.020777 2026] [security2:error] [pid 643573:tid 643787] [client 85.204.70.98:45394] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sua.nyx.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuBXfxWyxgRnoFKAJ_1CQAAAmE"]
[Thu Jul 30 11:52:45.286110 2026] [security2:error] [pid 642360:tid 642599] [client 85.204.70.98:45408] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sua.nyx.temporary.site"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuBXZSUkh3e5AhEJOBwhwAAAfw"]
[Thu Jul 30 11:52:45.517939 2026] [core:notice] [pid 643573:tid 643810] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:45.521873 2026] [security2:error] [pid 643573:tid 643810] [client 103.215.74.26:43510] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "752"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBXfxWyxgRnoFKAJ_1DAAAAng"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:45.572112 2026] [security2:error] [pid 643573:tid 643762] [client 85.204.70.98:45412] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sua.nyx.temporary.site"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuBXfxWyxgRnoFKAJ_1DQAAAkg"]
[Thu Jul 30 11:52:45.903468 2026] [security2:error] [pid 642360:tid 642537] [client 85.204.70.98:45414] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sua.nyx.temporary.site"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuBXZSUkh3e5AhEJOBwjwAAAb4"]
[Thu Jul 30 11:52:46.164569 2026] [security2:error] [pid 643573:tid 643783] [client 85.204.70.98:45426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sua.nyx.temporary.site"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuBXvxWyxgRnoFKAJ_1FgAAAl0"]
[Thu Jul 30 11:52:46.278310 2026] [core:notice] [pid 642360:tid 642565] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:46.282807 2026] [security2:error] [pid 642360:tid 642565] [client 103.215.74.26:43520] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBXpSUkh3e5AhEJOBwkwAAAdo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:46.323373 2026] [core:notice] [pid 643573:tid 643721] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:46.430122 2026] [security2:error] [pid 642360:tid 642614] [client 85.204.70.98:28314] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sua.nyx.temporary.site"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuBXpSUkh3e5AhEJOBwlAAAAgs"]
[Thu Jul 30 11:52:46.489474 2026] [security2:error] [pid 643573:tid 643712] [client 68.221.186.136:26620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/a4.php"] [unique_id "amuBXvxWyxgRnoFKAJ_1HAAAAhY"]
[Thu Jul 30 11:52:46.708344 2026] [security2:error] [pid 643573:tid 643816] [client 85.204.70.98:45444] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sua.nyx.temporary.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuBXvxWyxgRnoFKAJ_1HgAAAn4"]
[Thu Jul 30 11:52:46.975791 2026] [security2:error] [pid 643573:tid 643829] [client 85.204.70.98:45452] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sua.nyx.temporary.site"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuBXvxWyxgRnoFKAJ_1IQAAAos"]
[Thu Jul 30 11:52:47.022628 2026] [core:notice] [pid 643253:tid 643417] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:47.029648 2026] [security2:error] [pid 643253:tid 643417] [client 103.215.74.26:43524] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBX8jqbtjBYzqM1uYmgwAAACE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:47.226063 2026] [security2:error] [pid 643253:tid 643482] [client 85.204.70.98:45456] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sua.nyx.temporary.site"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuBX8jqbtjBYzqM1uYmhAAAAGI"]
[Thu Jul 30 11:52:47.491240 2026] [security2:error] [pid 643573:tid 643718] [client 85.204.70.98:45472] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sua.nyx.temporary.site"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuBX_xWyxgRnoFKAJ_1MAAAAhw"]
[Thu Jul 30 11:52:47.758528 2026] [security2:error] [pid 643253:tid 643477] [client 68.221.186.136:44940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/accueil.php"] [unique_id "amuBX8jqbtjBYzqM1uYmhgAAAF0"]
[Thu Jul 30 11:52:47.761801 2026] [core:notice] [pid 643573:tid 643768] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:47.768486 2026] [security2:error] [pid 643573:tid 643768] [client 103.215.74.26:43528] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBX_xWyxgRnoFKAJ_1NAAAAk4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:48.226708 2026] [security2:error] [pid 642360:tid 642587] [client 57.141.0.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuBX5SUkh3e5AhEJOBwoAAAAfA"]
[Thu Jul 30 11:52:48.486090 2026] [core:notice] [pid 642360:tid 642508] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:48.491057 2026] [security2:error] [pid 642360:tid 642508] [client 103.215.74.26:43530] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBYJSUkh3e5AhEJOBwpgAAAaE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:48.573170 2026] [security2:error] [pid 642360:tid 642563] [client 68.221.186.136:42587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/dashboard.php"] [unique_id "amuBYJSUkh3e5AhEJOBwpwAAAdg"]
[Thu Jul 30 11:52:48.954932 2026] [security2:error] [pid 643573:tid 643824] [client 2a03:2880:f800:3f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBYPxWyxgRnoFKAJ_1OQAChmk"]
[Thu Jul 30 11:52:49.182480 2026] [security2:error] [pid 643573:tid 643755] [client 68.221.186.136:43818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/radio.php"] [unique_id "amuBYfxWyxgRnoFKAJ_1QQAAAkE"]
[Thu Jul 30 11:52:49.222713 2026] [core:notice] [pid 643253:tid 643434] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:49.226862 2026] [security2:error] [pid 643253:tid 643434] [client 103.215.74.26:43540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "771"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBYcjqbtjBYzqM1uYmhwAAADI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:49.624985 2026] [security2:error] [pid 643573:tid 643785] [client 86.241.173.36:59790] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuBYfxWyxgRnoFKAJ_1RQAAAl8"], referer: http://pkf.jo
[Thu Jul 30 11:52:50.035339 2026] [security2:error] [pid 643573:tid 643827] [client 59.183.69.7:59000] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuBYfxWyxgRnoFKAJ_1SwAAAok"], referer: http://pkf.jo
[Thu Jul 30 11:52:50.045554 2026] [security2:error] [pid 643573:tid 643833] [client 170.64.210.244:58938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:lang. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:lang"] [severity "CRITICAL"] [hostname "50.6.43.58"] [uri "/remote/fgt_lang"] [unique_id "amuBYvxWyxgRnoFKAJ_1TgAAAo8"]
[Thu Jul 30 11:52:50.175459 2026] [security2:error] [pid 643253:tid 643493] [client 68.221.186.136:26571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wpsml-sys.php"] [unique_id "amuBYsjqbtjBYzqM1uYmiwAAAG0"]
[Thu Jul 30 11:52:50.625949 2026] [security2:error] [pid 643253:tid 643409] [client 176.241.66.87:56862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBYsjqbtjBYzqM1uYmjQAAABk"]
[Thu Jul 30 11:52:50.626089 2026] [security2:error] [pid 643253:tid 643409] [client 176.241.66.87:56862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBYsjqbtjBYzqM1uYmjQAAABk"]
[Thu Jul 30 11:52:50.973824 2026] [security2:error] [pid 643573:tid 643726] [client 2a03:2880:f800:30:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBYvxWyxgRnoFKAJ_1UgACJCU"]
[Thu Jul 30 11:52:51.441468 2026] [security2:error] [pid 642360:tid 642511] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fantasynamelist.com"] [uri "/media/system/js/core.js"] [unique_id "amuBY5SUkh3e5AhEJOBwvgAAAaQ"]
[Thu Jul 30 11:52:51.584381 2026] [security2:error] [pid 643573:tid 643708] [remote 216.73.216.152:44174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuBY_xWyxgRnoFKAJ_1YAAChn8"]
[Thu Jul 30 11:52:52.453855 2026] [security2:error] [pid 643573:tid 643829] [client 106.76.74.61:37539] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuBZPxWyxgRnoFKAJ_1ZgAAAos"], referer: http://pkf.jo
[Thu Jul 30 11:52:53.068740 2026] [core:error] [pid 643573:tid 643774] [client 74.7.244.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:53.068761 2026] [core:error] [pid 643573:tid 643774] [client 74.7.244.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:53.068877 2026] [security2:error] [pid 643573:tid 643774] [client 74.7.244.37:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.ymk.udi.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/index.php"] [unique_id "amuBZfxWyxgRnoFKAJ_1bgAAAlQ"]
[Thu Jul 30 11:52:53.069531 2026] [security2:error] [pid 642360:tid 642542] [client 74.7.244.37:33888] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.ymk.udi.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "amuBZZSUkh3e5AhEJOBwygABw20"]
[Thu Jul 30 11:52:53.822511 2026] [security2:error] [pid 643573:tid 643746] [client 74.7.244.59:54442] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.adbacklink.com"] [uri "/robots.txt"] [unique_id "amuBZfxWyxgRnoFKAJ_1dAACOHg"]
[Thu Jul 30 11:52:54.183723 2026] [security2:error] [pid 643573:tid 643814] [client 68.221.186.136:42969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/02.php"] [unique_id "amuBZvxWyxgRnoFKAJ_1egAAAnw"]
[Thu Jul 30 11:52:54.390581 2026] [security2:error] [pid 643573:tid 643819] [client 2a03:2880:f800:32:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBZfxWyxgRnoFKAJ_1cQACgW4"]
[Thu Jul 30 11:52:54.747127 2026] [security2:error] [pid 643573:tid 643819] [client 2a03:2880:f800:2f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBZfxWyxgRnoFKAJ_1dwACgQg"]
[Thu Jul 30 11:52:54.986427 2026] [core:notice] [pid 642360:tid 642597] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:54.993242 2026] [security2:error] [pid 642360:tid 642597] [client 103.215.74.26:33700] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBZpSUkh3e5AhEJOBw3AAAAfo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:55.723349 2026] [core:notice] [pid 643573:tid 643769] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:55.727381 2026] [security2:error] [pid 643573:tid 643769] [client 103.215.74.26:33708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "784"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBZ_xWyxgRnoFKAJ_1gQAAAk8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:56.456321 2026] [core:notice] [pid 643573:tid 643716] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:56.460295 2026] [security2:error] [pid 643573:tid 643716] [client 103.215.74.26:33718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "756"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBaPxWyxgRnoFKAJ_1hQAAAho"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:57.197544 2026] [security2:error] [pid 643573:tid 643587] [remote 216.73.216.152:4166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuBafxWyxgRnoFKAJ_1iwACVAY"]
[Thu Jul 30 11:52:57.199256 2026] [core:notice] [pid 643573:tid 643788] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:57.203176 2026] [security2:error] [pid 643573:tid 643788] [client 103.215.74.26:33726] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBafxWyxgRnoFKAJ_1jAAAAmI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:57.236353 2026] [security2:error] [pid 642360:tid 642523] [client 62.102.148.185:37376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuBaZSUkh3e5AhEJOBw6wAAAbA"]
[Thu Jul 30 11:52:57.236437 2026] [security2:error] [pid 642360:tid 642523] [client 62.102.148.185:37376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuBaZSUkh3e5AhEJOBw6wAAAbA"]
[Thu Jul 30 11:52:57.240514 2026] [security2:error] [pid 642360:tid 642503] [client 74.7.175.142:49464] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bep-viet.bonafideadvisors.com"] [uri "/index.php"] [unique_id "amuBZJSUkh3e5AhEJOBwxQABnAM"]
[Thu Jul 30 11:52:57.989232 2026] [core:notice] [pid 642360:tid 642561] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:57.993226 2026] [security2:error] [pid 642360:tid 642561] [client 103.215.74.26:33742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "766"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBaZSUkh3e5AhEJOBw8AAAAdY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:58.181474 2026] [security2:error] [pid 643573:tid 643595] [remote 51.161.37.104:58664] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "kicksity.com"] [uri "/product/nik-air-jordan-4-canyon-purple/feed/"] [unique_id "amuBavxWyxgRnoFKAJ_1lwACQg4"]
[Thu Jul 30 11:52:58.181616 2026] [security2:error] [pid 643573:tid 643756] [client 51.161.37.104:58664] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/product/nik-air-jordan-4-canyon-purple/feed/"] [unique_id "amuBavxWyxgRnoFKAJ_1lwACQg4"]
[Thu Jul 30 11:52:58.714309 2026] [core:notice] [pid 642360:tid 642563] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:58.718729 2026] [security2:error] [pid 642360:tid 642563] [client 103.215.74.26:33750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBapSUkh3e5AhEJOBw9wAAAdg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:59.158558 2026] [security2:error] [pid 643573:tid 643808] [client 68.221.186.136:44394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/infos.php"] [unique_id "amuBa_xWyxgRnoFKAJ_1owAAAnY"]
[Thu Jul 30 11:52:59.222342 2026] [security2:error] [pid 643573:tid 643727] [client 57.141.0.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuBavxWyxgRnoFKAJ_1ngAAAiU"]
[Thu Jul 30 11:52:59.447636 2026] [core:notice] [pid 643573:tid 643711] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:59.451738 2026] [security2:error] [pid 643573:tid 643711] [client 103.215.74.26:33754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBa_xWyxgRnoFKAJ_1pwAAAhU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:59.608372 2026] [security2:error] [pid 643573:tid 643714] [client 2a03:2880:f800:3e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBavxWyxgRnoFKAJ_1ogACGEY"]
[Thu Jul 30 11:52:59.681783 2026] [security2:error] [pid 643573:tid 643772] [client 77.83.36.161:35087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/administrator/index.php"] [unique_id "amuBa_xWyxgRnoFKAJ_1pgAAAlI"]
[Thu Jul 30 11:52:59.881770 2026] [core:notice] [pid 643573:tid 643684] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:00.173137 2026] [security2:error] [pid 643573:tid 643781] [client 68.221.186.136:43007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/updates.php"] [unique_id "amuBbPxWyxgRnoFKAJ_1tAAAAls"]
[Thu Jul 30 11:53:00.182038 2026] [core:notice] [pid 642360:tid 642532] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:00.185835 2026] [security2:error] [pid 642360:tid 642532] [client 103.215.74.26:33756] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBbJSUkh3e5AhEJOBxBAAAAbk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:00.246945 2026] [security2:error] [pid 643573:tid 643749] [client 77.83.36.161:35540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/administrator/index.php"] [unique_id "amuBbPxWyxgRnoFKAJ_1tQAAAjs"]
[Thu Jul 30 11:53:00.630059 2026] [security2:error] [pid 642360:tid 642555] [client 190.2.142.78:30488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.142.2.190.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alqahtanifurnituremoversllc.site"] [uri "/wp-login.php"] [unique_id "amuBbJSUkh3e5AhEJOBxCAAAAdA"]
[Thu Jul 30 11:53:00.804039 2026] [security2:error] [pid 643573:tid 643745] [client 77.83.36.161:35841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/administrator/index.php"] [unique_id "amuBbPxWyxgRnoFKAJ_1vgAAAjc"]
[Thu Jul 30 11:53:00.902794 2026] [security2:error] [pid 642360:tid 642562] [client 57.141.0.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuBbJSUkh3e5AhEJOBxBwAAAdc"]
[Thu Jul 30 11:53:00.910947 2026] [core:notice] [pid 643573:tid 643779] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:00.915348 2026] [security2:error] [pid 643573:tid 643779] [client 103.215.74.26:33766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBbPxWyxgRnoFKAJ_1wQAAAlk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:00.953301 2026] [security2:error] [pid 642360:tid 642593] [client 68.221.186.136:42987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/user.php"] [unique_id "amuBbJSUkh3e5AhEJOBxDQAAAfY"]
[Thu Jul 30 11:53:01.110348 2026] [core:error] [pid 643573:tid 643806] [client 190.2.142.78:30500] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:53:01.110372 2026] [core:error] [pid 643573:tid 643806] [client 190.2.142.78:30500] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:53:01.268458 2026] [security2:error] [pid 643573:tid 643763] [client 176.241.66.87:57626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBbfxWyxgRnoFKAJ_1xAAAAkk"]
[Thu Jul 30 11:53:01.268574 2026] [security2:error] [pid 643573:tid 643763] [client 176.241.66.87:57626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBbfxWyxgRnoFKAJ_1xAAAAkk"]
[Thu Jul 30 11:53:01.598709 2026] [autoindex:error] [pid 643573:tid 643748] [client 190.2.142.78:30512] AH01276: Cannot serve directory /home2/ubphmute/public_html/website_170cb886/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:53:01.604477 2026] [security2:error] [pid 643573:tid 643770] [client 68.221.186.136:26608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/admin-ajax.php"] [unique_id "amuBbfxWyxgRnoFKAJ_1xwAAAlA"]
[Thu Jul 30 11:53:01.606562 2026] [security2:error] [pid 643573:tid 643600] [remote 216.73.216.152:4166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuBbfxWyxgRnoFKAJ_1yAACKxM"]
[Thu Jul 30 11:53:01.636155 2026] [core:notice] [pid 643573:tid 643713] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:01.640396 2026] [security2:error] [pid 643573:tid 643713] [client 103.215.74.26:33770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBbfxWyxgRnoFKAJ_1yQAAAhc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:02.365101 2026] [core:notice] [pid 643573:tid 643831] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:02.369503 2026] [security2:error] [pid 643573:tid 643831] [client 103.215.74.26:33780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBbvxWyxgRnoFKAJ_10wAAAo0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:02.630099 2026] [security2:error] [pid 643573:tid 643753] [client 103.59.160.82:52538] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "bonafideadvisors.com"] [uri "/index.php"] [unique_id "amuBbvxWyxgRnoFKAJ_11QAAAj8"]
[Thu Jul 30 11:53:03.098146 2026] [core:notice] [pid 642360:tid 642599] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:03.102621 2026] [security2:error] [pid 642360:tid 642599] [client 103.215.74.26:12458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBb5SUkh3e5AhEJOBxHAAAAfw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:03.372915 2026] [security2:error] [pid 643573:tid 643737] [client 68.221.186.136:42569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/alfa.php"] [unique_id "amuBb_xWyxgRnoFKAJ_12wAAAi8"]
[Thu Jul 30 11:53:03.832908 2026] [core:notice] [pid 643573:tid 643820] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:03.837285 2026] [security2:error] [pid 643573:tid 643820] [client 103.215.74.26:12470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBb_xWyxgRnoFKAJ_13gAAAoI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:04.232028 2026] [security2:error] [pid 642360:tid 642615] [client 72.252.232.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBb5SUkh3e5AhEJOBxHgACDEg"], referer: https://allmontecristi.com
[Thu Jul 30 11:53:06.110855 2026] [security2:error] [pid 643573:tid 643759] [client 190.2.142.78:20012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.142.2.190.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alqimmafurnituremovers.xyz"] [uri "/wp-login.php"] [unique_id "amuBcvxWyxgRnoFKAJ_19QAAAkU"]
[Thu Jul 30 11:53:06.256795 2026] [proxy:error] [pid 643573:tid 643773] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:53:06.256898 2026] [proxy_http:error] [pid 643573:tid 643773] [client 68.221.186.136:42289] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:53:06.257894 2026] [proxy:error] [pid 643573:tid 643773] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:53:06.257955 2026] [proxy_http:error] [pid 643573:tid 643773] [client 68.221.186.136:42289] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:53:06.592704 2026] [core:error] [pid 643573:tid 643720] [client 190.2.142.78:20022] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:53:06.592726 2026] [core:error] [pid 643573:tid 643720] [client 190.2.142.78:20022] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:53:07.049046 2026] [security2:error] [pid 643573:tid 643808] [client 203.175.125.116:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "tmrfsl.com"] [uri "/wp-json/batch/v1"] [unique_id "amuBc_xWyxgRnoFKAJ_1_wAAAnY"]
[Thu Jul 30 11:53:07.117694 2026] [security2:error] [pid 643573:tid 643728] [client 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuBcvxWyxgRnoFKAJ_1_AACJjU"]
[Thu Jul 30 11:53:07.217633 2026] [security2:error] [pid 642360:tid 642454] [remote 216.73.216.152:24715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuBc5SUkh3e5AhEJOBxNgAB1l0"]
[Thu Jul 30 11:53:09.356635 2026] [security2:error] [pid 643573:tid 643782] [client 68.221.186.136:42583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/hehe.php"] [unique_id "amuBdfxWyxgRnoFKAJ_2DwAAAlw"]
[Thu Jul 30 11:53:09.598056 2026] [core:notice] [pid 642360:tid 642582] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:09.603205 2026] [security2:error] [pid 642360:tid 642582] [client 103.215.74.26:12506] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBdZSUkh3e5AhEJOBxTQAAAes"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:10.114867 2026] [security2:error] [pid 643573:tid 643810] [client 68.221.186.136:43017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/rk2.php"] [unique_id "amuBdvxWyxgRnoFKAJ_2FAAAAng"]
[Thu Jul 30 11:53:10.340325 2026] [core:notice] [pid 643573:tid 643809] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:10.344417 2026] [security2:error] [pid 643573:tid 643809] [client 103.215.74.26:12508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBdvxWyxgRnoFKAJ_2GwAAAnc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:10.582699 2026] [security2:error] [pid 643573:tid 643763] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "illicali.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "amuBdvxWyxgRnoFKAJ_2HAAAAkk"]
[Thu Jul 30 11:53:11.116542 2026] [core:notice] [pid 643573:tid 643804] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:11.120878 2026] [security2:error] [pid 643573:tid 643804] [client 103.215.74.26:12512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBd_xWyxgRnoFKAJ_2IQAAAnI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:11.616614 2026] [security2:error] [pid 642360:tid 642446] [remote 216.73.216.152:24715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuBd5SUkh3e5AhEJOBxXgABqFU"]
[Thu Jul 30 11:53:11.925212 2026] [security2:error] [pid 643573:tid 643821] [client 176.241.66.87:23255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBd_xWyxgRnoFKAJ_2JwAAAoM"]
[Thu Jul 30 11:53:11.925404 2026] [security2:error] [pid 643573:tid 643821] [client 176.241.66.87:23255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBd_xWyxgRnoFKAJ_2JwAAAoM"]
[Thu Jul 30 11:53:12.743843 2026] [security2:error] [pid 643573:tid 643737] [client 68.221.186.136:43049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/setup-config.php"] [unique_id "amuBePxWyxgRnoFKAJ_2MgAAAi8"]
[Thu Jul 30 11:53:13.505722 2026] [security2:error] [pid 642360:tid 642594] [client 172.213.208.20:6668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wk/index.php"] [unique_id "amuBeZSUkh3e5AhEJOBxeAAAAfc"]
[Thu Jul 30 11:53:13.596542 2026] [security2:error] [pid 643573:tid 643769] [client 68.221.186.136:26561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/a7.php"] [unique_id "amuBefxWyxgRnoFKAJ_2OAAAAk8"]
[Thu Jul 30 11:53:14.376257 2026] [security2:error] [pid 643573:tid 643776] [client 172.213.208.20:22611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/av.php"] [unique_id "amuBevxWyxgRnoFKAJ_2PAAAAlY"]
[Thu Jul 30 11:53:15.499511 2026] [security2:error] [pid 643573:tid 643710] [client 172.213.208.20:44816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/mini.php"] [unique_id "amuBe_xWyxgRnoFKAJ_2QgAAAhQ"]
[Thu Jul 30 11:53:15.701405 2026] [security2:error] [pid 643573:tid 643828] [client 68.221.186.136:43266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/f7.php"] [unique_id "amuBe_xWyxgRnoFKAJ_2RwAAAoo"]
[Thu Jul 30 11:53:15.802537 2026] [security2:error] [pid 643253:tid 643408] [client 57.141.0.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuBe8jqbtjBYzqM1uYmmAAAABg"]
[Thu Jul 30 11:53:15.841657 2026] [security2:error] [pid 643573:tid 643607] [remote 57.141.0.42:63024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuBe_xWyxgRnoFKAJ_2SAACHho"]
[Thu Jul 30 11:53:16.294736 2026] [security2:error] [pid 643253:tid 643488] [client 68.221.186.136:44706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/nw.php"] [unique_id "amuBfMjqbtjBYzqM1uYmmgAAAGg"]
[Thu Jul 30 11:53:16.846913 2026] [core:notice] [pid 643573:tid 643809] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:16.851299 2026] [security2:error] [pid 643573:tid 643809] [client 103.215.74.26:26388] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBfPxWyxgRnoFKAJ_2UgAAAnc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:17.225153 2026] [security2:error] [pid 643573:tid 643658] [remote 216.73.216.152:61267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuBffxWyxgRnoFKAJ_2VwACck0"]
[Thu Jul 30 11:53:18.091603 2026] [security2:error] [pid 643573:tid 643836] [client 68.221.186.136:43068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/ova.php"] [unique_id "amuBfvxWyxgRnoFKAJ_2XgAAApI"]
[Thu Jul 30 11:53:18.380677 2026] [security2:error] [pid 643573:tid 643755] [client 34.86.95.193:52091] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "skcarrental.ae"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuBfvxWyxgRnoFKAJ_2YgAAAkE"]
[Thu Jul 30 11:53:18.642786 2026] [security2:error] [pid 643573:tid 643741] [client 172.213.208.20:6490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/aa.php"] [unique_id "amuBfvxWyxgRnoFKAJ_2ZwAAAjM"]
[Thu Jul 30 11:53:19.227927 2026] [security2:error] [pid 643253:tid 643489] [client 68.221.186.136:42522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/robots.php"] [unique_id "amuBf8jqbtjBYzqM1uYmnAAAAGk"]
[Thu Jul 30 11:53:19.228122 2026] [core:notice] [pid 643573:tid 643834] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:19.750487 2026] [security2:error] [pid 643573:tid 643714] [client 57.141.0.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuBf_xWyxgRnoFKAJ_2cQAAAhg"]
[Thu Jul 30 11:53:19.757796 2026] [security2:error] [pid 643573:tid 643827] [client 95.126.50.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBf_xWyxgRnoFKAJ_2bgACiUk"], referer: https://allmontecristi.com
[Thu Jul 30 11:53:20.017646 2026] [security2:error] [pid 643573:tid 643831] [client 68.221.186.136:45609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/alf.php"] [unique_id "amuBgPxWyxgRnoFKAJ_2fAAAAo0"]
[Thu Jul 30 11:53:20.134406 2026] [core:notice] [pid 643573:tid 643655] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:20.634230 2026] [security2:error] [pid 643573:tid 643671] [remote 74.7.241.60:41892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/article.php"] [unique_id "amuBgPxWyxgRnoFKAJ_2hAACa1o"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/bootstrap.bundle.min.js
[Thu Jul 30 11:53:20.693771 2026] [security2:error] [pid 643573:tid 643774] [client 62.102.148.185:45252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuBgPxWyxgRnoFKAJ_2iwAAAlQ"]
[Thu Jul 30 11:53:20.693876 2026] [security2:error] [pid 643573:tid 643774] [client 62.102.148.185:45252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuBgPxWyxgRnoFKAJ_2iwAAAlQ"]
[Thu Jul 30 11:53:20.700209 2026] [security2:error] [pid 643573:tid 643723] [client 216.244.66.242:37788] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/category/politica/hc/en-us/articles/41383541904281-Envato-Market-Terms"] [unique_id "amuBgPxWyxgRnoFKAJ_2jQAAAiE"]
[Thu Jul 30 11:53:20.700351 2026] [security2:error] [pid 643573:tid 643723] [client 216.244.66.242:37788] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/category/politica/hc/en-us/articles/41383541904281-Envato-Market-Terms"] [unique_id "amuBgPxWyxgRnoFKAJ_2jQAAAiE"]
[Thu Jul 30 11:53:20.749307 2026] [core:error] [pid 643573:tid 643755] [client 206.238.68.173:55404] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh)
[Thu Jul 30 11:53:21.006169 2026] [security2:error] [pid 643573:tid 643751] [client 172.213.208.20:14846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/w.php"] [unique_id "amuBgfxWyxgRnoFKAJ_2kwAAAj0"]
[Thu Jul 30 11:53:21.009789 2026] [autoindex:error] [pid 643573:tid 643761] [client 101.33.55.204:54440] AH01276: Cannot serve directory /home2/kiinyxte/xexrecords.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:53:21.018630 2026] [security2:error] [pid 643573:tid 643781] [client 68.221.186.136:45598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/feedback.php"] [unique_id "amuBgfxWyxgRnoFKAJ_2lAAAAls"]
[Thu Jul 30 11:53:21.623920 2026] [security2:error] [pid 643573:tid 643666] [remote 216.73.216.152:61267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuBgfxWyxgRnoFKAJ_2ngACTlU"]
[Thu Jul 30 11:53:21.799430 2026] [core:error] [pid 643573:tid 643663] [remote 216.73.217.1:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:53:21.799453 2026] [core:error] [pid 643573:tid 643663] [remote 216.73.217.1:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:53:21.869973 2026] [security2:error] [pid 642360:tid 642523] [client 172.213.208.20:18515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/admin.php"] [unique_id "amuBgZSUkh3e5AhEJOBxvwAAAbA"]
[Thu Jul 30 11:53:22.097059 2026] [security2:error] [pid 642360:tid 642557] [client 68.221.186.136:44524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/gettest.php"] [unique_id "amuBgpSUkh3e5AhEJOBxwgAAAdI"]
[Thu Jul 30 11:53:22.243591 2026] [core:notice] [pid 642360:tid 642480] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:22.523013 2026] [security2:error] [pid 643573:tid 643802] [client 176.241.66.87:23925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBgvxWyxgRnoFKAJ_2qAAAAnA"]
[Thu Jul 30 11:53:22.523150 2026] [security2:error] [pid 643573:tid 643802] [client 176.241.66.87:23925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBgvxWyxgRnoFKAJ_2qAAAAnA"]
[Thu Jul 30 11:53:22.632366 2026] [core:notice] [pid 643253:tid 643391] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:22.636530 2026] [security2:error] [pid 643253:tid 643391] [client 103.215.74.26:26400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBgsjqbtjBYzqM1uYmngAAAAc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:22.884306 2026] [autoindex:error] [pid 643573:tid 643732] [client 195.96.139.114:51223] AH01276: Cannot serve directory /home2/mbmudite/koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:53:22.978862 2026] [security2:error] [pid 643573:tid 643828] [client 34.86.95.193:60105] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "skcarrental.ae"] [uri "/xmlrpc.php"] [unique_id "amuBgvxWyxgRnoFKAJ_2qQAAAoo"]
[Thu Jul 30 11:53:23.280056 2026] [security2:error] [pid 642360:tid 642563] [client 187.249.92.243:33474] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuBgpSUkh3e5AhEJOBxyQAAAdg"], referer: http://pkf.jo
[Thu Jul 30 11:53:23.295793 2026] [security2:error] [pid 642360:tid 642521] [client 68.221.186.136:43267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/maint.php"] [unique_id "amuBg5SUkh3e5AhEJOBxzwAAAa4"]
[Thu Jul 30 11:53:23.302010 2026] [core:notice] [pid 642360:tid 642376] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:23.316769 2026] [core:notice] [pid 643573:tid 643648] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:23.322067 2026] [core:notice] [pid 642360:tid 642365] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:23.371619 2026] [core:notice] [pid 643253:tid 643432] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:23.375767 2026] [security2:error] [pid 643253:tid 643432] [client 103.215.74.26:56034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "757"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBg8jqbtjBYzqM1uYmoQAAADA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:23.479916 2026] [security2:error] [pid 642360:tid 642528] [client 172.213.208.20:36541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuBg5SUkh3e5AhEJOBx1AAAAbU"]
[Thu Jul 30 11:53:23.606994 2026] [security2:error] [pid 643573:tid 643745] [client 138.36.48.104:23892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuBg_xWyxgRnoFKAJ_2rgAAAjc"], referer: http://pkf.jo
[Thu Jul 30 11:53:23.677046 2026] [security2:error] [pid 643573:tid 643763] [client 2a03:2880:f800:1c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBg_xWyxgRnoFKAJ_2rAACSVw"]
[Thu Jul 30 11:53:24.090246 2026] [core:notice] [pid 643573:tid 643769] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:24.095131 2026] [security2:error] [pid 643573:tid 643769] [client 103.215.74.26:56046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBhPxWyxgRnoFKAJ_2twAAAk8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:24.198291 2026] [security2:error] [pid 642360:tid 642566] [client 34.86.95.193:62859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "skcarrental.ae"] [uri "/xmlrpc.php"] [unique_id "amuBhJSUkh3e5AhEJOBx2QAAAds"]
[Thu Jul 30 11:53:24.458392 2026] [security2:error] [pid 642360:tid 642494] [client 68.221.186.136:43057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/files.php"] [unique_id "amuBhJSUkh3e5AhEJOBx2wAAAZM"]
[Thu Jul 30 11:53:24.531180 2026] [security2:error] [pid 642360:tid 642590] [client 172.213.208.20:6214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/m.php"] [unique_id "amuBhJSUkh3e5AhEJOBx3gAAAfM"]
[Thu Jul 30 11:53:24.820579 2026] [core:notice] [pid 643573:tid 643788] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:24.824951 2026] [security2:error] [pid 643573:tid 643788] [client 103.215.74.26:56058] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBhPxWyxgRnoFKAJ_2vAAAAmI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:25.334120 2026] [security2:error] [pid 643573:tid 643835] [client 85.107.103.96:41264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuBhfxWyxgRnoFKAJ_2vgAAApE"], referer: http://pkf.jo
[Thu Jul 30 11:53:25.353259 2026] [security2:error] [pid 643573:tid 643768] [client 34.86.95.193:62762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "skcarrental.ae"] [uri "/xmlrpc.php"] [unique_id "amuBhfxWyxgRnoFKAJ_2wwAAAk4"]
[Thu Jul 30 11:53:25.441568 2026] [autoindex:error] [pid 643573:tid 643738] [client 129.226.174.80:35156] AH01276: Cannot serve directory /home1/khwnyxte/arabiantourz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:53:25.546246 2026] [core:notice] [pid 643573:tid 643831] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:25.552230 2026] [security2:error] [pid 643573:tid 643831] [client 103.215.74.26:56066] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBhfxWyxgRnoFKAJ_2yAAAAo0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:26.279183 2026] [core:notice] [pid 643573:tid 643779] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:26.286029 2026] [security2:error] [pid 643573:tid 643779] [client 103.215.74.26:56076] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBhvxWyxgRnoFKAJ_20QAAAlk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:26.357155 2026] [core:notice] [pid 642360:tid 642602] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:26.516501 2026] [security2:error] [pid 643253:tid 643446] [client 34.86.95.193:62128] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "skcarrental.ae"] [uri "/xmlrpc.php"] [unique_id "amuBhsjqbtjBYzqM1uYmogAAAD4"]
[Thu Jul 30 11:53:26.627737 2026] [security2:error] [pid 642360:tid 642515] [client 172.213.208.20:43749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuBhpSUkh3e5AhEJOBx7QAAAag"]
[Thu Jul 30 11:53:26.996601 2026] [core:notice] [pid 642360:tid 642526] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:27.000777 2026] [security2:error] [pid 642360:tid 642526] [client 103.215.74.26:56078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBhpSUkh3e5AhEJOBx8QAAAbM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:27.271386 2026] [security2:error] [pid 643573:tid 643687] [remote 216.73.216.152:22365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuBh_xWyxgRnoFKAJ_26AACg2o"]
[Thu Jul 30 11:53:27.630263 2026] [security2:error] [pid 642360:tid 642512] [client 172.237.109.114:14420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBh5SUkh3e5AhEJOBx8gAAAaU"]
[Thu Jul 30 11:53:27.689740 2026] [security2:error] [pid 643573:tid 643786] [client 172.237.109.114:29500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBh_xWyxgRnoFKAJ_24gAAAmA"]
[Thu Jul 30 11:53:27.708095 2026] [security2:error] [pid 643573:tid 643735] [client 172.237.109.114:48149] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBh_xWyxgRnoFKAJ_24QAAAi0"]
[Thu Jul 30 11:53:27.720246 2026] [core:notice] [pid 643573:tid 643711] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:27.724352 2026] [security2:error] [pid 643573:tid 643711] [client 103.215.74.26:56082] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "773"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBh_xWyxgRnoFKAJ_27QAAAhU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:27.750545 2026] [security2:error] [pid 643573:tid 643795] [client 172.237.109.114:4671] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBh_xWyxgRnoFKAJ_25AAAAmk"]
[Thu Jul 30 11:53:27.750649 2026] [security2:error] [pid 643573:tid 643748] [client 172.237.109.114:64789] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBh_xWyxgRnoFKAJ_24wAAAjo"]
[Thu Jul 30 11:53:27.755330 2026] [security2:error] [pid 643573:tid 643726] [client 34.86.95.193:55588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "skcarrental.ae"] [uri "/xmlrpc.php"] [unique_id "amuBh_xWyxgRnoFKAJ_26wAAAiQ"]
[Thu Jul 30 11:53:27.771445 2026] [security2:error] [pid 643573:tid 643767] [client 172.237.109.114:27602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBh_xWyxgRnoFKAJ_25QAAAk0"]
[Thu Jul 30 11:53:28.326150 2026] [security2:error] [pid 643573:tid 643698] [remote 57.141.0.44:25524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuBiPxWyxgRnoFKAJ_2_QACJXU"]
[Thu Jul 30 11:53:28.462550 2026] [core:notice] [pid 643573:tid 643824] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:28.473899 2026] [security2:error] [pid 643573:tid 643824] [client 103.215.74.26:56086] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBiPxWyxgRnoFKAJ_2_gAAAoY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:28.725930 2026] [security2:error] [pid 643573:tid 643749] [client 68.221.186.136:42525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/gecko.php"] [unique_id "amuBiPxWyxgRnoFKAJ_3AQAAAjs"]
[Thu Jul 30 11:53:29.032177 2026] [security2:error] [pid 642360:tid 642603] [client 34.86.95.193:49154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "skcarrental.ae"] [uri "/xmlrpc.php"] [unique_id "amuBiJSUkh3e5AhEJOByBQAAAgA"]
[Thu Jul 30 11:53:29.205291 2026] [core:notice] [pid 643573:tid 643807] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:29.209418 2026] [security2:error] [pid 643573:tid 643807] [client 103.215.74.26:56098] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "786"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBifxWyxgRnoFKAJ_3BwAAAnU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:29.252342 2026] [security2:error] [pid 643573:tid 643829] [client 172.237.109.114:9417] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBiPxWyxgRnoFKAJ_28QAAAos"]
[Thu Jul 30 11:53:29.284887 2026] [security2:error] [pid 643573:tid 643732] [client 172.237.109.114:58705] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBiPxWyxgRnoFKAJ_28AAAAio"]
[Thu Jul 30 11:53:29.287096 2026] [security2:error] [pid 643573:tid 643755] [client 172.237.109.114:59970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBiPxWyxgRnoFKAJ_28gAAAkE"]
[Thu Jul 30 11:53:29.308004 2026] [security2:error] [pid 643573:tid 643810] [client 172.237.109.114:38041] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBiPxWyxgRnoFKAJ_28wAAAng"]
[Thu Jul 30 11:53:29.315361 2026] [security2:error] [pid 643573:tid 643803] [client 68.221.186.136:46274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/zwso.php"] [unique_id "amuBifxWyxgRnoFKAJ_3CgAAAnE"]
[Thu Jul 30 11:53:29.317043 2026] [security2:error] [pid 642360:tid 642507] [client 172.237.109.114:13050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBiJSUkh3e5AhEJOBx-gAAAaA"]
[Thu Jul 30 11:53:29.320537 2026] [security2:error] [pid 643573:tid 643745] [client 172.237.109.114:63840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBiPxWyxgRnoFKAJ_29AAAAjc"]
[Thu Jul 30 11:53:29.367353 2026] [security2:error] [pid 642360:tid 642580] [client 172.237.109.114:28612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBiJSUkh3e5AhEJOBx-wAAAek"]
[Thu Jul 30 11:53:29.378968 2026] [security2:error] [pid 642360:tid 642591] [client 172.237.109.114:16876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBiJSUkh3e5AhEJOBx_AAAAfQ"]
[Thu Jul 30 11:53:29.385400 2026] [security2:error] [pid 642360:tid 642578] [client 172.237.109.114:1658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBiJSUkh3e5AhEJOBx-QAAAec"]
[Thu Jul 30 11:53:29.409881 2026] [security2:error] [pid 642360:tid 642594] [client 172.237.109.114:53114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBiJSUkh3e5AhEJOBx_gAAAfc"]
[Thu Jul 30 11:53:29.422529 2026] [security2:error] [pid 642360:tid 642545] [client 172.237.109.114:42406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBiJSUkh3e5AhEJOBx_QAAAcY"]
[Thu Jul 30 11:53:29.423717 2026] [security2:error] [pid 643573:tid 643724] [client 172.237.109.114:42555] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBiPxWyxgRnoFKAJ_29gAAAiI"]
[Thu Jul 30 11:53:29.439286 2026] [security2:error] [pid 643573:tid 643725] [client 172.237.109.114:24790] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBiPxWyxgRnoFKAJ_29QAAAiM"]
[Thu Jul 30 11:53:29.461905 2026] [security2:error] [pid 643573:tid 643785] [client 172.237.109.114:17862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBiPxWyxgRnoFKAJ_2-AAAAl8"]
[Thu Jul 30 11:53:29.490675 2026] [security2:error] [pid 643573:tid 643697] [remote 57.141.0.60:62790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amuBifxWyxgRnoFKAJ_3DQACgXQ"]
[Thu Jul 30 11:53:29.951843 2026] [core:notice] [pid 643573:tid 643779] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:29.956936 2026] [security2:error] [pid 643573:tid 643779] [client 103.215.74.26:56100] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBifxWyxgRnoFKAJ_3EgAAAlk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:29.988255 2026] [security2:error] [pid 643573:tid 643831] [client 2a03:2880:f800:10:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBifxWyxgRnoFKAJ_3CwACjWI"]
[Thu Jul 30 11:53:30.198798 2026] [security2:error] [pid 643573:tid 643746] [client 34.86.95.193:61304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "skcarrental.ae"] [uri "/xmlrpc.php"] [unique_id "amuBivxWyxgRnoFKAJ_3EwAAAjg"]
[Thu Jul 30 11:53:30.463373 2026] [security2:error] [pid 643573:tid 643780] [client 68.221.186.136:46319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/13.php"] [unique_id "amuBivxWyxgRnoFKAJ_3HAAAAlo"]
[Thu Jul 30 11:53:30.480492 2026] [proxy:error] [pid 643573:tid 643801] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:53:30.480586 2026] [proxy_http:error] [pid 643573:tid 643801] [client 34.224.175.62:35920] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:53:30.481423 2026] [proxy:error] [pid 643573:tid 643801] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:53:30.481482 2026] [proxy_http:error] [pid 643573:tid 643801] [client 34.224.175.62:35920] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:53:30.514548 2026] [proxy:error] [pid 643573:tid 643713] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:53:30.514627 2026] [proxy_http:error] [pid 643573:tid 643713] [client 34.233.129.35:49502] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:53:30.515470 2026] [proxy:error] [pid 643573:tid 643713] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:53:30.515528 2026] [proxy_http:error] [pid 643573:tid 643713] [client 34.233.129.35:49502] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:53:30.667846 2026] [security2:error] [pid 643573:tid 643800] [client 172.213.208.20:16296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/classwithtostring.php"] [unique_id "amuBivxWyxgRnoFKAJ_3IQAAAm4"]
[Thu Jul 30 11:53:30.789282 2026] [security2:error] [pid 643573:tid 643692] [remote 57.141.0.12:49256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/358522518/feed/rss2/"] [unique_id "amuBivxWyxgRnoFKAJ_3IwACf28"]
[Thu Jul 30 11:53:30.890068 2026] [core:error] [pid 643573:tid 643803] [client 158.173.25.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://appliancerepairservice.one/
[Thu Jul 30 11:53:30.890090 2026] [core:error] [pid 643573:tid 643803] [client 158.173.25.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://appliancerepairservice.one/
[Thu Jul 30 11:53:30.970664 2026] [core:notice] [pid 643573:tid 643729] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:31.175362 2026] [core:error] [pid 643573:tid 643708] [remote 74.7.175.160:38496] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:53:31.175397 2026] [core:error] [pid 643573:tid 643708] [remote 74.7.175.160:38496] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:53:31.175697 2026] [security2:error] [pid 643573:tid 643708] [remote 74.7.175.160:38496] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.website-78cdf888.ubp.hmu.temporary.site"] [uri "/index.php"] [unique_id "amuBi_xWyxgRnoFKAJ_3NgACFn8"]
[Thu Jul 30 11:53:31.408293 2026] [security2:error] [pid 643573:tid 643768] [client 34.86.95.193:54046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "skcarrental.ae"] [uri "/xmlrpc.php"] [unique_id "amuBi_xWyxgRnoFKAJ_3NwAAAk4"]
[Thu Jul 30 11:53:31.543338 2026] [security2:error] [pid 642360:tid 642516] [client 2a03:2880:f800:d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBipSUkh3e5AhEJOByFgABqUM"]
[Thu Jul 30 11:53:31.633444 2026] [security2:error] [pid 643573:tid 643690] [remote 216.73.216.152:22365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuBi_xWyxgRnoFKAJ_3OwACRm0"]
[Thu Jul 30 11:53:31.698249 2026] [security2:error] [pid 642360:tid 642490] [client 43.172.198.249:37618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.198.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/05/12/robes-pour-un-mariage-d-ete/"] [unique_id "amuBi5SUkh3e5AhEJOByIwAAAY8"]
[Thu Jul 30 11:53:32.077678 2026] [proxy:error] [pid 643573:tid 643718] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:53:32.077746 2026] [proxy_http:error] [pid 643573:tid 643718] [client 87.236.176.48:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.koinjp189.com:8080
[Thu Jul 30 11:53:32.078368 2026] [proxy:error] [pid 643573:tid 643718] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:53:32.078413 2026] [proxy_http:error] [pid 643573:tid 643718] [client 87.236.176.48:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.koinjp189.com:8080
[Thu Jul 30 11:53:32.182455 2026] [security2:error] [pid 643573:tid 643810] [client 68.221.186.136:46282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/ava.php"] [unique_id "amuBjPxWyxgRnoFKAJ_3SAAAAng"]
[Thu Jul 30 11:53:32.431232 2026] [security2:error] [pid 643573:tid 643745] [client 172.237.109.114:60273] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi_xWyxgRnoFKAJ_3JwAAAjc"]
[Thu Jul 30 11:53:32.432648 2026] [security2:error] [pid 643253:tid 643506] [client 172.237.109.114:35593] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi8jqbtjBYzqM1uYmqQAAAHo"]
[Thu Jul 30 11:53:32.455041 2026] [core:notice] [pid 643573:tid 643771] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:32.464548 2026] [security2:error] [pid 643573:tid 643771] [client 43.173.175.10:59698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/05/12/robes-pour-un-mariage-d-ete/"] [unique_id "amuBjPxWyxgRnoFKAJ_3TAAAAlE"], referer: https://carnetdeshopping.com/index.php/2014/05/12/robes-pour-un-mariage-d-ete/
[Thu Jul 30 11:53:32.493916 2026] [security2:error] [pid 643573:tid 643805] [client 172.237.109.114:55236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi_xWyxgRnoFKAJ_3KAAAAnM"]
[Thu Jul 30 11:53:32.541440 2026] [security2:error] [pid 643573:tid 643786] [client 172.237.109.114:10682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi_xWyxgRnoFKAJ_3KwAAAmA"]
[Thu Jul 30 11:53:32.571776 2026] [security2:error] [pid 643573:tid 643778] [client 172.237.109.114:6681] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi_xWyxgRnoFKAJ_3MAAAAlg"]
[Thu Jul 30 11:53:32.573817 2026] [security2:error] [pid 643573:tid 643836] [client 172.237.109.114:40263] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi_xWyxgRnoFKAJ_3MwAAApI"]
[Thu Jul 30 11:53:32.577511 2026] [security2:error] [pid 643573:tid 643724] [client 172.237.109.114:39179] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi_xWyxgRnoFKAJ_3LgAAAiI"]
[Thu Jul 30 11:53:32.644408 2026] [security2:error] [pid 642360:tid 642525] [client 34.86.95.193:62305] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "skcarrental.ae"] [uri "/xmlrpc.php"] [unique_id "amuBjJSUkh3e5AhEJOByKAAAAbI"]
[Thu Jul 30 11:53:32.736474 2026] [security2:error] [pid 643573:tid 643802] [client 85.208.96.207:16962] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/05/17/cicero-descarta-que-progressistas-possa-seguir-caminho-divergente-do-de-joao-e-prega-uniao-em-torno-do-melhor-para-a-paraiba/"] [unique_id "amuBjPxWyxgRnoFKAJ_3TgAAAnA"]
[Thu Jul 30 11:53:32.736588 2026] [security2:error] [pid 643573:tid 643802] [client 85.208.96.207:16962] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/05/17/cicero-descarta-que-progressistas-possa-seguir-caminho-divergente-do-de-joao-e-prega-uniao-em-torno-do-melhor-para-a-paraiba/"] [unique_id "amuBjPxWyxgRnoFKAJ_3TgAAAnA"]
[Thu Jul 30 11:53:33.206587 2026] [security2:error] [pid 643573:tid 643803] [client 176.241.66.87:24571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBjfxWyxgRnoFKAJ_3UwAAAnE"]
[Thu Jul 30 11:53:33.206710 2026] [security2:error] [pid 643573:tid 643803] [client 176.241.66.87:24571] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBjfxWyxgRnoFKAJ_3UwAAAnE"]
[Thu Jul 30 11:53:33.219856 2026] [security2:error] [pid 643573:tid 643795] [client 172.237.109.114:4265] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi_xWyxgRnoFKAJ_3LQAAAmk"]
[Thu Jul 30 11:53:33.229481 2026] [security2:error] [pid 643573:tid 643765] [client 172.237.109.114:61956] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi_xWyxgRnoFKAJ_3KgAAAks"]
[Thu Jul 30 11:53:33.229858 2026] [security2:error] [pid 642360:tid 642566] [client 172.237.109.114:53403] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi5SUkh3e5AhEJOByHgAAAds"]
[Thu Jul 30 11:53:33.234301 2026] [security2:error] [pid 643573:tid 643785] [client 172.237.109.114:57746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi_xWyxgRnoFKAJ_3NQAAAl8"]
[Thu Jul 30 11:53:33.240007 2026] [security2:error] [pid 643573:tid 643740] [client 172.237.109.114:52813] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi_xWyxgRnoFKAJ_3KQAAAjI"]
[Thu Jul 30 11:53:33.241053 2026] [security2:error] [pid 643573:tid 643726] [client 172.237.109.114:35978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi_xWyxgRnoFKAJ_3MQAAAiQ"]
[Thu Jul 30 11:53:33.241342 2026] [security2:error] [pid 643573:tid 643735] [client 172.237.109.114:36723] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi_xWyxgRnoFKAJ_3LAAAAi0"]
[Thu Jul 30 11:53:33.262269 2026] [security2:error] [pid 643253:tid 643418] [client 172.237.109.114:34663] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi8jqbtjBYzqM1uYmqwAAACI"]
[Thu Jul 30 11:53:33.270062 2026] [security2:error] [pid 643573:tid 643767] [client 172.237.109.114:29207] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi_xWyxgRnoFKAJ_3NAAAAk0"]
[Thu Jul 30 11:53:33.287344 2026] [security2:error] [pid 643253:tid 643454] [client 172.237.109.114:31242] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi8jqbtjBYzqM1uYmqgAAAEY"]
[Thu Jul 30 11:53:33.329421 2026] [security2:error] [pid 643573:tid 643725] [client 172.237.109.114:3407] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi_xWyxgRnoFKAJ_3MgAAAiM"]
[Thu Jul 30 11:53:33.330410 2026] [security2:error] [pid 643573:tid 643748] [client 172.237.109.114:56603] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi_xWyxgRnoFKAJ_3LwAAAjo"]
[Thu Jul 30 11:53:33.336208 2026] [security2:error] [pid 642360:tid 642588] [client 172.237.109.114:49470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi5SUkh3e5AhEJOByHQAAAfE"]
[Thu Jul 30 11:53:33.879802 2026] [security2:error] [pid 642360:tid 642514] [client 34.86.95.193:63342] ModSecurity: Warning. Operator GE matched 2 at IP:dos_burst_counter. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "99"] [id "350114"] [rev "1"] [msg "Atomicorp.com WAF Rules: Potential Denial of Service (DoS) Attack from - # of Request Bursts: 2"] [severity "ERROR"] [tag "no_ar"] [hostname "skcarrental.ae"] [uri "/xmlrpc.php"] [unique_id "amuBjZSUkh3e5AhEJOByNAAAAac"]
[Thu Jul 30 11:53:33.879841 2026] [security2:error] [pid 642360:tid 642514] [client 34.86.95.193:63342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "skcarrental.ae"] [uri "/xmlrpc.php"] [unique_id "amuBjZSUkh3e5AhEJOByNAAAAac"]
[Thu Jul 30 11:53:34.324482 2026] [security2:error] [pid 643573:tid 643728] [client 57.141.0.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuBjfxWyxgRnoFKAJ_3WQAAAiY"]
[Thu Jul 30 11:53:34.328878 2026] [security2:error] [pid 643573:tid 643727] [client 172.213.208.20:30425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/gmo.php"] [unique_id "amuBjvxWyxgRnoFKAJ_3XQAAAiU"]
[Thu Jul 30 11:53:35.062423 2026] [security2:error] [pid 643573:tid 643758] [client 34.86.95.193:58138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "skcarrental.ae"] [uri "/xmlrpc.php"] [unique_id "amuBjvxWyxgRnoFKAJ_3ZQAAAkQ"]
[Thu Jul 30 11:53:35.681298 2026] [core:notice] [pid 643573:tid 643828] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:35.685306 2026] [security2:error] [pid 643573:tid 643828] [client 103.215.74.26:43814] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "752"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBj_xWyxgRnoFKAJ_3bQAAAoo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:36.101512 2026] [security2:error] [pid 643573:tid 643820] [client 34.86.95.193:57134] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "skcarrental.ae"] [uri "/xmlrpc.php"] [unique_id "amuBkPxWyxgRnoFKAJ_3dgAAAoI"]
[Thu Jul 30 11:53:36.101618 2026] [security2:error] [pid 643573:tid 643820] [client 34.86.95.193:57134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "skcarrental.ae"] [uri "/xmlrpc.php"] [unique_id "amuBkPxWyxgRnoFKAJ_3dgAAAoI"]
[Thu Jul 30 11:53:36.198537 2026] [security2:error] [pid 643573:tid 643790] [client 68.221.186.136:44031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/main.php"] [unique_id "amuBkPxWyxgRnoFKAJ_3dwAAAmQ"]
[Thu Jul 30 11:53:36.445804 2026] [core:notice] [pid 643573:tid 643822] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:36.449774 2026] [security2:error] [pid 643573:tid 643822] [client 103.215.74.26:43824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBkPxWyxgRnoFKAJ_3egAAAoQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:37.034660 2026] [core:notice] [pid 643253:tid 643341] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:37.177336 2026] [core:notice] [pid 643573:tid 643742] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:37.181933 2026] [security2:error] [pid 643573:tid 643742] [client 103.215.74.26:43834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBkfxWyxgRnoFKAJ_3fwAAAjQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:37.262466 2026] [security2:error] [pid 642360:tid 642608] [client 172.213.208.20:16271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-content/languages/index.php"] [unique_id "amuBkZSUkh3e5AhEJOByTQAAAgU"]
[Thu Jul 30 11:53:37.296889 2026] [security2:error] [pid 643573:tid 643623] [remote 216.73.216.152:19096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuBkfxWyxgRnoFKAJ_3gAACWSo"]
[Thu Jul 30 11:53:37.901342 2026] [core:notice] [pid 642360:tid 642535] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:37.905213 2026] [security2:error] [pid 642360:tid 642535] [client 103.215.74.26:43850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBkZSUkh3e5AhEJOByVQAAAbw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:38.436562 2026] [security2:error] [pid 642360:tid 642528] [client 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuBkpSUkh3e5AhEJOByVgABtVw"]
[Thu Jul 30 11:53:38.653999 2026] [core:notice] [pid 643573:tid 643801] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:38.658003 2026] [security2:error] [pid 643573:tid 643801] [client 103.215.74.26:43858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBkvxWyxgRnoFKAJ_3hQAAAm8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:39.382227 2026] [core:notice] [pid 643573:tid 643812] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:39.389628 2026] [security2:error] [pid 643573:tid 643812] [client 103.215.74.26:43862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBk_xWyxgRnoFKAJ_3iwAAAno"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:40.107950 2026] [core:notice] [pid 643573:tid 643711] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:40.112783 2026] [security2:error] [pid 643573:tid 643711] [client 103.215.74.26:43866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBlPxWyxgRnoFKAJ_3kQAAAhU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:40.117374 2026] [security2:error] [pid 642360:tid 642590] [client 57.141.0.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuBk5SUkh3e5AhEJOByYgAAAfM"]
[Thu Jul 30 11:53:40.226309 2026] [security2:error] [pid 643573:tid 643757] [client 68.221.186.136:44509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-file.php"] [unique_id "amuBlPxWyxgRnoFKAJ_3kgAAAkM"]
[Thu Jul 30 11:53:40.827942 2026] [core:notice] [pid 643573:tid 643725] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:40.832763 2026] [security2:error] [pid 643573:tid 643725] [client 103.215.74.26:43870] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBlPxWyxgRnoFKAJ_3mgAAAiM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:40.861487 2026] [core:notice] [pid 643573:tid 643820] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:40.866337 2026] [core:notice] [pid 643573:tid 643791] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:41.531020 2026] [security2:error] [pid 642360:tid 642549] [client 172.213.208.20:19111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-the.php"] [unique_id "amuBlZSUkh3e5AhEJOBydwAAAco"]
[Thu Jul 30 11:53:41.558659 2026] [core:notice] [pid 643573:tid 643761] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:41.562792 2026] [security2:error] [pid 643573:tid 643761] [client 103.215.74.26:43880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBlfxWyxgRnoFKAJ_3ogAAAkc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:41.639999 2026] [security2:error] [pid 643573:tid 643638] [remote 216.73.216.152:19096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuBlfxWyxgRnoFKAJ_3pQAChjk"]
[Thu Jul 30 11:53:42.290704 2026] [core:notice] [pid 643573:tid 643777] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:42.296151 2026] [security2:error] [pid 643573:tid 643777] [client 103.215.74.26:43890] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBlvxWyxgRnoFKAJ_3rQAAAlc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:42.463300 2026] [security2:error] [pid 643573:tid 643796] [client 68.221.186.136:45700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-signin.php"] [unique_id "amuBlvxWyxgRnoFKAJ_3rgAAAmo"]
[Thu Jul 30 11:53:43.012714 2026] [core:notice] [pid 642360:tid 642548] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:43.017106 2026] [security2:error] [pid 642360:tid 642548] [client 103.215.74.26:18372] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBl5SUkh3e5AhEJOBygwAAAck"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:43.750989 2026] [core:notice] [pid 643573:tid 643783] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:43.755384 2026] [security2:error] [pid 643573:tid 643783] [client 103.215.74.26:18376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBl_xWyxgRnoFKAJ_3uwAAAl0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:43.879477 2026] [security2:error] [pid 643573:tid 643756] [client 176.241.66.87:59904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBl_xWyxgRnoFKAJ_3vQAAAkI"]
[Thu Jul 30 11:53:43.879631 2026] [security2:error] [pid 643573:tid 643756] [client 176.241.66.87:59904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBl_xWyxgRnoFKAJ_3vQAAAkI"]
[Thu Jul 30 11:53:43.935048 2026] [autoindex:error] [pid 643573:tid 643738] [client 66.249.74.34:0] AH01276: Cannot serve directory /home2/tfyudite/inmobiliariadia.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:53:44.485269 2026] [core:notice] [pid 643573:tid 643757] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:44.489455 2026] [security2:error] [pid 643573:tid 643757] [client 103.215.74.26:18380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBmPxWyxgRnoFKAJ_3xgAAAkM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:44.995405 2026] [security2:error] [pid 643573:tid 643674] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "shiftofy.it.com"] [uri "/"] [unique_id "amuBmPxWyxgRnoFKAJ_3zQACNl0"]
[Thu Jul 30 11:53:45.211117 2026] [core:notice] [pid 643573:tid 643820] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:45.215954 2026] [security2:error] [pid 643573:tid 643820] [client 103.215.74.26:18394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBmfxWyxgRnoFKAJ_30AAAAoI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:45.412191 2026] [security2:error] [pid 642360:tid 642569] [client 68.221.186.136:45183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/simi.php"] [unique_id "amuBmZSUkh3e5AhEJOBymwAAAd4"]
[Thu Jul 30 11:53:45.933218 2026] [core:notice] [pid 643573:tid 643831] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:45.937306 2026] [security2:error] [pid 643573:tid 643831] [client 103.215.74.26:18408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBmfxWyxgRnoFKAJ_31AAAAo0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:45.974299 2026] [security2:error] [pid 643253:tid 643436] [client 68.221.186.136:43972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-conf.php"] [unique_id "amuBmcjqbtjBYzqM1uYmtwAAADQ"]
[Thu Jul 30 11:53:46.337734 2026] [security2:error] [pid 643573:tid 643825] [client 172.213.208.20:52357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/404.php"] [unique_id "amuBmvxWyxgRnoFKAJ_31QAAAoc"]
[Thu Jul 30 11:53:46.658394 2026] [core:notice] [pid 642360:tid 642601] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:46.899236 2026] [security2:error] [pid 643573:tid 643745] [client 68.221.186.136:42527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/WZGHHra0r3.php"] [unique_id "amuBmvxWyxgRnoFKAJ_32gAAAjc"]
[Thu Jul 30 11:53:47.190372 2026] [security2:error] [pid 643573:tid 643829] [client 172.213.208.20:52400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/init.php"] [unique_id "amuBm_xWyxgRnoFKAJ_33QAAAos"]
[Thu Jul 30 11:53:47.521327 2026] [security2:error] [pid 643573:tid 643723] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "shiftofy.it.com"] [uri "/"] [unique_id "amuBm_xWyxgRnoFKAJ_34AAAAiE"]
[Thu Jul 30 11:53:47.740836 2026] [security2:error] [pid 643573:tid 643741] [client 209.126.2.173:53137] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "shop-mevius.com"] [uri "/"] [unique_id "amuBm_xWyxgRnoFKAJ_35AAAAjM"]
[Thu Jul 30 11:53:48.036998 2026] [security2:error] [pid 643573:tid 643837] [client 172.213.208.20:25040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/file5.php"] [unique_id "amuBnPxWyxgRnoFKAJ_35gAAApM"]
[Thu Jul 30 11:53:48.713872 2026] [security2:error] [pid 642360:tid 642510] [client 172.237.109.114:5627] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBnJSUkh3e5AhEJOByuAAAAaM"]
[Thu Jul 30 11:53:48.727008 2026] [security2:error] [pid 642360:tid 642490] [client 172.237.109.114:55962] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBnJSUkh3e5AhEJOBytQAAAY8"]
[Thu Jul 30 11:53:48.733237 2026] [security2:error] [pid 642360:tid 642562] [client 172.237.109.114:58264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBnJSUkh3e5AhEJOBytgAAAdc"]
[Thu Jul 30 11:53:48.763252 2026] [security2:error] [pid 642360:tid 642590] [client 172.237.109.114:10513] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBnJSUkh3e5AhEJOBytwAAAfM"]
[Thu Jul 30 11:53:48.773044 2026] [security2:error] [pid 643573:tid 643809] [client 172.237.109.114:57220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBnPxWyxgRnoFKAJ_35wAAAnc"]
[Thu Jul 30 11:53:49.081517 2026] [security2:error] [pid 643573:tid 643743] [client 172.213.208.20:26047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amuBnfxWyxgRnoFKAJ_37QAAAjU"]
[Thu Jul 30 11:53:49.652358 2026] [security2:error] [pid 643573:tid 643773] [client 68.221.186.136:45166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/bala.php"] [unique_id "amuBnfxWyxgRnoFKAJ_38AAAAlM"]
[Thu Jul 30 11:53:49.804173 2026] [security2:error] [pid 643573:tid 643759] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "kinyeraagro.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "amuBnfxWyxgRnoFKAJ_38QAAAkU"]
[Thu Jul 30 11:53:49.809851 2026] [security2:error] [pid 642360:tid 642576] [client 209.126.2.173:51002] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "shop-mevius.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "amuBnZSUkh3e5AhEJOByxAAAAeU"]
[Thu Jul 30 11:53:50.913818 2026] [security2:error] [pid 643573:tid 643754] [client 68.221.186.136:42548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/bk.php"] [unique_id "amuBnvxWyxgRnoFKAJ_3-QAAAkA"]
[Thu Jul 30 11:53:51.231268 2026] [security2:error] [pid 642360:tid 642557] [client 209.126.2.173:53245] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "shop-mevius.com"] [uri "/media/system/js/core.js"] [unique_id "amuBn5SUkh3e5AhEJOBy1AAAAdI"]
[Thu Jul 30 11:53:51.520799 2026] [security2:error] [pid 642360:tid 642592] [client 68.221.186.136:45552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/ahax.php"] [unique_id "amuBn5SUkh3e5AhEJOBy3gAAAfU"]
[Thu Jul 30 11:53:51.661912 2026] [core:notice] [pid 642360:tid 642586] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:51.666488 2026] [security2:error] [pid 642360:tid 642586] [client 103.215.74.26:18412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBn5SUkh3e5AhEJOBy3wAAAe8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:52.135074 2026] [security2:error] [pid 643573:tid 643744] [client 74.7.230.23:33326] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.qse.gzj.temporary.site"] [uri "/robots.txt"] [unique_id "amuBoPxWyxgRnoFKAJ_4DgAAAjY"]
[Thu Jul 30 11:53:52.383703 2026] [core:notice] [pid 643573:tid 643820] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:52.387792 2026] [security2:error] [pid 643573:tid 643820] [client 103.215.74.26:18424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "746"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBoPxWyxgRnoFKAJ_4EAAAAoI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:52.612693 2026] [security2:error] [pid 643573:tid 643731] [client 95.86.50.135:29725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.50.86.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuBoPxWyxgRnoFKAJ_4DwAAAik"]
[Thu Jul 30 11:53:52.612899 2026] [security2:error] [pid 643573:tid 643731] [client 95.86.50.135:29725] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuBoPxWyxgRnoFKAJ_4DwAAAik"]
[Thu Jul 30 11:53:53.000798 2026] [core:error] [pid 643253:tid 643463] [client 74.7.241.141:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:53:53.000818 2026] [core:error] [pid 643253:tid 643463] [client 74.7.241.141:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:53:53.000910 2026] [security2:error] [pid 643253:tid 643463] [client 74.7.241.141:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.akth.com.pk"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amuBoMjqbtjBYzqM1uYmwgAAAE8"]
[Thu Jul 30 11:53:53.001468 2026] [security2:error] [pid 643573:tid 643752] [client 74.7.241.141:41712] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.akth.com.pk"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuBoPxWyxgRnoFKAJ_4EwACPks"]
[Thu Jul 30 11:53:53.110974 2026] [core:notice] [pid 643253:tid 643494] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:53.115406 2026] [security2:error] [pid 643253:tid 643494] [client 103.215.74.26:49110] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBocjqbtjBYzqM1uYmxQAAAG4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:53.813617 2026] [core:notice] [pid 643573:tid 643825] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:53.824730 2026] [core:notice] [pid 643573:tid 643735] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:53.830754 2026] [security2:error] [pid 643573:tid 643735] [client 103.215.74.26:49116] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBofxWyxgRnoFKAJ_4GAAAAi0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:53.943753 2026] [core:notice] [pid 643253:tid 643344] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:53.949226 2026] [security2:error] [pid 643253:tid 643445] [client 47.128.96.122:36396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/2656"] [unique_id "amuBocjqbtjBYzqM1uYmyAAAPVk"]
[Thu Jul 30 11:53:54.188691 2026] [security2:error] [pid 643253:tid 643392] [client 185.191.171.10:40474] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cal-sync.co"] [uri "/robots.txt"] [unique_id "amuBosjqbtjBYzqM1uYmyQAAAAg"]
[Thu Jul 30 11:53:54.188805 2026] [security2:error] [pid 643253:tid 643392] [client 185.191.171.10:40474] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cal-sync.co"] [uri "/robots.txt"] [unique_id "amuBosjqbtjBYzqM1uYmyQAAAAg"]
[Thu Jul 30 11:53:54.222429 2026] [core:notice] [pid 642360:tid 642426] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:54.340147 2026] [core:notice] [pid 642360:tid 642402] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:54.340203 2026] [core:notice] [pid 642360:tid 642396] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:54.549618 2026] [core:notice] [pid 642360:tid 642490] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:54.556033 2026] [security2:error] [pid 642360:tid 642490] [client 103.215.74.26:49122] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBopSUkh3e5AhEJOBzAAAAAY8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:54.558042 2026] [security2:error] [pid 643573:tid 643789] [client 176.241.66.87:60464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBovxWyxgRnoFKAJ_4HgAAAmM"]
[Thu Jul 30 11:53:54.558159 2026] [security2:error] [pid 643573:tid 643789] [client 176.241.66.87:60464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBovxWyxgRnoFKAJ_4HgAAAmM"]
[Thu Jul 30 11:53:55.092083 2026] [security2:error] [pid 642360:tid 642567] [client 85.208.96.210:54148] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cal-sync.co"] [uri "/"] [unique_id "amuBo5SUkh3e5AhEJOBzDAAAAdw"]
[Thu Jul 30 11:53:55.092186 2026] [security2:error] [pid 642360:tid 642567] [client 85.208.96.210:54148] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cal-sync.co"] [uri "/"] [unique_id "amuBo5SUkh3e5AhEJOBzDAAAAdw"]
[Thu Jul 30 11:53:55.266629 2026] [security2:error] [pid 643573:tid 643794] [client 172.213.208.20:19083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/shell.php"] [unique_id "amuBo_xWyxgRnoFKAJ_4IwAAAmg"]
[Thu Jul 30 11:53:55.301614 2026] [core:notice] [pid 643573:tid 643759] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:55.305788 2026] [security2:error] [pid 643573:tid 643759] [client 103.215.74.26:49126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBo_xWyxgRnoFKAJ_4JAAAAkU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:55.517434 2026] [core:notice] [pid 643573:tid 643766] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:56.675311 2026] [security2:error] [pid 643573:tid 643813] [client 172.116.43.68:34369] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuBpPxWyxgRnoFKAJ_4LQAAAns"], referer: http://pkf.jo
[Thu Jul 30 11:53:56.729041 2026] [security2:error] [pid 642360:tid 642523] [client 14.171.253.47:58720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuBpJSUkh3e5AhEJOBzFgAAAbA"], referer: http://pkf.jo
[Thu Jul 30 11:53:56.786325 2026] [security2:error] [pid 642360:tid 642609] [client 172.213.208.20:28798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/f35.php"] [unique_id "amuBpJSUkh3e5AhEJOBzIQAAAgY"]
[Thu Jul 30 11:53:57.494727 2026] [security2:error] [pid 643573:tid 643741] [client 172.213.208.20:19100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/new.php"] [unique_id "amuBpfxWyxgRnoFKAJ_4NAAAAjM"]
[Thu Jul 30 11:53:58.264765 2026] [security2:error] [pid 643573:tid 643824] [client 172.213.208.20:37203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/adminfuns.php"] [unique_id "amuBpvxWyxgRnoFKAJ_4OgAAAoY"]
[Thu Jul 30 11:53:58.339004 2026] [security2:error] [pid 642360:tid 642569] [client 189.203.39.144:19014] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuBppSUkh3e5AhEJOBzKgAAAd4"], referer: http://pkf.jo
[Thu Jul 30 11:54:00.747297 2026] [core:notice] [pid 643573:tid 643711] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:01.027093 2026] [core:notice] [pid 642360:tid 642602] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:01.031134 2026] [security2:error] [pid 642360:tid 642602] [client 103.215.74.26:49134] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "765"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBqZSUkh3e5AhEJOBzSQAAAf8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:01.253090 2026] [security2:error] [pid 642360:tid 642495] [client 57.141.0.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuBqJSUkh3e5AhEJOBzQgAAAZQ"]
[Thu Jul 30 11:54:01.769298 2026] [core:notice] [pid 643573:tid 643744] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:01.776201 2026] [security2:error] [pid 643573:tid 643744] [client 103.215.74.26:49146] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBqfxWyxgRnoFKAJ_4WwAAAjY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:01.795177 2026] [autoindex:error] [pid 642360:tid 642615] [client 43.131.253.14:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_d836eabf/wp-content/uploads/2026/07/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:54:01.816207 2026] [security2:error] [pid 643573:tid 643767] [client 85.208.96.195:47280] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "carnetdeshopping.com"] [uri "/robots.txt"] [unique_id "amuBqfxWyxgRnoFKAJ_4XQAAAk0"]
[Thu Jul 30 11:54:01.816321 2026] [security2:error] [pid 643573:tid 643767] [client 85.208.96.195:47280] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "carnetdeshopping.com"] [uri "/robots.txt"] [unique_id "amuBqfxWyxgRnoFKAJ_4XQAAAk0"]
[Thu Jul 30 11:54:02.240741 2026] [security2:error] [pid 643573:tid 643751] [client 57.141.0.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuBqfxWyxgRnoFKAJ_4WAAAAj0"]
[Thu Jul 30 11:54:02.493553 2026] [core:notice] [pid 643573:tid 643824] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:02.497507 2026] [security2:error] [pid 643573:tid 643824] [client 103.215.74.26:49158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "778"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBqvxWyxgRnoFKAJ_4ZQAAAoY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:02.926411 2026] [security2:error] [pid 643253:tid 643412] [client 185.191.171.15:15688] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "carnetdeshopping.com"] [uri "/index.php/about/"] [unique_id "amuBqsjqbtjBYzqM1uYm1gAAABw"]
[Thu Jul 30 11:54:02.926537 2026] [security2:error] [pid 643253:tid 643412] [client 185.191.171.15:15688] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "carnetdeshopping.com"] [uri "/index.php/about/"] [unique_id "amuBqsjqbtjBYzqM1uYm1gAAABw"]
[Thu Jul 30 11:54:03.252047 2026] [core:notice] [pid 643573:tid 643804] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:03.256023 2026] [security2:error] [pid 643573:tid 643804] [client 103.215.74.26:11580] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBq_xWyxgRnoFKAJ_4bgAAAnI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:03.543845 2026] [security2:error] [pid 643573:tid 643802] [client 185.191.171.1:10666] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cal-sync.co"] [uri "/sitemap.xml"] [unique_id "amuBq_xWyxgRnoFKAJ_4dAAAAnA"]
[Thu Jul 30 11:54:03.543943 2026] [security2:error] [pid 643573:tid 643802] [client 185.191.171.1:10666] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cal-sync.co"] [uri "/sitemap.xml"] [unique_id "amuBq_xWyxgRnoFKAJ_4dAAAAnA"]
[Thu Jul 30 11:54:03.992207 2026] [core:notice] [pid 643573:tid 643774] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:03.996449 2026] [security2:error] [pid 643573:tid 643774] [client 103.215.74.26:11582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBq_xWyxgRnoFKAJ_4dwAAAlQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:04.127701 2026] [security2:error] [pid 642360:tid 642579] [client 34.53.152.12:54882] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vzz.udi.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuBrJSUkh3e5AhEJOBzYgAAAeg"]
[Thu Jul 30 11:54:04.737043 2026] [core:notice] [pid 642360:tid 642500] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:04.740947 2026] [security2:error] [pid 642360:tid 642500] [client 103.215.74.26:11598] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "738"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBrJSUkh3e5AhEJOBzZQAAAZk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:05.092332 2026] [security2:error] [pid 643573:tid 643779] [client 172.213.208.20:37200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/fm.php"] [unique_id "amuBrfxWyxgRnoFKAJ_4hAAAAlk"]
[Thu Jul 30 11:54:05.118364 2026] [security2:error] [pid 642360:tid 642591] [client 176.241.66.87:61022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBrZSUkh3e5AhEJOBzaQAAAfQ"]
[Thu Jul 30 11:54:05.118484 2026] [security2:error] [pid 642360:tid 642591] [client 176.241.66.87:61022] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBrZSUkh3e5AhEJOBzaQAAAfQ"]
[Thu Jul 30 11:54:05.274465 2026] [core:notice] [pid 642360:tid 642447] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:05.485505 2026] [core:notice] [pid 643573:tid 643717] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:05.488251 2026] [proxy:error] [pid 643573:tid 643788] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:54:05.488354 2026] [proxy_http:error] [pid 643573:tid 643788] [client 74.7.241.155:59574] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:54:05.489023 2026] [proxy:error] [pid 643573:tid 643788] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:54:05.489072 2026] [proxy_http:error] [pid 643573:tid 643788] [client 74.7.241.155:59574] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:54:05.489203 2026] [security2:error] [pid 643573:tid 643788] [client 74.7.241.155:59574] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "cpcalendars.dqy.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuBrfxWyxgRnoFKAJ_4iAAAAmI"]
[Thu Jul 30 11:54:05.489437 2026] [security2:error] [pid 643573:tid 643717] [client 103.215.74.26:11612] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "740"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBrfxWyxgRnoFKAJ_4hwAAAhs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:06.218459 2026] [core:notice] [pid 642360:tid 642517] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:06.222442 2026] [security2:error] [pid 642360:tid 642517] [client 103.215.74.26:11620] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "732"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBrpSUkh3e5AhEJOBzcwAAAao"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:06.963376 2026] [core:notice] [pid 642360:tid 642574] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:06.968075 2026] [security2:error] [pid 642360:tid 642574] [client 103.215.74.26:11630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "740"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBrpSUkh3e5AhEJOBzfQAAAeM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:07.268259 2026] [security2:error] [pid 643573:tid 643712] [client 57.141.0.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuBrvxWyxgRnoFKAJ_4lwAAAhY"]
[Thu Jul 30 11:54:07.284241 2026] [core:notice] [pid 642360:tid 642509] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:07.616531 2026] [security2:error] [pid 643573:tid 643719] [client 34.53.152.12:58461] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vzz.udi.temporary.site"] [uri "/index.php"] [unique_id "amuBr_xWyxgRnoFKAJ_4pgAAAh0"]
[Thu Jul 30 11:54:07.697634 2026] [core:notice] [pid 643573:tid 643742] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:07.701742 2026] [security2:error] [pid 643573:tid 643742] [client 103.215.74.26:11640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBr_xWyxgRnoFKAJ_4qAAAAjQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:08.111548 2026] [security2:error] [pid 643573:tid 643734] [client 34.53.152.12:58461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vzz.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuBr_xWyxgRnoFKAJ_4qwAAAiw"]
[Thu Jul 30 11:54:08.139336 2026] [security2:error] [pid 643573:tid 643722] [client 66.249.66.73:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.lalibanista.com"] [uri "/index.php"] [unique_id "amuBrvxWyxgRnoFKAJ_4ngACIFY"]
[Thu Jul 30 11:54:08.259094 2026] [security2:error] [pid 643573:tid 643727] [client 172.213.208.20:45951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/file.php"] [unique_id "amuBsPxWyxgRnoFKAJ_4sAAAAiU"]
[Thu Jul 30 11:54:08.423923 2026] [core:notice] [pid 643573:tid 643788] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:08.427957 2026] [security2:error] [pid 643573:tid 643788] [client 103.215.74.26:11644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBsPxWyxgRnoFKAJ_4sQAAAmI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:09.011922 2026] [security2:error] [pid 643573:tid 643835] [client 34.53.152.12:62699] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vzz.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuBsPxWyxgRnoFKAJ_4tAAAApE"]
[Thu Jul 30 11:54:09.158711 2026] [core:notice] [pid 642360:tid 642546] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:09.163078 2026] [security2:error] [pid 642360:tid 642546] [client 103.215.74.26:11654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBsZSUkh3e5AhEJOBzlwAAAcc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:09.740260 2026] [security2:error] [pid 642360:tid 642530] [client 34.53.152.12:51772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vzz.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuBsZSUkh3e5AhEJOBzmQAAAbc"]
[Thu Jul 30 11:54:09.781641 2026] [security2:error] [pid 642360:tid 642456] [remote 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuBsZSUkh3e5AhEJOBzngABp18"]
[Thu Jul 30 11:54:09.781823 2026] [security2:error] [pid 642360:tid 642514] [client 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuBsZSUkh3e5AhEJOBzngABp18"]
[Thu Jul 30 11:54:09.903343 2026] [core:notice] [pid 643573:tid 643736] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:09.907387 2026] [security2:error] [pid 643573:tid 643736] [client 103.215.74.26:11664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBsfxWyxgRnoFKAJ_4vAAAAi4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:10.445222 2026] [security2:error] [pid 643253:tid 643355] [remote 157.55.39.195:53262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.39.55.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/blogs/likejapan%E6%9C%83%E5%93%A1%E5%84%AA%E6%83%A0%E5%90%88%E9%9B%86-%E9%81%8A%E6%97%A5%E5%84%AA%E6%83%A0%E5%8A%B5/article.php"] [unique_id "amuBssjqbtjBYzqM1uYm3AAAFmQ"]
[Thu Jul 30 11:54:10.521880 2026] [security2:error] [pid 642360:tid 642565] [client 34.53.152.12:59165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vzz.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuBspSUkh3e5AhEJOBzoQAAAdo"]
[Thu Jul 30 11:54:10.621816 2026] [core:notice] [pid 643253:tid 643424] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:10.625995 2026] [security2:error] [pid 643253:tid 643424] [client 103.215.74.26:11670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBssjqbtjBYzqM1uYm3QAAACg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:11.227661 2026] [security2:error] [pid 643573:tid 643782] [client 34.53.152.12:60043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vzz.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuBs_xWyxgRnoFKAJ_4xQAAAlw"]
[Thu Jul 30 11:54:11.359838 2026] [core:notice] [pid 643573:tid 643837] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:11.364756 2026] [security2:error] [pid 643573:tid 643837] [client 103.215.74.26:11676] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBs_xWyxgRnoFKAJ_4zQAAApM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:11.772087 2026] [security2:error] [pid 643573:tid 643717] [client 62.102.148.185:57250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuBs_xWyxgRnoFKAJ_41QAAAhs"]
[Thu Jul 30 11:54:11.772173 2026] [security2:error] [pid 643573:tid 643717] [client 62.102.148.185:57250] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuBs_xWyxgRnoFKAJ_41QAAAhs"]
[Thu Jul 30 11:54:11.787213 2026] [security2:error] [pid 643573:tid 643683] [remote 57.141.0.31:25082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuBs_xWyxgRnoFKAJ_41gACUWY"]
[Thu Jul 30 11:54:12.097407 2026] [core:notice] [pid 643573:tid 643758] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:12.101920 2026] [security2:error] [pid 643573:tid 643758] [client 103.215.74.26:11686] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBtPxWyxgRnoFKAJ_42gAAAkQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:12.144891 2026] [security2:error] [pid 643573:tid 643710] [client 34.53.152.12:59087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vzz.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuBs_xWyxgRnoFKAJ_42QAAAhQ"]
[Thu Jul 30 11:54:12.842057 2026] [core:notice] [pid 643573:tid 643720] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:12.846783 2026] [security2:error] [pid 643573:tid 643720] [client 103.215.74.26:11696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBtPxWyxgRnoFKAJ_44AAAAh4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:12.958249 2026] [security2:error] [pid 642360:tid 642499] [client 34.53.152.12:58899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vzz.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuBtJSUkh3e5AhEJOBzsgAAAZg"]
[Thu Jul 30 11:54:13.571772 2026] [core:notice] [pid 643573:tid 643830] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:13.576214 2026] [security2:error] [pid 643573:tid 643830] [client 103.215.74.26:46668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBtfxWyxgRnoFKAJ_45wAAAow"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:13.688850 2026] [security2:error] [pid 643573:tid 643781] [client 34.53.152.12:61718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vzz.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuBtfxWyxgRnoFKAJ_45QAAAls"]
[Thu Jul 30 11:54:13.762604 2026] [security2:error] [pid 643573:tid 643752] [client 52.28.162.93:62498] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuBtfxWyxgRnoFKAJ_46AAAAj4"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 11:54:14.164409 2026] [core:notice] [pid 643573:tid 643799] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:14.168794 2026] [security2:error] [pid 643573:tid 643799] [client 52.28.162.93:62512] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBtvxWyxgRnoFKAJ_47gAAAm0"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 11:54:14.289380 2026] [core:notice] [pid 643573:tid 643760] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:14.296762 2026] [security2:error] [pid 643573:tid 643760] [client 103.215.74.26:46670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBtvxWyxgRnoFKAJ_48AAAAkY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:14.331160 2026] [security2:error] [pid 642360:tid 642570] [client 2a03:2880:f800:1:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBtZSUkh3e5AhEJOBzvAAB3xs"]
[Thu Jul 30 11:54:14.400628 2026] [security2:error] [pid 643573:tid 643796] [client 34.53.152.12:59547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vzz.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuBtvxWyxgRnoFKAJ_47wAAAmo"]
[Thu Jul 30 11:54:14.606725 2026] [security2:error] [pid 643573:tid 643727] [client 52.28.162.93:62518] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuBtvxWyxgRnoFKAJ_48gAAAiU"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 11:54:15.039675 2026] [core:notice] [pid 643573:tid 643821] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:15.044103 2026] [security2:error] [pid 643573:tid 643821] [client 103.215.74.26:46686] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBt_xWyxgRnoFKAJ_48wAAAoM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:15.135120 2026] [security2:error] [pid 642360:tid 642611] [client 34.53.152.12:57114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vzz.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuBtpSUkh3e5AhEJOBzyQAAAgg"]
[Thu Jul 30 11:54:15.774790 2026] [core:notice] [pid 643573:tid 643773] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:15.779108 2026] [security2:error] [pid 643573:tid 643773] [client 103.215.74.26:46698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBt_xWyxgRnoFKAJ_4-wAAAlM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:15.872065 2026] [security2:error] [pid 643573:tid 643835] [client 176.241.66.87:27021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBt_xWyxgRnoFKAJ_4_QAAApE"]
[Thu Jul 30 11:54:15.872196 2026] [security2:error] [pid 643573:tid 643835] [client 176.241.66.87:27021] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBt_xWyxgRnoFKAJ_4_QAAApE"]
[Thu Jul 30 11:54:15.970621 2026] [core:notice] [pid 643573:tid 643828] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:16.047207 2026] [security2:error] [pid 643573:tid 643724] [client 34.53.152.12:58187] ModSecurity: Warning. Operator GE matched 2 at IP:dos_burst_counter. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "99"] [id "350114"] [rev "1"] [msg "Atomicorp.com WAF Rules: Potential Denial of Service (DoS) Attack from - # of Request Bursts: 2"] [severity "ERROR"] [tag "no_ar"] [hostname "vzz.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuBt_xWyxgRnoFKAJ_4_AAAAiI"]
[Thu Jul 30 11:54:16.047244 2026] [security2:error] [pid 643573:tid 643724] [client 34.53.152.12:58187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vzz.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuBt_xWyxgRnoFKAJ_4_AAAAiI"]
[Thu Jul 30 11:54:16.193133 2026] [security2:error] [pid 643573:tid 643808] [client 74.7.175.150:38764] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.pwy.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amuBuPxWyxgRnoFKAJ_5AwAAAnY"]
[Thu Jul 30 11:54:16.515255 2026] [core:notice] [pid 643573:tid 643814] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:16.519663 2026] [security2:error] [pid 643573:tid 643814] [client 103.215.74.26:46714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBuPxWyxgRnoFKAJ_5BgAAAnw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:16.561260 2026] [security2:error] [pid 642360:tid 642562] [client 34.53.152.12:52830] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "vzz.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuBuJSUkh3e5AhEJOBz1QAAAdc"]
[Thu Jul 30 11:54:16.561377 2026] [security2:error] [pid 642360:tid 642562] [client 34.53.152.12:52830] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "vzz.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuBuJSUkh3e5AhEJOBz1QAAAdc"]
[Thu Jul 30 11:54:17.244231 2026] [core:notice] [pid 643573:tid 643752] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:17.248755 2026] [security2:error] [pid 643573:tid 643752] [client 103.215.74.26:46726] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBufxWyxgRnoFKAJ_5CgAAAj4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:17.461851 2026] [security2:error] [pid 642360:tid 642535] [client 74.7.175.177:54296] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-87175f7b.bkv.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuBtpSUkh3e5AhEJOBzxAABvBk"]
[Thu Jul 30 11:54:17.974796 2026] [core:notice] [pid 643573:tid 643746] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:17.978972 2026] [security2:error] [pid 643573:tid 643746] [client 103.215.74.26:46730] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBufxWyxgRnoFKAJ_5DwAAAjg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:18.701887 2026] [core:notice] [pid 643573:tid 643816] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:18.705885 2026] [security2:error] [pid 643573:tid 643816] [client 103.215.74.26:46746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "741"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBuvxWyxgRnoFKAJ_5FAAAAn4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:18.997052 2026] [security2:error] [pid 642360:tid 642565] [client 178.20.47.39:64659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.47.20.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/email-now.php"] [unique_id "amuBupSUkh3e5AhEJOBz7AAAAdo"], referer: http://arabiandubaisafari.com/contact.html
[Thu Jul 30 11:54:19.169477 2026] [core:error] [pid 643573:tid 643744] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:54:19.169498 2026] [core:error] [pid 643573:tid 643744] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:54:19.174879 2026] [core:error] [pid 643573:tid 643754] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:54:19.174895 2026] [core:error] [pid 643573:tid 643754] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:54:19.185640 2026] [core:error] [pid 642360:tid 642603] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:54:19.185657 2026] [core:error] [pid 642360:tid 642603] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:54:19.186076 2026] [core:error] [pid 643573:tid 643750] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:54:19.186090 2026] [core:error] [pid 643573:tid 643750] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:54:19.187615 2026] [core:error] [pid 642360:tid 642612] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:54:19.187630 2026] [core:error] [pid 642360:tid 642612] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:54:19.277626 2026] [core:notice] [pid 642360:tid 642372] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:19.417888 2026] [core:notice] [pid 643573:tid 643833] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:19.422675 2026] [security2:error] [pid 643573:tid 643833] [client 103.215.74.26:46756] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "738"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBu_xWyxgRnoFKAJ_5MgAAAo8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:20.145768 2026] [core:notice] [pid 643573:tid 643760] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:20.150065 2026] [security2:error] [pid 643573:tid 643760] [client 103.215.74.26:46768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBvPxWyxgRnoFKAJ_5OgAAAkY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:20.825574 2026] [security2:error] [pid 643573:tid 643836] [client 198.54.128.138:59462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuBvPxWyxgRnoFKAJ_5PgAAApI"]
[Thu Jul 30 11:54:20.825683 2026] [security2:error] [pid 643573:tid 643836] [client 198.54.128.138:59462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuBvPxWyxgRnoFKAJ_5PgAAApI"]
[Thu Jul 30 11:54:20.851765 2026] [security2:error] [pid 643573:tid 643746] [client 172.213.208.20:45927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/bolt.php"] [unique_id "amuBvPxWyxgRnoFKAJ_5PwAAAjg"]
[Thu Jul 30 11:54:20.868333 2026] [core:notice] [pid 642360:tid 642540] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:20.874563 2026] [security2:error] [pid 642360:tid 642540] [client 103.215.74.26:46778] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBvJSUkh3e5AhEJOB0AgAAAcE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:21.598356 2026] [core:notice] [pid 643573:tid 643811] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:21.605240 2026] [security2:error] [pid 643573:tid 643811] [client 103.215.74.26:46786] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBvfxWyxgRnoFKAJ_5RgAAAnk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:21.820691 2026] [security2:error] [pid 643573:tid 643794] [client 172.213.208.20:27989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/3.php"] [unique_id "amuBvfxWyxgRnoFKAJ_5SAAAAmg"]
[Thu Jul 30 11:54:21.878418 2026] [security2:error] [pid 643573:tid 643622] [remote 57.141.0.30:33146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/JSTE/announcement"] [unique_id "amuBvfxWyxgRnoFKAJ_5TAACISk"]
[Thu Jul 30 11:54:22.339482 2026] [core:notice] [pid 642360:tid 642611] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:22.343327 2026] [security2:error] [pid 642360:tid 642611] [client 103.215.74.26:46794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBvpSUkh3e5AhEJOB0EAAAAgg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:22.673509 2026] [security2:error] [pid 643573:tid 643754] [client 66.249.73.100:47155] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuBvvxWyxgRnoFKAJ_5UgAAAkA"]
[Thu Jul 30 11:54:23.068654 2026] [core:notice] [pid 642360:tid 642494] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:23.072513 2026] [security2:error] [pid 642360:tid 642494] [client 103.215.74.26:28442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "757"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBv5SUkh3e5AhEJOB0FwAAAZM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:23.193375 2026] [security2:error] [pid 642360:tid 642552] [client 74.7.244.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.fud.udi.temporary.site"] [uri "/index.php"] [unique_id "amuBu5SUkh3e5AhEJOBz7gAAAc0"]
[Thu Jul 30 11:54:23.194461 2026] [security2:error] [pid 643573:tid 643726] [client 74.7.244.63:47406] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.fud.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amuBu_xWyxgRnoFKAJ_5HAACJGk"]
[Thu Jul 30 11:54:23.248060 2026] [security2:error] [pid 643573:tid 643715] [client 94.154.43.184:36768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "shop-mevius.com"] [uri "/.env"] [unique_id "amuBv_xWyxgRnoFKAJ_5XwAAAhk"]
[Thu Jul 30 11:54:23.819056 2026] [core:notice] [pid 643573:tid 643809] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:23.825558 2026] [security2:error] [pid 643573:tid 643809] [client 103.215.74.26:28444] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBv_xWyxgRnoFKAJ_5YwAAAnc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:23.846689 2026] [security2:error] [pid 642360:tid 642616] [client 66.249.73.96:37592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuBv5SUkh3e5AhEJOB0GwAAAg0"]
[Thu Jul 30 11:54:23.987927 2026] [security2:error] [pid 643573:tid 643804] [client 74.7.175.190:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.fyi.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuBvvxWyxgRnoFKAJ_5VwAAAnI"]
[Thu Jul 30 11:54:23.988850 2026] [security2:error] [pid 642360:tid 642604] [client 74.7.175.190:54454] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.fyi.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuBvpSUkh3e5AhEJOB0FQACAUU"]
[Thu Jul 30 11:54:24.391445 2026] [security2:error] [pid 643573:tid 643606] [remote 47.128.27.88:22538] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/shop/"] [unique_id "amuBwPxWyxgRnoFKAJ_5awACRBk"]
[Thu Jul 30 11:54:24.407269 2026] [security2:error] [pid 642360:tid 642506] [client 172.213.208.20:45911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/222.php"] [unique_id "amuBwJSUkh3e5AhEJOB0JQAAAZ8"]
[Thu Jul 30 11:54:24.556373 2026] [core:notice] [pid 642360:tid 642535] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:24.560192 2026] [security2:error] [pid 642360:tid 642535] [client 103.215.74.26:28454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "770"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBwJSUkh3e5AhEJOB0JgAAAbw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:24.625758 2026] [core:notice] [pid 643573:tid 643693] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:24.940296 2026] [security2:error] [pid 643573:tid 643700] [remote 74.7.241.60:58672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/img/login.php"] [unique_id "amuBwPxWyxgRnoFKAJ_5dAACbnc"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/img/main_image_6a2a8e70efd49.jpg
[Thu Jul 30 11:54:25.297837 2026] [core:notice] [pid 643573:tid 643808] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:25.301858 2026] [security2:error] [pid 643573:tid 643808] [client 103.215.74.26:28458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "740"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBwfxWyxgRnoFKAJ_5egAAAnY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:25.680873 2026] [security2:error] [pid 642360:tid 642515] [client 74.7.241.130:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.fdd.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuBwJSUkh3e5AhEJOB0IQAAAag"]
[Thu Jul 30 11:54:25.681901 2026] [security2:error] [pid 643573:tid 643761] [client 74.7.241.130:50492] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.fdd.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuBwPxWyxgRnoFKAJ_5aQACR24"]
[Thu Jul 30 11:54:26.037212 2026] [security2:error] [pid 643573:tid 643696] [remote 40.77.167.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/jipkl/article/download/209/204/406"] [unique_id "amuBwvxWyxgRnoFKAJ_5gAACXHM"]
[Thu Jul 30 11:54:26.376877 2026] [security2:error] [pid 643573:tid 643828] [client 176.241.66.87:27661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBwvxWyxgRnoFKAJ_5hAAAAoo"]
[Thu Jul 30 11:54:26.377034 2026] [security2:error] [pid 643573:tid 643828] [client 176.241.66.87:27661] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBwvxWyxgRnoFKAJ_5hAAAAoo"]
[Thu Jul 30 11:54:26.624825 2026] [security2:error] [pid 643573:tid 643731] [client 2a03:2880:f800:b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBwvxWyxgRnoFKAJ_5fwACKQ4"]
[Thu Jul 30 11:54:27.682784 2026] [security2:error] [pid 643573:tid 643807] [client 74.7.230.57:37088] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-300f3810.ahk.tqa.temporary.site"] [uri "/index.php"] [unique_id "amuBw_xWyxgRnoFKAJ_5jwACdSM"]
[Thu Jul 30 11:54:28.607440 2026] [security2:error] [pid 643573:tid 643829] [client 172.213.208.20:28014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amuBxPxWyxgRnoFKAJ_5mQAAAos"]
[Thu Jul 30 11:54:29.633162 2026] [security2:error] [pid 643573:tid 643716] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "saptora.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "amuBxfxWyxgRnoFKAJ_5nQAAAho"]
[Thu Jul 30 11:54:30.044769 2026] [security2:error] [pid 643573:tid 643779] [client 46.232.235.4:60310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.greensparkle.net"] [uri "/.env"] [unique_id "amuBxvxWyxgRnoFKAJ_5nwAAAlk"]
[Thu Jul 30 11:54:30.299943 2026] [security2:error] [pid 642360:tid 642569] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "saptora.com"] [uri "/media/system/js/core.js"] [unique_id "amuBxpSUkh3e5AhEJOB0UAAAAd4"]
[Thu Jul 30 11:54:31.037820 2026] [core:notice] [pid 642360:tid 642511] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:31.042013 2026] [security2:error] [pid 642360:tid 642511] [client 103.215.74.26:28460] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBx5SUkh3e5AhEJOB0WQAAAaQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:31.102725 2026] [authz_core:error] [pid 642360:tid 642544] [client 46.232.235.4:45738] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.env
[Thu Jul 30 11:54:31.144520 2026] [authz_core:error] [pid 643573:tid 643756] [client 46.232.235.4:45762] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.env
[Thu Jul 30 11:54:31.547818 2026] [authz_core:error] [pid 643573:tid 643732] [client 46.232.235.4:45728] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.git
[Thu Jul 30 11:54:31.562692 2026] [authz_core:error] [pid 642360:tid 642613] [client 46.232.235.4:45748] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.git
[Thu Jul 30 11:54:31.760587 2026] [core:notice] [pid 643573:tid 643822] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:31.764634 2026] [security2:error] [pid 643573:tid 643822] [client 103.215.74.26:28474] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBx_xWyxgRnoFKAJ_5tAAAAoQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:31.875487 2026] [security2:error] [pid 643573:tid 643775] [client 172.213.208.20:22040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amuBx_xWyxgRnoFKAJ_5tgAAAlU"]
[Thu Jul 30 11:54:32.493887 2026] [core:notice] [pid 643573:tid 643767] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:32.498242 2026] [security2:error] [pid 643573:tid 643767] [client 103.215.74.26:28488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuByPxWyxgRnoFKAJ_5vAAAAk0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:32.605260 2026] [security2:error] [pid 643573:tid 643730] [client 57.141.0.64:51562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuByPxWyxgRnoFKAJ_5uQACKEQ"], referer: https://igetvape-australia.com/product/iget-bar-pro-strawberry-raspberry/?add-to-cart=103
[Thu Jul 30 11:54:32.842586 2026] [authz_core:error] [pid 643573:tid 643752] [client 46.232.235.4:45776] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.env
[Thu Jul 30 11:54:33.045049 2026] [authz_core:error] [pid 642360:tid 642534] [client 46.232.235.4:45778] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.git
[Thu Jul 30 11:54:33.246847 2026] [core:notice] [pid 642360:tid 642548] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:33.250905 2026] [security2:error] [pid 642360:tid 642548] [client 103.215.74.26:55018] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuByZSUkh3e5AhEJOB0iAAAAck"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:33.577693 2026] [core:notice] [pid 642360:tid 642522] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:33.979571 2026] [core:notice] [pid 643573:tid 643743] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:33.983429 2026] [security2:error] [pid 643573:tid 643743] [client 103.215.74.26:55032] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuByfxWyxgRnoFKAJ_5xAAAAjU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:34.719193 2026] [core:notice] [pid 643573:tid 643811] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:34.723618 2026] [security2:error] [pid 643573:tid 643811] [client 103.215.74.26:55044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuByvxWyxgRnoFKAJ_5xwAAAnk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:35.088429 2026] [security2:error] [pid 642360:tid 642507] [client 172.213.208.20:28010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-content/admin.php"] [unique_id "amuBy5SUkh3e5AhEJOB0nQAAAaA"]
[Thu Jul 30 11:54:35.464146 2026] [core:notice] [pid 643573:tid 643711] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:35.468396 2026] [security2:error] [pid 643573:tid 643711] [client 103.215.74.26:55060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBy_xWyxgRnoFKAJ_5zQAAAhU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:35.742893 2026] [security2:error] [pid 643573:tid 643792] [client 172.213.208.20:18644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-configs.php"] [unique_id "amuBy_xWyxgRnoFKAJ_50AAAAmY"]
[Thu Jul 30 11:54:36.017454 2026] [security2:error] [pid 643573:tid 643795] [client 85.208.96.205:24204] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2021/01/18/inter-soma-quase-triplo-de-pontos-do-sao-paulo-em-seis-rodadas-e-esquenta-disputa-pelo-titulo/"] [unique_id "amuBzPxWyxgRnoFKAJ_50wAAAmk"]
[Thu Jul 30 11:54:36.017563 2026] [security2:error] [pid 643573:tid 643795] [client 85.208.96.205:24204] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2021/01/18/inter-soma-quase-triplo-de-pontos-do-sao-paulo-em-seis-rodadas-e-esquenta-disputa-pelo-titulo/"] [unique_id "amuBzPxWyxgRnoFKAJ_50wAAAmk"]
[Thu Jul 30 11:54:36.317487 2026] [security2:error] [pid 643573:tid 643585] [remote 194.116.184.179:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.184.116.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "imailearninghub.com"] [uri "/wp/xmlrpc.php"] [unique_id "amuBzPxWyxgRnoFKAJ_51AACVgQ"]
[Thu Jul 30 11:54:36.317732 2026] [security2:error] [pid 643573:tid 643776] [client 194.116.184.179:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "imailearninghub.com"] [uri "/wp/xmlrpc.php"] [unique_id "amuBzPxWyxgRnoFKAJ_51AACVgQ"]
[Thu Jul 30 11:54:36.413251 2026] [security2:error] [pid 643573:tid 643716] [client 172.213.208.20:44715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/php.php"] [unique_id "amuBzPxWyxgRnoFKAJ_51wAAAho"]
[Thu Jul 30 11:54:36.826550 2026] [security2:error] [pid 642360:tid 642586] [client 2a03:2880:f800:2b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBzJSUkh3e5AhEJOB0pAAB73I"]
[Thu Jul 30 11:54:37.074369 2026] [security2:error] [pid 643573:tid 643824] [client 176.241.66.87:28281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBzfxWyxgRnoFKAJ_53wAAAoY"]
[Thu Jul 30 11:54:37.074512 2026] [security2:error] [pid 643573:tid 643824] [client 176.241.66.87:28281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBzfxWyxgRnoFKAJ_53wAAAoY"]
[Thu Jul 30 11:54:37.652000 2026] [security2:error] [pid 643573:tid 643720] [client 172.213.208.20:22028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-includes/index.php"] [unique_id "amuBzfxWyxgRnoFKAJ_54wAAAh4"]
[Thu Jul 30 11:54:39.894335 2026] [security2:error] [pid 642360:tid 642551] [client 198.54.128.138:35540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuBz5SUkh3e5AhEJOB0xgAAAcw"]
[Thu Jul 30 11:54:39.894434 2026] [security2:error] [pid 642360:tid 642551] [client 198.54.128.138:35540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuBz5SUkh3e5AhEJOB0xgAAAcw"]
[Thu Jul 30 11:54:40.253235 2026] [authz_core:error] [pid 642360:tid 642566] [client 46.232.235.4:45830] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.env
[Thu Jul 30 11:54:40.582101 2026] [authz_core:error] [pid 642360:tid 642602] [client 46.232.235.4:45838] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.env
[Thu Jul 30 11:54:41.216526 2026] [core:notice] [pid 643573:tid 643733] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:41.220894 2026] [security2:error] [pid 643573:tid 643733] [client 103.215.74.26:55076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB0fxWyxgRnoFKAJ_59wAAAis"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:41.223658 2026] [security2:error] [pid 643573:tid 643825] [client 57.141.0.6:58224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuB0PxWyxgRnoFKAJ_59QACh3Y"], referer: https://igetvape-australia.com/product/alibarbar-ingot-wtf-grapefruit-9000-puffs/?add-to-cart=924
[Thu Jul 30 11:54:41.317464 2026] [authz_core:error] [pid 643573:tid 643805] [client 46.232.235.4:46256] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.git
[Thu Jul 30 11:54:41.355132 2026] [authz_core:error] [pid 643573:tid 643717] [client 46.232.235.4:46242] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.git
[Thu Jul 30 11:54:41.665016 2026] [security2:error] [pid 643573:tid 643706] [remote 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuB0fxWyxgRnoFKAJ_5_gACSn0"]
[Thu Jul 30 11:54:41.665173 2026] [security2:error] [pid 643573:tid 643764] [client 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuB0fxWyxgRnoFKAJ_5_gACSn0"]
[Thu Jul 30 11:54:41.783839 2026] [security2:error] [pid 642360:tid 642526] [client 123.28.19.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "journeywomenscenter.org"] [uri "/index.php"] [unique_id "amuB0JSUkh3e5AhEJOB0yQAAAbM"], referer: https://journeywomenscenter.org/
[Thu Jul 30 11:54:41.956614 2026] [core:notice] [pid 642360:tid 642525] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:41.964207 2026] [security2:error] [pid 642360:tid 642525] [client 103.215.74.26:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB0ZSUkh3e5AhEJOB03gAAAbI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:42.339954 2026] [security2:error] [pid 643573:tid 643818] [client 172.213.208.20:14740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-admin/a.php"] [unique_id "amuB0vxWyxgRnoFKAJ_6DQAAAoA"]
[Thu Jul 30 11:54:42.702157 2026] [core:notice] [pid 642360:tid 642559] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:42.709618 2026] [security2:error] [pid 642360:tid 642559] [client 103.215.74.26:55090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB0pSUkh3e5AhEJOB06gAAAdQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:42.915500 2026] [core:notice] [pid 643573:tid 643797] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:43.207541 2026] [core:notice] [pid 643573:tid 643674] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:43.457468 2026] [core:notice] [pid 643573:tid 643754] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:43.461907 2026] [security2:error] [pid 643573:tid 643754] [client 103.215.74.26:48092] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB0_xWyxgRnoFKAJ_6FAAAAkA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:44.191265 2026] [core:notice] [pid 642360:tid 642569] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:44.195650 2026] [security2:error] [pid 642360:tid 642569] [client 103.215.74.26:48100] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB1JSUkh3e5AhEJOB0-AAAAd4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:44.317402 2026] [security2:error] [pid 642360:tid 642596] [client 57.141.0.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuB05SUkh3e5AhEJOB08gAAAfk"]
[Thu Jul 30 11:54:44.936947 2026] [core:notice] [pid 642360:tid 642509] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:44.941552 2026] [security2:error] [pid 642360:tid 642509] [client 103.215.74.26:48114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB1JSUkh3e5AhEJOB1BQAAAaI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:45.669365 2026] [core:notice] [pid 643253:tid 643417] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:45.673707 2026] [security2:error] [pid 643253:tid 643417] [client 103.215.74.26:48120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB1cjqbtjBYzqM1uYm8wAAACE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:46.125431 2026] [security2:error] [pid 643573:tid 643788] [client 74.7.230.11:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.rru.djb.temporary.site"] [uri "/index.php"] [unique_id "amuB1PxWyxgRnoFKAJ_6HgAAAmI"]
[Thu Jul 30 11:54:46.126349 2026] [security2:error] [pid 642360:tid 642563] [client 74.7.230.11:50752] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.rru.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amuB1JSUkh3e5AhEJOB0_QAB2Ao"]
[Thu Jul 30 11:54:46.286304 2026] [security2:error] [pid 643573:tid 643819] [client 172.213.208.20:19850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuB1vxWyxgRnoFKAJ_6KAAAAoE"]
[Thu Jul 30 11:54:46.434092 2026] [core:notice] [pid 643573:tid 643755] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:46.440894 2026] [security2:error] [pid 643573:tid 643755] [client 103.215.74.26:48124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB1vxWyxgRnoFKAJ_6KgAAAkE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:47.185105 2026] [core:notice] [pid 642360:tid 642536] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:47.188845 2026] [security2:error] [pid 642360:tid 642536] [client 103.215.74.26:48138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "741"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB15SUkh3e5AhEJOB1GwAAAb0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:47.611593 2026] [security2:error] [pid 643573:tid 643761] [client 176.241.66.87:63245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuB1_xWyxgRnoFKAJ_6OAAAAkc"]
[Thu Jul 30 11:54:47.611746 2026] [security2:error] [pid 643573:tid 643761] [client 176.241.66.87:63245] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuB1_xWyxgRnoFKAJ_6OAAAAkc"]
[Thu Jul 30 11:54:47.918764 2026] [core:notice] [pid 643573:tid 643828] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:47.922764 2026] [security2:error] [pid 643573:tid 643828] [client 103.215.74.26:48144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "738"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB1_xWyxgRnoFKAJ_6OQAAAoo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:48.000380 2026] [autoindex:error] [pid 643573:tid 643779] [client 52.4.19.39:4043] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_cfd6e8f6/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:54:48.073724 2026] [security2:error] [pid 642360:tid 642553] [client 172.213.208.20:45949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-admin.php"] [unique_id "amuB2JSUkh3e5AhEJOB1IgAAAc4"]
[Thu Jul 30 11:54:48.658587 2026] [core:notice] [pid 643573:tid 643759] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:48.662933 2026] [security2:error] [pid 643573:tid 643759] [client 103.215.74.26:48152] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB2PxWyxgRnoFKAJ_6QQAAAkU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:49.388477 2026] [core:notice] [pid 643573:tid 643756] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:49.395127 2026] [security2:error] [pid 643573:tid 643756] [client 103.215.74.26:48160] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB2fxWyxgRnoFKAJ_6QwAAAkI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:50.131563 2026] [core:notice] [pid 643573:tid 643753] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:50.138470 2026] [security2:error] [pid 643573:tid 643753] [client 103.215.74.26:48174] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB2vxWyxgRnoFKAJ_6TgAAAj8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:50.793219 2026] [security2:error] [pid 643573:tid 643795] [client 172.213.208.20:38311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/size.php"] [unique_id "amuB2vxWyxgRnoFKAJ_6VAAAAmk"]
[Thu Jul 30 11:54:50.860371 2026] [core:notice] [pid 643573:tid 643815] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:50.864141 2026] [security2:error] [pid 643573:tid 643815] [client 103.215.74.26:48190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB2vxWyxgRnoFKAJ_6VwAAAn0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:51.595508 2026] [core:notice] [pid 642360:tid 642560] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:51.599780 2026] [security2:error] [pid 642360:tid 642560] [client 103.215.74.26:48198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "757"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB25SUkh3e5AhEJOB1PgAAAdU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:51.701334 2026] [security2:error] [pid 643573:tid 643727] [client 57.141.0.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuB2_xWyxgRnoFKAJ_6XAAAAiU"]
[Thu Jul 30 11:54:51.886854 2026] [core:error] [pid 642360:tid 642600] [client 74.7.230.5:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:54:51.886874 2026] [core:error] [pid 642360:tid 642600] [client 74.7.230.5:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:54:51.887002 2026] [security2:error] [pid 642360:tid 642600] [client 74.7.230.5:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.thdinfinity.com"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "amuB25SUkh3e5AhEJOB1RAAAAf0"]
[Thu Jul 30 11:54:51.887729 2026] [security2:error] [pid 643573:tid 643717] [client 74.7.230.5:47126] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.thdinfinity.com"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuB2_xWyxgRnoFKAJ_6ZQACG0w"]
[Thu Jul 30 11:54:52.364314 2026] [core:notice] [pid 643573:tid 643723] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:52.370619 2026] [security2:error] [pid 643573:tid 643723] [client 103.215.74.26:48200] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB3PxWyxgRnoFKAJ_6awAAAiE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:53.087675 2026] [core:notice] [pid 643573:tid 643736] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:53.091813 2026] [security2:error] [pid 643573:tid 643736] [client 103.215.74.26:3014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "770"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB3fxWyxgRnoFKAJ_6dgAAAi4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:53.532748 2026] [security2:error] [pid 642360:tid 642457] [remote 20.52.125.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saptora.com"] [uri "/.well-known/autoload_classmap.php"] [unique_id "amuB3ZSUkh3e5AhEJOB1UQABwGA"]
[Thu Jul 30 11:54:53.823620 2026] [core:notice] [pid 642360:tid 642616] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:53.827483 2026] [security2:error] [pid 642360:tid 642616] [client 103.215.74.26:3028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB3ZSUkh3e5AhEJOB1VAAAAg0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:53.987689 2026] [security2:error] [pid 643573:tid 643655] [remote 20.52.125.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saptora.com"] [uri "/.well-known/flower.php"] [unique_id "amuB3fxWyxgRnoFKAJ_6fgACWko"]
[Thu Jul 30 11:54:54.160312 2026] [security2:error] [pid 643573:tid 643834] [client 172.213.208.20:17674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-includes/wp-class.php"] [unique_id "amuB3vxWyxgRnoFKAJ_6fwAAApA"]
[Thu Jul 30 11:54:54.422366 2026] [security2:error] [pid 642360:tid 642405] [remote 20.52.125.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saptora.com"] [uri "/.well-known/xleet.php"] [unique_id "amuB3pSUkh3e5AhEJOB1WgAB2Cw"]
[Thu Jul 30 11:54:54.560292 2026] [core:notice] [pid 642360:tid 642604] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:54.564288 2026] [security2:error] [pid 642360:tid 642604] [client 103.215.74.26:3032] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB3pSUkh3e5AhEJOB1WwAAAgE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:54.815779 2026] [security2:error] [pid 642360:tid 642416] [remote 20.52.125.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saptora.com"] [uri "/.well-known/acme-challenge/flower.php"] [unique_id "amuB3pSUkh3e5AhEJOB1XwAB-jc"]
[Thu Jul 30 11:54:55.289902 2026] [security2:error] [pid 643573:tid 643765] [client 74.7.241.182:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "qax.tqa.temporary.site"] [uri "/index.php"] [unique_id "amuB3PxWyxgRnoFKAJ_6cQAAAks"]
[Thu Jul 30 11:54:55.290636 2026] [security2:error] [pid 643573:tid 643750] [client 74.7.241.182:48618] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "qax.tqa.temporary.site"] [uri "/robots.txt"] [unique_id "amuB3PxWyxgRnoFKAJ_6bgACPEg"]
[Thu Jul 30 11:54:55.294557 2026] [core:notice] [pid 643573:tid 643801] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:55.298502 2026] [security2:error] [pid 643573:tid 643801] [client 103.215.74.26:3040] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB3_xWyxgRnoFKAJ_6iAAAAm8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:55.302847 2026] [security2:error] [pid 642360:tid 642495] [client 172.213.208.20:14751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/403.php"] [unique_id "amuB35SUkh3e5AhEJOB1YQAAAZQ"]
[Thu Jul 30 11:54:55.720923 2026] [core:notice] [pid 643573:tid 643797] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:55.787878 2026] [security2:error] [pid 643573:tid 643781] [client 74.7.241.150:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cpanel.nexiummedication.store"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amuB3_xWyxgRnoFKAJ_6kAAAAls"]
[Thu Jul 30 11:54:56.269474 2026] [security2:error] [pid 643573:tid 643740] [client 57.141.0.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuB3_xWyxgRnoFKAJ_6jgAAAjI"]
[Thu Jul 30 11:54:56.563687 2026] [security2:error] [pid 643573:tid 643802] [client 172.213.208.20:17703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amuB4PxWyxgRnoFKAJ_6lgAAAnA"]
[Thu Jul 30 11:54:56.975572 2026] [security2:error] [pid 643253:tid 643420] [client 114.119.132.101:41297] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "deltaedu.net"] [uri "/robots.txt"] [unique_id "amuB4MjqbtjBYzqM1uYm_gAAACQ"], referer: http://deltaedu.net/robots.txt
[Thu Jul 30 11:54:57.045972 2026] [security2:error] [pid 643253:tid 643471] [client 57.141.0.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuB4MjqbtjBYzqM1uYm_AAAAFc"]
[Thu Jul 30 11:54:57.114810 2026] [security2:error] [pid 643573:tid 643632] [remote 57.141.0.50:32432] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "thdinfinity.com"] [uri "/search/74297757886/feed/rss2/"] [unique_id "amuB4fxWyxgRnoFKAJ_6nwACWDM"]
[Thu Jul 30 11:54:57.173283 2026] [core:notice] [pid 643573:tid 643770] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:57.472176 2026] [security2:error] [pid 643573:tid 643789] [client 2a03:2880:f800:3:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuB4PxWyxgRnoFKAJ_6mwACYwo"]
[Thu Jul 30 11:54:58.347544 2026] [security2:error] [pid 643573:tid 643790] [client 176.241.66.87:29481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuB4vxWyxgRnoFKAJ_6rgAAAmQ"]
[Thu Jul 30 11:54:58.347651 2026] [security2:error] [pid 643573:tid 643790] [client 176.241.66.87:29481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuB4vxWyxgRnoFKAJ_6rgAAAmQ"]
[Thu Jul 30 11:54:58.935810 2026] [core:notice] [pid 643573:tid 643712] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:59.129641 2026] [core:notice] [pid 643573:tid 643720] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:59.519517 2026] [core:notice] [pid 643573:tid 643771] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:59.685360 2026] [core:notice] [pid 643573:tid 643713] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:00.507805 2026] [security2:error] [pid 642360:tid 642511] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tuwaiq-sa.tech"] [uri "/wp-includes/css/buttons.css"] [unique_id "amuB5JSUkh3e5AhEJOB1iAAAAaQ"]
[Thu Jul 30 11:55:01.034361 2026] [core:notice] [pid 643573:tid 643820] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:01.038729 2026] [security2:error] [pid 643573:tid 643820] [client 103.215.74.26:3044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB5fxWyxgRnoFKAJ_6yAAAAoI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:01.057620 2026] [security2:error] [pid 642360:tid 642600] [client 190.2.142.78:23636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.142.2.190.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuB5JSUkh3e5AhEJOB1jAAAAf0"]
[Thu Jul 30 11:55:01.238811 2026] [security2:error] [pid 642360:tid 642509] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tuwaiq-sa.tech"] [uri "/media/system/js/core.js"] [unique_id "amuB5ZSUkh3e5AhEJOB1kgAAAaI"]
[Thu Jul 30 11:55:01.350550 2026] [security2:error] [pid 643573:tid 643676] [remote 190.2.142.78:18970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.142.2.190.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuB5fxWyxgRnoFKAJ_6ywACiF8"], referer: http://alseermarine.ae/wp-login.php
[Thu Jul 30 11:55:01.798518 2026] [core:notice] [pid 643573:tid 643754] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:01.805534 2026] [security2:error] [pid 643573:tid 643754] [client 103.215.74.26:3052] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "738"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB5fxWyxgRnoFKAJ_61wAAAkA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:01.863509 2026] [security2:error] [pid 643573:tid 643836] [client 172.213.208.20:44677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/as.php"] [unique_id "amuB5fxWyxgRnoFKAJ_62gAAApI"]
[Thu Jul 30 11:55:02.177928 2026] [security2:error] [pid 643573:tid 643832] [client 50.6.43.217:25558] ModSecurity: Warning. Matched phrase "fq" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "alseermarine.com"] [uri "/wp-cron.php"] [unique_id "amuB5vxWyxgRnoFKAJ_63gAAAo4"]
[Thu Jul 30 11:55:02.335943 2026] [security2:error] [pid 643573:tid 643806] [client 2a03:2880:f800:36:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuB5fxWyxgRnoFKAJ_60wACdCQ"]
[Thu Jul 30 11:55:02.433399 2026] [core:notice] [pid 642360:tid 642586] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:02.469855 2026] [security2:error] [pid 643573:tid 643771] [client 172.213.208.20:45896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-admin/includes/index.php"] [unique_id "amuB5vxWyxgRnoFKAJ_64QAAAlE"]
[Thu Jul 30 11:55:02.899596 2026] [security2:error] [pid 642360:tid 642514] [client 190.2.142.78:18982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuB5pSUkh3e5AhEJOB1pQABp2I"], referer: http://alseermarine.com/wp-admin/
[Thu Jul 30 11:55:02.899870 2026] [security2:error] [pid 642360:tid 642514] [client 190.2.142.78:18982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuB5pSUkh3e5AhEJOB1pAABp3A"], referer: https://www.alseermarine.com/wp-admin/
[Thu Jul 30 11:55:03.506789 2026] [security2:error] [pid 643573:tid 643735] [client 112.86.225.114:37086] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product-category/sneaker/nike-sneaker/nike-sb-dunk/"] [unique_id "amuB5_xWyxgRnoFKAJ_68QAAAi0"]
[Thu Jul 30 11:55:03.506889 2026] [security2:error] [pid 643573:tid 643735] [client 112.86.225.114:37086] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/product-category/sneaker/nike-sneaker/nike-sb-dunk/"] [unique_id "amuB5_xWyxgRnoFKAJ_68QAAAi0"]
[Thu Jul 30 11:55:04.313220 2026] [security2:error] [pid 642360:tid 642567] [client 190.2.142.78:18982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuB6JSUkh3e5AhEJOB1tAAB3Gw"], referer: http://alseermarine.com/wp-admin/
[Thu Jul 30 11:55:05.280567 2026] [core:notice] [pid 643573:tid 643818] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:05.583647 2026] [security2:error] [pid 643573:tid 643760] [client 91.142.73.116:53492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.73.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/register"] [unique_id "amuB6fxWyxgRnoFKAJ_6-gAAAkY"], referer: https://cnpinyin.com/register
[Thu Jul 30 11:55:06.442020 2026] [security2:error] [pid 643573:tid 643794] [client 91.142.73.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuB6vxWyxgRnoFKAJ_7AQAAAmg"], referer: https://cnpinyin.com/register
[Thu Jul 30 11:55:07.583353 2026] [core:notice] [pid 643573:tid 643762] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:07.587311 2026] [security2:error] [pid 643573:tid 643762] [client 103.215.74.26:24620] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "738"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB6_xWyxgRnoFKAJ_7CgAAAkg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:07.654467 2026] [security2:error] [pid 642360:tid 642556] [client 172.213.208.20:17692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amuB65SUkh3e5AhEJOB12AAAAdE"]
[Thu Jul 30 11:55:07.943667 2026] [security2:error] [pid 643573:tid 643754] [client 47.128.122.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuB6_xWyxgRnoFKAJ_7DgAAAkA"]
[Thu Jul 30 11:55:08.324109 2026] [core:notice] [pid 643573:tid 643752] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:08.328475 2026] [security2:error] [pid 643573:tid 643752] [client 103.215.74.26:24636] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB7PxWyxgRnoFKAJ_7EQAAAj4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:09.040489 2026] [security2:error] [pid 642360:tid 642588] [client 176.241.66.87:30099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuB7ZSUkh3e5AhEJOB15QAAAfE"]
[Thu Jul 30 11:55:09.040651 2026] [security2:error] [pid 642360:tid 642588] [client 176.241.66.87:30099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuB7ZSUkh3e5AhEJOB15QAAAfE"]
[Thu Jul 30 11:55:09.060950 2026] [core:notice] [pid 643573:tid 643728] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:09.065417 2026] [security2:error] [pid 643573:tid 643728] [client 103.215.74.26:24648] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB7fxWyxgRnoFKAJ_7FAAAAiY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:09.632401 2026] [security2:error] [pid 642360:tid 642373] [remote 194.116.184.179:55843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.184.116.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/wp-login.php"] [unique_id "amuB7ZSUkh3e5AhEJOB16gABygw"]
[Thu Jul 30 11:55:11.507805 2026] [security2:error] [pid 643573:tid 643836] [client 34.86.95.193:63707] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "psz.dtn.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuB7_xWyxgRnoFKAJ_7JwAAApI"]
[Thu Jul 30 11:55:12.550259 2026] [security2:error] [pid 643573:tid 643834] [client 34.86.95.193:52313] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "psz.dtn.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuB8PxWyxgRnoFKAJ_7MQAAApA"]
[Thu Jul 30 11:55:13.211740 2026] [security2:error] [pid 643573:tid 643597] [remote 52.204.253.129:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "appliancerepairservice.one"] [uri "/"] [unique_id "amuB8fxWyxgRnoFKAJ_7PwAChxA"]
[Thu Jul 30 11:55:13.928660 2026] [core:notice] [pid 642360:tid 642502] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:13.937858 2026] [security2:error] [pid 642360:tid 642536] [client 172.213.208.20:38385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/plugins.php"] [unique_id "amuB8ZSUkh3e5AhEJOB2CgAAAb0"]
[Thu Jul 30 11:55:14.039308 2026] [security2:error] [pid 643573:tid 643698] [remote 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuB8vxWyxgRnoFKAJ_7RAACiXU"]
[Thu Jul 30 11:55:14.039461 2026] [security2:error] [pid 643573:tid 643827] [client 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuB8vxWyxgRnoFKAJ_7RAACiXU"]
[Thu Jul 30 11:55:14.488553 2026] [security2:error] [pid 643573:tid 643728] [client 52.167.144.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuB8PxWyxgRnoFKAJ_7NQAAAiY"]
[Thu Jul 30 11:55:14.794560 2026] [core:notice] [pid 642360:tid 642569] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:14.799451 2026] [security2:error] [pid 642360:tid 642569] [client 103.215.74.26:10742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB8pSUkh3e5AhEJOB2GAAAAd4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:15.076735 2026] [security2:error] [pid 642360:tid 642550] [client 172.213.208.20:17657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-includes/js/index.php"] [unique_id "amuB85SUkh3e5AhEJOB2GwAAAcs"]
[Thu Jul 30 11:55:15.133641 2026] [security2:error] [pid 642360:tid 642593] [client 190.2.142.78:42970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.142.2.190.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/wp-login.php"] [unique_id "amuB85SUkh3e5AhEJOB2HAAAAfY"]
[Thu Jul 30 11:55:15.399490 2026] [security2:error] [pid 643573:tid 643793] [client 34.86.95.193:52313] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "psz.dtn.temporary.site"] [uri "/index.php"] [unique_id "amuB8_xWyxgRnoFKAJ_7WAAAAmc"]
[Thu Jul 30 11:55:15.527418 2026] [core:notice] [pid 643573:tid 643771] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:15.532479 2026] [security2:error] [pid 643573:tid 643771] [client 103.215.74.26:10748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB8_xWyxgRnoFKAJ_7WwAAAlE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:15.799063 2026] [security2:error] [pid 643573:tid 643794] [client 34.86.95.193:52313] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "psz.dtn.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuB8_xWyxgRnoFKAJ_7XAAAAmg"]
[Thu Jul 30 11:55:15.799162 2026] [security2:error] [pid 643573:tid 643794] [client 34.86.95.193:52313] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "psz.dtn.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuB8_xWyxgRnoFKAJ_7XAAAAmg"]
[Thu Jul 30 11:55:16.796289 2026] [security2:error] [pid 642360:tid 642586] [client 190.153.80.20:4655] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuB9JSUkh3e5AhEJOB2LQAAAe8"], referer: http://pkf.jo
[Thu Jul 30 11:55:17.067332 2026] [security2:error] [pid 642360:tid 642514] [client 52.167.144.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuB9JSUkh3e5AhEJOB2MwAAAac"]
[Thu Jul 30 11:55:17.344782 2026] [security2:error] [pid 642360:tid 642599] [client 152.231.104.86:57637] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuB9JSUkh3e5AhEJOB2MQAAAfw"], referer: http://pkf.jo
[Thu Jul 30 11:55:17.386069 2026] [security2:error] [pid 642360:tid 642493] [client 45.190.91.98:40566] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuB9JSUkh3e5AhEJOB2MgAAAZI"], referer: http://pkf.jo
[Thu Jul 30 11:55:17.389388 2026] [security2:error] [pid 643573:tid 643766] [client 2a03:2880:f800:7:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuB9PxWyxgRnoFKAJ_7XQACTHk"]
[Thu Jul 30 11:55:17.409784 2026] [security2:error] [pid 642360:tid 642506] [client 2a03:2880:f800:43:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuB9JSUkh3e5AhEJOB2LAABnys"]
[Thu Jul 30 11:55:17.497873 2026] [security2:error] [pid 643573:tid 643827] [client 172.213.208.20:38280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/go.php"] [unique_id "amuB9fxWyxgRnoFKAJ_7awAAAok"]
[Thu Jul 30 11:55:18.103228 2026] [core:notice] [pid 643573:tid 643832] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:18.106880 2026] [security2:error] [pid 642360:tid 642553] [client 172.213.208.20:44681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/test1.php"] [unique_id "amuB9pSUkh3e5AhEJOB2QgAAAc4"]
[Thu Jul 30 11:55:18.610031 2026] [security2:error] [pid 643573:tid 643780] [client 177.201.241.2:33868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuB9vxWyxgRnoFKAJ_7dgAAAlo"], referer: http://pkf.jo
[Thu Jul 30 11:55:19.240191 2026] [core:notice] [pid 643573:tid 643756] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:19.810586 2026] [security2:error] [pid 643573:tid 643801] [client 176.241.66.87:30735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuB9_xWyxgRnoFKAJ_7hAAAAm8"]
[Thu Jul 30 11:55:19.810733 2026] [security2:error] [pid 643573:tid 643801] [client 176.241.66.87:30735] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuB9_xWyxgRnoFKAJ_7hAAAAm8"]
[Thu Jul 30 11:55:20.628329 2026] [security2:error] [pid 642360:tid 642532] [client 185.231.155.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuB95SUkh3e5AhEJOB2UgABuV0"], referer: https://allmontecristi.com/5-important-characteristics-to-identify-an-export-panama-hat/?srsltid=afmbooobpjslvy1dcritpm3oyoloutbopk2q0t238sboel09-jvs0f2z
[Thu Jul 30 11:55:21.291152 2026] [core:notice] [pid 643573:tid 643815] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:21.295378 2026] [security2:error] [pid 643573:tid 643815] [client 103.215.74.26:10762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB-fxWyxgRnoFKAJ_7igAAAn0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:21.724804 2026] [core:notice] [pid 643253:tid 643511] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:21.989904 2026] [security2:error] [pid 643573:tid 643726] [client 185.231.155.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuB-fxWyxgRnoFKAJ_7iwACJH4"], referer: https://allmontecristi.com/contact/
[Thu Jul 30 11:55:22.023499 2026] [core:notice] [pid 643573:tid 643714] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:22.028540 2026] [security2:error] [pid 643573:tid 643714] [client 103.215.74.26:10764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB-vxWyxgRnoFKAJ_7jwAAAhg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:22.552970 2026] [security2:error] [pid 643573:tid 643783] [client 172.213.208.20:30242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/images/index.php"] [unique_id "amuB-vxWyxgRnoFKAJ_7kgAAAl0"]
[Thu Jul 30 11:55:22.752811 2026] [core:notice] [pid 643573:tid 643727] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:22.757373 2026] [security2:error] [pid 643573:tid 643727] [client 103.215.74.26:10778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB-vxWyxgRnoFKAJ_7lwAAAiU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:23.485206 2026] [core:notice] [pid 643253:tid 643449] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:23.489772 2026] [security2:error] [pid 643253:tid 643449] [client 103.215.74.26:7440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB-8jqbtjBYzqM1uYnJQAAAEE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:26.868710 2026] [core:notice] [pid 643573:tid 643751] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:27.141707 2026] [security2:error] [pid 643573:tid 643795] [client 44.205.192.249:4911] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/robots.txt"] [unique_id "amuB__xWyxgRnoFKAJ_7wQAAAmk"]
[Thu Jul 30 11:55:27.584309 2026] [security2:error] [pid 643573:tid 643819] [client 107.170.61.160:35534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ylw.gpl.temporary.site"] [uri "/.env"] [unique_id "amuB__xWyxgRnoFKAJ_7xQAAAoE"]
[Thu Jul 30 11:55:28.804230 2026] [security2:error] [pid 643573:tid 643684] [remote 74.7.241.60:58700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/img/article.php"] [unique_id "amuCAPxWyxgRnoFKAJ_70wACcWc"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/img/main_image_6a2a8e70efd49.jpg
[Thu Jul 30 11:55:28.929399 2026] [security2:error] [pid 643573:tid 643800] [client 204.12.208.18:58124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-content/brb1944e/index.php"] [unique_id "amuCAPxWyxgRnoFKAJ_70gAAAm4"], referer: http://thdinfinity.com/wp-content/brb1944e/index.php
[Thu Jul 30 11:55:29.237867 2026] [core:notice] [pid 643573:tid 643718] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:29.242209 2026] [security2:error] [pid 643573:tid 643718] [client 103.215.74.26:7450] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCAfxWyxgRnoFKAJ_71QAAAhw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:29.538355 2026] [security2:error] [pid 643573:tid 643713] [client 204.12.208.18:58139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-content/brb1944e/index.php"] [unique_id "amuCAfxWyxgRnoFKAJ_72AAAAhc"], referer: http://thdinfinity.com/wp-content/brb1944e/index.php
[Thu Jul 30 11:55:29.613949 2026] [security2:error] [pid 643573:tid 643810] [client 172.213.208.20:25934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/asd.php"] [unique_id "amuCAfxWyxgRnoFKAJ_72QAAAng"]
[Thu Jul 30 11:55:29.836733 2026] [security2:error] [pid 643573:tid 643761] [client 52.204.71.8:44225] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/arquivos/noticias/783/x01cae62c33381bef08ae27cbbb8b72e4.jpg.pagespeed.ic.vbgVUHucDG.webp"] [unique_id "amuCAfxWyxgRnoFKAJ_73gAAAkc"]
[Thu Jul 30 11:55:29.963837 2026] [core:notice] [pid 643573:tid 643790] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:29.967797 2026] [security2:error] [pid 643573:tid 643790] [client 103.215.74.26:7452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "738"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCAfxWyxgRnoFKAJ_74AAAAmQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:30.160790 2026] [security2:error] [pid 642360:tid 642555] [client 204.12.208.18:58154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-content/brb1944e/index.php"] [unique_id "amuCApSUkh3e5AhEJOB2sgAAAdA"], referer: http://thdinfinity.com/wp-content/brb1944e/index.php
[Thu Jul 30 11:55:30.364861 2026] [security2:error] [pid 642360:tid 642556] [client 176.241.66.87:65478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCApSUkh3e5AhEJOB2swAAAdE"]
[Thu Jul 30 11:55:30.365019 2026] [security2:error] [pid 642360:tid 642556] [client 176.241.66.87:65478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCApSUkh3e5AhEJOB2swAAAdE"]
[Thu Jul 30 11:55:31.100077 2026] [security2:error] [pid 642360:tid 642546] [client 172.213.208.20:45903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-includes/customize/index.php"] [unique_id "amuCA5SUkh3e5AhEJOB2vAAAAcc"]
[Thu Jul 30 11:55:32.249582 2026] [security2:error] [pid 643573:tid 643585] [remote 190.92.174.188:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "echomemoversalain.casa"] [uri "/xmlrpc.php"] [unique_id "amuCBPxWyxgRnoFKAJ_79QACTwQ"]
[Thu Jul 30 11:55:32.249773 2026] [security2:error] [pid 643573:tid 643769] [client 190.92.174.188:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "echomemoversalain.casa"] [uri "/xmlrpc.php"] [unique_id "amuCBPxWyxgRnoFKAJ_79QACTwQ"]
[Thu Jul 30 11:55:32.258136 2026] [security2:error] [pid 642360:tid 642599] [client 17.241.219.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuCBJSUkh3e5AhEJOB2ywAAAfw"]
[Thu Jul 30 11:55:33.070953 2026] [security2:error] [pid 643573:tid 643836] [client 50.6.43.217:32614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuCBPxWyxgRnoFKAJ_7_AACkgs"]
[Thu Jul 30 11:55:33.071010 2026] [security2:error] [pid 643573:tid 643836] [client 50.6.43.217:32614] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuCBPxWyxgRnoFKAJ_7_AACkgs"]
[Thu Jul 30 11:55:34.385770 2026] [security2:error] [pid 643253:tid 643480] [client 186.79.68.169:45462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCBsjqbtjBYzqM1uYnKQAAAGA"], referer: http://pkf.jo
[Thu Jul 30 11:55:34.681847 2026] [security2:error] [pid 643573:tid 643792] [client 172.213.208.20:20827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amuCBvxWyxgRnoFKAJ_8BwAAAmY"]
[Thu Jul 30 11:55:35.542256 2026] [security2:error] [pid 642360:tid 642531] [client 52.70.209.13:22594] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/robots.txt"] [unique_id "amuCB5SUkh3e5AhEJOB26gAAAbg"]
[Thu Jul 30 11:55:35.716099 2026] [core:notice] [pid 642360:tid 642527] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:35.720274 2026] [security2:error] [pid 642360:tid 642527] [client 103.215.74.26:10572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "740"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCB5SUkh3e5AhEJOB27QAAAbQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:36.208159 2026] [security2:error] [pid 643573:tid 643800] [client 172.213.208.20:39407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/atomlib.php"] [unique_id "amuCCPxWyxgRnoFKAJ_8DQAAAm4"]
[Thu Jul 30 11:55:36.502460 2026] [core:notice] [pid 643573:tid 643744] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:36.506393 2026] [security2:error] [pid 643573:tid 643744] [client 103.215.74.26:10584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "737"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCCPxWyxgRnoFKAJ_8EQAAAjY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:37.274721 2026] [core:notice] [pid 643573:tid 643740] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:37.278858 2026] [security2:error] [pid 643573:tid 643740] [client 103.215.74.26:10586] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCCfxWyxgRnoFKAJ_8GgAAAjI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:37.712599 2026] [security2:error] [pid 643573:tid 643779] [client 54.84.147.79:35233] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/robots.txt"] [unique_id "amuCCfxWyxgRnoFKAJ_8HgAAAlk"]
[Thu Jul 30 11:55:38.006082 2026] [core:notice] [pid 643573:tid 643720] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:38.012843 2026] [security2:error] [pid 643573:tid 643720] [client 103.215.74.26:10590] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCCvxWyxgRnoFKAJ_8KgAAAh4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:38.079891 2026] [core:notice] [pid 643573:tid 643625] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:38.639525 2026] [security2:error] [pid 643573:tid 643808] [client 50.6.43.217:32626] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuCCvxWyxgRnoFKAJ_8NQAAAnY"]
[Thu Jul 30 11:55:38.670744 2026] [security2:error] [pid 643573:tid 643822] [client 50.6.43.217:32628] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuCCvxWyxgRnoFKAJ_8OAAAAoQ"]
[Thu Jul 30 11:55:38.767316 2026] [core:notice] [pid 642360:tid 642566] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:38.773896 2026] [security2:error] [pid 642360:tid 642566] [client 103.215.74.26:10602] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCCpSUkh3e5AhEJOB3BAAAAds"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:39.500453 2026] [core:notice] [pid 643573:tid 643742] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:39.504468 2026] [security2:error] [pid 643573:tid 643742] [client 103.215.74.26:10604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "738"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCC_xWyxgRnoFKAJ_8QAAAAjQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:40.249570 2026] [core:notice] [pid 643573:tid 643754] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:40.253516 2026] [security2:error] [pid 643573:tid 643754] [client 103.215.74.26:10618] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "756"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCDPxWyxgRnoFKAJ_8SQAAAkA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:40.705939 2026] [security2:error] [pid 643573:tid 643783] [client 50.6.43.217:32642] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuCDPxWyxgRnoFKAJ_8TQAAAl0"]
[Thu Jul 30 11:55:40.876125 2026] [security2:error] [pid 643573:tid 643825] [client 50.6.43.217:32656] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuCDPxWyxgRnoFKAJ_8TgAAAoc"]
[Thu Jul 30 11:55:40.986992 2026] [core:notice] [pid 643573:tid 643789] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:40.993443 2026] [security2:error] [pid 643573:tid 643789] [client 103.215.74.26:10634] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCDPxWyxgRnoFKAJ_8UAAAAmM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:40.997506 2026] [security2:error] [pid 643573:tid 643824] [client 176.241.66.87:32007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCDPxWyxgRnoFKAJ_8UQAAAoY"]
[Thu Jul 30 11:55:40.997611 2026] [security2:error] [pid 643573:tid 643824] [client 176.241.66.87:32007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCDPxWyxgRnoFKAJ_8UQAAAoY"]
[Thu Jul 30 11:55:41.607178 2026] [security2:error] [pid 642360:tid 642553] [client 20.91.199.21:56529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/011i.php"] [unique_id "amuCDZSUkh3e5AhEJOB3JAAAAc4"]
[Thu Jul 30 11:55:41.738746 2026] [core:notice] [pid 642360:tid 642508] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:41.742669 2026] [security2:error] [pid 642360:tid 642508] [client 103.215.74.26:10648] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "769"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCDZSUkh3e5AhEJOB3JwAAAaE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:41.779447 2026] [core:notice] [pid 643573:tid 643739] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:41.998310 2026] [security2:error] [pid 642360:tid 642564] [client 57.141.0.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCDZSUkh3e5AhEJOB3IAAAAdk"]
[Thu Jul 30 11:55:42.365939 2026] [security2:error] [pid 643573:tid 643775] [client 185.191.171.6:26912] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/09/03/instituicao-oferece-plataforma-gratuita-para-quem-quer-estudar-para-o-enem/"] [unique_id "amuCDvxWyxgRnoFKAJ_8YQAAAlU"]
[Thu Jul 30 11:55:42.366070 2026] [security2:error] [pid 643573:tid 643775] [client 185.191.171.6:26912] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/09/03/instituicao-oferece-plataforma-gratuita-para-quem-quer-estudar-para-o-enem/"] [unique_id "amuCDvxWyxgRnoFKAJ_8YQAAAlU"]
[Thu Jul 30 11:55:42.490847 2026] [core:notice] [pid 643573:tid 643805] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:42.494843 2026] [security2:error] [pid 643573:tid 643805] [client 103.215.74.26:10656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "741"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCDvxWyxgRnoFKAJ_8YgAAAnM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:42.831732 2026] [security2:error] [pid 642360:tid 642540] [client 57.141.0.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCDpSUkh3e5AhEJOB3LAAAAcE"]
[Thu Jul 30 11:55:43.240451 2026] [core:notice] [pid 643253:tid 643445] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:43.244748 2026] [security2:error] [pid 643253:tid 643445] [client 103.215.74.26:56512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "745"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCD8jqbtjBYzqM1uYnOAAAAD0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:44.001608 2026] [core:notice] [pid 643253:tid 643433] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:44.005752 2026] [security2:error] [pid 643253:tid 643433] [client 103.215.74.26:56518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCD8jqbtjBYzqM1uYnPAAAADE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:44.495141 2026] [security2:error] [pid 643573:tid 643716] [client 2a03:2880:f800:28:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuCD_xWyxgRnoFKAJ_8aQACGkA"]
[Thu Jul 30 11:55:44.567152 2026] [security2:error] [pid 643573:tid 643607] [remote 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuCEPxWyxgRnoFKAJ_8bwACVBo"]
[Thu Jul 30 11:55:44.567321 2026] [security2:error] [pid 643573:tid 643774] [client 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuCEPxWyxgRnoFKAJ_8bwACVBo"]
[Thu Jul 30 11:55:44.603480 2026] [security2:error] [pid 643573:tid 643781] [client 20.91.199.21:52390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/03a005685d.php"] [unique_id "amuCEPxWyxgRnoFKAJ_8cAAAAls"]
[Thu Jul 30 11:55:44.749610 2026] [core:notice] [pid 643573:tid 643830] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:44.753826 2026] [security2:error] [pid 643573:tid 643830] [client 103.215.74.26:56526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCEPxWyxgRnoFKAJ_8cQAAAow"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:45.423375 2026] [lsapi:error] [pid 643573:tid 643694] [remote 102.209.111.62:0] [host flixon.net] Error receiving response: ReceiveResponse: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1009; user ID 1009), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://flixon.net/video/teen-lust-vj-emmy/
[Thu Jul 30 11:55:45.512536 2026] [core:notice] [pid 643573:tid 643737] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:45.516489 2026] [security2:error] [pid 643573:tid 643737] [client 103.215.74.26:56528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "740"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCEfxWyxgRnoFKAJ_8gQAAAi8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:45.703587 2026] [security2:error] [pid 642360:tid 642590] [client 57.141.0.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCEZSUkh3e5AhEJOB3RAAAAfM"]
[Thu Jul 30 11:55:45.921589 2026] [security2:error] [pid 643573:tid 643776] [client 57.141.0.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCEfxWyxgRnoFKAJ_8fgAAAlY"]
[Thu Jul 30 11:55:46.123496 2026] [core:notice] [pid 643573:tid 643658] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:46.133897 2026] [core:error] [pid 643573:tid 643658] [remote 66.249.74.12:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:55:46.134110 2026] [security2:error] [pid 643573:tid 643820] [client 66.249.74.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/view/29/32.html.html.html.html.html.html.html.html.html.html"] [unique_id "amuCEfxWyxgRnoFKAJ_8hAACgk0"]
[Thu Jul 30 11:55:46.227688 2026] [security2:error] [pid 643573:tid 643777] [client 172.213.208.20:39479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amuCEvxWyxgRnoFKAJ_8hgAAAlc"]
[Thu Jul 30 11:55:46.267533 2026] [core:notice] [pid 643573:tid 643798] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:46.271268 2026] [security2:error] [pid 643573:tid 643798] [client 103.215.74.26:56540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "740"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCEvxWyxgRnoFKAJ_8hwAAAmw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:46.507912 2026] [security2:error] [pid 643573:tid 643730] [client 20.91.199.21:36500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/403.php"] [unique_id "amuCEvxWyxgRnoFKAJ_8jgAAAig"]
[Thu Jul 30 11:55:46.831710 2026] [core:notice] [pid 643573:tid 643655] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:46.993688 2026] [core:notice] [pid 643253:tid 643415] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:46.998328 2026] [security2:error] [pid 643253:tid 643415] [client 103.215.74.26:56554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCEsjqbtjBYzqM1uYnPwAAAB8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:47.121188 2026] [security2:error] [pid 643573:tid 643790] [client 2a03:2880:f800:3c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuCEvxWyxgRnoFKAJ_8jQACZEE"]
[Thu Jul 30 11:55:47.489619 2026] [security2:error] [pid 642360:tid 642517] [client 107.170.60.13:37586] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.tvs.nyx.temporary.site"] [uri "/.env"] [unique_id "amuCE5SUkh3e5AhEJOB3WgAAAao"]
[Thu Jul 30 11:55:47.731433 2026] [core:notice] [pid 643573:tid 643732] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:47.735837 2026] [security2:error] [pid 643573:tid 643732] [client 103.215.74.26:56558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCE_xWyxgRnoFKAJ_8mgAAAio"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:47.946157 2026] [security2:error] [pid 643573:tid 643792] [client 20.91.199.21:52800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/404.php"] [unique_id "amuCE_xWyxgRnoFKAJ_8nAAAAmY"]
[Thu Jul 30 11:55:48.377915 2026] [security2:error] [pid 643573:tid 643720] [client 40.77.167.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuCFPxWyxgRnoFKAJ_8nwAAAh4"]
[Thu Jul 30 11:55:48.504141 2026] [core:notice] [pid 643573:tid 643806] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:48.508388 2026] [security2:error] [pid 643573:tid 643806] [client 103.215.74.26:56574] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCFPxWyxgRnoFKAJ_8qwAAAnQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:48.687591 2026] [security2:error] [pid 643573:tid 643807] [client 113.173.144.54:44823] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCFPxWyxgRnoFKAJ_8pwAAAnU"], referer: http://pkf.jo
[Thu Jul 30 11:55:48.864339 2026] [security2:error] [pid 642360:tid 642506] [client 92.118.39.171:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bestdogproductguide.com"] [uri "/.env"] [unique_id "amuCFJSUkh3e5AhEJOB3ZAAAAZ8"]
[Thu Jul 30 11:55:48.870275 2026] [security2:error] [pid 643573:tid 643753] [client 40.77.167.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuCFPxWyxgRnoFKAJ_8rgAAAj8"]
[Thu Jul 30 11:55:49.241209 2026] [core:notice] [pid 643573:tid 643782] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:49.245387 2026] [security2:error] [pid 643573:tid 643782] [client 103.215.74.26:56578] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCFfxWyxgRnoFKAJ_8tQAAAlw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:49.253555 2026] [security2:error] [pid 643573:tid 643788] [client 92.118.39.171:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "bestdogproductguide.com"] [uri "/"] [unique_id "amuCFfxWyxgRnoFKAJ_8tgAAAmI"]
[Thu Jul 30 11:55:49.971096 2026] [security2:error] [pid 643573:tid 643722] [client 84.32.223.22:37902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCFfxWyxgRnoFKAJ_8vQAAAiA"], referer: http://pkf.jo
[Thu Jul 30 11:55:50.297398 2026] [security2:error] [pid 643573:tid 643762] [client 2a03:2880:f800:14:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuCFfxWyxgRnoFKAJ_8vAACSD8"]
[Thu Jul 30 11:55:50.811132 2026] [security2:error] [pid 643253:tid 643486] [client 216.145.84.209:49843] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCFsjqbtjBYzqM1uYnQQAAAGY"], referer: http://pkf.jo
[Thu Jul 30 11:55:51.729719 2026] [security2:error] [pid 643253:tid 643489] [client 176.241.66.87:32647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCF8jqbtjBYzqM1uYnQgAAAGk"]
[Thu Jul 30 11:55:51.729906 2026] [security2:error] [pid 643253:tid 643489] [client 176.241.66.87:32647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCF8jqbtjBYzqM1uYnQgAAAGk"]
[Thu Jul 30 11:55:52.090208 2026] [security2:error] [pid 642360:tid 642528] [client 57.141.0.1:63730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuCF5SUkh3e5AhEJOB3fQABtR4"], referer: https://igetvape-australia.com/product-tag/alibarbar-ice-adjust-12000-puffs-skittles/
[Thu Jul 30 11:55:52.272295 2026] [core:error] [pid 642360:tid 642589] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:55:52.272320 2026] [core:error] [pid 642360:tid 642589] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:55:52.296606 2026] [core:error] [pid 643253:tid 643469] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:55:52.296642 2026] [core:error] [pid 643253:tid 643469] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:55:53.083944 2026] [security2:error] [pid 643573:tid 643808] [client 185.223.152.54:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "propertyspro.com"] [uri "/"] [unique_id "amuCGfxWyxgRnoFKAJ_82QAAAnY"]
[Thu Jul 30 11:55:53.150547 2026] [security2:error] [pid 643573:tid 643761] [client 20.91.199.21:53489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/aa.php"] [unique_id "amuCGfxWyxgRnoFKAJ_82wAAAkc"]
[Thu Jul 30 11:55:53.462861 2026] [security2:error] [pid 643573:tid 643759] [client 2a03:2880:f800:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuCGPxWyxgRnoFKAJ_81AACRVQ"]
[Thu Jul 30 11:55:53.521968 2026] [security2:error] [pid 643253:tid 643499] [client 57.141.0.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCGMjqbtjBYzqM1uYnRQAAAHM"]
[Thu Jul 30 11:55:53.793161 2026] [security2:error] [pid 643573:tid 643831] [client 185.223.152.54:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "propertyspro.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "amuCGfxWyxgRnoFKAJ_84gAAAo0"]
[Thu Jul 30 11:55:53.824609 2026] [security2:error] [pid 643573:tid 643722] [client 20.91.199.21:53015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/aafewc0k.php"] [unique_id "amuCGfxWyxgRnoFKAJ_85AAAAiA"]
[Thu Jul 30 11:55:53.983914 2026] [security2:error] [pid 643573:tid 643738] [client 57.141.0.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCGfxWyxgRnoFKAJ_83gAAAjA"]
[Thu Jul 30 11:55:54.476149 2026] [core:notice] [pid 643573:tid 643754] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:54.541232 2026] [security2:error] [pid 643573:tid 643732] [client 185.223.152.54:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "propertyspro.com"] [uri "/media/system/js/core.js"] [unique_id "amuCGvxWyxgRnoFKAJ_87AAAAio"]
[Thu Jul 30 11:55:54.901077 2026] [security2:error] [pid 643573:tid 643734] [client 20.91.199.21:53503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/abcd.php"] [unique_id "amuCGvxWyxgRnoFKAJ_87wAAAiw"]
[Thu Jul 30 11:55:54.972273 2026] [core:notice] [pid 643253:tid 643430] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:54.979506 2026] [security2:error] [pid 643253:tid 643430] [client 103.215.74.26:42440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCGsjqbtjBYzqM1uYnSQAAAC4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:55.722107 2026] [core:notice] [pid 643253:tid 643400] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:55.726582 2026] [security2:error] [pid 643253:tid 643400] [client 103.215.74.26:42464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCG8jqbtjBYzqM1uYnUQAAABA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:56.207951 2026] [security2:error] [pid 643573:tid 643713] [client 20.91.199.21:52858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/about.php"] [unique_id "amuCHPxWyxgRnoFKAJ_8-gAAAhc"]
[Thu Jul 30 11:55:56.455644 2026] [core:notice] [pid 643253:tid 643440] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:56.460503 2026] [security2:error] [pid 643253:tid 643440] [client 103.215.74.26:42470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCHMjqbtjBYzqM1uYnUwAAADg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:56.851200 2026] [security2:error] [pid 643573:tid 643737] [client 216.73.216.144:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aakmiddleast.com"] [uri "/index.php"] [unique_id "amuCHPxWyxgRnoFKAJ_8_AACLwE"]
[Thu Jul 30 11:55:57.203618 2026] [core:notice] [pid 643573:tid 643753] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:57.208003 2026] [security2:error] [pid 643573:tid 643753] [client 103.215.74.26:42476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCHfxWyxgRnoFKAJ_8_wAAAj8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:57.871640 2026] [security2:error] [pid 643573:tid 643681] [remote 47.86.33.52:4076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-login.php"] [unique_id "amuCHfxWyxgRnoFKAJ_9BgACUGQ"]
[Thu Jul 30 11:55:57.937387 2026] [core:notice] [pid 643573:tid 643837] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:57.941748 2026] [security2:error] [pid 643573:tid 643837] [client 103.215.74.26:42484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCHfxWyxgRnoFKAJ_9CAAAApM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:58.078056 2026] [security2:error] [pid 643253:tid 643418] [client 172.213.208.20:42369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/inputs.php"] [unique_id "amuCHsjqbtjBYzqM1uYnVQAAACI"]
[Thu Jul 30 11:55:58.665919 2026] [core:notice] [pid 642360:tid 642578] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:58.669842 2026] [security2:error] [pid 642360:tid 642578] [client 103.215.74.26:42496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "740"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCHpSUkh3e5AhEJOB3vgAAAec"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:59.064531 2026] [core:notice] [pid 643573:tid 643819] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:59.413040 2026] [core:notice] [pid 643573:tid 643786] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:59.416971 2026] [security2:error] [pid 643573:tid 643786] [client 103.215.74.26:42510] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCH_xWyxgRnoFKAJ_9IAAAAmA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:00.148322 2026] [core:notice] [pid 643573:tid 643720] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:00.152215 2026] [security2:error] [pid 643573:tid 643720] [client 103.215.74.26:42516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCIPxWyxgRnoFKAJ_9NgAAAh4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:00.539740 2026] [security2:error] [pid 643573:tid 643813] [client 172.213.208.20:39461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-content/index.php"] [unique_id "amuCIPxWyxgRnoFKAJ_9QAAAAns"]
[Thu Jul 30 11:56:00.542027 2026] [security2:error] [pid 643573:tid 643781] [client 20.91.199.21:52848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/admin.php"] [unique_id "amuCIPxWyxgRnoFKAJ_9QQAAAls"]
[Thu Jul 30 11:56:00.898362 2026] [core:notice] [pid 643573:tid 643736] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:00.902702 2026] [security2:error] [pid 643573:tid 643736] [client 103.215.74.26:42528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCIPxWyxgRnoFKAJ_9SgAAAi4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:01.155910 2026] [security2:error] [pid 643573:tid 643808] [client 172.213.208.20:52539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-admin/network/index.php"] [unique_id "amuCIfxWyxgRnoFKAJ_9VgAAAnY"]
[Thu Jul 30 11:56:01.240151 2026] [security2:error] [pid 643573:tid 643766] [client 20.91.199.21:53051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/adminfuns.php"] [unique_id "amuCIfxWyxgRnoFKAJ_9XwAAAkw"]
[Thu Jul 30 11:56:01.655536 2026] [core:notice] [pid 643573:tid 643722] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:01.666415 2026] [security2:error] [pid 643573:tid 643722] [client 103.215.74.26:42544] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCIfxWyxgRnoFKAJ_9aAAAAiA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:01.736512 2026] [security2:error] [pid 643573:tid 643761] [client 172.237.109.114:58484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCIfxWyxgRnoFKAJ_9UQAAAkc"]
[Thu Jul 30 11:56:01.739819 2026] [security2:error] [pid 643573:tid 643811] [client 172.237.109.114:18963] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCIfxWyxgRnoFKAJ_9UAAAAnk"]
[Thu Jul 30 11:56:01.740385 2026] [security2:error] [pid 642360:tid 642611] [client 172.237.109.114:40852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCIZSUkh3e5AhEJOB30wAAAgg"]
[Thu Jul 30 11:56:01.791721 2026] [security2:error] [pid 642360:tid 642570] [client 172.237.109.114:16091] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCIZSUkh3e5AhEJOB31AAAAd8"]
[Thu Jul 30 11:56:01.810381 2026] [security2:error] [pid 643573:tid 643777] [client 172.237.109.114:60802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCIfxWyxgRnoFKAJ_9VQAAAlc"]
[Thu Jul 30 11:56:01.847043 2026] [security2:error] [pid 643573:tid 643779] [client 172.213.208.20:39473] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-content/1.php"] [unique_id "amuCIfxWyxgRnoFKAJ_9bgAAAlk"]
[Thu Jul 30 11:56:01.847160 2026] [security2:error] [pid 643573:tid 643779] [client 172.213.208.20:39473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-content/1.php"] [unique_id "amuCIfxWyxgRnoFKAJ_9bgAAAlk"]
[Thu Jul 30 11:56:02.149992 2026] [core:notice] [pid 643573:tid 643630] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:02.374668 2026] [security2:error] [pid 643573:tid 643784] [client 176.241.66.87:50762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCIvxWyxgRnoFKAJ_9egAAAl4"]
[Thu Jul 30 11:56:02.374807 2026] [security2:error] [pid 643573:tid 643784] [client 176.241.66.87:50762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCIvxWyxgRnoFKAJ_9egAAAl4"]
[Thu Jul 30 11:56:02.417806 2026] [core:notice] [pid 643573:tid 643768] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:02.424438 2026] [security2:error] [pid 643573:tid 643768] [client 103.215.74.26:42560] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCIvxWyxgRnoFKAJ_9ewAAAk4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:02.783329 2026] [security2:error] [pid 643573:tid 643821] [client 20.91.199.21:53038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/albin.php"] [unique_id "amuCIvxWyxgRnoFKAJ_9gwAAAoM"]
[Thu Jul 30 11:56:03.147471 2026] [core:notice] [pid 643573:tid 643781] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:03.152638 2026] [security2:error] [pid 643573:tid 643781] [client 103.215.74.26:46542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "740"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCI_xWyxgRnoFKAJ_9igAAAls"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:03.174566 2026] [security2:error] [pid 643573:tid 643750] [client 2a03:2880:f800:43:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuCIvxWyxgRnoFKAJ_9fQACPDg"]
[Thu Jul 30 11:56:03.264516 2026] [core:notice] [pid 643573:tid 643837] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:03.888863 2026] [core:notice] [pid 642360:tid 642614] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:03.892830 2026] [security2:error] [pid 642360:tid 642614] [client 103.215.74.26:46548] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCI5SUkh3e5AhEJOB37wAAAgs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:04.099414 2026] [core:notice] [pid 643573:tid 643809] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:04.502060 2026] [security2:error] [pid 643573:tid 643740] [client 20.91.199.21:56516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/amfsqvgv.php"] [unique_id "amuCJPxWyxgRnoFKAJ_9rQAAAjI"]
[Thu Jul 30 11:56:05.043598 2026] [security2:error] [pid 643573:tid 643727] [client 20.91.199.21:36452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/ant.php"] [unique_id "amuCJfxWyxgRnoFKAJ_97gAAAiU"]
[Thu Jul 30 11:56:05.485650 2026] [proxy:error] [pid 642360:tid 642376] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:56:05.485707 2026] [proxy_http:error] [pid 642360:tid 642376] [remote 74.7.175.156:41440] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:56:05.486564 2026] [proxy:error] [pid 642360:tid 642376] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:56:05.486613 2026] [proxy_http:error] [pid 642360:tid 642376] [remote 74.7.175.156:41440] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:56:05.652266 2026] [security2:error] [pid 643573:tid 643729] [client 172.237.109.114:39866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCJfxWyxgRnoFKAJ_97wAAAic"]
[Thu Jul 30 11:56:05.666767 2026] [security2:error] [pid 643573:tid 643763] [client 172.237.109.114:49264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCJfxWyxgRnoFKAJ_98AAAAkk"]
[Thu Jul 30 11:56:05.803892 2026] [security2:error] [pid 643573:tid 643711] [client 50.6.43.217:36196] ModSecurity: Warning. Matched phrase "fq" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "alseermarine.com"] [uri "/wp-cron.php"] [unique_id "amuCJfxWyxgRnoFKAJ_9_AAAAhU"]
[Thu Jul 30 11:56:05.810153 2026] [security2:error] [pid 642360:tid 642492] [client 172.237.109.114:35171] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCJZSUkh3e5AhEJOB3-AAAAZE"]
[Thu Jul 30 11:56:05.810855 2026] [security2:error] [pid 643573:tid 643764] [client 172.237.109.114:47124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCJfxWyxgRnoFKAJ_98QAAAko"]
[Thu Jul 30 11:56:05.819358 2026] [security2:error] [pid 643573:tid 643830] [client 172.237.109.114:29950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCJfxWyxgRnoFKAJ_98gAAAow"]
[Thu Jul 30 11:56:05.929258 2026] [security2:error] [pid 643573:tid 643803] [client 20.91.199.21:53000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/appreciators.php"] [unique_id "amuCJfxWyxgRnoFKAJ_-BwAAAnE"]
[Thu Jul 30 11:56:06.034587 2026] [security2:error] [pid 643573:tid 643783] [client 2a03:2880:f800:41:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuCJfxWyxgRnoFKAJ_99AACXRE"]
[Thu Jul 30 11:56:06.065850 2026] [core:notice] [pid 643573:tid 643621] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:06.069660 2026] [security2:error] [pid 643573:tid 643737] [client 66.249.65.202:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/view/230/224"] [unique_id "amuCJfxWyxgRnoFKAJ_-AQACLyg"]
[Thu Jul 30 11:56:06.391082 2026] [security2:error] [pid 643573:tid 643743] [client 41.108.145.88:48432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCJvxWyxgRnoFKAJ_-CgAAAjU"], referer: http://pkf.jo
[Thu Jul 30 11:56:06.663870 2026] [security2:error] [pid 643573:tid 643821] [client 65.55.210.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dapperdangolf.com"] [uri "/index.php"] [unique_id "amuCJvxWyxgRnoFKAJ_-EQACg10"]
[Thu Jul 30 11:56:06.748677 2026] [security2:error] [pid 643573:tid 643807] [client 20.91.199.21:52395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/archive.php"] [unique_id "amuCJvxWyxgRnoFKAJ_-EgAAAnU"]
[Thu Jul 30 11:56:07.009322 2026] [proxy:error] [pid 643573:tid 643798] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:56:07.009397 2026] [proxy_http:error] [pid 643573:tid 643798] [client 193.47.62.167:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:56:07.009947 2026] [proxy:error] [pid 643573:tid 643798] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:56:07.010000 2026] [proxy_http:error] [pid 643573:tid 643798] [client 193.47.62.167:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:56:07.240312 2026] [core:notice] [pid 643573:tid 643633] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:07.772139 2026] [core:notice] [pid 643573:tid 643796] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:08.497544 2026] [security2:error] [pid 643253:tid 643371] [remote 57.141.0.5:64302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/626900273/feed/rss2/"] [unique_id "amuCKMjqbtjBYzqM1uYnWQAAOnQ"]
[Thu Jul 30 11:56:09.076094 2026] [security2:error] [pid 642360:tid 642616] [client 20.91.199.21:52356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/as.php"] [unique_id "amuCKZSUkh3e5AhEJOB4HgAAAg0"]
[Thu Jul 30 11:56:09.166308 2026] [security2:error] [pid 643573:tid 643645] [remote 151.158.180.11:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.180.158.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "itrnetwork.org"] [uri "/wp-login.php"] [unique_id "amuCKfxWyxgRnoFKAJ_-JgACOkA"]
[Thu Jul 30 11:56:09.609749 2026] [core:notice] [pid 643573:tid 643786] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:09.616111 2026] [security2:error] [pid 643573:tid 643786] [client 103.215.74.26:46550] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCKfxWyxgRnoFKAJ_-MAAAAmA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:10.085395 2026] [security2:error] [pid 642360:tid 642584] [client 172.213.208.20:44865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/plugin.php"] [unique_id "amuCKpSUkh3e5AhEJOB4KAAAAe0"]
[Thu Jul 30 11:56:10.365320 2026] [core:notice] [pid 643573:tid 643774] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:10.369241 2026] [security2:error] [pid 643573:tid 643774] [client 103.215.74.26:46554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "771"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCKvxWyxgRnoFKAJ_-PQAAAlQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:10.617197 2026] [security2:error] [pid 643573:tid 643800] [client 20.91.199.21:52353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/atomlib.php"] [unique_id "amuCKvxWyxgRnoFKAJ_-QQAAAm4"]
[Thu Jul 30 11:56:11.094218 2026] [core:notice] [pid 643573:tid 643720] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:11.098139 2026] [security2:error] [pid 643573:tid 643720] [client 103.215.74.26:46564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "733"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCK_xWyxgRnoFKAJ_-SQAAAh4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:11.856447 2026] [core:notice] [pid 643573:tid 643745] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:11.861504 2026] [security2:error] [pid 643573:tid 643745] [client 103.215.74.26:46576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "737"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCK_xWyxgRnoFKAJ_-UQAAAjc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:12.029295 2026] [security2:error] [pid 643573:tid 643735] [client 20.91.199.21:52860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/autoload_classmap.php"] [unique_id "amuCLPxWyxgRnoFKAJ_-UwAAAi0"]
[Thu Jul 30 11:56:12.579509 2026] [security2:error] [pid 643573:tid 643822] [client 172.213.208.20:18152] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/1.php"] [unique_id "amuCLPxWyxgRnoFKAJ_-VgAAAoQ"]
[Thu Jul 30 11:56:12.579634 2026] [security2:error] [pid 643573:tid 643822] [client 172.213.208.20:18152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/1.php"] [unique_id "amuCLPxWyxgRnoFKAJ_-VgAAAoQ"]
[Thu Jul 30 11:56:12.616421 2026] [core:notice] [pid 643573:tid 643750] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:12.620551 2026] [security2:error] [pid 643573:tid 643750] [client 103.215.74.26:46578] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCLPxWyxgRnoFKAJ_-WAAAAjw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:13.019873 2026] [security2:error] [pid 643573:tid 643837] [client 176.241.66.87:33991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCLfxWyxgRnoFKAJ_-YAAAApM"]
[Thu Jul 30 11:56:13.020044 2026] [security2:error] [pid 643573:tid 643837] [client 176.241.66.87:33991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCLfxWyxgRnoFKAJ_-YAAAApM"]
[Thu Jul 30 11:56:13.343468 2026] [core:notice] [pid 642360:tid 642534] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:13.348121 2026] [security2:error] [pid 642360:tid 642534] [client 103.215.74.26:44130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCLZSUkh3e5AhEJOB4TQAAAbs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:13.610782 2026] [security2:error] [pid 643573:tid 643714] [client 172.213.208.20:34081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/gg.php"] [unique_id "amuCLfxWyxgRnoFKAJ_-aQAAAhg"]
[Thu Jul 30 11:56:13.871129 2026] [security2:error] [pid 643573:tid 643817] [client 20.91.199.21:36479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/bb.php"] [unique_id "amuCLfxWyxgRnoFKAJ_-bQAAAn8"]
[Thu Jul 30 11:56:14.084018 2026] [security2:error] [pid 643253:tid 643502] [client 57.141.0.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCLcjqbtjBYzqM1uYnXAAAAHY"]
[Thu Jul 30 11:56:14.105023 2026] [core:notice] [pid 643573:tid 643761] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:14.111538 2026] [security2:error] [pid 643573:tid 643761] [client 103.215.74.26:44138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "732"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCLvxWyxgRnoFKAJ_-bwAAAkc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:14.339161 2026] [security2:error] [pid 642360:tid 642610] [client 57.141.0.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCLZSUkh3e5AhEJOB4UgAAAgc"]
[Thu Jul 30 11:56:14.841660 2026] [core:notice] [pid 643573:tid 643716] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:14.845632 2026] [security2:error] [pid 643573:tid 643716] [client 103.215.74.26:44142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "732"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCLvxWyxgRnoFKAJ_-cgAAAho"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:16.165199 2026] [security2:error] [pid 643573:tid 643746] [client 20.91.199.21:36424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/bnm.php"] [unique_id "amuCMPxWyxgRnoFKAJ_-xwAAAjg"]
[Thu Jul 30 11:56:16.713710 2026] [security2:error] [pid 643573:tid 643751] [client 20.91.199.21:52998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/bootstrap.php"] [unique_id "amuCMPxWyxgRnoFKAJ_-0QAAAj0"]
[Thu Jul 30 11:56:17.726971 2026] [security2:error] [pid 642360:tid 642544] [client 20.91.199.21:53048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/buy.php"] [unique_id "amuCMZSUkh3e5AhEJOB4eQAAAcU"]
[Thu Jul 30 11:56:18.652779 2026] [security2:error] [pid 643253:tid 643397] [client 20.91.199.21:52838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/chosen.php"] [unique_id "amuCMsjqbtjBYzqM1uYnYAAAAA0"]
[Thu Jul 30 11:56:18.700821 2026] [security2:error] [pid 643253:tid 643417] [client 66.249.73.98:61057] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCMsjqbtjBYzqM1uYnXwAAACE"]
[Thu Jul 30 11:56:18.941399 2026] [core:notice] [pid 643573:tid 643632] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:19.578219 2026] [security2:error] [pid 642360:tid 642535] [client 2a03:2880:f800:9:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuCMpSUkh3e5AhEJOB4iQABvGE"]
[Thu Jul 30 11:56:19.792496 2026] [security2:error] [pid 643573:tid 643785] [client 173.249.217.7:41688] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuCM_xWyxgRnoFKAJ__EgAAAl8"]
[Thu Jul 30 11:56:19.792600 2026] [security2:error] [pid 643573:tid 643785] [client 173.249.217.7:41688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuCM_xWyxgRnoFKAJ__EgAAAl8"]
[Thu Jul 30 11:56:19.822314 2026] [security2:error] [pid 643253:tid 643402] [client 182.10.183.57:6994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCM8jqbtjBYzqM1uYnYwAAABI"], referer: http://pkf.jo
[Thu Jul 30 11:56:20.634345 2026] [core:notice] [pid 643573:tid 643723] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:20.638554 2026] [security2:error] [pid 643573:tid 643723] [client 103.215.74.26:44146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCNPxWyxgRnoFKAJ__KwAAAiE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:20.717814 2026] [security2:error] [pid 643573:tid 643773] [client 203.175.125.36:58427] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "fireworkskenya.co.ke"] [uri "/wp-json/batch/v1"] [unique_id "amuCNPxWyxgRnoFKAJ__LQAAAlM"]
[Thu Jul 30 11:56:20.739228 2026] [security2:error] [pid 642360:tid 642538] [client 57.141.0.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCNJSUkh3e5AhEJOB4mAAAAb8"]
[Thu Jul 30 11:56:21.412477 2026] [security2:error] [pid 643573:tid 643765] [client 172.213.208.20:45826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp.php"] [unique_id "amuCNfxWyxgRnoFKAJ__OwAAAks"]
[Thu Jul 30 11:56:21.426735 2026] [security2:error] [pid 643573:tid 643719] [client 2a03:2880:f800:45:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuCNPxWyxgRnoFKAJ__MAACHV4"]
[Thu Jul 30 11:56:21.903545 2026] [security2:error] [pid 642360:tid 642477] [remote 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuCNZSUkh3e5AhEJOB4pQAB53Q"]
[Thu Jul 30 11:56:21.903745 2026] [security2:error] [pid 642360:tid 642578] [client 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuCNZSUkh3e5AhEJOB4pQAB53Q"]
[Thu Jul 30 11:56:22.020941 2026] [security2:error] [pid 643573:tid 643758] [client 108.52.149.162:56222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCNfxWyxgRnoFKAJ__TwAAAkQ"], referer: http://pkf.jo
[Thu Jul 30 11:56:22.380723 2026] [security2:error] [pid 643573:tid 643732] [client 172.213.208.20:32323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuCNvxWyxgRnoFKAJ__kAAAAio"]
[Thu Jul 30 11:56:22.932863 2026] [security2:error] [pid 643573:tid 643727] [client 223.123.111.153:12226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCNvxWyxgRnoFKAJ__kwAAAiU"], referer: http://pkf.jo
[Thu Jul 30 11:56:23.593075 2026] [security2:error] [pid 642360:tid 642589] [client 176.241.66.87:51862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCN5SUkh3e5AhEJOB4tQAAAfI"]
[Thu Jul 30 11:56:23.593219 2026] [security2:error] [pid 642360:tid 642589] [client 176.241.66.87:51862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCN5SUkh3e5AhEJOB4tQAAAfI"]
[Thu Jul 30 11:56:23.718122 2026] [security2:error] [pid 642360:tid 642583] [client 20.91.199.21:49375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/class-wp-image.php"] [unique_id "amuCN5SUkh3e5AhEJOB4tgAAAew"]
[Thu Jul 30 11:56:24.479754 2026] [security2:error] [pid 643573:tid 643787] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "embassyofspaininpakistan.info"] [uri "/media/system/js/core.js"] [unique_id "amuCOPxWyxgRnoFKAJ__mgAAAmE"]
[Thu Jul 30 11:56:25.353669 2026] [security2:error] [pid 643573:tid 643801] [client 20.91.199.21:36417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/classsmtps.php"] [unique_id "amuCOfxWyxgRnoFKAJ__oAAAAm8"]
[Thu Jul 30 11:56:25.684868 2026] [security2:error] [pid 642360:tid 642497] [client 172.213.208.20:20401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-admin/file.php"] [unique_id "amuCOZSUkh3e5AhEJOB4wwAAAZY"]
[Thu Jul 30 11:56:25.782451 2026] [core:notice] [pid 643253:tid 643504] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:26.137337 2026] [security2:error] [pid 643573:tid 643766] [client 20.91.199.21:56831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/classwithtostring.php"] [unique_id "amuCOvxWyxgRnoFKAJ__pAAAAkw"]
[Thu Jul 30 11:56:26.365592 2026] [core:notice] [pid 643573:tid 643831] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:26.372751 2026] [security2:error] [pid 643573:tid 643831] [client 103.215.74.26:61518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCOvxWyxgRnoFKAJ__pQAAAo0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:27.103601 2026] [core:notice] [pid 642360:tid 642491] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:27.108128 2026] [security2:error] [pid 642360:tid 642491] [client 103.215.74.26:61526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCO5SUkh3e5AhEJOB40QAAAZA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:27.648599 2026] [security2:error] [pid 643573:tid 643722] [client 172.213.208.20:31243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-admin/user/index.php"] [unique_id "amuCO_xWyxgRnoFKAJ__sAAAAiA"]
[Thu Jul 30 11:56:27.885523 2026] [security2:error] [pid 643253:tid 643433] [client 20.91.199.21:53006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/config.php"] [unique_id "amuCO8jqbtjBYzqM1uYndAAAADE"]
[Thu Jul 30 11:56:28.526567 2026] [security2:error] [pid 643253:tid 643448] [client 20.91.199.21:49797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/core.php"] [unique_id "amuCPMjqbtjBYzqM1uYndQAAAEA"]
[Thu Jul 30 11:56:28.696375 2026] [security2:error] [pid 642360:tid 642610] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuCPJSUkh3e5AhEJOB44AAAAgc"]
[Thu Jul 30 11:56:28.696498 2026] [security2:error] [pid 642360:tid 642610] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuCPJSUkh3e5AhEJOB44AAAAgc"]
[Thu Jul 30 11:56:29.073583 2026] [security2:error] [pid 643573:tid 643602] [remote 74.7.241.60:57380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/img/article.php"] [unique_id "amuCPfxWyxgRnoFKAJ__vQACWBU"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/img/main_image_6a2a8e70efd49.jpg
[Thu Jul 30 11:56:29.180482 2026] [security2:error] [pid 643573:tid 643737] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuCPfxWyxgRnoFKAJ__vgAAAi8"]
[Thu Jul 30 11:56:29.180591 2026] [security2:error] [pid 643573:tid 643737] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuCPfxWyxgRnoFKAJ__vgAAAi8"]
[Thu Jul 30 11:56:29.500355 2026] [security2:error] [pid 642360:tid 642608] [client 172.213.208.20:24082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amuCPZSUkh3e5AhEJOB46gAAAgU"]
[Thu Jul 30 11:56:29.697375 2026] [security2:error] [pid 642360:tid 642540] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/xstelth.php"] [unique_id "amuCPZSUkh3e5AhEJOB47gAAAcE"]
[Thu Jul 30 11:56:29.697495 2026] [security2:error] [pid 642360:tid 642540] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/xstelth.php"] [unique_id "amuCPZSUkh3e5AhEJOB47gAAAcE"]
[Thu Jul 30 11:56:29.959350 2026] [security2:error] [pid 643253:tid 643415] [client 57.141.0.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCPcjqbtjBYzqM1uYndwAAAB8"]
[Thu Jul 30 11:56:29.995740 2026] [security2:error] [pid 643573:tid 643822] [client 20.91.199.21:49403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/css.php"] [unique_id "amuCPfxWyxgRnoFKAJ__wgAAAoQ"]
[Thu Jul 30 11:56:30.186144 2026] [security2:error] [pid 642360:tid 642498] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/584062352875874akp.php"] [unique_id "amuCPpSUkh3e5AhEJOB49QAAAZc"]
[Thu Jul 30 11:56:30.186257 2026] [security2:error] [pid 642360:tid 642498] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/584062352875874akp.php"] [unique_id "amuCPpSUkh3e5AhEJOB49QAAAZc"]
[Thu Jul 30 11:56:30.243737 2026] [security2:error] [pid 642360:tid 642574] [client 172.213.208.20:49771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/index/function.php"] [unique_id "amuCPpSUkh3e5AhEJOB49gAAAeM"]
[Thu Jul 30 11:56:30.333391 2026] [security2:error] [pid 643253:tid 643427] [client 50.6.43.217:28012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuCPcjqbtjBYzqM1uYneAAAACs"]
[Thu Jul 30 11:56:30.691259 2026] [security2:error] [pid 643253:tid 643414] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/newfile.php"] [unique_id "amuCPsjqbtjBYzqM1uYnewAAAB4"]
[Thu Jul 30 11:56:30.691424 2026] [security2:error] [pid 643253:tid 643414] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/newfile.php"] [unique_id "amuCPsjqbtjBYzqM1uYnewAAAB4"]
[Thu Jul 30 11:56:31.052263 2026] [security2:error] [pid 642360:tid 642598] [client 50.6.43.217:28026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuCPpSUkh3e5AhEJOB49wAAAfs"]
[Thu Jul 30 11:56:31.150515 2026] [security2:error] [pid 643253:tid 643489] [client 57.141.0.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCPsjqbtjBYzqM1uYneQAAAGk"]
[Thu Jul 30 11:56:31.175879 2026] [security2:error] [pid 643573:tid 643836] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/tBEZGQz.php"] [unique_id "amuCP_xWyxgRnoFKAJ__yQAAApI"]
[Thu Jul 30 11:56:31.175968 2026] [security2:error] [pid 643573:tid 643836] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/tBEZGQz.php"] [unique_id "amuCP_xWyxgRnoFKAJ__yQAAApI"]
[Thu Jul 30 11:56:31.700272 2026] [security2:error] [pid 643573:tid 643712] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.propertyspro.com"] [uri "/___proxy_subdomain_webdisk/phpinfo"] [unique_id "amuCP_xWyxgRnoFKAJ__zgAAAhY"]
[Thu Jul 30 11:56:31.960134 2026] [security2:error] [pid 643573:tid 643816] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/drykl.php"] [unique_id "amuCP_xWyxgRnoFKAJ__0gAAAn4"]
[Thu Jul 30 11:56:31.960259 2026] [security2:error] [pid 643573:tid 643816] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/drykl.php"] [unique_id "amuCP_xWyxgRnoFKAJ__0gAAAn4"]
[Thu Jul 30 11:56:32.089319 2026] [core:notice] [pid 643573:tid 643584] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:32.494972 2026] [security2:error] [pid 643573:tid 643759] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.propertyspro.com"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/colors/blue/"] [unique_id "amuCQPxWyxgRnoFKAJ__2AAAAkU"]
[Thu Jul 30 11:56:32.557361 2026] [security2:error] [pid 642360:tid 642544] [client 20.91.199.21:52804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/database.php"] [unique_id "amuCQJSUkh3e5AhEJOB5DQAAAcU"]
[Thu Jul 30 11:56:32.857277 2026] [core:notice] [pid 643573:tid 643790] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:32.861674 2026] [security2:error] [pid 643573:tid 643790] [client 103.215.74.26:61536] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCQPxWyxgRnoFKAJ__3QAAAmQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:32.980851 2026] [security2:error] [pid 642360:tid 642530] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/ls.php"] [unique_id "amuCQJSUkh3e5AhEJOB5EAAAAbc"]
[Thu Jul 30 11:56:32.980964 2026] [security2:error] [pid 642360:tid 642530] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/ls.php"] [unique_id "amuCQJSUkh3e5AhEJOB5EAAAAbc"]
[Thu Jul 30 11:56:33.485352 2026] [security2:error] [pid 643573:tid 643764] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/dx.php"] [unique_id "amuCQfxWyxgRnoFKAJ__5QAAAko"]
[Thu Jul 30 11:56:33.485457 2026] [security2:error] [pid 643573:tid 643764] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/dx.php"] [unique_id "amuCQfxWyxgRnoFKAJ__5QAAAko"]
[Thu Jul 30 11:56:33.595214 2026] [core:notice] [pid 643573:tid 643720] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:33.599599 2026] [security2:error] [pid 643573:tid 643720] [client 103.215.74.26:17794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCQfxWyxgRnoFKAJ__5gAAAh4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:33.755005 2026] [security2:error] [pid 643573:tid 643833] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/mac.php"] [unique_id "amuCQfxWyxgRnoFKAJ__7QAAAo8"]
[Thu Jul 30 11:56:33.755136 2026] [security2:error] [pid 643573:tid 643833] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/mac.php"] [unique_id "amuCQfxWyxgRnoFKAJ__7QAAAo8"]
[Thu Jul 30 11:56:33.804844 2026] [core:error] [pid 643573:tid 643812] [client 74.7.230.45:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:56:33.804868 2026] [core:error] [pid 643573:tid 643812] [client 74.7.230.45:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:56:33.804987 2026] [security2:error] [pid 643573:tid 643812] [client 74.7.230.45:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.mhh.zzt.temporary.site"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amuCQfxWyxgRnoFKAJ__8AAAAno"]
[Thu Jul 30 11:56:33.805596 2026] [security2:error] [pid 643573:tid 643756] [client 74.7.230.45:48142] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.mhh.zzt.temporary.site"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amuCQfxWyxgRnoFKAJ__7gACQms"]
[Thu Jul 30 11:56:34.000274 2026] [security2:error] [pid 642360:tid 642549] [client 57.141.0.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCQZSUkh3e5AhEJOB5FAAAAco"]
[Thu Jul 30 11:56:34.299501 2026] [security2:error] [pid 643573:tid 643807] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/485.php"] [unique_id "amuCQvxWyxgRnoFKAJ__9QAAAnU"]
[Thu Jul 30 11:56:34.299589 2026] [security2:error] [pid 643573:tid 643807] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/485.php"] [unique_id "amuCQvxWyxgRnoFKAJ__9QAAAnU"]
[Thu Jul 30 11:56:34.302602 2026] [security2:error] [pid 643573:tid 643770] [client 176.241.66.87:52410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCQvxWyxgRnoFKAJ__9gAAAlA"]
[Thu Jul 30 11:56:34.302732 2026] [security2:error] [pid 643573:tid 643770] [client 176.241.66.87:52410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCQvxWyxgRnoFKAJ__9gAAAlA"]
[Thu Jul 30 11:56:34.340258 2026] [security2:error] [pid 643573:tid 643731] [client 110.249.202.228:36196] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.shorewooddaycare.com"] [uri "/robots.txt"] [unique_id "amuCQvxWyxgRnoFKAJ__9wAAAik"]
[Thu Jul 30 11:56:34.810531 2026] [security2:error] [pid 642360:tid 642581] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/gelio1.php"] [unique_id "amuCQpSUkh3e5AhEJOB5HAAAAeo"]
[Thu Jul 30 11:56:34.810663 2026] [security2:error] [pid 642360:tid 642581] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/gelio1.php"] [unique_id "amuCQpSUkh3e5AhEJOB5HAAAAeo"]
[Thu Jul 30 11:56:34.957454 2026] [security2:error] [pid 643573:tid 643831] [client 143.244.57.92:50964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kamiliacademy.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuCQvxWyxgRnoFKAJ8ABwAAAo0"]
[Thu Jul 30 11:56:35.330197 2026] [security2:error] [pid 642360:tid 642506] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/lp6.php"] [unique_id "amuCQ5SUkh3e5AhEJOB5IwAAAZ8"]
[Thu Jul 30 11:56:35.330329 2026] [security2:error] [pid 642360:tid 642506] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/lp6.php"] [unique_id "amuCQ5SUkh3e5AhEJOB5IwAAAZ8"]
[Thu Jul 30 11:56:35.765601 2026] [security2:error] [pid 643573:tid 643780] [client 143.244.57.92:45626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kamiliacademy.com"] [uri "/xmlrpc.php"] [unique_id "amuCQ_xWyxgRnoFKAJ8AEwAAAlo"]
[Thu Jul 30 11:56:35.876008 2026] [security2:error] [pid 643573:tid 643717] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuCQ_xWyxgRnoFKAJ8AFwAAAhs"]
[Thu Jul 30 11:56:35.876109 2026] [security2:error] [pid 643573:tid 643717] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuCQ_xWyxgRnoFKAJ8AFwAAAhs"]
[Thu Jul 30 11:56:36.423000 2026] [security2:error] [pid 642360:tid 642502] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.propertyspro.com"] [uri "/___proxy_subdomain_webdisk/wp-includes/sodium_compat/"] [unique_id "amuCRJSUkh3e5AhEJOB5KgAAAZs"]
[Thu Jul 30 11:56:36.529797 2026] [core:notice] [pid 643573:tid 643618] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:36.674525 2026] [security2:error] [pid 642360:tid 642592] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/w3llscc.php"] [unique_id "amuCRJSUkh3e5AhEJOB5KwAAAfU"]
[Thu Jul 30 11:56:36.674642 2026] [security2:error] [pid 642360:tid 642592] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/w3llscc.php"] [unique_id "amuCRJSUkh3e5AhEJOB5KwAAAfU"]
[Thu Jul 30 11:56:37.180839 2026] [security2:error] [pid 643573:tid 643734] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/miru3.php"] [unique_id "amuCRfxWyxgRnoFKAJ8AJQAAAiw"]
[Thu Jul 30 11:56:37.180955 2026] [security2:error] [pid 643573:tid 643734] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/miru3.php"] [unique_id "amuCRfxWyxgRnoFKAJ8AJQAAAiw"]
[Thu Jul 30 11:56:37.635317 2026] [security2:error] [pid 643573:tid 643794] [client 20.91.199.21:36028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/db.php"] [unique_id "amuCRfxWyxgRnoFKAJ8AOQAAAmg"]
[Thu Jul 30 11:56:37.693033 2026] [security2:error] [pid 643573:tid 643823] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/autoload_classmap.php"] [unique_id "amuCRfxWyxgRnoFKAJ8AOgAAAoU"]
[Thu Jul 30 11:56:37.693146 2026] [security2:error] [pid 643573:tid 643823] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/autoload_classmap.php"] [unique_id "amuCRfxWyxgRnoFKAJ8AOgAAAoU"]
[Thu Jul 30 11:56:38.223582 2026] [security2:error] [pid 643573:tid 643740] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.propertyspro.com"] [uri "/___proxy_subdomain_webdisk/wp-content/"] [unique_id "amuCRvxWyxgRnoFKAJ8ARgAAAjI"]
[Thu Jul 30 11:56:38.483120 2026] [security2:error] [pid 643573:tid 643755] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuCRvxWyxgRnoFKAJ8ATgAAAkE"]
[Thu Jul 30 11:56:38.483218 2026] [security2:error] [pid 643573:tid 643755] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuCRvxWyxgRnoFKAJ8ATgAAAkE"]
[Thu Jul 30 11:56:38.994919 2026] [security2:error] [pid 643253:tid 643446] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/av.php"] [unique_id "amuCRsjqbtjBYzqM1uYngQAAAD4"]
[Thu Jul 30 11:56:38.995032 2026] [security2:error] [pid 643253:tid 643446] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/av.php"] [unique_id "amuCRsjqbtjBYzqM1uYngQAAAD4"]
[Thu Jul 30 11:56:39.354747 2026] [core:notice] [pid 642360:tid 642498] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:39.358830 2026] [security2:error] [pid 642360:tid 642498] [client 103.215.74.26:17806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCR5SUkh3e5AhEJOB5UgAAAZc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:39.534010 2026] [security2:error] [pid 642360:tid 642500] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.propertyspro.com"] [uri "/___proxy_subdomain_webdisk/wp-includes/l10n/"] [unique_id "amuCR5SUkh3e5AhEJOB5VQAAAZk"]
[Thu Jul 30 11:56:39.607839 2026] [security2:error] [pid 643573:tid 643775] [client 143.244.57.92:45636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kamiliacademy.com"] [uri "/xmlrpc.php"] [unique_id "amuCR_xWyxgRnoFKAJ8AWwAAAlU"]
[Thu Jul 30 11:56:39.607953 2026] [security2:error] [pid 643573:tid 643775] [client 143.244.57.92:45636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kamiliacademy.com"] [uri "/xmlrpc.php"] [unique_id "amuCR_xWyxgRnoFKAJ8AWwAAAlU"]
[Thu Jul 30 11:56:39.849149 2026] [security2:error] [pid 642360:tid 642577] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.propertyspro.com"] [uri "/___proxy_subdomain_webdisk/wordpress/wp-admin/maint/"] [unique_id "amuCR5SUkh3e5AhEJOB5WAAAAeY"]
[Thu Jul 30 11:56:40.097183 2026] [core:notice] [pid 642360:tid 642593] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:40.101625 2026] [security2:error] [pid 642360:tid 642593] [client 103.215.74.26:17816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCSJSUkh3e5AhEJOB5XQAAAfY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:40.134753 2026] [security2:error] [pid 642360:tid 642562] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/tiny.php"] [unique_id "amuCSJSUkh3e5AhEJOB5XgAAAdc"]
[Thu Jul 30 11:56:40.134838 2026] [security2:error] [pid 642360:tid 642562] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/tiny.php"] [unique_id "amuCSJSUkh3e5AhEJOB5XgAAAdc"]
[Thu Jul 30 11:56:40.165567 2026] [security2:error] [pid 643573:tid 643773] [client 143.244.57.92:45638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kamiliacademy.com"] [uri "/xmlrpc.php"] [unique_id "amuCSPxWyxgRnoFKAJ8AXwAAAlM"]
[Thu Jul 30 11:56:40.165671 2026] [security2:error] [pid 643573:tid 643773] [client 143.244.57.92:45638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kamiliacademy.com"] [uri "/xmlrpc.php"] [unique_id "amuCSPxWyxgRnoFKAJ8AXwAAAlM"]
[Thu Jul 30 11:56:40.654511 2026] [security2:error] [pid 643573:tid 643731] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "emmanueljrodriguez.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "amuCSPxWyxgRnoFKAJ8AYwAAAik"]
[Thu Jul 30 11:56:40.659379 2026] [security2:error] [pid 642360:tid 642546] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuCSJSUkh3e5AhEJOB5ZAAAAcc"]
[Thu Jul 30 11:56:40.659491 2026] [security2:error] [pid 642360:tid 642546] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuCSJSUkh3e5AhEJOB5ZAAAAcc"]
[Thu Jul 30 11:56:40.819107 2026] [core:notice] [pid 642360:tid 642554] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:40.823399 2026] [security2:error] [pid 642360:tid 642554] [client 103.215.74.26:17822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCSJSUkh3e5AhEJOB5ZgAAAc8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:41.156419 2026] [security2:error] [pid 643573:tid 643824] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/zrrhj.php"] [unique_id "amuCSfxWyxgRnoFKAJ8AbwAAAoY"]
[Thu Jul 30 11:56:41.156514 2026] [security2:error] [pid 643573:tid 643824] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/zrrhj.php"] [unique_id "amuCSfxWyxgRnoFKAJ8AbwAAAoY"]
[Thu Jul 30 11:56:41.665269 2026] [security2:error] [pid 643573:tid 643816] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuCSfxWyxgRnoFKAJ8AcgAAAn4"]
[Thu Jul 30 11:56:41.665421 2026] [security2:error] [pid 643573:tid 643816] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuCSfxWyxgRnoFKAJ8AcgAAAn4"]
[Thu Jul 30 11:56:42.174486 2026] [security2:error] [pid 642360:tid 642535] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/wpgum.php"] [unique_id "amuCSpSUkh3e5AhEJOB5dQAAAbw"]
[Thu Jul 30 11:56:42.174607 2026] [security2:error] [pid 642360:tid 642535] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/wpgum.php"] [unique_id "amuCSpSUkh3e5AhEJOB5dQAAAbw"]
[Thu Jul 30 11:56:42.670292 2026] [security2:error] [pid 643573:tid 643809] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/ywwbf.php"] [unique_id "amuCSvxWyxgRnoFKAJ8AewAAAnc"]
[Thu Jul 30 11:56:42.670398 2026] [security2:error] [pid 643573:tid 643809] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/ywwbf.php"] [unique_id "amuCSvxWyxgRnoFKAJ8AewAAAnc"]
[Thu Jul 30 11:56:43.180036 2026] [security2:error] [pid 642360:tid 642502] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/xoldj.php"] [unique_id "amuCS5SUkh3e5AhEJOB5fwAAAZs"]
[Thu Jul 30 11:56:43.180184 2026] [security2:error] [pid 642360:tid 642502] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/xoldj.php"] [unique_id "amuCS5SUkh3e5AhEJOB5fwAAAZs"]
[Thu Jul 30 11:56:44.142184 2026] [security2:error] [pid 643573:tid 643787] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/f35.php"] [unique_id "amuCTPxWyxgRnoFKAJ8AjAAAAmE"]
[Thu Jul 30 11:56:44.142319 2026] [security2:error] [pid 643573:tid 643787] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/f35.php"] [unique_id "amuCTPxWyxgRnoFKAJ8AjAAAAmE"]
[Thu Jul 30 11:56:44.674328 2026] [security2:error] [pid 642360:tid 642529] [client 57.141.0.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCTJSUkh3e5AhEJOB5jgAAAbY"]
[Thu Jul 30 11:56:44.685682 2026] [security2:error] [pid 643573:tid 643806] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/gk.php"] [unique_id "amuCTPxWyxgRnoFKAJ8AjgAAAnQ"]
[Thu Jul 30 11:56:44.685815 2026] [security2:error] [pid 643573:tid 643806] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/gk.php"] [unique_id "amuCTPxWyxgRnoFKAJ8AjgAAAnQ"]
[Thu Jul 30 11:56:44.725388 2026] [security2:error] [pid 643253:tid 643462] [client 35.239.2.194:52916] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "alnukhbafurnituremovers.cc"] [uri "/"] [unique_id "amuCTMjqbtjBYzqM1uYnhwAAAE4"]
[Thu Jul 30 11:56:45.045077 2026] [security2:error] [pid 643573:tid 643793] [client 176.241.66.87:36053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCTfxWyxgRnoFKAJ8AkQAAAmc"]
[Thu Jul 30 11:56:45.045235 2026] [security2:error] [pid 643573:tid 643793] [client 176.241.66.87:36053] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCTfxWyxgRnoFKAJ8AkQAAAmc"]
[Thu Jul 30 11:56:45.226871 2026] [security2:error] [pid 642360:tid 642507] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/584062352875874akp.php"] [unique_id "amuCTZSUkh3e5AhEJOB5mQAAAaA"]
[Thu Jul 30 11:56:45.226996 2026] [security2:error] [pid 642360:tid 642507] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/584062352875874akp.php"] [unique_id "amuCTZSUkh3e5AhEJOB5mQAAAaA"]
[Thu Jul 30 11:56:45.485117 2026] [security2:error] [pid 642360:tid 642585] [client 2a03:2880:f800:30:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuCTJSUkh3e5AhEJOB5kwAB7gc"]
[Thu Jul 30 11:56:45.711001 2026] [security2:error] [pid 643573:tid 643719] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/wper3.php"] [unique_id "amuCTfxWyxgRnoFKAJ8AmQAAAh0"]
[Thu Jul 30 11:56:45.711106 2026] [security2:error] [pid 643573:tid 643719] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/wper3.php"] [unique_id "amuCTfxWyxgRnoFKAJ8AmQAAAh0"]
[Thu Jul 30 11:56:46.224234 2026] [security2:error] [pid 643573:tid 643772] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/bthil.php"] [unique_id "amuCTvxWyxgRnoFKAJ8AmwAAAlI"]
[Thu Jul 30 11:56:46.224343 2026] [security2:error] [pid 643573:tid 643772] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/bthil.php"] [unique_id "amuCTvxWyxgRnoFKAJ8AmwAAAlI"]
[Thu Jul 30 11:56:46.295757 2026] [security2:error] [pid 642360:tid 642543] [client 172.213.208.20:29089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/aaa.php"] [unique_id "amuCTpSUkh3e5AhEJOB5nwAAAcQ"]
[Thu Jul 30 11:56:46.554954 2026] [core:notice] [pid 643253:tid 643416] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:46.559384 2026] [security2:error] [pid 643253:tid 643416] [client 103.215.74.26:57824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCTsjqbtjBYzqM1uYnjAAAACA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:46.740776 2026] [security2:error] [pid 642360:tid 642568] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/wyzer1.php"] [unique_id "amuCTpSUkh3e5AhEJOB5pQAAAd0"]
[Thu Jul 30 11:56:46.740868 2026] [security2:error] [pid 642360:tid 642568] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/wyzer1.php"] [unique_id "amuCTpSUkh3e5AhEJOB5pQAAAd0"]
[Thu Jul 30 11:56:47.223836 2026] [security2:error] [pid 643573:tid 643740] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/mh.php"] [unique_id "amuCT_xWyxgRnoFKAJ8AoQAAAjI"]
[Thu Jul 30 11:56:47.223928 2026] [security2:error] [pid 643573:tid 643740] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/mh.php"] [unique_id "amuCT_xWyxgRnoFKAJ8AoQAAAjI"]
[Thu Jul 30 11:56:47.303466 2026] [core:notice] [pid 643573:tid 643730] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:47.307572 2026] [security2:error] [pid 643573:tid 643730] [client 103.215.74.26:57830] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "732"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCT_xWyxgRnoFKAJ8AogAAAig"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:47.380948 2026] [proxy:error] [pid 642360:tid 642482] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:56:47.381019 2026] [proxy_http:error] [pid 642360:tid 642482] [remote 74.7.230.58:38990] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:56:47.381574 2026] [proxy:error] [pid 642360:tid 642482] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:56:47.381616 2026] [proxy_http:error] [pid 642360:tid 642482] [remote 74.7.230.58:38990] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:56:47.547255 2026] [security2:error] [pid 642360:tid 642566] [client 172.213.208.20:33522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/getid3-core.php"] [unique_id "amuCT5SUkh3e5AhEJOB5sAAAAds"]
[Thu Jul 30 11:56:47.735464 2026] [security2:error] [pid 642360:tid 642554] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuCT5SUkh3e5AhEJOB5sQAAAc8"]
[Thu Jul 30 11:56:47.735583 2026] [security2:error] [pid 642360:tid 642554] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuCT5SUkh3e5AhEJOB5sQAAAc8"]
[Thu Jul 30 11:56:48.061259 2026] [core:notice] [pid 642360:tid 642595] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:48.065456 2026] [security2:error] [pid 642360:tid 642595] [client 103.215.74.26:57834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "734"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCUJSUkh3e5AhEJOB5twAAAfg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:48.250592 2026] [security2:error] [pid 642360:tid 642525] [client 20.104.16.169:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.propertyspro.com"] [uri "/1.php"] [unique_id "amuCUJSUkh3e5AhEJOB5uAAAAbI"]
[Thu Jul 30 11:56:48.250704 2026] [security2:error] [pid 642360:tid 642525] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/1.php"] [unique_id "amuCUJSUkh3e5AhEJOB5uAAAAbI"]
[Thu Jul 30 11:56:48.250815 2026] [security2:error] [pid 642360:tid 642525] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/1.php"] [unique_id "amuCUJSUkh3e5AhEJOB5uAAAAbI"]
[Thu Jul 30 11:56:48.489599 2026] [security2:error] [pid 643573:tid 643720] [client 37.120.155.179:51796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.155.120.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuCUPxWyxgRnoFKAJ8ArAAAAh4"]
[Thu Jul 30 11:56:48.489710 2026] [security2:error] [pid 643573:tid 643720] [client 37.120.155.179:51796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuCUPxWyxgRnoFKAJ8ArAAAAh4"]
[Thu Jul 30 11:56:48.633804 2026] [core:notice] [pid 642360:tid 642501] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:48.756686 2026] [security2:error] [pid 643253:tid 643429] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/chosen.php"] [unique_id "amuCUMjqbtjBYzqM1uYnjgAAAC0"]
[Thu Jul 30 11:56:48.756851 2026] [security2:error] [pid 643253:tid 643429] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/chosen.php"] [unique_id "amuCUMjqbtjBYzqM1uYnjgAAAC0"]
[Thu Jul 30 11:56:48.799450 2026] [core:notice] [pid 642360:tid 642495] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:48.803449 2026] [security2:error] [pid 642360:tid 642495] [client 103.215.74.26:57840] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "731"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCUJSUkh3e5AhEJOB5vwAAAZQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:49.006459 2026] [security2:error] [pid 643573:tid 643774] [client 172.213.208.20:33479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/adminer.php"] [unique_id "amuCUfxWyxgRnoFKAJ8ArwAAAlQ"]
[Thu Jul 30 11:56:49.047400 2026] [core:notice] [pid 643573:tid 643753] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:49.050403 2026] [security2:error] [pid 643573:tid 643753] [client 66.249.65.195:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/view/81/84"] [unique_id "amuCUPxWyxgRnoFKAJ8ArgAAAj8"]
[Thu Jul 30 11:56:49.258078 2026] [security2:error] [pid 642360:tid 642575] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/sd.php"] [unique_id "amuCUZSUkh3e5AhEJOB5xAAAAeQ"]
[Thu Jul 30 11:56:49.258219 2026] [security2:error] [pid 642360:tid 642575] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/sd.php"] [unique_id "amuCUZSUkh3e5AhEJOB5xAAAAeQ"]
[Thu Jul 30 11:56:49.564080 2026] [core:notice] [pid 643253:tid 643438] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:49.568802 2026] [security2:error] [pid 643253:tid 643438] [client 103.215.74.26:57854] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCUcjqbtjBYzqM1uYnkAAAADY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:49.628768 2026] [security2:error] [pid 643253:tid 643389] [client 20.91.199.21:49378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/default.php"] [unique_id "amuCUcjqbtjBYzqM1uYnkQAAAAU"]
[Thu Jul 30 11:56:49.764934 2026] [security2:error] [pid 642360:tid 642524] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/z60.php"] [unique_id "amuCUZSUkh3e5AhEJOB5yQAAAbE"]
[Thu Jul 30 11:56:49.765095 2026] [security2:error] [pid 642360:tid 642524] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/z60.php"] [unique_id "amuCUZSUkh3e5AhEJOB5yQAAAbE"]
[Thu Jul 30 11:56:50.016019 2026] [core:notice] [pid 643573:tid 643628] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:50.246741 2026] [security2:error] [pid 642360:tid 642582] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/home.php"] [unique_id "amuCUpSUkh3e5AhEJOB50AAAAes"]
[Thu Jul 30 11:56:50.246860 2026] [security2:error] [pid 642360:tid 642582] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/home.php"] [unique_id "amuCUpSUkh3e5AhEJOB50AAAAes"]
[Thu Jul 30 11:56:50.297105 2026] [core:notice] [pid 643573:tid 643746] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:50.304052 2026] [security2:error] [pid 643573:tid 643746] [client 103.215.74.26:57858] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCUvxWyxgRnoFKAJ8AuAAAAjg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:50.727229 2026] [security2:error] [pid 643573:tid 643793] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/ws58.php"] [unique_id "amuCUvxWyxgRnoFKAJ8AvgAAAmc"]
[Thu Jul 30 11:56:50.727345 2026] [security2:error] [pid 643573:tid 643793] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/ws58.php"] [unique_id "amuCUvxWyxgRnoFKAJ8AvgAAAmc"]
[Thu Jul 30 11:56:50.800512 2026] [core:notice] [pid 643573:tid 643640] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:50.963332 2026] [security2:error] [pid 643573:tid 643727] [client 119.73.97.132:30991] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuCUvxWyxgRnoFKAJ8AuQACJQc"], referer: https://www.urwru.club/wp-admin/post.php?post=685&action=elementor
[Thu Jul 30 11:56:51.020927 2026] [core:notice] [pid 643573:tid 643837] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:51.027603 2026] [security2:error] [pid 643573:tid 643837] [client 103.215.74.26:57874] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCU_xWyxgRnoFKAJ8AwwAAApM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:51.042899 2026] [core:notice] [pid 643573:tid 643611] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:51.253270 2026] [security2:error] [pid 642360:tid 642541] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/gulu.php"] [unique_id "amuCU5SUkh3e5AhEJOB52AAAAcI"]
[Thu Jul 30 11:56:51.253401 2026] [security2:error] [pid 642360:tid 642541] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/gulu.php"] [unique_id "amuCU5SUkh3e5AhEJOB52AAAAcI"]
[Thu Jul 30 11:56:51.746048 2026] [security2:error] [pid 642360:tid 642540] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuCU5SUkh3e5AhEJOB54AAAAcE"]
[Thu Jul 30 11:56:51.746158 2026] [security2:error] [pid 642360:tid 642540] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuCU5SUkh3e5AhEJOB54AAAAcE"]
[Thu Jul 30 11:56:51.788774 2026] [core:notice] [pid 643573:tid 643831] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:51.793161 2026] [security2:error] [pid 643573:tid 643831] [client 103.215.74.26:57886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "732"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCU_xWyxgRnoFKAJ8A0QAAAo0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:52.156713 2026] [security2:error] [pid 643253:tid 643256] [remote 34.9.172.22:10112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.172.9.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Responsif/about"] [unique_id "amuCU8jqbtjBYzqM1uYnlgAAGgE"]
[Thu Jul 30 11:56:52.274654 2026] [security2:error] [pid 643573:tid 643762] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/wpls.php"] [unique_id "amuCVPxWyxgRnoFKAJ8A1QAAAkg"]
[Thu Jul 30 11:56:52.274762 2026] [security2:error] [pid 643573:tid 643762] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/wpls.php"] [unique_id "amuCVPxWyxgRnoFKAJ8A1QAAAkg"]
[Thu Jul 30 11:56:52.645678 2026] [security2:error] [pid 643573:tid 643782] [client 20.91.199.21:36430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/dropdown.php"] [unique_id "amuCVPxWyxgRnoFKAJ8A2wAAAlw"]
[Thu Jul 30 11:56:52.768463 2026] [security2:error] [pid 643573:tid 643753] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/php.php"] [unique_id "amuCVPxWyxgRnoFKAJ8A3wAAAj8"]
[Thu Jul 30 11:56:52.768555 2026] [security2:error] [pid 643573:tid 643753] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/php.php"] [unique_id "amuCVPxWyxgRnoFKAJ8A3wAAAj8"]
[Thu Jul 30 11:56:53.069144 2026] [core:notice] [pid 643253:tid 643257] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:53.118402 2026] [core:notice] [pid 643573:tid 643631] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:53.285519 2026] [security2:error] [pid 643573:tid 643769] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/100.php"] [unique_id "amuCVfxWyxgRnoFKAJ8A4gAAAk8"]
[Thu Jul 30 11:56:53.285624 2026] [security2:error] [pid 643573:tid 643769] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/100.php"] [unique_id "amuCVfxWyxgRnoFKAJ8A4gAAAk8"]
[Thu Jul 30 11:56:53.339066 2026] [core:notice] [pid 643253:tid 643258] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:53.352490 2026] [security2:error] [pid 643253:tid 643452] [client 20.91.199.21:36460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/edit.php"] [unique_id "amuCVcjqbtjBYzqM1uYnmgAAAEQ"]
[Thu Jul 30 11:56:53.387528 2026] [core:notice] [pid 643573:tid 643639] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:53.713422 2026] [core:notice] [pid 642360:tid 642373] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:53.783682 2026] [security2:error] [pid 642360:tid 642497] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/BDKR28WP.php"] [unique_id "amuCVZSUkh3e5AhEJOB5-AAAAZY"]
[Thu Jul 30 11:56:53.783830 2026] [security2:error] [pid 642360:tid 642497] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/BDKR28WP.php"] [unique_id "amuCVZSUkh3e5AhEJOB5-AAAAZY"]
[Thu Jul 30 11:56:53.966998 2026] [security2:error] [pid 643573:tid 643635] [remote 121.200.217.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.217.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espairsa.com"] [uri "/wp-login.php"] [unique_id "amuCVfxWyxgRnoFKAJ8A6AACXjY"]
[Thu Jul 30 11:56:55.347236 2026] [security2:error] [pid 643573:tid 643636] [remote 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuCV_xWyxgRnoFKAJ8A8gACFzc"]
[Thu Jul 30 11:56:55.347423 2026] [security2:error] [pid 643573:tid 643713] [client 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuCV_xWyxgRnoFKAJ8A8gACFzc"]
[Thu Jul 30 11:56:55.377009 2026] [security2:error] [pid 643573:tid 643779] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/browse.php"] [unique_id "amuCV_xWyxgRnoFKAJ8A8wAAAlk"]
[Thu Jul 30 11:56:55.377107 2026] [security2:error] [pid 643573:tid 643779] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/browse.php"] [unique_id "amuCV_xWyxgRnoFKAJ8A8wAAAlk"]
[Thu Jul 30 11:56:55.571946 2026] [security2:error] [pid 643253:tid 643403] [client 176.241.66.87:53504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCV8jqbtjBYzqM1uYnnAAAABM"]
[Thu Jul 30 11:56:55.572099 2026] [security2:error] [pid 643253:tid 643403] [client 176.241.66.87:53504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCV8jqbtjBYzqM1uYnnAAAABM"]
[Thu Jul 30 11:56:55.709321 2026] [security2:error] [pid 643573:tid 643739] [client 173.249.217.7:56546] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuCV_xWyxgRnoFKAJ8A9AAAAjE"]
[Thu Jul 30 11:56:55.709426 2026] [security2:error] [pid 643573:tid 643739] [client 173.249.217.7:56546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuCV_xWyxgRnoFKAJ8A9AAAAjE"]
[Thu Jul 30 11:56:55.886134 2026] [security2:error] [pid 643573:tid 643740] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/wp-good.php"] [unique_id "amuCV_xWyxgRnoFKAJ8A-QAAAjI"]
[Thu Jul 30 11:56:55.886263 2026] [security2:error] [pid 643573:tid 643740] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/wp-good.php"] [unique_id "amuCV_xWyxgRnoFKAJ8A-QAAAjI"]
[Thu Jul 30 11:56:55.995272 2026] [security2:error] [pid 643253:tid 643413] [client 172.213.208.20:6938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/alfa.php"] [unique_id "amuCV8jqbtjBYzqM1uYnnQAAAB0"]
[Thu Jul 30 11:56:56.397229 2026] [security2:error] [pid 642360:tid 642548] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/8573.php"] [unique_id "amuCWJSUkh3e5AhEJOB6DAAAAck"]
[Thu Jul 30 11:56:56.397352 2026] [security2:error] [pid 642360:tid 642548] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/8573.php"] [unique_id "amuCWJSUkh3e5AhEJOB6DAAAAck"]
[Thu Jul 30 11:56:56.659387 2026] [security2:error] [pid 642360:tid 642522] [client 5.161.177.47:49510] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuCV5SUkh3e5AhEJOB6BgAAAa8"], referer: https://globalmarks.pk/
[Thu Jul 30 11:56:57.334609 2026] [security2:error] [pid 643573:tid 643773] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/wp-admin/install.php"] [unique_id "amuCWfxWyxgRnoFKAJ8BCAAAAlM"]
[Thu Jul 30 11:56:57.334722 2026] [security2:error] [pid 643573:tid 643773] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/wp-admin/install.php"] [unique_id "amuCWfxWyxgRnoFKAJ8BCAAAAlM"]
[Thu Jul 30 11:56:57.533731 2026] [core:notice] [pid 643573:tid 643763] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:57.537599 2026] [security2:error] [pid 643573:tid 643763] [client 103.215.74.26:9528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCWfxWyxgRnoFKAJ8BCwAAAkk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:57.856718 2026] [security2:error] [pid 643573:tid 643728] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/classwithtostring.php"] [unique_id "amuCWfxWyxgRnoFKAJ8BDwAAAiY"]
[Thu Jul 30 11:56:57.856824 2026] [security2:error] [pid 643573:tid 643728] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/classwithtostring.php"] [unique_id "amuCWfxWyxgRnoFKAJ8BDwAAAiY"]
[Thu Jul 30 11:56:57.957866 2026] [security2:error] [pid 643573:tid 643817] [client 20.91.199.21:36002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/f35.php"] [unique_id "amuCWfxWyxgRnoFKAJ8BEQAAAn8"]
[Thu Jul 30 11:56:58.298419 2026] [core:notice] [pid 642360:tid 642538] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:58.304970 2026] [security2:error] [pid 642360:tid 642538] [client 103.215.74.26:9532] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCWpSUkh3e5AhEJOB6GAAAAb8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:58.393258 2026] [security2:error] [pid 643573:tid 643738] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/ohct.php"] [unique_id "amuCWvxWyxgRnoFKAJ8BEgAAAjA"]
[Thu Jul 30 11:56:58.393380 2026] [security2:error] [pid 643573:tid 643738] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/ohct.php"] [unique_id "amuCWvxWyxgRnoFKAJ8BEgAAAjA"]
[Thu Jul 30 11:56:58.686435 2026] [security2:error] [pid 642360:tid 642610] [client 20.91.199.21:49393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/f7.php"] [unique_id "amuCWpSUkh3e5AhEJOB6HwAAAgc"]
[Thu Jul 30 11:56:58.891411 2026] [security2:error] [pid 643573:tid 643779] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/bless.php"] [unique_id "amuCWvxWyxgRnoFKAJ8BFAAAAlk"]
[Thu Jul 30 11:56:58.891539 2026] [security2:error] [pid 643573:tid 643779] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/bless.php"] [unique_id "amuCWvxWyxgRnoFKAJ8BFAAAAlk"]
[Thu Jul 30 11:56:59.405567 2026] [security2:error] [pid 643573:tid 643732] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/about.php"] [unique_id "amuCW_xWyxgRnoFKAJ8BFwAAAio"]
[Thu Jul 30 11:56:59.405695 2026] [security2:error] [pid 643573:tid 643732] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/about.php"] [unique_id "amuCW_xWyxgRnoFKAJ8BFwAAAio"]
[Thu Jul 30 11:56:59.781932 2026] [security2:error] [pid 643573:tid 643791] [client 172.213.208.20:22114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amuCW_xWyxgRnoFKAJ8BGgAAAmU"]
[Thu Jul 30 11:56:59.913386 2026] [security2:error] [pid 643573:tid 643757] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuCW_xWyxgRnoFKAJ8BGwAAAkM"]
[Thu Jul 30 11:56:59.913512 2026] [security2:error] [pid 643573:tid 643757] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuCW_xWyxgRnoFKAJ8BGwAAAkM"]
[Thu Jul 30 11:57:00.459035 2026] [security2:error] [pid 643573:tid 643800] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/ta0ol.php"] [unique_id "amuCXPxWyxgRnoFKAJ8BHgAAAm4"]
[Thu Jul 30 11:57:00.459214 2026] [security2:error] [pid 643573:tid 643800] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/ta0ol.php"] [unique_id "amuCXPxWyxgRnoFKAJ8BHgAAAm4"]
[Thu Jul 30 11:57:01.011162 2026] [security2:error] [pid 643573:tid 643756] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/sa.php7"] [unique_id "amuCXfxWyxgRnoFKAJ8BIgAAAkI"]
[Thu Jul 30 11:57:01.011342 2026] [security2:error] [pid 643573:tid 643756] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/sa.php7"] [unique_id "amuCXfxWyxgRnoFKAJ8BIgAAAkI"]
[Thu Jul 30 11:57:01.526869 2026] [security2:error] [pid 642360:tid 642584] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/wp-class.php"] [unique_id "amuCXZSUkh3e5AhEJOB6NQAAAe0"]
[Thu Jul 30 11:57:01.526998 2026] [security2:error] [pid 642360:tid 642584] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/wp-class.php"] [unique_id "amuCXZSUkh3e5AhEJOB6NQAAAe0"]
[Thu Jul 30 11:57:02.048577 2026] [security2:error] [pid 643573:tid 643784] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/8.php"] [unique_id "amuCXvxWyxgRnoFKAJ8BKwAAAl4"]
[Thu Jul 30 11:57:02.048675 2026] [security2:error] [pid 643573:tid 643784] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/8.php"] [unique_id "amuCXvxWyxgRnoFKAJ8BKwAAAl4"]
[Thu Jul 30 11:57:02.570985 2026] [security2:error] [pid 643573:tid 643819] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/bootstrap.php"] [unique_id "amuCXvxWyxgRnoFKAJ8BLgAAAoE"]
[Thu Jul 30 11:57:02.571108 2026] [security2:error] [pid 643573:tid 643819] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/bootstrap.php"] [unique_id "amuCXvxWyxgRnoFKAJ8BLgAAAoE"]
[Thu Jul 30 11:57:03.095933 2026] [security2:error] [pid 643573:tid 643766] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/wp-blog-header.php"] [unique_id "amuCX_xWyxgRnoFKAJ8BMQAAAkw"]
[Thu Jul 30 11:57:03.096060 2026] [security2:error] [pid 643573:tid 643766] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/wp-blog-header.php"] [unique_id "amuCX_xWyxgRnoFKAJ8BMQAAAkw"]
[Thu Jul 30 11:57:03.145718 2026] [security2:error] [pid 643573:tid 643823] [client 172.213.208.20:16900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuCX_xWyxgRnoFKAJ8BMgAAAoU"]
[Thu Jul 30 11:57:03.615616 2026] [security2:error] [pid 643253:tid 643459] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/aa.php"] [unique_id "amuCX8jqbtjBYzqM1uYnoAAAAEs"]
[Thu Jul 30 11:57:03.615725 2026] [security2:error] [pid 643253:tid 643459] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/aa.php"] [unique_id "amuCX8jqbtjBYzqM1uYnoAAAAEs"]
[Thu Jul 30 11:57:04.025061 2026] [core:notice] [pid 642360:tid 642567] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:04.028970 2026] [security2:error] [pid 642360:tid 642567] [client 103.215.74.26:45712] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "763"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCYJSUkh3e5AhEJOB6XQAAAdw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:04.074695 2026] [security2:error] [pid 643253:tid 643507] [client 47.128.114.17:49670] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "globalmarks.pk"] [uri "/robots.txt"] [unique_id "amuCYMjqbtjBYzqM1uYnogAAAHs"]
[Thu Jul 30 11:57:04.117582 2026] [security2:error] [pid 643573:tid 643808] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/tx79.php"] [unique_id "amuCYPxWyxgRnoFKAJ8BNgAAAnY"]
[Thu Jul 30 11:57:04.117719 2026] [security2:error] [pid 643573:tid 643808] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/tx79.php"] [unique_id "amuCYPxWyxgRnoFKAJ8BNgAAAnY"]
[Thu Jul 30 11:57:04.610238 2026] [security2:error] [pid 643573:tid 643780] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/motu.php"] [unique_id "amuCYPxWyxgRnoFKAJ8BOwAAAlo"]
[Thu Jul 30 11:57:04.610444 2026] [security2:error] [pid 643573:tid 643780] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/motu.php"] [unique_id "amuCYPxWyxgRnoFKAJ8BOwAAAlo"]
[Thu Jul 30 11:57:04.723550 2026] [security2:error] [pid 643573:tid 643727] [client 38.22.182.134:52912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCYPxWyxgRnoFKAJ8BOAAAAiU"], referer: http://pkf.jo
[Thu Jul 30 11:57:04.765600 2026] [core:notice] [pid 643573:tid 643758] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:04.769441 2026] [security2:error] [pid 643573:tid 643758] [client 103.215.74.26:45722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCYPxWyxgRnoFKAJ8BPQAAAkQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:05.029747 2026] [security2:error] [pid 642360:tid 642548] [client 123.26.92.241:50377] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCYJSUkh3e5AhEJOB6XgAAAck"], referer: http://pkf.jo
[Thu Jul 30 11:57:05.152479 2026] [core:notice] [pid 643573:tid 643671] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:05.274135 2026] [security2:error] [pid 643573:tid 643722] [client 181.211.104.23:16419] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCYPxWyxgRnoFKAJ8BPgAAAiA"], referer: http://pkf.jo
[Thu Jul 30 11:57:05.325242 2026] [core:notice] [pid 643573:tid 643717] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:05.484481 2026] [core:notice] [pid 643573:tid 643803] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:05.488434 2026] [security2:error] [pid 643573:tid 643803] [client 103.215.74.26:45730] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCYfxWyxgRnoFKAJ8BUwAAAnE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:05.499490 2026] [security2:error] [pid 642360:tid 642536] [client 201.216.101.53:64143] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCYZSUkh3e5AhEJOB6aQAAAb0"], referer: http://pkf.jo
[Thu Jul 30 11:57:05.580624 2026] [security2:error] [pid 643573:tid 643787] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/wp-head.php"] [unique_id "amuCYfxWyxgRnoFKAJ8BVQAAAmE"]
[Thu Jul 30 11:57:05.580724 2026] [security2:error] [pid 643573:tid 643787] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/wp-head.php"] [unique_id "amuCYfxWyxgRnoFKAJ8BVQAAAmE"]
[Thu Jul 30 11:57:05.979668 2026] [security2:error] [pid 643573:tid 643783] [client 2a03:2880:f800:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuCYfxWyxgRnoFKAJ8BTwACXT8"]
[Thu Jul 30 11:57:06.072612 2026] [security2:error] [pid 643573:tid 643801] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuCYvxWyxgRnoFKAJ8BWQAAAm8"]
[Thu Jul 30 11:57:06.072747 2026] [security2:error] [pid 643573:tid 643801] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuCYvxWyxgRnoFKAJ8BWQAAAm8"]
[Thu Jul 30 11:57:06.217778 2026] [core:notice] [pid 643573:tid 643822] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:06.221745 2026] [security2:error] [pid 643573:tid 643822] [client 103.215.74.26:45744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCYvxWyxgRnoFKAJ8BWgAAAoQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:06.266268 2026] [security2:error] [pid 643573:tid 643806] [client 176.241.66.87:37495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCYvxWyxgRnoFKAJ8BWwAAAnQ"]
[Thu Jul 30 11:57:06.266396 2026] [security2:error] [pid 643573:tid 643806] [client 176.241.66.87:37495] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCYvxWyxgRnoFKAJ8BWwAAAnQ"]
[Thu Jul 30 11:57:06.561918 2026] [security2:error] [pid 643573:tid 643795] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/60856e3a4findex.php"] [unique_id "amuCYvxWyxgRnoFKAJ8BXgAAAmk"]
[Thu Jul 30 11:57:06.562036 2026] [security2:error] [pid 643573:tid 643795] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/60856e3a4findex.php"] [unique_id "amuCYvxWyxgRnoFKAJ8BXgAAAmk"]
[Thu Jul 30 11:57:06.955997 2026] [core:notice] [pid 642360:tid 642504] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:06.959923 2026] [security2:error] [pid 642360:tid 642504] [client 103.215.74.26:45756] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCYpSUkh3e5AhEJOB6eAAAAZ0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:07.055278 2026] [security2:error] [pid 643573:tid 643670] [remote 34.44.196.215:1024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.196.44.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Responsif/about"] [unique_id "amuCYvxWyxgRnoFKAJ8BXwACPFk"]
[Thu Jul 30 11:57:07.378852 2026] [security2:error] [pid 643573:tid 643804] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/wp-the.php"] [unique_id "amuCY_xWyxgRnoFKAJ8BZwAAAnI"]
[Thu Jul 30 11:57:07.378986 2026] [security2:error] [pid 643573:tid 643804] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/wp-the.php"] [unique_id "amuCY_xWyxgRnoFKAJ8BZwAAAnI"]
[Thu Jul 30 11:57:07.874268 2026] [security2:error] [pid 643573:tid 643779] [client 172.213.208.20:17342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amuCY_xWyxgRnoFKAJ8BawAAAlk"]
[Thu Jul 30 11:57:07.878657 2026] [security2:error] [pid 643573:tid 643712] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/wp.php"] [unique_id "amuCY_xWyxgRnoFKAJ8BbAAAAhY"]
[Thu Jul 30 11:57:07.878750 2026] [security2:error] [pid 643573:tid 643712] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/wp.php"] [unique_id "amuCY_xWyxgRnoFKAJ8BbAAAAhY"]
[Thu Jul 30 11:57:08.128853 2026] [security2:error] [pid 643573:tid 643599] [remote 47.128.112.245:60702] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "club4.au"] [uri "/robots.txt"] [unique_id "amuCZPxWyxgRnoFKAJ8BcwACURI"]
[Thu Jul 30 11:57:08.371725 2026] [security2:error] [pid 643573:tid 643791] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/users.php"] [unique_id "amuCZPxWyxgRnoFKAJ8BdQAAAmU"]
[Thu Jul 30 11:57:08.371844 2026] [security2:error] [pid 643573:tid 643791] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/users.php"] [unique_id "amuCZPxWyxgRnoFKAJ8BdQAAAmU"]
[Thu Jul 30 11:57:08.872359 2026] [security2:error] [pid 643573:tid 643830] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/tinysd.php"] [unique_id "amuCZPxWyxgRnoFKAJ8BfQAAAow"]
[Thu Jul 30 11:57:08.872479 2026] [security2:error] [pid 643573:tid 643830] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/tinysd.php"] [unique_id "amuCZPxWyxgRnoFKAJ8BfQAAAow"]
[Thu Jul 30 11:57:09.121841 2026] [autoindex:error] [pid 643573:tid 643756] [client 106.54.62.156:0] AH01276: Cannot serve directory /home2/mbmudite/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://n1rmalabet88.com
[Thu Jul 30 11:57:09.335693 2026] [security2:error] [pid 643573:tid 643752] [client 161.153.99.62:42094] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuCZfxWyxgRnoFKAJ8BgwAAAj4"], referer: https://historiadevenezuela.org/partido-conservador/?main_page=product_info&products_id=5167
[Thu Jul 30 11:57:09.335816 2026] [security2:error] [pid 643573:tid 643752] [client 161.153.99.62:42094] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuCZfxWyxgRnoFKAJ8BgwAAAj4"], referer: https://historiadevenezuela.org/partido-conservador/?main_page=product_info&products_id=5167
[Thu Jul 30 11:57:09.358525 2026] [security2:error] [pid 643573:tid 643802] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/ws78.php"] [unique_id "amuCZfxWyxgRnoFKAJ8BhAAAAnA"]
[Thu Jul 30 11:57:09.358612 2026] [security2:error] [pid 643573:tid 643802] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/ws78.php"] [unique_id "amuCZfxWyxgRnoFKAJ8BhAAAAnA"]
[Thu Jul 30 11:57:09.870663 2026] [security2:error] [pid 643573:tid 643763] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/elp.php"] [unique_id "amuCZfxWyxgRnoFKAJ8BiAAAAkk"]
[Thu Jul 30 11:57:09.870793 2026] [security2:error] [pid 643573:tid 643763] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/elp.php"] [unique_id "amuCZfxWyxgRnoFKAJ8BiAAAAkk"]
[Thu Jul 30 11:57:10.295761 2026] [security2:error] [pid 643573:tid 643807] [client 172.213.208.20:7001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/edit.php"] [unique_id "amuCZvxWyxgRnoFKAJ8BjQAAAnU"]
[Thu Jul 30 11:57:10.353522 2026] [security2:error] [pid 643573:tid 643728] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/atomlib.php"] [unique_id "amuCZvxWyxgRnoFKAJ8BjgAAAiY"]
[Thu Jul 30 11:57:10.353614 2026] [security2:error] [pid 643573:tid 643728] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/atomlib.php"] [unique_id "amuCZvxWyxgRnoFKAJ8BjgAAAiY"]
[Thu Jul 30 11:57:10.847299 2026] [security2:error] [pid 643573:tid 643827] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/wyzer3.php"] [unique_id "amuCZvxWyxgRnoFKAJ8BlAAAAok"]
[Thu Jul 30 11:57:10.847390 2026] [security2:error] [pid 643573:tid 643827] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/wyzer3.php"] [unique_id "amuCZvxWyxgRnoFKAJ8BlAAAAok"]
[Thu Jul 30 11:57:11.373590 2026] [security2:error] [pid 643573:tid 643740] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/max.php"] [unique_id "amuCZ_xWyxgRnoFKAJ8BlwAAAjI"]
[Thu Jul 30 11:57:11.373706 2026] [security2:error] [pid 643573:tid 643740] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/max.php"] [unique_id "amuCZ_xWyxgRnoFKAJ8BlwAAAjI"]
[Thu Jul 30 11:57:11.916272 2026] [security2:error] [pid 643573:tid 643777] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/ftde.php"] [unique_id "amuCZ_xWyxgRnoFKAJ8BngAAAlc"]
[Thu Jul 30 11:57:11.916385 2026] [security2:error] [pid 643573:tid 643777] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/ftde.php"] [unique_id "amuCZ_xWyxgRnoFKAJ8BngAAAlc"]
[Thu Jul 30 11:57:12.685072 2026] [core:notice] [pid 643573:tid 643812] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:12.689039 2026] [security2:error] [pid 643573:tid 643812] [client 103.215.74.26:45764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "752"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCaPxWyxgRnoFKAJ8BqQAAAno"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:13.118832 2026] [security2:error] [pid 642360:tid 642581] [client 103.59.160.82:49354] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "azureskyfilms.com"] [uri "/index.php"] [unique_id "amuCaZSUkh3e5AhEJOB6owAAAeo"]
[Thu Jul 30 11:57:13.410245 2026] [core:notice] [pid 642360:tid 642587] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:13.414438 2026] [security2:error] [pid 642360:tid 642587] [client 103.215.74.26:26306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCaZSUkh3e5AhEJOB6rgAAAfA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:14.156390 2026] [core:notice] [pid 643253:tid 643492] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:14.160586 2026] [security2:error] [pid 643253:tid 643492] [client 103.215.74.26:26312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "764"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCasjqbtjBYzqM1uYnqQAAAGw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:14.510790 2026] [security2:error] [pid 642360:tid 642511] [client 123.21.175.29:37386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCapSUkh3e5AhEJOB6vwAAAaQ"], referer: http://pkf.jo
[Thu Jul 30 11:57:14.911743 2026] [core:notice] [pid 642360:tid 642513] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:14.915811 2026] [security2:error] [pid 642360:tid 642513] [client 103.215.74.26:26326] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "770"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCapSUkh3e5AhEJOB6yQAAAaY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:15.629104 2026] [security2:error] [pid 643253:tid 643392] [client 57.141.0.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCasjqbtjBYzqM1uYnrQAAAAg"]
[Thu Jul 30 11:57:15.632508 2026] [core:notice] [pid 642360:tid 642552] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:15.636860 2026] [security2:error] [pid 642360:tid 642552] [client 103.215.74.26:26332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCa5SUkh3e5AhEJOB60wAAAc0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:16.096861 2026] [security2:error] [pid 643253:tid 643475] [client 191.114.12.14:59986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCa8jqbtjBYzqM1uYnsAAAAFs"], referer: http://pkf.jo
[Thu Jul 30 11:57:16.363691 2026] [core:notice] [pid 642360:tid 642616] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:16.367489 2026] [security2:error] [pid 642360:tid 642616] [client 103.215.74.26:26336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCbJSUkh3e5AhEJOB62wAAAg0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:16.882758 2026] [security2:error] [pid 643253:tid 643488] [client 176.241.66.87:54604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCbMjqbtjBYzqM1uYntgAAAGg"]
[Thu Jul 30 11:57:16.882867 2026] [security2:error] [pid 643253:tid 643488] [client 176.241.66.87:54604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCbMjqbtjBYzqM1uYntgAAAGg"]
[Thu Jul 30 11:57:17.093579 2026] [core:notice] [pid 643253:tid 643501] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:17.097833 2026] [security2:error] [pid 643253:tid 643501] [client 103.215.74.26:26348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCbcjqbtjBYzqM1uYntwAAAHU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:17.605446 2026] [security2:error] [pid 643253:tid 643391] [client 172.213.208.20:30609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/sf.php"] [unique_id "amuCbcjqbtjBYzqM1uYnugAAAAc"]
[Thu Jul 30 11:57:17.832194 2026] [core:notice] [pid 642360:tid 642597] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:17.836545 2026] [security2:error] [pid 642360:tid 642597] [client 103.215.74.26:26350] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCbZSUkh3e5AhEJOB67gAAAfo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:18.556968 2026] [core:notice] [pid 642360:tid 642567] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:18.561274 2026] [security2:error] [pid 642360:tid 642567] [client 103.215.74.26:26352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCbpSUkh3e5AhEJOB69wAAAdw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:19.280946 2026] [core:notice] [pid 643253:tid 643421] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:19.285210 2026] [security2:error] [pid 643253:tid 643421] [client 103.215.74.26:26364] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCb8jqbtjBYzqM1uYnvgAAACU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:20.018300 2026] [core:notice] [pid 643253:tid 643454] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:20.022864 2026] [security2:error] [pid 643253:tid 643454] [client 103.215.74.26:26368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCcMjqbtjBYzqM1uYnxwAAAEY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:20.763313 2026] [core:notice] [pid 643253:tid 643399] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:20.767767 2026] [security2:error] [pid 643253:tid 643399] [client 103.215.74.26:26378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCcMjqbtjBYzqM1uYnyQAAAA8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:21.501825 2026] [core:notice] [pid 642360:tid 642606] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:21.506267 2026] [security2:error] [pid 642360:tid 642606] [client 103.215.74.26:26388] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCcZSUkh3e5AhEJOB7IwAAAgM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:21.714279 2026] [security2:error] [pid 642360:tid 642572] [client 74.7.244.37:54272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCcZSUkh3e5AhEJOB7IgAAAeE"]
[Thu Jul 30 11:57:22.378731 2026] [security2:error] [pid 642360:tid 642598] [client 57.141.0.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCcZSUkh3e5AhEJOB7JQAAAfs"]
[Thu Jul 30 11:57:23.006225 2026] [security2:error] [pid 642360:tid 642558] [client 172.213.208.20:23554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wso.php"] [unique_id "amuCc5SUkh3e5AhEJOB7PgAAAdM"]
[Thu Jul 30 11:57:23.607772 2026] [security2:error] [pid 642360:tid 642616] [client 35.221.246.130:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-212fe300.mty.djb.temporary.site"] [uri "/index.php"] [unique_id "amuCcZSUkh3e5AhEJOB7HgAAAg0"]
[Thu Jul 30 11:57:23.607808 2026] [security2:error] [pid 642360:tid 642616] [client 35.221.246.130:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-212fe300.mty.djb.temporary.site"] [uri "/index.php"] [unique_id "amuCcZSUkh3e5AhEJOB7HgAAAg0"]
[Thu Jul 30 11:57:23.608586 2026] [security2:error] [pid 643253:tid 643438] [client 35.221.246.130:45800] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-212fe300.mty.djb.temporary.site"] [uri "/.git/config"] [unique_id "amuCccjqbtjBYzqM1uYnzAAAADY"]
[Thu Jul 30 11:57:23.940624 2026] [security2:error] [pid 642360:tid 642492] [client 172.213.208.20:6757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/ioxi-o.php"] [unique_id "amuCc5SUkh3e5AhEJOB7VAAAAZE"]
[Thu Jul 30 11:57:24.167619 2026] [security2:error] [pid 642360:tid 642576] [client 103.178.2.97:37414] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "ghggeneralcontracting.com"] [uri "/wp-comments-post.php"] [unique_id "amuCc5SUkh3e5AhEJOB7SwAAAeU"]
[Thu Jul 30 11:57:24.436518 2026] [security2:error] [pid 642360:tid 642576] [client 103.178.2.97:37414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "ghggeneralcontracting.com"] [uri "/wp-comments-post.php"] [unique_id "amuCc5SUkh3e5AhEJOB7SwAAAeU"]
[Thu Jul 30 11:57:24.470115 2026] [security2:error] [pid 642360:tid 642419] [remote 184.168.126.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.126.168.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.spececigarette.com"] [uri "/wp-login.php"] [unique_id "amuCdJSUkh3e5AhEJOB7WQAB7Do"]
[Thu Jul 30 11:57:24.653126 2026] [security2:error] [pid 642360:tid 642550] [client 172.213.208.20:23612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/file56.php"] [unique_id "amuCdJSUkh3e5AhEJOB7XQAAAcs"]
[Thu Jul 30 11:57:26.362593 2026] [security2:error] [pid 642360:tid 642598] [client 172.213.208.20:6590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amuCdpSUkh3e5AhEJOB7bQAAAfs"]
[Thu Jul 30 11:57:27.235444 2026] [core:notice] [pid 642360:tid 642612] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:27.247200 2026] [security2:error] [pid 642360:tid 642612] [client 103.215.74.26:58192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCd5SUkh3e5AhEJOB7kQAAAgk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:27.346533 2026] [security2:error] [pid 642360:tid 642558] [client 172.213.208.20:43681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-admin/css/index.php"] [unique_id "amuCd5SUkh3e5AhEJOB7kgAAAdM"]
[Thu Jul 30 11:57:27.510640 2026] [security2:error] [pid 642360:tid 642565] [client 176.241.66.87:38943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCd5SUkh3e5AhEJOB7lgAAAdo"]
[Thu Jul 30 11:57:27.510846 2026] [security2:error] [pid 642360:tid 642565] [client 176.241.66.87:38943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCd5SUkh3e5AhEJOB7lgAAAdo"]
[Thu Jul 30 11:57:28.578670 2026] [security2:error] [pid 643253:tid 643445] [client 172.237.109.114:54939] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd8jqbtjBYzqM1uYn5QAAAD0"]
[Thu Jul 30 11:57:28.583880 2026] [security2:error] [pid 643253:tid 643433] [client 172.237.109.114:32001] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd8jqbtjBYzqM1uYn5gAAADE"]
[Thu Jul 30 11:57:28.597261 2026] [security2:error] [pid 642360:tid 642541] [client 172.237.109.114:13824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd5SUkh3e5AhEJOB7hAAAAcI"]
[Thu Jul 30 11:57:28.601035 2026] [security2:error] [pid 642360:tid 642523] [client 172.237.109.114:11772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd5SUkh3e5AhEJOB7fQAAAbA"]
[Thu Jul 30 11:57:28.683022 2026] [security2:error] [pid 643253:tid 643501] [client 172.213.208.20:36363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-content/edit.php"] [unique_id "amuCeMjqbtjBYzqM1uYn7wAAAHU"]
[Thu Jul 30 11:57:28.981342 2026] [core:notice] [pid 642360:tid 642439] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:29.217427 2026] [security2:error] [pid 642360:tid 642616] [client 172.237.109.114:17404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd5SUkh3e5AhEJOB7jwAAAg0"]
[Thu Jul 30 11:57:29.229015 2026] [security2:error] [pid 642360:tid 642499] [client 172.237.109.114:11191] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd5SUkh3e5AhEJOB7fAAAAZg"]
[Thu Jul 30 11:57:29.237212 2026] [security2:error] [pid 642360:tid 642532] [client 172.237.109.114:25339] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd5SUkh3e5AhEJOB7jQAAAbk"]
[Thu Jul 30 11:57:29.243463 2026] [security2:error] [pid 642360:tid 642592] [client 172.237.109.114:62653] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd5SUkh3e5AhEJOB7ggAAAfU"]
[Thu Jul 30 11:57:29.250461 2026] [security2:error] [pid 642360:tid 642514] [client 172.237.109.114:20534] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd5SUkh3e5AhEJOB7fwAAAac"]
[Thu Jul 30 11:57:29.250567 2026] [security2:error] [pid 642360:tid 642594] [client 172.237.109.114:2021] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd5SUkh3e5AhEJOB7hQAAAfc"]
[Thu Jul 30 11:57:29.256929 2026] [security2:error] [pid 642360:tid 642587] [client 172.237.109.114:16153] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd5SUkh3e5AhEJOB7iAAAAfA"]
[Thu Jul 30 11:57:29.271495 2026] [security2:error] [pid 642360:tid 642529] [client 172.237.109.114:36059] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd5SUkh3e5AhEJOB7hwAAAbY"]
[Thu Jul 30 11:57:29.275234 2026] [core:notice] [pid 642360:tid 642462] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:29.289146 2026] [security2:error] [pid 642360:tid 642560] [client 172.237.109.114:16152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd5SUkh3e5AhEJOB7iwAAAdU"]
[Thu Jul 30 11:57:29.325689 2026] [security2:error] [pid 642360:tid 642578] [client 172.237.109.114:29282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd5SUkh3e5AhEJOB7gQAAAec"]
[Thu Jul 30 11:57:29.337371 2026] [security2:error] [pid 642360:tid 642601] [client 172.237.109.114:5319] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd5SUkh3e5AhEJOB7jgAAAf4"]
[Thu Jul 30 11:57:29.382327 2026] [security2:error] [pid 642360:tid 642614] [client 172.237.109.114:44812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd5SUkh3e5AhEJOB7kAAAAgs"]
[Thu Jul 30 11:57:29.391651 2026] [security2:error] [pid 642360:tid 642617] [client 172.237.109.114:41994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd5SUkh3e5AhEJOB7iQAAAg4"]
[Thu Jul 30 11:57:29.424527 2026] [security2:error] [pid 642360:tid 642582] [client 172.237.109.114:60718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd5SUkh3e5AhEJOB7hgAAAes"]
[Thu Jul 30 11:57:29.442245 2026] [security2:error] [pid 642360:tid 642503] [client 172.237.109.114:15898] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd5SUkh3e5AhEJOB7jAAAAZw"]
[Thu Jul 30 11:57:29.449092 2026] [security2:error] [pid 642360:tid 642504] [client 172.237.109.114:29791] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd5SUkh3e5AhEJOB7igAAAZ0"]
[Thu Jul 30 11:57:31.309110 2026] [security2:error] [pid 643253:tid 643466] [client 34.194.226.74:35382] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "ai-kr.com"] [uri "/"] [unique_id "amuCe8jqbtjBYzqM1uYoAgAAAFI"]
[Thu Jul 30 11:57:32.965856 2026] [core:notice] [pid 643253:tid 643435] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:32.970331 2026] [security2:error] [pid 643253:tid 643435] [client 103.215.74.26:58206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCfMjqbtjBYzqM1uYoCAAAADM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:33.352663 2026] [security2:error] [pid 643253:tid 643275] [remote 74.7.241.60:54156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/img/article.php"] [unique_id "amuCfcjqbtjBYzqM1uYoCgAAYhQ"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/img/main_image_6a2a8e70efd49.jpg
[Thu Jul 30 11:57:33.643647 2026] [core:notice] [pid 643253:tid 643467] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:33.692842 2026] [core:notice] [pid 643253:tid 643426] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:33.697512 2026] [security2:error] [pid 643253:tid 643426] [client 103.215.74.26:62538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCfcjqbtjBYzqM1uYoEQAAACo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:33.796734 2026] [security2:error] [pid 642360:tid 642530] [client 172.213.208.20:6464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/2.php"] [unique_id "amuCfZSUkh3e5AhEJOB74wAAAbc"]
[Thu Jul 30 11:57:34.422924 2026] [core:notice] [pid 643253:tid 643484] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:34.426771 2026] [security2:error] [pid 643253:tid 643484] [client 103.215.74.26:62554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCfsjqbtjBYzqM1uYoFQAAAGQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:34.446959 2026] [security2:error] [pid 643253:tid 643493] [client 172.213.208.20:6524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "amuCfsjqbtjBYzqM1uYoFgAAAG0"]
[Thu Jul 30 11:57:35.171488 2026] [core:notice] [pid 643253:tid 643447] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:35.175423 2026] [security2:error] [pid 643253:tid 643447] [client 103.215.74.26:62562] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "761"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCf8jqbtjBYzqM1uYoHAAAAD8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:35.905709 2026] [core:notice] [pid 642360:tid 642575] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:35.909827 2026] [security2:error] [pid 642360:tid 642575] [client 103.215.74.26:62566] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCf5SUkh3e5AhEJOB7-AAAAeQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:36.525911 2026] [security2:error] [pid 643253:tid 643404] [client 172.213.208.20:44805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/mah.php"] [unique_id "amuCgMjqbtjBYzqM1uYoIgAAABQ"]
[Thu Jul 30 11:57:36.660691 2026] [core:notice] [pid 643253:tid 643501] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:36.813784 2026] [security2:error] [pid 643253:tid 643445] [client 43.173.174.102:51526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.174.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/11/09/au-hasard-toile-29/"] [unique_id "amuCgMjqbtjBYzqM1uYoIwAAAD0"]
[Thu Jul 30 11:57:36.832045 2026] [core:notice] [pid 643253:tid 643414] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:36.984694 2026] [security2:error] [pid 643253:tid 643499] [client 14.173.161.232:59234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCgMjqbtjBYzqM1uYoJAAAAHM"], referer: http://pkf.jo
[Thu Jul 30 11:57:37.132637 2026] [security2:error] [pid 642360:tid 642534] [client 85.208.96.193:64486] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/12/21/morre-o-ator-pedro-paulo-rangel-de-gabriela-e-o-cravo-e-a-rosa-aos-74-anos/"] [unique_id "amuCgZSUkh3e5AhEJOB8CgAAAbs"]
[Thu Jul 30 11:57:37.132789 2026] [security2:error] [pid 642360:tid 642534] [client 85.208.96.193:64486] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/12/21/morre-o-ator-pedro-paulo-rangel-de-gabriela-e-o-cravo-e-a-rosa-aos-74-anos/"] [unique_id "amuCgZSUkh3e5AhEJOB8CgAAAbs"]
[Thu Jul 30 11:57:37.431057 2026] [core:notice] [pid 642360:tid 642500] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:37.435739 2026] [security2:error] [pid 642360:tid 642500] [client 43.173.180.250:43434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/11/09/au-hasard-toile-29/"] [unique_id "amuCgZSUkh3e5AhEJOB8EAAAAZk"], referer: https://carnetdeshopping.com/index.php/2014/11/09/au-hasard-toile-29/
[Thu Jul 30 11:57:37.512260 2026] [security2:error] [pid 642360:tid 642379] [remote 72.167.132.114:59504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kamiliacademy.com"] [uri "/wp-login.php"] [unique_id "amuCgZSUkh3e5AhEJOB8EQABwRI"]
[Thu Jul 30 11:57:37.615895 2026] [security2:error] [pid 642360:tid 642490] [client 102.209.220.142:9241] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCgZSUkh3e5AhEJOB8DwAAAY8"], referer: http://pkf.jo
[Thu Jul 30 11:57:38.080392 2026] [security2:error] [pid 642360:tid 642513] [client 36.50.197.107:46458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCgZSUkh3e5AhEJOB8GQAAAaY"], referer: http://pkf.jo
[Thu Jul 30 11:57:38.141380 2026] [security2:error] [pid 642360:tid 642576] [client 176.241.66.87:55714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCgpSUkh3e5AhEJOB8HwAAAeU"]
[Thu Jul 30 11:57:38.141506 2026] [security2:error] [pid 642360:tid 642576] [client 176.241.66.87:55714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCgpSUkh3e5AhEJOB8HwAAAeU"]
[Thu Jul 30 11:57:38.201626 2026] [security2:error] [pid 642360:tid 642593] [client 202.163.81.152:21373] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCgZSUkh3e5AhEJOB8GgAAAfY"], referer: http://pkf.jo
[Thu Jul 30 11:57:38.502881 2026] [security2:error] [pid 642360:tid 642550] [client 160.226.222.221:40060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCgpSUkh3e5AhEJOB8IAAAAcs"], referer: http://pkf.jo
[Thu Jul 30 11:57:39.223633 2026] [core:error] [pid 642360:tid 642377] [remote 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:57:39.223653 2026] [core:error] [pid 642360:tid 642377] [remote 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:57:39.334058 2026] [core:error] [pid 642360:tid 642506] [client 74.7.228.63:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:57:39.334087 2026] [core:error] [pid 642360:tid 642506] [client 74.7.228.63:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:57:39.334206 2026] [security2:error] [pid 642360:tid 642506] [client 74.7.228.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.zmt.fcn.temporary.site"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amuCg5SUkh3e5AhEJOB8OwAAAZ8"]
[Thu Jul 30 11:57:39.334776 2026] [security2:error] [pid 642360:tid 642592] [client 74.7.228.63:42494] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.zmt.fcn.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuCg5SUkh3e5AhEJOB8OQAB9QA"]
[Thu Jul 30 11:57:39.484307 2026] [security2:error] [pid 642360:tid 642581] [client 172.213.208.20:36522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/send.php"] [unique_id "amuCg5SUkh3e5AhEJOB8PQAAAeo"]
[Thu Jul 30 11:57:40.282731 2026] [security2:error] [pid 642360:tid 642536] [client 74.7.228.31:37970] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.eow.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuChJSUkh3e5AhEJOB8RgABvRw"]
[Thu Jul 30 11:57:41.640118 2026] [core:notice] [pid 642360:tid 642571] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:41.647157 2026] [security2:error] [pid 642360:tid 642571] [client 103.215.74.26:62572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuChZSUkh3e5AhEJOB8XwAAAeA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:41.765345 2026] [security2:error] [pid 642360:tid 642543] [client 172.213.208.20:36488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amuChZSUkh3e5AhEJOB8YAAAAcQ"]
[Thu Jul 30 11:57:42.379565 2026] [core:notice] [pid 642360:tid 642555] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:42.386335 2026] [security2:error] [pid 642360:tid 642555] [client 103.215.74.26:62574] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuChpSUkh3e5AhEJOB8bgAAAdA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:43.120893 2026] [core:notice] [pid 643253:tid 643405] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:43.127761 2026] [security2:error] [pid 643253:tid 643405] [client 103.215.74.26:31256] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCh8jqbtjBYzqM1uYoNAAAABU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:43.877274 2026] [core:notice] [pid 643253:tid 643474] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:43.881321 2026] [security2:error] [pid 643253:tid 643474] [client 103.215.74.26:31272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCh8jqbtjBYzqM1uYoNgAAAFo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:44.547635 2026] [core:notice] [pid 643253:tid 643396] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:44.602700 2026] [core:notice] [pid 642360:tid 642520] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:44.607707 2026] [security2:error] [pid 642360:tid 642520] [client 103.215.74.26:31280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "777"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCiJSUkh3e5AhEJOB8lAAAAa0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:44.702742 2026] [core:notice] [pid 642360:tid 642415] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:45.290077 2026] [core:notice] [pid 642360:tid 642393] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:45.385624 2026] [proxy:error] [pid 642360:tid 642590] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:57:45.385685 2026] [proxy_http:error] [pid 642360:tid 642590] [client 44.216.125.112:51279] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:57:45.386262 2026] [proxy:error] [pid 642360:tid 642590] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:57:45.386313 2026] [proxy_http:error] [pid 642360:tid 642590] [client 44.216.125.112:51279] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:57:45.960299 2026] [core:error] [pid 642360:tid 642599] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:57:45.960326 2026] [core:error] [pid 642360:tid 642599] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:57:45.971943 2026] [core:error] [pid 642360:tid 642561] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:57:45.971959 2026] [core:error] [pid 642360:tid 642561] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:57:45.987853 2026] [core:error] [pid 642360:tid 642501] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:57:45.987871 2026] [core:error] [pid 642360:tid 642501] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:57:45.998163 2026] [core:error] [pid 642360:tid 642602] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:57:45.998188 2026] [core:error] [pid 642360:tid 642602] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:57:46.007964 2026] [core:error] [pid 642360:tid 642517] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:57:46.008002 2026] [core:error] [pid 642360:tid 642517] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:57:46.929783 2026] [security2:error] [pid 642360:tid 642575] [client 187.244.73.74:45224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCipSUkh3e5AhEJOB8vgAAAeQ"], referer: http://pkf.jo
[Thu Jul 30 11:57:48.854866 2026] [security2:error] [pid 643253:tid 643469] [client 176.241.66.87:40407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCjMjqbtjBYzqM1uYoUgAAAFU"]
[Thu Jul 30 11:57:48.855024 2026] [security2:error] [pid 643253:tid 643469] [client 176.241.66.87:40407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCjMjqbtjBYzqM1uYoUgAAAFU"]
[Thu Jul 30 11:57:49.502030 2026] [security2:error] [pid 643253:tid 643414] [client 157.34.209.103:37249] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCjcjqbtjBYzqM1uYoVAAAAB4"], referer: http://pkf.jo
[Thu Jul 30 11:57:50.036634 2026] [security2:error] [pid 643253:tid 643499] [client 20.226.5.174:27875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/011i.php"] [unique_id "amuCjsjqbtjBYzqM1uYoVgAAAHM"]
[Thu Jul 30 11:57:50.053794 2026] [security2:error] [pid 642360:tid 642497] [client 74.7.230.21:34694] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-54a868fb.vdb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuCjpSUkh3e5AhEJOB87AABlmQ"]
[Thu Jul 30 11:57:50.164854 2026] [security2:error] [pid 642360:tid 642547] [client 87.217.47.18:57682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCjZSUkh3e5AhEJOB86gAAAcg"], referer: http://pkf.jo
[Thu Jul 30 11:57:50.232039 2026] [security2:error] [pid 642360:tid 642537] [client 102.129.68.138:34708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCjZSUkh3e5AhEJOB86wAAAb4"], referer: http://pkf.jo
[Thu Jul 30 11:57:50.361442 2026] [core:notice] [pid 642360:tid 642563] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:50.368262 2026] [security2:error] [pid 642360:tid 642563] [client 103.215.74.26:31288] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCjpSUkh3e5AhEJOB88AAAAdg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:50.554784 2026] [security2:error] [pid 642360:tid 642572] [client 74.7.244.24:48900] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "webmail.asd.fyv.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuCjpSUkh3e5AhEJOB89QAAAeE"]
[Thu Jul 30 11:57:51.126002 2026] [core:notice] [pid 642360:tid 642514] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:51.130445 2026] [security2:error] [pid 642360:tid 642514] [client 103.215.74.26:31294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "790"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCj5SUkh3e5AhEJOB8_gAAAac"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:51.178188 2026] [security2:error] [pid 642360:tid 642609] [client 37.120.155.179:58432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.155.120.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuCj5SUkh3e5AhEJOB9AAAAAgY"]
[Thu Jul 30 11:57:51.178317 2026] [security2:error] [pid 642360:tid 642609] [client 37.120.155.179:58432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuCj5SUkh3e5AhEJOB9AAAAAgY"]
[Thu Jul 30 11:57:51.191721 2026] [security2:error] [pid 642360:tid 642578] [client 20.226.5.174:28270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/03a005685d.php"] [unique_id "amuCj5SUkh3e5AhEJOB9AQAAAec"]
[Thu Jul 30 11:57:51.736135 2026] [security2:error] [pid 642360:tid 642522] [client 57.141.0.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCj5SUkh3e5AhEJOB8_wAAAa8"]
[Thu Jul 30 11:57:51.821823 2026] [security2:error] [pid 642360:tid 642566] [client 172.213.208.20:36274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/about.php"] [unique_id "amuCj5SUkh3e5AhEJOB9CAAAAds"]
[Thu Jul 30 11:57:51.866294 2026] [core:notice] [pid 643253:tid 643400] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:51.871155 2026] [security2:error] [pid 643253:tid 643400] [client 103.215.74.26:31300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCj8jqbtjBYzqM1uYoXAAAABA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:52.500818 2026] [security2:error] [pid 642360:tid 642520] [client 20.226.5.174:28236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/403.php"] [unique_id "amuCkJSUkh3e5AhEJOB9EwAAAa0"]
[Thu Jul 30 11:57:52.636763 2026] [core:notice] [pid 642360:tid 642538] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:52.640823 2026] [security2:error] [pid 642360:tid 642538] [client 103.215.74.26:31306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "764"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCkJSUkh3e5AhEJOB9GAAAAb8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:52.773491 2026] [security2:error] [pid 643253:tid 643454] [client 172.213.208.20:27253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/options.php"] [unique_id "amuCkMjqbtjBYzqM1uYoYwAAAEY"]
[Thu Jul 30 11:57:53.385754 2026] [core:notice] [pid 642360:tid 642589] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:53.392317 2026] [security2:error] [pid 642360:tid 642589] [client 103.215.74.26:6894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "770"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCkZSUkh3e5AhEJOB9IQAAAfI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:53.581434 2026] [security2:error] [pid 642360:tid 642492] [client 20.226.5.174:28233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/404.php"] [unique_id "amuCkZSUkh3e5AhEJOB9KAAAAZE"]
[Thu Jul 30 11:57:54.119026 2026] [core:notice] [pid 643253:tid 643429] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:54.123787 2026] [security2:error] [pid 643253:tid 643429] [client 103.215.74.26:6900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCksjqbtjBYzqM1uYoaQAAAC0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:54.407787 2026] [core:notice] [pid 643253:tid 643387] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:54.812916 2026] [security2:error] [pid 643253:tid 643503] [client 20.226.5.174:28242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/aa.php"] [unique_id "amuCksjqbtjBYzqM1uYobgAAAHc"]
[Thu Jul 30 11:57:54.864708 2026] [core:notice] [pid 643253:tid 643436] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:54.872559 2026] [security2:error] [pid 643253:tid 643436] [client 103.215.74.26:6914] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCksjqbtjBYzqM1uYobwAAADQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:54.880453 2026] [security2:error] [pid 642360:tid 642517] [client 49.36.105.4:42722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCkpSUkh3e5AhEJOB9NQAAAao"], referer: http://pkf.jo
[Thu Jul 30 11:57:54.978611 2026] [security2:error] [pid 643253:tid 643478] [client 64.31.3.126:32598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuCkcjqbtjBYzqM1uYoZAAAAEU"], referer: https://globalmarks.pk/2023/08/28/parent-guide-babys-first-tooth-and-what-parents-must-know/#comment-2269
[Thu Jul 30 11:57:55.212420 2026] [security2:error] [pid 642360:tid 642544] [client 154.208.54.20:7729] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCkpSUkh3e5AhEJOB9OQAAAcU"], referer: http://pkf.jo
[Thu Jul 30 11:57:55.220752 2026] [security2:error] [pid 642360:tid 642611] [client 172.213.208.20:15330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuCk5SUkh3e5AhEJOB9QAAAAgg"]
[Thu Jul 30 11:57:55.604464 2026] [core:notice] [pid 642360:tid 642617] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:55.608198 2026] [security2:error] [pid 642360:tid 642617] [client 103.215.74.26:6922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCk5SUkh3e5AhEJOB9RAAAAg4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:55.853959 2026] [security2:error] [pid 642360:tid 642526] [client 20.226.5.174:28313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/aafewc0k.php"] [unique_id "amuCk5SUkh3e5AhEJOB9SAAAAbM"]
[Thu Jul 30 11:57:56.130230 2026] [security2:error] [pid 642360:tid 642591] [client 172.213.208.20:52394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-file.php"] [unique_id "amuClJSUkh3e5AhEJOB9TQAAAfQ"]
[Thu Jul 30 11:57:56.364479 2026] [core:notice] [pid 643253:tid 643397] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:56.368797 2026] [security2:error] [pid 643253:tid 643397] [client 103.215.74.26:6938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuClMjqbtjBYzqM1uYocgAAAA0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:56.983740 2026] [core:notice] [pid 642360:tid 642520] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:57.090846 2026] [core:notice] [pid 642360:tid 642585] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:57.095020 2026] [security2:error] [pid 642360:tid 642585] [client 103.215.74.26:6954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuClZSUkh3e5AhEJOB9WgAAAe4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:57.104181 2026] [security2:error] [pid 643253:tid 643467] [client 172.213.208.20:16356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/sid3.php"] [unique_id "amuClcjqbtjBYzqM1uYodwAAAFM"]
[Thu Jul 30 11:57:57.305455 2026] [security2:error] [pid 643253:tid 643485] [client 20.226.5.174:28276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/abcd.php"] [unique_id "amuClcjqbtjBYzqM1uYoeQAAAGU"]
[Thu Jul 30 11:57:57.378262 2026] [security2:error] [pid 642360:tid 642510] [client 169.224.19.57:22868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuClZSUkh3e5AhEJOB9WQAAAaM"], referer: http://pkf.jo
[Thu Jul 30 11:57:57.830394 2026] [security2:error] [pid 642360:tid 642398] [remote 45.252.248.17:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.248.252.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "baitultateeqmoverscompany.com"] [uri "/xmlrpc.php"] [unique_id "amuClZSUkh3e5AhEJOB9ZwAB_CU"]
[Thu Jul 30 11:57:57.830548 2026] [security2:error] [pid 642360:tid 642599] [client 45.252.248.17:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "baitultateeqmoverscompany.com"] [uri "/xmlrpc.php"] [unique_id "amuClZSUkh3e5AhEJOB9ZwAB_CU"]
[Thu Jul 30 11:57:58.565208 2026] [security2:error] [pid 642360:tid 642496] [client 20.226.5.174:28237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/about.php"] [unique_id "amuClpSUkh3e5AhEJOB9cAAAAZU"]
[Thu Jul 30 11:57:59.556807 2026] [security2:error] [pid 642360:tid 642559] [client 176.241.66.87:41101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCl5SUkh3e5AhEJOB9gQAAAdQ"]
[Thu Jul 30 11:57:59.556952 2026] [security2:error] [pid 642360:tid 642559] [client 176.241.66.87:41101] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCl5SUkh3e5AhEJOB9gQAAAdQ"]
[Thu Jul 30 11:57:59.800680 2026] [security2:error] [pid 642360:tid 642519] [client 37.120.155.179:41252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.155.120.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuCl5SUkh3e5AhEJOB9hQAAAaw"]
[Thu Jul 30 11:57:59.800787 2026] [security2:error] [pid 642360:tid 642519] [client 37.120.155.179:41252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuCl5SUkh3e5AhEJOB9hQAAAaw"]
[Thu Jul 30 11:58:00.591111 2026] [core:error] [pid 643253:tid 643447] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:58:00.591136 2026] [core:error] [pid 643253:tid 643447] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:58:01.309871 2026] [core:notice] [pid 643253:tid 643303] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:01.536879 2026] [security2:error] [pid 643253:tid 643500] [client 20.226.5.174:28342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/admin.php"] [unique_id "amuCmcjqbtjBYzqM1uYojgAAAHQ"]
[Thu Jul 30 11:58:02.765852 2026] [security2:error] [pid 643253:tid 643412] [client 20.226.5.174:27943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/adminfuns.php"] [unique_id "amuCmsjqbtjBYzqM1uYokgAAABw"]
[Thu Jul 30 11:58:02.852059 2026] [core:notice] [pid 642360:tid 642552] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:02.856279 2026] [security2:error] [pid 642360:tid 642552] [client 103.215.74.26:6966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCmpSUkh3e5AhEJOB9rgAAAc0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:03.330534 2026] [security2:error] [pid 642360:tid 642529] [client 158.158.38.215:40022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.38.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuCm5SUkh3e5AhEJOB9swAAAbY"]
[Thu Jul 30 11:58:03.330648 2026] [security2:error] [pid 642360:tid 642529] [client 158.158.38.215:40022] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "globalmarks.pk"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuCm5SUkh3e5AhEJOB9swAAAbY"]
[Thu Jul 30 11:58:03.589343 2026] [core:notice] [pid 643253:tid 643385] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:03.594564 2026] [security2:error] [pid 643253:tid 643385] [client 103.215.74.26:31136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCm8jqbtjBYzqM1uYolgAAAAE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:03.605362 2026] [security2:error] [pid 643253:tid 643460] [client 158.158.38.215:36819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.38.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuCm8jqbtjBYzqM1uYolwAAAEw"]
[Thu Jul 30 11:58:03.605508 2026] [security2:error] [pid 643253:tid 643460] [client 158.158.38.215:36819] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "globalmarks.pk"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuCm8jqbtjBYzqM1uYolwAAAEw"]
[Thu Jul 30 11:58:03.809327 2026] [core:notice] [pid 642360:tid 642611] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:03.964688 2026] [security2:error] [pid 642360:tid 642592] [client 158.158.38.215:48422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.38.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wawe.php"] [unique_id "amuCm5SUkh3e5AhEJOB9vgAAAfU"]
[Thu Jul 30 11:58:03.964809 2026] [security2:error] [pid 642360:tid 642592] [client 158.158.38.215:48422] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "globalmarks.pk"] [uri "/wawe.php"] [unique_id "amuCm5SUkh3e5AhEJOB9vgAAAfU"]
[Thu Jul 30 11:58:03.988664 2026] [lsapi:error] [pid 643573:tid 643629] [remote 41.210.167.242:0] [host flixon.net] Error receiving response: ReceiveResponse: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1009; user ID 1009), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://flixon.net/video/the-killer-vj-junior/
[Thu Jul 30 11:58:04.278960 2026] [security2:error] [pid 643253:tid 643401] [client 158.158.38.215:42126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.38.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/alfa123.php"] [unique_id "amuCnMjqbtjBYzqM1uYomQAAABE"]
[Thu Jul 30 11:58:04.279104 2026] [security2:error] [pid 643253:tid 643401] [client 158.158.38.215:42126] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "globalmarks.pk"] [uri "/alfa123.php"] [unique_id "amuCnMjqbtjBYzqM1uYomQAAABE"]
[Thu Jul 30 11:58:04.327586 2026] [core:notice] [pid 642360:tid 642553] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:04.332053 2026] [security2:error] [pid 642360:tid 642553] [client 103.215.74.26:31148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCnJSUkh3e5AhEJOB9wgAAAc4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:04.639072 2026] [core:notice] [pid 642360:tid 642431] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:04.725795 2026] [core:notice] [pid 643253:tid 643391] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:04.741415 2026] [security2:error] [pid 642360:tid 642555] [client 158.158.38.215:48441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.38.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/kn.php"] [unique_id "amuCnJSUkh3e5AhEJOB9ygAAAdA"]
[Thu Jul 30 11:58:04.741499 2026] [security2:error] [pid 642360:tid 642555] [client 158.158.38.215:48441] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "globalmarks.pk"] [uri "/kn.php"] [unique_id "amuCnJSUkh3e5AhEJOB9ygAAAdA"]
[Thu Jul 30 11:58:05.057539 2026] [core:notice] [pid 642360:tid 642526] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:05.064634 2026] [security2:error] [pid 642360:tid 642526] [client 103.215.74.26:31158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCnZSUkh3e5AhEJOB9zwAAAbM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:05.143815 2026] [security2:error] [pid 642360:tid 642534] [client 158.158.38.215:42140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.38.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/class-wp.php"] [unique_id "amuCnZSUkh3e5AhEJOB91gAAAbs"]
[Thu Jul 30 11:58:05.143973 2026] [security2:error] [pid 642360:tid 642534] [client 158.158.38.215:42140] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "globalmarks.pk"] [uri "/class-wp.php"] [unique_id "amuCnZSUkh3e5AhEJOB91gAAAbs"]
[Thu Jul 30 11:58:05.629152 2026] [security2:error] [pid 643253:tid 643454] [client 158.158.38.215:36807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.38.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/shelp.php"] [unique_id "amuCncjqbtjBYzqM1uYoqwAAAEY"]
[Thu Jul 30 11:58:05.629331 2026] [security2:error] [pid 643253:tid 643454] [client 158.158.38.215:36807] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "globalmarks.pk"] [uri "/shelp.php"] [unique_id "amuCncjqbtjBYzqM1uYoqwAAAEY"]
[Thu Jul 30 11:58:05.805542 2026] [core:notice] [pid 643253:tid 643418] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:05.810223 2026] [security2:error] [pid 643253:tid 643418] [client 103.215.74.26:31174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCncjqbtjBYzqM1uYorAAAACI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:05.942465 2026] [security2:error] [pid 642360:tid 642510] [client 158.158.38.215:48389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.38.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/phpi.php"] [unique_id "amuCnZSUkh3e5AhEJOB94wAAAaM"]
[Thu Jul 30 11:58:05.942578 2026] [security2:error] [pid 642360:tid 642510] [client 158.158.38.215:48389] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "globalmarks.pk"] [uri "/phpi.php"] [unique_id "amuCnZSUkh3e5AhEJOB94wAAAaM"]
[Thu Jul 30 11:58:05.980332 2026] [security2:error] [pid 642360:tid 642610] [client 103.138.171.41:48196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCnZSUkh3e5AhEJOB93wAAAgc"], referer: http://pkf.jo
[Thu Jul 30 11:58:06.258738 2026] [core:error] [pid 642360:tid 642552] [client 34.150.193.0:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:58:06.258777 2026] [core:error] [pid 642360:tid 642552] [client 34.150.193.0:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:58:06.306189 2026] [security2:error] [pid 642360:tid 642569] [client 158.158.38.215:40054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.38.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/birlingsless.php"] [unique_id "amuCnpSUkh3e5AhEJOB99gAAAd4"]
[Thu Jul 30 11:58:06.306421 2026] [security2:error] [pid 642360:tid 642569] [client 158.158.38.215:40054] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "globalmarks.pk"] [uri "/birlingsless.php"] [unique_id "amuCnpSUkh3e5AhEJOB99gAAAd4"]
[Thu Jul 30 11:58:06.622497 2026] [security2:error] [pid 643253:tid 643425] [client 158.158.38.215:42532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.38.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/shell20211028.php"] [unique_id "amuCnsjqbtjBYzqM1uYouAAAACk"]
[Thu Jul 30 11:58:06.622688 2026] [security2:error] [pid 643253:tid 643425] [client 158.158.38.215:42532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "globalmarks.pk"] [uri "/shell20211028.php"] [unique_id "amuCnsjqbtjBYzqM1uYouAAAACk"]
[Thu Jul 30 11:58:06.940752 2026] [core:notice] [pid 642360:tid 642550] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:07.160991 2026] [core:error] [pid 642360:tid 642491] [client 34.150.193.0:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:58:07.161015 2026] [core:error] [pid 642360:tid 642491] [client 34.150.193.0:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:58:07.169620 2026] [core:notice] [pid 642360:tid 642517] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:07.237724 2026] [security2:error] [pid 643253:tid 643424] [client 172.237.109.114:21221] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCncjqbtjBYzqM1uYonwAAACg"]
[Thu Jul 30 11:58:07.239171 2026] [security2:error] [pid 642360:tid 642612] [client 172.237.109.114:6493] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnZSUkh3e5AhEJOB90AAAAgk"]
[Thu Jul 30 11:58:07.264374 2026] [security2:error] [pid 643253:tid 643400] [client 172.237.109.114:59849] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCncjqbtjBYzqM1uYopAAAABA"]
[Thu Jul 30 11:58:07.305330 2026] [security2:error] [pid 642360:tid 642574] [client 172.237.109.114:1378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnZSUkh3e5AhEJOB90QAAAeM"]
[Thu Jul 30 11:58:07.315515 2026] [security2:error] [pid 643253:tid 643421] [client 172.237.109.114:56738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCncjqbtjBYzqM1uYoogAAACU"]
[Thu Jul 30 11:58:07.327237 2026] [security2:error] [pid 642360:tid 642535] [client 158.158.38.215:36862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuCn5SUkh3e5AhEJOB-AQAAAbw"]
[Thu Jul 30 11:58:07.327278 2026] [security2:error] [pid 642360:tid 642535] [client 158.158.38.215:36862] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuCn5SUkh3e5AhEJOB-AQAAAbw"]
[Thu Jul 30 11:58:07.358949 2026] [security2:error] [pid 643253:tid 643476] [client 172.237.109.114:5069] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCncjqbtjBYzqM1uYoqAAAAFw"]
[Thu Jul 30 11:58:07.361198 2026] [security2:error] [pid 643253:tid 643509] [client 172.237.109.114:46418] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCncjqbtjBYzqM1uYooQAAAH0"]
[Thu Jul 30 11:58:07.362215 2026] [security2:error] [pid 643253:tid 643506] [client 172.237.109.114:43257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCncjqbtjBYzqM1uYoowAAAHo"]
[Thu Jul 30 11:58:07.387155 2026] [security2:error] [pid 642360:tid 642565] [client 172.237.109.114:14866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnZSUkh3e5AhEJOB92AAAAdo"]
[Thu Jul 30 11:58:07.443694 2026] [security2:error] [pid 643253:tid 643458] [client 172.237.109.114:51508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCncjqbtjBYzqM1uYongAAAEo"]
[Thu Jul 30 11:58:07.469110 2026] [security2:error] [pid 643253:tid 643431] [client 172.237.109.114:43452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCncjqbtjBYzqM1uYooAAAAC8"]
[Thu Jul 30 11:58:07.483244 2026] [security2:error] [pid 642360:tid 642591] [client 172.237.109.114:5467] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnZSUkh3e5AhEJOB91QAAAfQ"]
[Thu Jul 30 11:58:07.487909 2026] [security2:error] [pid 643253:tid 643386] [client 172.237.109.114:61139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCncjqbtjBYzqM1uYopgAAAAI"]
[Thu Jul 30 11:58:07.496093 2026] [security2:error] [pid 642360:tid 642542] [client 172.237.109.114:42570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnZSUkh3e5AhEJOB92QAAAcM"]
[Thu Jul 30 11:58:07.499194 2026] [security2:error] [pid 643253:tid 643440] [client 172.237.109.114:14719] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCncjqbtjBYzqM1uYopQAAADg"]
[Thu Jul 30 11:58:07.513021 2026] [security2:error] [pid 642360:tid 642608] [client 172.237.109.114:24887] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnZSUkh3e5AhEJOB91wAAAgU"]
[Thu Jul 30 11:58:07.696206 2026] [core:notice] [pid 643253:tid 643397] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:07.699273 2026] [security2:error] [pid 642360:tid 642615] [client 158.158.38.215:36862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.38.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-slss.php"] [unique_id "amuCn5SUkh3e5AhEJOB-CAAAAgw"]
[Thu Jul 30 11:58:07.699382 2026] [security2:error] [pid 642360:tid 642615] [client 158.158.38.215:36862] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "globalmarks.pk"] [uri "/wp-slss.php"] [unique_id "amuCn5SUkh3e5AhEJOB-CAAAAgw"]
[Thu Jul 30 11:58:08.242826 2026] [security2:error] [pid 642360:tid 642558] [client 172.237.109.114:64901] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnZSUkh3e5AhEJOB90gAAAdM"]
[Thu Jul 30 11:58:08.257106 2026] [security2:error] [pid 642360:tid 642524] [client 172.237.109.114:6195] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnZSUkh3e5AhEJOB90wAAAbE"]
[Thu Jul 30 11:58:08.294331 2026] [security2:error] [pid 643253:tid 643416] [client 172.237.109.114:11624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCncjqbtjBYzqM1uYoqQAAACA"]
[Thu Jul 30 11:58:08.308397 2026] [security2:error] [pid 642360:tid 642502] [client 172.237.109.114:54403] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnZSUkh3e5AhEJOB91AAAAZs"]
[Thu Jul 30 11:58:08.399473 2026] [security2:error] [pid 643253:tid 643406] [client 172.237.109.114:64203] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCncjqbtjBYzqM1uYopwAAABY"]
[Thu Jul 30 11:58:08.499093 2026] [security2:error] [pid 642360:tid 642528] [client 158.158.38.215:42504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuCoJSUkh3e5AhEJOB-FQAAAbU"]
[Thu Jul 30 11:58:08.499131 2026] [security2:error] [pid 642360:tid 642528] [client 158.158.38.215:42504] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuCoJSUkh3e5AhEJOB-FQAAAbU"]
[Thu Jul 30 11:58:08.541083 2026] [autoindex:error] [pid 642360:tid 642526] [client 20.193.250.173:59086] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_d35de2e9/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Thu Jul 30 11:58:08.567798 2026] [security2:error] [pid 642360:tid 642518] [client 172.237.109.114:60938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnpSUkh3e5AhEJOB96gAAAas"]
[Thu Jul 30 11:58:08.721157 2026] [security2:error] [pid 643253:tid 643409] [client 103.240.207.111:14618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCoMjqbtjBYzqM1uYowQAAABk"], referer: http://pkf.jo
[Thu Jul 30 11:58:08.904953 2026] [security2:error] [pid 642360:tid 642490] [client 158.158.38.215:42504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.38.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/amxloxxr.php"] [unique_id "amuCoJSUkh3e5AhEJOB-IAAAAY8"]
[Thu Jul 30 11:58:08.905085 2026] [security2:error] [pid 642360:tid 642490] [client 158.158.38.215:42504] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "globalmarks.pk"] [uri "/amxloxxr.php"] [unique_id "amuCoJSUkh3e5AhEJOB-IAAAAY8"]
[Thu Jul 30 11:58:09.099879 2026] [security2:error] [pid 642360:tid 642577] [client 94.54.228.168:37072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCoJSUkh3e5AhEJOB-HAAAAeY"], referer: http://pkf.jo
[Thu Jul 30 11:58:09.265244 2026] [security2:error] [pid 642360:tid 642571] [client 172.237.109.114:28688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnpSUkh3e5AhEJOB96QAAAeA"]
[Thu Jul 30 11:58:09.266513 2026] [security2:error] [pid 642360:tid 642492] [client 172.237.109.114:29036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnpSUkh3e5AhEJOB96wAAAZE"]
[Thu Jul 30 11:58:09.276808 2026] [security2:error] [pid 642360:tid 642545] [client 172.237.109.114:14982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnpSUkh3e5AhEJOB97QAAAcY"]
[Thu Jul 30 11:58:09.353085 2026] [security2:error] [pid 642360:tid 642523] [client 172.237.109.114:14858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnpSUkh3e5AhEJOB97AAAAbA"]
[Thu Jul 30 11:58:09.358201 2026] [security2:error] [pid 642360:tid 642511] [client 172.237.109.114:15897] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnpSUkh3e5AhEJOB98AAAAaQ"]
[Thu Jul 30 11:58:09.358483 2026] [security2:error] [pid 643253:tid 643453] [client 172.237.109.114:62041] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnsjqbtjBYzqM1uYorgAAAEU"]
[Thu Jul 30 11:58:09.378795 2026] [security2:error] [pid 642360:tid 642541] [client 172.237.109.114:50454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnpSUkh3e5AhEJOB96AAAAcI"]
[Thu Jul 30 11:58:09.400052 2026] [security2:error] [pid 643253:tid 643444] [client 172.237.109.114:64428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnsjqbtjBYzqM1uYosAAAADw"]
[Thu Jul 30 11:58:09.401236 2026] [security2:error] [pid 643253:tid 643511] [client 172.237.109.114:7712] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnsjqbtjBYzqM1uYosQAAAH8"]
[Thu Jul 30 11:58:09.420395 2026] [security2:error] [pid 642360:tid 642606] [client 172.237.109.114:42338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnpSUkh3e5AhEJOB97gAAAgM"]
[Thu Jul 30 11:58:09.468717 2026] [security2:error] [pid 643253:tid 643487] [client 172.237.109.114:8442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnsjqbtjBYzqM1uYoswAAAGc"]
[Thu Jul 30 11:58:09.476035 2026] [security2:error] [pid 643253:tid 643439] [client 172.237.109.114:19530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnsjqbtjBYzqM1uYorwAAADc"]
[Thu Jul 30 11:58:09.477198 2026] [security2:error] [pid 643253:tid 643410] [client 172.237.109.114:52843] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnsjqbtjBYzqM1uYotAAAABo"]
[Thu Jul 30 11:58:09.485273 2026] [security2:error] [pid 642360:tid 642607] [client 172.237.109.114:59630] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnpSUkh3e5AhEJOB97wAAAgQ"]
[Thu Jul 30 11:58:09.500421 2026] [security2:error] [pid 642360:tid 642599] [client 172.237.109.114:25661] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnpSUkh3e5AhEJOB98QAAAfw"]
[Thu Jul 30 11:58:09.503992 2026] [security2:error] [pid 642360:tid 642586] [client 172.237.109.114:32839] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnpSUkh3e5AhEJOB98gAAAe8"]
[Thu Jul 30 11:58:09.547763 2026] [security2:error] [pid 643253:tid 643405] [client 172.237.109.114:27813] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnsjqbtjBYzqM1uYotQAAABU"]
[Thu Jul 30 11:58:09.547785 2026] [security2:error] [pid 643253:tid 643429] [client 172.237.109.114:37668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnsjqbtjBYzqM1uYosgAAAC0"]
[Thu Jul 30 11:58:10.110691 2026] [security2:error] [pid 643253:tid 643486] [client 176.241.66.87:41813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCosjqbtjBYzqM1uYozQAAAGY"]
[Thu Jul 30 11:58:10.110834 2026] [security2:error] [pid 643253:tid 643486] [client 176.241.66.87:41813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCosjqbtjBYzqM1uYozQAAAGY"]
[Thu Jul 30 11:58:10.182018 2026] [security2:error] [pid 642360:tid 642535] [client 196.217.180.183:46272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCoZSUkh3e5AhEJOB-LwAAAbw"], referer: http://pkf.jo
[Thu Jul 30 11:58:11.521598 2026] [core:notice] [pid 642360:tid 642553] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:11.526664 2026] [security2:error] [pid 642360:tid 642553] [client 103.215.74.26:31196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCo5SUkh3e5AhEJOB-QQAAAc4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:12.256606 2026] [core:notice] [pid 642360:tid 642516] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:12.260921 2026] [security2:error] [pid 642360:tid 642516] [client 103.215.74.26:31210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCpJSUkh3e5AhEJOB-SwAAAak"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:13.004897 2026] [core:notice] [pid 642360:tid 642564] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:13.008875 2026] [security2:error] [pid 642360:tid 642564] [client 103.215.74.26:31226] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCpZSUkh3e5AhEJOB-VgAAAdk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:13.172889 2026] [core:notice] [pid 642360:tid 642596] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:13.714274 2026] [core:notice] [pid 642360:tid 642523] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:13.752063 2026] [core:notice] [pid 642360:tid 642521] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:13.756276 2026] [security2:error] [pid 642360:tid 642521] [client 103.215.74.26:12112] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "761"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCpZSUkh3e5AhEJOB-XQAAAa4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:13.920569 2026] [core:notice] [pid 642360:tid 642557] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:14.335115 2026] [security2:error] [pid 642360:tid 642537] [client 74.7.241.191:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.inmobiliariadia.com.tfy.udi.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuCppSUkh3e5AhEJOB-aAAAAb4"]
[Thu Jul 30 11:58:14.335735 2026] [security2:error] [pid 643253:tid 643510] [client 74.7.241.191:53320] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.inmobiliariadia.com.tfy.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amuCpsjqbtjBYzqM1uYo3QAAfjk"]
[Thu Jul 30 11:58:14.847924 2026] [security2:error] [pid 642360:tid 642561] [client 20.226.5.174:27915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/albin.php"] [unique_id "amuCppSUkh3e5AhEJOB-cAAAAdY"]
[Thu Jul 30 11:58:15.081903 2026] [proxy:error] [pid 643253:tid 643403] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:58:15.081957 2026] [proxy_http:error] [pid 643253:tid 643403] [client 185.247.137.138:46381] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:58:15.082538 2026] [proxy:error] [pid 643253:tid 643403] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:58:15.082582 2026] [proxy_http:error] [pid 643253:tid 643403] [client 185.247.137.138:46381] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:58:15.138303 2026] [security2:error] [pid 642360:tid 642506] [client 57.141.0.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCppSUkh3e5AhEJOB-bQAAAZ8"]
[Thu Jul 30 11:58:15.178757 2026] [autoindex:error] [pid 643253:tid 643479] [client 74.7.242.49:0] AH01276: Cannot serve directory /home2/tfyudite/inmobiliariadia.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:16.154383 2026] [security2:error] [pid 642360:tid 642601] [client 20.226.5.174:27925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/amfsqvgv.php"] [unique_id "amuCqJSUkh3e5AhEJOB-hAAAAf4"]
[Thu Jul 30 11:58:16.174607 2026] [core:notice] [pid 643253:tid 643417] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:16.223556 2026] [core:notice] [pid 643253:tid 643491] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:16.228376 2026] [security2:error] [pid 643253:tid 643491] [client 195.23.32.200:54656] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.carnetdeshopping.com"] [uri "/feed/"] [unique_id "amuCqMjqbtjBYzqM1uYo5wAAAGs"]
[Thu Jul 30 11:58:17.132863 2026] [core:notice] [pid 643253:tid 643485] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:17.137601 2026] [security2:error] [pid 643253:tid 643485] [client 195.23.32.200:54744] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/feed/"] [unique_id "amuCqcjqbtjBYzqM1uYo6gAAAGU"]
[Thu Jul 30 11:58:17.252376 2026] [security2:error] [pid 642360:tid 642494] [client 20.226.5.174:34777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/ant.php"] [unique_id "amuCqZSUkh3e5AhEJOB-lgAAAZM"]
[Thu Jul 30 11:58:18.701253 2026] [security2:error] [pid 643253:tid 643416] [client 195.23.32.200:54810] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuCqsjqbtjBYzqM1uYo7gAAACA"]
[Thu Jul 30 11:58:19.360538 2026] [security2:error] [pid 642360:tid 642616] [client 189.244.154.225:41928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCq5SUkh3e5AhEJOB-qgAAAg0"], referer: http://pkf.jo
[Thu Jul 30 11:58:19.469431 2026] [core:notice] [pid 643253:tid 643457] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:19.473292 2026] [security2:error] [pid 643253:tid 643457] [client 103.215.74.26:12122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCq8jqbtjBYzqM1uYo9AAAAEk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:19.495887 2026] [security2:error] [pid 643253:tid 643492] [client 213.152.161.219:59346] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuCq8jqbtjBYzqM1uYo8gAAAGw"]
[Thu Jul 30 11:58:19.496024 2026] [security2:error] [pid 643253:tid 643492] [client 213.152.161.219:59346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuCq8jqbtjBYzqM1uYo8gAAAGw"]
[Thu Jul 30 11:58:20.207528 2026] [core:notice] [pid 643253:tid 643453] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:20.212001 2026] [security2:error] [pid 643253:tid 643453] [client 103.215.74.26:12128] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCrMjqbtjBYzqM1uYo9wAAAEU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:20.734174 2026] [security2:error] [pid 642360:tid 642580] [client 176.241.66.87:58292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCrJSUkh3e5AhEJOB-wgAAAek"]
[Thu Jul 30 11:58:20.734293 2026] [security2:error] [pid 642360:tid 642580] [client 176.241.66.87:58292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCrJSUkh3e5AhEJOB-wgAAAek"]
[Thu Jul 30 11:58:20.946000 2026] [core:notice] [pid 642360:tid 642496] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:20.952495 2026] [security2:error] [pid 642360:tid 642496] [client 103.215.74.26:12144] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCrJSUkh3e5AhEJOB-xgAAAZU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:21.187817 2026] [security2:error] [pid 642360:tid 642593] [client 20.226.5.174:34601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/appreciators.php"] [unique_id "amuCrZSUkh3e5AhEJOB-yAAAAfY"]
[Thu Jul 30 11:58:21.270437 2026] [autoindex:error] [pid 642360:tid 642551] [client 52.202.41.153:56141] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_cfd6e8f6/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:21.677105 2026] [core:notice] [pid 642360:tid 642589] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:21.684763 2026] [security2:error] [pid 642360:tid 642589] [client 103.215.74.26:12148] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCrZSUkh3e5AhEJOB-0QAAAfI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:22.409672 2026] [core:notice] [pid 643253:tid 643420] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:22.416333 2026] [security2:error] [pid 643253:tid 643420] [client 103.215.74.26:12164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCrsjqbtjBYzqM1uYo_wAAACQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:22.858031 2026] [security2:error] [pid 642360:tid 642597] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mannyplatoncuevas.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "amuCrpSUkh3e5AhEJOB-5AAAAfo"]
[Thu Jul 30 11:58:23.423069 2026] [security2:error] [pid 642360:tid 642363] [remote 57.141.0.19:54032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuCr5SUkh3e5AhEJOB-7QABoQI"]
[Thu Jul 30 11:58:23.499896 2026] [security2:error] [pid 643253:tid 643433] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mannyplatoncuevas.com"] [uri "/media/system/js/core.js"] [unique_id "amuCr8jqbtjBYzqM1uYpAQAAADE"]
[Thu Jul 30 11:58:23.809459 2026] [security2:error] [pid 643253:tid 643500] [client 20.226.5.174:34770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/archive.php"] [unique_id "amuCr8jqbtjBYzqM1uYpAwAAAHQ"]
[Thu Jul 30 11:58:24.011844 2026] [core:notice] [pid 642360:tid 642512] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:24.643251 2026] [security2:error] [pid 642360:tid 642372] [remote 47.128.28.119:39480] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/nike-air-jordan-1-high-og-wmns-silver-toe/"] [unique_id "amuCsJSUkh3e5AhEJOB-_QABxgs"]
[Thu Jul 30 11:58:24.923385 2026] [core:notice] [pid 643253:tid 643414] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:24.951494 2026] [security2:error] [pid 642360:tid 642424] [remote 57.141.0.25:36296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuCsJSUkh3e5AhEJOB_AQABzD8"]
[Thu Jul 30 11:58:25.022514 2026] [core:notice] [pid 642360:tid 642513] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:25.126271 2026] [security2:error] [pid 642360:tid 642500] [client 20.226.5.174:34586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/as.php"] [unique_id "amuCsZSUkh3e5AhEJOB_BgAAAZk"]
[Thu Jul 30 11:58:25.471910 2026] [core:notice] [pid 642360:tid 642556] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:27.348953 2026] [security2:error] [pid 643253:tid 643498] [client 213.152.161.219:49394] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCs8jqbtjBYzqM1uYpCQAAAHI"]
[Thu Jul 30 11:58:27.349067 2026] [security2:error] [pid 643253:tid 643498] [client 213.152.161.219:49394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCs8jqbtjBYzqM1uYpCQAAAHI"]
[Thu Jul 30 11:58:27.738496 2026] [autoindex:error] [pid 642360:tid 642417] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:27.739426 2026] [security2:error] [pid 642360:tid 642490] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCs5SUkh3e5AhEJOB_MQABjzg"]
[Thu Jul 30 11:58:28.127258 2026] [core:notice] [pid 642360:tid 642568] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:28.131241 2026] [security2:error] [pid 642360:tid 642568] [client 103.215.74.26:38634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "777"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCtJSUkh3e5AhEJOB_NgAAAd0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:28.145831 2026] [autoindex:error] [pid 642360:tid 642412] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:28.146681 2026] [security2:error] [pid 642360:tid 642511] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCtJSUkh3e5AhEJOB_NwABpDM"]
[Thu Jul 30 11:58:28.315546 2026] [autoindex:error] [pid 642360:tid 642437] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:28.316443 2026] [security2:error] [pid 642360:tid 642590] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCtJSUkh3e5AhEJOB_PQAB80w"]
[Thu Jul 30 11:58:28.388613 2026] [security2:error] [pid 642360:tid 642522] [client 2a03:2880:f800:17:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuCs5SUkh3e5AhEJOB_KwABrzw"]
[Thu Jul 30 11:58:28.483777 2026] [autoindex:error] [pid 642360:tid 642418] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:28.484622 2026] [security2:error] [pid 642360:tid 642584] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCtJSUkh3e5AhEJOB_PgAB7Tk"]
[Thu Jul 30 11:58:28.650934 2026] [autoindex:error] [pid 642360:tid 642378] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:28.651707 2026] [security2:error] [pid 642360:tid 642556] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCtJSUkh3e5AhEJOB_QAAB0RE"]
[Thu Jul 30 11:58:28.819245 2026] [autoindex:error] [pid 642360:tid 642440] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:28.820020 2026] [security2:error] [pid 642360:tid 642594] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCtJSUkh3e5AhEJOB_RwAB908"]
[Thu Jul 30 11:58:28.901171 2026] [core:notice] [pid 642360:tid 642586] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:28.907613 2026] [security2:error] [pid 642360:tid 642586] [client 103.215.74.26:38644] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCtJSUkh3e5AhEJOB_SgAAAe8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:28.989338 2026] [autoindex:error] [pid 642360:tid 642401] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/SimplePie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:28.990106 2026] [security2:error] [pid 642360:tid 642491] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCtJSUkh3e5AhEJOB_SwABkCg"]
[Thu Jul 30 11:58:29.160504 2026] [autoindex:error] [pid 642360:tid 642419] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:29.161514 2026] [security2:error] [pid 642360:tid 642612] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCtZSUkh3e5AhEJOB_TwACCTo"]
[Thu Jul 30 11:58:29.646214 2026] [core:notice] [pid 643253:tid 643387] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:29.651324 2026] [security2:error] [pid 643253:tid 643387] [client 103.215.74.26:38648] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "790"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCtcjqbtjBYzqM1uYpEAAAAAM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:29.652971 2026] [security2:error] [pid 642360:tid 642505] [client 2a03:2880:f800:26:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuCtZSUkh3e5AhEJOB_TAABnjE"]
[Thu Jul 30 11:58:29.702990 2026] [core:error] [pid 642360:tid 642566] [client 191.96.227.82:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://airevoduct.ltd/
[Thu Jul 30 11:58:29.703015 2026] [core:error] [pid 642360:tid 642566] [client 191.96.227.82:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://airevoduct.ltd/
[Thu Jul 30 11:58:29.726777 2026] [security2:error] [pid 642360:tid 642530] [client 20.226.5.174:34766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/atomlib.php"] [unique_id "amuCtZSUkh3e5AhEJOB_WwAAAbc"]
[Thu Jul 30 11:58:30.378871 2026] [core:notice] [pid 642360:tid 642605] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:30.383136 2026] [security2:error] [pid 642360:tid 642605] [client 103.215.74.26:38656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCtpSUkh3e5AhEJOB_ZAAAAgI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:30.806864 2026] [security2:error] [pid 643253:tid 643446] [client 2a03:2880:f800:3d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuCtsjqbtjBYzqM1uYpEwAAPkA"]
[Thu Jul 30 11:58:31.026827 2026] [core:notice] [pid 642360:tid 642527] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:31.280716 2026] [security2:error] [pid 642360:tid 642542] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCtZSUkh3e5AhEJOB_UgABwys"]
[Thu Jul 30 11:58:31.280752 2026] [security2:error] [pid 642360:tid 642542] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCtZSUkh3e5AhEJOB_UgABwys"]
[Thu Jul 30 11:58:31.936853 2026] [security2:error] [pid 642360:tid 642571] [client 176.241.66.87:58846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCt5SUkh3e5AhEJOB_dwAAAeA"]
[Thu Jul 30 11:58:31.937003 2026] [security2:error] [pid 642360:tid 642571] [client 176.241.66.87:58846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCt5SUkh3e5AhEJOB_dwAAAeA"]
[Thu Jul 30 11:58:31.939653 2026] [security2:error] [pid 643253:tid 643400] [client 20.226.5.174:34575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/autoload_classmap.php"] [unique_id "amuCt8jqbtjBYzqM1uYpGgAAABA"]
[Thu Jul 30 11:58:32.032120 2026] [core:notice] [pid 642360:tid 642583] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:32.092717 2026] [security2:error] [pid 642360:tid 642610] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCt5SUkh3e5AhEJOB_cgACB00"]
[Thu Jul 30 11:58:32.092755 2026] [security2:error] [pid 642360:tid 642610] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCt5SUkh3e5AhEJOB_cgACB00"]
[Thu Jul 30 11:58:32.282370 2026] [core:notice] [pid 642360:tid 642569] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:32.659719 2026] [security2:error] [pid 642360:tid 642556] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCuJSUkh3e5AhEJOB_fQAB0VI"]
[Thu Jul 30 11:58:32.659747 2026] [security2:error] [pid 642360:tid 642556] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCuJSUkh3e5AhEJOB_fQAB0VI"]
[Thu Jul 30 11:58:32.829613 2026] [autoindex:error] [pid 642360:tid 642446] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:32.830405 2026] [security2:error] [pid 642360:tid 642612] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCuJSUkh3e5AhEJOB_iwACCVU"]
[Thu Jul 30 11:58:32.923036 2026] [security2:error] [pid 642360:tid 642616] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "kbaagency.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "amuCuJSUkh3e5AhEJOB_jwAAAg0"]
[Thu Jul 30 11:58:33.001495 2026] [autoindex:error] [pid 642360:tid 642467] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:33.002425 2026] [security2:error] [pid 642360:tid 642591] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCuJSUkh3e5AhEJOB_kgAB9Go"]
[Thu Jul 30 11:58:33.171062 2026] [security2:error] [pid 642360:tid 642517] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "spececigarette.com"] [uri "/wp-includes/blocks/index.php"] [unique_id "amuCuZSUkh3e5AhEJOB_lAABqmQ"]
[Thu Jul 30 11:58:33.238077 2026] [security2:error] [pid 642360:tid 642546] [client 20.226.5.174:27787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/bb.php"] [unique_id "amuCuZSUkh3e5AhEJOB_lQAAAcc"]
[Thu Jul 30 11:58:33.347805 2026] [autoindex:error] [pid 642360:tid 642407] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:33.348609 2026] [security2:error] [pid 642360:tid 642611] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCuZSUkh3e5AhEJOB_lgACCC4"]
[Thu Jul 30 11:58:33.517792 2026] [autoindex:error] [pid 642360:tid 642445] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:33.518621 2026] [security2:error] [pid 642360:tid 642548] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCuZSUkh3e5AhEJOB_mQAByVQ"]
[Thu Jul 30 11:58:33.684842 2026] [autoindex:error] [pid 642360:tid 642466] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:33.685686 2026] [security2:error] [pid 642360:tid 642567] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCuZSUkh3e5AhEJOB_ngAB3Gk"]
[Thu Jul 30 11:58:33.854582 2026] [autoindex:error] [pid 642360:tid 642464] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:33.855470 2026] [security2:error] [pid 642360:tid 642588] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCuZSUkh3e5AhEJOB_nwAB8Wc"]
[Thu Jul 30 11:58:34.024906 2026] [autoindex:error] [pid 642360:tid 642456] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:34.025733 2026] [security2:error] [pid 642360:tid 642509] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCupSUkh3e5AhEJOB_owABol8"]
[Thu Jul 30 11:58:34.519443 2026] [security2:error] [pid 642360:tid 642527] [client 20.226.5.174:27820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/bnm.php"] [unique_id "amuCupSUkh3e5AhEJOB_qwAAAbQ"]
[Thu Jul 30 11:58:34.566361 2026] [security2:error] [pid 642360:tid 642490] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCupSUkh3e5AhEJOB_pwABj1c"]
[Thu Jul 30 11:58:34.566398 2026] [security2:error] [pid 642360:tid 642490] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCupSUkh3e5AhEJOB_pwABj1c"]
[Thu Jul 30 11:58:35.114107 2026] [security2:error] [pid 642360:tid 642577] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCupSUkh3e5AhEJOB_rwAB5mM"]
[Thu Jul 30 11:58:35.114139 2026] [security2:error] [pid 642360:tid 642577] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCupSUkh3e5AhEJOB_rwAB5mM"]
[Thu Jul 30 11:58:35.418359 2026] [autoindex:error] [pid 642360:tid 642477] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:35.419198 2026] [security2:error] [pid 642360:tid 642554] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCu5SUkh3e5AhEJOB_uQABz3Q"]
[Thu Jul 30 11:58:35.585836 2026] [cgid:error] [pid 642360:tid 642471] [remote 143.244.57.82:0] AH01265: stderr from /home1/injnyxte/public_html/cgi-bin/: attempt to invoke directory as script
[Thu Jul 30 11:58:35.586655 2026] [security2:error] [pid 642360:tid 642552] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCu5SUkh3e5AhEJOB_vQABzW4"]
[Thu Jul 30 11:58:36.102253 2026] [core:notice] [pid 643253:tid 643397] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:36.106262 2026] [security2:error] [pid 643253:tid 643397] [client 103.215.74.26:24612] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "763"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCvMjqbtjBYzqM1uYpIwAAAA0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:36.136213 2026] [security2:error] [pid 642360:tid 642483] [remote 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCu5SUkh3e5AhEJOB_wAAB_3o"]
[Thu Jul 30 11:58:36.136249 2026] [security2:error] [pid 642360:tid 642483] [remote 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCu5SUkh3e5AhEJOB_wAAB_3o"]
[Thu Jul 30 11:58:36.181701 2026] [security2:error] [pid 643253:tid 643322] [remote 74.7.241.60:46880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/img/article.php"] [unique_id "amuCvMjqbtjBYzqM1uYpJAAAYEM"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/img/main_image_6a2a8e70efd49.jpg
[Thu Jul 30 11:58:36.702447 2026] [core:notice] [pid 642360:tid 642502] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:36.836720 2026] [core:notice] [pid 642360:tid 642508] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:36.844436 2026] [security2:error] [pid 642360:tid 642508] [client 103.215.74.26:24618] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "769"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCvJSUkh3e5AhEJOB_0wAAAaE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:36.893111 2026] [security2:error] [pid 642360:tid 642546] [client 20.226.5.174:27801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/bootstrap.php"] [unique_id "amuCvJSUkh3e5AhEJOB_1AAAAcc"]
[Thu Jul 30 11:58:36.911161 2026] [security2:error] [pid 642360:tid 642491] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCvJSUkh3e5AhEJOB_zgABkBo"]
[Thu Jul 30 11:58:36.911184 2026] [security2:error] [pid 642360:tid 642491] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCvJSUkh3e5AhEJOB_zgABkBo"]
[Thu Jul 30 11:58:37.164771 2026] [security2:error] [pid 642360:tid 642540] [client 173.239.218.8:43615] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/"] [unique_id "amuCvZSUkh3e5AhEJOB_2wAAAcE"]
[Thu Jul 30 11:58:37.454655 2026] [security2:error] [pid 642360:tid 642578] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCvZSUkh3e5AhEJOB_2gAB52s"]
[Thu Jul 30 11:58:37.454686 2026] [security2:error] [pid 642360:tid 642578] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCvZSUkh3e5AhEJOB_2gAB52s"]
[Thu Jul 30 11:58:37.570059 2026] [core:notice] [pid 642360:tid 642510] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:37.575708 2026] [security2:error] [pid 642360:tid 642510] [client 103.215.74.26:24634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCvZSUkh3e5AhEJOB_4gAAAaM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:37.883432 2026] [security2:error] [pid 642360:tid 642610] [client 213.152.187.225:58308] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuCvZSUkh3e5AhEJOB_5wAAAgc"]
[Thu Jul 30 11:58:37.883536 2026] [security2:error] [pid 642360:tid 642610] [client 213.152.187.225:58308] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuCvZSUkh3e5AhEJOB_5wAAAgc"]
[Thu Jul 30 11:58:37.995397 2026] [security2:error] [pid 642360:tid 642576] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCvZSUkh3e5AhEJOB_5AAB5Rs"]
[Thu Jul 30 11:58:37.995431 2026] [security2:error] [pid 642360:tid 642576] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCvZSUkh3e5AhEJOB_5AAB5Rs"]
[Thu Jul 30 11:58:38.223226 2026] [security2:error] [pid 642360:tid 642600] [client 20.226.5.174:27835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/buy.php"] [unique_id "amuCvpSUkh3e5AhEJOB_7QAAAf0"]
[Thu Jul 30 11:58:38.300178 2026] [core:notice] [pid 642360:tid 642599] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:38.304148 2026] [security2:error] [pid 642360:tid 642599] [client 103.215.74.26:24644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCvpSUkh3e5AhEJOB_8AAAAfw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:38.334489 2026] [security2:error] [pid 642360:tid 642612] [client 173.239.218.125:49919] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "amuCvpSUkh3e5AhEJOB_9gAAAgk"]
[Thu Jul 30 11:58:38.543281 2026] [security2:error] [pid 642360:tid 642523] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCvpSUkh3e5AhEJOB_7AABsG0"]
[Thu Jul 30 11:58:38.543328 2026] [security2:error] [pid 642360:tid 642523] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCvpSUkh3e5AhEJOB_7AABsG0"]
[Thu Jul 30 11:58:39.025704 2026] [core:notice] [pid 642360:tid 642533] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:39.029734 2026] [security2:error] [pid 642360:tid 642533] [client 103.215.74.26:24646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCv5SUkh3e5AhEJOB__gAAAbo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:39.049071 2026] [core:notice] [pid 642360:tid 642544] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:39.085037 2026] [security2:error] [pid 642360:tid 642563] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCvpSUkh3e5AhEJOB_-gAB2CI"]
[Thu Jul 30 11:58:39.085067 2026] [security2:error] [pid 642360:tid 642563] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCvpSUkh3e5AhEJOB_-gAB2CI"]
[Thu Jul 30 11:58:39.246111 2026] [security2:error] [pid 642360:tid 642605] [client 173.239.218.90:31395] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/media/system/js/core.js"] [unique_id "amuCv5SUkh3e5AhEJOCABAAAAgI"]
[Thu Jul 30 11:58:39.468565 2026] [core:notice] [pid 643253:tid 643492] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:39.626355 2026] [security2:error] [pid 642360:tid 642507] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCv5SUkh3e5AhEJOCAAwABoHY"]
[Thu Jul 30 11:58:39.626386 2026] [security2:error] [pid 642360:tid 642507] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCv5SUkh3e5AhEJOCAAwABoHY"]
[Thu Jul 30 11:58:39.917533 2026] [security2:error] [pid 642360:tid 642540] [client 20.226.5.174:27781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/chosen.php"] [unique_id "amuCv5SUkh3e5AhEJOCAIwAAAcE"]
[Thu Jul 30 11:58:39.976516 2026] [core:notice] [pid 643253:tid 643453] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:40.178663 2026] [security2:error] [pid 642360:tid 642538] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCv5SUkh3e5AhEJOCAIgABvx8"]
[Thu Jul 30 11:58:40.178697 2026] [security2:error] [pid 642360:tid 642538] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCv5SUkh3e5AhEJOCAIgABvx8"]
[Thu Jul 30 11:58:40.179668 2026] [security2:error] [pid 642360:tid 642527] [client 57.141.0.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuCwJSUkh3e5AhEJOCAJgAAAbQ"]
[Thu Jul 30 11:58:40.488169 2026] [core:notice] [pid 643253:tid 643439] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:40.562745 2026] [security2:error] [pid 642360:tid 642515] [client 173.249.217.7:47840] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuCwJSUkh3e5AhEJOCAKwAAAag"]
[Thu Jul 30 11:58:40.562887 2026] [security2:error] [pid 642360:tid 642515] [client 173.249.217.7:47840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuCwJSUkh3e5AhEJOCAKwAAAag"]
[Thu Jul 30 11:58:40.650155 2026] [security2:error] [pid 642360:tid 642583] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCwJSUkh3e5AhEJOCALAAB7Ew"]
[Thu Jul 30 11:58:40.650183 2026] [security2:error] [pid 642360:tid 642583] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCwJSUkh3e5AhEJOCALAAB7Ew"]
[Thu Jul 30 11:58:41.260374 2026] [security2:error] [pid 642360:tid 642570] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "spececigarette.com"] [uri "/wp-admin/index.php"] [unique_id "amuCwJSUkh3e5AhEJOCAMgAB3zk"]
[Thu Jul 30 11:58:41.402117 2026] [security2:error] [pid 642360:tid 642435] [remote 143.244.57.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/wp-login.php"] [unique_id "amuCwZSUkh3e5AhEJOCAOgACCUo"]
[Thu Jul 30 11:58:41.402318 2026] [security2:error] [pid 642360:tid 642612] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "spececigarette.com"] [uri "/wp-login.php"] [unique_id "amuCwZSUkh3e5AhEJOCAOgACCUo"]
[Thu Jul 30 11:58:41.954734 2026] [security2:error] [pid 642360:tid 642561] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCwZSUkh3e5AhEJOCAPQAB1k8"]
[Thu Jul 30 11:58:41.954759 2026] [security2:error] [pid 642360:tid 642561] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCwZSUkh3e5AhEJOCAPQAB1k8"]
[Thu Jul 30 11:58:41.984276 2026] [security2:error] [pid 643253:tid 643490] [client 57.141.0.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCwcjqbtjBYzqM1uYpOgAAAGo"]
[Thu Jul 30 11:58:42.159966 2026] [security2:error] [pid 642360:tid 642574] [client 20.226.5.174:34564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/class-wp-image.php"] [unique_id "amuCwpSUkh3e5AhEJOCASQAAAeM"]
[Thu Jul 30 11:58:42.295802 2026] [security2:error] [pid 642360:tid 642535] [client 57.141.0.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCwZSUkh3e5AhEJOCAQAAAAbw"]
[Thu Jul 30 11:58:42.302040 2026] [security2:error] [pid 642360:tid 642575] [client 176.241.66.87:44006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCwpSUkh3e5AhEJOCASgAAAeQ"]
[Thu Jul 30 11:58:42.302219 2026] [security2:error] [pid 642360:tid 642575] [client 176.241.66.87:44006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCwpSUkh3e5AhEJOCASgAAAeQ"]
[Thu Jul 30 11:58:42.501799 2026] [security2:error] [pid 642360:tid 642579] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCwpSUkh3e5AhEJOCASAAB6Do"]
[Thu Jul 30 11:58:42.501827 2026] [security2:error] [pid 642360:tid 642579] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCwpSUkh3e5AhEJOCASAAB6Do"]
[Thu Jul 30 11:58:43.066924 2026] [security2:error] [pid 642360:tid 642546] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCwpSUkh3e5AhEJOCAUwABxyY"]
[Thu Jul 30 11:58:43.066952 2026] [security2:error] [pid 642360:tid 642546] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCwpSUkh3e5AhEJOCAUwABxyY"]
[Thu Jul 30 11:58:43.420751 2026] [security2:error] [pid 642360:tid 642496] [client 57.141.0.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCwpSUkh3e5AhEJOCAWAAAAZU"]
[Thu Jul 30 11:58:43.622816 2026] [security2:error] [pid 642360:tid 642536] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCw5SUkh3e5AhEJOCAXgABvV0"]
[Thu Jul 30 11:58:43.622849 2026] [security2:error] [pid 642360:tid 642536] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCw5SUkh3e5AhEJOCAXgABvV0"]
[Thu Jul 30 11:58:44.185416 2026] [security2:error] [pid 642360:tid 642577] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCw5SUkh3e5AhEJOCAaQAB5jA"]
[Thu Jul 30 11:58:44.185446 2026] [security2:error] [pid 642360:tid 642577] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCw5SUkh3e5AhEJOCAaQAB5jA"]
[Thu Jul 30 11:58:44.742518 2026] [security2:error] [pid 642360:tid 642552] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCxJSUkh3e5AhEJOCAcQABzV4"]
[Thu Jul 30 11:58:44.742550 2026] [security2:error] [pid 642360:tid 642552] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCxJSUkh3e5AhEJOCAcQABzV4"]
[Thu Jul 30 11:58:44.780108 2026] [core:notice] [pid 643253:tid 643470] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:44.784579 2026] [security2:error] [pid 643253:tid 643470] [client 103.215.74.26:39190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCxMjqbtjBYzqM1uYpRQAAAFY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:45.310596 2026] [security2:error] [pid 642360:tid 642611] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCxJSUkh3e5AhEJOCAeQACCE4"]
[Thu Jul 30 11:58:45.310634 2026] [security2:error] [pid 642360:tid 642611] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCxJSUkh3e5AhEJOCAeQACCE4"]
[Thu Jul 30 11:58:45.502283 2026] [core:notice] [pid 642360:tid 642506] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:45.509725 2026] [security2:error] [pid 642360:tid 642506] [client 103.215.74.26:39194] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCxZSUkh3e5AhEJOCAhQAAAZ8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:45.864363 2026] [security2:error] [pid 642360:tid 642601] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCxZSUkh3e5AhEJOCAgwAB_lg"]
[Thu Jul 30 11:58:45.864401 2026] [security2:error] [pid 642360:tid 642601] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCxZSUkh3e5AhEJOCAgwAB_lg"]
[Thu Jul 30 11:58:46.260645 2026] [core:notice] [pid 643253:tid 643404] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:46.266033 2026] [security2:error] [pid 643253:tid 643404] [client 103.215.74.26:39196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCxsjqbtjBYzqM1uYpSQAAABQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:46.434444 2026] [security2:error] [pid 642360:tid 642604] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCxpSUkh3e5AhEJOCAkAACAWQ"]
[Thu Jul 30 11:58:46.434474 2026] [security2:error] [pid 642360:tid 642604] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCxpSUkh3e5AhEJOCAkAACAWQ"]
[Thu Jul 30 11:58:46.974098 2026] [security2:error] [pid 642360:tid 642550] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCxpSUkh3e5AhEJOCAmgABy2E"]
[Thu Jul 30 11:58:46.974128 2026] [security2:error] [pid 642360:tid 642550] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCxpSUkh3e5AhEJOCAmgABy2E"]
[Thu Jul 30 11:58:46.980575 2026] [core:notice] [pid 642360:tid 642547] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:46.984719 2026] [security2:error] [pid 642360:tid 642547] [client 103.215.74.26:39212] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCxpSUkh3e5AhEJOCAnwAAAcg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:47.563187 2026] [security2:error] [pid 642360:tid 642565] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCx5SUkh3e5AhEJOCApQAB2l8"]
[Thu Jul 30 11:58:47.563223 2026] [security2:error] [pid 642360:tid 642565] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCx5SUkh3e5AhEJOCApQAB2l8"]
[Thu Jul 30 11:58:47.713527 2026] [core:notice] [pid 643253:tid 643474] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:47.717929 2026] [security2:error] [pid 643253:tid 643474] [client 103.215.74.26:39214] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCx8jqbtjBYzqM1uYpUQAAAFo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:48.107521 2026] [security2:error] [pid 642360:tid 642535] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCx5SUkh3e5AhEJOCAsAABvHE"]
[Thu Jul 30 11:58:48.107547 2026] [security2:error] [pid 642360:tid 642535] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCx5SUkh3e5AhEJOCAsAABvHE"]
[Thu Jul 30 11:58:48.329656 2026] [security2:error] [pid 642360:tid 642519] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCyJSUkh3e5AhEJOCAuAABrHg"]
[Thu Jul 30 11:58:48.455271 2026] [core:notice] [pid 642360:tid 642558] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:48.459575 2026] [security2:error] [pid 642360:tid 642558] [client 103.215.74.26:39224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCyJSUkh3e5AhEJOCAuwAAAdM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:48.879144 2026] [security2:error] [pid 642360:tid 642542] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCyJSUkh3e5AhEJOCAvAABw3Q"]
[Thu Jul 30 11:58:48.879173 2026] [security2:error] [pid 642360:tid 642542] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCyJSUkh3e5AhEJOCAvAABw3Q"]
[Thu Jul 30 11:58:49.191219 2026] [core:notice] [pid 642360:tid 642524] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:49.195953 2026] [security2:error] [pid 642360:tid 642524] [client 103.215.74.26:39230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCyZSUkh3e5AhEJOCAyAAAAbE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:49.435850 2026] [security2:error] [pid 642360:tid 642531] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCyZSUkh3e5AhEJOCAxQABuHM"]
[Thu Jul 30 11:58:49.435880 2026] [security2:error] [pid 642360:tid 642531] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCyZSUkh3e5AhEJOCAxQABuHM"]
[Thu Jul 30 11:58:49.912194 2026] [core:notice] [pid 642360:tid 642584] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:49.916710 2026] [security2:error] [pid 642360:tid 642584] [client 103.215.74.26:39244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCyZSUkh3e5AhEJOCA2AAAAe0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:49.989614 2026] [security2:error] [pid 642360:tid 642526] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCyZSUkh3e5AhEJOCA0AABsxg"]
[Thu Jul 30 11:58:49.989646 2026] [security2:error] [pid 642360:tid 642526] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCyZSUkh3e5AhEJOCA0AABsxg"]
[Thu Jul 30 11:58:50.542816 2026] [security2:error] [pid 642360:tid 642554] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCypSUkh3e5AhEJOCA2QABz38"]
[Thu Jul 30 11:58:50.542845 2026] [security2:error] [pid 642360:tid 642554] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCypSUkh3e5AhEJOCA2QABz38"]
[Thu Jul 30 11:58:50.582709 2026] [security2:error] [pid 642360:tid 642504] [client 20.226.5.174:27784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/classsmtps.php"] [unique_id "amuCypSUkh3e5AhEJOCA5QAAAZ0"]
[Thu Jul 30 11:58:50.640792 2026] [core:notice] [pid 643253:tid 643421] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:50.646020 2026] [security2:error] [pid 643253:tid 643421] [client 103.215.74.26:39260] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCysjqbtjBYzqM1uYpWgAAACU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:51.083962 2026] [security2:error] [pid 642360:tid 642528] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCypSUkh3e5AhEJOCA6QABtWs"]
[Thu Jul 30 11:58:51.084004 2026] [security2:error] [pid 642360:tid 642528] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCypSUkh3e5AhEJOCA6QABtWs"]
[Thu Jul 30 11:58:51.407378 2026] [core:notice] [pid 642360:tid 642533] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:51.411950 2026] [security2:error] [pid 642360:tid 642533] [client 103.215.74.26:39272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCy5SUkh3e5AhEJOCA8wAAAbo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:51.561488 2026] [security2:error] [pid 643253:tid 643339] [remote 57.141.0.36:38000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/86927149125/feed/rss2/"] [unique_id "amuCy8jqbtjBYzqM1uYpXAAASlQ"]
[Thu Jul 30 11:58:51.618711 2026] [security2:error] [pid 642360:tid 642469] [remote 57.141.0.8:54102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuCy5SUkh3e5AhEJOCA9AABuWw"]
[Thu Jul 30 11:58:51.629914 2026] [security2:error] [pid 642360:tid 642580] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCy5SUkh3e5AhEJOCA7AAB6XI"]
[Thu Jul 30 11:58:51.629942 2026] [security2:error] [pid 642360:tid 642580] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCy5SUkh3e5AhEJOCA7AAB6XI"]
[Thu Jul 30 11:58:52.119003 2026] [core:notice] [pid 642360:tid 642379] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:52.145557 2026] [core:notice] [pid 642360:tid 642492] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:52.149582 2026] [security2:error] [pid 642360:tid 642492] [client 103.215.74.26:39286] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCzJSUkh3e5AhEJOCA_QAAAZE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:52.251508 2026] [security2:error] [pid 642360:tid 642521] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCy5SUkh3e5AhEJOCA-AABriU"]
[Thu Jul 30 11:58:52.251537 2026] [security2:error] [pid 642360:tid 642521] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCy5SUkh3e5AhEJOCA-AABriU"]
[Thu Jul 30 11:58:52.389137 2026] [core:notice] [pid 642360:tid 642370] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:52.468578 2026] [autoindex:error] [pid 642360:tid 642395] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:52.469468 2026] [security2:error] [pid 642360:tid 642527] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCzJSUkh3e5AhEJOCBAwABtCI"]
[Thu Jul 30 11:58:52.537997 2026] [security2:error] [pid 643253:tid 643482] [client 20.226.5.174:27819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/classwithtostring.php"] [unique_id "amuCzMjqbtjBYzqM1uYpYQAAAGI"]
[Thu Jul 30 11:58:52.878790 2026] [core:notice] [pid 642360:tid 642547] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:52.882744 2026] [security2:error] [pid 642360:tid 642547] [client 103.215.74.26:39292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "757"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCzJSUkh3e5AhEJOCBDAAAAcg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:52.944382 2026] [security2:error] [pid 642360:tid 642534] [client 176.241.66.87:44708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCzJSUkh3e5AhEJOCBDQAAAbs"]
[Thu Jul 30 11:58:52.944574 2026] [security2:error] [pid 642360:tid 642534] [client 176.241.66.87:44708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCzJSUkh3e5AhEJOCBDQAAAbs"]
[Thu Jul 30 11:58:52.954918 2026] [proxy:error] [pid 642360:tid 642386] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:58:52.955021 2026] [proxy_http:error] [pid 642360:tid 642386] [remote 74.7.228.22:59822] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:58:52.955674 2026] [proxy:error] [pid 642360:tid 642386] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:58:52.955719 2026] [proxy_http:error] [pid 642360:tid 642386] [remote 74.7.228.22:59822] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:58:53.019920 2026] [security2:error] [pid 642360:tid 642550] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCzJSUkh3e5AhEJOCBBwABywQ"]
[Thu Jul 30 11:58:53.019962 2026] [security2:error] [pid 642360:tid 642550] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCzJSUkh3e5AhEJOCBBwABywQ"]
[Thu Jul 30 11:58:53.192601 2026] [autoindex:error] [pid 642360:tid 642424] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-content/cache/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:53.193511 2026] [security2:error] [pid 642360:tid 642609] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCzZSUkh3e5AhEJOCBEQACBj8"]
[Thu Jul 30 11:58:53.317682 2026] [security2:error] [pid 642360:tid 642515] [client 2a03:2880:f800:c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuCzJSUkh3e5AhEJOCBCAABqAI"]
[Thu Jul 30 11:58:53.411539 2026] [autoindex:error] [pid 642360:tid 642400] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:53.412361 2026] [security2:error] [pid 642360:tid 642603] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCzZSUkh3e5AhEJOCBEgACACc"]
[Thu Jul 30 11:58:53.608714 2026] [core:notice] [pid 642360:tid 642565] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:53.613171 2026] [security2:error] [pid 642360:tid 642565] [client 103.215.74.26:52694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCzZSUkh3e5AhEJOCBGgAAAdo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:53.969995 2026] [security2:error] [pid 642360:tid 642602] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCzZSUkh3e5AhEJOCBGQAB_yM"]
[Thu Jul 30 11:58:53.970028 2026] [security2:error] [pid 642360:tid 642602] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCzZSUkh3e5AhEJOCBGQAB_yM"]
[Thu Jul 30 11:58:54.142769 2026] [autoindex:error] [pid 642360:tid 642389] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:54.143511 2026] [security2:error] [pid 642360:tid 642616] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCzpSUkh3e5AhEJOCBIQACDRw"]
[Thu Jul 30 11:58:54.195156 2026] [security2:error] [pid 642360:tid 642614] [client 74.248.33.8:35645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuCzpSUkh3e5AhEJOCBIgAAAgs"]
[Thu Jul 30 11:58:54.312607 2026] [autoindex:error] [pid 642360:tid 642423] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:54.313392 2026] [security2:error] [pid 642360:tid 642617] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCzpSUkh3e5AhEJOCBIwACDj4"]
[Thu Jul 30 11:58:54.334749 2026] [core:notice] [pid 643253:tid 643467] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:54.341304 2026] [security2:error] [pid 643253:tid 643467] [client 103.215.74.26:52710] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCzsjqbtjBYzqM1uYpZAAAAFM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:54.481822 2026] [autoindex:error] [pid 642360:tid 642480] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:54.482670 2026] [security2:error] [pid 642360:tid 642528] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCzpSUkh3e5AhEJOCBJgABtXc"]
[Thu Jul 30 11:58:54.591684 2026] [security2:error] [pid 642360:tid 642390] [remote 37.140.254.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.254.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/archivarix.cms.php"] [unique_id "amuCzpSUkh3e5AhEJOCBKwAByh0"]
[Thu Jul 30 11:58:54.598477 2026] [core:notice] [pid 642360:tid 642505] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:54.600632 2026] [core:notice] [pid 643253:tid 643341] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:54.651671 2026] [autoindex:error] [pid 642360:tid 642429] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:54.652506 2026] [security2:error] [pid 642360:tid 642507] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCzpSUkh3e5AhEJOCBMQABoEQ"]
[Thu Jul 30 11:58:54.820317 2026] [autoindex:error] [pid 642360:tid 642392] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:54.821161 2026] [security2:error] [pid 642360:tid 642564] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCzpSUkh3e5AhEJOCBMgAB2R8"]
[Thu Jul 30 11:58:54.988561 2026] [autoindex:error] [pid 642360:tid 642408] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:54.989455 2026] [security2:error] [pid 642360:tid 642546] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCzpSUkh3e5AhEJOCBNQABxy8"]
[Thu Jul 30 11:58:55.096155 2026] [core:notice] [pid 642360:tid 642545] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:55.102821 2026] [security2:error] [pid 642360:tid 642545] [client 103.215.74.26:52720] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCz5SUkh3e5AhEJOCBOQAAAcY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:55.159047 2026] [autoindex:error] [pid 642360:tid 642437] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:55.159901 2026] [security2:error] [pid 642360:tid 642571] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCz5SUkh3e5AhEJOCBOwAB4Ew"]
[Thu Jul 30 11:58:55.288371 2026] [core:notice] [pid 642360:tid 642510] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:55.289769 2026] [security2:error] [pid 642360:tid 642580] [client 74.248.33.8:26176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/m.php"] [unique_id "amuCz5SUkh3e5AhEJOCBPQAAAek"]
[Thu Jul 30 11:58:55.328591 2026] [autoindex:error] [pid 642360:tid 642371] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:55.329398 2026] [security2:error] [pid 642360:tid 642590] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCz5SUkh3e5AhEJOCBPgAB8wo"]
[Thu Jul 30 11:58:55.593151 2026] [security2:error] [pid 642360:tid 642604] [client 213.152.161.219:49416] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuCz5SUkh3e5AhEJOCBRwAAAgE"]
[Thu Jul 30 11:58:55.593304 2026] [security2:error] [pid 642360:tid 642604] [client 213.152.161.219:49416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuCz5SUkh3e5AhEJOCBRwAAAgE"]
[Thu Jul 30 11:58:55.837039 2026] [core:notice] [pid 642360:tid 642551] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:55.840951 2026] [security2:error] [pid 642360:tid 642551] [client 103.215.74.26:52732] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCz5SUkh3e5AhEJOCBSAAAAcw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:55.876207 2026] [security2:error] [pid 642360:tid 642531] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCz5SUkh3e5AhEJOCBQQABuCo"]
[Thu Jul 30 11:58:55.876231 2026] [security2:error] [pid 642360:tid 642531] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCz5SUkh3e5AhEJOCBQQABuCo"]
[Thu Jul 30 11:58:55.978204 2026] [security2:error] [pid 642360:tid 642556] [client 172.237.109.114:1877] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.env.old"] [unique_id "amuCz5SUkh3e5AhEJOCBTAAAAdE"]
[Thu Jul 30 11:58:55.992678 2026] [security2:error] [pid 643253:tid 643416] [client 172.237.109.114:51913] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.env"] [unique_id "amuCz8jqbtjBYzqM1uYpagAAACA"]
[Thu Jul 30 11:58:56.050513 2026] [security2:error] [pid 642360:tid 642513] [client 185.191.171.3:14730] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2023/01/02/voces-ouviram-lula-falar-em-combater-a-corrupcao-nos-seus-discursos-diz-sergio-moro/"] [unique_id "amuC0JSUkh3e5AhEJOCBUwAAAaY"]
[Thu Jul 30 11:58:56.050663 2026] [security2:error] [pid 642360:tid 642513] [client 185.191.171.3:14730] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2023/01/02/voces-ouviram-lula-falar-em-combater-a-corrupcao-nos-seus-discursos-diz-sergio-moro/"] [unique_id "amuC0JSUkh3e5AhEJOCBUwAAAaY"]
[Thu Jul 30 11:58:56.053006 2026] [autoindex:error] [pid 642360:tid 642378] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:56.053870 2026] [security2:error] [pid 642360:tid 642612] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuC0JSUkh3e5AhEJOCBUgACCRE"]
[Thu Jul 30 11:58:56.094584 2026] [security2:error] [pid 642360:tid 642555] [client 20.226.5.174:27829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/config.php"] [unique_id "amuC0JSUkh3e5AhEJOCBVwAAAdA"]
[Thu Jul 30 11:58:56.229901 2026] [autoindex:error] [pid 642360:tid 642427] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:56.231018 2026] [security2:error] [pid 642360:tid 642495] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuC0JSUkh3e5AhEJOCBWAABlEI"]
[Thu Jul 30 11:58:56.411897 2026] [autoindex:error] [pid 642360:tid 642440] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:56.412858 2026] [security2:error] [pid 642360:tid 642503] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuC0JSUkh3e5AhEJOCBWgABnE8"]
[Thu Jul 30 11:58:56.583161 2026] [core:notice] [pid 643253:tid 643407] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:56.589220 2026] [security2:error] [pid 643253:tid 643407] [client 103.215.74.26:52744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "776"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC0MjqbtjBYzqM1uYpbwAAABc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:56.590611 2026] [autoindex:error] [pid 642360:tid 642431] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:56.591772 2026] [security2:error] [pid 642360:tid 642517] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuC0JSUkh3e5AhEJOCBXQABqkY"]
[Thu Jul 30 11:58:56.633158 2026] [security2:error] [pid 642360:tid 642577] [client 172.237.109.114:19191] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCz5SUkh3e5AhEJOCBSgAAAeY"]
[Thu Jul 30 11:58:56.656850 2026] [security2:error] [pid 642360:tid 642578] [client 172.237.109.114:6743] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCz5SUkh3e5AhEJOCBSQAAAec"]
[Thu Jul 30 11:58:56.657320 2026] [security2:error] [pid 642360:tid 642547] [client 172.237.109.114:14657] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCz5SUkh3e5AhEJOCBSwAAAcg"]
[Thu Jul 30 11:58:56.657551 2026] [security2:error] [pid 643253:tid 643406] [client 172.237.109.114:57124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCz8jqbtjBYzqM1uYpaAAAABY"]
[Thu Jul 30 11:58:56.663758 2026] [security2:error] [pid 642360:tid 642562] [client 172.237.109.114:29294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCz5SUkh3e5AhEJOCBTgAAAdc"]
[Thu Jul 30 11:58:56.686299 2026] [security2:error] [pid 642360:tid 642599] [client 172.237.109.114:1473] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuC0JSUkh3e5AhEJOCBTwAAAfw"]
[Thu Jul 30 11:58:56.690653 2026] [security2:error] [pid 642360:tid 642560] [client 172.237.109.114:45338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCz5SUkh3e5AhEJOCBTQAAAdU"]
[Thu Jul 30 11:58:56.691118 2026] [security2:error] [pid 643253:tid 643471] [client 172.237.109.114:10365] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCz8jqbtjBYzqM1uYpaQAAAFc"]
[Thu Jul 30 11:58:56.719816 2026] [security2:error] [pid 643253:tid 643456] [client 172.237.109.114:30055] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuC0MjqbtjBYzqM1uYpbAAAAEg"]
[Thu Jul 30 11:58:56.728528 2026] [security2:error] [pid 643253:tid 643461] [client 172.237.109.114:54309] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuC0MjqbtjBYzqM1uYpawAAAE0"]
[Thu Jul 30 11:58:56.759665 2026] [autoindex:error] [pid 642360:tid 642406] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/theme-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:56.760441 2026] [security2:error] [pid 642360:tid 642574] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuC0JSUkh3e5AhEJOCBYwAB4y0"]
[Thu Jul 30 11:58:56.928382 2026] [autoindex:error] [pid 642360:tid 642419] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:56.929239 2026] [security2:error] [pid 642360:tid 642605] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuC0JSUkh3e5AhEJOCBZAACAjo"]
[Thu Jul 30 11:58:56.956680 2026] [security2:error] [pid 642360:tid 642584] [client 74.248.33.8:35627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuC0JSUkh3e5AhEJOCBYgAAAe0"]
[Thu Jul 30 11:58:57.168797 2026] [autoindex:error] [pid 642360:tid 642422] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:57.169597 2026] [security2:error] [pid 642360:tid 642616] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuC0ZSUkh3e5AhEJOCBZQACDT0"]
[Thu Jul 30 11:58:57.263718 2026] [security2:error] [pid 642360:tid 642502] [client 20.226.5.174:27807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/core.php"] [unique_id "amuC0ZSUkh3e5AhEJOCBawAAAZs"]
[Thu Jul 30 11:58:57.329201 2026] [core:notice] [pid 642360:tid 642614] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:57.335969 2026] [security2:error] [pid 642360:tid 642614] [client 103.215.74.26:52746] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC0ZSUkh3e5AhEJOCBbQAAAgs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:57.387810 2026] [autoindex:error] [pid 642360:tid 642413] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:57.388677 2026] [security2:error] [pid 642360:tid 642533] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuC0ZSUkh3e5AhEJOCBbAABujQ"]
[Thu Jul 30 11:58:57.555732 2026] [security2:error] [pid 643253:tid 643429] [client 74.248.33.8:50269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/wk/index.php"] [unique_id "amuC0cjqbtjBYzqM1uYpeQAAAC0"]
[Thu Jul 30 11:58:57.792341 2026] [security2:error] [pid 642360:tid 642519] [client 57.141.0.18:53226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuC0ZSUkh3e5AhEJOCBbgABrCA"], referer: https://igetvape-australia.com/product/iget-bar-strawberry-kiwi-ice/?add-to-cart=118
[Thu Jul 30 11:58:58.005630 2026] [security2:error] [pid 642360:tid 642538] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC0ZSUkh3e5AhEJOCBcAABvyY"]
[Thu Jul 30 11:58:58.005665 2026] [security2:error] [pid 642360:tid 642538] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC0ZSUkh3e5AhEJOCBcAABvyY"]
[Thu Jul 30 11:58:58.079486 2026] [security2:error] [pid 642360:tid 642534] [client 104.28.196.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fantasynamelist.com"] [uri "/index.php"] [unique_id "amuC0JSUkh3e5AhEJOCBWQABu0g"]
[Thu Jul 30 11:58:58.083623 2026] [core:notice] [pid 642360:tid 642606] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:58.088500 2026] [security2:error] [pid 642360:tid 642606] [client 103.215.74.26:52752] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "789"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC0pSUkh3e5AhEJOCBdQAAAgM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:58.549164 2026] [security2:error] [pid 642360:tid 642491] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC0pSUkh3e5AhEJOCBeAABkGA"]
[Thu Jul 30 11:58:58.549203 2026] [security2:error] [pid 642360:tid 642491] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC0pSUkh3e5AhEJOCBeAABkGA"]
[Thu Jul 30 11:58:58.819487 2026] [core:notice] [pid 642360:tid 642492] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:58.823462 2026] [security2:error] [pid 642360:tid 642492] [client 103.215.74.26:52764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "761"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC0pSUkh3e5AhEJOCBgwAAAZE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:59.097345 2026] [security2:error] [pid 642360:tid 642607] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC0pSUkh3e5AhEJOCBfQACBGg"]
[Thu Jul 30 11:58:59.097375 2026] [security2:error] [pid 642360:tid 642607] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC0pSUkh3e5AhEJOCBfQACBGg"]
[Thu Jul 30 11:58:59.322554 2026] [security2:error] [pid 642360:tid 642585] [client 74.248.33.8:37701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/mini.php"] [unique_id "amuC05SUkh3e5AhEJOCBjAAAAe4"]
[Thu Jul 30 11:58:59.549531 2026] [core:notice] [pid 642360:tid 642608] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:59.554250 2026] [security2:error] [pid 642360:tid 642608] [client 103.215.74.26:52776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "765"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC05SUkh3e5AhEJOCBkQAAAgU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:59.590122 2026] [security2:error] [pid 642360:tid 642531] [client 85.208.96.201:22196] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/12/29/joao-azevedo-exonera-zezinho-do-botafogo-do-cargo-de-secretario-de-esporte-da-paraiba/"] [unique_id "amuC05SUkh3e5AhEJOCBkgAAAbg"]
[Thu Jul 30 11:58:59.590267 2026] [security2:error] [pid 642360:tid 642531] [client 85.208.96.201:22196] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/12/29/joao-azevedo-exonera-zezinho-do-botafogo-do-cargo-de-secretario-de-esporte-da-paraiba/"] [unique_id "amuC05SUkh3e5AhEJOCBkgAAAbg"]
[Thu Jul 30 11:58:59.651266 2026] [security2:error] [pid 642360:tid 642555] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC05SUkh3e5AhEJOCBiQAB0Fw"]
[Thu Jul 30 11:58:59.651299 2026] [security2:error] [pid 642360:tid 642555] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC05SUkh3e5AhEJOCBiQAB0Fw"]
[Thu Jul 30 11:58:59.887671 2026] [core:error] [pid 642360:tid 642579] [client 74.7.244.55:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:58:59.887693 2026] [core:error] [pid 642360:tid 642579] [client 74.7.244.55:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:58:59.887825 2026] [security2:error] [pid 642360:tid 642579] [client 74.7.244.55:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.hvacairductscleaners.us"] [uri "/___proxy_subdomain_webdisk/website_141a2c45/index.php"] [unique_id "amuC05SUkh3e5AhEJOCBmwAAAeg"]
[Thu Jul 30 11:58:59.888566 2026] [security2:error] [pid 643253:tid 643501] [client 74.7.244.55:46548] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.hvacairductscleaners.us"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuC08jqbtjBYzqM1uYpiAAAdV8"]
[Thu Jul 30 11:59:00.203011 2026] [authz_core:error] [pid 643253:tid 643404] [client 94.154.43.229:45654] AH01630: client denied by server configuration: /home1/jstnyxte/public_html/website_42104935/.env
[Thu Jul 30 11:59:00.224763 2026] [security2:error] [pid 642360:tid 642562] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC05SUkh3e5AhEJOCBlgAB11Y"]
[Thu Jul 30 11:59:00.224789 2026] [security2:error] [pid 642360:tid 642562] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC05SUkh3e5AhEJOCBlgAB11Y"]
[Thu Jul 30 11:59:00.248242 2026] [security2:error] [pid 643253:tid 643486] [client 172.202.44.182:45102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/chosen.php"] [unique_id "amuC1MjqbtjBYzqM1uYpigAAAGY"]
[Thu Jul 30 11:59:00.420811 2026] [security2:error] [pid 642360:tid 642611] [client 20.226.5.174:34590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/css.php"] [unique_id "amuC1JSUkh3e5AhEJOCBowAAAgg"]
[Thu Jul 30 11:59:00.781456 2026] [security2:error] [pid 642360:tid 642568] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC1JSUkh3e5AhEJOCBogAB3VU"]
[Thu Jul 30 11:59:00.781490 2026] [security2:error] [pid 642360:tid 642568] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC1JSUkh3e5AhEJOCBogAB3VU"]
[Thu Jul 30 11:59:01.329120 2026] [security2:error] [pid 642360:tid 642519] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC1JSUkh3e5AhEJOCBqgABrFg"]
[Thu Jul 30 11:59:01.329149 2026] [security2:error] [pid 642360:tid 642519] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC1JSUkh3e5AhEJOCBqgABrFg"]
[Thu Jul 30 11:59:01.336892 2026] [security2:error] [pid 642360:tid 642508] [client 172.202.44.182:45116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/xleet.php"] [unique_id "amuC1ZSUkh3e5AhEJOCBrQAAAaE"]
[Thu Jul 30 11:59:01.496036 2026] [core:notice] [pid 642360:tid 642534] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:01.514569 2026] [security2:error] [pid 642360:tid 642549] [client 66.249.66.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.allmontecristi.com"] [uri "/index.php"] [unique_id "amuC1JSUkh3e5AhEJOCBpAAByh4"]
[Thu Jul 30 11:59:01.545539 2026] [security2:error] [pid 643253:tid 643388] [client 74.248.33.8:15448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/aa.php"] [unique_id "amuC1cjqbtjBYzqM1uYpjgAAAAQ"]
[Thu Jul 30 11:59:01.925775 2026] [security2:error] [pid 642360:tid 642521] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC1ZSUkh3e5AhEJOCBsgABrlo"]
[Thu Jul 30 11:59:01.925803 2026] [security2:error] [pid 642360:tid 642521] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC1ZSUkh3e5AhEJOCBsgABrlo"]
[Thu Jul 30 11:59:02.316607 2026] [security2:error] [pid 643253:tid 643449] [client 74.248.33.8:26951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/w.php"] [unique_id "amuC1sjqbtjBYzqM1uYpkgAAAEE"]
[Thu Jul 30 11:59:02.481318 2026] [security2:error] [pid 642360:tid 642526] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC1pSUkh3e5AhEJOCBvAABs2E"]
[Thu Jul 30 11:59:02.481357 2026] [security2:error] [pid 642360:tid 642526] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC1pSUkh3e5AhEJOCBvAABs2E"]
[Thu Jul 30 11:59:02.611946 2026] [security2:error] [pid 642360:tid 642586] [client 172.202.44.182:45103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/ds.php"] [unique_id "amuC1pSUkh3e5AhEJOCBwwAAAe8"]
[Thu Jul 30 11:59:02.944990 2026] [core:notice] [pid 642360:tid 642608] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:03.008582 2026] [security2:error] [pid 642360:tid 642536] [client 20.226.5.174:27837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/database.php"] [unique_id "amuC15SUkh3e5AhEJOCBzgAAAb0"]
[Thu Jul 30 11:59:03.039701 2026] [security2:error] [pid 642360:tid 642550] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC1pSUkh3e5AhEJOCBxQAByxM"]
[Thu Jul 30 11:59:03.039734 2026] [security2:error] [pid 642360:tid 642550] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC1pSUkh3e5AhEJOCBxQAByxM"]
[Thu Jul 30 11:59:03.214123 2026] [autoindex:error] [pid 642360:tid 642485] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-content/plugins/contact-form-7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:59:03.214934 2026] [security2:error] [pid 642360:tid 642554] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuC15SUkh3e5AhEJOCBzwABz3w"]
[Thu Jul 30 11:59:03.236125 2026] [security2:error] [pid 642360:tid 642547] [client 74.248.33.8:33200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/admin.php"] [unique_id "amuC15SUkh3e5AhEJOCB0AAAAcg"]
[Thu Jul 30 11:59:03.252743 2026] [security2:error] [pid 642360:tid 642592] [client 66.249.66.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuC1pSUkh3e5AhEJOCBxAAB9Xs"]
[Thu Jul 30 11:59:03.573511 2026] [security2:error] [pid 642360:tid 642504] [client 176.241.66.87:45381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuC15SUkh3e5AhEJOCB2AAAAZ0"]
[Thu Jul 30 11:59:03.573644 2026] [security2:error] [pid 642360:tid 642504] [client 176.241.66.87:45381] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuC15SUkh3e5AhEJOCB2AAAAZ0"]
[Thu Jul 30 11:59:03.726337 2026] [security2:error] [pid 643253:tid 643421] [client 172.202.44.182:45068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/f5.php"] [unique_id "amuC18jqbtjBYzqM1uYpmAAAACU"]
[Thu Jul 30 11:59:03.767681 2026] [security2:error] [pid 642360:tid 642529] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC15SUkh3e5AhEJOCB0gABtg0"]
[Thu Jul 30 11:59:03.767733 2026] [security2:error] [pid 642360:tid 642529] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC15SUkh3e5AhEJOCB0gABtg0"]
[Thu Jul 30 11:59:03.897543 2026] [core:notice] [pid 642360:tid 642593] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:03.995473 2026] [autoindex:error] [pid 642360:tid 642460] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:59:03.996406 2026] [security2:error] [pid 642360:tid 642614] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuC15SUkh3e5AhEJOCB2gACC2M"]
[Thu Jul 30 11:59:04.346438 2026] [security2:error] [pid 643253:tid 643403] [client 20.226.5.174:34585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/db.php"] [unique_id "amuC2MjqbtjBYzqM1uYpmwAAABM"]
[Thu Jul 30 11:59:04.515617 2026] [security2:error] [pid 642360:tid 642533] [client 74.248.33.8:15477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/404.php"] [unique_id "amuC2JSUkh3e5AhEJOCB5gAAAbo"]
[Thu Jul 30 11:59:04.542885 2026] [security2:error] [pid 642360:tid 642507] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC2JSUkh3e5AhEJOCB3wABoH4"]
[Thu Jul 30 11:59:04.542913 2026] [security2:error] [pid 642360:tid 642507] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC2JSUkh3e5AhEJOCB3wABoH4"]
[Thu Jul 30 11:59:04.591479 2026] [security2:error] [pid 642360:tid 642610] [client 172.202.44.182:13074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/god4m.php"] [unique_id "amuC2JSUkh3e5AhEJOCB6QAAAgc"]
[Thu Jul 30 11:59:05.091635 2026] [security2:error] [pid 642360:tid 642539] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC2JSUkh3e5AhEJOCB6gABwBU"]
[Thu Jul 30 11:59:05.091685 2026] [security2:error] [pid 642360:tid 642539] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC2JSUkh3e5AhEJOCB6gABwBU"]
[Thu Jul 30 11:59:05.273529 2026] [core:notice] [pid 643253:tid 643485] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:05.277429 2026] [security2:error] [pid 643253:tid 643485] [client 103.215.74.26:46066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "771"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC2cjqbtjBYzqM1uYpoAAAAGU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:05.558023 2026] [core:notice] [pid 642360:tid 642612] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:05.647010 2026] [security2:error] [pid 642360:tid 642552] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC2ZSUkh3e5AhEJOCB9QABzQg"]
[Thu Jul 30 11:59:05.647052 2026] [security2:error] [pid 642360:tid 642552] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC2ZSUkh3e5AhEJOCB9QABzQg"]
[Thu Jul 30 11:59:05.819740 2026] [autoindex:error] [pid 642360:tid 642469] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-content/plugins/woocommerce/assets/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:59:05.820551 2026] [security2:error] [pid 642360:tid 642595] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuC2ZSUkh3e5AhEJOCCAQAB-Gw"]
[Thu Jul 30 11:59:05.852083 2026] [security2:error] [pid 642360:tid 642573] [client 172.202.44.182:45056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/info.php"] [unique_id "amuC2ZSUkh3e5AhEJOCCAgAAAeI"]
[Thu Jul 30 11:59:05.989881 2026] [autoindex:error] [pid 642360:tid 642475] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-content/plugins/woocommerce/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:59:05.990676 2026] [security2:error] [pid 642360:tid 642536] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuC2ZSUkh3e5AhEJOCCBAABvXI"]
[Thu Jul 30 11:59:06.015128 2026] [core:notice] [pid 642360:tid 642560] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:06.019140 2026] [security2:error] [pid 642360:tid 642560] [client 103.215.74.26:46070] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC2pSUkh3e5AhEJOCCBQAAAdU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:06.215849 2026] [security2:error] [pid 642360:tid 642515] [client 177.32.179.54:62578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.179.32.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "asian-connect.com"] [uri "/xmlrpc.php"] [unique_id "amuC2ZSUkh3e5AhEJOCCAwAAAag"]
[Thu Jul 30 11:59:06.216056 2026] [security2:error] [pid 642360:tid 642515] [client 177.32.179.54:62578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "asian-connect.com"] [uri "/xmlrpc.php"] [unique_id "amuC2ZSUkh3e5AhEJOCCAwAAAag"]
[Thu Jul 30 11:59:06.548056 2026] [security2:error] [pid 642360:tid 642587] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC2pSUkh3e5AhEJOCCCQAB8Bc"]
[Thu Jul 30 11:59:06.548084 2026] [security2:error] [pid 642360:tid 642587] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC2pSUkh3e5AhEJOCCCQAB8Bc"]
[Thu Jul 30 11:59:06.688188 2026] [security2:error] [pid 643253:tid 643397] [client 74.248.33.8:24929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/init.php"] [unique_id "amuC2sjqbtjBYzqM1uYpowAAAA0"]
[Thu Jul 30 11:59:06.764913 2026] [core:notice] [pid 643253:tid 643507] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:06.770077 2026] [security2:error] [pid 643253:tid 643507] [client 103.215.74.26:46074] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC2sjqbtjBYzqM1uYppQAAAHs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:06.788843 2026] [security2:error] [pid 642360:tid 642563] [client 20.215.191.139:54661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/json.php"] [unique_id "amuC2pSUkh3e5AhEJOCCEAAAAdg"]
[Thu Jul 30 11:59:06.928050 2026] [security2:error] [pid 643253:tid 643508] [client 199.195.248.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fantasynamelist.com"] [uri "/index.php"] [unique_id "amuC2sjqbtjBYzqM1uYppAAAfGU"]
[Thu Jul 30 11:59:07.096381 2026] [security2:error] [pid 642360:tid 642605] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "spececigarette.com"] [uri "/wp-admin/network/index.php"] [unique_id "amuC2pSUkh3e5AhEJOCCDgACAm0"]
[Thu Jul 30 11:59:07.231702 2026] [security2:error] [pid 642360:tid 642395] [remote 143.244.57.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/wp-login.php"] [unique_id "amuC25SUkh3e5AhEJOCCFwAB3SI"]
[Thu Jul 30 11:59:07.231972 2026] [security2:error] [pid 642360:tid 642568] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "spececigarette.com"] [uri "/wp-login.php"] [unique_id "amuC25SUkh3e5AhEJOCCFwAB3SI"]
[Thu Jul 30 11:59:07.324508 2026] [core:notice] [pid 642360:tid 642502] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:07.399377 2026] [security2:error] [pid 642360:tid 642601] [client 20.215.191.139:54669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/mini.php"] [unique_id "amuC25SUkh3e5AhEJOCCHQAAAf4"]
[Thu Jul 30 11:59:07.494852 2026] [core:notice] [pid 642360:tid 642572] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:07.498926 2026] [security2:error] [pid 642360:tid 642572] [client 103.215.74.26:46076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC25SUkh3e5AhEJOCCHgAAAeE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:07.523255 2026] [proxy:error] [pid 642360:tid 642564] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:59:07.523313 2026] [proxy_http:error] [pid 642360:tid 642564] [client 172.202.44.182:39224] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:59:07.523855 2026] [proxy:error] [pid 642360:tid 642564] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:59:07.523896 2026] [proxy_http:error] [pid 642360:tid 642564] [client 172.202.44.182:39224] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:59:07.763571 2026] [security2:error] [pid 642360:tid 642519] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "spececigarette.com"] [uri "/wp-admin/user/index.php"] [unique_id "amuC25SUkh3e5AhEJOCCHAABrAk"]
[Thu Jul 30 11:59:07.898794 2026] [security2:error] [pid 642360:tid 642365] [remote 143.244.57.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/wp-login.php"] [unique_id "amuC25SUkh3e5AhEJOCCKAABkQQ"]
[Thu Jul 30 11:59:07.898961 2026] [security2:error] [pid 642360:tid 642492] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "spececigarette.com"] [uri "/wp-login.php"] [unique_id "amuC25SUkh3e5AhEJOCCKAABkQQ"]
[Thu Jul 30 11:59:07.977480 2026] [authz_core:error] [pid 642360:tid 642491] [client 94.154.43.186:44060] AH01630: client denied by server configuration: /home1/jstnyxte/public_html/website_42104935/.env
[Thu Jul 30 11:59:08.028301 2026] [security2:error] [pid 642360:tid 642499] [client 20.215.191.139:54381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/chosen.php"] [unique_id "amuC3JSUkh3e5AhEJOCCLAAAAZg"]
[Thu Jul 30 11:59:08.068489 2026] [security2:error] [pid 642360:tid 642521] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "spececigarette.com"] [uri "/wp-content/index.php"] [unique_id "amuC3JSUkh3e5AhEJOCCLgABrj8"]
[Thu Jul 30 11:59:08.236240 2026] [core:notice] [pid 643253:tid 643484] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:08.240695 2026] [security2:error] [pid 643253:tid 643484] [client 103.215.74.26:46082] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC3MjqbtjBYzqM1uYpqwAAAGQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:08.241219 2026] [security2:error] [pid 642360:tid 642540] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "spececigarette.com"] [uri "/wp-content/plugins/index.php"] [unique_id "amuC3JSUkh3e5AhEJOCCLwABwQI"]
[Thu Jul 30 11:59:08.312701 2026] [core:notice] [pid 642360:tid 642591] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:08.413008 2026] [security2:error] [pid 642360:tid 642531] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "spececigarette.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuC3JSUkh3e5AhEJOCCNwABuAA"]
[Thu Jul 30 11:59:08.635697 2026] [autoindex:error] [pid 642360:tid 642396] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:59:08.636462 2026] [security2:error] [pid 642360:tid 642612] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuC3JSUkh3e5AhEJOCCOAACCSM"]
[Thu Jul 30 11:59:08.927201 2026] [security2:error] [pid 642360:tid 642570] [client 172.202.44.182:50523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/.__info.php"] [unique_id "amuC3JSUkh3e5AhEJOCCQAAAAd8"]
[Thu Jul 30 11:59:08.940954 2026] [core:notice] [pid 642360:tid 642561] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:08.977129 2026] [core:notice] [pid 642360:tid 642536] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:08.981497 2026] [security2:error] [pid 642360:tid 642536] [client 103.215.74.26:46086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC3JSUkh3e5AhEJOCCQgAAAb0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:09.167644 2026] [security2:error] [pid 642360:tid 642550] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "spececigarette.com"] [uri "/wp-admin/index.php"] [unique_id "amuC3JSUkh3e5AhEJOCCPAABy0E"]
[Thu Jul 30 11:59:09.303449 2026] [security2:error] [pid 642360:tid 642402] [remote 143.244.57.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/wp-login.php"] [unique_id "amuC3ZSUkh3e5AhEJOCCRwABvCk"]
[Thu Jul 30 11:59:09.303703 2026] [security2:error] [pid 642360:tid 642535] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "spececigarette.com"] [uri "/wp-login.php"] [unique_id "amuC3ZSUkh3e5AhEJOCCRwABvCk"]
[Thu Jul 30 11:59:09.320397 2026] [security2:error] [pid 642360:tid 642523] [client 20.215.191.139:54656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/kj.php"] [unique_id "amuC3ZSUkh3e5AhEJOCCSAAAAbA"]
[Thu Jul 30 11:59:09.471804 2026] [autoindex:error] [pid 642360:tid 642397] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:59:09.472550 2026] [security2:error] [pid 642360:tid 642490] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuC3ZSUkh3e5AhEJOCCTAABjyQ"]
[Thu Jul 30 11:59:09.505478 2026] [security2:error] [pid 642360:tid 642597] [client 20.226.5.174:27788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/default.php"] [unique_id "amuC3ZSUkh3e5AhEJOCCTQAAAfo"]
[Thu Jul 30 11:59:09.701324 2026] [core:notice] [pid 642360:tid 642528] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:09.705734 2026] [security2:error] [pid 642360:tid 642528] [client 103.215.74.26:46088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC3ZSUkh3e5AhEJOCCUQAAAbU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:09.762812 2026] [security2:error] [pid 642360:tid 642547] [client 193.46.199.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuC3ZSUkh3e5AhEJOCCQwAByD4"]
[Thu Jul 30 11:59:10.349313 2026] [security2:error] [pid 642360:tid 642572] [client 20.215.191.139:54362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/wp-files.php"] [unique_id "amuC3pSUkh3e5AhEJOCCWAAAAeE"]
[Thu Jul 30 11:59:10.426751 2026] [core:notice] [pid 643253:tid 643405] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:10.432073 2026] [security2:error] [pid 643253:tid 643405] [client 103.215.74.26:46104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC3sjqbtjBYzqM1uYprgAAABU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:10.620215 2026] [security2:error] [pid 643253:tid 643437] [client 20.226.5.174:34573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/dropdown.php"] [unique_id "amuC3sjqbtjBYzqM1uYpsAAAADU"]
[Thu Jul 30 11:59:10.763485 2026] [security2:error] [pid 642360:tid 642496] [client 172.202.44.182:45075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/0.php"] [unique_id "amuC3pSUkh3e5AhEJOCCXwAAAZU"]
[Thu Jul 30 11:59:10.799314 2026] [core:notice] [pid 642360:tid 642500] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:11.134962 2026] [security2:error] [pid 643253:tid 643419] [client 20.215.191.139:54358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/wp-setup.php"] [unique_id "amuC38jqbtjBYzqM1uYpsgAAACM"]
[Thu Jul 30 11:59:11.185086 2026] [core:notice] [pid 642360:tid 642513] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:11.189504 2026] [security2:error] [pid 642360:tid 642513] [client 103.215.74.26:46108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC35SUkh3e5AhEJOCCZAAAAaY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:11.776313 2026] [security2:error] [pid 642360:tid 642514] [client 20.215.191.139:43354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.tmb/LA.php"] [unique_id "amuC35SUkh3e5AhEJOCCbQAAAac"]
[Thu Jul 30 11:59:11.846176 2026] [security2:error] [pid 642360:tid 642531] [client 20.226.5.174:27822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/edit.php"] [unique_id "amuC35SUkh3e5AhEJOCCbgAAAbg"]
[Thu Jul 30 11:59:11.913157 2026] [core:notice] [pid 643253:tid 643483] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:11.917607 2026] [security2:error] [pid 643253:tid 643483] [client 103.215.74.26:46116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC38jqbtjBYzqM1uYptQAAAGM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:12.634575 2026] [core:notice] [pid 643253:tid 643472] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:12.639514 2026] [core:notice] [pid 642360:tid 642599] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:12.644672 2026] [security2:error] [pid 642360:tid 642599] [client 103.215.74.26:46132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC4JSUkh3e5AhEJOCCeAAAAfw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:13.290664 2026] [security2:error] [pid 642360:tid 642574] [client 20.215.191.139:17594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.tmb/admin.php"] [unique_id "amuC4ZSUkh3e5AhEJOCCfwAAAeM"]
[Thu Jul 30 11:59:13.368970 2026] [core:notice] [pid 642360:tid 642516] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:13.373197 2026] [security2:error] [pid 642360:tid 642516] [client 103.215.74.26:20950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC4ZSUkh3e5AhEJOCCggAAAak"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:13.619985 2026] [security2:error] [pid 642360:tid 642544] [client 172.202.44.182:45096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/07.php"] [unique_id "amuC4ZSUkh3e5AhEJOCChQAAAcU"]
[Thu Jul 30 11:59:14.113960 2026] [core:notice] [pid 642360:tid 642507] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:14.118404 2026] [security2:error] [pid 642360:tid 642507] [client 103.215.74.26:20952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC4pSUkh3e5AhEJOCCigAAAaA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:14.295930 2026] [security2:error] [pid 642360:tid 642492] [client 176.241.66.87:46071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuC4pSUkh3e5AhEJOCCjgAAAZE"]
[Thu Jul 30 11:59:14.296078 2026] [security2:error] [pid 642360:tid 642492] [client 176.241.66.87:46071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuC4pSUkh3e5AhEJOCCjgAAAZE"]
[Thu Jul 30 11:59:14.345488 2026] [core:notice] [pid 642360:tid 642557] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:14.859624 2026] [core:notice] [pid 642360:tid 642607] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:14.863660 2026] [security2:error] [pid 642360:tid 642607] [client 103.215.74.26:20954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC4pSUkh3e5AhEJOCClwAAAgQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:15.011028 2026] [core:notice] [pid 643253:tid 643474] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:15.241282 2026] [security2:error] [pid 642360:tid 642511] [client 20.215.191.139:36148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.tmb/class_api.php"] [unique_id "amuC45SUkh3e5AhEJOCCoQAAAaQ"]
[Thu Jul 30 11:59:15.258471 2026] [security2:error] [pid 642360:tid 642537] [client 172.202.44.182:45070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/dropdown.php"] [unique_id "amuC45SUkh3e5AhEJOCCogAAAb4"]
[Thu Jul 30 11:59:15.619036 2026] [core:notice] [pid 642360:tid 642536] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:15.623295 2026] [security2:error] [pid 642360:tid 642536] [client 103.215.74.26:20964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "762"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC45SUkh3e5AhEJOCCpgAAAb0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:15.803366 2026] [security2:error] [pid 643253:tid 643441] [client 54.235.232.111:46546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuC4cjqbtjBYzqM1uYpxAAAADk"]
[Thu Jul 30 11:59:15.978993 2026] [core:notice] [pid 642360:tid 642575] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:16.194068 2026] [security2:error] [pid 642360:tid 642592] [client 20.226.5.174:34752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/f35.php"] [unique_id "amuC5JSUkh3e5AhEJOCCsQAAAfU"]
[Thu Jul 30 11:59:16.344281 2026] [core:notice] [pid 643253:tid 643435] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:16.346638 2026] [core:notice] [pid 642360:tid 642509] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:16.348250 2026] [security2:error] [pid 643253:tid 643435] [client 103.215.74.26:20968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC5MjqbtjBYzqM1uYpzgAAADM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:16.406546 2026] [security2:error] [pid 642360:tid 642616] [client 172.202.44.182:45095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/makeasmtp.php"] [unique_id "amuC5JSUkh3e5AhEJOCCuAAAAg0"]
[Thu Jul 30 11:59:16.484742 2026] [security2:error] [pid 642360:tid 642490] [client 20.215.191.139:36142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.tmb/cpabpkyk.php"] [unique_id "amuC5JSUkh3e5AhEJOCCuQAAAY8"]
[Thu Jul 30 11:59:16.785422 2026] [security2:error] [pid 642360:tid 642532] [client 20.215.191.139:54660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/defaults.php"] [unique_id "amuC5JSUkh3e5AhEJOCCvQAAAbk"]
[Thu Jul 30 11:59:17.069931 2026] [core:notice] [pid 642360:tid 642520] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:17.077185 2026] [security2:error] [pid 642360:tid 642520] [client 103.215.74.26:20980] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC5ZSUkh3e5AhEJOCCxAAAAa0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:17.392970 2026] [security2:error] [pid 643253:tid 643452] [client 74.7.241.181:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.saptora.com"] [uri "/index.php"] [unique_id "amuC4sjqbtjBYzqM1uYpxwAAAEQ"]
[Thu Jul 30 11:59:17.393703 2026] [security2:error] [pid 643253:tid 643418] [client 74.7.241.181:60406] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.saptora.com"] [uri "/robots.txt"] [unique_id "amuC4sjqbtjBYzqM1uYpxgAAInA"]
[Thu Jul 30 11:59:17.618773 2026] [core:notice] [pid 642360:tid 642613] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:17.682823 2026] [security2:error] [pid 642360:tid 642521] [client 20.215.191.139:55112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.tmb/wp-login.php"] [unique_id "amuC5ZSUkh3e5AhEJOCCyQAAAa4"]
[Thu Jul 30 11:59:17.692955 2026] [security2:error] [pid 642360:tid 642604] [client 74.7.228.24:49168] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "webdisk.ols.fyv.temporary.site"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuC5ZSUkh3e5AhEJOCCzgAAAgE"]
[Thu Jul 30 11:59:17.709245 2026] [core:notice] [pid 642360:tid 642495] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:17.851256 2026] [core:notice] [pid 642360:tid 642609] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:17.862131 2026] [security2:error] [pid 642360:tid 642609] [client 103.215.74.26:20984] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC5ZSUkh3e5AhEJOCC0wAAAgY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:18.374190 2026] [security2:error] [pid 642360:tid 642537] [client 20.215.191.139:36137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known//.well-known/owlmailer.php"] [unique_id "amuC5pSUkh3e5AhEJOCC2gAAAb4"]
[Thu Jul 30 11:59:18.571421 2026] [core:notice] [pid 642360:tid 642562] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:18.577872 2026] [security2:error] [pid 642360:tid 642562] [client 103.215.74.26:20988] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC5pSUkh3e5AhEJOCC3wAAAdc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:18.589291 2026] [security2:error] [pid 642360:tid 642576] [client 20.226.5.174:34764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/f7.php"] [unique_id "amuC5pSUkh3e5AhEJOCC4AAAAeU"]
[Thu Jul 30 11:59:18.750034 2026] [security2:error] [pid 642360:tid 642514] [client 20.215.191.139:54664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/gtc.php"] [unique_id "amuC5pSUkh3e5AhEJOCC4gAAAac"]
[Thu Jul 30 11:59:18.857086 2026] [security2:error] [pid 642360:tid 642575] [client 49.13.134.145:59324] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuC5pSUkh3e5AhEJOCC5gAAAeQ"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 11:59:19.086311 2026] [security2:error] [pid 642360:tid 642592] [client 20.215.191.139:36294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/991176.php"] [unique_id "amuC55SUkh3e5AhEJOCC6gAAAfU"]
[Thu Jul 30 11:59:19.238135 2026] [core:notice] [pid 642360:tid 642601] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:19.245125 2026] [security2:error] [pid 642360:tid 642601] [client 49.13.134.145:59326] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC55SUkh3e5AhEJOCC6wAAAf4"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 11:59:19.305991 2026] [core:notice] [pid 642360:tid 642502] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:19.309833 2026] [security2:error] [pid 642360:tid 642502] [client 103.215.74.26:20992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC55SUkh3e5AhEJOCC8QAAAZs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:19.858071 2026] [security2:error] [pid 642360:tid 642534] [client 49.13.134.145:59342] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuC55SUkh3e5AhEJOCC-AAAAbs"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 11:59:19.893813 2026] [security2:error] [pid 642360:tid 642588] [client 20.215.191.139:54346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/import.php"] [unique_id "amuC55SUkh3e5AhEJOCC-gAAAfE"]
[Thu Jul 30 11:59:19.926117 2026] [security2:error] [pid 642360:tid 642564] [client 172.202.44.182:39190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/wp-sigunq.php"] [unique_id "amuC55SUkh3e5AhEJOCC-wAAAdk"]
[Thu Jul 30 11:59:20.038461 2026] [core:notice] [pid 642360:tid 642557] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:20.042467 2026] [security2:error] [pid 642360:tid 642557] [client 103.215.74.26:20998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "778"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC6JSUkh3e5AhEJOCC_AAAAdI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:20.276056 2026] [core:error] [pid 643253:tid 643451] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:59:20.276077 2026] [core:error] [pid 643253:tid 643451] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:59:20.285898 2026] [core:error] [pid 642360:tid 642607] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:59:20.285915 2026] [core:error] [pid 642360:tid 642607] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:59:20.652797 2026] [security2:error] [pid 642360:tid 642604] [client 20.215.191.139:54692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/lufix.php"] [unique_id "amuC6JSUkh3e5AhEJOCDDQAAAgE"]
[Thu Jul 30 11:59:20.783004 2026] [core:notice] [pid 642360:tid 642608] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:20.790127 2026] [security2:error] [pid 642360:tid 642608] [client 103.215.74.26:21012] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC6JSUkh3e5AhEJOCDEAAAAgU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:20.990230 2026] [security2:error] [pid 642360:tid 642500] [client 20.215.191.139:36151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/adminfuns.php"] [unique_id "amuC6JSUkh3e5AhEJOCDEwAAAZk"]
[Thu Jul 30 11:59:21.472277 2026] [security2:error] [pid 642360:tid 642563] [client 20.215.191.139:54670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/Geforce.php"] [unique_id "amuC6ZSUkh3e5AhEJOCDHQAAAdg"]
[Thu Jul 30 11:59:21.526264 2026] [core:notice] [pid 642360:tid 642581] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:21.530496 2026] [security2:error] [pid 642360:tid 642581] [client 103.215.74.26:21026] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "791"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC6ZSUkh3e5AhEJOCDIAAAAeo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:21.934134 2026] [security2:error] [pid 643253:tid 643406] [client 20.215.191.139:43339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "amuC6cjqbtjBYzqM1uYp5QAAABY"]
[Thu Jul 30 11:59:22.270431 2026] [core:notice] [pid 642360:tid 642527] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:22.274456 2026] [security2:error] [pid 642360:tid 642527] [client 103.215.74.26:21028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC6pSUkh3e5AhEJOCDKgAAAbQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:22.493638 2026] [security2:error] [pid 643253:tid 643416] [client 172.202.44.182:39185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/wso112233.php"] [unique_id "amuC6sjqbtjBYzqM1uYp-QAAACA"]
[Thu Jul 30 11:59:22.794882 2026] [security2:error] [pid 643253:tid 643419] [client 20.215.191.139:54367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/a4.php"] [unique_id "amuC6sjqbtjBYzqM1uYp-wAAACM"]
[Thu Jul 30 11:59:23.003375 2026] [core:notice] [pid 643253:tid 643412] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:23.007538 2026] [security2:error] [pid 643253:tid 643412] [client 103.215.74.26:21034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "757"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC68jqbtjBYzqM1uYp_AAAABw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:23.289605 2026] [security2:error] [pid 643253:tid 643262] [remote 74.7.241.59:34448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuC68jqbtjBYzqM1uYp_gAAQgc"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/theme-builder/documents
[Thu Jul 30 11:59:23.485532 2026] [security2:error] [pid 643253:tid 643488] [client 20.215.191.139:36110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/classsmtps.php"] [unique_id "amuC68jqbtjBYzqM1uYp_wAAAGg"]
[Thu Jul 30 11:59:23.725764 2026] [core:notice] [pid 643253:tid 643455] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:23.729726 2026] [security2:error] [pid 643253:tid 643455] [client 103.215.74.26:8956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "763"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC68jqbtjBYzqM1uYqAAAAAEc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:24.187610 2026] [security2:error] [pid 642360:tid 642586] [client 20.215.191.139:35021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "amuC7JSUkh3e5AhEJOCDQAAAAe8"]
[Thu Jul 30 11:59:24.321575 2026] [security2:error] [pid 642360:tid 642615] [client 74.7.244.17:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.saiqon.net"] [uri "/index.php"] [unique_id "amuC6pSUkh3e5AhEJOCDMAAAAgw"]
[Thu Jul 30 11:59:24.322476 2026] [security2:error] [pid 642360:tid 642557] [client 74.7.244.17:51080] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.saiqon.net"] [uri "/robots.txt"] [unique_id "amuC6pSUkh3e5AhEJOCDLgAB0h4"]
[Thu Jul 30 11:59:24.451318 2026] [core:notice] [pid 643253:tid 643391] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:24.455743 2026] [security2:error] [pid 643253:tid 643391] [client 103.215.74.26:8968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC7MjqbtjBYzqM1uYqBwAAAAc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:24.860063 2026] [security2:error] [pid 643253:tid 643464] [client 20.215.191.139:17553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/doc.php"] [unique_id "amuC7MjqbtjBYzqM1uYqCAAAAFA"]
[Thu Jul 30 11:59:24.880031 2026] [security2:error] [pid 642360:tid 642548] [client 176.241.66.87:46749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuC7JSUkh3e5AhEJOCDSgAAAck"]
[Thu Jul 30 11:59:24.880196 2026] [security2:error] [pid 642360:tid 642548] [client 176.241.66.87:46749] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuC7JSUkh3e5AhEJOCDSgAAAck"]
[Thu Jul 30 11:59:25.187730 2026] [core:notice] [pid 642360:tid 642597] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:25.191596 2026] [security2:error] [pid 642360:tid 642597] [client 103.215.74.26:8978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "752"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC7ZSUkh3e5AhEJOCDUAAAAfo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:25.401443 2026] [security2:error] [pid 643253:tid 643486] [client 74.7.241.165:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "saiqon.net"] [uri "/index.php"] [unique_id "amuC7cjqbtjBYzqM1uYqCQAAZgk"]
[Thu Jul 30 11:59:25.841040 2026] [security2:error] [pid 643253:tid 643408] [client 20.215.191.139:55114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/fond.php"] [unique_id "amuC7cjqbtjBYzqM1uYqDAAAABg"]
[Thu Jul 30 11:59:25.933122 2026] [core:notice] [pid 642360:tid 642601] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:25.936888 2026] [security2:error] [pid 642360:tid 642601] [client 103.215.74.26:8988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "752"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC7ZSUkh3e5AhEJOCDWgAAAf4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:26.461925 2026] [security2:error] [pid 643253:tid 643267] [remote 74.7.241.59:34448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuC7sjqbtjBYzqM1uYqDwAAOQw"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/theme-builder/documents
[Thu Jul 30 11:59:26.548075 2026] [security2:error] [pid 642360:tid 642591] [client 20.215.191.139:54344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/accueil.php"] [unique_id "amuC7pSUkh3e5AhEJOCDYAAAAfQ"]
[Thu Jul 30 11:59:26.663927 2026] [core:notice] [pid 642360:tid 642533] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:26.668328 2026] [security2:error] [pid 642360:tid 642533] [client 103.215.74.26:8996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC7pSUkh3e5AhEJOCDZAAAAbo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:26.727054 2026] [security2:error] [pid 643253:tid 643472] [client 172.202.44.182:50527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/alfanew.php"] [unique_id "amuC7sjqbtjBYzqM1uYqEAAAAFg"]
[Thu Jul 30 11:59:27.394899 2026] [core:notice] [pid 643253:tid 643452] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:27.399295 2026] [security2:error] [pid 643253:tid 643452] [client 103.215.74.26:9000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC78jqbtjBYzqM1uYqFAAAAEQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:27.899064 2026] [security2:error] [pid 643253:tid 643481] [client 20.215.191.139:17564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "amuC78jqbtjBYzqM1uYqFgAAAGE"]
[Thu Jul 30 11:59:28.128370 2026] [core:notice] [pid 642360:tid 642552] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:28.132831 2026] [security2:error] [pid 642360:tid 642552] [client 103.215.74.26:9012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC8JSUkh3e5AhEJOCDdAAAAc0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:28.435687 2026] [security2:error] [pid 643253:tid 643503] [client 172.202.44.182:50534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/fw.php"] [unique_id "amuC8MjqbtjBYzqM1uYqGgAAAHc"]
[Thu Jul 30 11:59:28.552958 2026] [core:notice] [pid 642360:tid 642607] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:28.941441 2026] [core:notice] [pid 642360:tid 642599] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:28.945798 2026] [security2:error] [pid 642360:tid 642599] [client 103.215.74.26:9020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC8JSUkh3e5AhEJOCDggAAAfw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:29.705143 2026] [core:notice] [pid 642360:tid 642601] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:29.709525 2026] [security2:error] [pid 642360:tid 642601] [client 103.215.74.26:9026] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC8ZSUkh3e5AhEJOCDkgAAAf4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:29.822933 2026] [security2:error] [pid 642360:tid 642615] [client 20.215.191.139:54357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/dashboard.php"] [unique_id "amuC8ZSUkh3e5AhEJOCDkwAAAgw"]
[Thu Jul 30 11:59:30.442919 2026] [core:notice] [pid 642360:tid 642594] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:30.447342 2026] [security2:error] [pid 642360:tid 642594] [client 103.215.74.26:9034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC8pSUkh3e5AhEJOCDpAAAAfc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:30.633295 2026] [security2:error] [pid 642360:tid 642540] [client 20.215.191.139:54365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/radio.php"] [unique_id "amuC8pSUkh3e5AhEJOCDpQAAAcE"]
[Thu Jul 30 11:59:31.174628 2026] [core:notice] [pid 642360:tid 642612] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:31.179057 2026] [security2:error] [pid 642360:tid 642612] [client 103.215.74.26:9048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC85SUkh3e5AhEJOCDrgAAAgk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:31.259761 2026] [security2:error] [pid 642360:tid 642544] [client 172.202.44.182:45097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/wp-login.php"] [unique_id "amuC8pSUkh3e5AhEJOCDrAAAAcU"]
[Thu Jul 30 11:59:31.418440 2026] [security2:error] [pid 642360:tid 642504] [client 139.28.219.70:47854] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rocket-bookkeepers.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuC85SUkh3e5AhEJOCDsgAAAZ0"]
[Thu Jul 30 11:59:31.655476 2026] [core:error] [pid 642360:tid 642518] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:59:31.655499 2026] [core:error] [pid 642360:tid 642518] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:59:31.912704 2026] [core:notice] [pid 642360:tid 642610] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:31.917079 2026] [security2:error] [pid 642360:tid 642610] [client 103.215.74.26:9064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC85SUkh3e5AhEJOCDuwAAAgc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:31.968377 2026] [security2:error] [pid 642360:tid 642500] [client 20.215.191.139:54386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/wpsml-sys.php"] [unique_id "amuC85SUkh3e5AhEJOCDvAAAAZk"]
[Thu Jul 30 11:59:32.089949 2026] [security2:error] [pid 642360:tid 642563] [client 139.28.219.70:47858] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rocket-bookkeepers.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuC9JSUkh3e5AhEJOCDwgAAAdg"]
[Thu Jul 30 11:59:32.356803 2026] [security2:error] [pid 642360:tid 642508] [client 139.28.219.70:47860] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rocket-bookkeepers.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuC9JSUkh3e5AhEJOCDwwAAAaE"]
[Thu Jul 30 11:59:32.630622 2026] [security2:error] [pid 642360:tid 642572] [client 139.28.219.70:47874] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rocket-bookkeepers.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuC9JSUkh3e5AhEJOCDyQAAAeE"]
[Thu Jul 30 11:59:32.650342 2026] [core:notice] [pid 643253:tid 643471] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:32.655046 2026] [security2:error] [pid 643253:tid 643471] [client 103.215.74.26:9068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC9MjqbtjBYzqM1uYqJQAAAFc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:32.897701 2026] [security2:error] [pid 642360:tid 642510] [client 139.28.219.70:47888] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rocket-bookkeepers.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuC9JSUkh3e5AhEJOCDygAAAaM"]
[Thu Jul 30 11:59:33.168670 2026] [security2:error] [pid 642360:tid 642603] [client 139.28.219.70:47896] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rocket-bookkeepers.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuC9ZSUkh3e5AhEJOCD0QAAAgA"]
[Thu Jul 30 11:59:33.380284 2026] [core:notice] [pid 642360:tid 642569] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:33.384206 2026] [security2:error] [pid 642360:tid 642569] [client 103.215.74.26:62836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "752"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC9ZSUkh3e5AhEJOCD0wAAAd4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:33.392434 2026] [core:notice] [pid 642360:tid 642574] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:33.439217 2026] [security2:error] [pid 642360:tid 642530] [client 139.28.219.70:47910] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rocket-bookkeepers.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuC9ZSUkh3e5AhEJOCD1QAAAbc"]
[Thu Jul 30 11:59:33.799102 2026] [security2:error] [pid 642360:tid 642570] [client 139.28.219.70:47924] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rocket-bookkeepers.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuC9ZSUkh3e5AhEJOCD3AAAAd8"]
[Thu Jul 30 11:59:34.113764 2026] [core:notice] [pid 642360:tid 642552] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:34.117640 2026] [security2:error] [pid 642360:tid 642552] [client 103.215.74.26:62846] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC9pSUkh3e5AhEJOCD4QAAAc0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:34.147503 2026] [security2:error] [pid 642360:tid 642511] [client 139.28.219.70:47940] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rocket-bookkeepers.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuC9pSUkh3e5AhEJOCD4wAAAaQ"]
[Thu Jul 30 11:59:34.433756 2026] [security2:error] [pid 642360:tid 642548] [client 139.28.219.70:47952] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rocket-bookkeepers.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuC9pSUkh3e5AhEJOCD5gAAAck"]
[Thu Jul 30 11:59:34.746651 2026] [security2:error] [pid 642360:tid 642597] [client 139.28.219.70:47966] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rocket-bookkeepers.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuC9pSUkh3e5AhEJOCD7QAAAfo"]
[Thu Jul 30 11:59:34.866844 2026] [core:notice] [pid 643253:tid 643392] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:34.871549 2026] [security2:error] [pid 643253:tid 643392] [client 103.215.74.26:62866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC9sjqbtjBYzqM1uYqKwAAAAg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:35.049912 2026] [security2:error] [pid 642360:tid 642568] [client 139.28.219.70:47976] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rocket-bookkeepers.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuC95SUkh3e5AhEJOCD8AAAAd0"]
[Thu Jul 30 11:59:35.323148 2026] [security2:error] [pid 643253:tid 643420] [client 139.28.219.70:47978] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rocket-bookkeepers.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuC98jqbtjBYzqM1uYqMAAAACQ"]
[Thu Jul 30 11:59:35.593987 2026] [security2:error] [pid 643253:tid 643433] [client 139.28.219.70:47988] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rocket-bookkeepers.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuC98jqbtjBYzqM1uYqMgAAADE"]
[Thu Jul 30 11:59:35.602202 2026] [core:notice] [pid 642360:tid 642508] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:35.606624 2026] [security2:error] [pid 642360:tid 642508] [client 103.215.74.26:62880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC95SUkh3e5AhEJOCD-AAAAaE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:35.622140 2026] [security2:error] [pid 643253:tid 643490] [client 176.241.66.87:62174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuC98jqbtjBYzqM1uYqMwAAAGo"]
[Thu Jul 30 11:59:35.622336 2026] [security2:error] [pid 643253:tid 643490] [client 176.241.66.87:62174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuC98jqbtjBYzqM1uYqMwAAAGo"]
[Thu Jul 30 11:59:35.873343 2026] [security2:error] [pid 642360:tid 642492] [client 139.28.219.70:48000] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rocket-bookkeepers.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuC95SUkh3e5AhEJOCEBQAAAZE"]
[Thu Jul 30 11:59:36.064590 2026] [security2:error] [pid 642360:tid 642414] [remote 74.7.241.59:54104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuC-JSUkh3e5AhEJOCEBgABozU"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/theme-builder/documents
[Thu Jul 30 11:59:36.183494 2026] [core:error] [pid 642360:tid 642598] [client 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:59:36.183521 2026] [core:error] [pid 642360:tid 642598] [client 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:59:36.208661 2026] [security2:error] [pid 643253:tid 643477] [client 20.215.191.139:54373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/02.php"] [unique_id "amuC-MjqbtjBYzqM1uYqNAAAAF0"]
[Thu Jul 30 11:59:36.235181 2026] [security2:error] [pid 642360:tid 642520] [client 139.28.219.70:48010] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rocket-bookkeepers.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuC-JSUkh3e5AhEJOCEEQAAAa0"]
[Thu Jul 30 11:59:36.352257 2026] [core:notice] [pid 642360:tid 642589] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:36.358773 2026] [security2:error] [pid 642360:tid 642589] [client 103.215.74.26:62882] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC-JSUkh3e5AhEJOCEEgAAAfI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:36.553680 2026] [security2:error] [pid 642360:tid 642501] [client 20.215.191.139:43345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/license.php"] [unique_id "amuC-JSUkh3e5AhEJOCEFAAAAZo"]
[Thu Jul 30 11:59:36.735878 2026] [core:notice] [pid 642360:tid 642578] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:36.960029 2026] [security2:error] [pid 642360:tid 642591] [client 172.202.44.182:45064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/simple.php"] [unique_id "amuC-JSUkh3e5AhEJOCEHgAAAfQ"]
[Thu Jul 30 11:59:36.999910 2026] [security2:error] [pid 642360:tid 642608] [client 20.215.191.139:54394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/infos.php"] [unique_id "amuC-JSUkh3e5AhEJOCEIgAAAgU"]
[Thu Jul 30 11:59:37.107561 2026] [core:notice] [pid 642360:tid 642561] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:37.114326 2026] [security2:error] [pid 642360:tid 642561] [client 103.215.74.26:62898] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC-ZSUkh3e5AhEJOCEIwAAAdY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:37.490741 2026] [security2:error] [pid 643253:tid 643415] [client 20.215.191.139:54347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/updates.php"] [unique_id "amuC-cjqbtjBYzqM1uYqNgAAAB8"]
[Thu Jul 30 11:59:37.599477 2026] [security2:error] [pid 642360:tid 642560] [client 20.215.191.139:17595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/mariju.php"] [unique_id "amuC-ZSUkh3e5AhEJOCEKgAAAdU"]
[Thu Jul 30 11:59:37.848255 2026] [core:notice] [pid 642360:tid 642505] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:37.852196 2026] [security2:error] [pid 642360:tid 642505] [client 103.215.74.26:62904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "752"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC-ZSUkh3e5AhEJOCELgAAAZ4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:38.213880 2026] [security2:error] [pid 642360:tid 642573] [client 43.153.73.200:42742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.73.153.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/tumed/issue/current"] [unique_id "amuC-pSUkh3e5AhEJOCEMgAAAeI"], referer: https://ejournalugj.com/index_php/tumed/issue/current
[Thu Jul 30 11:59:38.280393 2026] [security2:error] [pid 642360:tid 642605] [client 172.202.44.182:45114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/classsmtps.php"] [unique_id "amuC-pSUkh3e5AhEJOCENgAAAgI"]
[Thu Jul 30 11:59:38.594391 2026] [core:notice] [pid 642360:tid 642498] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:38.598487 2026] [security2:error] [pid 642360:tid 642498] [client 103.215.74.26:62912] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "770"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC-pSUkh3e5AhEJOCEOQAAAZc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:38.736157 2026] [security2:error] [pid 642360:tid 642529] [client 20.215.191.139:54363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/user.php"] [unique_id "amuC-pSUkh3e5AhEJOCEOwAAAbY"]
[Thu Jul 30 11:59:38.820018 2026] [core:notice] [pid 643253:tid 643385] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:38.889235 2026] [security2:error] [pid 642360:tid 642440] [remote 74.7.241.60:57288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/content/article.php"] [unique_id "amuC-pSUkh3e5AhEJOCEQQAB-U8"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/content/1784123347_ed%20inclusive.jpg
[Thu Jul 30 11:59:39.238653 2026] [security2:error] [pid 642360:tid 642491] [client 185.191.171.16:59030] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/10/28/90-dos-eleitores-de-nilvan-no-1o-turno-declaram-voto-em-pedro-mesmo-com-neutralidade/"] [unique_id "amuC-5SUkh3e5AhEJOCEQgAAAZA"]
[Thu Jul 30 11:59:39.238849 2026] [security2:error] [pid 642360:tid 642491] [client 185.191.171.16:59030] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/10/28/90-dos-eleitores-de-nilvan-no-1o-turno-declaram-voto-em-pedro-mesmo-com-neutralidade/"] [unique_id "amuC-5SUkh3e5AhEJOCEQgAAAZA"]
[Thu Jul 30 11:59:39.322067 2026] [core:notice] [pid 642360:tid 642496] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:39.328530 2026] [security2:error] [pid 642360:tid 642496] [client 103.215.74.26:62922] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC-5SUkh3e5AhEJOCERgAAAZU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:39.332769 2026] [security2:error] [pid 643253:tid 643460] [client 20.215.191.139:54666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/admin-ajax.php"] [unique_id "amuC-8jqbtjBYzqM1uYqPAAAAEw"]
[Thu Jul 30 11:59:39.868952 2026] [security2:error] [pid 642360:tid 642419] [remote 198.244.226.21:54408] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "koriusa.info"] [uri "/robots.txt"] [unique_id "amuC-5SUkh3e5AhEJOCEUQACBDo"]
[Thu Jul 30 11:59:39.869100 2026] [security2:error] [pid 642360:tid 642607] [client 198.244.226.21:54408] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "koriusa.info"] [uri "/robots.txt"] [unique_id "amuC-5SUkh3e5AhEJOCEUQACBDo"]
[Thu Jul 30 11:59:40.048466 2026] [core:notice] [pid 642360:tid 642582] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:40.052502 2026] [security2:error] [pid 642360:tid 642582] [client 103.215.74.26:62924] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "783"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC_JSUkh3e5AhEJOCEVAAAAes"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:40.088402 2026] [security2:error] [pid 643253:tid 643496] [client 20.215.191.139:35055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/moon.php"] [unique_id "amuC_MjqbtjBYzqM1uYqPwAAAHA"]
[Thu Jul 30 11:59:40.618538 2026] [security2:error] [pid 643253:tid 643486] [client 172.202.44.182:50524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/wp-blog-header.php"] [unique_id "amuC_MjqbtjBYzqM1uYqQwAAAGY"]
[Thu Jul 30 11:59:40.782681 2026] [core:notice] [pid 642360:tid 642538] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:40.786646 2026] [security2:error] [pid 642360:tid 642538] [client 103.215.74.26:62968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC_JSUkh3e5AhEJOCEWwAAAb8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:40.984517 2026] [security2:error] [pid 642360:tid 642597] [client 20.215.191.139:36143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amuC_JSUkh3e5AhEJOCEYgAAAfo"]
[Thu Jul 30 11:59:41.242801 2026] [security2:error] [pid 642360:tid 642444] [remote 198.244.183.195:33546] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "koriusa.info"] [uri "/adjustable-airflow-vape-guide-why-its-essential-in-2026/"] [unique_id "amuC_ZSUkh3e5AhEJOCEZAABrFM"]
[Thu Jul 30 11:59:41.242967 2026] [security2:error] [pid 642360:tid 642519] [client 198.244.183.195:33546] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "koriusa.info"] [uri "/adjustable-airflow-vape-guide-why-its-essential-in-2026/"] [unique_id "amuC_ZSUkh3e5AhEJOCEZAABrFM"]
[Thu Jul 30 11:59:41.517824 2026] [core:notice] [pid 642360:tid 642572] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:41.521884 2026] [security2:error] [pid 642360:tid 642572] [client 103.215.74.26:62986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC_ZSUkh3e5AhEJOCEawAAAeE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:41.755402 2026] [security2:error] [pid 642360:tid 642565] [client 20.215.191.139:54273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/alfa.php"] [unique_id "amuC_ZSUkh3e5AhEJOCEbQAAAdo"]
[Thu Jul 30 11:59:42.258787 2026] [core:notice] [pid 642360:tid 642553] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:42.262853 2026] [security2:error] [pid 642360:tid 642553] [client 103.215.74.26:62988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC_pSUkh3e5AhEJOCEdgAAAc4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:42.989847 2026] [core:notice] [pid 642360:tid 642544] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:42.996082 2026] [security2:error] [pid 642360:tid 642544] [client 103.215.74.26:62990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC_pSUkh3e5AhEJOCEfwAAAcU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:43.024952 2026] [core:notice] [pid 642360:tid 642517] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:43.173717 2026] [security2:error] [pid 642360:tid 642576] [client 20.215.191.139:54348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/hehe.php"] [unique_id "amuC_5SUkh3e5AhEJOCEhAAAAeU"]
[Thu Jul 30 11:59:43.759772 2026] [core:notice] [pid 642360:tid 642610] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:43.763736 2026] [security2:error] [pid 642360:tid 642610] [client 103.215.74.26:20576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC_5SUkh3e5AhEJOCEigAAAgc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:43.835158 2026] [security2:error] [pid 642360:tid 642536] [client 57.141.0.2:38494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuC_5SUkh3e5AhEJOCEhQABvVs"], referer: https://igetvape-australia.com/product/iget-moon-pomegranate-kiwi-ice/?add-to-cart=177
[Thu Jul 30 11:59:44.498959 2026] [core:notice] [pid 642360:tid 642508] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:44.502970 2026] [security2:error] [pid 642360:tid 642508] [client 103.215.74.26:20590] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDAJSUkh3e5AhEJOCElQAAAaE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:45.149071 2026] [security2:error] [pid 643253:tid 643474] [client 20.215.191.139:39423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "amuDAcjqbtjBYzqM1uYqeAAAAFo"]
[Thu Jul 30 11:59:45.230525 2026] [core:notice] [pid 643253:tid 643481] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:45.237178 2026] [security2:error] [pid 643253:tid 643481] [client 103.215.74.26:20602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDAcjqbtjBYzqM1uYqfAAAAGE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:45.412786 2026] [security2:error] [pid 642360:tid 642503] [client 216.244.66.243:36062] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabiandubaisafari.com"] [uri "/robots.txt"] [unique_id "amuDAZSUkh3e5AhEJOCEogAAAZw"]
[Thu Jul 30 11:59:45.412928 2026] [security2:error] [pid 642360:tid 642503] [client 216.244.66.243:36062] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "arabiandubaisafari.com"] [uri "/robots.txt"] [unique_id "amuDAZSUkh3e5AhEJOCEogAAAZw"]
[Thu Jul 30 11:59:45.603445 2026] [security2:error] [pid 643253:tid 643482] [client 50.6.43.217:45624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jesus.claims"] [uri "/index.php"] [unique_id "amuDAcjqbtjBYzqM1uYqfQAAAGI"]
[Thu Jul 30 11:59:45.672440 2026] [security2:error] [pid 642360:tid 642580] [client 172.202.44.182:45090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/wp-trackback.php"] [unique_id "amuDAZSUkh3e5AhEJOCEpgAAAek"]
[Thu Jul 30 11:59:45.726054 2026] [security2:error] [pid 643253:tid 643428] [client 50.6.43.217:45638] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jesus.claims"] [uri "/index.php"] [unique_id "amuDAcjqbtjBYzqM1uYqfgAAACw"]
[Thu Jul 30 11:59:45.838267 2026] [security2:error] [pid 643253:tid 643426] [client 20.215.191.139:43357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "amuDAcjqbtjBYzqM1uYqgAAAACo"]
[Thu Jul 30 11:59:45.972283 2026] [core:notice] [pid 643253:tid 643467] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:45.976229 2026] [security2:error] [pid 643253:tid 643467] [client 103.215.74.26:20616] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDAcjqbtjBYzqM1uYqgQAAAFM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:46.195790 2026] [security2:error] [pid 642360:tid 642451] [remote 5.39.1.236:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "massageandspaislamabad.rest"] [uri "/robots.txt"] [unique_id "amuDApSUkh3e5AhEJOCErgABmFo"]
[Thu Jul 30 11:59:46.195963 2026] [security2:error] [pid 642360:tid 642499] [client 5.39.1.236:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "massageandspaislamabad.rest"] [uri "/robots.txt"] [unique_id "amuDApSUkh3e5AhEJOCErgABmFo"]
[Thu Jul 30 11:59:46.321959 2026] [security2:error] [pid 643253:tid 643473] [client 176.241.66.87:48145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDAsjqbtjBYzqM1uYqhAAAAFk"]
[Thu Jul 30 11:59:46.322139 2026] [security2:error] [pid 643253:tid 643473] [client 176.241.66.87:48145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDAsjqbtjBYzqM1uYqhAAAAFk"]
[Thu Jul 30 11:59:46.564645 2026] [security2:error] [pid 642360:tid 642537] [client 172.202.44.182:50514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/wp-signup.php"] [unique_id "amuDApSUkh3e5AhEJOCEtQAAAb4"]
[Thu Jul 30 11:59:46.705846 2026] [core:notice] [pid 643253:tid 643507] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:46.710231 2026] [security2:error] [pid 643253:tid 643507] [client 103.215.74.26:20628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDAsjqbtjBYzqM1uYqhwAAAHs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:46.825958 2026] [security2:error] [pid 642360:tid 642517] [client 20.215.191.139:35010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/amaxx.php"] [unique_id "amuDApSUkh3e5AhEJOCEvgAAAao"]
[Thu Jul 30 11:59:47.006391 2026] [core:notice] [pid 642360:tid 642577] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:47.039955 2026] [core:notice] [pid 642360:tid 642380] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:47.431498 2026] [core:notice] [pid 642360:tid 642538] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:47.435654 2026] [security2:error] [pid 642360:tid 642538] [client 103.215.74.26:20630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDA5SUkh3e5AhEJOCEyAAAAb8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:47.591567 2026] [security2:error] [pid 642360:tid 642490] [client 20.215.191.139:17528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/bek.php"] [unique_id "amuDA5SUkh3e5AhEJOCEyQAAAY8"]
[Thu Jul 30 11:59:48.182044 2026] [core:notice] [pid 642360:tid 642508] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:48.186098 2026] [security2:error] [pid 642360:tid 642508] [client 103.215.74.26:20632] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDBJSUkh3e5AhEJOCE0gAAAaE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:48.239525 2026] [security2:error] [pid 642360:tid 642546] [client 3.255.255.17:24014] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/2024/04/favicon-300x300.jpg"] [unique_id "amuDBJSUkh3e5AhEJOCE1AABx3E"]
[Thu Jul 30 11:59:48.270992 2026] [security2:error] [pid 642360:tid 642492] [client 43.172.194.241:33510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.194.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/wp-json/oembed/1.0/embed"] [unique_id "amuDBJSUkh3e5AhEJOCE0QAAAZE"]
[Thu Jul 30 11:59:48.681055 2026] [security2:error] [pid 643253:tid 643511] [client 191.232.199.39:7085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/chosen.php"] [unique_id "amuDBMjqbtjBYzqM1uYqjQAAAH8"]
[Thu Jul 30 11:59:48.739360 2026] [security2:error] [pid 643253:tid 643409] [client 34.245.220.244:57262] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/2024/05/parlx-services-commercial-5.jpg"] [unique_id "amuDBMjqbtjBYzqM1uYqjAAAGT8"]
[Thu Jul 30 11:59:48.975535 2026] [core:notice] [pid 642360:tid 642613] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:48.981041 2026] [security2:error] [pid 642360:tid 642613] [client 43.173.173.127:42498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/wp-json/oembed/1.0/embed"] [unique_id "amuDBJSUkh3e5AhEJOCE4QAAAgo"], referer: https://carnetdeshopping.com/index.php/wp-json/oembed/1.0/embed?url=https%3A%2F%2Fcarnetdeshopping.com%2Findex.php%2F2012%2F06%2F07%2Fmiami-excursion-au-parc-national-des-everglades%2F&format=xml
[Thu Jul 30 11:59:49.301789 2026] [security2:error] [pid 642360:tid 642504] [client 20.215.191.139:54686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/rk2.php"] [unique_id "amuDBZSUkh3e5AhEJOCE4gAAAZ0"]
[Thu Jul 30 11:59:49.964284 2026] [security2:error] [pid 642360:tid 642608] [client 191.232.199.39:7059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/xleet.php"] [unique_id "amuDBZSUkh3e5AhEJOCE8QAAAgU"]
[Thu Jul 30 11:59:49.975671 2026] [security2:error] [pid 642360:tid 642578] [client 43.173.182.22:50336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.182.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sellvia.womenclothingbox.com"] [uri "/"] [unique_id "amuDBZSUkh3e5AhEJOCE6QAAAec"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:49.998765 2026] [security2:error] [pid 642360:tid 642610] [client 172.202.44.182:50507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/wp-comments-post.php"] [unique_id "amuDBZSUkh3e5AhEJOCE9QAAAgc"]
[Thu Jul 30 11:59:50.057606 2026] [security2:error] [pid 642360:tid 642487] [remote 47.128.96.2:25992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.96.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/2045"] [unique_id "amuDBZSUkh3e5AhEJOCE6gABzX4"]
[Thu Jul 30 11:59:50.105778 2026] [security2:error] [pid 642360:tid 642570] [client 20.215.191.139:54380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/setup-config.php"] [unique_id "amuDBpSUkh3e5AhEJOCE9gAAAd8"]
[Thu Jul 30 11:59:50.129659 2026] [core:notice] [pid 642360:tid 642366] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:50.134199 2026] [security2:error] [pid 642360:tid 642587] [client 47.128.96.2:25992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/2045"] [unique_id "amuDBpSUkh3e5AhEJOCE9wAB8AU"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 11:59:50.294791 2026] [core:notice] [pid 642360:tid 642382] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:50.380299 2026] [core:notice] [pid 642360:tid 642385] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:50.380499 2026] [core:notice] [pid 642360:tid 642478] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:50.610095 2026] [security2:error] [pid 642360:tid 642507] [client 20.215.191.139:35069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/caches.php.suspected"] [unique_id "amuDBpSUkh3e5AhEJOCFAQAAAaA"]
[Thu Jul 30 11:59:51.306517 2026] [security2:error] [pid 643253:tid 643460] [client 191.232.199.39:7041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/ds.php"] [unique_id "amuDB8jqbtjBYzqM1uYqkwAAAEw"]
[Thu Jul 30 11:59:51.537776 2026] [security2:error] [pid 643253:tid 643320] [remote 92.222.104.209:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "massageandspaislamabad.rest"] [uri "/"] [unique_id "amuDB8jqbtjBYzqM1uYqlAAAUEE"]
[Thu Jul 30 11:59:51.537926 2026] [security2:error] [pid 643253:tid 643464] [client 92.222.104.209:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "massageandspaislamabad.rest"] [uri "/"] [unique_id "amuDB8jqbtjBYzqM1uYqlAAAUEE"]
[Thu Jul 30 11:59:51.582504 2026] [security2:error] [pid 643253:tid 643430] [client 20.215.191.139:54355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/a7.php"] [unique_id "amuDB8jqbtjBYzqM1uYqlQAAAC4"]
[Thu Jul 30 11:59:52.292530 2026] [core:notice] [pid 643253:tid 643321] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:52.311469 2026] [security2:error] [pid 642360:tid 642503] [client 172.202.44.182:50556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/wp-mail.php"] [unique_id "amuDCJSUkh3e5AhEJOCFFgAAAZw"]
[Thu Jul 30 11:59:52.338792 2026] [core:error] [pid 642360:tid 642589] [client 66.249.73.204:45465] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:59:52.338811 2026] [core:error] [pid 642360:tid 642589] [client 66.249.73.204:45465] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:59:52.456625 2026] [security2:error] [pid 642360:tid 642502] [client 20.215.191.139:17515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/class.api.php"] [unique_id "amuDCJSUkh3e5AhEJOCFGAAAAZs"]
[Thu Jul 30 11:59:52.775962 2026] [security2:error] [pid 642360:tid 642606] [client 191.232.199.39:57725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/f5.php"] [unique_id "amuDCJSUkh3e5AhEJOCFHgAAAgM"]
[Thu Jul 30 11:59:52.789513 2026] [security2:error] [pid 642360:tid 642612] [client 74.7.230.58:52008] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.iig.gpl.temporary.site"] [uri "/robots.txt"] [unique_id "amuDCJSUkh3e5AhEJOCFHwAAAgk"]
[Thu Jul 30 11:59:53.005191 2026] [core:error] [pid 643253:tid 643322] [remote 74.7.230.10:44554] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:59:53.005521 2026] [core:error] [pid 643253:tid 643322] [remote 74.7.230.10:44554] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:59:53.005697 2026] [security2:error] [pid 643253:tid 643442] [client 74.7.230.10:44554] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.website-170cb886.ubp.hmu.temporary.site"] [uri "/index.php"] [unique_id "amuDCcjqbtjBYzqM1uYqmQAAOkM"]
[Thu Jul 30 11:59:53.090505 2026] [security2:error] [pid 643253:tid 643387] [client 20.215.191.139:54691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/f7.php"] [unique_id "amuDCcjqbtjBYzqM1uYqmgAAAAM"]
[Thu Jul 30 11:59:53.858141 2026] [security2:error] [pid 642360:tid 642614] [client 20.215.191.139:54389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/nw.php"] [unique_id "amuDCZSUkh3e5AhEJOCFLgAAAgs"]
[Thu Jul 30 11:59:53.921920 2026] [security2:error] [pid 642360:tid 642560] [client 172.245.102.89:61529] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "moswey.com"] [uri "/"] [unique_id "amuDCZSUkh3e5AhEJOCFLwAAAdU"]
[Thu Jul 30 11:59:53.959243 2026] [security2:error] [pid 643253:tid 643436] [client 191.232.199.39:57763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/god4m.php"] [unique_id "amuDCcjqbtjBYzqM1uYqngAAADQ"]
[Thu Jul 30 11:59:54.085081 2026] [core:notice] [pid 643253:tid 643478] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:54.089652 2026] [security2:error] [pid 643253:tid 643478] [client 103.215.74.26:55898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDCsjqbtjBYzqM1uYqnwAAAF4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:54.152403 2026] [security2:error] [pid 643253:tid 643452] [client 20.215.191.139:36153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/cong.php"] [unique_id "amuDCsjqbtjBYzqM1uYqoAAAAEQ"]
[Thu Jul 30 11:59:54.817509 2026] [core:notice] [pid 642360:tid 642563] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:54.821790 2026] [security2:error] [pid 642360:tid 642563] [client 103.215.74.26:55914] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDCpSUkh3e5AhEJOCFPwAAAdg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:54.842904 2026] [security2:error] [pid 642360:tid 642605] [client 136.144.33.249:28787] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "moswey.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "amuDCpSUkh3e5AhEJOCFQAAAAgI"]
[Thu Jul 30 11:59:54.869890 2026] [core:notice] [pid 643253:tid 643323] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:55.045443 2026] [security2:error] [pid 643253:tid 643474] [client 20.215.191.139:39365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/content.php"] [unique_id "amuDC8jqbtjBYzqM1uYqogAAAFo"]
[Thu Jul 30 11:59:55.363629 2026] [security2:error] [pid 642360:tid 642573] [client 20.215.191.139:54398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/ova.php"] [unique_id "amuDC5SUkh3e5AhEJOCFRgAAAeI"]
[Thu Jul 30 11:59:55.557178 2026] [core:notice] [pid 642360:tid 642572] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:55.561624 2026] [security2:error] [pid 642360:tid 642572] [client 103.215.74.26:55922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDC5SUkh3e5AhEJOCFSAAAAeE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:55.610572 2026] [security2:error] [pid 643253:tid 643434] [client 191.232.199.39:6269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/info.php"] [unique_id "amuDC8jqbtjBYzqM1uYqpgAAADI"]
[Thu Jul 30 11:59:55.833110 2026] [security2:error] [pid 642360:tid 642590] [client 136.144.33.66:22959] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "moswey.com"] [uri "/media/system/js/core.js"] [unique_id "amuDC5SUkh3e5AhEJOCFTgAAAfM"]
[Thu Jul 30 11:59:55.851858 2026] [security2:error] [pid 642360:tid 642565] [client 20.215.191.139:39984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/cwianpri.php"] [unique_id "amuDC5SUkh3e5AhEJOCFTwAAAdo"]
[Thu Jul 30 11:59:56.267466 2026] [security2:error] [pid 643253:tid 643428] [client 20.215.191.139:54370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/robots.php"] [unique_id "amuDDMjqbtjBYzqM1uYqqAAAACw"]
[Thu Jul 30 11:59:56.305672 2026] [core:notice] [pid 642360:tid 642516] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:56.310186 2026] [security2:error] [pid 642360:tid 642516] [client 103.215.74.26:55926] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDDJSUkh3e5AhEJOCFVgAAAak"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:56.548751 2026] [security2:error] [pid 642360:tid 642512] [client 20.215.191.139:39408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/elp.php"] [unique_id "amuDDJSUkh3e5AhEJOCFVwAAAaU"]
[Thu Jul 30 11:59:56.949639 2026] [security2:error] [pid 643253:tid 643324] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/chosen.php"] [unique_id "amuDDMjqbtjBYzqM1uYqqgAAQ0U"]
[Thu Jul 30 11:59:56.971266 2026] [security2:error] [pid 642360:tid 642544] [client 57.141.0.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuDDJSUkh3e5AhEJOCFYAAAAcU"]
[Thu Jul 30 11:59:57.049141 2026] [security2:error] [pid 642360:tid 642586] [client 176.241.66.87:48817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDDZSUkh3e5AhEJOCFZAAAAe8"]
[Thu Jul 30 11:59:57.049256 2026] [security2:error] [pid 642360:tid 642586] [client 176.241.66.87:48817] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDDZSUkh3e5AhEJOCFZAAAAe8"]
[Thu Jul 30 11:59:57.052895 2026] [core:notice] [pid 642360:tid 642591] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:57.057278 2026] [security2:error] [pid 642360:tid 642591] [client 103.215.74.26:55930] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDDZSUkh3e5AhEJOCFZQAAAfQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:57.347354 2026] [security2:error] [pid 643253:tid 643426] [client 20.215.191.139:54675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/alf.php"] [unique_id "amuDDcjqbtjBYzqM1uYqrQAAACo"]
[Thu Jul 30 11:59:57.761051 2026] [security2:error] [pid 643253:tid 643508] [client 191.232.199.39:6252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/.__info.php"] [unique_id "amuDDcjqbtjBYzqM1uYqrwAAAHw"]
[Thu Jul 30 11:59:57.796376 2026] [core:notice] [pid 642360:tid 642555] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:57.802520 2026] [security2:error] [pid 642360:tid 642555] [client 103.215.74.26:55942] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDDZSUkh3e5AhEJOCFdQAAAdA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:57.813929 2026] [security2:error] [pid 642360:tid 642373] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/xleet.php"] [unique_id "amuDDZSUkh3e5AhEJOCFdgABsgw"]
[Thu Jul 30 11:59:58.148470 2026] [security2:error] [pid 642360:tid 642426] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/ds.php"] [unique_id "amuDDpSUkh3e5AhEJOCFeQABrEE"]
[Thu Jul 30 11:59:58.206152 2026] [security2:error] [pid 642360:tid 642507] [client 20.215.191.139:54336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/feedback.php"] [unique_id "amuDDpSUkh3e5AhEJOCFegAAAaA"]
[Thu Jul 30 11:59:58.215695 2026] [security2:error] [pid 642360:tid 642550] [client 178.20.45.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDDZSUkh3e5AhEJOCFaAAByyk"], referer: https://allmontecristi.com/5-important-characteristics-to-identify-an-export-panama-hat/?srsltid=afmbooobpjslvy1dcritpm3oyoloutbopk2q0t238sboel09-jvs0f2z
[Thu Jul 30 11:59:58.455810 2026] [security2:error] [pid 642360:tid 642392] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/f5.php"] [unique_id "amuDDpSUkh3e5AhEJOCFgAABlx8"]
[Thu Jul 30 11:59:58.535320 2026] [core:notice] [pid 642360:tid 642532] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:58.539713 2026] [security2:error] [pid 642360:tid 642532] [client 103.215.74.26:55948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDDpSUkh3e5AhEJOCFgQAAAbk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:58.766844 2026] [security2:error] [pid 642360:tid 642408] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/god4m.php"] [unique_id "amuDDpSUkh3e5AhEJOCFggABny8"]
[Thu Jul 30 11:59:58.883641 2026] [security2:error] [pid 643253:tid 643493] [client 20.215.191.139:35009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/kwggvpup.php"] [unique_id "amuDDsjqbtjBYzqM1uYqsgAAAG0"]
[Thu Jul 30 11:59:58.886573 2026] [security2:error] [pid 642360:tid 642617] [client 2a03:2880:f800:d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDDpSUkh3e5AhEJOCFeAACDnY"]
[Thu Jul 30 11:59:58.986577 2026] [security2:error] [pid 642360:tid 642603] [client 20.215.191.139:54369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/gettest.php"] [unique_id "amuDDpSUkh3e5AhEJOCFiAAAAgA"]
[Thu Jul 30 11:59:59.075610 2026] [security2:error] [pid 642360:tid 642437] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/info.php"] [unique_id "amuDD5SUkh3e5AhEJOCFiQAB8Uw"]
[Thu Jul 30 11:59:59.102808 2026] [security2:error] [pid 643253:tid 643480] [client 191.232.199.39:6259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/0.php"] [unique_id "amuDD8jqbtjBYzqM1uYqswAAAGA"]
[Thu Jul 30 11:59:59.391254 2026] [security2:error] [pid 643253:tid 643409] [client 20.215.191.139:39399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/101d2ae2-f2f3-4977-b35d-b3a0ad74a469.php"] [unique_id "amuDD8jqbtjBYzqM1uYqtQAAABk"]
[Thu Jul 30 11:59:59.741987 2026] [security2:error] [pid 643253:tid 643438] [client 178.20.45.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDD8jqbtjBYzqM1uYqtAAANkg"], referer: https://allmontecristi.com/contact/
[Thu Jul 30 12:00:00.270219 2026] [security2:error] [pid 642360:tid 642522] [client 191.232.199.39:36418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/07.php"] [unique_id "amuDEJSUkh3e5AhEJOCFmwAAAa8"]
[Thu Jul 30 12:00:00.358768 2026] [security2:error] [pid 642360:tid 642491] [client 172.202.44.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDD5SUkh3e5AhEJOCFkAABkEA"]
[Thu Jul 30 12:00:00.657201 2026] [autoindex:error] [pid 643253:tid 643423] [client 44.213.206.96:16713] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_b1080a24/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:00:00.783062 2026] [security2:error] [pid 642360:tid 642539] [client 172.202.44.182:45106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/wp-activate.php"] [unique_id "amuDEJSUkh3e5AhEJOCFpwAAAcA"]
[Thu Jul 30 12:00:00.821677 2026] [security2:error] [pid 643253:tid 643475] [client 2a03:2880:f800:7:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDD8jqbtjBYzqM1uYqtwAAW0c"]
[Thu Jul 30 12:00:00.838482 2026] [security2:error] [pid 642360:tid 642516] [client 20.215.191.139:54395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/maint.php"] [unique_id "amuDEJSUkh3e5AhEJOCFqAAAAak"]
[Thu Jul 30 12:00:00.945057 2026] [security2:error] [pid 643253:tid 643331] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/.__info.php"] [unique_id "amuDEMjqbtjBYzqM1uYqvAAAI0w"]
[Thu Jul 30 12:00:01.234815 2026] [security2:error] [pid 643253:tid 643329] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/0.php"] [unique_id "amuDEcjqbtjBYzqM1uYqvQAACko"]
[Thu Jul 30 12:00:01.482303 2026] [security2:error] [pid 643253:tid 643450] [client 20.215.191.139:54663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/files.php"] [unique_id "amuDEcjqbtjBYzqM1uYqwgAAAEI"]
[Thu Jul 30 12:00:01.513197 2026] [security2:error] [pid 643253:tid 643333] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/07.php"] [unique_id "amuDEcjqbtjBYzqM1uYqxAAAaU4"]
[Thu Jul 30 12:00:01.537325 2026] [security2:error] [pid 642360:tid 642515] [client 191.232.199.39:6232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/dropdown.php"] [unique_id "amuDEZSUkh3e5AhEJOCFswAAAag"]
[Thu Jul 30 12:00:01.761961 2026] [security2:error] [pid 643253:tid 643335] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/dropdown.php"] [unique_id "amuDEcjqbtjBYzqM1uYqyQAATlA"]
[Thu Jul 30 12:00:01.859401 2026] [core:notice] [pid 643253:tid 643336] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:02.068472 2026] [security2:error] [pid 642360:tid 642528] [client 20.215.191.139:54399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/gecko.php"] [unique_id "amuDEpSUkh3e5AhEJOCFuQAAAbU"]
[Thu Jul 30 12:00:02.072579 2026] [security2:error] [pid 643253:tid 643334] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/makeasmtp.php"] [unique_id "amuDEsjqbtjBYzqM1uYqzAAAFE8"]
[Thu Jul 30 12:00:02.189494 2026] [security2:error] [pid 642360:tid 642577] [client 172.202.44.182:45105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/post.php"] [unique_id "amuDEpSUkh3e5AhEJOCFwAAAAeY"]
[Thu Jul 30 12:00:02.321039 2026] [security2:error] [pid 643253:tid 643337] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-sigunq.php"] [unique_id "amuDEsjqbtjBYzqM1uYq0AAAJlI"]
[Thu Jul 30 12:00:02.377731 2026] [security2:error] [pid 642360:tid 642592] [client 20.215.191.139:40207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/LA.php"] [unique_id "amuDEpSUkh3e5AhEJOCFwwAAAfU"]
[Thu Jul 30 12:00:02.566417 2026] [security2:error] [pid 642360:tid 642444] [remote 74.7.241.59:60676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuDEpSUkh3e5AhEJOCFxwACAlM"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/theme-builder/documents
[Thu Jul 30 12:00:02.571308 2026] [security2:error] [pid 643253:tid 643339] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wso112233.php"] [unique_id "amuDEsjqbtjBYzqM1uYq0gAAAFQ"]
[Thu Jul 30 12:00:02.790942 2026] [security2:error] [pid 643253:tid 643460] [client 172.237.109.114:17111] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDEsjqbtjBYzqM1uYqzQAAAEw"]
[Thu Jul 30 12:00:02.793200 2026] [security2:error] [pid 642360:tid 642611] [client 172.237.109.114:57009] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDEpSUkh3e5AhEJOCFugAAAgg"]
[Thu Jul 30 12:00:02.813949 2026] [security2:error] [pid 643253:tid 643395] [client 172.237.109.114:6908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDEsjqbtjBYzqM1uYqzgAAAAs"]
[Thu Jul 30 12:00:02.822701 2026] [security2:error] [pid 643253:tid 643338] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/alfanew.php"] [unique_id "amuDEsjqbtjBYzqM1uYq1AAAUVM"]
[Thu Jul 30 12:00:02.826922 2026] [security2:error] [pid 643253:tid 643464] [client 172.237.109.114:47879] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDEsjqbtjBYzqM1uYqzwAAAFA"]
[Thu Jul 30 12:00:02.828488 2026] [security2:error] [pid 642360:tid 642490] [client 172.237.109.114:42763] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDEpSUkh3e5AhEJOCFvgAAAY8"]
[Thu Jul 30 12:00:02.830491 2026] [security2:error] [pid 642360:tid 642493] [client 172.237.109.114:40699] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDEpSUkh3e5AhEJOCFvwAAAZI"]
[Thu Jul 30 12:00:02.958043 2026] [security2:error] [pid 642360:tid 642599] [client 191.232.199.39:6241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/makeasmtp.php"] [unique_id "amuDEpSUkh3e5AhEJOCF0AAAAfw"]
[Thu Jul 30 12:00:03.070706 2026] [security2:error] [pid 643253:tid 643340] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/fw.php"] [unique_id "amuDE8jqbtjBYzqM1uYq1QAAQVU"]
[Thu Jul 30 12:00:03.319708 2026] [security2:error] [pid 643253:tid 643341] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-login.php"] [unique_id "amuDE8jqbtjBYzqM1uYq3wAAM1Y"]
[Thu Jul 30 12:00:03.604728 2026] [security2:error] [pid 643253:tid 643342] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/simple.php"] [unique_id "amuDE8jqbtjBYzqM1uYq4QAAXlc"]
[Thu Jul 30 12:00:03.852771 2026] [security2:error] [pid 643253:tid 643343] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/classsmtps.php"] [unique_id "amuDE8jqbtjBYzqM1uYq4wAARFg"]
[Thu Jul 30 12:00:04.093008 2026] [security2:error] [pid 642360:tid 642558] [client 20.215.191.139:40227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/Newsupway.php"] [unique_id "amuDFJSUkh3e5AhEJOCF4wAAAdM"]
[Thu Jul 30 12:00:04.258653 2026] [core:notice] [pid 642360:tid 642607] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:04.261930 2026] [security2:error] [pid 642360:tid 642531] [client 172.237.109.114:40813] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDE5SUkh3e5AhEJOCF0gAAAbg"]
[Thu Jul 30 12:00:04.266187 2026] [security2:error] [pid 642360:tid 642607] [client 103.215.74.26:43502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDFJSUkh3e5AhEJOCF5gAAAgQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:04.268806 2026] [security2:error] [pid 643253:tid 643388] [client 172.237.109.114:19861] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDE8jqbtjBYzqM1uYq2AAAAAQ"]
[Thu Jul 30 12:00:04.269362 2026] [security2:error] [pid 643253:tid 643466] [client 172.237.109.114:64870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDE8jqbtjBYzqM1uYq1wAAAFI"]
[Thu Jul 30 12:00:04.274783 2026] [security2:error] [pid 643253:tid 643345] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-blog-header.php"] [unique_id "amuDFMjqbtjBYzqM1uYq5gAAWlo"]
[Thu Jul 30 12:00:04.283154 2026] [security2:error] [pid 642360:tid 642574] [client 172.237.109.114:55658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDE5SUkh3e5AhEJOCF0QAAAeM"]
[Thu Jul 30 12:00:04.283744 2026] [security2:error] [pid 642360:tid 642409] [remote 57.141.0.52:39074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/tumed/index"] [unique_id "amuDFJSUkh3e5AhEJOCF5wABwTA"]
[Thu Jul 30 12:00:04.290379 2026] [security2:error] [pid 643253:tid 643501] [client 172.237.109.114:61384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDE8jqbtjBYzqM1uYq1gAAAHU"]
[Thu Jul 30 12:00:04.294517 2026] [security2:error] [pid 642360:tid 642520] [client 172.237.109.114:6334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDE5SUkh3e5AhEJOCF1AAAAa0"]
[Thu Jul 30 12:00:04.352836 2026] [security2:error] [pid 643253:tid 643389] [client 172.237.109.114:52777] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDE8jqbtjBYzqM1uYq2QAAAAU"]
[Thu Jul 30 12:00:04.364996 2026] [security2:error] [pid 643253:tid 643390] [client 172.237.109.114:63236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDE8jqbtjBYzqM1uYq2gAAAAY"]
[Thu Jul 30 12:00:04.369543 2026] [security2:error] [pid 642360:tid 642565] [client 172.237.109.114:57959] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDE5SUkh3e5AhEJOCF0wAAAdo"]
[Thu Jul 30 12:00:04.378225 2026] [security2:error] [pid 642360:tid 642596] [client 172.237.109.114:21059] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDE5SUkh3e5AhEJOCF1wAAAfk"]
[Thu Jul 30 12:00:04.381649 2026] [security2:error] [pid 643253:tid 643408] [client 172.237.109.114:51490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDE8jqbtjBYzqM1uYq3AAAABg"]
[Thu Jul 30 12:00:04.398159 2026] [security2:error] [pid 643253:tid 643387] [client 172.237.109.114:47995] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDE8jqbtjBYzqM1uYq3QAAAAM"]
[Thu Jul 30 12:00:04.422941 2026] [security2:error] [pid 643253:tid 643441] [client 172.237.109.114:17850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDE8jqbtjBYzqM1uYq3gAAADk"]
[Thu Jul 30 12:00:04.425113 2026] [security2:error] [pid 642360:tid 642521] [client 172.237.109.114:51373] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDE5SUkh3e5AhEJOCF2AAAAa4"]
[Thu Jul 30 12:00:04.522885 2026] [security2:error] [pid 643253:tid 643346] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-trackback.php"] [unique_id "amuDFMjqbtjBYzqM1uYq5wAASls"]
[Thu Jul 30 12:00:04.742752 2026] [security2:error] [pid 643253:tid 643431] [client 191.232.199.39:59605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-sigunq.php"] [unique_id "amuDFMjqbtjBYzqM1uYq6wAAAC8"]
[Thu Jul 30 12:00:04.807553 2026] [security2:error] [pid 643253:tid 643347] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-signup.php"] [unique_id "amuDFMjqbtjBYzqM1uYq7AAAblw"]
[Thu Jul 30 12:00:04.990792 2026] [core:notice] [pid 643253:tid 643468] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:04.995529 2026] [security2:error] [pid 643253:tid 643468] [client 103.215.74.26:43514] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDFMjqbtjBYzqM1uYq7QAAAFQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:05.058051 2026] [security2:error] [pid 643253:tid 643349] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-comments-post.php"] [unique_id "amuDFcjqbtjBYzqM1uYq7gAAT14"]
[Thu Jul 30 12:00:05.304899 2026] [security2:error] [pid 643253:tid 643350] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-mail.php"] [unique_id "amuDFcjqbtjBYzqM1uYq7wAAF18"]
[Thu Jul 30 12:00:05.564703 2026] [security2:error] [pid 643253:tid 643348] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-activate.php"] [unique_id "amuDFcjqbtjBYzqM1uYq8gAAbF0"]
[Thu Jul 30 12:00:05.726340 2026] [core:notice] [pid 642360:tid 642569] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:05.730331 2026] [security2:error] [pid 642360:tid 642569] [client 103.215.74.26:43528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDFZSUkh3e5AhEJOCF_QAAAd4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:05.781169 2026] [security2:error] [pid 643253:tid 643398] [client 20.215.191.139:17490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/a.php"] [unique_id "amuDFcjqbtjBYzqM1uYq9AAAAA4"]
[Thu Jul 30 12:00:05.886558 2026] [security2:error] [pid 643253:tid 643351] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/post.php"] [unique_id "amuDFcjqbtjBYzqM1uYq9QAAZ2A"]
[Thu Jul 30 12:00:06.137573 2026] [security2:error] [pid 643253:tid 643353] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-2019.php"] [unique_id "amuDFsjqbtjBYzqM1uYq9gAAPGI"]
[Thu Jul 30 12:00:06.309023 2026] [security2:error] [pid 642360:tid 642504] [client 213.152.161.219:40610] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuDFpSUkh3e5AhEJOCGAgAAAZ0"]
[Thu Jul 30 12:00:06.309142 2026] [security2:error] [pid 642360:tid 642504] [client 213.152.161.219:40610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuDFpSUkh3e5AhEJOCGAgAAAZ0"]
[Thu Jul 30 12:00:06.409749 2026] [security2:error] [pid 643253:tid 643352] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/hoot.php"] [unique_id "amuDFsjqbtjBYzqM1uYq-AAALWE"]
[Thu Jul 30 12:00:06.460046 2026] [core:notice] [pid 642360:tid 642522] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:06.464511 2026] [security2:error] [pid 642360:tid 642522] [client 103.215.74.26:43542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDFpSUkh3e5AhEJOCGCgAAAa8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:06.531767 2026] [security2:error] [pid 642360:tid 642604] [client 191.232.199.39:36453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wso112233.php"] [unique_id "amuDFpSUkh3e5AhEJOCGCwAAAgE"]
[Thu Jul 30 12:00:06.656727 2026] [security2:error] [pid 643253:tid 643354] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/log.php"] [unique_id "amuDFsjqbtjBYzqM1uYq-QAANmM"]
[Thu Jul 30 12:00:07.116574 2026] [security2:error] [pid 643253:tid 643355] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/bak.php"] [unique_id "amuDF8jqbtjBYzqM1uYq_QAAMWQ"]
[Thu Jul 30 12:00:07.186852 2026] [core:notice] [pid 642360:tid 642615] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:07.190944 2026] [security2:error] [pid 642360:tid 642615] [client 103.215.74.26:43558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDF5SUkh3e5AhEJOCGEwAAAgw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:07.397131 2026] [security2:error] [pid 643253:tid 643356] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/content.php"] [unique_id "amuDF8jqbtjBYzqM1uYq_gAAJ2U"]
[Thu Jul 30 12:00:07.398154 2026] [security2:error] [pid 642360:tid 642466] [remote 198.38.90.25:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.90.38.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "altaazi.com"] [uri "/wp-login.php"] [unique_id "amuDF5SUkh3e5AhEJOCGGgAB72k"]
[Thu Jul 30 12:00:07.647444 2026] [security2:error] [pid 643253:tid 643357] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/upfile.php"] [unique_id "amuDF8jqbtjBYzqM1uYq_wAAS2Y"]
[Thu Jul 30 12:00:07.692914 2026] [security2:error] [pid 642360:tid 642520] [client 176.241.66.87:49497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDF5SUkh3e5AhEJOCGHAAAAa0"]
[Thu Jul 30 12:00:07.693034 2026] [security2:error] [pid 642360:tid 642520] [client 176.241.66.87:49497] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDF5SUkh3e5AhEJOCGHAAAAa0"]
[Thu Jul 30 12:00:07.697955 2026] [security2:error] [pid 643253:tid 643427] [client 57.141.0.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuDF8jqbtjBYzqM1uYq_AAAACs"]
[Thu Jul 30 12:00:07.758333 2026] [proxy:error] [pid 642360:tid 642552] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:00:07.758397 2026] [proxy_http:error] [pid 642360:tid 642552] [client 34.233.129.35:30914] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:00:07.758932 2026] [proxy:error] [pid 642360:tid 642552] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:00:07.758988 2026] [proxy_http:error] [pid 642360:tid 642552] [client 34.233.129.35:30914] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:00:07.809204 2026] [security2:error] [pid 642360:tid 642596] [client 20.215.191.139:39387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "amuDF5SUkh3e5AhEJOCGJAAAAfk"]
[Thu Jul 30 12:00:07.833287 2026] [security2:error] [pid 642360:tid 642591] [client 191.232.199.39:57732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/alfanew.php"] [unique_id "amuDF5SUkh3e5AhEJOCGJQAAAfQ"]
[Thu Jul 30 12:00:07.969107 2026] [security2:error] [pid 643253:tid 643358] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/bypass.php"] [unique_id "amuDF8jqbtjBYzqM1uYrAAAAHGc"]
[Thu Jul 30 12:00:07.970369 2026] [core:notice] [pid 642360:tid 642542] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:07.974687 2026] [security2:error] [pid 642360:tid 642542] [client 103.215.74.26:43564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDF5SUkh3e5AhEJOCGJgAAAcM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:08.107325 2026] [security2:error] [pid 642360:tid 642526] [client 172.202.44.182:45067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/wp-2019.php"] [unique_id "amuDGJSUkh3e5AhEJOCGKgAAAbM"]
[Thu Jul 30 12:00:08.225575 2026] [security2:error] [pid 643253:tid 643359] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/updates.php"] [unique_id "amuDGMjqbtjBYzqM1uYrAQAACmg"]
[Thu Jul 30 12:00:08.272955 2026] [security2:error] [pid 642360:tid 642551] [client 192.250.229.28:11760] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuDGJSUkh3e5AhEJOCGLQABzFc"]
[Thu Jul 30 12:00:08.473372 2026] [security2:error] [pid 643253:tid 643361] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/xmrlpc.php"] [unique_id "amuDGMjqbtjBYzqM1uYrAwAACWo"]
[Thu Jul 30 12:00:08.610311 2026] [security2:error] [pid 642360:tid 642605] [client 20.215.191.139:39965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/amaxx.php"] [unique_id "amuDGJSUkh3e5AhEJOCGNAAAAgI"]
[Thu Jul 30 12:00:08.718871 2026] [core:notice] [pid 642360:tid 642603] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:08.725634 2026] [security2:error] [pid 642360:tid 642603] [client 103.215.74.26:43568] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDGJSUkh3e5AhEJOCGNQAAAgA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:08.799224 2026] [security2:error] [pid 643253:tid 643360] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/ae.php"] [unique_id "amuDGMjqbtjBYzqM1uYrBAAAeWk"]
[Thu Jul 30 12:00:09.010812 2026] [security2:error] [pid 642360:tid 642611] [client 191.232.199.39:6317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/fw.php"] [unique_id "amuDGZSUkh3e5AhEJOCGPgAAAgg"]
[Thu Jul 30 12:00:09.066430 2026] [security2:error] [pid 643253:tid 643362] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/moon.php"] [unique_id "amuDGcjqbtjBYzqM1uYrBgAAaGs"]
[Thu Jul 30 12:00:09.098867 2026] [security2:error] [pid 642360:tid 642533] [client 172.202.44.182:45071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/hoot.php"] [unique_id "amuDGZSUkh3e5AhEJOCGPwAAAbo"]
[Thu Jul 30 12:00:09.200489 2026] [security2:error] [pid 642360:tid 642590] [client 66.249.73.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "vvr.hfl.temporary.site"] [uri "/index.php"] [unique_id "amuDGJSUkh3e5AhEJOCGOgAAAfM"]
[Thu Jul 30 12:00:09.330896 2026] [security2:error] [pid 642360:tid 642503] [client 20.215.191.139:40240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/bb.php"] [unique_id "amuDGZSUkh3e5AhEJOCGQwAAAZw"]
[Thu Jul 30 12:00:09.340432 2026] [security2:error] [pid 643253:tid 643363] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/blog.php"] [unique_id "amuDGcjqbtjBYzqM1uYrBwAAaWw"]
[Thu Jul 30 12:00:09.469558 2026] [core:notice] [pid 642360:tid 642557] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:09.476412 2026] [security2:error] [pid 642360:tid 642557] [client 103.215.74.26:43584] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDGZSUkh3e5AhEJOCGRQAAAdI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:09.652226 2026] [security2:error] [pid 643253:tid 643364] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/ini.php"] [unique_id "amuDGcjqbtjBYzqM1uYrCAAAc20"]
[Thu Jul 30 12:00:09.902016 2026] [security2:error] [pid 643253:tid 643365] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/admin-ajax.php"] [unique_id "amuDGcjqbtjBYzqM1uYrCQAAVm4"]
[Thu Jul 30 12:00:09.978130 2026] [core:error] [pid 642360:tid 642548] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:00:09.978154 2026] [core:error] [pid 642360:tid 642548] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:00:10.111880 2026] [security2:error] [pid 642360:tid 642585] [client 20.215.191.139:17494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/cifcxgxm.php"] [unique_id "amuDGpSUkh3e5AhEJOCGWAAAAe4"]
[Thu Jul 30 12:00:10.133016 2026] [security2:error] [pid 642360:tid 642523] [client 172.202.44.182:45085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/log.php"] [unique_id "amuDGpSUkh3e5AhEJOCGWgAAAbA"]
[Thu Jul 30 12:00:10.205416 2026] [core:notice] [pid 643253:tid 643453] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:10.209367 2026] [security2:error] [pid 643253:tid 643453] [client 103.215.74.26:43592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDGsjqbtjBYzqM1uYrCgAAAEU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:10.347867 2026] [proxy:error] [pid 642360:tid 642596] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:00:10.347943 2026] [proxy_http:error] [pid 642360:tid 642596] [client 143.244.57.82:52584] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:00:10.348537 2026] [proxy:error] [pid 642360:tid 642596] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:00:10.348593 2026] [proxy_http:error] [pid 642360:tid 642596] [client 143.244.57.82:52584] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:00:10.373373 2026] [security2:error] [pid 643253:tid 643368] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/akc.php"] [unique_id "amuDGsjqbtjBYzqM1uYrCwAAAXE"]
[Thu Jul 30 12:00:10.639863 2026] [proxy:error] [pid 642360:tid 642577] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:00:10.639934 2026] [proxy_http:error] [pid 642360:tid 642577] [client 143.244.57.82:52590] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:00:10.640509 2026] [proxy:error] [pid 642360:tid 642577] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:00:10.640554 2026] [proxy_http:error] [pid 642360:tid 642577] [client 143.244.57.82:52590] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:00:10.642387 2026] [security2:error] [pid 643253:tid 643367] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/akcc.php"] [unique_id "amuDGsjqbtjBYzqM1uYrDQAAPXA"]
[Thu Jul 30 12:00:10.790373 2026] [security2:error] [pid 642360:tid 642597] [client 20.215.191.139:39388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/ckyocyyp.php"] [unique_id "amuDGpSUkh3e5AhEJOCGZQAAAfo"]
[Thu Jul 30 12:00:10.858095 2026] [security2:error] [pid 642360:tid 642582] [client 191.232.199.39:6215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-login.php"] [unique_id "amuDGpSUkh3e5AhEJOCGYwAAAes"]
[Thu Jul 30 12:00:10.890314 2026] [security2:error] [pid 643253:tid 643366] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/asasx.php"] [unique_id "amuDGsjqbtjBYzqM1uYrDgAAJm8"]
[Thu Jul 30 12:00:10.925878 2026] [security2:error] [pid 642360:tid 642601] [client 143.244.57.82:52604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.yaz.gzj.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuDGpSUkh3e5AhEJOCGagAAAf4"]
[Thu Jul 30 12:00:10.927741 2026] [core:notice] [pid 643253:tid 643414] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:10.931937 2026] [security2:error] [pid 643253:tid 643414] [client 103.215.74.26:43594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "767"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDGsjqbtjBYzqM1uYrDwAAAB4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:11.136434 2026] [security2:error] [pid 643253:tid 643369] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/axx.php"] [unique_id "amuDG8jqbtjBYzqM1uYrEQAAAHI"]
[Thu Jul 30 12:00:11.216055 2026] [security2:error] [pid 642360:tid 642588] [client 143.244.57.82:52612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.yaz.gzj.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuDG5SUkh3e5AhEJOCGcAAAAfE"]
[Thu Jul 30 12:00:11.385835 2026] [security2:error] [pid 643253:tid 643370] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/berax.php"] [unique_id "amuDG8jqbtjBYzqM1uYrEgAAZnM"]
[Thu Jul 30 12:00:11.491126 2026] [security2:error] [pid 643253:tid 643472] [client 143.244.57.82:52626] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.yaz.gzj.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuDG8jqbtjBYzqM1uYrFAAAAFg"]
[Thu Jul 30 12:00:11.528871 2026] [security2:error] [pid 642360:tid 642490] [client 20.215.191.139:39372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/classwithtostring.php"] [unique_id "amuDG5SUkh3e5AhEJOCGdAAAAY8"]
[Thu Jul 30 12:00:11.562073 2026] [security2:error] [pid 643253:tid 643401] [client 20.91.199.21:52458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/011i.php"] [unique_id "amuDG8jqbtjBYzqM1uYrFQAAABE"]
[Thu Jul 30 12:00:11.682853 2026] [security2:error] [pid 643253:tid 643371] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/build.php"] [unique_id "amuDG8jqbtjBYzqM1uYrFgAAKXQ"]
[Thu Jul 30 12:00:11.684258 2026] [core:notice] [pid 642360:tid 642572] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:11.691117 2026] [security2:error] [pid 642360:tid 642572] [client 103.215.74.26:43600] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDG5SUkh3e5AhEJOCGeAAAAeE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:11.773488 2026] [security2:error] [pid 642360:tid 642503] [client 143.244.57.82:52642] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.yaz.gzj.temporary.site"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuDG5SUkh3e5AhEJOCGeQAAAZw"]
[Thu Jul 30 12:00:11.930356 2026] [security2:error] [pid 643253:tid 643373] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/buy.php"] [unique_id "amuDG8jqbtjBYzqM1uYrGQAAM3Y"]
[Thu Jul 30 12:00:12.068100 2026] [security2:error] [pid 643253:tid 643436] [client 143.244.57.82:52658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.yaz.gzj.temporary.site"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuDHMjqbtjBYzqM1uYrGgAAADQ"]
[Thu Jul 30 12:00:12.149307 2026] [security2:error] [pid 642360:tid 642538] [client 172.202.44.182:45062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/bak.php"] [unique_id "amuDHJSUkh3e5AhEJOCGfwAAAb8"]
[Thu Jul 30 12:00:12.179448 2026] [security2:error] [pid 643253:tid 643374] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/checkbox.php"] [unique_id "amuDHMjqbtjBYzqM1uYrGwAAXnc"]
[Thu Jul 30 12:00:12.266449 2026] [security2:error] [pid 643253:tid 643424] [client 191.232.199.39:57772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/simple.php"] [unique_id "amuDHMjqbtjBYzqM1uYrHAAAACg"]
[Thu Jul 30 12:00:12.291868 2026] [security2:error] [pid 642360:tid 642613] [client 20.215.191.139:54594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/zwso.php"] [unique_id "amuDHJSUkh3e5AhEJOCGgAAAAgo"]
[Thu Jul 30 12:00:12.346663 2026] [security2:error] [pid 642360:tid 642600] [client 143.244.57.82:52668] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.yaz.gzj.temporary.site"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuDHJSUkh3e5AhEJOCGggAAAf0"]
[Thu Jul 30 12:00:12.419704 2026] [core:notice] [pid 642360:tid 642604] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:12.423770 2026] [security2:error] [pid 642360:tid 642604] [client 103.215.74.26:43604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "780"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDHJSUkh3e5AhEJOCGgwAAAgE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:12.446798 2026] [security2:error] [pid 643253:tid 643375] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/cong.php"] [unique_id "amuDHMjqbtjBYzqM1uYrHQAARHg"]
[Thu Jul 30 12:00:12.523101 2026] [security2:error] [pid 642360:tid 642576] [client 64.31.3.126:53313] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuDGpSUkh3e5AhEJOCGaQAAAgM"], referer: https://globalmarks.pk/2023/08/28/parent-guide-babys-first-tooth-and-what-parents-must-know/#comment-2269
[Thu Jul 30 12:00:12.535022 2026] [security2:error] [pid 642360:tid 642583] [client 20.91.199.21:52683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/03a005685d.php"] [unique_id "amuDHJSUkh3e5AhEJOCGhwAAAew"]
[Thu Jul 30 12:00:12.580431 2026] [security2:error] [pid 643253:tid 643502] [client 2a03:2880:f800:1:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDG8jqbtjBYzqM1uYrFwAAdnU"]
[Thu Jul 30 12:00:12.621754 2026] [security2:error] [pid 643253:tid 643400] [client 143.244.57.82:52674] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.yaz.gzj.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuDHMjqbtjBYzqM1uYrHgAAABA"]
[Thu Jul 30 12:00:12.694541 2026] [security2:error] [pid 643253:tid 643376] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/file4.php"] [unique_id "amuDHMjqbtjBYzqM1uYrHwAAfnk"]
[Thu Jul 30 12:00:12.911332 2026] [security2:error] [pid 643253:tid 643466] [client 143.244.57.82:52682] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.yaz.gzj.temporary.site"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuDHMjqbtjBYzqM1uYrIAAAAFI"]
[Thu Jul 30 12:00:12.973018 2026] [security2:error] [pid 643253:tid 643377] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/flower.php"] [unique_id "amuDHMjqbtjBYzqM1uYrIQAAWno"]
[Thu Jul 30 12:00:13.203606 2026] [security2:error] [pid 643253:tid 643386] [client 143.244.57.82:52686] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.yaz.gzj.temporary.site"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuDHcjqbtjBYzqM1uYrIwAAAAI"]
[Thu Jul 30 12:00:13.310337 2026] [security2:error] [pid 642360:tid 642519] [client 114.119.159.236:61267] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "alseermarine.com"] [uri "/investor-relations-2/share-series"] [unique_id "amuDHZSUkh3e5AhEJOCGlAAAAaw"], referer: https://alseermarine.com/investor-relations/fact-sheet
[Thu Jul 30 12:00:13.438964 2026] [security2:error] [pid 643253:tid 643378] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/form.php"] [unique_id "amuDHcjqbtjBYzqM1uYrJAAAA3s"]
[Thu Jul 30 12:00:13.456229 2026] [security2:error] [pid 642360:tid 642610] [client 2a03:2880:f800:32:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDHJSUkh3e5AhEJOCGjgACB3I"]
[Thu Jul 30 12:00:13.480377 2026] [security2:error] [pid 643253:tid 643441] [client 143.244.57.82:52698] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.yaz.gzj.temporary.site"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuDHcjqbtjBYzqM1uYrJQAAADk"]
[Thu Jul 30 12:00:13.734681 2026] [security2:error] [pid 643253:tid 643379] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/gecko.php"] [unique_id "amuDHcjqbtjBYzqM1uYrJgAAXHw"]
[Thu Jul 30 12:00:13.746522 2026] [security2:error] [pid 642360:tid 642596] [client 191.232.199.39:6242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/classsmtps.php"] [unique_id "amuDHZSUkh3e5AhEJOCGmwAAAfk"]
[Thu Jul 30 12:00:13.784698 2026] [security2:error] [pid 642360:tid 642571] [client 143.244.57.82:52708] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.yaz.gzj.temporary.site"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuDHZSUkh3e5AhEJOCGnAAAAeA"]
[Thu Jul 30 12:00:14.020657 2026] [security2:error] [pid 643253:tid 643382] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/kyami.php"] [unique_id "amuDHsjqbtjBYzqM1uYrJwAAX38"]
[Thu Jul 30 12:00:14.096104 2026] [security2:error] [pid 642360:tid 642506] [client 143.244.57.82:52718] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.yaz.gzj.temporary.site"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuDHpSUkh3e5AhEJOCGowAAAZ8"]
[Thu Jul 30 12:00:14.180912 2026] [security2:error] [pid 643253:tid 643481] [client 20.91.199.21:55335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/403.php"] [unique_id "amuDHsjqbtjBYzqM1uYrKAAAAGE"]
[Thu Jul 30 12:00:14.267842 2026] [security2:error] [pid 643253:tid 643380] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/manager.php"] [unique_id "amuDHsjqbtjBYzqM1uYrKQAAJX0"]
[Thu Jul 30 12:00:14.375436 2026] [security2:error] [pid 642360:tid 642490] [client 143.244.57.82:52732] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.yaz.gzj.temporary.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuDHpSUkh3e5AhEJOCGpwAAAY8"]
[Thu Jul 30 12:00:14.559123 2026] [security2:error] [pid 643253:tid 643255] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/mari.php"] [unique_id "amuDHsjqbtjBYzqM1uYrKgAAYgA"]
[Thu Jul 30 12:00:14.678373 2026] [security2:error] [pid 642360:tid 642594] [client 143.244.57.82:52740] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.yaz.gzj.temporary.site"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuDHpSUkh3e5AhEJOCGqwAAAfc"]
[Thu Jul 30 12:00:14.758824 2026] [security2:error] [pid 642360:tid 642509] [client 172.202.44.182:45089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/content.php"] [unique_id "amuDHpSUkh3e5AhEJOCGrwAAAaI"]
[Thu Jul 30 12:00:14.806269 2026] [security2:error] [pid 643253:tid 643381] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/nc4.php"] [unique_id "amuDHsjqbtjBYzqM1uYrKwAAO34"]
[Thu Jul 30 12:00:14.947754 2026] [security2:error] [pid 643253:tid 643458] [client 191.232.199.39:58491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-blog-header.php"] [unique_id "amuDHsjqbtjBYzqM1uYrLAAAAEo"]
[Thu Jul 30 12:00:14.951732 2026] [security2:error] [pid 643253:tid 643403] [client 20.91.199.21:56803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/404.php"] [unique_id "amuDHsjqbtjBYzqM1uYrLQAAABM"]
[Thu Jul 30 12:00:14.969622 2026] [security2:error] [pid 643253:tid 643428] [client 143.244.57.82:52746] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.yaz.gzj.temporary.site"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuDHsjqbtjBYzqM1uYrLgAAACw"]
[Thu Jul 30 12:00:15.140355 2026] [cgid:error] [pid 643253:tid 643256] [remote 172.202.44.182:0] AH01265: stderr from /home2/xncnyxte/public_html/website_32476423/cgi-bin/: attempt to invoke directory as script
[Thu Jul 30 12:00:15.260875 2026] [security2:error] [pid 642360:tid 642587] [client 143.244.57.82:52750] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.yaz.gzj.temporary.site"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuDH5SUkh3e5AhEJOCGtgAAAfA"]
[Thu Jul 30 12:00:15.384053 2026] [core:notice] [pid 642360:tid 642497] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:15.556647 2026] [security2:error] [pid 642360:tid 642493] [client 2a03:2880:f800:2a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDHpSUkh3e5AhEJOCGsAABkg4"]
[Thu Jul 30 12:00:15.643143 2026] [security2:error] [pid 643253:tid 643451] [client 20.91.199.21:56564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/aa.php"] [unique_id "amuDH8jqbtjBYzqM1uYrMAAAAEM"]
[Thu Jul 30 12:00:15.647558 2026] [security2:error] [pid 642360:tid 642560] [client 114.119.154.215:59833] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2023/01/200.webp"] [unique_id "amuDH5SUkh3e5AhEJOCGvgAAAdU"], referer: https://portal9nordeste.com.br/mulher-e-crianca-morrem-apos-desabamento-de-estrutura-de-concreto-em-cajazeiras-nordeste-1/
[Thu Jul 30 12:00:15.995463 2026] [security2:error] [pid 642360:tid 642616] [client 172.202.44.182:50533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/upfile.php"] [unique_id "amuDH5SUkh3e5AhEJOCGwgAAAg0"]
[Thu Jul 30 12:00:16.144898 2026] [security2:error] [pid 642360:tid 642541] [client 191.232.199.39:58422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-trackback.php"] [unique_id "amuDIJSUkh3e5AhEJOCGxgAAAcI"]
[Thu Jul 30 12:00:16.372804 2026] [security2:error] [pid 643253:tid 643431] [client 20.91.199.21:56569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/aafewc0k.php"] [unique_id "amuDIMjqbtjBYzqM1uYrMwAAAC8"]
[Thu Jul 30 12:00:16.632685 2026] [security2:error] [pid 643253:tid 643498] [client 50.6.43.217:47168] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cmplboard.com"] [uri "/public/tools/reg_refetch.php"] [unique_id "amuDEcjqbtjBYzqM1uYqyAAAAHI"]
[Thu Jul 30 12:00:17.532529 2026] [security2:error] [pid 642360:tid 642594] [client 191.232.199.39:58459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-signup.php"] [unique_id "amuDIZSUkh3e5AhEJOCG5gAAAfc"]
[Thu Jul 30 12:00:17.735883 2026] [security2:error] [pid 642360:tid 642599] [client 172.202.44.182:50515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/bypass.php"] [unique_id "amuDIZSUkh3e5AhEJOCG7AAAAfw"]
[Thu Jul 30 12:00:18.049157 2026] [security2:error] [pid 642360:tid 642613] [client 20.215.191.139:17568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/content.php"] [unique_id "amuDIpSUkh3e5AhEJOCG-AAAAgo"]
[Thu Jul 30 12:00:18.168834 2026] [core:notice] [pid 642360:tid 642567] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:18.172821 2026] [security2:error] [pid 642360:tid 642567] [client 103.215.74.26:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDIpSUkh3e5AhEJOCG-QAAAdw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:18.299737 2026] [security2:error] [pid 642360:tid 642585] [client 176.241.66.87:50238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDIpSUkh3e5AhEJOCG_QAAAe4"]
[Thu Jul 30 12:00:18.299857 2026] [security2:error] [pid 642360:tid 642585] [client 176.241.66.87:50238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDIpSUkh3e5AhEJOCG_QAAAe4"]
[Thu Jul 30 12:00:18.670406 2026] [security2:error] [pid 642360:tid 642577] [client 37.120.155.179:54164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.155.120.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuDIpSUkh3e5AhEJOCHAQAAAeY"]
[Thu Jul 30 12:00:18.670513 2026] [security2:error] [pid 642360:tid 642577] [client 37.120.155.179:54164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuDIpSUkh3e5AhEJOCHAQAAAeY"]
[Thu Jul 30 12:00:18.897622 2026] [core:notice] [pid 642360:tid 642596] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:18.902450 2026] [security2:error] [pid 642360:tid 642596] [client 103.215.74.26:60084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDIpSUkh3e5AhEJOCHBAAAAfk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:18.959141 2026] [security2:error] [pid 642360:tid 642519] [client 191.232.199.39:58427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-comments-post.php"] [unique_id "amuDIpSUkh3e5AhEJOCHBQAAAaw"]
[Thu Jul 30 12:00:18.985940 2026] [security2:error] [pid 642360:tid 642569] [client 20.91.199.21:52727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/abcd.php"] [unique_id "amuDIpSUkh3e5AhEJOCHBgAAAd4"]
[Thu Jul 30 12:00:19.306590 2026] [security2:error] [pid 642360:tid 642606] [client 114.119.128.6:59745] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sv.radiojelli.com"] [uri "/why-i-love-to-watch-football"] [unique_id "amuDI5SUkh3e5AhEJOCHDAAAAgM"], referer: https://sv.radiojelli.com/sitemaps/sitemap0.xml
[Thu Jul 30 12:00:19.647264 2026] [core:notice] [pid 643253:tid 643409] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:19.651442 2026] [security2:error] [pid 643253:tid 643409] [client 103.215.74.26:60092] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDI8jqbtjBYzqM1uYrQAAAABk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:19.892195 2026] [security2:error] [pid 642360:tid 642580] [client 20.91.199.21:36543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/about.php"] [unique_id "amuDI5SUkh3e5AhEJOCHGwAAAek"]
[Thu Jul 30 12:00:20.398519 2026] [core:notice] [pid 642360:tid 642565] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:20.404008 2026] [security2:error] [pid 642360:tid 642565] [client 103.215.74.26:60096] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDJJSUkh3e5AhEJOCHHwAAAdo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:20.438141 2026] [security2:error] [pid 642360:tid 642597] [client 172.202.44.182:45101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/updates.php"] [unique_id "amuDJJSUkh3e5AhEJOCHJAAAAfo"]
[Thu Jul 30 12:00:20.502723 2026] [security2:error] [pid 643253:tid 643410] [client 191.232.199.39:58455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-mail.php"] [unique_id "amuDJMjqbtjBYzqM1uYrRAAAABo"]
[Thu Jul 30 12:00:20.843134 2026] [security2:error] [pid 643253:tid 643394] [client 20.91.199.21:56800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/admin.php"] [unique_id "amuDJMjqbtjBYzqM1uYrRgAAAAo"]
[Thu Jul 30 12:00:21.138958 2026] [core:notice] [pid 643253:tid 643505] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:21.142958 2026] [security2:error] [pid 643253:tid 643505] [client 103.215.74.26:60100] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDJcjqbtjBYzqM1uYrSAAAAHk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:21.496985 2026] [security2:error] [pid 642360:tid 642585] [client 20.91.199.21:56521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/adminfuns.php"] [unique_id "amuDJZSUkh3e5AhEJOCHNQAAAe4"]
[Thu Jul 30 12:00:21.823278 2026] [security2:error] [pid 643253:tid 643489] [client 191.232.199.39:6257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-activate.php"] [unique_id "amuDJcjqbtjBYzqM1uYrSQAAAGk"]
[Thu Jul 30 12:00:21.881739 2026] [core:notice] [pid 643253:tid 643499] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:21.885788 2026] [security2:error] [pid 643253:tid 643499] [client 103.215.74.26:60112] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDJcjqbtjBYzqM1uYrSgAAAHM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:22.446654 2026] [security2:error] [pid 642360:tid 642573] [client 20.91.199.21:52704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/albin.php"] [unique_id "amuDJpSUkh3e5AhEJOCHPwAAAeI"]
[Thu Jul 30 12:00:22.607695 2026] [core:notice] [pid 642360:tid 642603] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:22.611828 2026] [security2:error] [pid 642360:tid 642603] [client 103.215.74.26:60122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDJpSUkh3e5AhEJOCHQwAAAgA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:22.696539 2026] [security2:error] [pid 642360:tid 642557] [client 20.215.191.139:54713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/13.php"] [unique_id "amuDJpSUkh3e5AhEJOCHSAAAAdI"]
[Thu Jul 30 12:00:22.796021 2026] [security2:error] [pid 642360:tid 642553] [client 114.119.138.27:52087] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.carnetdeshopping.com"] [uri "/un-long-week-end-a-stockholm-norrmalm-et-ostermalm/stockholm-norrmalm_5/"] [unique_id "amuDJpSUkh3e5AhEJOCHSwAAAc4"], referer: https://www.carnetdeshopping.com/un-long-week-end-a-stockholm-norrmalm-et-ostermalm/stockholm-norrmalm_5/
[Thu Jul 30 12:00:23.018755 2026] [security2:error] [pid 643253:tid 643487] [client 20.215.191.139:40221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/content.php.suspected"] [unique_id "amuDJ8jqbtjBYzqM1uYrTgAAAGc"]
[Thu Jul 30 12:00:23.243098 2026] [security2:error] [pid 642360:tid 642517] [client 191.232.199.39:6270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/post.php"] [unique_id "amuDJ5SUkh3e5AhEJOCHUgAAAao"]
[Thu Jul 30 12:00:23.344031 2026] [core:notice] [pid 642360:tid 642604] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:23.348263 2026] [security2:error] [pid 642360:tid 642604] [client 103.215.74.26:65446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDJ5SUkh3e5AhEJOCHVQAAAgE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:23.769719 2026] [security2:error] [pid 642360:tid 642565] [client 20.91.199.21:36496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/amfsqvgv.php"] [unique_id "amuDJ5SUkh3e5AhEJOCHWgAAAdo"]
[Thu Jul 30 12:00:24.094161 2026] [core:notice] [pid 642360:tid 642493] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:24.098720 2026] [security2:error] [pid 642360:tid 642493] [client 103.215.74.26:65448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDKJSUkh3e5AhEJOCHYwAAAZI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:24.721515 2026] [security2:error] [pid 643253:tid 643384] [client 191.232.199.39:57755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-2019.php"] [unique_id "amuDKMjqbtjBYzqM1uYrUgAAAAA"]
[Thu Jul 30 12:00:24.824105 2026] [core:notice] [pid 642360:tid 642581] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:24.828448 2026] [security2:error] [pid 642360:tid 642581] [client 103.215.74.26:65450] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDKJSUkh3e5AhEJOCHaQAAAeo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:24.969211 2026] [autoindex:error] [pid 643253:tid 643442] [client 3.228.112.215:64287] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_b1080a24/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:00:25.183347 2026] [security2:error] [pid 643253:tid 643266] [remote 57.141.0.58:59260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuDKMjqbtjBYzqM1uYrUwAAUAs"]
[Thu Jul 30 12:00:25.326446 2026] [security2:error] [pid 642360:tid 642607] [client 20.215.191.139:54620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/ava.php"] [unique_id "amuDKZSUkh3e5AhEJOCHbwAAAgQ"]
[Thu Jul 30 12:00:25.497579 2026] [security2:error] [pid 643253:tid 643483] [client 20.215.191.139:17546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/doc.php"] [unique_id "amuDKcjqbtjBYzqM1uYrWQAAAGM"]
[Thu Jul 30 12:00:25.562673 2026] [core:notice] [pid 642360:tid 642598] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:25.567257 2026] [security2:error] [pid 642360:tid 642598] [client 103.215.74.26:65454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDKZSUkh3e5AhEJOCHcgAAAfs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:25.567987 2026] [security2:error] [pid 643253:tid 643465] [client 20.91.199.21:52697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/ant.php"] [unique_id "amuDKcjqbtjBYzqM1uYrWgAAAFE"]
[Thu Jul 30 12:00:25.639957 2026] [security2:error] [pid 642360:tid 642454] [remote 62.81.179.164:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.179.81.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "urbanshiftmovingcompany.one"] [uri "/xmlrpc.php"] [unique_id "amuDKZSUkh3e5AhEJOCHdQACAl0"]
[Thu Jul 30 12:00:25.640124 2026] [security2:error] [pid 642360:tid 642605] [client 62.81.179.164:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "urbanshiftmovingcompany.one"] [uri "/xmlrpc.php"] [unique_id "amuDKZSUkh3e5AhEJOCHdQACAl0"]
[Thu Jul 30 12:00:25.918794 2026] [security2:error] [pid 642360:tid 642606] [client 172.202.44.182:45086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/xmrlpc.php"] [unique_id "amuDKZSUkh3e5AhEJOCHdgAAAgM"]
[Thu Jul 30 12:00:26.235693 2026] [security2:error] [pid 643253:tid 643446] [client 20.215.191.139:40229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/fond.php"] [unique_id "amuDKsjqbtjBYzqM1uYrXQAAAD4"]
[Thu Jul 30 12:00:26.298073 2026] [core:notice] [pid 643253:tid 643510] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:26.302467 2026] [security2:error] [pid 643253:tid 643510] [client 103.215.74.26:65456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDKsjqbtjBYzqM1uYrXgAAAH4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:26.303741 2026] [security2:error] [pid 642360:tid 642569] [client 191.232.199.39:58457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/hoot.php"] [unique_id "amuDKpSUkh3e5AhEJOCHfAAAAd4"]
[Thu Jul 30 12:00:27.020897 2026] [core:notice] [pid 643253:tid 643501] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:27.025163 2026] [security2:error] [pid 643253:tid 643501] [client 103.215.74.26:65468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDK8jqbtjBYzqM1uYrYAAAAHU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:27.433243 2026] [security2:error] [pid 642360:tid 642566] [client 20.215.191.139:17493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/gkiliuew.php"] [unique_id "amuDK5SUkh3e5AhEJOCHiAAAAds"]
[Thu Jul 30 12:00:27.610200 2026] [security2:error] [pid 643253:tid 643386] [client 172.202.44.182:50521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/ae.php"] [unique_id "amuDK8jqbtjBYzqM1uYrYgAAAAI"]
[Thu Jul 30 12:00:27.738944 2026] [core:notice] [pid 643253:tid 643387] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:27.743329 2026] [security2:error] [pid 643253:tid 643387] [client 103.215.74.26:65476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDK8jqbtjBYzqM1uYrYwAAAAM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:27.924675 2026] [security2:error] [pid 642360:tid 642572] [client 191.232.199.39:58446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/log.php"] [unique_id "amuDK5SUkh3e5AhEJOCHkQAAAeE"]
[Thu Jul 30 12:00:27.968917 2026] [core:notice] [pid 642360:tid 642520] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:28.216361 2026] [security2:error] [pid 643253:tid 643509] [client 20.215.191.139:54647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/main.php"] [unique_id "amuDLMjqbtjBYzqM1uYrZQAAAH0"]
[Thu Jul 30 12:00:28.275221 2026] [security2:error] [pid 642360:tid 642560] [client 20.215.191.139:17492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/iR7SzrsOUEP.php"] [unique_id "amuDLJSUkh3e5AhEJOCHnAAAAdU"]
[Thu Jul 30 12:00:28.487056 2026] [core:notice] [pid 642360:tid 642549] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:28.494568 2026] [security2:error] [pid 642360:tid 642549] [client 103.215.74.26:65490] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDLJSUkh3e5AhEJOCHngAAAco"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:28.496529 2026] [security2:error] [pid 643253:tid 643421] [client 20.91.199.21:55309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/appreciators.php"] [unique_id "amuDLMjqbtjBYzqM1uYrZgAAACU"]
[Thu Jul 30 12:00:28.898103 2026] [security2:error] [pid 642360:tid 642610] [client 176.241.66.87:50955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDLJSUkh3e5AhEJOCHowAAAgc"]
[Thu Jul 30 12:00:28.898224 2026] [security2:error] [pid 642360:tid 642610] [client 176.241.66.87:50955] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDLJSUkh3e5AhEJOCHowAAAgc"]
[Thu Jul 30 12:00:29.142215 2026] [security2:error] [pid 642360:tid 642507] [client 172.202.44.182:45077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/moon.php"] [unique_id "amuDLZSUkh3e5AhEJOCHqAAAAaA"]
[Thu Jul 30 12:00:29.237369 2026] [security2:error] [pid 643253:tid 643485] [client 20.215.191.139:40718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/ibkejxnu.php"] [unique_id "amuDLcjqbtjBYzqM1uYrawAAAGU"]
[Thu Jul 30 12:00:29.253422 2026] [security2:error] [pid 643253:tid 643482] [client 74.7.230.36:46444] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuDLMjqbtjBYzqM1uYraAAAYgc"]
[Thu Jul 30 12:00:29.253449 2026] [security2:error] [pid 643253:tid 643482] [client 74.7.230.36:46444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuDLMjqbtjBYzqM1uYraAAAYgc"]
[Thu Jul 30 12:00:29.524309 2026] [security2:error] [pid 643253:tid 643417] [client 191.232.199.39:58398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/bak.php"] [unique_id "amuDLcjqbtjBYzqM1uYrcAAAACE"]
[Thu Jul 30 12:00:29.825048 2026] [security2:error] [pid 642360:tid 642502] [client 20.215.191.139:54634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/wp-file.php"] [unique_id "amuDLZSUkh3e5AhEJOCHswAAAZs"]
[Thu Jul 30 12:00:30.427448 2026] [security2:error] [pid 643253:tid 643507] [client 74.7.230.36:46450] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuDLcjqbtjBYzqM1uYrdQAAewk"], referer: https://www.fireworkskenya.co.ke/robots.txt
[Thu Jul 30 12:00:30.669954 2026] [security2:error] [pid 643253:tid 643429] [client 57.141.0.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuDLsjqbtjBYzqM1uYregAAAC0"]
[Thu Jul 30 12:00:30.767158 2026] [security2:error] [pid 642360:tid 642513] [client 191.232.199.39:58378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/content.php"] [unique_id "amuDLpSUkh3e5AhEJOCHxQAAAaY"]
[Thu Jul 30 12:00:30.850970 2026] [security2:error] [pid 643253:tid 643484] [client 20.91.199.21:55324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/archive.php"] [unique_id "amuDLsjqbtjBYzqM1uYrewAAAGQ"]
[Thu Jul 30 12:00:30.959095 2026] [security2:error] [pid 642360:tid 642602] [client 20.215.191.139:54375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/wp-signin.php"] [unique_id "amuDLpSUkh3e5AhEJOCHyQAAAf8"]
[Thu Jul 30 12:00:31.083857 2026] [core:notice] [pid 643253:tid 643268] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:31.228686 2026] [security2:error] [pid 643253:tid 643494] [client 57.141.0.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuDLcjqbtjBYzqM1uYrcgAAAG4"]
[Thu Jul 30 12:00:31.742643 2026] [security2:error] [pid 643253:tid 643412] [client 114.119.145.116:21487] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kendarikomputer.com"] [uri "/search"] [unique_id "amuDL8jqbtjBYzqM1uYrgQAAABw"], referer: https://www.kendarikomputer.com/search?updated-max=2023-05-30T13%3A43%3A00%2B08%3A00&max-results=10&reverse-paginate=true&m=1
[Thu Jul 30 12:00:31.758022 2026] [core:notice] [pid 643253:tid 643269] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:31.892619 2026] [core:notice] [pid 643253:tid 643419] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:32.094157 2026] [security2:error] [pid 643253:tid 643393] [client 191.232.199.39:48431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/upfile.php"] [unique_id "amuDMMjqbtjBYzqM1uYriAAAAAk"]
[Thu Jul 30 12:00:32.125629 2026] [security2:error] [pid 643253:tid 643270] [remote 47.86.33.52:41370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jgp.fxh.temporary.site"] [uri "/wp-login.php"] [unique_id "amuDMMjqbtjBYzqM1uYriQAAaQ8"]
[Thu Jul 30 12:00:32.845392 2026] [security2:error] [pid 643253:tid 643394] [client 20.91.199.21:52732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/as.php"] [unique_id "amuDMMjqbtjBYzqM1uYrkQAAAAo"]
[Thu Jul 30 12:00:33.099617 2026] [security2:error] [pid 643253:tid 643480] [client 20.215.191.139:17481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/install.php"] [unique_id "amuDMcjqbtjBYzqM1uYrlQAAAGA"]
[Thu Jul 30 12:00:33.181496 2026] [core:notice] [pid 643253:tid 643464] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:33.358834 2026] [security2:error] [pid 643253:tid 643418] [client 191.232.199.39:6308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/bypass.php"] [unique_id "amuDMcjqbtjBYzqM1uYrmQAAACI"]
[Thu Jul 30 12:00:33.915571 2026] [security2:error] [pid 642360:tid 642590] [client 20.215.191.139:54645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/simi.php"] [unique_id "amuDMZSUkh3e5AhEJOCH5QAAAfM"]
[Thu Jul 30 12:00:34.235614 2026] [core:notice] [pid 642360:tid 642501] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:34.242188 2026] [security2:error] [pid 642360:tid 642501] [client 103.215.74.26:37200] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDMpSUkh3e5AhEJOCH6QAAAZo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:34.494217 2026] [security2:error] [pid 642360:tid 642503] [client 20.215.191.139:54648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/wp-conf.php"] [unique_id "amuDMpSUkh3e5AhEJOCH7AAAAZw"]
[Thu Jul 30 12:00:34.551550 2026] [core:notice] [pid 642360:tid 642476] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:34.782931 2026] [security2:error] [pid 642360:tid 642509] [client 20.215.191.139:40739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/lang-load-role.php"] [unique_id "amuDMpSUkh3e5AhEJOCH8QAAAaI"]
[Thu Jul 30 12:00:34.841310 2026] [security2:error] [pid 643253:tid 643472] [client 191.232.199.39:48411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/updates.php"] [unique_id "amuDMsjqbtjBYzqM1uYrngAAAFg"]
[Thu Jul 30 12:00:34.987813 2026] [core:notice] [pid 643253:tid 643509] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:34.993822 2026] [security2:error] [pid 643253:tid 643509] [client 103.215.74.26:37202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDMsjqbtjBYzqM1uYroAAAAH0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:35.231091 2026] [security2:error] [pid 642360:tid 642611] [client 20.91.199.21:56827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/atomlib.php"] [unique_id "amuDM5SUkh3e5AhEJOCH-QAAAgg"]
[Thu Jul 30 12:00:35.460606 2026] [core:notice] [pid 642360:tid 642477] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:35.680418 2026] [core:notice] [pid 643253:tid 643275] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:35.690319 2026] [security2:error] [pid 643253:tid 643426] [client 20.215.191.139:40216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/link.php"] [unique_id "amuDM8jqbtjBYzqM1uYrpgAAACo"]
[Thu Jul 30 12:00:36.034409 2026] [security2:error] [pid 643253:tid 643431] [client 20.91.199.21:55336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/autoload_classmap.php"] [unique_id "amuDNMjqbtjBYzqM1uYrpwAAAC8"]
[Thu Jul 30 12:00:36.321679 2026] [security2:error] [pid 642360:tid 642572] [client 20.215.191.139:54597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/WZGHHra0r3.php"] [unique_id "amuDNJSUkh3e5AhEJOCIBgAAAeE"]
[Thu Jul 30 12:00:36.432254 2026] [security2:error] [pid 643253:tid 643508] [client 191.232.199.39:48166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/xmrlpc.php"] [unique_id "amuDNMjqbtjBYzqM1uYrqQAAAHw"]
[Thu Jul 30 12:00:36.541305 2026] [security2:error] [pid 642360:tid 642616] [client 173.249.217.7:35294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuDNJSUkh3e5AhEJOCIBQAAAg0"]
[Thu Jul 30 12:00:36.541413 2026] [security2:error] [pid 642360:tid 642616] [client 173.249.217.7:35294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuDNJSUkh3e5AhEJOCIBQAAAg0"]
[Thu Jul 30 12:00:36.703276 2026] [security2:error] [pid 642360:tid 642524] [client 34.91.100.7:32768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.cnpinyin.com"] [uri "/"] [unique_id "amuDNJSUkh3e5AhEJOCICwAAAbE"]
[Thu Jul 30 12:00:36.703371 2026] [security2:error] [pid 642360:tid 642524] [client 34.91.100.7:32768] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.cnpinyin.com"] [uri "/"] [unique_id "amuDNJSUkh3e5AhEJOCICwAAAbE"]
[Thu Jul 30 12:00:36.719483 2026] [security2:error] [pid 642360:tid 642545] [client 172.202.44.182:50548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/blog.php"] [unique_id "amuDNJSUkh3e5AhEJOCIDAAAAcY"]
[Thu Jul 30 12:00:36.725192 2026] [security2:error] [pid 642360:tid 642369] [remote 114.119.157.108:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/citationstylelanguage/get/vancouver"] [unique_id "amuDNJSUkh3e5AhEJOCIDQAB2Ag"], referer: https://www.jipkl.com/index.php/JIPKL/article/view/79
[Thu Jul 30 12:00:37.009823 2026] [security2:error] [pid 642360:tid 642510] [client 20.215.191.139:38821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/mar.php"] [unique_id "amuDNZSUkh3e5AhEJOCIEAAAAaM"]
[Thu Jul 30 12:00:37.158862 2026] [security2:error] [pid 643253:tid 643398] [client 20.215.191.139:54601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/bala.php"] [unique_id "amuDNcjqbtjBYzqM1uYrrQAAAA4"]
[Thu Jul 30 12:00:37.209677 2026] [core:notice] [pid 642360:tid 642528] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:37.726675 2026] [security2:error] [pid 643253:tid 643429] [client 114.119.158.251:43011] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "saifalkhaleejest.com"] [uri "/the-importance-of-alloy-steel-chains-in-construction/"] [unique_id "amuDNcjqbtjBYzqM1uYrsAAAAC0"], referer: https://saifalkhaleejest.com/the-importance-of-alloy-steel-chains-in-construction/
[Thu Jul 30 12:00:37.906007 2026] [security2:error] [pid 642360:tid 642491] [client 66.249.73.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuDNZSUkh3e5AhEJOCIHgAAAZA"]
[Thu Jul 30 12:00:38.200204 2026] [security2:error] [pid 643253:tid 643409] [client 191.232.199.39:48402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/ae.php"] [unique_id "amuDNsjqbtjBYzqM1uYrtAAAABk"]
[Thu Jul 30 12:00:38.717663 2026] [security2:error] [pid 642360:tid 642557] [client 20.91.199.21:56798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/bb.php"] [unique_id "amuDNpSUkh3e5AhEJOCIJwAAAdI"]
[Thu Jul 30 12:00:38.888329 2026] [security2:error] [pid 643253:tid 643433] [client 50.6.43.217:57150] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuDNsjqbtjBYzqM1uYrswAAADE"]
[Thu Jul 30 12:00:39.047887 2026] [security2:error] [pid 642360:tid 642538] [client 172.202.44.182:45061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/ini.php"] [unique_id "amuDN5SUkh3e5AhEJOCILAAAAb8"]
[Thu Jul 30 12:00:39.206941 2026] [security2:error] [pid 642360:tid 642511] [client 20.215.191.139:54630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/bk.php"] [unique_id "amuDN5SUkh3e5AhEJOCIMAAAAaQ"]
[Thu Jul 30 12:00:39.589881 2026] [security2:error] [pid 643253:tid 643419] [client 50.6.43.217:57152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuDNsjqbtjBYzqM1uYrvAAAACM"]
[Thu Jul 30 12:00:39.624831 2026] [security2:error] [pid 642360:tid 642615] [client 191.232.199.39:32518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/moon.php"] [unique_id "amuDN5SUkh3e5AhEJOCINgAAAgw"]
[Thu Jul 30 12:00:39.748445 2026] [security2:error] [pid 643253:tid 643477] [client 176.241.66.87:51663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDN8jqbtjBYzqM1uYrvwAAAF0"]
[Thu Jul 30 12:00:39.748600 2026] [security2:error] [pid 643253:tid 643477] [client 176.241.66.87:51663] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDN8jqbtjBYzqM1uYrvwAAAF0"]
[Thu Jul 30 12:00:39.868828 2026] [security2:error] [pid 642360:tid 642583] [client 20.91.199.21:53033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/bnm.php"] [unique_id "amuDN5SUkh3e5AhEJOCIOQAAAew"]
[Thu Jul 30 12:00:40.332439 2026] [security2:error] [pid 642360:tid 642559] [client 172.202.44.182:50520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/admin-ajax.php"] [unique_id "amuDOJSUkh3e5AhEJOCIQQAAAdQ"]
[Thu Jul 30 12:00:40.397622 2026] [core:notice] [pid 642360:tid 642400] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:40.599247 2026] [security2:error] [pid 642360:tid 642584] [client 20.215.191.139:40720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "amuDOJSUkh3e5AhEJOCIRAAAAe0"]
[Thu Jul 30 12:00:40.655963 2026] [security2:error] [pid 643253:tid 643454] [client 20.215.191.139:54625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/ahax.php"] [unique_id "amuDOMjqbtjBYzqM1uYrwwAAAEY"]
[Thu Jul 30 12:00:40.770314 2026] [core:notice] [pid 643253:tid 643497] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:40.774569 2026] [security2:error] [pid 643253:tid 643497] [client 103.215.74.26:37210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDOMjqbtjBYzqM1uYrxQAAAHE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:40.849304 2026] [core:notice] [pid 642360:tid 642372] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:40.906155 2026] [core:notice] [pid 642360:tid 642396] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:40.926557 2026] [security2:error] [pid 643253:tid 643414] [client 191.232.199.39:48178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/blog.php"] [unique_id "amuDOMjqbtjBYzqM1uYrxwAAAB4"]
[Thu Jul 30 12:00:41.297011 2026] [security2:error] [pid 643253:tid 643460] [client 20.91.199.21:36480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/bootstrap.php"] [unique_id "amuDOcjqbtjBYzqM1uYryQAAAEw"]
[Thu Jul 30 12:00:41.394537 2026] [security2:error] [pid 642360:tid 642490] [client 20.215.191.139:38819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "amuDOZSUkh3e5AhEJOCIUwAAAY8"]
[Thu Jul 30 12:00:41.523133 2026] [core:notice] [pid 642360:tid 642534] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:41.527636 2026] [security2:error] [pid 642360:tid 642534] [client 103.215.74.26:37218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDOZSUkh3e5AhEJOCIVAAAAbs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:41.548088 2026] [core:notice] [pid 642360:tid 642480] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:41.553020 2026] [security2:error] [pid 642360:tid 642573] [client 172.202.44.182:50551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/akc.php"] [unique_id "amuDOZSUkh3e5AhEJOCIVgAAAeI"]
[Thu Jul 30 12:00:41.704163 2026] [core:notice] [pid 642360:tid 642423] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:41.961654 2026] [security2:error] [pid 642360:tid 642588] [client 57.141.0.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuDOZSUkh3e5AhEJOCIUAAAAfE"]
[Thu Jul 30 12:00:42.123717 2026] [security2:error] [pid 642360:tid 642432] [remote 74.7.241.60:50116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/article.php"] [unique_id "amuDOpSUkh3e5AhEJOCIYQAB2kc"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/main_image_6a3229a631e84.jpg
[Thu Jul 30 12:00:42.234507 2026] [security2:error] [pid 642360:tid 642594] [client 2a03:2880:f800:1c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDOZSUkh3e5AhEJOCIVwAB9yQ"]
[Thu Jul 30 12:00:42.259167 2026] [security2:error] [pid 642360:tid 642587] [client 191.232.199.39:58924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/ini.php"] [unique_id "amuDOpSUkh3e5AhEJOCIZQAAAfA"]
[Thu Jul 30 12:00:42.282930 2026] [core:notice] [pid 642360:tid 642525] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:42.289163 2026] [security2:error] [pid 642360:tid 642525] [client 103.215.74.26:37234] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDOpSUkh3e5AhEJOCIZwAAAbI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:42.510272 2026] [security2:error] [pid 642360:tid 642493] [client 43.172.195.199:37786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.195.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2011/05/21/vente-privee-de-maillots-de-bain-seafolly/"] [unique_id "amuDOpSUkh3e5AhEJOCIZgAAAZI"]
[Thu Jul 30 12:00:42.622300 2026] [security2:error] [pid 642360:tid 642523] [client 43.173.178.198:42614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.178.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/03/30/on-va-decouvrir-la-collection-pe14-naf-naf-avec-leighton-meester/"] [unique_id "amuDOpSUkh3e5AhEJOCIagAAAbA"]
[Thu Jul 30 12:00:42.649960 2026] [security2:error] [pid 643253:tid 643388] [client 172.202.44.182:50552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/akcc.php"] [unique_id "amuDOsjqbtjBYzqM1uYr0wAAAAQ"]
[Thu Jul 30 12:00:42.767823 2026] [core:notice] [pid 642360:tid 642518] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:42.772447 2026] [security2:error] [pid 642360:tid 642518] [client 43.173.178.253:36810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2011/05/21/vente-privee-de-maillots-de-bain-seafolly/"] [unique_id "amuDOpSUkh3e5AhEJOCIcQAAAas"], referer: https://carnetdeshopping.com/index.php/2011/05/21/vente-privee-de-maillots-de-bain-seafolly/
[Thu Jul 30 12:00:42.809617 2026] [core:notice] [pid 642360:tid 642607] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:42.814642 2026] [security2:error] [pid 642360:tid 642607] [client 43.172.194.135:48396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/03/30/on-va-decouvrir-la-collection-pe14-naf-naf-avec-leighton-meester/"] [unique_id "amuDOpSUkh3e5AhEJOCIdgAAAgQ"], referer: https://carnetdeshopping.com/index.php/2014/03/30/on-va-decouvrir-la-collection-pe14-naf-naf-avec-leighton-meester/?replytocom=1195
[Thu Jul 30 12:00:42.871076 2026] [security2:error] [pid 642360:tid 642615] [client 57.141.0.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuDOpSUkh3e5AhEJOCIaQAAAgw"]
[Thu Jul 30 12:00:43.522063 2026] [security2:error] [pid 642360:tid 642610] [client 191.232.199.39:6475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/admin-ajax.php"] [unique_id "amuDO5SUkh3e5AhEJOCIgAAAAgc"]
[Thu Jul 30 12:00:43.871329 2026] [security2:error] [pid 642360:tid 642563] [client 20.215.191.139:61109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/plugins.php"] [unique_id "amuDO5SUkh3e5AhEJOCIhQAAAdg"]
[Thu Jul 30 12:00:44.002595 2026] [core:notice] [pid 642360:tid 642417] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:44.114094 2026] [security2:error] [pid 642360:tid 642551] [client 20.91.199.21:36495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/buy.php"] [unique_id "amuDPJSUkh3e5AhEJOCIjAAAAcw"]
[Thu Jul 30 12:00:44.387537 2026] [security2:error] [pid 642360:tid 642604] [client 114.119.137.64:53221] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.arabiantourz.com"] [uri "/soldes/homme-superdry-waterpolo-swim-short-bleu-maillots-shorts-de-bain"] [unique_id "amuDPJSUkh3e5AhEJOCIjQAAAgE"], referer: https://www.arabiantourz.com/soldes/homme-superdry-waterpolo-swim-short-bleu-maillots-shorts-de-bain
[Thu Jul 30 12:00:44.566022 2026] [core:notice] [pid 642360:tid 642378] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:44.581222 2026] [security2:error] [pid 642360:tid 642500] [client 172.202.44.182:50508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/asasx.php"] [unique_id "amuDPJSUkh3e5AhEJOCIlwAAAZk"]
[Thu Jul 30 12:00:44.815147 2026] [security2:error] [pid 643253:tid 643434] [client 191.232.199.39:7017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/akc.php"] [unique_id "amuDPMjqbtjBYzqM1uYr1wAAADI"]
[Thu Jul 30 12:00:44.974880 2026] [security2:error] [pid 642360:tid 642573] [client 20.215.191.139:38828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/post.php"] [unique_id "amuDPJSUkh3e5AhEJOCInAAAAeI"]
[Thu Jul 30 12:00:45.657520 2026] [security2:error] [pid 642360:tid 642611] [client 20.91.199.21:56515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/chosen.php"] [unique_id "amuDPZSUkh3e5AhEJOCIqAAAAgg"]
[Thu Jul 30 12:00:45.841676 2026] [security2:error] [pid 643253:tid 643404] [client 20.215.191.139:40253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/shell.php"] [unique_id "amuDPcjqbtjBYzqM1uYr3gAAABQ"]
[Thu Jul 30 12:00:46.241857 2026] [security2:error] [pid 643253:tid 643491] [client 191.232.199.39:7039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/akcc.php"] [unique_id "amuDPsjqbtjBYzqM1uYr3wAAAGs"]
[Thu Jul 30 12:00:46.264281 2026] [security2:error] [pid 642360:tid 642533] [client 114.119.140.175:57853] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kingstarenterprises.com"] [uri "/product-category/gym-club-accessories/weight-lifting-half-finger-gloves/"] [unique_id "amuDPpSUkh3e5AhEJOCIrwAAAbo"], referer: http://www.kingstarenterprises.com/
[Thu Jul 30 12:00:46.364283 2026] [security2:error] [pid 643253:tid 643467] [client 57.141.0.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuDPcjqbtjBYzqM1uYr3QAAAFM"]
[Thu Jul 30 12:00:46.406536 2026] [security2:error] [pid 642360:tid 642515] [client 172.202.44.182:39201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/axx.php"] [unique_id "amuDPpSUkh3e5AhEJOCIsQAAAag"]
[Thu Jul 30 12:00:46.528507 2026] [security2:error] [pid 643253:tid 643413] [client 20.215.191.139:40218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/ssl.php"] [unique_id "amuDPsjqbtjBYzqM1uYr4AAAAB0"]
[Thu Jul 30 12:00:47.388911 2026] [security2:error] [pid 643253:tid 643426] [client 172.202.44.182:50523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/berax.php"] [unique_id "amuDP8jqbtjBYzqM1uYr4gAAACo"]
[Thu Jul 30 12:00:47.461913 2026] [security2:error] [pid 642360:tid 642609] [client 20.91.199.21:49887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/class-wp-image.php"] [unique_id "amuDP5SUkh3e5AhEJOCIvwAAAgY"]
[Thu Jul 30 12:00:47.508854 2026] [security2:error] [pid 642360:tid 642580] [client 213.152.161.219:38406] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuDP5SUkh3e5AhEJOCIwAAAAek"]
[Thu Jul 30 12:00:47.508943 2026] [security2:error] [pid 642360:tid 642580] [client 213.152.161.219:38406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuDP5SUkh3e5AhEJOCIwAAAAek"]
[Thu Jul 30 12:00:47.642415 2026] [security2:error] [pid 642360:tid 642563] [client 191.232.199.39:6476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/asasx.php"] [unique_id "amuDP5SUkh3e5AhEJOCIyAAAAdg"]
[Thu Jul 30 12:00:47.646427 2026] [security2:error] [pid 642360:tid 642517] [client 20.215.191.139:61075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/sx.php"] [unique_id "amuDP5SUkh3e5AhEJOCIyQAAAao"]
[Thu Jul 30 12:00:47.786157 2026] [security2:error] [pid 642360:tid 642544] [client 213.152.187.225:42954] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuDP5SUkh3e5AhEJOCIwQAAAcU"]
[Thu Jul 30 12:00:47.786307 2026] [security2:error] [pid 642360:tid 642544] [client 213.152.187.225:42954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuDP5SUkh3e5AhEJOCIwQAAAcU"]
[Thu Jul 30 12:00:48.023582 2026] [core:notice] [pid 643253:tid 643506] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:48.030871 2026] [security2:error] [pid 643253:tid 643506] [client 103.215.74.26:48066] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDQMjqbtjBYzqM1uYr4wAAAHo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:48.135147 2026] [security2:error] [pid 642360:tid 642531] [client 114.119.131.200:24159] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabiandubaisafari.com"] [uri "/docs/5cfb7b-portsmouth-kit-20/5cfb7b-who-wrote-the-original-valerie-song"] [unique_id "amuDQJSUkh3e5AhEJOCI0QAAAbg"], referer: https://arabiandubaisafari.com/docs/5cfb7b-portsmouth-kit-20/5cfb7b-who-wrote-the-original-valerie-song
[Thu Jul 30 12:00:48.200905 2026] [security2:error] [pid 642360:tid 642558] [client 20.91.199.21:53048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/classsmtps.php"] [unique_id "amuDQJSUkh3e5AhEJOCI1QAAAdM"]
[Thu Jul 30 12:00:48.364750 2026] [security2:error] [pid 642360:tid 642494] [client 172.202.44.182:50506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/build.php"] [unique_id "amuDQJSUkh3e5AhEJOCI1gAAAZM"]
[Thu Jul 30 12:00:48.772649 2026] [core:notice] [pid 643253:tid 643511] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:48.776670 2026] [security2:error] [pid 643253:tid 643511] [client 103.215.74.26:48076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDQMjqbtjBYzqM1uYr5QAAAH8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:48.796480 2026] [security2:error] [pid 642360:tid 642591] [client 114.119.158.112:63269] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabian-tours.com"] [uri "/site/michael-scholar-56216b"] [unique_id "amuDQJSUkh3e5AhEJOCI3wAAAfQ"], referer: https://arabian-tours.com/site/sweeney_sydney-instagram-56216b
[Thu Jul 30 12:00:48.912547 2026] [security2:error] [pid 642360:tid 642572] [client 20.91.199.21:36522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/classwithtostring.php"] [unique_id "amuDQJSUkh3e5AhEJOCI4AAAAeE"]
[Thu Jul 30 12:00:49.097949 2026] [security2:error] [pid 642360:tid 642543] [client 191.232.199.39:58895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/axx.php"] [unique_id "amuDQZSUkh3e5AhEJOCI4wAAAcQ"]
[Thu Jul 30 12:00:49.505873 2026] [core:notice] [pid 642360:tid 642498] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:49.509881 2026] [security2:error] [pid 642360:tid 642498] [client 103.215.74.26:48090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "767"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDQZSUkh3e5AhEJOCI7AAAAZc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:50.250149 2026] [security2:error] [pid 642360:tid 642578] [client 176.241.66.87:52670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDQpSUkh3e5AhEJOCI9wAAAec"]
[Thu Jul 30 12:00:50.250354 2026] [security2:error] [pid 642360:tid 642578] [client 176.241.66.87:52670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDQpSUkh3e5AhEJOCI9wAAAec"]
[Thu Jul 30 12:00:50.280536 2026] [core:notice] [pid 642360:tid 642516] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:50.287140 2026] [security2:error] [pid 642360:tid 642516] [client 103.215.74.26:48104] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDQpSUkh3e5AhEJOCI-AAAAak"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:50.338010 2026] [security2:error] [pid 642360:tid 642491] [client 191.232.199.39:6500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/berax.php"] [unique_id "amuDQpSUkh3e5AhEJOCI-QAAAZA"]
[Thu Jul 30 12:00:50.343275 2026] [security2:error] [pid 642360:tid 642595] [client 172.202.44.182:45076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/buy.php"] [unique_id "amuDQpSUkh3e5AhEJOCI-gAAAfg"]
[Thu Jul 30 12:00:50.877803 2026] [security2:error] [pid 642360:tid 642610] [client 20.215.191.139:40949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/themes.php"] [unique_id "amuDQpSUkh3e5AhEJOCJAwAAAgc"]
[Thu Jul 30 12:00:51.024400 2026] [core:notice] [pid 642360:tid 642530] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:51.028578 2026] [security2:error] [pid 642360:tid 642530] [client 103.215.74.26:48120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "780"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDQ5SUkh3e5AhEJOCJBwAAAbc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:51.164545 2026] [core:error] [pid 642360:tid 642446] [remote 74.7.175.142:40992] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:00:51.164577 2026] [core:error] [pid 642360:tid 642446] [remote 74.7.175.142:40992] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:00:51.164803 2026] [security2:error] [pid 642360:tid 642565] [client 74.7.175.142:40992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "website-8880a99c.lld.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuDQ5SUkh3e5AhEJOCJCAAB2lU"]
[Thu Jul 30 12:00:51.251318 2026] [security2:error] [pid 642360:tid 642587] [client 172.202.44.182:45099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/checkbox.php"] [unique_id "amuDQ5SUkh3e5AhEJOCJDAAAAfA"]
[Thu Jul 30 12:00:51.641119 2026] [security2:error] [pid 642360:tid 642510] [client 191.232.199.39:58834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/build.php"] [unique_id "amuDQ5SUkh3e5AhEJOCJEAAAAaM"]
[Thu Jul 30 12:00:51.733721 2026] [core:notice] [pid 642360:tid 642568] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:51.742726 2026] [core:notice] [pid 642360:tid 642494] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:51.746489 2026] [security2:error] [pid 642360:tid 642494] [client 103.215.74.26:48130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDQ5SUkh3e5AhEJOCJFQAAAZM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:51.781743 2026] [security2:error] [pid 642360:tid 642461] [remote 217.182.128.41:42678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.xfx.hfl.temporary.site"] [uri "/wp-login.php"] [unique_id "amuDQ5SUkh3e5AhEJOCJFgAB6GQ"]
[Thu Jul 30 12:00:52.302897 2026] [security2:error] [pid 642360:tid 642603] [client 74.7.244.54:57458] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "msz.udi.temporary.site"] [uri "/index.php"] [unique_id "amuDQpSUkh3e5AhEJOCI9gACAAE"]
[Thu Jul 30 12:00:52.399700 2026] [security2:error] [pid 642360:tid 642529] [client 20.215.191.139:38800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/worksec.php"] [unique_id "amuDRJSUkh3e5AhEJOCJHwAAAbY"]
[Thu Jul 30 12:00:52.458372 2026] [security2:error] [pid 642360:tid 642582] [client 20.91.199.21:49863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/config.php"] [unique_id "amuDRJSUkh3e5AhEJOCJIAAAAes"]
[Thu Jul 30 12:00:52.483649 2026] [core:notice] [pid 642360:tid 642590] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:52.487780 2026] [security2:error] [pid 642360:tid 642590] [client 103.215.74.26:48134] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDRJSUkh3e5AhEJOCJIQAAAfM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:52.637557 2026] [security2:error] [pid 642360:tid 642611] [client 172.202.44.182:50546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/cong.php"] [unique_id "amuDRJSUkh3e5AhEJOCJJAAAAgg"]
[Thu Jul 30 12:00:53.212745 2026] [core:notice] [pid 642360:tid 642501] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:53.219193 2026] [security2:error] [pid 642360:tid 642501] [client 103.215.74.26:34820] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDRZSUkh3e5AhEJOCJMAAAAZo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:53.341519 2026] [security2:error] [pid 642360:tid 642507] [client 191.232.199.39:58850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/buy.php"] [unique_id "amuDRZSUkh3e5AhEJOCJNAAAAaA"]
[Thu Jul 30 12:00:53.377717 2026] [security2:error] [pid 643253:tid 643416] [client 20.91.199.21:53468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/core.php"] [unique_id "amuDRcjqbtjBYzqM1uYr7QAAACA"]
[Thu Jul 30 12:00:53.819195 2026] [security2:error] [pid 642360:tid 642544] [client 193.9.48.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuDRZSUkh3e5AhEJOCJOwAAAcU"], referer: https://cnpinyin.com/register
[Thu Jul 30 12:00:53.894829 2026] [security2:error] [pid 642360:tid 642563] [client 172.202.44.182:45070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/file4.php"] [unique_id "amuDRZSUkh3e5AhEJOCJPwAAAdg"]
[Thu Jul 30 12:00:53.949878 2026] [core:notice] [pid 643253:tid 643475] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:53.954377 2026] [security2:error] [pid 643253:tid 643475] [client 103.215.74.26:34832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDRcjqbtjBYzqM1uYr7gAAAFs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:54.592769 2026] [security2:error] [pid 643253:tid 643463] [client 20.215.191.139:40725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/wp-admin/install.php"] [unique_id "amuDRsjqbtjBYzqM1uYr8AAAAE8"]
[Thu Jul 30 12:00:54.671854 2026] [core:notice] [pid 642360:tid 642566] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:54.675810 2026] [security2:error] [pid 642360:tid 642566] [client 103.215.74.26:34834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDRpSUkh3e5AhEJOCJSAAAAds"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:54.729862 2026] [security2:error] [pid 643253:tid 643505] [client 191.232.199.39:58848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/checkbox.php"] [unique_id "amuDRsjqbtjBYzqM1uYr8QAAAHk"]
[Thu Jul 30 12:00:55.022624 2026] [security2:error] [pid 642360:tid 642614] [client 20.91.199.21:49866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/css.php"] [unique_id "amuDR5SUkh3e5AhEJOCJSwAAAgs"]
[Thu Jul 30 12:00:55.060782 2026] [security2:error] [pid 642360:tid 642581] [client 172.202.44.182:45073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/flower.php"] [unique_id "amuDR5SUkh3e5AhEJOCJTAAAAeo"]
[Thu Jul 30 12:00:55.426779 2026] [core:notice] [pid 643253:tid 643419] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:55.432871 2026] [security2:error] [pid 643253:tid 643419] [client 103.215.74.26:34840] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDR8jqbtjBYzqM1uYr9gAAACM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:56.127896 2026] [security2:error] [pid 642360:tid 642605] [client 191.232.199.39:48220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/cong.php"] [unique_id "amuDSJSUkh3e5AhEJOCJVgAAAgI"]
[Thu Jul 30 12:00:56.169408 2026] [core:notice] [pid 642360:tid 642533] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:56.176381 2026] [security2:error] [pid 642360:tid 642533] [client 103.215.74.26:34852] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDSJSUkh3e5AhEJOCJWgAAAbo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:56.332310 2026] [security2:error] [pid 642360:tid 642571] [client 172.202.44.182:50505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/form.php"] [unique_id "amuDSJSUkh3e5AhEJOCJWwAAAeA"]
[Thu Jul 30 12:00:56.363309 2026] [security2:error] [pid 642360:tid 642532] [client 114.119.139.115:34997] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/shop/page/40/"] [unique_id "amuDSJSUkh3e5AhEJOCJXAAAAbk"], referer: https://kicksity.com/shop/?min_price=140&max_price=280&filtering=1&filter_product_cat=166%2C231%2C146%2C186%2C157
[Thu Jul 30 12:00:56.416036 2026] [security2:error] [pid 643253:tid 643401] [client 114.119.155.115:39163] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pkf.jo"] [uri "/contact-2/"] [unique_id "amuDSMjqbtjBYzqM1uYr_AAAABE"], referer: http://pkf.jo/Home/News?id=7142&parid=0<id=4
[Thu Jul 30 12:00:56.603953 2026] [security2:error] [pid 643253:tid 643393] [client 172.237.109.114:24572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDSMjqbtjBYzqM1uYr-gAAAAk"]
[Thu Jul 30 12:00:56.944662 2026] [core:notice] [pid 643253:tid 643414] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:56.949930 2026] [security2:error] [pid 643253:tid 643414] [client 103.215.74.26:34864] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDSMjqbtjBYzqM1uYsAAAAAB4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:57.286675 2026] [security2:error] [pid 642360:tid 642572] [client 20.215.191.139:40901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "amuDSZSUkh3e5AhEJOCJYQAAAeE"]
[Thu Jul 30 12:00:57.510771 2026] [security2:error] [pid 643253:tid 643452] [client 191.232.199.39:58852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/file4.php"] [unique_id "amuDScjqbtjBYzqM1uYsBQAAAEQ"]
[Thu Jul 30 12:00:57.604774 2026] [security2:error] [pid 642360:tid 642544] [client 51.68.111.240:34593] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "womenclothingbox.com"] [uri "/robots.txt"] [unique_id "amuDSZSUkh3e5AhEJOCJegAAAcU"]
[Thu Jul 30 12:00:57.604961 2026] [security2:error] [pid 642360:tid 642544] [client 51.68.111.240:34593] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "womenclothingbox.com"] [uri "/robots.txt"] [unique_id "amuDSZSUkh3e5AhEJOCJegAAAcU"]
[Thu Jul 30 12:00:57.715815 2026] [core:notice] [pid 642360:tid 642509] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:57.720230 2026] [security2:error] [pid 642360:tid 642509] [client 103.215.74.26:34872] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDSZSUkh3e5AhEJOCJewAAAaI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:57.722611 2026] [security2:error] [pid 642360:tid 642385] [remote 57.141.0.71:49578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/491057609/feed/rss2/"] [unique_id "amuDSZSUkh3e5AhEJOCJfAABlRg"]
[Thu Jul 30 12:00:58.107465 2026] [security2:error] [pid 643253:tid 643483] [client 250.49.135.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuDSMjqbtjBYzqM1uYr_wAAYx8"]
[Thu Jul 30 12:00:58.322114 2026] [security2:error] [pid 643253:tid 643442] [client 172.237.109.114:60471] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDScjqbtjBYzqM1uYsAQAAADo"]
[Thu Jul 30 12:00:58.422185 2026] [security2:error] [pid 643253:tid 643418] [client 172.237.109.114:61223] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDScjqbtjBYzqM1uYsAgAAACI"]
[Thu Jul 30 12:00:58.455209 2026] [security2:error] [pid 642360:tid 642534] [client 172.237.109.114:1575] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDSZSUkh3e5AhEJOCJbQAAAbs"]
[Thu Jul 30 12:00:58.458096 2026] [security2:error] [pid 642360:tid 642580] [client 172.237.109.114:20232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDSZSUkh3e5AhEJOCJaAAAAek"]
[Thu Jul 30 12:00:58.472353 2026] [security2:error] [pid 642360:tid 642514] [client 172.237.109.114:59009] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDSZSUkh3e5AhEJOCJZgAAAac"]
[Thu Jul 30 12:00:58.475235 2026] [security2:error] [pid 642360:tid 642499] [client 172.237.109.114:55705] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDSZSUkh3e5AhEJOCJZwAAAZg"]
[Thu Jul 30 12:00:58.477971 2026] [security2:error] [pid 642360:tid 642561] [client 172.237.109.114:9397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDSZSUkh3e5AhEJOCJZQAAAdY"]
[Thu Jul 30 12:00:58.485138 2026] [security2:error] [pid 643253:tid 643502] [client 172.237.109.114:63315] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDScjqbtjBYzqM1uYsAwAAAHY"]
[Thu Jul 30 12:00:58.488724 2026] [security2:error] [pid 642360:tid 642521] [client 172.237.109.114:60207] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDSZSUkh3e5AhEJOCJagAAAa4"]
[Thu Jul 30 12:00:58.493100 2026] [security2:error] [pid 642360:tid 642609] [client 172.237.109.114:60984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDSZSUkh3e5AhEJOCJaQAAAgY"]
[Thu Jul 30 12:00:58.501499 2026] [security2:error] [pid 642360:tid 642551] [client 172.237.109.114:55185] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDSZSUkh3e5AhEJOCJawAAAcw"]
[Thu Jul 30 12:00:58.505275 2026] [security2:error] [pid 642360:tid 642516] [client 172.237.109.114:59288] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDSZSUkh3e5AhEJOCJbgAAAak"]
[Thu Jul 30 12:00:58.519641 2026] [security2:error] [pid 642360:tid 642578] [client 172.237.109.114:16753] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDSZSUkh3e5AhEJOCJbAAAAec"]
[Thu Jul 30 12:00:58.530405 2026] [security2:error] [pid 642360:tid 642491] [client 172.237.109.114:28937] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDSZSUkh3e5AhEJOCJbwAAAZA"]
[Thu Jul 30 12:00:58.551115 2026] [security2:error] [pid 643253:tid 643478] [client 172.237.109.114:31203] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDScjqbtjBYzqM1uYsBAAAAF4"]
[Thu Jul 30 12:00:59.047203 2026] [security2:error] [pid 642360:tid 642543] [client 191.232.199.39:39774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/flower.php"] [unique_id "amuDS5SUkh3e5AhEJOCJlwAAAcQ"]
[Thu Jul 30 12:00:59.486589 2026] [security2:error] [pid 643253:tid 643388] [client 172.237.109.114:26199] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDSsjqbtjBYzqM1uYsDAAAAAQ"]
[Thu Jul 30 12:00:59.521035 2026] [security2:error] [pid 642360:tid 642587] [client 172.237.109.114:29651] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDSpSUkh3e5AhEJOCJiAAAAfA"]
[Thu Jul 30 12:01:00.037468 2026] [security2:error] [pid 642360:tid 642522] [client 20.91.199.21:53490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/database.php"] [unique_id "amuDTJSUkh3e5AhEJOCJrQAAAa8"]
[Thu Jul 30 12:01:00.216335 2026] [security2:error] [pid 642360:tid 642612] [client 172.237.109.114:52925] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDSpSUkh3e5AhEJOCJhwAAAgk"]
[Thu Jul 30 12:01:00.242645 2026] [security2:error] [pid 642360:tid 642613] [client 172.237.109.114:18506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDSpSUkh3e5AhEJOCJjQAAAgo"]
[Thu Jul 30 12:01:00.248274 2026] [security2:error] [pid 642360:tid 642531] [client 172.237.109.114:50569] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDSpSUkh3e5AhEJOCJiQAAAbg"]
[Thu Jul 30 12:01:00.388811 2026] [security2:error] [pid 642360:tid 642610] [client 191.232.199.39:6465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/form.php"] [unique_id "amuDTJSUkh3e5AhEJOCJsgAAAgc"]
[Thu Jul 30 12:01:00.458370 2026] [security2:error] [pid 643253:tid 643408] [client 172.237.109.114:26178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDSsjqbtjBYzqM1uYsDQAAABg"]
[Thu Jul 30 12:01:00.662286 2026] [proxy:error] [pid 642360:tid 642583] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:01:00.662379 2026] [proxy_http:error] [pid 642360:tid 642583] [client 193.47.62.167:54384] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:01:00.663123 2026] [proxy:error] [pid 642360:tid 642583] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:01:00.663169 2026] [proxy_http:error] [pid 642360:tid 642583] [client 193.47.62.167:54384] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:01:00.847251 2026] [security2:error] [pid 642360:tid 642575] [client 20.91.199.21:53015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/db.php"] [unique_id "amuDTJSUkh3e5AhEJOCJtgAAAeQ"]
[Thu Jul 30 12:01:01.228819 2026] [security2:error] [pid 642360:tid 642524] [client 172.237.109.114:18918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDS5SUkh3e5AhEJOCJowAAAbE"]
[Thu Jul 30 12:01:01.233733 2026] [security2:error] [pid 642360:tid 642490] [client 172.237.109.114:20191] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDS5SUkh3e5AhEJOCJpAAAAY8"]
[Thu Jul 30 12:01:01.240731 2026] [security2:error] [pid 643253:tid 643434] [client 172.237.109.114:30773] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDS8jqbtjBYzqM1uYsEgAAADI"]
[Thu Jul 30 12:01:01.251432 2026] [security2:error] [pid 642360:tid 642536] [client 172.237.109.114:1997] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDS5SUkh3e5AhEJOCJngAAAb0"]
[Thu Jul 30 12:01:01.255792 2026] [security2:error] [pid 642360:tid 642589] [client 172.237.109.114:3642] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDS5SUkh3e5AhEJOCJnAAAAfI"]
[Thu Jul 30 12:01:01.287613 2026] [security2:error] [pid 642360:tid 642504] [client 172.237.109.114:39802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDS5SUkh3e5AhEJOCJmgAAAZ0"]
[Thu Jul 30 12:01:01.320019 2026] [security2:error] [pid 643253:tid 643421] [client 172.237.109.114:14989] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDS8jqbtjBYzqM1uYsFAAAACU"]
[Thu Jul 30 12:01:01.322625 2026] [security2:error] [pid 642360:tid 642569] [client 172.237.109.114:37806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDS5SUkh3e5AhEJOCJnwAAAd4"]
[Thu Jul 30 12:01:01.330744 2026] [security2:error] [pid 642360:tid 642519] [client 172.237.109.114:54018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDS5SUkh3e5AhEJOCJmAAAAaw"]
[Thu Jul 30 12:01:01.338607 2026] [security2:error] [pid 643253:tid 643476] [client 172.237.109.114:59932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDS8jqbtjBYzqM1uYsEQAAAFw"]
[Thu Jul 30 12:01:01.342661 2026] [security2:error] [pid 642360:tid 642564] [client 172.237.109.114:6162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDS5SUkh3e5AhEJOCJmQAAAdk"]
[Thu Jul 30 12:01:01.343942 2026] [security2:error] [pid 642360:tid 642503] [client 172.237.109.114:26225] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDS5SUkh3e5AhEJOCJogAAAZw"]
[Thu Jul 30 12:01:01.346682 2026] [security2:error] [pid 642360:tid 642606] [client 172.237.109.114:10011] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDS5SUkh3e5AhEJOCJmwAAAgM"]
[Thu Jul 30 12:01:01.354584 2026] [security2:error] [pid 642360:tid 642495] [client 172.237.109.114:25245] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDS5SUkh3e5AhEJOCJnQAAAZQ"]
[Thu Jul 30 12:01:01.370263 2026] [security2:error] [pid 643253:tid 643472] [client 172.237.109.114:40796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDS8jqbtjBYzqM1uYsEAAAAFg"]
[Thu Jul 30 12:01:01.416242 2026] [security2:error] [pid 643253:tid 643509] [client 172.237.109.114:39027] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDS8jqbtjBYzqM1uYsFQAAAH0"]
[Thu Jul 30 12:01:01.432505 2026] [security2:error] [pid 642360:tid 642546] [client 176.241.66.87:53643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDTZSUkh3e5AhEJOCJvgAAAcc"]
[Thu Jul 30 12:01:01.432644 2026] [security2:error] [pid 642360:tid 642546] [client 176.241.66.87:53643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDTZSUkh3e5AhEJOCJvgAAAcc"]
[Thu Jul 30 12:01:01.439939 2026] [security2:error] [pid 643253:tid 643443] [client 172.237.109.114:28122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDS8jqbtjBYzqM1uYsFgAAADs"]
[Thu Jul 30 12:01:01.467599 2026] [security2:error] [pid 642360:tid 642501] [client 172.237.109.114:25859] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDS5SUkh3e5AhEJOCJpQAAAZo"]
[Thu Jul 30 12:01:01.861155 2026] [security2:error] [pid 642360:tid 642596] [client 191.232.199.39:58943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/gecko.php"] [unique_id "amuDTZSUkh3e5AhEJOCJxgAAAfk"]
[Thu Jul 30 12:01:01.887951 2026] [security2:error] [pid 642360:tid 642532] [client 20.91.199.21:53491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/default.php"] [unique_id "amuDTZSUkh3e5AhEJOCJxwAAAbk"]
[Thu Jul 30 12:01:01.983702 2026] [core:notice] [pid 643253:tid 643293] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:02.467958 2026] [security2:error] [pid 643253:tid 643429] [client 2a03:2880:f800:36:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDTcjqbtjBYzqM1uYsJAAALRI"]
[Thu Jul 30 12:01:02.637877 2026] [security2:error] [pid 643253:tid 643423] [client 114.119.132.238:32793] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "online-hope.com"] [uri "/product/black-devil-3/"] [unique_id "amuDTsjqbtjBYzqM1uYsKAAAACc"], referer: https://online-hope.com/
[Thu Jul 30 12:01:02.711641 2026] [proxy:error] [pid 642360:tid 642537] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:01:02.711695 2026] [proxy_http:error] [pid 642360:tid 642537] [client 3.228.112.215:5655] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:01:02.712253 2026] [proxy:error] [pid 642360:tid 642537] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:01:02.712305 2026] [proxy_http:error] [pid 642360:tid 642537] [client 3.228.112.215:5655] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:01:02.814771 2026] [security2:error] [pid 642360:tid 642509] [client 114.119.162.251:46277] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toscanamall.com"] [uri "/product-reviews/B0DG4WZZPV/ref=acr_dp_hist_2"] [unique_id "amuDTpSUkh3e5AhEJOCJ1wAAAaI"], referer: http://www.bedandbreakfast-skye.com/
[Thu Jul 30 12:01:02.822226 2026] [security2:error] [pid 642360:tid 642531] [client 20.91.199.21:52830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/dropdown.php"] [unique_id "amuDTpSUkh3e5AhEJOCJ2QAAAbg"]
[Thu Jul 30 12:01:03.300304 2026] [security2:error] [pid 642360:tid 642552] [client 191.232.199.39:58893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/kyami.php"] [unique_id "amuDT5SUkh3e5AhEJOCJ6QAAAc0"]
[Thu Jul 30 12:01:03.581011 2026] [core:notice] [pid 642360:tid 642561] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:03.585241 2026] [security2:error] [pid 642360:tid 642561] [client 103.215.74.26:21886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDT5SUkh3e5AhEJOCJ8wAAAdY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:03.631886 2026] [security2:error] [pid 642360:tid 642516] [client 20.91.199.21:53006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/edit.php"] [unique_id "amuDT5SUkh3e5AhEJOCJ9QAAAak"]
[Thu Jul 30 12:01:04.199018 2026] [security2:error] [pid 642360:tid 642528] [client 20.91.199.21:49913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/f35.php"] [unique_id "amuDUJSUkh3e5AhEJOCJ_QAAAbU"]
[Thu Jul 30 12:01:04.418015 2026] [security2:error] [pid 642360:tid 642605] [client 57.141.0.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuDT5SUkh3e5AhEJOCJ9wAAAgI"]
[Thu Jul 30 12:01:04.994609 2026] [security2:error] [pid 642360:tid 642597] [client 191.232.199.39:60599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/manager.php"] [unique_id "amuDUJSUkh3e5AhEJOCKCgAAAfo"]
[Thu Jul 30 12:01:05.334656 2026] [security2:error] [pid 643253:tid 643488] [client 2a03:2880:f800:20:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDUMjqbtjBYzqM1uYsMQAAaCw"]
[Thu Jul 30 12:01:05.818541 2026] [security2:error] [pid 642360:tid 642408] [remote 57.141.0.5:37470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/7514146397/feed/rss2/"] [unique_id "amuDUZSUkh3e5AhEJOCKFAABki8"]
[Thu Jul 30 12:01:06.243956 2026] [security2:error] [pid 642360:tid 642614] [client 191.232.199.39:60545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/mari.php"] [unique_id "amuDUpSUkh3e5AhEJOCKHgAAAgs"]
[Thu Jul 30 12:01:06.475218 2026] [security2:error] [pid 642360:tid 642601] [client 2a03:2880:f800:27:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDUZSUkh3e5AhEJOCKGQAB_kw"]
[Thu Jul 30 12:01:06.742836 2026] [security2:error] [pid 643253:tid 643298] [remote 74.7.241.59:47970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuDUsjqbtjBYzqM1uYsNQAAcSs"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/theme-builder/documents
[Thu Jul 30 12:01:06.970863 2026] [security2:error] [pid 643253:tid 643307] [remote 57.141.0.41:31138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuDUsjqbtjBYzqM1uYsNwAACTQ"]
[Thu Jul 30 12:01:07.519459 2026] [security2:error] [pid 643253:tid 643430] [client 20.91.199.21:53478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/f7.php"] [unique_id "amuDU8jqbtjBYzqM1uYsOQAAAC4"]
[Thu Jul 30 12:01:07.619506 2026] [security2:error] [pid 643253:tid 643424] [client 178.20.45.128:60455] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "178.20.45.128" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "deltaedu.net"] [uri "/wp-comments-post.php"] [unique_id "amuDU8jqbtjBYzqM1uYsOwAAACg"], referer: https://deltaedu.net/2016/11/04/university-scholarship-2017/#comment-25
[Thu Jul 30 12:01:07.619610 2026] [security2:error] [pid 643253:tid 643424] [client 178.20.45.128:60455] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "deltaedu.net"] [uri "/wp-comments-post.php"] [unique_id "amuDU8jqbtjBYzqM1uYsOwAAACg"], referer: https://deltaedu.net/2016/11/04/university-scholarship-2017/#comment-25
[Thu Jul 30 12:01:07.887697 2026] [security2:error] [pid 642360:tid 642510] [client 191.232.199.39:6473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/nc4.php"] [unique_id "amuDU5SUkh3e5AhEJOCKQAAAAaM"]
[Thu Jul 30 12:01:07.944037 2026] [security2:error] [pid 643253:tid 643501] [client 127.0.0.1:36914] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuDU8jqbtjBYzqM1uYsPgAAAHU"]
[Thu Jul 30 12:01:07.944050 2026] [security2:error] [pid 642360:tid 642550] [client 127.0.0.1:36904] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.ssm.njr.temporary.site"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuDU5SUkh3e5AhEJOCKQgAAAcs"]
[Thu Jul 30 12:01:07.944217 2026] [security2:error] [pid 642360:tid 642506] [client 74.7.228.11:57860] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.ssm.njr.temporary.site"] [uri "/robots.txt"] [unique_id "amuDU5SUkh3e5AhEJOCKQQABn0g"]
[Thu Jul 30 12:01:08.012752 2026] [security2:error] [pid 642360:tid 642507] [client 57.141.0.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuDU5SUkh3e5AhEJOCKNQAAAaA"]
[Thu Jul 30 12:01:08.498418 2026] [security2:error] [pid 643253:tid 643494] [client 172.202.44.182:45093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/gecko.php"] [unique_id "amuDVMjqbtjBYzqM1uYsQQAAAG4"]
[Thu Jul 30 12:01:09.254614 2026] [cgid:error] [pid 642360:tid 642519] [client 191.232.199.39:0] AH01265: stderr from /home1/ssadjbte/public_html/cgi-bin/: attempt to invoke directory as script
[Thu Jul 30 12:01:09.297543 2026] [core:notice] [pid 642360:tid 642609] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:09.301825 2026] [security2:error] [pid 642360:tid 642609] [client 103.215.74.26:21898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDVZSUkh3e5AhEJOCKWwAAAgY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:10.029393 2026] [core:notice] [pid 643253:tid 643413] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:10.033750 2026] [security2:error] [pid 643253:tid 643413] [client 103.215.74.26:21904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDVsjqbtjBYzqM1uYsTwAAAB0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:10.425781 2026] [security2:error] [pid 642360:tid 642528] [client 172.202.44.182:45066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/kyami.php"] [unique_id "amuDVpSUkh3e5AhEJOCKbAAAAbU"]
[Thu Jul 30 12:01:10.770033 2026] [core:notice] [pid 642360:tid 642513] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:10.774382 2026] [security2:error] [pid 642360:tid 642513] [client 103.215.74.26:21912] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDVpSUkh3e5AhEJOCKbgAAAaY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:12.129229 2026] [security2:error] [pid 642360:tid 642555] [client 172.202.44.182:50557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/manager.php"] [unique_id "amuDWJSUkh3e5AhEJOCKgQAAAdA"]
[Thu Jul 30 12:01:12.448178 2026] [security2:error] [pid 642360:tid 642493] [client 176.241.66.87:50730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDWJSUkh3e5AhEJOCKiAAAAZI"]
[Thu Jul 30 12:01:12.448342 2026] [security2:error] [pid 642360:tid 642493] [client 176.241.66.87:50730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDWJSUkh3e5AhEJOCKiAAAAZI"]
[Thu Jul 30 12:01:12.985366 2026] [security2:error] [pid 642360:tid 642514] [client 47.128.112.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "club4.au"] [uri "/index.php"] [unique_id "amuDVZSUkh3e5AhEJOCKUwAAAac"]
[Thu Jul 30 12:01:13.347240 2026] [security2:error] [pid 643253:tid 643509] [client 172.202.44.182:39197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/mari.php"] [unique_id "amuDWcjqbtjBYzqM1uYsWgAAAH0"]
[Thu Jul 30 12:01:15.345783 2026] [security2:error] [pid 642360:tid 642568] [client 74.7.175.152:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amuDWpSUkh3e5AhEJOCKsQAAAd0"]
[Thu Jul 30 12:01:15.346561 2026] [security2:error] [pid 642360:tid 642579] [client 74.7.175.152:60030] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "kool-shop.com"] [uri "/robots.txt"] [unique_id "amuDWpSUkh3e5AhEJOCKrwAB6FI"]
[Thu Jul 30 12:01:15.547064 2026] [security2:error] [pid 643253:tid 643444] [client 172.202.44.182:50541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/nc4.php"] [unique_id "amuDW8jqbtjBYzqM1uYsXgAAADw"]
[Thu Jul 30 12:01:16.493719 2026] [core:notice] [pid 642360:tid 642510] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:16.498107 2026] [security2:error] [pid 642360:tid 642510] [client 103.215.74.26:64558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDXJSUkh3e5AhEJOCK0wAAAaM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:17.197938 2026] [core:notice] [pid 642360:tid 642476] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:17.228619 2026] [core:notice] [pid 643253:tid 643508] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:17.234207 2026] [security2:error] [pid 643253:tid 643508] [client 103.215.74.26:64562] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDXcjqbtjBYzqM1uYsYAAAAHw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:17.958454 2026] [core:notice] [pid 642360:tid 642551] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:17.962497 2026] [security2:error] [pid 642360:tid 642551] [client 103.215.74.26:64564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDXZSUkh3e5AhEJOCK6wAAAcw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:18.089637 2026] [proxy:error] [pid 642360:tid 642583] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:01:18.089723 2026] [proxy_http:error] [pid 642360:tid 642583] [client 172.202.44.182:50497] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:01:18.090398 2026] [proxy:error] [pid 642360:tid 642583] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:01:18.090447 2026] [proxy_http:error] [pid 642360:tid 642583] [client 172.202.44.182:50497] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:01:18.685842 2026] [security2:error] [pid 642360:tid 642613] [client 85.208.96.202:49420] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/05/13/hospital-de-clinicas-inicia-consultas-para-cirurgias-ortopedicas-pelo-opera-paraiba/"] [unique_id "amuDXpSUkh3e5AhEJOCK8gAAAgo"]
[Thu Jul 30 12:01:18.685966 2026] [security2:error] [pid 642360:tid 642613] [client 85.208.96.202:49420] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/05/13/hospital-de-clinicas-inicia-consultas-para-cirurgias-ortopedicas-pelo-opera-paraiba/"] [unique_id "amuDXpSUkh3e5AhEJOCK8gAAAgo"]
[Thu Jul 30 12:01:18.728217 2026] [core:notice] [pid 642360:tid 642582] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:18.732082 2026] [security2:error] [pid 642360:tid 642582] [client 103.215.74.26:64578] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDXpSUkh3e5AhEJOCK9gAAAes"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:19.505402 2026] [core:notice] [pid 642360:tid 642493] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:19.509446 2026] [security2:error] [pid 642360:tid 642493] [client 103.215.74.26:64582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDX5SUkh3e5AhEJOCLAAAAAZI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:19.653658 2026] [security2:error] [pid 643253:tid 643318] [remote 57.141.0.63:47622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/PBB/article/view/7396"] [unique_id "amuDX8jqbtjBYzqM1uYsaAAAeT8"]
[Thu Jul 30 12:01:19.827084 2026] [security2:error] [pid 642360:tid 642609] [client 20.215.191.139:50817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/json.php"] [unique_id "amuDX5SUkh3e5AhEJOCLBQAAAgY"]
[Thu Jul 30 12:01:19.873747 2026] [security2:error] [pid 642360:tid 642506] [client 74.7.228.30:36518] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "webmail.tereasshop.com"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuDX5SUkh3e5AhEJOCLBgAAAZ8"]
[Thu Jul 30 12:01:20.224055 2026] [core:notice] [pid 643253:tid 643469] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:20.228602 2026] [security2:error] [pid 643253:tid 643469] [client 103.215.74.26:64594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDYMjqbtjBYzqM1uYsagAAAFU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:20.528947 2026] [security2:error] [pid 642360:tid 642532] [client 20.215.191.139:51416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/mini.php"] [unique_id "amuDYJSUkh3e5AhEJOCLDQAAAbk"]
[Thu Jul 30 12:01:20.950492 2026] [core:notice] [pid 642360:tid 642537] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:20.961188 2026] [security2:error] [pid 642360:tid 642537] [client 103.215.74.26:64608] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDYJSUkh3e5AhEJOCLEQAAAb4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:21.011126 2026] [core:notice] [pid 642360:tid 642549] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:21.129233 2026] [security2:error] [pid 642360:tid 642528] [client 20.215.191.139:50824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/chosen.php"] [unique_id "amuDYZSUkh3e5AhEJOCLFwAAAbU"]
[Thu Jul 30 12:01:21.211547 2026] [security2:error] [pid 642360:tid 642558] [client 54.223.173.193:61920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.jesus.claims"] [uri "/index.php"] [unique_id "amuDYZSUkh3e5AhEJOCLFgAAAdM"]
[Thu Jul 30 12:01:21.686511 2026] [core:notice] [pid 642360:tid 642565] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:21.693278 2026] [security2:error] [pid 642360:tid 642565] [client 103.215.74.26:64610] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDYZSUkh3e5AhEJOCLHQAAAdo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:22.092317 2026] [security2:error] [pid 642360:tid 642547] [client 114.119.137.160:29635] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lark-shop.com"] [uri "/product/black-devil%e9%bb%91%e9%ad%94%e9%ac%bc%e8%96%84%e8%8d%b7%e9%a6%99%e7%85%9910mg%e6%97%a5%e6%9c%ac%e6%9c%ac%e5%9c%9f%e5%85%8d%e7%a8%85%e9%a6%99%e6%b8%af%e7%8f%be%e8%b2%a8/"] [unique_id "amuDYpSUkh3e5AhEJOCLJAAAAcg"], referer: https://lark-shop.com/product/black-devil%E9%BB%91%E9%AD%94%E9%AC%BC%E6%9C%B1%E5%8F%A4%E5%8A%9B%E9%A6%99%E7%85%9910mg%E6%97%A5%E6%9C%AC%E6%9C%AC%E5%9C%9F%E5%85%8D%E7%A8%85%E9%A6%99%E6%B8%AF%E7%8F%BE%E8%B2%A8/
[Thu Jul 30 12:01:22.261197 2026] [security2:error] [pid 642360:tid 642499] [client 20.215.191.139:50842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/kj.php"] [unique_id "amuDYpSUkh3e5AhEJOCLJQAAAZg"]
[Thu Jul 30 12:01:22.448091 2026] [core:notice] [pid 642360:tid 642491] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:22.452065 2026] [security2:error] [pid 642360:tid 642491] [client 103.215.74.26:64622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDYpSUkh3e5AhEJOCLKQAAAZA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:22.855890 2026] [security2:error] [pid 642360:tid 642561] [client 20.215.191.139:51401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/wp-files.php"] [unique_id "amuDYpSUkh3e5AhEJOCLLgAAAdY"]
[Thu Jul 30 12:01:23.106134 2026] [security2:error] [pid 642360:tid 642591] [client 114.119.145.102:23895] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.shorewooddaycare.com"] [uri "/leatherflower/darkmans53852.html"] [unique_id "amuDY5SUkh3e5AhEJOCLNAAAAfQ"], referer: https://www.shorewooddaycare.com/leatherflower/darkmans53852.html
[Thu Jul 30 12:01:23.445379 2026] [security2:error] [pid 643253:tid 643384] [client 176.241.66.87:55724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDY8jqbtjBYzqM1uYscwAAAAA"]
[Thu Jul 30 12:01:23.445565 2026] [security2:error] [pid 643253:tid 643384] [client 176.241.66.87:55724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDY8jqbtjBYzqM1uYscwAAAAA"]
[Thu Jul 30 12:01:23.515263 2026] [proxy:error] [pid 642360:tid 642543] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:01:23.515352 2026] [proxy_http:error] [pid 642360:tid 642543] [client 18.211.55.47:22774] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:01:23.515896 2026] [proxy:error] [pid 642360:tid 642543] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:01:23.515938 2026] [proxy_http:error] [pid 642360:tid 642543] [client 18.211.55.47:22774] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:01:24.535374 2026] [core:error] [pid 642360:tid 642386] [remote 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:01:24.535403 2026] [core:error] [pid 642360:tid 642386] [remote 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:01:24.777921 2026] [security2:error] [pid 642360:tid 642605] [client 20.215.191.139:51413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/wp-setup.php"] [unique_id "amuDZJSUkh3e5AhEJOCLTgAAAgI"]
[Thu Jul 30 12:01:24.939665 2026] [security2:error] [pid 642360:tid 642522] [client 114.119.143.77:50733] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "fireworkskenya.co.ke"] [uri "/our-products/consumer-fireworks/missiles"] [unique_id "amuDZJSUkh3e5AhEJOCLTwAAAa8"], referer: https://fireworkskenya.co.ke/our-products/consumer-fireworks/big-display-cakes/hangoverator-z2093-square-cake-36-shots
[Thu Jul 30 12:01:25.384802 2026] [security2:error] [pid 643253:tid 643396] [client 20.215.191.139:50839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/defaults.php"] [unique_id "amuDZcjqbtjBYzqM1uYseAAAAAw"]
[Thu Jul 30 12:01:25.395073 2026] [core:error] [pid 642360:tid 642480] [remote 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:01:25.395091 2026] [core:error] [pid 642360:tid 642480] [remote 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:01:25.747818 2026] [proxy:error] [pid 642360:tid 642535] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:01:25.747901 2026] [proxy_http:error] [pid 642360:tid 642535] [client 98.87.102.177:32111] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:01:25.748485 2026] [proxy:error] [pid 642360:tid 642535] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:01:25.748534 2026] [proxy_http:error] [pid 642360:tid 642535] [client 98.87.102.177:32111] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:01:25.841842 2026] [security2:error] [pid 643253:tid 643414] [client 114.119.130.26:42489] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cnpinyin.com"] [uri "/study/Chinese-grammar/%E6%9C%89%E7%82%B9%2Bor%2B%E6%9C%89%E4%B8%80%E7%82%B9%2B"] [unique_id "amuDZcjqbtjBYzqM1uYsegAAAB4"], referer: http://cnpinyin.com/study/chinese-grammar/page/21
[Thu Jul 30 12:01:26.166102 2026] [security2:error] [pid 643253:tid 643424] [client 20.215.191.139:50852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/gtc.php"] [unique_id "amuDZsjqbtjBYzqM1uYsfAAAACg"]
[Thu Jul 30 12:01:26.688881 2026] [proxy:error] [pid 642360:tid 642402] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:01:26.688942 2026] [proxy_http:error] [pid 642360:tid 642402] [remote 74.7.244.14:35588] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:01:26.689727 2026] [proxy:error] [pid 642360:tid 642402] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:01:26.689781 2026] [proxy_http:error] [pid 642360:tid 642402] [remote 74.7.244.14:35588] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:01:26.799637 2026] [security2:error] [pid 642360:tid 642556] [client 20.215.191.139:50822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/import.php"] [unique_id "amuDZpSUkh3e5AhEJOCLcgAAAdE"]
[Thu Jul 30 12:01:27.565383 2026] [security2:error] [pid 643253:tid 643418] [client 20.215.191.139:50856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/lufix.php"] [unique_id "amuDZ8jqbtjBYzqM1uYsggAAACI"]
[Thu Jul 30 12:01:27.913918 2026] [security2:error] [pid 642360:tid 642603] [client 57.141.0.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuDZZSUkh3e5AhEJOCLYwAAAgA"]
[Thu Jul 30 12:01:28.214270 2026] [security2:error] [pid 642360:tid 642557] [client 123.1.209.245:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amuDZ5SUkh3e5AhEJOCLhgAAAdI"]
[Thu Jul 30 12:01:28.231438 2026] [core:notice] [pid 642360:tid 642504] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:28.238269 2026] [security2:error] [pid 642360:tid 642504] [client 103.215.74.26:25186] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "766"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDaJSUkh3e5AhEJOCLjwAAAZ0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:28.610063 2026] [security2:error] [pid 643253:tid 643478] [client 123.1.209.245:50282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amuDZ8jqbtjBYzqM1uYshQAAXkI"]
[Thu Jul 30 12:01:28.610398 2026] [security2:error] [pid 643253:tid 643320] [remote 123.1.209.245:50282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amuDZ8jqbtjBYzqM1uYshAAAXkE"]
[Thu Jul 30 12:01:28.982228 2026] [core:notice] [pid 642360:tid 642529] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:28.988995 2026] [security2:error] [pid 642360:tid 642529] [client 103.215.74.26:25200] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDaJSUkh3e5AhEJOCLpQAAAbY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:29.173648 2026] [fcgid:warn] [pid 642360:tid 642513] (70014)End of file found: [client 167.94.146.61:3922] mod_fcgid: can't get data from http client
[Thu Jul 30 12:01:29.295540 2026] [autoindex:error] [pid 642360:tid 642510] [client 18.211.55.47:5075] AH01276: Cannot serve directory /home2/kiinyxte/xexrecords.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:01:29.571751 2026] [security2:error] [pid 642360:tid 642499] [client 114.119.130.248:38017] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.hmhs.ph"] [uri "/events/retreat-dates/eventsbyday/2026/5/16/-"] [unique_id "amuDaZSUkh3e5AhEJOCLsgAAAZg"], referer: https://www.hmhs.ph/events/retreat-dates/monthcalendar/2026/5/-
[Thu Jul 30 12:01:29.723160 2026] [core:notice] [pid 642360:tid 642532] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:29.727158 2026] [security2:error] [pid 642360:tid 642532] [client 103.215.74.26:25232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "779"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDaZSUkh3e5AhEJOCLswAAAbk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:30.444251 2026] [core:notice] [pid 643253:tid 643440] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:30.448487 2026] [security2:error] [pid 643253:tid 643440] [client 103.215.74.26:25238] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDasjqbtjBYzqM1uYsowAAADg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:31.185468 2026] [core:notice] [pid 642360:tid 642559] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:31.189345 2026] [security2:error] [pid 642360:tid 642559] [client 103.215.74.26:25272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDa5SUkh3e5AhEJOCL0wAAAdQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:31.926098 2026] [core:notice] [pid 642360:tid 642548] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:31.929841 2026] [security2:error] [pid 642360:tid 642548] [client 103.215.74.26:25278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "761"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDa5SUkh3e5AhEJOCL4gAAAck"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:32.568993 2026] [security2:error] [pid 642360:tid 642511] [client 20.215.191.139:50858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/Geforce.php"] [unique_id "amuDbJSUkh3e5AhEJOCL_AAAAaQ"]
[Thu Jul 30 12:01:32.719103 2026] [core:notice] [pid 642360:tid 642557] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:32.723505 2026] [security2:error] [pid 642360:tid 642557] [client 103.215.74.26:25316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDbJSUkh3e5AhEJOCL_gAAAdI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:33.395029 2026] [security2:error] [pid 642360:tid 642615] [client 20.215.191.139:50866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/a4.php"] [unique_id "amuDbZSUkh3e5AhEJOCMDgAAAgw"]
[Thu Jul 30 12:01:33.477862 2026] [core:notice] [pid 643253:tid 643401] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:33.482040 2026] [security2:error] [pid 643253:tid 643401] [client 103.215.74.26:34056] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDbcjqbtjBYzqM1uYtCAAAABE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:34.209169 2026] [core:notice] [pid 642360:tid 642549] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:34.213132 2026] [security2:error] [pid 642360:tid 642549] [client 103.215.74.26:34070] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDbpSUkh3e5AhEJOCMIAAAAco"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:34.373346 2026] [security2:error] [pid 642360:tid 642608] [client 176.241.66.87:56772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDbpSUkh3e5AhEJOCMIQAAAgU"]
[Thu Jul 30 12:01:34.373499 2026] [security2:error] [pid 642360:tid 642608] [client 176.241.66.87:56772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDbpSUkh3e5AhEJOCMIQAAAgU"]
[Thu Jul 30 12:01:34.521072 2026] [security2:error] [pid 642360:tid 642515] [client 20.215.191.139:50857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/accueil.php"] [unique_id "amuDbpSUkh3e5AhEJOCMJAAAAag"]
[Thu Jul 30 12:01:34.948951 2026] [core:notice] [pid 642360:tid 642570] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:34.953503 2026] [security2:error] [pid 642360:tid 642570] [client 103.215.74.26:34086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDbpSUkh3e5AhEJOCMLgAAAd8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:34.988888 2026] [security2:error] [pid 642360:tid 642560] [client 114.119.151.192:51973] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.dhowcruisedinner.com"] [uri "/new-year-party-canal.html"] [unique_id "amuDbpSUkh3e5AhEJOCMMwAAAdU"]
[Thu Jul 30 12:01:35.108421 2026] [security2:error] [pid 642360:tid 642525] [client 74.7.228.21:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "vvr.hfl.temporary.site"] [uri "/index.php"] [unique_id "amuDbpSUkh3e5AhEJOCMLQAAAbI"]
[Thu Jul 30 12:01:35.109272 2026] [security2:error] [pid 642360:tid 642593] [client 74.7.228.21:58914] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "vvr.hfl.temporary.site"] [uri "/robots.txt"] [unique_id "amuDbpSUkh3e5AhEJOCMKwAB9lk"]
[Thu Jul 30 12:01:35.276159 2026] [security2:error] [pid 642360:tid 642568] [client 20.215.191.139:50859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/dashboard.php"] [unique_id "amuDb5SUkh3e5AhEJOCMPQAAAd0"]
[Thu Jul 30 12:01:35.397991 2026] [security2:error] [pid 642360:tid 642536] [client 158.181.41.199:3672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuDb5SUkh3e5AhEJOCMNwAAAb0"]
[Thu Jul 30 12:01:35.710551 2026] [core:notice] [pid 643253:tid 643441] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:35.715911 2026] [security2:error] [pid 643253:tid 643441] [client 103.215.74.26:34100] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDb8jqbtjBYzqM1uYtEAAAADk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:36.452335 2026] [core:notice] [pid 642360:tid 642553] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:36.456867 2026] [security2:error] [pid 642360:tid 642553] [client 103.215.74.26:34112] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDcJSUkh3e5AhEJOCMUAAAAc4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:36.990739 2026] [security2:error] [pid 642360:tid 642609] [client 20.215.191.139:51013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/radio.php"] [unique_id "amuDcJSUkh3e5AhEJOCMWwAAAgY"]
[Thu Jul 30 12:01:37.205273 2026] [core:notice] [pid 642360:tid 642533] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:37.209636 2026] [security2:error] [pid 642360:tid 642533] [client 103.215.74.26:34122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDcZSUkh3e5AhEJOCMXwAAAbo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:37.378372 2026] [security2:error] [pid 643253:tid 643386] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuDccjqbtjBYzqM1uYtFwAAAAI"]
[Thu Jul 30 12:01:37.379743 2026] [security2:error] [pid 643253:tid 643386] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuDccjqbtjBYzqM1uYtFwAAAAI"]
[Thu Jul 30 12:01:37.934035 2026] [core:notice] [pid 642360:tid 642504] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:37.937253 2026] [security2:error] [pid 642360:tid 642535] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuDcZSUkh3e5AhEJOCMbgAAAbw"]
[Thu Jul 30 12:01:37.937371 2026] [security2:error] [pid 642360:tid 642535] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuDcZSUkh3e5AhEJOCMbgAAAbw"]
[Thu Jul 30 12:01:37.938476 2026] [security2:error] [pid 642360:tid 642504] [client 103.215.74.26:34130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDcZSUkh3e5AhEJOCMbQAAAZ0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:38.064060 2026] [security2:error] [pid 642360:tid 642617] [client 74.7.244.22:53388] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "smoke-tfhk.com"] [uri "/robots.txt"] [unique_id "amuDcpSUkh3e5AhEJOCMcAACDmE"]
[Thu Jul 30 12:01:38.480890 2026] [security2:error] [pid 642360:tid 642584] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wicked.php"] [unique_id "amuDcpSUkh3e5AhEJOCMeAAAAe0"]
[Thu Jul 30 12:01:38.481070 2026] [security2:error] [pid 642360:tid 642584] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wicked.php"] [unique_id "amuDcpSUkh3e5AhEJOCMeAAAAe0"]
[Thu Jul 30 12:01:38.659028 2026] [core:notice] [pid 643253:tid 643413] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:38.663455 2026] [security2:error] [pid 643253:tid 643413] [client 103.215.74.26:34138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDcsjqbtjBYzqM1uYtIAAAAB0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:38.987849 2026] [security2:error] [pid 642360:tid 642510] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wpx.php"] [unique_id "amuDcpSUkh3e5AhEJOCMgQAAAaM"]
[Thu Jul 30 12:01:38.987994 2026] [security2:error] [pid 642360:tid 642510] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wpx.php"] [unique_id "amuDcpSUkh3e5AhEJOCMgQAAAaM"]
[Thu Jul 30 12:01:39.160397 2026] [security2:error] [pid 643253:tid 643387] [client 20.215.191.139:50832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/wpsml-sys.php"] [unique_id "amuDc8jqbtjBYzqM1uYtIwAAAAM"]
[Thu Jul 30 12:01:39.351691 2026] [security2:error] [pid 642360:tid 642607] [client 43.173.174.152:42374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.174.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/11/16/sacs-a-main-en-cuir-automne-2015/"] [unique_id "amuDc5SUkh3e5AhEJOCMhQAAAgQ"]
[Thu Jul 30 12:01:39.388313 2026] [core:notice] [pid 642360:tid 642543] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:39.392688 2026] [security2:error] [pid 642360:tid 642543] [client 103.215.74.26:34142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDc5SUkh3e5AhEJOCMiwAAAcQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:39.529074 2026] [security2:error] [pid 642360:tid 642520] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/images.php"] [unique_id "amuDc5SUkh3e5AhEJOCMjwAAAa0"]
[Thu Jul 30 12:01:39.529163 2026] [security2:error] [pid 642360:tid 642520] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/images.php"] [unique_id "amuDc5SUkh3e5AhEJOCMjwAAAa0"]
[Thu Jul 30 12:01:39.561001 2026] [core:notice] [pid 642360:tid 642499] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:39.565701 2026] [security2:error] [pid 642360:tid 642499] [client 43.172.195.84:60838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/11/16/sacs-a-main-en-cuir-automne-2015/"] [unique_id "amuDc5SUkh3e5AhEJOCMkQAAAZg"], referer: https://carnetdeshopping.com/index.php/2015/11/16/sacs-a-main-en-cuir-automne-2015/
[Thu Jul 30 12:01:39.614149 2026] [security2:error] [pid 642360:tid 642542] [client 43.173.174.75:50564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.174.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2016/07/01/alternative-fragrance-beauty-2016/"] [unique_id "amuDc5SUkh3e5AhEJOCMhwAAAcM"]
[Thu Jul 30 12:01:39.619134 2026] [security2:error] [pid 642360:tid 642553] [client 43.172.194.163:56666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.194.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/11/09/lenseigne-espagnole-suiteblanco-lance-son-eshop-en-france/"] [unique_id "amuDc5SUkh3e5AhEJOCMhgAAAc4"]
[Thu Jul 30 12:01:40.052700 2026] [core:notice] [pid 642360:tid 642533] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:40.057482 2026] [security2:error] [pid 642360:tid 642533] [client 43.173.180.204:35128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2016/07/01/alternative-fragrance-beauty-2016/"] [unique_id "amuDdJSUkh3e5AhEJOCMnAAAAbo"], referer: https://carnetdeshopping.com/index.php/2016/07/01/alternative-fragrance-beauty-2016/
[Thu Jul 30 12:01:40.107486 2026] [security2:error] [pid 642360:tid 642523] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/1xmomo.php"] [unique_id "amuDdJSUkh3e5AhEJOCMngAAAbA"]
[Thu Jul 30 12:01:40.107575 2026] [security2:error] [pid 642360:tid 642523] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/1xmomo.php"] [unique_id "amuDdJSUkh3e5AhEJOCMngAAAbA"]
[Thu Jul 30 12:01:40.141591 2026] [core:notice] [pid 642360:tid 642522] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:40.145937 2026] [security2:error] [pid 642360:tid 642522] [client 103.215.74.26:34154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDdJSUkh3e5AhEJOCMnwAAAa8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:40.347389 2026] [core:notice] [pid 642360:tid 642551] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:40.354580 2026] [security2:error] [pid 642360:tid 642551] [client 43.173.173.143:52060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/11/09/lenseigne-espagnole-suiteblanco-lance-son-eshop-en-france/"] [unique_id "amuDdJSUkh3e5AhEJOCMpgAAAcw"], referer: https://carnetdeshopping.com/index.php/2012/11/09/lenseigne-espagnole-suiteblanco-lance-son-eshop-en-france/
[Thu Jul 30 12:01:40.544801 2026] [security2:error] [pid 642360:tid 642518] [client 57.141.0.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuDc5SUkh3e5AhEJOCMmgAAAas"]
[Thu Jul 30 12:01:40.669766 2026] [security2:error] [pid 642360:tid 642611] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/1revo.php"] [unique_id "amuDdJSUkh3e5AhEJOCMrAAAAgg"]
[Thu Jul 30 12:01:40.669907 2026] [security2:error] [pid 642360:tid 642611] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/1revo.php"] [unique_id "amuDdJSUkh3e5AhEJOCMrAAAAgg"]
[Thu Jul 30 12:01:40.872046 2026] [core:notice] [pid 642360:tid 642497] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:40.876547 2026] [security2:error] [pid 642360:tid 642497] [client 103.215.74.26:34160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDdJSUkh3e5AhEJOCMswAAAZY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:41.218601 2026] [security2:error] [pid 643253:tid 643509] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/cong.php"] [unique_id "amuDdcjqbtjBYzqM1uYtJgAAAH0"]
[Thu Jul 30 12:01:41.218705 2026] [security2:error] [pid 643253:tid 643509] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/cong.php"] [unique_id "amuDdcjqbtjBYzqM1uYtJgAAAH0"]
[Thu Jul 30 12:01:41.334512 2026] [security2:error] [pid 642360:tid 642567] [client 20.215.191.139:51052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/02.php"] [unique_id "amuDdZSUkh3e5AhEJOCMugAAAdw"]
[Thu Jul 30 12:01:41.617516 2026] [core:notice] [pid 642360:tid 642556] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:41.621514 2026] [security2:error] [pid 642360:tid 642556] [client 103.215.74.26:34164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDdZSUkh3e5AhEJOCMwwAAAdE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:41.754859 2026] [security2:error] [pid 642360:tid 642597] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/a.php"] [unique_id "amuDdZSUkh3e5AhEJOCMxAAAAfo"]
[Thu Jul 30 12:01:41.755018 2026] [security2:error] [pid 642360:tid 642597] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/a.php"] [unique_id "amuDdZSUkh3e5AhEJOCMxAAAAfo"]
[Thu Jul 30 12:01:42.292574 2026] [security2:error] [pid 642360:tid 642591] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/srontol.php"] [unique_id "amuDdpSUkh3e5AhEJOCMzQAAAfQ"]
[Thu Jul 30 12:01:42.292682 2026] [security2:error] [pid 642360:tid 642591] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/srontol.php"] [unique_id "amuDdpSUkh3e5AhEJOCMzQAAAfQ"]
[Thu Jul 30 12:01:42.401597 2026] [core:notice] [pid 642360:tid 642538] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:42.405466 2026] [security2:error] [pid 642360:tid 642538] [client 103.215.74.26:34170] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "752"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDdpSUkh3e5AhEJOCMzwAAAb8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:42.500721 2026] [security2:error] [pid 642360:tid 642487] [remote 74.7.241.60:47012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/content/article.php"] [unique_id "amuDdpSUkh3e5AhEJOCM1QACBn4"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/content/1784123347_ed%20inclusive.jpg
[Thu Jul 30 12:01:42.836159 2026] [security2:error] [pid 642360:tid 642551] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/reop3.php"] [unique_id "amuDdpSUkh3e5AhEJOCM2QAAAcw"]
[Thu Jul 30 12:01:42.836264 2026] [security2:error] [pid 642360:tid 642551] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/reop3.php"] [unique_id "amuDdpSUkh3e5AhEJOCM2QAAAcw"]
[Thu Jul 30 12:01:43.132201 2026] [core:notice] [pid 643253:tid 643474] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:43.136195 2026] [security2:error] [pid 643253:tid 643474] [client 103.215.74.26:64342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDd8jqbtjBYzqM1uYtKgAAAFo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:43.409339 2026] [security2:error] [pid 642360:tid 642563] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/file5.php"] [unique_id "amuDd5SUkh3e5AhEJOCM4gAAAdg"]
[Thu Jul 30 12:01:43.409479 2026] [security2:error] [pid 642360:tid 642563] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/file5.php"] [unique_id "amuDd5SUkh3e5AhEJOCM4gAAAdg"]
[Thu Jul 30 12:01:43.656328 2026] [security2:error] [pid 642360:tid 642611] [client 114.119.130.32:25255] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ejournalugj.com"] [uri "/index_php/jibm"] [unique_id "amuDd5SUkh3e5AhEJOCM6QAAAgg"], referer: https://www.ejournalugj.com/
[Thu Jul 30 12:01:43.963717 2026] [security2:error] [pid 643253:tid 643444] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/domvf.php"] [unique_id "amuDd8jqbtjBYzqM1uYtLQAAADw"]
[Thu Jul 30 12:01:43.963818 2026] [security2:error] [pid 643253:tid 643444] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/domvf.php"] [unique_id "amuDd8jqbtjBYzqM1uYtLQAAADw"]
[Thu Jul 30 12:01:44.454934 2026] [security2:error] [pid 643253:tid 643447] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/zero.php"] [unique_id "amuDeMjqbtjBYzqM1uYtLwAAAD8"]
[Thu Jul 30 12:01:44.455044 2026] [security2:error] [pid 643253:tid 643447] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/zero.php"] [unique_id "amuDeMjqbtjBYzqM1uYtLwAAAD8"]
[Thu Jul 30 12:01:44.953438 2026] [security2:error] [pid 642360:tid 642587] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/002.php"] [unique_id "amuDeJSUkh3e5AhEJOCM9QAAAfA"]
[Thu Jul 30 12:01:44.953560 2026] [security2:error] [pid 642360:tid 642587] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/002.php"] [unique_id "amuDeJSUkh3e5AhEJOCM9QAAAfA"]
[Thu Jul 30 12:01:45.511893 2026] [security2:error] [pid 642360:tid 642578] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/thoms.php"] [unique_id "amuDeZSUkh3e5AhEJOCM_wAAAec"]
[Thu Jul 30 12:01:45.512018 2026] [security2:error] [pid 642360:tid 642578] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/thoms.php"] [unique_id "amuDeZSUkh3e5AhEJOCM_wAAAec"]
[Thu Jul 30 12:01:45.630064 2026] [security2:error] [pid 642360:tid 642534] [client 176.241.66.87:58020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDeZSUkh3e5AhEJOCNAgAAAbs"]
[Thu Jul 30 12:01:45.630222 2026] [security2:error] [pid 642360:tid 642534] [client 176.241.66.87:58020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDeZSUkh3e5AhEJOCNAgAAAbs"]
[Thu Jul 30 12:01:45.804436 2026] [security2:error] [pid 642360:tid 642564] [client 20.215.191.139:51066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/infos.php"] [unique_id "amuDeZSUkh3e5AhEJOCNBQAAAdk"]
[Thu Jul 30 12:01:46.098575 2026] [security2:error] [pid 643253:tid 643462] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/fi22.php"] [unique_id "amuDesjqbtjBYzqM1uYtOgAAAE4"]
[Thu Jul 30 12:01:46.098670 2026] [security2:error] [pid 643253:tid 643462] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/fi22.php"] [unique_id "amuDesjqbtjBYzqM1uYtOgAAAE4"]
[Thu Jul 30 12:01:46.519417 2026] [core:notice] [pid 642360:tid 642547] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:46.644996 2026] [security2:error] [pid 642360:tid 642614] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/___proxy_subdomain_webdisk/wp-content/"] [unique_id "amuDepSUkh3e5AhEJOCNEQAAAgs"]
[Thu Jul 30 12:01:46.910726 2026] [security2:error] [pid 642360:tid 642511] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/82.php"] [unique_id "amuDepSUkh3e5AhEJOCNFAAAAaQ"]
[Thu Jul 30 12:01:46.910835 2026] [security2:error] [pid 642360:tid 642511] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/82.php"] [unique_id "amuDepSUkh3e5AhEJOCNFAAAAaQ"]
[Thu Jul 30 12:01:47.408761 2026] [security2:error] [pid 642360:tid 642509] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/sx.php"] [unique_id "amuDe5SUkh3e5AhEJOCNHwAAAaI"]
[Thu Jul 30 12:01:47.408882 2026] [security2:error] [pid 642360:tid 642509] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/sx.php"] [unique_id "amuDe5SUkh3e5AhEJOCNHwAAAaI"]
[Thu Jul 30 12:01:47.673002 2026] [core:error] [pid 642360:tid 642398] [remote 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:01:47.673057 2026] [core:error] [pid 642360:tid 642398] [remote 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:01:47.682564 2026] [core:notice] [pid 643253:tid 643305] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:47.696100 2026] [security2:error] [pid 642360:tid 642577] [client 57.141.0.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuDe5SUkh3e5AhEJOCNGQAAAeY"]
[Thu Jul 30 12:01:47.918712 2026] [security2:error] [pid 643253:tid 643464] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/dex.php"] [unique_id "amuDe8jqbtjBYzqM1uYtSQAAAFA"]
[Thu Jul 30 12:01:47.918820 2026] [security2:error] [pid 643253:tid 643464] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/dex.php"] [unique_id "amuDe8jqbtjBYzqM1uYtSQAAAFA"]
[Thu Jul 30 12:01:48.471411 2026] [security2:error] [pid 642360:tid 642520] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/fpwch.php"] [unique_id "amuDfJSUkh3e5AhEJOCNMAAAAa0"]
[Thu Jul 30 12:01:48.471521 2026] [security2:error] [pid 642360:tid 642520] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/fpwch.php"] [unique_id "amuDfJSUkh3e5AhEJOCNMAAAAa0"]
[Thu Jul 30 12:01:48.531088 2026] [security2:error] [pid 642360:tid 642537] [client 20.215.191.139:51020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/updates.php"] [unique_id "amuDfJSUkh3e5AhEJOCNMQAAAb4"]
[Thu Jul 30 12:01:48.783717 2026] [security2:error] [pid 643253:tid 643494] [client 93.152.221.59:59212] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "lark-shop.com"] [uri "/"] [unique_id "amuDfMjqbtjBYzqM1uYtTQAAAG4"]
[Thu Jul 30 12:01:48.859907 2026] [core:notice] [pid 643253:tid 643416] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:48.864291 2026] [security2:error] [pid 643253:tid 643416] [client 103.215.74.26:64354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDfMjqbtjBYzqM1uYtUAAAACA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:48.996114 2026] [core:error] [pid 643253:tid 643301] [remote 74.7.230.41:43942] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:01:48.996135 2026] [core:error] [pid 643253:tid 643301] [remote 74.7.230.41:43942] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:01:48.996359 2026] [security2:error] [pid 643253:tid 643502] [client 74.7.230.41:43942] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "mail.chicago-mfg.com"] [uri "/index.php"] [unique_id "amuDfMjqbtjBYzqM1uYtUwAAdi4"]
[Thu Jul 30 12:01:49.038934 2026] [security2:error] [pid 643253:tid 643481] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/black.php"] [unique_id "amuDfcjqbtjBYzqM1uYtVQAAAGE"]
[Thu Jul 30 12:01:49.039075 2026] [security2:error] [pid 643253:tid 643481] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/black.php"] [unique_id "amuDfcjqbtjBYzqM1uYtVQAAAGE"]
[Thu Jul 30 12:01:49.080673 2026] [security2:error] [pid 642360:tid 642424] [remote 45.252.248.45:41900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.248.252.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.lxw.gpl.temporary.site"] [uri "/wp-login.php"] [unique_id "amuDfJSUkh3e5AhEJOCNNwABsz8"]
[Thu Jul 30 12:01:49.547480 2026] [security2:error] [pid 643253:tid 643386] [client 20.215.191.139:51070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/user.php"] [unique_id "amuDfcjqbtjBYzqM1uYtWQAAAAI"]
[Thu Jul 30 12:01:49.586569 2026] [core:notice] [pid 642360:tid 642609] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:49.586947 2026] [security2:error] [pid 643253:tid 643471] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/loader.php"] [unique_id "amuDfcjqbtjBYzqM1uYtWgAAAFc"]
[Thu Jul 30 12:01:49.587058 2026] [security2:error] [pid 643253:tid 643471] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/loader.php"] [unique_id "amuDfcjqbtjBYzqM1uYtWgAAAFc"]
[Thu Jul 30 12:01:49.592561 2026] [security2:error] [pid 642360:tid 642609] [client 103.215.74.26:64360] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDfZSUkh3e5AhEJOCNQQAAAgY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:50.101452 2026] [security2:error] [pid 642360:tid 642614] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/file61.php"] [unique_id "amuDfpSUkh3e5AhEJOCNSwAAAgs"]
[Thu Jul 30 12:01:50.101559 2026] [security2:error] [pid 642360:tid 642614] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/file61.php"] [unique_id "amuDfpSUkh3e5AhEJOCNSwAAAgs"]
[Thu Jul 30 12:01:50.336917 2026] [core:notice] [pid 642360:tid 642593] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:50.343715 2026] [security2:error] [pid 642360:tid 642593] [client 103.215.74.26:64364] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDfpSUkh3e5AhEJOCNTwAAAfY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:50.646611 2026] [security2:error] [pid 642360:tid 642567] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-css.php"] [unique_id "amuDfpSUkh3e5AhEJOCNWAAAAdw"]
[Thu Jul 30 12:01:50.646771 2026] [security2:error] [pid 642360:tid 642567] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-css.php"] [unique_id "amuDfpSUkh3e5AhEJOCNWAAAAdw"]
[Thu Jul 30 12:01:50.784021 2026] [security2:error] [pid 643253:tid 643413] [client 2a03:2880:f800:20:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDfsjqbtjBYzqM1uYtWwAAHTY"]
[Thu Jul 30 12:01:51.121060 2026] [core:notice] [pid 642360:tid 642550] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:51.125170 2026] [security2:error] [pid 642360:tid 642550] [client 103.215.74.26:64374] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDf5SUkh3e5AhEJOCNZQAAAcs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:51.254681 2026] [security2:error] [pid 642360:tid 642587] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-blink.php"] [unique_id "amuDf5SUkh3e5AhEJOCNZgAAAfA"]
[Thu Jul 30 12:01:51.254797 2026] [security2:error] [pid 642360:tid 642587] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-blink.php"] [unique_id "amuDf5SUkh3e5AhEJOCNZgAAAfA"]
[Thu Jul 30 12:01:51.257014 2026] [security2:error] [pid 643253:tid 643498] [client 57.141.0.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuDfsjqbtjBYzqM1uYtXAAAAHI"]
[Thu Jul 30 12:01:51.275440 2026] [security2:error] [pid 642360:tid 642571] [client 20.215.191.139:51016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/admin-ajax.php"] [unique_id "amuDf5SUkh3e5AhEJOCNZwAAAeA"]
[Thu Jul 30 12:01:51.831052 2026] [security2:error] [pid 642360:tid 642608] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/txets.php"] [unique_id "amuDf5SUkh3e5AhEJOCNbQAAAgU"]
[Thu Jul 30 12:01:51.831181 2026] [security2:error] [pid 642360:tid 642608] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/txets.php"] [unique_id "amuDf5SUkh3e5AhEJOCNbQAAAgU"]
[Thu Jul 30 12:01:51.900323 2026] [core:notice] [pid 642360:tid 642597] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:51.904076 2026] [security2:error] [pid 642360:tid 642597] [client 103.215.74.26:64380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "768"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDf5SUkh3e5AhEJOCNcQAAAfo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:52.390639 2026] [security2:error] [pid 642360:tid 642495] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/pucci.php"] [unique_id "amuDgJSUkh3e5AhEJOCNdgAAAZQ"]
[Thu Jul 30 12:01:52.390743 2026] [security2:error] [pid 642360:tid 642495] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/pucci.php"] [unique_id "amuDgJSUkh3e5AhEJOCNdgAAAZQ"]
[Thu Jul 30 12:01:52.405169 2026] [core:notice] [pid 643253:tid 643510] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:52.630793 2026] [core:notice] [pid 642360:tid 642514] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:52.637406 2026] [security2:error] [pid 642360:tid 642514] [client 103.215.74.26:64388] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDgJSUkh3e5AhEJOCNegAAAac"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:52.913162 2026] [security2:error] [pid 642360:tid 642605] [client 2a03:2880:f800:8:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDgJSUkh3e5AhEJOCNdQACAkQ"]
[Thu Jul 30 12:01:52.927153 2026] [security2:error] [pid 643253:tid 643456] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/xwpg.php"] [unique_id "amuDgMjqbtjBYzqM1uYtZgAAAEg"]
[Thu Jul 30 12:01:52.927251 2026] [security2:error] [pid 643253:tid 643456] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/xwpg.php"] [unique_id "amuDgMjqbtjBYzqM1uYtZgAAAEg"]
[Thu Jul 30 12:01:53.365533 2026] [core:notice] [pid 642360:tid 642559] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:53.369523 2026] [security2:error] [pid 642360:tid 642559] [client 103.215.74.26:7514] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "781"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDgZSUkh3e5AhEJOCNggAAAdQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:53.507127 2026] [security2:error] [pid 642360:tid 642611] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ops.php"] [unique_id "amuDgZSUkh3e5AhEJOCNhwAAAgg"]
[Thu Jul 30 12:01:53.507219 2026] [security2:error] [pid 642360:tid 642611] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ops.php"] [unique_id "amuDgZSUkh3e5AhEJOCNhwAAAgg"]
[Thu Jul 30 12:01:54.080088 2026] [security2:error] [pid 642360:tid 642596] [client 52.165.196.84:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/1.php"] [unique_id "amuDgpSUkh3e5AhEJOCNkgAAAfk"]
[Thu Jul 30 12:01:54.080195 2026] [security2:error] [pid 642360:tid 642596] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/1.php"] [unique_id "amuDgpSUkh3e5AhEJOCNkgAAAfk"]
[Thu Jul 30 12:01:54.080263 2026] [security2:error] [pid 642360:tid 642596] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/1.php"] [unique_id "amuDgpSUkh3e5AhEJOCNkgAAAfk"]
[Thu Jul 30 12:01:54.093792 2026] [core:notice] [pid 642360:tid 642568] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:54.097890 2026] [security2:error] [pid 642360:tid 642568] [client 103.215.74.26:7526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDgpSUkh3e5AhEJOCNkwAAAd0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:54.449043 2026] [security2:error] [pid 642360:tid 642598] [client 14.191.136.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fantasynamelist.com"] [uri "/index.php"] [unique_id "amuDgpSUkh3e5AhEJOCNlAAB-zg"]
[Thu Jul 30 12:01:54.657279 2026] [security2:error] [pid 642360:tid 642528] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/mac.php"] [unique_id "amuDgpSUkh3e5AhEJOCNmwAAAbU"]
[Thu Jul 30 12:01:54.657426 2026] [security2:error] [pid 642360:tid 642528] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/mac.php"] [unique_id "amuDgpSUkh3e5AhEJOCNmwAAAbU"]
[Thu Jul 30 12:01:54.818255 2026] [core:notice] [pid 642360:tid 642571] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:54.822511 2026] [security2:error] [pid 642360:tid 642571] [client 103.215.74.26:7530] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDgpSUkh3e5AhEJOCNnAAAAeA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:55.222762 2026] [security2:error] [pid 643253:tid 643507] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-admin/js/index.php"] [unique_id "amuDg8jqbtjBYzqM1uYtZwAAAHs"]
[Thu Jul 30 12:01:55.222882 2026] [security2:error] [pid 643253:tid 643507] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-admin/js/index.php"] [unique_id "amuDg8jqbtjBYzqM1uYtZwAAAHs"]
[Thu Jul 30 12:01:55.558403 2026] [core:notice] [pid 642360:tid 642508] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:55.564748 2026] [security2:error] [pid 642360:tid 642508] [client 103.215.74.26:7542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDg5SUkh3e5AhEJOCNqQAAAaE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:55.660908 2026] [security2:error] [pid 642360:tid 642533] [client 20.215.191.139:50826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/alfa.php"] [unique_id "amuDg5SUkh3e5AhEJOCNrgAAAbo"]
[Thu Jul 30 12:01:55.758884 2026] [security2:error] [pid 643253:tid 643392] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/aa.php"] [unique_id "amuDg8jqbtjBYzqM1uYtaQAAAAg"]
[Thu Jul 30 12:01:55.759045 2026] [security2:error] [pid 643253:tid 643392] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/aa.php"] [unique_id "amuDg8jqbtjBYzqM1uYtaQAAAAg"]
[Thu Jul 30 12:01:56.281143 2026] [security2:error] [pid 642360:tid 642545] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/xyn.php"] [unique_id "amuDhJSUkh3e5AhEJOCNuAAAAcY"]
[Thu Jul 30 12:01:56.281278 2026] [security2:error] [pid 642360:tid 642545] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/xyn.php"] [unique_id "amuDhJSUkh3e5AhEJOCNuAAAAcY"]
[Thu Jul 30 12:01:56.292031 2026] [core:notice] [pid 643253:tid 643397] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:56.296475 2026] [security2:error] [pid 643253:tid 643397] [client 103.215.74.26:7552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDhMjqbtjBYzqM1uYtagAAAA0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:56.726242 2026] [security2:error] [pid 642360:tid 642512] [client 176.241.66.87:59057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDhJSUkh3e5AhEJOCNwgAAAaU"]
[Thu Jul 30 12:01:56.726364 2026] [security2:error] [pid 642360:tid 642512] [client 176.241.66.87:59057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDhJSUkh3e5AhEJOCNwgAAAaU"]
[Thu Jul 30 12:01:56.787005 2026] [security2:error] [pid 642360:tid 642540] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-wp.php"] [unique_id "amuDhJSUkh3e5AhEJOCNwwAAAcE"]
[Thu Jul 30 12:01:56.787115 2026] [security2:error] [pid 642360:tid 642540] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-wp.php"] [unique_id "amuDhJSUkh3e5AhEJOCNwwAAAcE"]
[Thu Jul 30 12:01:57.036600 2026] [core:notice] [pid 643253:tid 643475] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:57.040534 2026] [security2:error] [pid 643253:tid 643475] [client 103.215.74.26:7562] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDhcjqbtjBYzqM1uYtbAAAAFs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:57.267351 2026] [security2:error] [pid 642360:tid 642588] [client 74.7.241.181:37158] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "mail.ege.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuDg5SUkh3e5AhEJOCNoQAB8U8"]
[Thu Jul 30 12:01:57.267377 2026] [security2:error] [pid 642360:tid 642588] [client 74.7.241.181:37158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.ege.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuDg5SUkh3e5AhEJOCNoQAB8U8"]
[Thu Jul 30 12:01:57.287731 2026] [security2:error] [pid 643253:tid 643433] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/aw.php"] [unique_id "amuDhcjqbtjBYzqM1uYtbgAAADE"]
[Thu Jul 30 12:01:57.287822 2026] [security2:error] [pid 643253:tid 643433] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/aw.php"] [unique_id "amuDhcjqbtjBYzqM1uYtbgAAADE"]
[Thu Jul 30 12:01:57.777872 2026] [core:notice] [pid 642360:tid 642566] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:57.780866 2026] [security2:error] [pid 643253:tid 643455] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/classwithtostring.php"] [unique_id "amuDhcjqbtjBYzqM1uYtcgAAAEc"]
[Thu Jul 30 12:01:57.780957 2026] [security2:error] [pid 643253:tid 643455] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/classwithtostring.php"] [unique_id "amuDhcjqbtjBYzqM1uYtcgAAAEc"]
[Thu Jul 30 12:01:57.784797 2026] [security2:error] [pid 642360:tid 642566] [client 103.215.74.26:7578] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDhZSUkh3e5AhEJOCNzwAAAds"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:58.300926 2026] [security2:error] [pid 643253:tid 643504] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/yawa.php"] [unique_id "amuDhsjqbtjBYzqM1uYtdAAAAHg"]
[Thu Jul 30 12:01:58.301086 2026] [security2:error] [pid 643253:tid 643504] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/yawa.php"] [unique_id "amuDhsjqbtjBYzqM1uYtdAAAAHg"]
[Thu Jul 30 12:01:58.506165 2026] [core:notice] [pid 643253:tid 643470] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:58.510491 2026] [security2:error] [pid 643253:tid 643470] [client 103.215.74.26:7582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDhsjqbtjBYzqM1uYtdQAAAFY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:58.565273 2026] [security2:error] [pid 642360:tid 642592] [client 74.7.241.181:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "medaxco.com"] [uri "/index.php"] [unique_id "amuDhpSUkh3e5AhEJOCN0gAB9V0"], referer: https://mail.ege.nyx.temporary.site/robots.txt
[Thu Jul 30 12:01:58.816838 2026] [security2:error] [pid 642360:tid 642549] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/sym403.php"] [unique_id "amuDhpSUkh3e5AhEJOCN2QAAAco"]
[Thu Jul 30 12:01:58.816940 2026] [security2:error] [pid 642360:tid 642549] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/sym403.php"] [unique_id "amuDhpSUkh3e5AhEJOCN2QAAAco"]
[Thu Jul 30 12:01:59.399970 2026] [security2:error] [pid 642360:tid 642521] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/colors/blue/"] [unique_id "amuDh5SUkh3e5AhEJOCN4QAAAa4"]
[Thu Jul 30 12:01:59.718177 2026] [security2:error] [pid 642360:tid 642551] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/adminner.php"] [unique_id "amuDh5SUkh3e5AhEJOCN5QAAAcw"]
[Thu Jul 30 12:01:59.718304 2026] [security2:error] [pid 642360:tid 642551] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/adminner.php"] [unique_id "amuDh5SUkh3e5AhEJOCN5QAAAcw"]
[Thu Jul 30 12:02:00.199641 2026] [security2:error] [pid 643253:tid 643436] [client 20.215.191.139:51053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/hehe.php"] [unique_id "amuDiMjqbtjBYzqM1uYtegAAADQ"]
[Thu Jul 30 12:02:00.334359 2026] [security2:error] [pid 643253:tid 643394] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/yup.php"] [unique_id "amuDiMjqbtjBYzqM1uYtfAAAAAo"]
[Thu Jul 30 12:02:00.334473 2026] [security2:error] [pid 643253:tid 643394] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/yup.php"] [unique_id "amuDiMjqbtjBYzqM1uYtfAAAAAo"]
[Thu Jul 30 12:02:00.510833 2026] [core:notice] [pid 643253:tid 643314] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:00.514949 2026] [security2:error] [pid 643253:tid 643477] [client 125.165.105.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/download/287/287"] [unique_id "amuDiMjqbtjBYzqM1uYtewAAXTs"]
[Thu Jul 30 12:02:00.917811 2026] [security2:error] [pid 643253:tid 643424] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/config.json.php"] [unique_id "amuDiMjqbtjBYzqM1uYtfgAAACg"]
[Thu Jul 30 12:02:00.917906 2026] [security2:error] [pid 643253:tid 643424] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/config.json.php"] [unique_id "amuDiMjqbtjBYzqM1uYtfgAAACg"]
[Thu Jul 30 12:02:00.999711 2026] [core:notice] [pid 642360:tid 642447] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:01.397516 2026] [security2:error] [pid 643253:tid 643452] [client 52.15.147.27:47262] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuDicjqbtjBYzqM1uYtgAAAAEQ"], referer: https://globalmarks.pk/
[Thu Jul 30 12:02:01.513658 2026] [security2:error] [pid 642360:tid 642596] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/___proxy_subdomain_webdisk/wp-includes/block-bindings/"] [unique_id "amuDiZSUkh3e5AhEJOCN_AAAAfk"]
[Thu Jul 30 12:02:01.528681 2026] [security2:error] [pid 642360:tid 642562] [client 20.215.191.139:50825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/rk2.php"] [unique_id "amuDiZSUkh3e5AhEJOCN_QAAAdc"]
[Thu Jul 30 12:02:01.821317 2026] [security2:error] [pid 642360:tid 642595] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/2.php"] [unique_id "amuDiZSUkh3e5AhEJOCN_gAAAfg"]
[Thu Jul 30 12:02:01.821446 2026] [security2:error] [pid 642360:tid 642595] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/2.php"] [unique_id "amuDiZSUkh3e5AhEJOCN_gAAAfg"]
[Thu Jul 30 12:02:02.355778 2026] [security2:error] [pid 642360:tid 642572] [client 20.215.191.139:50873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/setup-config.php"] [unique_id "amuDipSUkh3e5AhEJOCOCAAAAeE"]
[Thu Jul 30 12:02:02.397575 2026] [security2:error] [pid 642360:tid 642532] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/f35.update.php"] [unique_id "amuDipSUkh3e5AhEJOCOCQAAAbk"]
[Thu Jul 30 12:02:02.397672 2026] [security2:error] [pid 642360:tid 642532] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/f35.update.php"] [unique_id "amuDipSUkh3e5AhEJOCOCQAAAbk"]
[Thu Jul 30 12:02:02.940805 2026] [security2:error] [pid 643253:tid 643503] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/k.php"] [unique_id "amuDisjqbtjBYzqM1uYtgwAAAHc"]
[Thu Jul 30 12:02:02.940923 2026] [security2:error] [pid 643253:tid 643503] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/k.php"] [unique_id "amuDisjqbtjBYzqM1uYtgwAAAHc"]
[Thu Jul 30 12:02:03.349212 2026] [security2:error] [pid 643253:tid 643313] [remote 47.128.27.89:50610] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/search/Nike/page/59/"] [unique_id "amuDi8jqbtjBYzqM1uYthQAAIDo"]
[Thu Jul 30 12:02:03.518736 2026] [security2:error] [pid 642360:tid 642525] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/"] [unique_id "amuDi5SUkh3e5AhEJOCOHAAAAbI"]
[Thu Jul 30 12:02:03.784763 2026] [security2:error] [pid 642360:tid 642500] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/spadex.php"] [unique_id "amuDi5SUkh3e5AhEJOCOIgAAAZk"]
[Thu Jul 30 12:02:03.784911 2026] [security2:error] [pid 642360:tid 642500] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/spadex.php"] [unique_id "amuDi5SUkh3e5AhEJOCOIgAAAZk"]
[Thu Jul 30 12:02:03.865697 2026] [security2:error] [pid 642360:tid 642520] [client 20.215.191.139:50837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/a7.php"] [unique_id "amuDi5SUkh3e5AhEJOCOIwAAAa0"]
[Thu Jul 30 12:02:04.062007 2026] [security2:error] [pid 642360:tid 642505] [client 64.31.3.126:46892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuDipSUkh3e5AhEJOCOEAAAAfc"], referer: https://globalmarks.pk/2023/08/28/parent-guide-babys-first-tooth-and-what-parents-must-know/#comment-2266
[Thu Jul 30 12:02:04.235549 2026] [core:notice] [pid 643253:tid 643445] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:04.239969 2026] [security2:error] [pid 643253:tid 643445] [client 103.215.74.26:35160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDjMjqbtjBYzqM1uYtiAAAAD0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:04.282114 2026] [security2:error] [pid 642360:tid 642611] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/mg.php"] [unique_id "amuDjJSUkh3e5AhEJOCOKgAAAgg"]
[Thu Jul 30 12:02:04.282225 2026] [security2:error] [pid 642360:tid 642611] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/mg.php"] [unique_id "amuDjJSUkh3e5AhEJOCOKgAAAgg"]
[Thu Jul 30 12:02:04.845804 2026] [security2:error] [pid 642360:tid 642596] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/fnstall.php"] [unique_id "amuDjJSUkh3e5AhEJOCOMAAAAfk"]
[Thu Jul 30 12:02:04.845919 2026] [security2:error] [pid 642360:tid 642596] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/fnstall.php"] [unique_id "amuDjJSUkh3e5AhEJOCOMAAAAfk"]
[Thu Jul 30 12:02:04.986591 2026] [core:notice] [pid 643253:tid 643451] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:04.991183 2026] [security2:error] [pid 643253:tid 643451] [client 103.215.74.26:35168] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDjMjqbtjBYzqM1uYtigAAAEM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:05.368355 2026] [security2:error] [pid 642360:tid 642528] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ortasekerli1.php"] [unique_id "amuDjZSUkh3e5AhEJOCOQAAAAbU"]
[Thu Jul 30 12:02:05.368470 2026] [security2:error] [pid 642360:tid 642528] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ortasekerli1.php"] [unique_id "amuDjZSUkh3e5AhEJOCOQAAAAbU"]
[Thu Jul 30 12:02:05.450807 2026] [security2:error] [pid 642360:tid 642496] [client 20.215.191.139:50823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/f7.php"] [unique_id "amuDjZSUkh3e5AhEJOCOQgAAAZU"]
[Thu Jul 30 12:02:05.711617 2026] [core:notice] [pid 642360:tid 642530] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:05.715953 2026] [security2:error] [pid 642360:tid 642530] [client 103.215.74.26:35170] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDjZSUkh3e5AhEJOCORQAAAbc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:05.875170 2026] [security2:error] [pid 643253:tid 643402] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/sump1.php"] [unique_id "amuDjcjqbtjBYzqM1uYtkQAAABI"]
[Thu Jul 30 12:02:05.875265 2026] [security2:error] [pid 643253:tid 643402] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/sump1.php"] [unique_id "amuDjcjqbtjBYzqM1uYtkQAAABI"]
[Thu Jul 30 12:02:06.418476 2026] [security2:error] [pid 643253:tid 643473] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ops.php"] [unique_id "amuDjsjqbtjBYzqM1uYtkwAAAFk"]
[Thu Jul 30 12:02:06.418588 2026] [security2:error] [pid 643253:tid 643473] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ops.php"] [unique_id "amuDjsjqbtjBYzqM1uYtkwAAAFk"]
[Thu Jul 30 12:02:06.538985 2026] [core:notice] [pid 642360:tid 642557] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:06.543333 2026] [security2:error] [pid 642360:tid 642557] [client 103.215.74.26:35180] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDjpSUkh3e5AhEJOCOWAAAAdI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:06.957736 2026] [security2:error] [pid 642360:tid 642518] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-post-data.php"] [unique_id "amuDjpSUkh3e5AhEJOCObQAAAas"]
[Thu Jul 30 12:02:06.957817 2026] [security2:error] [pid 642360:tid 642518] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-post-data.php"] [unique_id "amuDjpSUkh3e5AhEJOCObQAAAas"]
[Thu Jul 30 12:02:07.152006 2026] [security2:error] [pid 643253:tid 643387] [client 20.215.191.139:51055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/nw.php"] [unique_id "amuDj8jqbtjBYzqM1uYtmAAAAAM"]
[Thu Jul 30 12:02:07.173411 2026] [security2:error] [pid 642360:tid 642473] [remote 45.148.10.21:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.massageandspaislamabad.rest"] [uri "/wp-json/batch/v1"] [unique_id "amuDj5SUkh3e5AhEJOCOcwACCXA"]
[Thu Jul 30 12:02:07.283270 2026] [core:notice] [pid 642360:tid 642494] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:07.287319 2026] [security2:error] [pid 642360:tid 642494] [client 103.215.74.26:35184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDj5SUkh3e5AhEJOCOdgAAAZM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:07.417418 2026] [security2:error] [pid 642360:tid 642383] [remote 74.7.241.59:36266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuDj5SUkh3e5AhEJOCOeQAB7xY"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/theme-builder/documents
[Thu Jul 30 12:02:07.494958 2026] [security2:error] [pid 642360:tid 642538] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/root.php"] [unique_id "amuDj5SUkh3e5AhEJOCOewAAAb8"]
[Thu Jul 30 12:02:07.495072 2026] [security2:error] [pid 642360:tid 642538] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/root.php"] [unique_id "amuDj5SUkh3e5AhEJOCOewAAAb8"]
[Thu Jul 30 12:02:07.708569 2026] [security2:error] [pid 642360:tid 642469] [remote 45.148.10.21:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.massageandspaislamabad.rest"] [uri "/"] [unique_id "amuDj5SUkh3e5AhEJOCOgAAB12w"]
[Thu Jul 30 12:02:07.806182 2026] [security2:error] [pid 642360:tid 642571] [client 176.241.66.87:60096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDj5SUkh3e5AhEJOCOhAAAAeA"]
[Thu Jul 30 12:02:07.806399 2026] [security2:error] [pid 642360:tid 642571] [client 176.241.66.87:60096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDj5SUkh3e5AhEJOCOhAAAAeA"]
[Thu Jul 30 12:02:08.058323 2026] [security2:error] [pid 643253:tid 643511] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/v543.php"] [unique_id "amuDkMjqbtjBYzqM1uYtmwAAAH8"]
[Thu Jul 30 12:02:08.058439 2026] [security2:error] [pid 643253:tid 643511] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/v543.php"] [unique_id "amuDkMjqbtjBYzqM1uYtmwAAAH8"]
[Thu Jul 30 12:02:08.062946 2026] [core:notice] [pid 642360:tid 642552] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:08.067781 2026] [security2:error] [pid 642360:tid 642552] [client 103.215.74.26:35198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDkJSUkh3e5AhEJOCOjQAAAc0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:08.169293 2026] [lsapi:error] [pid 643573:tid 643666] [remote 102.209.111.62:0] [host flixon.net] Error receiving response: ReceiveResponse: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1009; user ID 1009), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://flixon.net/video/fall-for-me-vj-junior/
[Thu Jul 30 12:02:08.173449 2026] [security2:error] [pid 642360:tid 642574] [client 20.215.191.139:50838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/ova.php"] [unique_id "amuDkJSUkh3e5AhEJOCOjgAAAeM"]
[Thu Jul 30 12:02:08.496076 2026] [security2:error] [pid 642360:tid 642395] [remote 103.57.220.209:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.57.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "edgecomm.info"] [uri "/wp-login.php"] [unique_id "amuDkJSUkh3e5AhEJOCOlAABxyI"]
[Thu Jul 30 12:02:08.589921 2026] [security2:error] [pid 642360:tid 642545] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/sixxis.php"] [unique_id "amuDkJSUkh3e5AhEJOCOlQAAAcY"]
[Thu Jul 30 12:02:08.590050 2026] [security2:error] [pid 642360:tid 642545] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/sixxis.php"] [unique_id "amuDkJSUkh3e5AhEJOCOlQAAAcY"]
[Thu Jul 30 12:02:08.968970 2026] [security2:error] [pid 643253:tid 643484] [client 20.215.191.139:50816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/robots.php"] [unique_id "amuDkMjqbtjBYzqM1uYtnQAAAGQ"]
[Thu Jul 30 12:02:09.128040 2026] [security2:error] [pid 642360:tid 642540] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ip.php"] [unique_id "amuDkZSUkh3e5AhEJOCOngAAAcE"]
[Thu Jul 30 12:02:09.128142 2026] [security2:error] [pid 642360:tid 642540] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ip.php"] [unique_id "amuDkZSUkh3e5AhEJOCOngAAAcE"]
[Thu Jul 30 12:02:09.685073 2026] [security2:error] [pid 642360:tid 642567] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/kq1.php"] [unique_id "amuDkZSUkh3e5AhEJOCOpwAAAdw"]
[Thu Jul 30 12:02:09.685184 2026] [security2:error] [pid 642360:tid 642567] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/kq1.php"] [unique_id "amuDkZSUkh3e5AhEJOCOpwAAAdw"]
[Thu Jul 30 12:02:09.932925 2026] [security2:error] [pid 643253:tid 643505] [client 20.215.191.139:51059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/alf.php"] [unique_id "amuDkcjqbtjBYzqM1uYtogAAAHk"]
[Thu Jul 30 12:02:10.181796 2026] [security2:error] [pid 642360:tid 642572] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/fw/faiyy.php"] [unique_id "amuDkpSUkh3e5AhEJOCOrAAAAeE"]
[Thu Jul 30 12:02:10.181952 2026] [security2:error] [pid 642360:tid 642572] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/fw/faiyy.php"] [unique_id "amuDkpSUkh3e5AhEJOCOrAAAAeE"]
[Thu Jul 30 12:02:10.740615 2026] [security2:error] [pid 642360:tid 642599] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/h02ugyh.php"] [unique_id "amuDkpSUkh3e5AhEJOCOtAAAAfw"]
[Thu Jul 30 12:02:10.740755 2026] [security2:error] [pid 642360:tid 642599] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/h02ugyh.php"] [unique_id "amuDkpSUkh3e5AhEJOCOtAAAAfw"]
[Thu Jul 30 12:02:11.357814 2026] [security2:error] [pid 642360:tid 642579] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-temp.php"] [unique_id "amuDk5SUkh3e5AhEJOCOugAAAeg"]
[Thu Jul 30 12:02:11.357919 2026] [security2:error] [pid 642360:tid 642579] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-temp.php"] [unique_id "amuDk5SUkh3e5AhEJOCOugAAAeg"]
[Thu Jul 30 12:02:11.795507 2026] [core:notice] [pid 643253:tid 643433] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:11.930328 2026] [security2:error] [pid 643253:tid 643395] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-content/cong.php"] [unique_id "amuDk8jqbtjBYzqM1uYtqQAAAAs"]
[Thu Jul 30 12:02:11.930438 2026] [security2:error] [pid 643253:tid 643395] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-content/cong.php"] [unique_id "amuDk8jqbtjBYzqM1uYtqQAAAAs"]
[Thu Jul 30 12:02:12.314957 2026] [security2:error] [pid 643253:tid 643455] [client 20.215.191.139:51065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/feedback.php"] [unique_id "amuDlMjqbtjBYzqM1uYtrQAAAEc"]
[Thu Jul 30 12:02:12.504997 2026] [security2:error] [pid 642360:tid 642511] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/___proxy_subdomain_webdisk/wp-admin/js/widget/"] [unique_id "amuDlJSUkh3e5AhEJOCO0QAAAaQ"]
[Thu Jul 30 12:02:12.797016 2026] [security2:error] [pid 642360:tid 642509] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-includes/css/index.php"] [unique_id "amuDlJSUkh3e5AhEJOCO2QAAAaI"]
[Thu Jul 30 12:02:12.797159 2026] [security2:error] [pid 642360:tid 642509] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-includes/css/index.php"] [unique_id "amuDlJSUkh3e5AhEJOCO2QAAAaI"]
[Thu Jul 30 12:02:12.923020 2026] [security2:error] [pid 642360:tid 642595] [client 206.0.24.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fantasynamelist.com"] [uri "/index.php"] [unique_id "amuDlJSUkh3e5AhEJOCO2AAB-DM"]
[Thu Jul 30 12:02:13.356433 2026] [security2:error] [pid 642360:tid 642493] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/jj.php"] [unique_id "amuDlZSUkh3e5AhEJOCO5AAAAZI"]
[Thu Jul 30 12:02:13.356570 2026] [security2:error] [pid 642360:tid 642493] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/jj.php"] [unique_id "amuDlZSUkh3e5AhEJOCO5AAAAZI"]
[Thu Jul 30 12:02:13.827359 2026] [core:notice] [pid 642360:tid 642508] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:13.831816 2026] [security2:error] [pid 642360:tid 642508] [client 103.215.74.26:60568] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDlZSUkh3e5AhEJOCO7QAAAaE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:13.901272 2026] [security2:error] [pid 642360:tid 642581] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/class-walker-footer-dev.php"] [unique_id "amuDlZSUkh3e5AhEJOCO7gAAAeo"]
[Thu Jul 30 12:02:13.901387 2026] [security2:error] [pid 642360:tid 642581] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/class-walker-footer-dev.php"] [unique_id "amuDlZSUkh3e5AhEJOCO7gAAAeo"]
[Thu Jul 30 12:02:14.157227 2026] [security2:error] [pid 643253:tid 643394] [client 157.230.8.64:60459] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "pvc.hfl.temporary.site"] [uri "/wp-json/batch/v1"] [unique_id "amuDlsjqbtjBYzqM1uYttQAAAAo"]
[Thu Jul 30 12:02:14.460395 2026] [security2:error] [pid 642360:tid 642565] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/xpwer1.php"] [unique_id "amuDlpSUkh3e5AhEJOCO9QAAAdo"]
[Thu Jul 30 12:02:14.460508 2026] [security2:error] [pid 642360:tid 642565] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/xpwer1.php"] [unique_id "amuDlpSUkh3e5AhEJOCO9QAAAdo"]
[Thu Jul 30 12:02:14.553826 2026] [security2:error] [pid 643253:tid 643480] [client 20.215.191.139:51026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/gettest.php"] [unique_id "amuDlsjqbtjBYzqM1uYttwAAAGA"]
[Thu Jul 30 12:02:14.555727 2026] [core:notice] [pid 642360:tid 642520] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:14.560119 2026] [security2:error] [pid 642360:tid 642520] [client 103.215.74.26:60578] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDlpSUkh3e5AhEJOCO9gAAAa0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:14.733419 2026] [security2:error] [pid 642360:tid 642597] [client 157.230.8.64:60516] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "pvc.hfl.temporary.site"] [uri "/"] [unique_id "amuDlpSUkh3e5AhEJOCO-QAAAfo"]
[Thu Jul 30 12:02:14.840273 2026] [security2:error] [pid 642360:tid 642500] [client 20.203.148.31:21591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/--wp-lgj.php"] [unique_id "amuDlpSUkh3e5AhEJOCO_AAAAZk"]
[Thu Jul 30 12:02:14.998067 2026] [security2:error] [pid 642360:tid 642616] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/flox.php"] [unique_id "amuDlpSUkh3e5AhEJOCO_QAAAg0"]
[Thu Jul 30 12:02:14.998176 2026] [security2:error] [pid 642360:tid 642616] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/flox.php"] [unique_id "amuDlpSUkh3e5AhEJOCO_QAAAg0"]
[Thu Jul 30 12:02:15.245228 2026] [security2:error] [pid 642360:tid 642604] [client 20.215.191.139:51047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/maint.php"] [unique_id "amuDl5SUkh3e5AhEJOCPBAAAAgE"]
[Thu Jul 30 12:02:15.289706 2026] [security2:error] [pid 642360:tid 642510] [client 157.230.8.64:60573] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "pvc.hfl.temporary.site"] [uri "/wp-json/batch/v1"] [unique_id "amuDl5SUkh3e5AhEJOCPCAAAAaM"]
[Thu Jul 30 12:02:15.317937 2026] [core:notice] [pid 642360:tid 642506] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:15.321805 2026] [security2:error] [pid 642360:tid 642506] [client 103.215.74.26:60580] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDl5SUkh3e5AhEJOCPCQAAAZ8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:15.478461 2026] [security2:error] [pid 642360:tid 642584] [client 20.203.148.31:20555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.well-known/autoload_classmap.php"] [unique_id "amuDl5SUkh3e5AhEJOCPCwAAAe0"]
[Thu Jul 30 12:02:15.596700 2026] [security2:error] [pid 643253:tid 643494] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/popo.php"] [unique_id "amuDl8jqbtjBYzqM1uYtugAAAG4"]
[Thu Jul 30 12:02:15.596820 2026] [security2:error] [pid 643253:tid 643494] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/popo.php"] [unique_id "amuDl8jqbtjBYzqM1uYtugAAAG4"]
[Thu Jul 30 12:02:16.059930 2026] [core:notice] [pid 642360:tid 642524] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:16.064320 2026] [security2:error] [pid 642360:tid 642524] [client 103.215.74.26:60588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDmJSUkh3e5AhEJOCPEwAAAbE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:16.129953 2026] [security2:error] [pid 643253:tid 643416] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/yas.php"] [unique_id "amuDmMjqbtjBYzqM1uYtvAAAACA"]
[Thu Jul 30 12:02:16.130086 2026] [security2:error] [pid 643253:tid 643416] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/yas.php"] [unique_id "amuDmMjqbtjBYzqM1uYtvAAAACA"]
[Thu Jul 30 12:02:16.168416 2026] [security2:error] [pid 642360:tid 642512] [client 2a03:2880:f800:20:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDl5SUkh3e5AhEJOCPDAABpUo"]
[Thu Jul 30 12:02:16.662600 2026] [security2:error] [pid 642360:tid 642523] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/water.php"] [unique_id "amuDmJSUkh3e5AhEJOCPGgAAAbA"]
[Thu Jul 30 12:02:16.662712 2026] [security2:error] [pid 642360:tid 642523] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/water.php"] [unique_id "amuDmJSUkh3e5AhEJOCPGgAAAbA"]
[Thu Jul 30 12:02:16.804011 2026] [core:notice] [pid 642360:tid 642534] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:16.807928 2026] [security2:error] [pid 642360:tid 642534] [client 103.215.74.26:60602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "741"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDmJSUkh3e5AhEJOCPGwAAAbs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:16.973765 2026] [security2:error] [pid 642360:tid 642493] [client 20.203.148.31:12574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.well-known/flower.php"] [unique_id "amuDmJSUkh3e5AhEJOCPHwAAAZI"]
[Thu Jul 30 12:02:17.238521 2026] [security2:error] [pid 642360:tid 642614] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/nano.php"] [unique_id "amuDmZSUkh3e5AhEJOCPJgAAAgs"]
[Thu Jul 30 12:02:17.238634 2026] [security2:error] [pid 642360:tid 642614] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/nano.php"] [unique_id "amuDmZSUkh3e5AhEJOCPJgAAAgs"]
[Thu Jul 30 12:02:17.515443 2026] [security2:error] [pid 642360:tid 642535] [client 20.203.148.31:18955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.well-known/xleet.php"] [unique_id "amuDmZSUkh3e5AhEJOCPKwAAAbw"]
[Thu Jul 30 12:02:17.529489 2026] [core:notice] [pid 642360:tid 642551] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:17.534498 2026] [security2:error] [pid 642360:tid 642551] [client 103.215.74.26:60610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDmZSUkh3e5AhEJOCPLAAAAcw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:17.733925 2026] [security2:error] [pid 642360:tid 642511] [client 188.166.98.61:33098] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.nordeste1.com"] [uri "/"] [unique_id "amuDmZSUkh3e5AhEJOCPMAAAAaQ"]
[Thu Jul 30 12:02:17.860871 2026] [security2:error] [pid 642360:tid 642589] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/moon.php"] [unique_id "amuDmZSUkh3e5AhEJOCPMwAAAfI"]
[Thu Jul 30 12:02:17.860995 2026] [security2:error] [pid 642360:tid 642589] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/moon.php"] [unique_id "amuDmZSUkh3e5AhEJOCPMwAAAfI"]
[Thu Jul 30 12:02:17.999108 2026] [security2:error] [pid 643253:tid 643442] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDmcjqbtjBYzqM1uYtwwAAOkQ"]
[Thu Jul 30 12:02:18.263095 2026] [core:notice] [pid 643253:tid 643482] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:18.269578 2026] [security2:error] [pid 643253:tid 643482] [client 103.215.74.26:60626] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDmsjqbtjBYzqM1uYtyAAAAGI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:18.421231 2026] [security2:error] [pid 642360:tid 642537] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-info.php"] [unique_id "amuDmpSUkh3e5AhEJOCPPwAAAb4"]
[Thu Jul 30 12:02:18.421338 2026] [security2:error] [pid 642360:tid 642537] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-info.php"] [unique_id "amuDmpSUkh3e5AhEJOCPPwAAAb4"]
[Thu Jul 30 12:02:18.697627 2026] [security2:error] [pid 642360:tid 642574] [client 20.203.148.31:12321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.well-known/acme-challenge/flower.php"] [unique_id "amuDmpSUkh3e5AhEJOCPQgAAAeM"]
[Thu Jul 30 12:02:18.952703 2026] [security2:error] [pid 642360:tid 642579] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/file5.php"] [unique_id "amuDmpSUkh3e5AhEJOCPSgAAAeg"]
[Thu Jul 30 12:02:18.952814 2026] [security2:error] [pid 642360:tid 642579] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/file5.php"] [unique_id "amuDmpSUkh3e5AhEJOCPSgAAAeg"]
[Thu Jul 30 12:02:18.954728 2026] [security2:error] [pid 643253:tid 643445] [client 20.215.191.139:50818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/files.php"] [unique_id "amuDmsjqbtjBYzqM1uYtzgAAAD0"]
[Thu Jul 30 12:02:18.962313 2026] [security2:error] [pid 643253:tid 643403] [client 176.241.66.87:61165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDmsjqbtjBYzqM1uYtzwAAABM"]
[Thu Jul 30 12:02:18.962420 2026] [security2:error] [pid 643253:tid 643403] [client 176.241.66.87:61165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDmsjqbtjBYzqM1uYtzwAAABM"]
[Thu Jul 30 12:02:18.996913 2026] [core:notice] [pid 642360:tid 642525] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:19.003430 2026] [security2:error] [pid 642360:tid 642525] [client 103.215.74.26:60650] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDmpSUkh3e5AhEJOCPSwAAAbI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:19.397905 2026] [security2:error] [pid 642360:tid 642534] [client 20.203.148.31:12588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.well-known/acme-challenge/xleet.php"] [unique_id "amuDm5SUkh3e5AhEJOCPTwAAAbs"]
[Thu Jul 30 12:02:19.620418 2026] [security2:error] [pid 643253:tid 643398] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/2000.php"] [unique_id "amuDm8jqbtjBYzqM1uYt0QAAAA4"]
[Thu Jul 30 12:02:19.620561 2026] [security2:error] [pid 643253:tid 643398] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/2000.php"] [unique_id "amuDm8jqbtjBYzqM1uYt0QAAAA4"]
[Thu Jul 30 12:02:19.676717 2026] [security2:error] [pid 643253:tid 643476] [client 20.215.191.139:51039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/gecko.php"] [unique_id "amuDm8jqbtjBYzqM1uYt0gAAAFw"]
[Thu Jul 30 12:02:19.739352 2026] [core:notice] [pid 643253:tid 643493] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:19.743362 2026] [security2:error] [pid 643253:tid 643493] [client 103.215.74.26:60654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDm8jqbtjBYzqM1uYt0wAAAG0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:20.199189 2026] [security2:error] [pid 642360:tid 642546] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/122.php"] [unique_id "amuDnJSUkh3e5AhEJOCPVwAAAcc"]
[Thu Jul 30 12:02:20.199319 2026] [security2:error] [pid 642360:tid 642546] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/122.php"] [unique_id "amuDnJSUkh3e5AhEJOCPVwAAAcc"]
[Thu Jul 30 12:02:20.460660 2026] [core:notice] [pid 643253:tid 643508] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:20.464596 2026] [security2:error] [pid 643253:tid 643508] [client 103.215.74.26:60668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDnMjqbtjBYzqM1uYt1QAAAHw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:20.509895 2026] [security2:error] [pid 642360:tid 642505] [client 20.215.191.139:50869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/zwso.php"] [unique_id "amuDnJSUkh3e5AhEJOCPWwAAAZ4"]
[Thu Jul 30 12:02:20.784592 2026] [security2:error] [pid 642360:tid 642513] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/mds.php"] [unique_id "amuDnJSUkh3e5AhEJOCPXwAAAaY"]
[Thu Jul 30 12:02:20.784724 2026] [security2:error] [pid 642360:tid 642513] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/mds.php"] [unique_id "amuDnJSUkh3e5AhEJOCPXwAAAaY"]
[Thu Jul 30 12:02:21.161820 2026] [security2:error] [pid 642360:tid 642519] [client 20.215.191.139:51064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/13.php"] [unique_id "amuDnZSUkh3e5AhEJOCPZQAAAaw"]
[Thu Jul 30 12:02:21.317077 2026] [security2:error] [pid 642360:tid 642517] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/zc-208.php"] [unique_id "amuDnZSUkh3e5AhEJOCPZgAAAao"]
[Thu Jul 30 12:02:21.317213 2026] [security2:error] [pid 642360:tid 642517] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/zc-208.php"] [unique_id "amuDnZSUkh3e5AhEJOCPZgAAAao"]
[Thu Jul 30 12:02:21.604678 2026] [security2:error] [pid 643253:tid 643392] [client 20.203.148.31:11160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amuDncjqbtjBYzqM1uYt1wAAAAg"]
[Thu Jul 30 12:02:21.873092 2026] [security2:error] [pid 642360:tid 642544] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/sid4.php"] [unique_id "amuDnZSUkh3e5AhEJOCPbwAAAcU"]
[Thu Jul 30 12:02:21.873202 2026] [security2:error] [pid 642360:tid 642544] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/sid4.php"] [unique_id "amuDnZSUkh3e5AhEJOCPbwAAAcU"]
[Thu Jul 30 12:02:22.041058 2026] [security2:error] [pid 643253:tid 643409] [client 20.215.191.139:51014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/ava.php"] [unique_id "amuDnsjqbtjBYzqM1uYt2gAAABk"]
[Thu Jul 30 12:02:22.118730 2026] [security2:error] [pid 642360:tid 642561] [client 20.203.148.31:2788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.well-known/pki-validation/autoload_classmap.php"] [unique_id "amuDnpSUkh3e5AhEJOCPdQAAAdY"]
[Thu Jul 30 12:02:22.438809 2026] [security2:error] [pid 642360:tid 642574] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/___proxy_subdomain_webdisk/wp-includes/l10n/"] [unique_id "amuDnpSUkh3e5AhEJOCPeQAAAeM"]
[Thu Jul 30 12:02:22.713901 2026] [security2:error] [pid 642360:tid 642503] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wmore1.php"] [unique_id "amuDnpSUkh3e5AhEJOCPfwAAAZw"]
[Thu Jul 30 12:02:22.714029 2026] [security2:error] [pid 642360:tid 642503] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wmore1.php"] [unique_id "amuDnpSUkh3e5AhEJOCPfwAAAZw"]
[Thu Jul 30 12:02:23.112218 2026] [security2:error] [pid 642360:tid 642523] [client 20.215.191.139:51062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/main.php"] [unique_id "amuDn5SUkh3e5AhEJOCPhgAAAbA"]
[Thu Jul 30 12:02:23.279567 2026] [security2:error] [pid 643253:tid 643490] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/solo1.php"] [unique_id "amuDn8jqbtjBYzqM1uYt3gAAAGo"]
[Thu Jul 30 12:02:23.279692 2026] [security2:error] [pid 643253:tid 643490] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/solo1.php"] [unique_id "amuDn8jqbtjBYzqM1uYt3gAAAGo"]
[Thu Jul 30 12:02:23.904010 2026] [security2:error] [pid 643253:tid 643384] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/___proxy_subdomain_webdisk/wp-includes/assets/"] [unique_id "amuDn8jqbtjBYzqM1uYt5gAAAAA"]
[Thu Jul 30 12:02:24.076529 2026] [security2:error] [pid 643253:tid 643470] [client 20.215.191.139:51022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/wp-file.php"] [unique_id "amuDoMjqbtjBYzqM1uYt6wAAAFY"]
[Thu Jul 30 12:02:24.203619 2026] [core:notice] [pid 643253:tid 643453] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:24.229907 2026] [security2:error] [pid 643253:tid 643400] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/___proxy_subdomain_webdisk/wp-includes/css/"] [unique_id "amuDoMjqbtjBYzqM1uYt8AAAABA"]
[Thu Jul 30 12:02:24.551752 2026] [security2:error] [pid 643253:tid 643457] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/public/css.php"] [unique_id "amuDoMjqbtjBYzqM1uYt-AAAAEk"]
[Thu Jul 30 12:02:24.551858 2026] [security2:error] [pid 643253:tid 643457] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/public/css.php"] [unique_id "amuDoMjqbtjBYzqM1uYt-AAAAEk"]
[Thu Jul 30 12:02:25.155071 2026] [security2:error] [pid 643253:tid 643458] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/output.php"] [unique_id "amuDocjqbtjBYzqM1uYuAwAAAEo"]
[Thu Jul 30 12:02:25.155177 2026] [security2:error] [pid 643253:tid 643458] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/output.php"] [unique_id "amuDocjqbtjBYzqM1uYuAwAAAEo"]
[Thu Jul 30 12:02:25.755379 2026] [security2:error] [pid 643253:tid 643468] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-file-120.php"] [unique_id "amuDocjqbtjBYzqM1uYuDwAAAFQ"]
[Thu Jul 30 12:02:25.755477 2026] [security2:error] [pid 643253:tid 643468] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-file-120.php"] [unique_id "amuDocjqbtjBYzqM1uYuDwAAAFQ"]
[Thu Jul 30 12:02:25.814880 2026] [security2:error] [pid 643253:tid 643478] [client 20.203.148.31:13640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.well-known/pki-validation/flower.php"] [unique_id "amuDocjqbtjBYzqM1uYuEAAAAF4"]
[Thu Jul 30 12:02:26.232448 2026] [core:notice] [pid 643253:tid 643443] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:26.239480 2026] [security2:error] [pid 643253:tid 643443] [client 103.215.74.26:21906] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDosjqbtjBYzqM1uYuFgAAADs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:26.329863 2026] [security2:error] [pid 643253:tid 643392] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/special.php"] [unique_id "amuDosjqbtjBYzqM1uYuHQAAAAg"]
[Thu Jul 30 12:02:26.330178 2026] [security2:error] [pid 643253:tid 643392] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/special.php"] [unique_id "amuDosjqbtjBYzqM1uYuHQAAAAg"]
[Thu Jul 30 12:02:26.343156 2026] [security2:error] [pid 643253:tid 643426] [client 114.119.142.72:29913] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "alseermarine.com"] [uri "/robots.txt"] [unique_id "amuDosjqbtjBYzqM1uYuHgAAACo"], referer: https://alseermarine.com/robots.txt
[Thu Jul 30 12:02:26.556094 2026] [security2:error] [pid 643253:tid 643397] [client 20.203.148.31:12383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.well-known/pki-validation/xleet.php"] [unique_id "amuDosjqbtjBYzqM1uYuSgAAAA0"]
[Thu Jul 30 12:02:26.745027 2026] [security2:error] [pid 643253:tid 643432] [client 20.203.148.31:56875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/json.php"] [unique_id "amuDosjqbtjBYzqM1uYuTAAAADA"]
[Thu Jul 30 12:02:26.871950 2026] [security2:error] [pid 643253:tid 643411] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/as.php"] [unique_id "amuDosjqbtjBYzqM1uYuTwAAABs"]
[Thu Jul 30 12:02:26.872075 2026] [security2:error] [pid 643253:tid 643411] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/as.php"] [unique_id "amuDosjqbtjBYzqM1uYuTwAAABs"]
[Thu Jul 30 12:02:26.976947 2026] [core:notice] [pid 643253:tid 643453] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:26.980889 2026] [security2:error] [pid 643253:tid 643453] [client 103.215.74.26:21908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "773"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDosjqbtjBYzqM1uYuUAAAAEU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:27.303471 2026] [security2:error] [pid 643253:tid 643387] [client 20.215.191.139:50870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/wp-signin.php"] [unique_id "amuDo8jqbtjBYzqM1uYuVwAAAAM"]
[Thu Jul 30 12:02:27.402873 2026] [security2:error] [pid 643253:tid 643502] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/cgi-bin/index.php"] [unique_id "amuDo8jqbtjBYzqM1uYuWAAAAHY"]
[Thu Jul 30 12:02:27.404592 2026] [security2:error] [pid 643253:tid 643502] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/cgi-bin/index.php"] [unique_id "amuDo8jqbtjBYzqM1uYuWAAAAHY"]
[Thu Jul 30 12:02:27.959285 2026] [security2:error] [pid 643253:tid 643486] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/w1px.php"] [unique_id "amuDo8jqbtjBYzqM1uYuYwAAAGY"]
[Thu Jul 30 12:02:27.959395 2026] [security2:error] [pid 643253:tid 643486] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/w1px.php"] [unique_id "amuDo8jqbtjBYzqM1uYuYwAAAGY"]
[Thu Jul 30 12:02:28.098909 2026] [security2:error] [pid 643253:tid 643459] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDo8jqbtjBYzqM1uYuXAAASwA"]
[Thu Jul 30 12:02:28.459630 2026] [security2:error] [pid 643253:tid 643389] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/js.php"] [unique_id "amuDpMjqbtjBYzqM1uYucwAAAAU"]
[Thu Jul 30 12:02:28.459757 2026] [security2:error] [pid 643253:tid 643389] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/js.php"] [unique_id "amuDpMjqbtjBYzqM1uYucwAAAAU"]
[Thu Jul 30 12:02:28.519423 2026] [core:notice] [pid 643253:tid 643478] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:28.523445 2026] [security2:error] [pid 643253:tid 643478] [client 103.215.74.26:21914] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDpMjqbtjBYzqM1uYudAAAAF4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:28.856731 2026] [security2:error] [pid 643253:tid 643415] [client 20.215.191.139:51019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/simi.php"] [unique_id "amuDpMjqbtjBYzqM1uYufQAAAB8"]
[Thu Jul 30 12:02:28.972161 2026] [security2:error] [pid 643253:tid 643420] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/core.php"] [unique_id "amuDpMjqbtjBYzqM1uYufgAAACQ"]
[Thu Jul 30 12:02:28.972280 2026] [security2:error] [pid 643253:tid 643420] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/core.php"] [unique_id "amuDpMjqbtjBYzqM1uYufgAAACQ"]
[Thu Jul 30 12:02:29.253571 2026] [core:notice] [pid 643253:tid 643500] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:29.257663 2026] [security2:error] [pid 643253:tid 643500] [client 103.215.74.26:21916] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDpcjqbtjBYzqM1uYuggAAAHQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:29.408117 2026] [security2:error] [pid 643253:tid 643384] [client 20.215.191.139:50835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/wp-conf.php"] [unique_id "amuDpcjqbtjBYzqM1uYuiQAAAAA"]
[Thu Jul 30 12:02:29.480350 2026] [security2:error] [pid 643253:tid 643401] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/fffm.php"] [unique_id "amuDpcjqbtjBYzqM1uYuigAAABE"]
[Thu Jul 30 12:02:29.480461 2026] [security2:error] [pid 643253:tid 643401] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/fffm.php"] [unique_id "amuDpcjqbtjBYzqM1uYuigAAABE"]
[Thu Jul 30 12:02:29.989370 2026] [core:notice] [pid 643253:tid 643424] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:29.994087 2026] [security2:error] [pid 643253:tid 643424] [client 103.215.74.26:21924] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDpcjqbtjBYzqM1uYukQAAACg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:30.029472 2026] [security2:error] [pid 643253:tid 643430] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ww.php"] [unique_id "amuDpsjqbtjBYzqM1uYukwAAAC4"]
[Thu Jul 30 12:02:30.029614 2026] [security2:error] [pid 643253:tid 643430] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ww.php"] [unique_id "amuDpsjqbtjBYzqM1uYukwAAAC4"]
[Thu Jul 30 12:02:30.084993 2026] [core:notice] [pid 643253:tid 643499] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:30.142949 2026] [security2:error] [pid 643253:tid 643441] [client 20.203.148.31:41403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/mini.php"] [unique_id "amuDpsjqbtjBYzqM1uYumAAAADk"]
[Thu Jul 30 12:02:30.155636 2026] [security2:error] [pid 643253:tid 643400] [client 176.241.66.87:54576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDpsjqbtjBYzqM1uYumQAAABA"]
[Thu Jul 30 12:02:30.155735 2026] [security2:error] [pid 643253:tid 643400] [client 176.241.66.87:54576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDpsjqbtjBYzqM1uYumQAAABA"]
[Thu Jul 30 12:02:30.288330 2026] [security2:error] [pid 643253:tid 643477] [client 20.215.191.139:51034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/WZGHHra0r3.php"] [unique_id "amuDpsjqbtjBYzqM1uYunAAAAF0"]
[Thu Jul 30 12:02:30.421010 2026] [proxy:error] [pid 643253:tid 643391] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:02:30.421093 2026] [proxy_http:error] [pid 643253:tid 643391] [client 193.47.62.167:41548] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:02:30.421657 2026] [proxy:error] [pid 643253:tid 643391] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:02:30.421699 2026] [proxy_http:error] [pid 643253:tid 643391] [client 193.47.62.167:41548] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:02:30.573262 2026] [security2:error] [pid 643253:tid 643485] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/domvf.php"] [unique_id "amuDpsjqbtjBYzqM1uYuoQAAAGU"]
[Thu Jul 30 12:02:30.573399 2026] [security2:error] [pid 643253:tid 643485] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/domvf.php"] [unique_id "amuDpsjqbtjBYzqM1uYuoQAAAGU"]
[Thu Jul 30 12:02:30.813206 2026] [core:notice] [pid 643253:tid 643417] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:30.817174 2026] [security2:error] [pid 643253:tid 643417] [client 103.215.74.26:21936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDpsjqbtjBYzqM1uYuqQAAACE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:31.096518 2026] [security2:error] [pid 643253:tid 643488] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/echkm.php"] [unique_id "amuDp8jqbtjBYzqM1uYurgAAAGg"]
[Thu Jul 30 12:02:31.096690 2026] [security2:error] [pid 643253:tid 643488] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/echkm.php"] [unique_id "amuDp8jqbtjBYzqM1uYurgAAAGg"]
[Thu Jul 30 12:02:31.100031 2026] [security2:error] [pid 643253:tid 643468] [client 20.215.191.139:50874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/bala.php"] [unique_id "amuDp8jqbtjBYzqM1uYurwAAAFQ"]
[Thu Jul 30 12:02:31.260154 2026] [security2:error] [pid 643253:tid 643280] [remote 97.74.93.24:40646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/wp-login.php"] [unique_id "amuDp8jqbtjBYzqM1uYutgAAWhk"]
[Thu Jul 30 12:02:31.528693 2026] [core:notice] [pid 643253:tid 643446] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:31.532799 2026] [security2:error] [pid 643253:tid 643446] [client 103.215.74.26:21938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDp8jqbtjBYzqM1uYuvQAAAD4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:31.655721 2026] [security2:error] [pid 643253:tid 643450] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ano.php"] [unique_id "amuDp8jqbtjBYzqM1uYuvwAAAEI"]
[Thu Jul 30 12:02:31.655882 2026] [security2:error] [pid 643253:tid 643450] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ano.php"] [unique_id "amuDp8jqbtjBYzqM1uYuvwAAAEI"]
[Thu Jul 30 12:02:31.900334 2026] [security2:error] [pid 643253:tid 643438] [client 74.7.244.51:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.topmoversandpackerssharjah.art"] [uri "/index.php"] [unique_id "amuDp8jqbtjBYzqM1uYuvgAANh8"]
[Thu Jul 30 12:02:31.900367 2026] [security2:error] [pid 643253:tid 643438] [client 74.7.244.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.topmoversandpackerssharjah.art"] [uri "/index.php"] [unique_id "amuDp8jqbtjBYzqM1uYuvgAANh8"]
[Thu Jul 30 12:02:32.180814 2026] [security2:error] [pid 643253:tid 643384] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ah25.php"] [unique_id "amuDqMjqbtjBYzqM1uYuxgAAAAA"]
[Thu Jul 30 12:02:32.180923 2026] [security2:error] [pid 643253:tid 643384] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ah25.php"] [unique_id "amuDqMjqbtjBYzqM1uYuxgAAAAA"]
[Thu Jul 30 12:02:32.193232 2026] [security2:error] [pid 643253:tid 643278] [remote 57.141.0.39:28072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuDqMjqbtjBYzqM1uYuxwAAdBc"]
[Thu Jul 30 12:02:32.277436 2026] [core:notice] [pid 643253:tid 643470] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:32.281389 2026] [security2:error] [pid 643253:tid 643470] [client 103.215.74.26:21948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDqMjqbtjBYzqM1uYuywAAAFY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:32.372332 2026] [security2:error] [pid 643253:tid 643407] [client 20.203.148.31:62018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/chosen.php"] [unique_id "amuDqMjqbtjBYzqM1uYuzAAAABc"]
[Thu Jul 30 12:02:32.446249 2026] [security2:error] [pid 643253:tid 643489] [client 20.215.191.139:51050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/bk.php"] [unique_id "amuDqMjqbtjBYzqM1uYuzQAAAGk"]
[Thu Jul 30 12:02:32.688029 2026] [security2:error] [pid 643253:tid 643425] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/term.php"] [unique_id "amuDqMjqbtjBYzqM1uYu0QAAACk"]
[Thu Jul 30 12:02:32.688154 2026] [security2:error] [pid 643253:tid 643425] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/term.php"] [unique_id "amuDqMjqbtjBYzqM1uYu0QAAACk"]
[Thu Jul 30 12:02:33.010070 2026] [core:notice] [pid 643253:tid 643400] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:33.016823 2026] [security2:error] [pid 643253:tid 643400] [client 103.215.74.26:4326] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDqcjqbtjBYzqM1uYu1gAAABA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:33.253491 2026] [security2:error] [pid 643253:tid 643391] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/we.php"] [unique_id "amuDqcjqbtjBYzqM1uYu3QAAAAc"]
[Thu Jul 30 12:02:33.253605 2026] [security2:error] [pid 643253:tid 643391] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/we.php"] [unique_id "amuDqcjqbtjBYzqM1uYu3QAAAAc"]
[Thu Jul 30 12:02:33.367700 2026] [security2:error] [pid 643253:tid 643457] [client 20.215.191.139:51008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/ahax.php"] [unique_id "amuDqcjqbtjBYzqM1uYu3gAAAEk"]
[Thu Jul 30 12:02:33.762450 2026] [core:notice] [pid 643253:tid 643404] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:33.766377 2026] [security2:error] [pid 643253:tid 643404] [client 103.215.74.26:4328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDqcjqbtjBYzqM1uYu6AAAABQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:33.810183 2026] [security2:error] [pid 643253:tid 643456] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/zip-onee.php"] [unique_id "amuDqcjqbtjBYzqM1uYu6QAAAEg"]
[Thu Jul 30 12:02:33.810283 2026] [security2:error] [pid 643253:tid 643456] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/zip-onee.php"] [unique_id "amuDqcjqbtjBYzqM1uYu6QAAAEg"]
[Thu Jul 30 12:02:34.305755 2026] [security2:error] [pid 643253:tid 643460] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/il.php"] [unique_id "amuDqsjqbtjBYzqM1uYu8AAAAEw"]
[Thu Jul 30 12:02:34.305865 2026] [security2:error] [pid 643253:tid 643460] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/il.php"] [unique_id "amuDqsjqbtjBYzqM1uYu8AAAAEw"]
[Thu Jul 30 12:02:34.439048 2026] [security2:error] [pid 643253:tid 643416] [client 20.203.148.31:58535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/kj.php"] [unique_id "amuDqsjqbtjBYzqM1uYu8QAAACA"]
[Thu Jul 30 12:02:34.529845 2026] [core:notice] [pid 643253:tid 643507] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:34.534200 2026] [security2:error] [pid 643253:tid 643507] [client 103.215.74.26:4330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDqsjqbtjBYzqM1uYu8gAAAHs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:34.832557 2026] [security2:error] [pid 643253:tid 643505] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/one.php"] [unique_id "amuDqsjqbtjBYzqM1uYu_QAAAHk"]
[Thu Jul 30 12:02:34.832654 2026] [security2:error] [pid 643253:tid 643505] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/one.php"] [unique_id "amuDqsjqbtjBYzqM1uYu_QAAAHk"]
[Thu Jul 30 12:02:34.890642 2026] [security2:error] [pid 643253:tid 643440] [client 217.165.158.188:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nafmedical.com"] [uri "/index.php"] [unique_id "amuDqsjqbtjBYzqM1uYu8wAAOCs"]
[Thu Jul 30 12:02:34.910883 2026] [core:notice] [pid 643253:tid 643484] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:35.279717 2026] [core:notice] [pid 643253:tid 643490] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:35.283784 2026] [security2:error] [pid 643253:tid 643490] [client 103.215.74.26:4344] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDq8jqbtjBYzqM1uYvCAAAAGo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:35.385470 2026] [security2:error] [pid 643253:tid 643449] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/002.php"] [unique_id "amuDq8jqbtjBYzqM1uYvCQAAAEE"]
[Thu Jul 30 12:02:35.385574 2026] [security2:error] [pid 643253:tid 643449] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/002.php"] [unique_id "amuDq8jqbtjBYzqM1uYvCQAAAEE"]
[Thu Jul 30 12:02:35.723099 2026] [security2:error] [pid 643253:tid 643405] [client 20.203.148.31:20055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.wp-cli/autoload_classmap.php"] [unique_id "amuDq8jqbtjBYzqM1uYvEAAAABU"]
[Thu Jul 30 12:02:35.924062 2026] [security2:error] [pid 643253:tid 643397] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/file1.php"] [unique_id "amuDq8jqbtjBYzqM1uYvEQAAAA0"]
[Thu Jul 30 12:02:35.924184 2026] [security2:error] [pid 643253:tid 643397] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/file1.php"] [unique_id "amuDq8jqbtjBYzqM1uYvEQAAAA0"]
[Thu Jul 30 12:02:36.223097 2026] [core:notice] [pid 643253:tid 643464] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:36.449018 2026] [security2:error] [pid 643253:tid 643466] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/akimet.php"] [unique_id "amuDrMjqbtjBYzqM1uYvGwAAAFI"]
[Thu Jul 30 12:02:36.449175 2026] [security2:error] [pid 643253:tid 643466] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/akimet.php"] [unique_id "amuDrMjqbtjBYzqM1uYvGwAAAFI"]
[Thu Jul 30 12:02:36.676140 2026] [security2:error] [pid 643253:tid 643435] [client 20.203.148.31:16544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.wp-cli/flower.php"] [unique_id "amuDrMjqbtjBYzqM1uYvIQAAADM"]
[Thu Jul 30 12:02:37.011880 2026] [core:notice] [pid 643253:tid 643312] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:37.017068 2026] [security2:error] [pid 643253:tid 643498] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/reop3.php"] [unique_id "amuDrcjqbtjBYzqM1uYvJgAAAHI"]
[Thu Jul 30 12:02:37.017150 2026] [security2:error] [pid 643253:tid 643498] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/reop3.php"] [unique_id "amuDrcjqbtjBYzqM1uYvJgAAAHI"]
[Thu Jul 30 12:02:37.186413 2026] [security2:error] [pid 643253:tid 643418] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDrMjqbtjBYzqM1uYvHAAAIjY"]
[Thu Jul 30 12:02:37.540332 2026] [security2:error] [pid 643253:tid 643488] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/h.php"] [unique_id "amuDrcjqbtjBYzqM1uYvLQAAAGg"]
[Thu Jul 30 12:02:37.540488 2026] [security2:error] [pid 643253:tid 643488] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/h.php"] [unique_id "amuDrcjqbtjBYzqM1uYvLQAAAGg"]
[Thu Jul 30 12:02:37.610192 2026] [core:notice] [pid 643253:tid 643507] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:37.782687 2026] [security2:error] [pid 643253:tid 643468] [client 20.203.148.31:16571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.wp-cli/xleet.php"] [unique_id "amuDrcjqbtjBYzqM1uYvNAAAAFQ"]
[Thu Jul 30 12:02:38.065309 2026] [security2:error] [pid 643253:tid 643440] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/2x.php"] [unique_id "amuDrsjqbtjBYzqM1uYvPAAAADg"]
[Thu Jul 30 12:02:38.065416 2026] [security2:error] [pid 643253:tid 643440] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/2x.php"] [unique_id "amuDrsjqbtjBYzqM1uYvPAAAADg"]
[Thu Jul 30 12:02:38.302501 2026] [security2:error] [pid 643253:tid 643495] [client 2a03:2880:f800:23:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDrcjqbtjBYzqM1uYvLwAAbz4"]
[Thu Jul 30 12:02:38.610118 2026] [security2:error] [pid 643253:tid 643509] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/petx.php"] [unique_id "amuDrsjqbtjBYzqM1uYvRwAAAH0"]
[Thu Jul 30 12:02:38.610225 2026] [security2:error] [pid 643253:tid 643509] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/petx.php"] [unique_id "amuDrsjqbtjBYzqM1uYvRwAAAH0"]
[Thu Jul 30 12:02:39.154330 2026] [security2:error] [pid 643253:tid 643489] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/zxz.php"] [unique_id "amuDr8jqbtjBYzqM1uYvTwAAAGk"]
[Thu Jul 30 12:02:39.154462 2026] [security2:error] [pid 643253:tid 643489] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/zxz.php"] [unique_id "amuDr8jqbtjBYzqM1uYvTwAAAGk"]
[Thu Jul 30 12:02:39.547951 2026] [security2:error] [pid 643253:tid 643501] [client 20.203.148.31:57978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/wp-files.php"] [unique_id "amuDr8jqbtjBYzqM1uYvVwAAAHU"]
[Thu Jul 30 12:02:39.721824 2026] [security2:error] [pid 643253:tid 643400] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/2.php"] [unique_id "amuDr8jqbtjBYzqM1uYvWgAAABA"]
[Thu Jul 30 12:02:39.721944 2026] [security2:error] [pid 643253:tid 643400] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/2.php"] [unique_id "amuDr8jqbtjBYzqM1uYvWgAAABA"]
[Thu Jul 30 12:02:40.124519 2026] [security2:error] [pid 643253:tid 643500] [client 20.203.148.31:17569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amuDsMjqbtjBYzqM1uYvYQAAAHQ"]
[Thu Jul 30 12:02:40.271924 2026] [security2:error] [pid 643253:tid 643386] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/op.php"] [unique_id "amuDsMjqbtjBYzqM1uYvYgAAAAI"]
[Thu Jul 30 12:02:40.272065 2026] [security2:error] [pid 643253:tid 643386] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/op.php"] [unique_id "amuDsMjqbtjBYzqM1uYvYgAAAAI"]
[Thu Jul 30 12:02:40.836393 2026] [security2:error] [pid 643253:tid 643418] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/a5.php"] [unique_id "amuDsMjqbtjBYzqM1uYvagAAACI"]
[Thu Jul 30 12:02:40.836500 2026] [security2:error] [pid 643253:tid 643418] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/a5.php"] [unique_id "amuDsMjqbtjBYzqM1uYvagAAACI"]
[Thu Jul 30 12:02:41.076833 2026] [core:notice] [pid 643253:tid 643451] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:41.080756 2026] [security2:error] [pid 643253:tid 643451] [client 103.215.74.26:4354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDscjqbtjBYzqM1uYvdQAAAEM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:41.254683 2026] [security2:error] [pid 643253:tid 643488] [client 41.220.17.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuDscjqbtjBYzqM1uYvdAAAAGg"], referer: https://cnpinyin.com/
[Thu Jul 30 12:02:41.301944 2026] [security2:error] [pid 643253:tid 643459] [client 176.241.66.87:63108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDscjqbtjBYzqM1uYvdwAAAEs"]
[Thu Jul 30 12:02:41.302075 2026] [security2:error] [pid 643253:tid 643459] [client 176.241.66.87:63108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDscjqbtjBYzqM1uYvdwAAAEs"]
[Thu Jul 30 12:02:41.411135 2026] [security2:error] [pid 643253:tid 643409] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ws80.php"] [unique_id "amuDscjqbtjBYzqM1uYveAAAABk"]
[Thu Jul 30 12:02:41.411247 2026] [security2:error] [pid 643253:tid 643409] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ws80.php"] [unique_id "amuDscjqbtjBYzqM1uYveAAAABk"]
[Thu Jul 30 12:02:41.620217 2026] [security2:error] [pid 643253:tid 643443] [client 20.203.148.31:61298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/wp-setup.php"] [unique_id "amuDscjqbtjBYzqM1uYvfwAAADs"]
[Thu Jul 30 12:02:41.645198 2026] [core:notice] [pid 643253:tid 643468] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:41.985220 2026] [security2:error] [pid 643253:tid 643454] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/xa.php"] [unique_id "amuDscjqbtjBYzqM1uYvhAAAAEY"]
[Thu Jul 30 12:02:41.985332 2026] [security2:error] [pid 643253:tid 643454] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/xa.php"] [unique_id "amuDscjqbtjBYzqM1uYvhAAAAEY"]
[Thu Jul 30 12:02:42.321395 2026] [security2:error] [pid 643253:tid 643455] [client 37.120.155.179:38726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.155.120.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuDssjqbtjBYzqM1uYviAAAAEc"]
[Thu Jul 30 12:02:42.321496 2026] [security2:error] [pid 643253:tid 643455] [client 37.120.155.179:38726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuDssjqbtjBYzqM1uYviAAAAEc"]
[Thu Jul 30 12:02:42.524482 2026] [security2:error] [pid 643253:tid 643401] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/asd67.php"] [unique_id "amuDssjqbtjBYzqM1uYvjgAAABE"]
[Thu Jul 30 12:02:42.524603 2026] [security2:error] [pid 643253:tid 643401] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/asd67.php"] [unique_id "amuDssjqbtjBYzqM1uYvjgAAABE"]
[Thu Jul 30 12:02:42.765138 2026] [security2:error] [pid 643253:tid 643449] [client 20.203.148.31:17092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/network/flower.php"] [unique_id "amuDssjqbtjBYzqM1uYvkgAAAEE"]
[Thu Jul 30 12:02:43.056822 2026] [security2:error] [pid 643253:tid 643420] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/bk.php"] [unique_id "amuDs8jqbtjBYzqM1uYvmQAAACQ"]
[Thu Jul 30 12:02:43.056940 2026] [security2:error] [pid 643253:tid 643420] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/bk.php"] [unique_id "amuDs8jqbtjBYzqM1uYvmQAAACQ"]
[Thu Jul 30 12:02:43.646873 2026] [security2:error] [pid 643253:tid 643386] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-links.php"] [unique_id "amuDs8jqbtjBYzqM1uYvpAAAAAI"]
[Thu Jul 30 12:02:43.647007 2026] [security2:error] [pid 643253:tid 643386] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-links.php"] [unique_id "amuDs8jqbtjBYzqM1uYvpAAAAAI"]
[Thu Jul 30 12:02:44.206877 2026] [security2:error] [pid 643253:tid 643445] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/mosty.php"] [unique_id "amuDtMjqbtjBYzqM1uYvrAAAAD0"]
[Thu Jul 30 12:02:44.207026 2026] [security2:error] [pid 643253:tid 643445] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/mosty.php"] [unique_id "amuDtMjqbtjBYzqM1uYvrAAAAD0"]
[Thu Jul 30 12:02:44.646361 2026] [security2:error] [pid 643253:tid 643428] [client 20.203.148.31:27306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/network/xleet.php/wp-content/flower.php"] [unique_id "amuDtMjqbtjBYzqM1uYvsQAAACw"]
[Thu Jul 30 12:02:44.736951 2026] [security2:error] [pid 643253:tid 643507] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/sump3.php"] [unique_id "amuDtMjqbtjBYzqM1uYvtQAAAHs"]
[Thu Jul 30 12:02:44.737114 2026] [security2:error] [pid 643253:tid 643507] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/sump3.php"] [unique_id "amuDtMjqbtjBYzqM1uYvtQAAAHs"]
[Thu Jul 30 12:02:45.284954 2026] [security2:error] [pid 643253:tid 643484] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/first.php"] [unique_id "amuDtcjqbtjBYzqM1uYvxAAAAGQ"]
[Thu Jul 30 12:02:45.285073 2026] [security2:error] [pid 643253:tid 643484] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/first.php"] [unique_id "amuDtcjqbtjBYzqM1uYvxAAAAGQ"]
[Thu Jul 30 12:02:45.715970 2026] [security2:error] [pid 643253:tid 643459] [client 172.237.109.114:11354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDtcjqbtjBYzqM1uYvvgAAAEs"]
[Thu Jul 30 12:02:45.716757 2026] [security2:error] [pid 643253:tid 643389] [client 172.237.109.114:17460] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDtcjqbtjBYzqM1uYvvQAAAAU"]
[Thu Jul 30 12:02:45.728780 2026] [security2:error] [pid 643253:tid 643409] [client 172.237.109.114:21959] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDtcjqbtjBYzqM1uYvwAAAABk"]
[Thu Jul 30 12:02:45.735195 2026] [security2:error] [pid 643253:tid 643493] [client 172.237.109.114:17804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDtcjqbtjBYzqM1uYvvAAAAG0"]
[Thu Jul 30 12:02:45.739050 2026] [security2:error] [pid 643253:tid 643437] [client 172.237.109.114:24530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDtcjqbtjBYzqM1uYvvwAAADU"]
[Thu Jul 30 12:02:45.871802 2026] [security2:error] [pid 643253:tid 643384] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/acp.php"] [unique_id "amuDtcjqbtjBYzqM1uYvzwAAAAA"]
[Thu Jul 30 12:02:45.871913 2026] [security2:error] [pid 643253:tid 643384] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/acp.php"] [unique_id "amuDtcjqbtjBYzqM1uYvzwAAAAA"]
[Thu Jul 30 12:02:46.457266 2026] [security2:error] [pid 643253:tid 643466] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-good.php"] [unique_id "amuDtsjqbtjBYzqM1uYv2QAAAFI"]
[Thu Jul 30 12:02:46.457398 2026] [security2:error] [pid 643253:tid 643466] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-good.php"] [unique_id "amuDtsjqbtjBYzqM1uYv2QAAAFI"]
[Thu Jul 30 12:02:46.652581 2026] [security2:error] [pid 643253:tid 643414] [client 20.203.148.31:33458] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.revolutionary-technologies.com"] [uri "/1.php"] [unique_id "amuDtsjqbtjBYzqM1uYv3gAAAB4"]
[Thu Jul 30 12:02:46.652719 2026] [security2:error] [pid 643253:tid 643414] [client 20.203.148.31:33458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/1.php"] [unique_id "amuDtsjqbtjBYzqM1uYv3gAAAB4"]
[Thu Jul 30 12:02:46.802690 2026] [core:notice] [pid 643253:tid 643387] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:46.807060 2026] [security2:error] [pid 643253:tid 643387] [client 103.215.74.26:33062] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDtsjqbtjBYzqM1uYv3wAAAAM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:47.054778 2026] [security2:error] [pid 643253:tid 643439] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDtsjqbtjBYzqM1uYv2gAAN24"]
[Thu Jul 30 12:02:47.057597 2026] [security2:error] [pid 643253:tid 643465] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/daerl3.php"] [unique_id "amuDt8jqbtjBYzqM1uYv5AAAAFE"]
[Thu Jul 30 12:02:47.057722 2026] [security2:error] [pid 643253:tid 643465] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/daerl3.php"] [unique_id "amuDt8jqbtjBYzqM1uYv5AAAAFE"]
[Thu Jul 30 12:02:47.222429 2026] [security2:error] [pid 643253:tid 643371] [remote 74.7.241.60:34698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/article.php"] [unique_id "amuDt8jqbtjBYzqM1uYv6AAABnQ"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/main_image_6a3229a631e84.jpg
[Thu Jul 30 12:02:47.534306 2026] [core:notice] [pid 643253:tid 643498] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:47.538632 2026] [security2:error] [pid 643253:tid 643498] [client 103.215.74.26:33074] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDt8jqbtjBYzqM1uYv7QAAAHI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:47.614193 2026] [security2:error] [pid 643253:tid 643432] [client 20.203.148.31:2958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/admin.php"] [unique_id "amuDt8jqbtjBYzqM1uYv7gAAADA"]
[Thu Jul 30 12:02:47.672169 2026] [security2:error] [pid 643253:tid 643507] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/php5.php"] [unique_id "amuDt8jqbtjBYzqM1uYv9gAAAHs"]
[Thu Jul 30 12:02:47.672286 2026] [security2:error] [pid 643253:tid 643507] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/php5.php"] [unique_id "amuDt8jqbtjBYzqM1uYv9gAAAHs"]
[Thu Jul 30 12:02:48.222267 2026] [security2:error] [pid 643253:tid 643495] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/xoot.php"] [unique_id "amuDuMjqbtjBYzqM1uYwAQAAAG8"]
[Thu Jul 30 12:02:48.222390 2026] [security2:error] [pid 643253:tid 643495] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/xoot.php"] [unique_id "amuDuMjqbtjBYzqM1uYwAQAAAG8"]
[Thu Jul 30 12:02:48.302568 2026] [core:notice] [pid 643253:tid 643511] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:48.306862 2026] [security2:error] [pid 643253:tid 643511] [client 103.215.74.26:33086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDuMjqbtjBYzqM1uYwAgAAAH8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:48.532627 2026] [security2:error] [pid 643253:tid 643462] [client 20.203.148.31:41050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/defaults.php"] [unique_id "amuDuMjqbtjBYzqM1uYwBgAAAE4"]
[Thu Jul 30 12:02:48.616092 2026] [security2:error] [pid 643253:tid 643450] [client 20.203.148.31:12854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/as.php"] [unique_id "amuDuMjqbtjBYzqM1uYwCgAAAEI"]
[Thu Jul 30 12:02:48.717329 2026] [security2:error] [pid 643253:tid 643394] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/clxcc.php"] [unique_id "amuDuMjqbtjBYzqM1uYwEgAAAAo"]
[Thu Jul 30 12:02:48.717443 2026] [security2:error] [pid 643253:tid 643394] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/clxcc.php"] [unique_id "amuDuMjqbtjBYzqM1uYwEgAAAAo"]
[Thu Jul 30 12:02:49.041861 2026] [core:notice] [pid 643253:tid 643396] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:49.046275 2026] [security2:error] [pid 643253:tid 643396] [client 103.215.74.26:33096] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDucjqbtjBYzqM1uYwHgAAAAw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:49.212834 2026] [security2:error] [pid 643253:tid 643430] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ai.php"] [unique_id "amuDucjqbtjBYzqM1uYwIgAAAC4"]
[Thu Jul 30 12:02:49.212963 2026] [security2:error] [pid 643253:tid 643430] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ai.php"] [unique_id "amuDucjqbtjBYzqM1uYwIgAAAC4"]
[Thu Jul 30 12:02:49.763735 2026] [core:notice] [pid 643253:tid 643406] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:49.768364 2026] [security2:error] [pid 643253:tid 643406] [client 103.215.74.26:33098] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDucjqbtjBYzqM1uYwKQAAABY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:49.772779 2026] [security2:error] [pid 643253:tid 643388] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/nwflm.php"] [unique_id "amuDucjqbtjBYzqM1uYwKgAAAAQ"]
[Thu Jul 30 12:02:49.772870 2026] [security2:error] [pid 643253:tid 643388] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/nwflm.php"] [unique_id "amuDucjqbtjBYzqM1uYwKgAAAAQ"]
[Thu Jul 30 12:02:50.050998 2026] [security2:error] [pid 643253:tid 643435] [client 20.203.148.31:2945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/autoload_classmap.php"] [unique_id "amuDusjqbtjBYzqM1uYwLgAAADM"]
[Thu Jul 30 12:02:50.353535 2026] [security2:error] [pid 643253:tid 643413] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/hypo.php"] [unique_id "amuDusjqbtjBYzqM1uYwNAAAAB0"]
[Thu Jul 30 12:02:50.353663 2026] [security2:error] [pid 643253:tid 643413] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/hypo.php"] [unique_id "amuDusjqbtjBYzqM1uYwNAAAAB0"]
[Thu Jul 30 12:02:50.517957 2026] [core:notice] [pid 643253:tid 643467] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:50.523247 2026] [security2:error] [pid 643253:tid 643467] [client 103.215.74.26:33102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDusjqbtjBYzqM1uYwOAAAAFM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:50.613749 2026] [security2:error] [pid 643253:tid 643408] [client 57.141.0.2:40150] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuDusjqbtjBYzqM1uYwMAAAGAo"], referer: https://igetvape-australia.com/product-category/alibarbar-ingot-9000-puffs/?add-to-cart=919
[Thu Jul 30 12:02:50.648703 2026] [security2:error] [pid 643253:tid 643442] [client 20.203.148.31:33434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/back.php"] [unique_id "amuDusjqbtjBYzqM1uYwOgAAADo"]
[Thu Jul 30 12:02:50.846313 2026] [core:notice] [pid 643253:tid 643476] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:50.870676 2026] [security2:error] [pid 643253:tid 643475] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/w3llscc.php"] [unique_id "amuDusjqbtjBYzqM1uYwQgAAAFs"]
[Thu Jul 30 12:02:50.870781 2026] [security2:error] [pid 643253:tid 643475] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/w3llscc.php"] [unique_id "amuDusjqbtjBYzqM1uYwQgAAAFs"]
[Thu Jul 30 12:02:50.878254 2026] [security2:error] [pid 643253:tid 643403] [client 20.203.148.31:62017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/gtc.php"] [unique_id "amuDusjqbtjBYzqM1uYwRAAAABM"]
[Thu Jul 30 12:02:51.272041 2026] [core:notice] [pid 643253:tid 643495] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:51.276412 2026] [security2:error] [pid 643253:tid 643495] [client 103.215.74.26:33106] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDu8jqbtjBYzqM1uYwRgAAAG8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:51.405225 2026] [core:notice] [pid 643253:tid 643490] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:51.434382 2026] [security2:error] [pid 643253:tid 643493] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/11PJcpMFsD8B.php"] [unique_id "amuDu8jqbtjBYzqM1uYwSwAAAG0"]
[Thu Jul 30 12:02:51.434496 2026] [security2:error] [pid 643253:tid 643493] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/11PJcpMFsD8B.php"] [unique_id "amuDu8jqbtjBYzqM1uYwSwAAAG0"]
[Thu Jul 30 12:02:51.576097 2026] [security2:error] [pid 643253:tid 643469] [client 20.203.148.31:22086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/c/autoload_classmap.php"] [unique_id "amuDu8jqbtjBYzqM1uYwTwAAAFU"]
[Thu Jul 30 12:02:51.997959 2026] [security2:error] [pid 643253:tid 643399] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/8.php"] [unique_id "amuDu8jqbtjBYzqM1uYwVAAAAA8"]
[Thu Jul 30 12:02:51.998096 2026] [security2:error] [pid 643253:tid 643399] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/8.php"] [unique_id "amuDu8jqbtjBYzqM1uYwVAAAAA8"]
[Thu Jul 30 12:02:52.057178 2026] [core:notice] [pid 643253:tid 643419] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:52.061910 2026] [security2:error] [pid 643253:tid 643419] [client 103.215.74.26:33114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDvMjqbtjBYzqM1uYwWQAAACM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:52.296713 2026] [security2:error] [pid 643253:tid 643449] [client 20.203.148.31:41225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/import.php"] [unique_id "amuDvMjqbtjBYzqM1uYwXQAAAEE"]
[Thu Jul 30 12:02:52.394793 2026] [security2:error] [pid 643253:tid 643496] [client 176.241.66.87:55734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDvMjqbtjBYzqM1uYwXwAAAHA"]
[Thu Jul 30 12:02:52.394921 2026] [security2:error] [pid 643253:tid 643496] [client 176.241.66.87:55734] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDvMjqbtjBYzqM1uYwXwAAAHA"]
[Thu Jul 30 12:02:52.540202 2026] [security2:error] [pid 643253:tid 643387] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/fnstall.php"] [unique_id "amuDvMjqbtjBYzqM1uYwZgAAAAM"]
[Thu Jul 30 12:02:52.540319 2026] [security2:error] [pid 643253:tid 643387] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/fnstall.php"] [unique_id "amuDvMjqbtjBYzqM1uYwZgAAAAM"]
[Thu Jul 30 12:02:52.806200 2026] [core:notice] [pid 643253:tid 643412] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:52.810614 2026] [security2:error] [pid 643253:tid 643412] [client 103.215.74.26:33128] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDvMjqbtjBYzqM1uYwaAAAABw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:52.874764 2026] [security2:error] [pid 643253:tid 643401] [client 20.203.148.31:22098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/c/flower.php"] [unique_id "amuDvMjqbtjBYzqM1uYwaQAAABE"]
[Thu Jul 30 12:02:52.991240 2026] [security2:error] [pid 643253:tid 643400] [client 2a03:2880:f800:3:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDvMjqbtjBYzqM1uYwXgAAECQ"]
[Thu Jul 30 12:02:53.046031 2026] [security2:error] [pid 643253:tid 643413] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/edorxrr.php"] [unique_id "amuDvcjqbtjBYzqM1uYwcwAAAB0"]
[Thu Jul 30 12:02:53.046124 2026] [security2:error] [pid 643253:tid 643413] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/edorxrr.php"] [unique_id "amuDvcjqbtjBYzqM1uYwcwAAAB0"]
[Thu Jul 30 12:02:53.129858 2026] [security2:error] [pid 643253:tid 643458] [client 20.203.148.31:58530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/lufix.php"] [unique_id "amuDvcjqbtjBYzqM1uYwdAAAAEo"]
[Thu Jul 30 12:02:53.541897 2026] [core:notice] [pid 643253:tid 643467] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:53.548574 2026] [security2:error] [pid 643253:tid 643467] [client 103.215.74.26:48082] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDvcjqbtjBYzqM1uYweAAAAFM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:53.607100 2026] [security2:error] [pid 643253:tid 643486] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/setup.php"] [unique_id "amuDvcjqbtjBYzqM1uYwfAAAAGY"]
[Thu Jul 30 12:02:53.607201 2026] [security2:error] [pid 643253:tid 643486] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/setup.php"] [unique_id "amuDvcjqbtjBYzqM1uYwfAAAAGY"]
[Thu Jul 30 12:02:54.190048 2026] [security2:error] [pid 643253:tid 643462] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/6.php"] [unique_id "amuDvsjqbtjBYzqM1uYwgwAAAE4"]
[Thu Jul 30 12:02:54.190179 2026] [security2:error] [pid 643253:tid 643462] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/6.php"] [unique_id "amuDvsjqbtjBYzqM1uYwgwAAAE4"]
[Thu Jul 30 12:02:54.348511 2026] [core:notice] [pid 643253:tid 643454] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:54.352485 2026] [security2:error] [pid 643253:tid 643454] [client 103.215.74.26:48086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDvsjqbtjBYzqM1uYwhAAAAEY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:54.748241 2026] [security2:error] [pid 643253:tid 643419] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/w3lls.php"] [unique_id "amuDvsjqbtjBYzqM1uYwiwAAACM"]
[Thu Jul 30 12:02:54.748358 2026] [security2:error] [pid 643253:tid 643419] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/w3lls.php"] [unique_id "amuDvsjqbtjBYzqM1uYwiwAAACM"]
[Thu Jul 30 12:02:54.817046 2026] [security2:error] [pid 643253:tid 643492] [client 20.203.148.31:17641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/c/xleet.php"] [unique_id "amuDvsjqbtjBYzqM1uYwjAAAAGw"]
[Thu Jul 30 12:02:55.081083 2026] [core:notice] [pid 643253:tid 643501] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:55.085048 2026] [security2:error] [pid 643253:tid 643501] [client 103.215.74.26:48118] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDv8jqbtjBYzqM1uYwkAAAAHU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:55.261634 2026] [security2:error] [pid 643253:tid 643423] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/99.php"] [unique_id "amuDv8jqbtjBYzqM1uYwlAAAACc"]
[Thu Jul 30 12:02:55.261745 2026] [security2:error] [pid 643253:tid 643423] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/99.php"] [unique_id "amuDv8jqbtjBYzqM1uYwlAAAACc"]
[Thu Jul 30 12:02:55.382305 2026] [security2:error] [pid 643253:tid 643447] [client 20.203.148.31:41074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/Geforce.php"] [unique_id "amuDv8jqbtjBYzqM1uYwlQAAAD8"]
[Thu Jul 30 12:02:55.749842 2026] [security2:error] [pid 643253:tid 643482] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-content/admin.php"] [unique_id "amuDv8jqbtjBYzqM1uYwnQAAAGI"]
[Thu Jul 30 12:02:55.750003 2026] [security2:error] [pid 643253:tid 643482] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-content/admin.php"] [unique_id "amuDv8jqbtjBYzqM1uYwnQAAAGI"]
[Thu Jul 30 12:02:55.853624 2026] [core:notice] [pid 643253:tid 643436] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:55.857972 2026] [security2:error] [pid 643253:tid 643436] [client 103.215.74.26:48154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDv8jqbtjBYzqM1uYwngAAADQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:56.015816 2026] [security2:error] [pid 643253:tid 643489] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDv8jqbtjBYzqM1uYwlgAAaSo"]
[Thu Jul 30 12:02:56.206839 2026] [security2:error] [pid 643253:tid 643400] [client 47.128.122.133:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuDwMjqbtjBYzqM1uYwoQAAABA"]
[Thu Jul 30 12:02:56.314346 2026] [security2:error] [pid 643253:tid 643461] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/media.php"] [unique_id "amuDwMjqbtjBYzqM1uYwqQAAAE0"]
[Thu Jul 30 12:02:56.314452 2026] [security2:error] [pid 643253:tid 643461] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/media.php"] [unique_id "amuDwMjqbtjBYzqM1uYwqQAAAE0"]
[Thu Jul 30 12:02:56.594538 2026] [core:notice] [pid 643253:tid 643458] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:56.601292 2026] [security2:error] [pid 643253:tid 643458] [client 103.215.74.26:48192] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDwMjqbtjBYzqM1uYwrAAAAEo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:56.757306 2026] [core:notice] [pid 643253:tid 643456] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:56.898118 2026] [security2:error] [pid 643253:tid 643481] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-includes/blocks/audio/index.php"] [unique_id "amuDwMjqbtjBYzqM1uYwtAAAAGE"]
[Thu Jul 30 12:02:56.898235 2026] [security2:error] [pid 643253:tid 643481] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-includes/blocks/audio/index.php"] [unique_id "amuDwMjqbtjBYzqM1uYwtAAAAGE"]
[Thu Jul 30 12:02:57.365565 2026] [core:notice] [pid 643253:tid 643475] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:57.372403 2026] [security2:error] [pid 643253:tid 643475] [client 103.215.74.26:48200] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDwcjqbtjBYzqM1uYwvQAAAFs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:57.456243 2026] [security2:error] [pid 643253:tid 643504] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/222.php"] [unique_id "amuDwcjqbtjBYzqM1uYwvgAAAHg"]
[Thu Jul 30 12:02:57.456400 2026] [security2:error] [pid 643253:tid 643504] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/222.php"] [unique_id "amuDwcjqbtjBYzqM1uYwvgAAAHg"]
[Thu Jul 30 12:02:57.530468 2026] [security2:error] [pid 643253:tid 643484] [client 20.203.148.31:41301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/a4.php"] [unique_id "amuDwcjqbtjBYzqM1uYwvwAAAGQ"]
[Thu Jul 30 12:02:57.983778 2026] [security2:error] [pid 643253:tid 643453] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-load.php"] [unique_id "amuDwcjqbtjBYzqM1uYwyQAAAEU"]
[Thu Jul 30 12:02:57.983872 2026] [security2:error] [pid 643253:tid 643453] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-load.php"] [unique_id "amuDwcjqbtjBYzqM1uYwyQAAAEU"]
[Thu Jul 30 12:02:58.100641 2026] [core:notice] [pid 643253:tid 643438] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:58.104577 2026] [security2:error] [pid 643253:tid 643438] [client 103.215.74.26:48202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDwsjqbtjBYzqM1uYwywAAADY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:58.216863 2026] [core:notice] [pid 643253:tid 643452] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:58.553139 2026] [security2:error] [pid 643253:tid 643391] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-content/themes/index.php"] [unique_id "amuDwsjqbtjBYzqM1uYw0wAAAAc"]
[Thu Jul 30 12:02:58.553256 2026] [security2:error] [pid 643253:tid 643391] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-content/themes/index.php"] [unique_id "amuDwsjqbtjBYzqM1uYw0wAAAAc"]
[Thu Jul 30 12:02:58.762863 2026] [core:notice] [pid 643253:tid 643395] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:58.810168 2026] [security2:error] [pid 643253:tid 643470] [client 20.203.148.31:17635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/classwithtostring.php"] [unique_id "amuDwsjqbtjBYzqM1uYw2wAAAFY"]
[Thu Jul 30 12:02:58.828755 2026] [core:notice] [pid 643253:tid 643447] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:58.832770 2026] [security2:error] [pid 643253:tid 643447] [client 103.215.74.26:48204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "767"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDwsjqbtjBYzqM1uYw3QAAAD8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:58.851134 2026] [security2:error] [pid 643253:tid 643410] [client 74.7.241.169:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "webmail.vwh.hfl.temporary.site"] [uri "/___proxy_subdomain_webmail/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuDwsjqbtjBYzqM1uYw4AAAABo"]
[Thu Jul 30 12:02:58.851810 2026] [security2:error] [pid 643253:tid 643502] [client 74.7.241.169:47060] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "webmail.vwh.hfl.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuDwsjqbtjBYzqM1uYw3gAAdj8"]
[Thu Jul 30 12:02:59.067509 2026] [core:notice] [pid 643253:tid 643427] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:59.073177 2026] [security2:error] [pid 643253:tid 643398] [client 74.7.241.169:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "webmail.vwh.hfl.temporary.site"] [uri "/___proxy_subdomain_webmail/___proxy_subdomain_webmail/cgi-sys/suspendedpage.cgi"] [unique_id "amuDw8jqbtjBYzqM1uYw5gAAAA4"], referer: https://webmail.vwh.hfl.temporary.site/robots.txt
[Thu Jul 30 12:02:59.073692 2026] [security2:error] [pid 643253:tid 643435] [client 74.7.241.169:47060] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "webmail.vwh.hfl.temporary.site"] [uri "/___proxy_subdomain_webmail/cgi-sys/suspendedpage.cgi"] [unique_id "amuDw8jqbtjBYzqM1uYw4QAAMz0"], referer: https://webmail.vwh.hfl.temporary.site/robots.txt
[Thu Jul 30 12:02:59.123946 2026] [security2:error] [pid 643253:tid 643413] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-admin/js/index.php"] [unique_id "amuDw8jqbtjBYzqM1uYw6AAAAB0"]
[Thu Jul 30 12:02:59.124057 2026] [security2:error] [pid 643253:tid 643413] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-admin/js/index.php"] [unique_id "amuDw8jqbtjBYzqM1uYw6AAAAB0"]
[Thu Jul 30 12:02:59.297603 2026] [security2:error] [pid 643253:tid 643488] [client 74.7.241.169:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "webmail.vwh.hfl.temporary.site"] [uri "/___proxy_subdomain_webmail/___proxy_subdomain_webmail/cgi-sys/suspendedpage.cgi"] [unique_id "amuDw8jqbtjBYzqM1uYw6wAAAGg"], referer: https://webmail.vwh.hfl.temporary.site/cgi-sys/suspendedpage.cgi
[Thu Jul 30 12:02:59.298155 2026] [security2:error] [pid 643253:tid 643400] [client 74.7.241.169:47060] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "webmail.vwh.hfl.temporary.site"] [uri "/___proxy_subdomain_webmail/cgi-sys/suspendedpage.cgi"] [unique_id "amuDw8jqbtjBYzqM1uYw6QAAED4"], referer: https://webmail.vwh.hfl.temporary.site/cgi-sys/suspendedpage.cgi
[Thu Jul 30 12:02:59.298812 2026] [core:notice] [pid 643253:tid 643404] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:59.415000 2026] [proxy:error] [pid 643253:tid 643431] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:02:59.415054 2026] [proxy_http:error] [pid 643253:tid 643431] [client 34.224.175.62:13720] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:02:59.415614 2026] [proxy:error] [pid 643253:tid 643431] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:02:59.415657 2026] [proxy_http:error] [pid 643253:tid 643431] [client 34.224.175.62:13720] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:02:59.519396 2026] [security2:error] [pid 643253:tid 643440] [client 74.7.241.169:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "webmail.vwh.hfl.temporary.site"] [uri "/___proxy_subdomain_webmail/___proxy_subdomain_webmail/cgi-sys/suspendedpage.cgi"] [unique_id "amuDw8jqbtjBYzqM1uYw9wAAADg"], referer: https://webmail.vwh.hfl.temporary.site/cgi-sys/suspendedpage.cgi
[Thu Jul 30 12:02:59.521417 2026] [security2:error] [pid 643253:tid 643446] [client 74.7.241.169:47060] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "webmail.vwh.hfl.temporary.site"] [uri "/___proxy_subdomain_webmail/cgi-sys/suspendedpage.cgi"] [unique_id "amuDw8jqbtjBYzqM1uYw9QAAPkA"], referer: https://webmail.vwh.hfl.temporary.site/cgi-sys/suspendedpage.cgi
[Thu Jul 30 12:02:59.597856 2026] [core:notice] [pid 643253:tid 643474] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:59.604776 2026] [security2:error] [pid 643253:tid 643474] [client 103.215.74.26:48210] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDw8jqbtjBYzqM1uYw-AAAAFo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:59.712243 2026] [security2:error] [pid 643253:tid 643505] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/memberfuns.php"] [unique_id "amuDw8jqbtjBYzqM1uYw-QAAAHk"]
[Thu Jul 30 12:02:59.712358 2026] [security2:error] [pid 643253:tid 643505] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/memberfuns.php"] [unique_id "amuDw8jqbtjBYzqM1uYw-QAAAHk"]
[Thu Jul 30 12:02:59.742474 2026] [security2:error] [pid 643253:tid 643468] [client 74.7.241.169:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "webmail.vwh.hfl.temporary.site"] [uri "/___proxy_subdomain_webmail/___proxy_subdomain_webmail/cgi-sys/suspendedpage.cgi"] [unique_id "amuDw8jqbtjBYzqM1uYw_AAAAFQ"], referer: https://webmail.vwh.hfl.temporary.site/cgi-sys/suspendedpage.cgi
[Thu Jul 30 12:02:59.742928 2026] [security2:error] [pid 643253:tid 643421] [client 74.7.241.169:47060] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "webmail.vwh.hfl.temporary.site"] [uri "/___proxy_subdomain_webmail/cgi-sys/suspendedpage.cgi"] [unique_id "amuDw8jqbtjBYzqM1uYw-gAAJUI"], referer: https://webmail.vwh.hfl.temporary.site/cgi-sys/suspendedpage.cgi
[Thu Jul 30 12:02:59.966926 2026] [security2:error] [pid 643253:tid 643450] [client 74.7.241.169:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "webmail.vwh.hfl.temporary.site"] [uri "/___proxy_subdomain_webmail/___proxy_subdomain_webmail/cgi-sys/suspendedpage.cgi"] [unique_id "amuDw8jqbtjBYzqM1uYxBQAAAEI"], referer: https://webmail.vwh.hfl.temporary.site/cgi-sys/suspendedpage.cgi
[Thu Jul 30 12:02:59.967560 2026] [security2:error] [pid 643253:tid 643416] [client 74.7.241.169:47060] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "webmail.vwh.hfl.temporary.site"] [uri "/___proxy_subdomain_webmail/cgi-sys/suspendedpage.cgi"] [unique_id "amuDw8jqbtjBYzqM1uYxAwAAIEg"], referer: https://webmail.vwh.hfl.temporary.site/cgi-sys/suspendedpage.cgi
[Thu Jul 30 12:03:00.270191 2026] [security2:error] [pid 643253:tid 643397] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/orange3.php"] [unique_id "amuDxMjqbtjBYzqM1uYxBgAAAA0"]
[Thu Jul 30 12:03:00.270310 2026] [security2:error] [pid 643253:tid 643397] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/orange3.php"] [unique_id "amuDxMjqbtjBYzqM1uYxBgAAAA0"]
[Thu Jul 30 12:03:00.331649 2026] [core:notice] [pid 643253:tid 643384] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:00.336539 2026] [security2:error] [pid 643253:tid 643384] [client 103.215.74.26:48220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "780"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDxMjqbtjBYzqM1uYxBwAAAAA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:00.852478 2026] [security2:error] [pid 643253:tid 643449] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amuDxMjqbtjBYzqM1uYxEwAAAEE"]
[Thu Jul 30 12:03:00.852609 2026] [security2:error] [pid 643253:tid 643449] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amuDxMjqbtjBYzqM1uYxEwAAAEE"]
[Thu Jul 30 12:03:00.955461 2026] [security2:error] [pid 643253:tid 643493] [client 2a03:2880:f800:1f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDxMjqbtjBYzqM1uYxCwAAbUk"]
[Thu Jul 30 12:03:01.069560 2026] [core:notice] [pid 643253:tid 643494] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:01.074726 2026] [security2:error] [pid 643253:tid 643494] [client 103.215.74.26:48228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDxcjqbtjBYzqM1uYxIQAAAG4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:01.234772 2026] [core:error] [pid 643253:tid 643489] [client 74.7.228.50:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:03:01.234801 2026] [core:error] [pid 643253:tid 643489] [client 74.7.228.50:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:03:01.234940 2026] [security2:error] [pid 643253:tid 643489] [client 74.7.228.50:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.met.nyx.temporary.site"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amuDxcjqbtjBYzqM1uYxJwAAAGk"]
[Thu Jul 30 12:03:01.235567 2026] [security2:error] [pid 643253:tid 643483] [client 74.7.228.50:53876] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.met.nyx.temporary.site"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amuDxcjqbtjBYzqM1uYxJQAAY1I"]
[Thu Jul 30 12:03:01.294892 2026] [security2:error] [pid 643253:tid 643453] [client 20.100.187.246:58651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/json.php"] [unique_id "amuDxcjqbtjBYzqM1uYxLAAAAEU"]
[Thu Jul 30 12:03:01.338308 2026] [security2:error] [pid 643253:tid 643480] [client 185.191.171.6:58460] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/"] [unique_id "amuDxcjqbtjBYzqM1uYxLQAAAGA"]
[Thu Jul 30 12:03:01.338457 2026] [security2:error] [pid 643253:tid 643480] [client 185.191.171.6:58460] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/"] [unique_id "amuDxcjqbtjBYzqM1uYxLQAAAGA"]
[Thu Jul 30 12:03:01.386850 2026] [security2:error] [pid 643253:tid 643430] [client 20.203.148.31:15172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/content.php"] [unique_id "amuDxcjqbtjBYzqM1uYxLwAAAC4"]
[Thu Jul 30 12:03:01.417009 2026] [security2:error] [pid 643253:tid 643404] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-the.php"] [unique_id "amuDxcjqbtjBYzqM1uYxMwAAABQ"]
[Thu Jul 30 12:03:01.417131 2026] [security2:error] [pid 643253:tid 643404] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-the.php"] [unique_id "amuDxcjqbtjBYzqM1uYxMwAAABQ"]
[Thu Jul 30 12:03:01.796966 2026] [core:notice] [pid 643253:tid 643456] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:01.800833 2026] [security2:error] [pid 643253:tid 643456] [client 103.215.74.26:48240] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDxcjqbtjBYzqM1uYxQAAAAEg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:01.930617 2026] [security2:error] [pid 643253:tid 643492] [client 20.203.148.31:57304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/accueil.php"] [unique_id "amuDxcjqbtjBYzqM1uYxRAAAAGw"]
[Thu Jul 30 12:03:01.998172 2026] [security2:error] [pid 643253:tid 643490] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/crgio.php"] [unique_id "amuDxcjqbtjBYzqM1uYxSAAAAGo"]
[Thu Jul 30 12:03:01.998280 2026] [security2:error] [pid 643253:tid 643490] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/crgio.php"] [unique_id "amuDxcjqbtjBYzqM1uYxSAAAAGo"]
[Thu Jul 30 12:03:02.436351 2026] [security2:error] [pid 643253:tid 643501] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuDxsjqbtjBYzqM1uYxUgAAAHU"]
[Thu Jul 30 12:03:02.436468 2026] [security2:error] [pid 643253:tid 643501] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuDxsjqbtjBYzqM1uYxUgAAAHU"]
[Thu Jul 30 12:03:02.520610 2026] [core:notice] [pid 643253:tid 643399] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:02.524505 2026] [security2:error] [pid 643253:tid 643399] [client 103.215.74.26:48262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDxsjqbtjBYzqM1uYxVgAAAA8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:02.561865 2026] [security2:error] [pid 643253:tid 643477] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ws13.php"] [unique_id "amuDxsjqbtjBYzqM1uYxWgAAAF0"]
[Thu Jul 30 12:03:02.561951 2026] [security2:error] [pid 643253:tid 643477] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ws13.php"] [unique_id "amuDxsjqbtjBYzqM1uYxWgAAAF0"]
[Thu Jul 30 12:03:02.683848 2026] [security2:error] [pid 643253:tid 643487] [client 20.203.148.31:41317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/dashboard.php"] [unique_id "amuDxsjqbtjBYzqM1uYxXgAAAGc"]
[Thu Jul 30 12:03:02.764622 2026] [security2:error] [pid 643253:tid 643482] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuDxsjqbtjBYzqM1uYxXwAAAGI"]
[Thu Jul 30 12:03:02.764746 2026] [security2:error] [pid 643253:tid 643482] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuDxsjqbtjBYzqM1uYxXwAAAGI"]
[Thu Jul 30 12:03:03.048446 2026] [security2:error] [pid 643253:tid 643386] [client 20.203.148.31:16003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/doc.php"] [unique_id "amuDx8jqbtjBYzqM1uYxbAAAAAI"]
[Thu Jul 30 12:03:03.094463 2026] [security2:error] [pid 643253:tid 643488] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/srontol.php"] [unique_id "amuDx8jqbtjBYzqM1uYxcAAAAGg"]
[Thu Jul 30 12:03:03.094599 2026] [security2:error] [pid 643253:tid 643488] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/srontol.php"] [unique_id "amuDx8jqbtjBYzqM1uYxcAAAAGg"]
[Thu Jul 30 12:03:03.202223 2026] [security2:error] [pid 643253:tid 643388] [client 85.208.96.199:16140] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/robots.txt"] [unique_id "amuDx8jqbtjBYzqM1uYxcgAAAAQ"]
[Thu Jul 30 12:03:03.202354 2026] [security2:error] [pid 643253:tid 643388] [client 85.208.96.199:16140] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/robots.txt"] [unique_id "amuDx8jqbtjBYzqM1uYxcgAAAAQ"]
[Thu Jul 30 12:03:03.263929 2026] [core:notice] [pid 643253:tid 643471] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:03.269114 2026] [security2:error] [pid 643253:tid 643471] [client 103.215.74.26:55702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDx8jqbtjBYzqM1uYxcwAAAFc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:03.462806 2026] [security2:error] [pid 643253:tid 643408] [client 20.203.148.31:41324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/radio.php"] [unique_id "amuDx8jqbtjBYzqM1uYxdAAAABg"]
[Thu Jul 30 12:03:03.503121 2026] [security2:error] [pid 643253:tid 643473] [client 20.100.187.246:59422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/mini.php"] [unique_id "amuDx8jqbtjBYzqM1uYxdQAAAFk"]
[Thu Jul 30 12:03:03.605439 2026] [security2:error] [pid 643253:tid 643486] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/miru3.php"] [unique_id "amuDx8jqbtjBYzqM1uYxegAAAGY"]
[Thu Jul 30 12:03:03.605591 2026] [security2:error] [pid 643253:tid 643486] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/miru3.php"] [unique_id "amuDx8jqbtjBYzqM1uYxegAAAGY"]
[Thu Jul 30 12:03:04.007152 2026] [core:notice] [pid 643253:tid 643479] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:04.011008 2026] [security2:error] [pid 643253:tid 643479] [client 103.215.74.26:55718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDyMjqbtjBYzqM1uYxhAAAAF8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:04.175535 2026] [security2:error] [pid 643253:tid 643416] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ingfo.php"] [unique_id "amuDyMjqbtjBYzqM1uYxjQAAACA"]
[Thu Jul 30 12:03:04.175650 2026] [security2:error] [pid 643253:tid 643416] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ingfo.php"] [unique_id "amuDyMjqbtjBYzqM1uYxjQAAACA"]
[Thu Jul 30 12:03:04.230173 2026] [security2:error] [pid 643253:tid 643504] [client 176.241.66.87:65114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDyMjqbtjBYzqM1uYxjgAAAHg"]
[Thu Jul 30 12:03:04.230381 2026] [security2:error] [pid 643253:tid 643504] [client 176.241.66.87:65114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDyMjqbtjBYzqM1uYxjgAAAHg"]
[Thu Jul 30 12:03:04.470120 2026] [security2:error] [pid 643253:tid 643490] [client 20.100.187.246:57351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/chosen.php"] [unique_id "amuDyMjqbtjBYzqM1uYxjwAAAGo"]
[Thu Jul 30 12:03:04.769573 2026] [security2:error] [pid 643253:tid 643449] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ey5.php"] [unique_id "amuDyMjqbtjBYzqM1uYxlgAAAEE"]
[Thu Jul 30 12:03:04.769676 2026] [security2:error] [pid 643253:tid 643449] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ey5.php"] [unique_id "amuDyMjqbtjBYzqM1uYxlgAAAEE"]
[Thu Jul 30 12:03:04.771764 2026] [core:notice] [pid 643253:tid 643448] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:04.775873 2026] [security2:error] [pid 643253:tid 643448] [client 103.215.74.26:55722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDyMjqbtjBYzqM1uYxlwAAAEA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:04.973936 2026] [security2:error] [pid 643253:tid 643470] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/xstelth.php"] [unique_id "amuDyMjqbtjBYzqM1uYxnAAAAFY"]
[Thu Jul 30 12:03:04.974077 2026] [security2:error] [pid 643253:tid 643470] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/xstelth.php"] [unique_id "amuDyMjqbtjBYzqM1uYxnAAAAFY"]
[Thu Jul 30 12:03:05.314519 2026] [security2:error] [pid 643253:tid 643398] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/584062352875874akp.php"] [unique_id "amuDycjqbtjBYzqM1uYxpAAAAA4"]
[Thu Jul 30 12:03:05.314633 2026] [security2:error] [pid 643253:tid 643398] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/584062352875874akp.php"] [unique_id "amuDycjqbtjBYzqM1uYxpAAAAA4"]
[Thu Jul 30 12:03:05.379644 2026] [security2:error] [pid 643253:tid 643432] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/fine.php"] [unique_id "amuDycjqbtjBYzqM1uYxpQAAADA"]
[Thu Jul 30 12:03:05.379780 2026] [security2:error] [pid 643253:tid 643432] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/fine.php"] [unique_id "amuDycjqbtjBYzqM1uYxpQAAADA"]
[Thu Jul 30 12:03:05.507867 2026] [core:notice] [pid 643253:tid 643439] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:05.514881 2026] [security2:error] [pid 643253:tid 643439] [client 103.215.74.26:55738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDycjqbtjBYzqM1uYxpwAAADc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:05.643613 2026] [security2:error] [pid 643253:tid 643465] [client 20.100.187.246:63539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/kj.php"] [unique_id "amuDycjqbtjBYzqM1uYxqQAAAFE"]
[Thu Jul 30 12:03:05.668707 2026] [security2:error] [pid 643253:tid 643483] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/newfile.php"] [unique_id "amuDycjqbtjBYzqM1uYxrAAAAGM"]
[Thu Jul 30 12:03:05.668807 2026] [security2:error] [pid 643253:tid 643483] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/newfile.php"] [unique_id "amuDycjqbtjBYzqM1uYxrAAAAGM"]
[Thu Jul 30 12:03:05.946279 2026] [security2:error] [pid 643253:tid 643464] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDycjqbtjBYzqM1uYxpgAAUHo"]
[Thu Jul 30 12:03:06.011711 2026] [security2:error] [pid 643253:tid 643406] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/tBEZGQz.php"] [unique_id "amuDysjqbtjBYzqM1uYxsAAAABY"]
[Thu Jul 30 12:03:06.011867 2026] [security2:error] [pid 643253:tid 643406] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/tBEZGQz.php"] [unique_id "amuDysjqbtjBYzqM1uYxsAAAABY"]
[Thu Jul 30 12:03:06.354416 2026] [proxy:error] [pid 643253:tid 643481] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:06.354491 2026] [proxy_http:error] [pid 643253:tid 643481] [client 20.100.173.28:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:06.355062 2026] [proxy:error] [pid 643253:tid 643481] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:06.355106 2026] [proxy_http:error] [pid 643253:tid 643481] [client 20.100.173.28:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:06.355204 2026] [security2:error] [pid 643253:tid 643481] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuDysjqbtjBYzqM1uYxuAAAAGE"]
[Thu Jul 30 12:03:06.502684 2026] [security2:error] [pid 643253:tid 643510] [client 47.128.27.6:64020] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/robots.txt"] [unique_id "amuDysjqbtjBYzqM1uYxuQAAAH4"]
[Thu Jul 30 12:03:06.684694 2026] [security2:error] [pid 643253:tid 643451] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/drykl.php"] [unique_id "amuDysjqbtjBYzqM1uYxugAAAEM"]
[Thu Jul 30 12:03:06.684827 2026] [security2:error] [pid 643253:tid 643451] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/drykl.php"] [unique_id "amuDysjqbtjBYzqM1uYxugAAAEM"]
[Thu Jul 30 12:03:06.701637 2026] [security2:error] [pid 643253:tid 643391] [client 20.203.148.31:27269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/dropdown.php"] [unique_id "amuDysjqbtjBYzqM1uYxuwAAAAc"]
[Thu Jul 30 12:03:07.012071 2026] [proxy:error] [pid 643253:tid 643450] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:07.012149 2026] [proxy_http:error] [pid 643253:tid 643450] [client 20.100.173.28:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:07.012707 2026] [proxy:error] [pid 643253:tid 643450] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:07.012765 2026] [proxy_http:error] [pid 643253:tid 643450] [client 20.100.173.28:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:07.012855 2026] [security2:error] [pid 643253:tid 643450] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuDy8jqbtjBYzqM1uYxwgAAAEI"]
[Thu Jul 30 12:03:07.190877 2026] [core:notice] [pid 643253:tid 643461] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:07.303783 2026] [security2:error] [pid 643253:tid 643369] [remote 185.61.152.44:60740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.152.61.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gkc.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuDy8jqbtjBYzqM1uYxygAAeHI"]
[Thu Jul 30 12:03:07.337272 2026] [security2:error] [pid 643253:tid 643437] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/ls.php"] [unique_id "amuDy8jqbtjBYzqM1uYxywAAADU"]
[Thu Jul 30 12:03:07.337374 2026] [security2:error] [pid 643253:tid 643437] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/ls.php"] [unique_id "amuDy8jqbtjBYzqM1uYxywAAADU"]
[Thu Jul 30 12:03:07.438223 2026] [security2:error] [pid 643253:tid 643462] [client 20.100.187.246:35929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/wp-files.php"] [unique_id "amuDy8jqbtjBYzqM1uYxzAAAAE4"]
[Thu Jul 30 12:03:07.670324 2026] [security2:error] [pid 643253:tid 643411] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/dx.php"] [unique_id "amuDy8jqbtjBYzqM1uYxzwAAABs"]
[Thu Jul 30 12:03:07.670439 2026] [security2:error] [pid 643253:tid 643411] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/dx.php"] [unique_id "amuDy8jqbtjBYzqM1uYxzwAAABs"]
[Thu Jul 30 12:03:08.028395 2026] [security2:error] [pid 643253:tid 643466] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/mac.php"] [unique_id "amuDzMjqbtjBYzqM1uYx2QAAAFI"]
[Thu Jul 30 12:03:08.028485 2026] [security2:error] [pid 643253:tid 643466] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/mac.php"] [unique_id "amuDzMjqbtjBYzqM1uYx2QAAAFI"]
[Thu Jul 30 12:03:08.110808 2026] [security2:error] [pid 643253:tid 643454] [client 20.203.148.31:23130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/ee.php"] [unique_id "amuDzMjqbtjBYzqM1uYx2gAAAEY"]
[Thu Jul 30 12:03:08.290421 2026] [security2:error] [pid 643253:tid 643266] [remote 74.7.241.59:49330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuDzMjqbtjBYzqM1uYx3gAAcAs"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/premium-addons-for-elementor/modules/woocommerce/templates
[Thu Jul 30 12:03:08.297912 2026] [security2:error] [pid 643253:tid 643395] [client 20.100.187.246:63511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/wp-setup.php"] [unique_id "amuDzMjqbtjBYzqM1uYx3wAAAAs"]
[Thu Jul 30 12:03:08.356368 2026] [security2:error] [pid 643253:tid 643427] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/485.php"] [unique_id "amuDzMjqbtjBYzqM1uYx4wAAACs"]
[Thu Jul 30 12:03:08.356495 2026] [security2:error] [pid 643253:tid 643427] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/485.php"] [unique_id "amuDzMjqbtjBYzqM1uYx4wAAACs"]
[Thu Jul 30 12:03:08.693357 2026] [security2:error] [pid 643253:tid 643453] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/gelio1.php"] [unique_id "amuDzMjqbtjBYzqM1uYx5AAAAEU"]
[Thu Jul 30 12:03:08.693474 2026] [security2:error] [pid 643253:tid 643453] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/gelio1.php"] [unique_id "amuDzMjqbtjBYzqM1uYx5AAAAEU"]
[Thu Jul 30 12:03:09.023934 2026] [security2:error] [pid 643253:tid 643471] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/lp6.php"] [unique_id "amuDzcjqbtjBYzqM1uYx6wAAAFc"]
[Thu Jul 30 12:03:09.024071 2026] [security2:error] [pid 643253:tid 643471] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/lp6.php"] [unique_id "amuDzcjqbtjBYzqM1uYx6wAAAFc"]
[Thu Jul 30 12:03:09.363634 2026] [security2:error] [pid 643253:tid 643505] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuDzcjqbtjBYzqM1uYx8AAAAHk"]
[Thu Jul 30 12:03:09.363741 2026] [security2:error] [pid 643253:tid 643505] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuDzcjqbtjBYzqM1uYx8AAAAHk"]
[Thu Jul 30 12:03:09.701821 2026] [proxy:error] [pid 643253:tid 643492] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:09.701888 2026] [proxy_http:error] [pid 643253:tid 643492] [client 20.100.173.28:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:09.702462 2026] [proxy:error] [pid 643253:tid 643492] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:09.702506 2026] [proxy_http:error] [pid 643253:tid 643492] [client 20.100.173.28:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:09.702598 2026] [security2:error] [pid 643253:tid 643492] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuDzcjqbtjBYzqM1uYx-AAAAGw"]
[Thu Jul 30 12:03:09.997478 2026] [security2:error] [pid 643253:tid 643462] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/w3llscc.php"] [unique_id "amuDzcjqbtjBYzqM1uYx_wAAAE4"]
[Thu Jul 30 12:03:09.997617 2026] [security2:error] [pid 643253:tid 643462] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/w3llscc.php"] [unique_id "amuDzcjqbtjBYzqM1uYx_wAAAE4"]
[Thu Jul 30 12:03:10.014649 2026] [security2:error] [pid 643253:tid 643461] [client 20.203.148.31:33439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/flower.php"] [unique_id "amuDzsjqbtjBYzqM1uYyAAAAAE0"]
[Thu Jul 30 12:03:10.300014 2026] [security2:error] [pid 643253:tid 643411] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/miru3.php"] [unique_id "amuDzsjqbtjBYzqM1uYyAQAAABs"]
[Thu Jul 30 12:03:10.300126 2026] [security2:error] [pid 643253:tid 643411] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/miru3.php"] [unique_id "amuDzsjqbtjBYzqM1uYyAQAAABs"]
[Thu Jul 30 12:03:10.622179 2026] [security2:error] [pid 643253:tid 643464] [client 20.100.187.246:63339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/defaults.php"] [unique_id "amuDzsjqbtjBYzqM1uYyDAAAAFA"]
[Thu Jul 30 12:03:10.635368 2026] [security2:error] [pid 643253:tid 643394] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/autoload_classmap.php"] [unique_id "amuDzsjqbtjBYzqM1uYyDQAAAAo"]
[Thu Jul 30 12:03:10.635479 2026] [security2:error] [pid 643253:tid 643394] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/autoload_classmap.php"] [unique_id "amuDzsjqbtjBYzqM1uYyDQAAAAo"]
[Thu Jul 30 12:03:10.968003 2026] [proxy:error] [pid 643253:tid 643414] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:10.968077 2026] [proxy_http:error] [pid 643253:tid 643414] [client 20.100.173.28:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:10.968660 2026] [proxy:error] [pid 643253:tid 643414] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:10.968704 2026] [proxy_http:error] [pid 643253:tid 643414] [client 20.100.173.28:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:10.968795 2026] [security2:error] [pid 643253:tid 643414] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuDzsjqbtjBYzqM1uYyEgAAAB4"]
[Thu Jul 30 12:03:11.084060 2026] [security2:error] [pid 643253:tid 643477] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDzsjqbtjBYzqM1uYyCQAAXQ0"]
[Thu Jul 30 12:03:11.300240 2026] [security2:error] [pid 643253:tid 643436] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-content/themes/index.php"] [unique_id "amuDz8jqbtjBYzqM1uYyFwAAADQ"]
[Thu Jul 30 12:03:11.300364 2026] [security2:error] [pid 643253:tid 643436] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-content/themes/index.php"] [unique_id "amuDz8jqbtjBYzqM1uYyFwAAADQ"]
[Thu Jul 30 12:03:11.309539 2026] [core:notice] [pid 643253:tid 643423] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:11.317032 2026] [security2:error] [pid 643253:tid 643423] [client 103.215.74.26:55746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDz8jqbtjBYzqM1uYyGAAAACc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:11.600967 2026] [security2:error] [pid 643253:tid 643439] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/av.php"] [unique_id "amuDz8jqbtjBYzqM1uYyHwAAADc"]
[Thu Jul 30 12:03:11.601126 2026] [security2:error] [pid 643253:tid 643439] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/av.php"] [unique_id "amuDz8jqbtjBYzqM1uYyHwAAADc"]
[Thu Jul 30 12:03:11.909673 2026] [proxy:error] [pid 643253:tid 643404] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:11.909748 2026] [proxy_http:error] [pid 643253:tid 643404] [client 20.100.173.28:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:11.910325 2026] [proxy:error] [pid 643253:tid 643404] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:11.910371 2026] [proxy_http:error] [pid 643253:tid 643404] [client 20.100.173.28:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:11.910467 2026] [security2:error] [pid 643253:tid 643404] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuDz8jqbtjBYzqM1uYyIgAAABQ"]
[Thu Jul 30 12:03:12.244474 2026] [proxy:error] [pid 643253:tid 643431] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:12.244550 2026] [proxy_http:error] [pid 643253:tid 643431] [client 20.100.173.28:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:12.245119 2026] [proxy:error] [pid 643253:tid 643431] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:12.245162 2026] [proxy_http:error] [pid 643253:tid 643431] [client 20.100.173.28:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:12.245253 2026] [security2:error] [pid 643253:tid 643431] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuD0MjqbtjBYzqM1uYyKQAAAC8"]
[Thu Jul 30 12:03:12.557781 2026] [security2:error] [pid 643253:tid 643401] [client 20.100.187.246:63322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/gtc.php"] [unique_id "amuD0MjqbtjBYzqM1uYyMAAAABE"]
[Thu Jul 30 12:03:12.572869 2026] [security2:error] [pid 643253:tid 643463] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/tiny.php"] [unique_id "amuD0MjqbtjBYzqM1uYyMQAAAE8"]
[Thu Jul 30 12:03:12.572946 2026] [security2:error] [pid 643253:tid 643463] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/tiny.php"] [unique_id "amuD0MjqbtjBYzqM1uYyMQAAAE8"]
[Thu Jul 30 12:03:12.917515 2026] [security2:error] [pid 643253:tid 643468] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuD0MjqbtjBYzqM1uYyMwAAAFQ"]
[Thu Jul 30 12:03:12.917636 2026] [security2:error] [pid 643253:tid 643468] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuD0MjqbtjBYzqM1uYyMwAAAFQ"]
[Thu Jul 30 12:03:13.001947 2026] [security2:error] [pid 643253:tid 643454] [client 20.203.148.31:23128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/gecko-new.php"] [unique_id "amuD0cjqbtjBYzqM1uYyOgAAAEY"]
[Thu Jul 30 12:03:13.250466 2026] [security2:error] [pid 643253:tid 643384] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/zrrhj.php"] [unique_id "amuD0cjqbtjBYzqM1uYyRAAAAAA"]
[Thu Jul 30 12:03:13.250571 2026] [security2:error] [pid 643253:tid 643384] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/zrrhj.php"] [unique_id "amuD0cjqbtjBYzqM1uYyRAAAAAA"]
[Thu Jul 30 12:03:13.492290 2026] [security2:error] [pid 643253:tid 643461] [client 127.0.0.1:26462] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuD0cjqbtjBYzqM1uYyTAAAAE0"]
[Thu Jul 30 12:03:13.492381 2026] [security2:error] [pid 643253:tid 643397] [client 74.7.175.152:37736] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.deltaedu.net"] [uri "/robots.txt"] [unique_id "amuD0cjqbtjBYzqM1uYySwAADRM"]
[Thu Jul 30 12:03:13.547724 2026] [security2:error] [pid 643253:tid 643503] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuD0cjqbtjBYzqM1uYyUgAAAHc"]
[Thu Jul 30 12:03:13.547818 2026] [security2:error] [pid 643253:tid 643503] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuD0cjqbtjBYzqM1uYyUgAAAHc"]
[Thu Jul 30 12:03:13.856870 2026] [security2:error] [pid 643253:tid 643393] [client 20.203.148.31:21518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/m.php"] [unique_id "amuD0cjqbtjBYzqM1uYyWQAAAAk"]
[Thu Jul 30 12:03:13.891971 2026] [security2:error] [pid 643253:tid 643477] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wpgum.php"] [unique_id "amuD0cjqbtjBYzqM1uYyWgAAAF0"]
[Thu Jul 30 12:03:13.892083 2026] [security2:error] [pid 643253:tid 643477] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wpgum.php"] [unique_id "amuD0cjqbtjBYzqM1uYyWgAAAF0"]
[Thu Jul 30 12:03:14.196686 2026] [security2:error] [pid 643253:tid 643457] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/ywwbf.php"] [unique_id "amuD0sjqbtjBYzqM1uYyYAAAAEk"]
[Thu Jul 30 12:03:14.196790 2026] [security2:error] [pid 643253:tid 643457] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/ywwbf.php"] [unique_id "amuD0sjqbtjBYzqM1uYyYAAAAEk"]
[Thu Jul 30 12:03:14.240829 2026] [security2:error] [pid 643253:tid 643491] [client 20.100.187.246:63284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/import.php"] [unique_id "amuD0sjqbtjBYzqM1uYyYQAAAGs"]
[Thu Jul 30 12:03:14.485774 2026] [core:notice] [pid 643253:tid 643508] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:14.581742 2026] [core:notice] [pid 643253:tid 643303] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:14.836520 2026] [lsapi:error] [pid 642360:tid 642436] [remote 41.210.167.242:0] [host flixon.net] Error receiving response: ReceiveResponse: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1009; user ID 1009), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://flixon.net/video/the-killer-vj-junior/
[Thu Jul 30 12:03:14.852725 2026] [core:notice] [pid 643253:tid 643390] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:14.928203 2026] [security2:error] [pid 643253:tid 643435] [client 250.49.135.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuD0sjqbtjBYzqM1uYyXwAAMyg"]
[Thu Jul 30 12:03:15.068626 2026] [security2:error] [pid 643253:tid 643406] [client 20.100.187.246:57379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/lufix.php"] [unique_id "amuD08jqbtjBYzqM1uYycwAAABY"]
[Thu Jul 30 12:03:15.461607 2026] [security2:error] [pid 643253:tid 643463] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/xoldj.php"] [unique_id "amuD08jqbtjBYzqM1uYydQAAAE8"]
[Thu Jul 30 12:03:15.461718 2026] [security2:error] [pid 643253:tid 643463] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/xoldj.php"] [unique_id "amuD08jqbtjBYzqM1uYydQAAAE8"]
[Thu Jul 30 12:03:15.574406 2026] [core:notice] [pid 643253:tid 643510] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:15.677458 2026] [security2:error] [pid 643253:tid 643468] [client 20.100.187.246:35757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/Geforce.php"] [unique_id "amuD08jqbtjBYzqM1uYyfgAAAFQ"]
[Thu Jul 30 12:03:15.806551 2026] [security2:error] [pid 643253:tid 643461] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/f35.php"] [unique_id "amuD08jqbtjBYzqM1uYygAAAAE0"]
[Thu Jul 30 12:03:15.806661 2026] [security2:error] [pid 643253:tid 643461] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/f35.php"] [unique_id "amuD08jqbtjBYzqM1uYygAAAAE0"]
[Thu Jul 30 12:03:15.832551 2026] [security2:error] [pid 643253:tid 643397] [client 185.191.171.10:36386] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/10/21/maioria-dos-novatos-na-camara-esta-em-pl-uniao-brasil-e-mdb/"] [unique_id "amuD08jqbtjBYzqM1uYygQAAAA0"]
[Thu Jul 30 12:03:15.832655 2026] [security2:error] [pid 643253:tid 643397] [client 185.191.171.10:36386] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/10/21/maioria-dos-novatos-na-camara-esta-em-pl-uniao-brasil-e-mdb/"] [unique_id "amuD08jqbtjBYzqM1uYygQAAAA0"]
[Thu Jul 30 12:03:16.121737 2026] [security2:error] [pid 643253:tid 643415] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/gk.php"] [unique_id "amuD1MjqbtjBYzqM1uYyggAAAB8"]
[Thu Jul 30 12:03:16.121871 2026] [security2:error] [pid 643253:tid 643415] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/gk.php"] [unique_id "amuD1MjqbtjBYzqM1uYyggAAAB8"]
[Thu Jul 30 12:03:16.194610 2026] [security2:error] [pid 643253:tid 643480] [client 20.203.148.31:18521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/mah/autoload_classmap.php"] [unique_id "amuD1MjqbtjBYzqM1uYyhgAAAGA"]
[Thu Jul 30 12:03:16.205861 2026] [security2:error] [pid 643253:tid 643475] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuD08jqbtjBYzqM1uYyfQAAWwU"]
[Thu Jul 30 12:03:16.431950 2026] [security2:error] [pid 643253:tid 643509] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/584062352875874akp.php"] [unique_id "amuD1MjqbtjBYzqM1uYyjAAAAH0"]
[Thu Jul 30 12:03:16.432071 2026] [security2:error] [pid 643253:tid 643509] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/584062352875874akp.php"] [unique_id "amuD1MjqbtjBYzqM1uYyjAAAAH0"]
[Thu Jul 30 12:03:16.455043 2026] [proxy:error] [pid 643253:tid 643476] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:16.455100 2026] [proxy_http:error] [pid 643253:tid 643476] [client 192.210.150.196:45418] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:16.455808 2026] [proxy:error] [pid 643253:tid 643476] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:16.455853 2026] [proxy_http:error] [pid 643253:tid 643476] [client 192.210.150.196:45418] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:16.600406 2026] [security2:error] [pid 643253:tid 643411] [client 176.241.66.87:1591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuD1MjqbtjBYzqM1uYyjgAAABs"]
[Thu Jul 30 12:03:16.600556 2026] [security2:error] [pid 643253:tid 643411] [client 176.241.66.87:1591] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuD1MjqbtjBYzqM1uYyjgAAABs"]
[Thu Jul 30 12:03:17.119167 2026] [core:notice] [pid 643253:tid 643487] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:17.123853 2026] [security2:error] [pid 643253:tid 643487] [client 103.215.74.26:47788] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD1cjqbtjBYzqM1uYylQAAAGc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:17.177514 2026] [security2:error] [pid 643253:tid 643448] [client 20.100.187.246:65495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/a4.php"] [unique_id "amuD1cjqbtjBYzqM1uYynAAAAEA"]
[Thu Jul 30 12:03:17.289873 2026] [security2:error] [pid 643253:tid 643465] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wper3.php"] [unique_id "amuD1cjqbtjBYzqM1uYyngAAAFE"]
[Thu Jul 30 12:03:17.289990 2026] [security2:error] [pid 643253:tid 643465] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wper3.php"] [unique_id "amuD1cjqbtjBYzqM1uYyngAAAFE"]
[Thu Jul 30 12:03:17.601386 2026] [security2:error] [pid 643253:tid 643439] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/bthil.php"] [unique_id "amuD1cjqbtjBYzqM1uYynwAAADc"]
[Thu Jul 30 12:03:17.601504 2026] [security2:error] [pid 643253:tid 643439] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/bthil.php"] [unique_id "amuD1cjqbtjBYzqM1uYynwAAADc"]
[Thu Jul 30 12:03:17.696877 2026] [security2:error] [pid 643253:tid 643393] [client 172.237.109.114:50037] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD1cjqbtjBYzqM1uYylwAAAAk"]
[Thu Jul 30 12:03:17.832080 2026] [proxy:error] [pid 643253:tid 643429] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:17.832172 2026] [proxy_http:error] [pid 643253:tid 643429] [client 192.210.150.196:32778] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:17.832745 2026] [proxy:error] [pid 643253:tid 643429] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:17.832787 2026] [proxy_http:error] [pid 643253:tid 643429] [client 192.210.150.196:32778] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:17.860650 2026] [core:notice] [pid 643253:tid 643485] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:17.865014 2026] [security2:error] [pid 643253:tid 643485] [client 103.215.74.26:47800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD1cjqbtjBYzqM1uYypwAAAGU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:17.915329 2026] [security2:error] [pid 643253:tid 643483] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wyzer1.php"] [unique_id "amuD1cjqbtjBYzqM1uYyqAAAAGM"]
[Thu Jul 30 12:03:17.915437 2026] [security2:error] [pid 643253:tid 643483] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wyzer1.php"] [unique_id "amuD1cjqbtjBYzqM1uYyqAAAAGM"]
[Thu Jul 30 12:03:18.246958 2026] [security2:error] [pid 643253:tid 643401] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/mh.php"] [unique_id "amuD1sjqbtjBYzqM1uYytgAAABE"]
[Thu Jul 30 12:03:18.247102 2026] [security2:error] [pid 643253:tid 643401] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/mh.php"] [unique_id "amuD1sjqbtjBYzqM1uYytgAAABE"]
[Thu Jul 30 12:03:18.557253 2026] [security2:error] [pid 643253:tid 643450] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuD1sjqbtjBYzqM1uYyugAAAEI"]
[Thu Jul 30 12:03:18.557413 2026] [security2:error] [pid 643253:tid 643450] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuD1sjqbtjBYzqM1uYyugAAAEI"]
[Thu Jul 30 12:03:18.565967 2026] [core:notice] [pid 643253:tid 643321] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:18.584761 2026] [security2:error] [pid 643253:tid 643460] [client 172.237.109.114:17696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD1sjqbtjBYzqM1uYyrQAAAEw"]
[Thu Jul 30 12:03:18.587049 2026] [core:notice] [pid 643253:tid 643497] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:18.594487 2026] [security2:error] [pid 643253:tid 643497] [client 103.215.74.26:47810] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD1sjqbtjBYzqM1uYyvAAAAHE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:18.645242 2026] [security2:error] [pid 643253:tid 643390] [client 172.237.109.114:34600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD1sjqbtjBYzqM1uYyrgAAAAY"]
[Thu Jul 30 12:03:18.651227 2026] [security2:error] [pid 643253:tid 643435] [client 172.237.109.114:56197] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD1sjqbtjBYzqM1uYyrwAAADM"]
[Thu Jul 30 12:03:18.653951 2026] [security2:error] [pid 643253:tid 643440] [client 172.237.109.114:32702] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD1sjqbtjBYzqM1uYysAAAADg"]
[Thu Jul 30 12:03:18.695570 2026] [security2:error] [pid 643253:tid 643467] [client 172.237.109.114:40631] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD1sjqbtjBYzqM1uYysQAAAFM"]
[Thu Jul 30 12:03:18.774198 2026] [core:notice] [pid 643253:tid 643488] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:18.868584 2026] [security2:error] [pid 643253:tid 643480] [client 20.100.173.28:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/1.php"] [unique_id "amuD1sjqbtjBYzqM1uYyxQAAAGA"]
[Thu Jul 30 12:03:18.868691 2026] [security2:error] [pid 643253:tid 643480] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/1.php"] [unique_id "amuD1sjqbtjBYzqM1uYyxQAAAGA"]
[Thu Jul 30 12:03:18.868780 2026] [security2:error] [pid 643253:tid 643480] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/1.php"] [unique_id "amuD1sjqbtjBYzqM1uYyxQAAAGA"]
[Thu Jul 30 12:03:18.967318 2026] [security2:error] [pid 643253:tid 643461] [client 20.100.187.246:63317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/accueil.php"] [unique_id "amuD1sjqbtjBYzqM1uYyxgAAAE0"]
[Thu Jul 30 12:03:19.205203 2026] [security2:error] [pid 643253:tid 643411] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/chosen.php"] [unique_id "amuD18jqbtjBYzqM1uYyyQAAABs"]
[Thu Jul 30 12:03:19.205370 2026] [security2:error] [pid 643253:tid 643411] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/chosen.php"] [unique_id "amuD18jqbtjBYzqM1uYyyQAAABs"]
[Thu Jul 30 12:03:19.313265 2026] [core:notice] [pid 643253:tid 643492] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:19.317734 2026] [security2:error] [pid 643253:tid 643492] [client 103.215.74.26:47832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD18jqbtjBYzqM1uYy0AAAAGw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:19.526697 2026] [security2:error] [pid 643253:tid 643487] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/sd.php"] [unique_id "amuD18jqbtjBYzqM1uYy0QAAAGc"]
[Thu Jul 30 12:03:19.526852 2026] [security2:error] [pid 643253:tid 643487] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/sd.php"] [unique_id "amuD18jqbtjBYzqM1uYy0QAAAGc"]
[Thu Jul 30 12:03:19.578256 2026] [security2:error] [pid 643253:tid 643509] [client 172.237.109.114:50182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD18jqbtjBYzqM1uYyxwAAAH0"]
[Thu Jul 30 12:03:19.836448 2026] [security2:error] [pid 643253:tid 643455] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/z60.php"] [unique_id "amuD18jqbtjBYzqM1uYy1wAAAEc"]
[Thu Jul 30 12:03:19.836529 2026] [security2:error] [pid 643253:tid 643455] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/z60.php"] [unique_id "amuD18jqbtjBYzqM1uYy1wAAAEc"]
[Thu Jul 30 12:03:20.042597 2026] [core:notice] [pid 643253:tid 643423] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:20.046932 2026] [security2:error] [pid 643253:tid 643423] [client 103.215.74.26:47836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD2MjqbtjBYzqM1uYy2gAAACc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:20.141175 2026] [security2:error] [pid 643253:tid 643471] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/home.php"] [unique_id "amuD2MjqbtjBYzqM1uYy4QAAAFc"]
[Thu Jul 30 12:03:20.141347 2026] [security2:error] [pid 643253:tid 643471] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/home.php"] [unique_id "amuD2MjqbtjBYzqM1uYy4QAAAFc"]
[Thu Jul 30 12:03:20.445826 2026] [security2:error] [pid 643253:tid 643406] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/ws58.php"] [unique_id "amuD2MjqbtjBYzqM1uYy6AAAABY"]
[Thu Jul 30 12:03:20.445929 2026] [security2:error] [pid 643253:tid 643406] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/ws58.php"] [unique_id "amuD2MjqbtjBYzqM1uYy6AAAABY"]
[Thu Jul 30 12:03:20.505727 2026] [security2:error] [pid 643253:tid 643418] [client 216.73.216.137:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuD1sjqbtjBYzqM1uYytQAAIkM"], referer: http://www.spececigarette.com/sitemap.xml
[Thu Jul 30 12:03:20.592443 2026] [security2:error] [pid 643253:tid 643430] [client 172.237.109.114:40879] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD2MjqbtjBYzqM1uYy3wAAAC4"]
[Thu Jul 30 12:03:20.601390 2026] [security2:error] [pid 643253:tid 643439] [client 172.237.109.114:13796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD2MjqbtjBYzqM1uYy3gAAADc"]
[Thu Jul 30 12:03:20.653960 2026] [security2:error] [pid 643253:tid 643444] [client 172.237.109.114:28938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD2MjqbtjBYzqM1uYy4AAAADw"]
[Thu Jul 30 12:03:20.769091 2026] [security2:error] [pid 643253:tid 643431] [client 20.100.187.246:63343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/dashboard.php"] [unique_id "amuD2MjqbtjBYzqM1uYy6wAAAC8"]
[Thu Jul 30 12:03:20.789096 2026] [security2:error] [pid 643253:tid 643495] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/gulu.php"] [unique_id "amuD2MjqbtjBYzqM1uYy7QAAAG8"]
[Thu Jul 30 12:03:20.789195 2026] [security2:error] [pid 643253:tid 643495] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/gulu.php"] [unique_id "amuD2MjqbtjBYzqM1uYy7QAAAG8"]
[Thu Jul 30 12:03:20.808042 2026] [core:notice] [pid 643253:tid 643391] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:20.812164 2026] [security2:error] [pid 643253:tid 643391] [client 103.215.74.26:47838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD2MjqbtjBYzqM1uYy8AAAAAc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:21.105796 2026] [security2:error] [pid 643253:tid 643419] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuD2cjqbtjBYzqM1uYy9AAAACM"]
[Thu Jul 30 12:03:21.105910 2026] [security2:error] [pid 643253:tid 643419] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuD2cjqbtjBYzqM1uYy9AAAACM"]
[Thu Jul 30 12:03:21.280327 2026] [security2:error] [pid 643253:tid 643505] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuD2MjqbtjBYzqM1uYy6gAAeVI"]
[Thu Jul 30 12:03:21.436021 2026] [security2:error] [pid 643253:tid 643473] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wpls.php"] [unique_id "amuD2cjqbtjBYzqM1uYy_QAAAFk"]
[Thu Jul 30 12:03:21.436133 2026] [security2:error] [pid 643253:tid 643473] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wpls.php"] [unique_id "amuD2cjqbtjBYzqM1uYy_QAAAFk"]
[Thu Jul 30 12:03:21.546660 2026] [core:notice] [pid 643253:tid 643384] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:21.551033 2026] [security2:error] [pid 643253:tid 643384] [client 103.215.74.26:47842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD2cjqbtjBYzqM1uYy_gAAAAA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:21.791143 2026] [security2:error] [pid 643253:tid 643490] [client 20.100.187.246:63529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/radio.php"] [unique_id "amuD2cjqbtjBYzqM1uYzBAAAAGo"]
[Thu Jul 30 12:03:22.276963 2026] [security2:error] [pid 643253:tid 643448] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/php.php"] [unique_id "amuD2sjqbtjBYzqM1uYzDwAAAEA"]
[Thu Jul 30 12:03:22.277097 2026] [security2:error] [pid 643253:tid 643448] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/php.php"] [unique_id "amuD2sjqbtjBYzqM1uYzDwAAAEA"]
[Thu Jul 30 12:03:22.290248 2026] [core:notice] [pid 643253:tid 643502] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:22.294249 2026] [security2:error] [pid 643253:tid 643502] [client 103.215.74.26:47844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD2sjqbtjBYzqM1uYzEAAAAHY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:22.526995 2026] [autoindex:error] [pid 643253:tid 643432] [client 34.224.175.62:38407] AH01276: Cannot serve directory /home2/kiinyxte/xexrecords.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:03:22.561089 2026] [core:notice] [pid 643253:tid 643470] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:22.630521 2026] [security2:error] [pid 643253:tid 643423] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/100.php"] [unique_id "amuD2sjqbtjBYzqM1uYzHAAAACc"]
[Thu Jul 30 12:03:22.630633 2026] [security2:error] [pid 643253:tid 643423] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/100.php"] [unique_id "amuD2sjqbtjBYzqM1uYzHAAAACc"]
[Thu Jul 30 12:03:22.661804 2026] [security2:error] [pid 643253:tid 643509] [client 173.252.87.112:45156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ecvh.ae"] [uri "/index.php"] [unique_id "amuD2sjqbtjBYzqM1uYzDgAAAH0"]
[Thu Jul 30 12:03:22.934946 2026] [security2:error] [pid 643253:tid 643452] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/BDKR28WP.php"] [unique_id "amuD2sjqbtjBYzqM1uYzIgAAAEQ"]
[Thu Jul 30 12:03:22.935057 2026] [security2:error] [pid 643253:tid 643452] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/BDKR28WP.php"] [unique_id "amuD2sjqbtjBYzqM1uYzIgAAAEQ"]
[Thu Jul 30 12:03:23.254964 2026] [security2:error] [pid 643253:tid 643444] [client 173.252.87.112:45170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecvh.ae"] [uri "/index.php"] [unique_id "amuD28jqbtjBYzqM1uYzKQAAADw"]
[Thu Jul 30 12:03:23.274464 2026] [security2:error] [pid 643253:tid 643495] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/browse.php"] [unique_id "amuD28jqbtjBYzqM1uYzKgAAAG8"]
[Thu Jul 30 12:03:23.274557 2026] [security2:error] [pid 643253:tid 643495] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/browse.php"] [unique_id "amuD28jqbtjBYzqM1uYzKgAAAG8"]
[Thu Jul 30 12:03:23.540911 2026] [security2:error] [pid 643253:tid 643465] [client 2a03:2880:f800:2a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuD2sjqbtjBYzqM1uYzIAAAUWc"]
[Thu Jul 30 12:03:23.548781 2026] [security2:error] [pid 643253:tid 643474] [client 173.252.87.4:51340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ecvh.ae"] [uri "/index.php"] [unique_id "amuD28jqbtjBYzqM1uYzMwAAAFo"]
[Thu Jul 30 12:03:23.587188 2026] [security2:error] [pid 643253:tid 643480] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-good.php"] [unique_id "amuD28jqbtjBYzqM1uYzSAAAAGA"]
[Thu Jul 30 12:03:23.587280 2026] [security2:error] [pid 643253:tid 643480] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-good.php"] [unique_id "amuD28jqbtjBYzqM1uYzSAAAAGA"]
[Thu Jul 30 12:03:23.895822 2026] [security2:error] [pid 643253:tid 643500] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/8573.php"] [unique_id "amuD28jqbtjBYzqM1uYzSwAAAHQ"]
[Thu Jul 30 12:03:23.895927 2026] [security2:error] [pid 643253:tid 643500] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/8573.php"] [unique_id "amuD28jqbtjBYzqM1uYzSwAAAHQ"]
[Thu Jul 30 12:03:24.063830 2026] [security2:error] [pid 643253:tid 643385] [client 173.252.87.4:51348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecvh.ae"] [uri "/index.php"] [unique_id "amuD3MjqbtjBYzqM1uYzZgAAAAE"]
[Thu Jul 30 12:03:24.227305 2026] [security2:error] [pid 643253:tid 643502] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-admin/install.php"] [unique_id "amuD3MjqbtjBYzqM1uYzaAAAAHY"]
[Thu Jul 30 12:03:24.227420 2026] [security2:error] [pid 643253:tid 643502] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-admin/install.php"] [unique_id "amuD3MjqbtjBYzqM1uYzaAAAAHY"]
[Thu Jul 30 12:03:24.564873 2026] [security2:error] [pid 643253:tid 643445] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/classwithtostring.php"] [unique_id "amuD3MjqbtjBYzqM1uYzbAAAAD0"]
[Thu Jul 30 12:03:24.564968 2026] [security2:error] [pid 643253:tid 643445] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/classwithtostring.php"] [unique_id "amuD3MjqbtjBYzqM1uYzbAAAAD0"]
[Thu Jul 30 12:03:24.924904 2026] [security2:error] [pid 643253:tid 643470] [client 173.252.87.7:44604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecvh.ae"] [uri "/index.php"] [unique_id "amuD3MjqbtjBYzqM1uYzcAAAVhU"]
[Thu Jul 30 12:03:25.222813 2026] [security2:error] [pid 643253:tid 643452] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/ohct.php"] [unique_id "amuD3cjqbtjBYzqM1uYzdwAAAEQ"]
[Thu Jul 30 12:03:25.222921 2026] [security2:error] [pid 643253:tid 643452] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/ohct.php"] [unique_id "amuD3cjqbtjBYzqM1uYzdwAAAEQ"]
[Thu Jul 30 12:03:25.528933 2026] [security2:error] [pid 643253:tid 643405] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/bless.php"] [unique_id "amuD3cjqbtjBYzqM1uYzfgAAABU"]
[Thu Jul 30 12:03:25.529041 2026] [security2:error] [pid 643253:tid 643405] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/bless.php"] [unique_id "amuD3cjqbtjBYzqM1uYzfgAAABU"]
[Thu Jul 30 12:03:25.843999 2026] [proxy:error] [pid 643253:tid 643477] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:25.844072 2026] [proxy_http:error] [pid 643253:tid 643477] [client 192.210.150.196:45434] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:25.844839 2026] [proxy:error] [pid 643253:tid 643477] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:25.844891 2026] [proxy_http:error] [pid 643253:tid 643477] [client 192.210.150.196:45434] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:25.879665 2026] [security2:error] [pid 643253:tid 643397] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/about.php"] [unique_id "amuD3cjqbtjBYzqM1uYziwAAAA0"]
[Thu Jul 30 12:03:25.879772 2026] [security2:error] [pid 643253:tid 643397] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/about.php"] [unique_id "amuD3cjqbtjBYzqM1uYziwAAAA0"]
[Thu Jul 30 12:03:26.190416 2026] [security2:error] [pid 643253:tid 643504] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuD3sjqbtjBYzqM1uYzlQAAAHg"]
[Thu Jul 30 12:03:26.190501 2026] [security2:error] [pid 643253:tid 643504] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuD3sjqbtjBYzqM1uYzlQAAAHg"]
[Thu Jul 30 12:03:26.199285 2026] [security2:error] [pid 643253:tid 643437] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuD3cjqbtjBYzqM1uYzgwAANSE"]
[Thu Jul 30 12:03:26.502400 2026] [security2:error] [pid 643253:tid 643399] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/ta0ol.php"] [unique_id "amuD3sjqbtjBYzqM1uYzlwAAAA8"]
[Thu Jul 30 12:03:26.502511 2026] [security2:error] [pid 643253:tid 643399] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/ta0ol.php"] [unique_id "amuD3sjqbtjBYzqM1uYzlwAAAA8"]
[Thu Jul 30 12:03:26.806380 2026] [security2:error] [pid 643253:tid 643447] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/sa.php7"] [unique_id "amuD3sjqbtjBYzqM1uYznwAAAD8"]
[Thu Jul 30 12:03:26.806507 2026] [security2:error] [pid 643253:tid 643447] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/sa.php7"] [unique_id "amuD3sjqbtjBYzqM1uYznwAAAD8"]
[Thu Jul 30 12:03:27.118724 2026] [security2:error] [pid 643253:tid 643423] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-class.php"] [unique_id "amuD38jqbtjBYzqM1uYz5gAAACc"]
[Thu Jul 30 12:03:27.118816 2026] [security2:error] [pid 643253:tid 643423] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-class.php"] [unique_id "amuD38jqbtjBYzqM1uYz5gAAACc"]
[Thu Jul 30 12:03:27.344334 2026] [security2:error] [pid 643253:tid 643492] [client 176.241.66.87:2470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuD38jqbtjBYzqM1uY0cAAAAGw"]
[Thu Jul 30 12:03:27.344442 2026] [security2:error] [pid 643253:tid 643492] [client 176.241.66.87:2470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuD38jqbtjBYzqM1uY0cAAAAGw"]
[Thu Jul 30 12:03:27.467810 2026] [security2:error] [pid 643253:tid 643427] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/8.php"] [unique_id "amuD38jqbtjBYzqM1uY0lwAAACs"]
[Thu Jul 30 12:03:27.467903 2026] [security2:error] [pid 643253:tid 643427] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/8.php"] [unique_id "amuD38jqbtjBYzqM1uY0lwAAACs"]
[Thu Jul 30 12:03:27.724834 2026] [security2:error] [pid 643253:tid 643448] [client 50.6.43.217:37500] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/1.jpg"] [unique_id "amuD38jqbtjBYzqM1uY0oQAAAEA"]
[Thu Jul 30 12:03:27.734341 2026] [security2:error] [pid 643253:tid 643396] [client 50.6.43.217:37504] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/2.jpg"] [unique_id "amuD38jqbtjBYzqM1uY0owAAAAw"]
[Thu Jul 30 12:03:27.744790 2026] [security2:error] [pid 643253:tid 643387] [client 50.6.43.217:37510] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/3.jpg"] [unique_id "amuD38jqbtjBYzqM1uY0pAAAAAM"]
[Thu Jul 30 12:03:27.998445 2026] [security2:error] [pid 643253:tid 643455] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/bootstrap.php"] [unique_id "amuD38jqbtjBYzqM1uY0rAAAAEc"]
[Thu Jul 30 12:03:27.998531 2026] [security2:error] [pid 643253:tid 643455] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/bootstrap.php"] [unique_id "amuD38jqbtjBYzqM1uY0rAAAAEc"]
[Thu Jul 30 12:03:28.043334 2026] [core:notice] [pid 643253:tid 643432] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:28.048127 2026] [security2:error] [pid 643253:tid 643432] [client 103.215.74.26:22266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD4MjqbtjBYzqM1uY0rQAAADA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:28.306522 2026] [security2:error] [pid 643253:tid 643495] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-blog-header.php"] [unique_id "amuD4MjqbtjBYzqM1uY0uAAAAG8"]
[Thu Jul 30 12:03:28.306624 2026] [security2:error] [pid 643253:tid 643495] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-blog-header.php"] [unique_id "amuD4MjqbtjBYzqM1uY0uAAAAG8"]
[Thu Jul 30 12:03:28.466756 2026] [security2:error] [pid 643253:tid 643510] [client 20.100.187.246:35742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/wpsml-sys.php"] [unique_id "amuD4MjqbtjBYzqM1uY0uQAAAH4"]
[Thu Jul 30 12:03:28.506150 2026] [core:notice] [pid 643253:tid 643491] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:28.525418 2026] [proxy:error] [pid 643253:tid 643481] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:28.525515 2026] [proxy_http:error] [pid 643253:tid 643481] [client 192.210.150.196:41498] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:28.526104 2026] [proxy:error] [pid 643253:tid 643481] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:28.526149 2026] [proxy_http:error] [pid 643253:tid 643481] [client 192.210.150.196:41498] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:28.625487 2026] [security2:error] [pid 643253:tid 643474] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/aa.php"] [unique_id "amuD4MjqbtjBYzqM1uY0vQAAAFo"]
[Thu Jul 30 12:03:28.625595 2026] [security2:error] [pid 643253:tid 643474] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/aa.php"] [unique_id "amuD4MjqbtjBYzqM1uY0vQAAAFo"]
[Thu Jul 30 12:03:28.938157 2026] [security2:error] [pid 643253:tid 643415] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/tx79.php"] [unique_id "amuD4MjqbtjBYzqM1uY0xAAAAB8"]
[Thu Jul 30 12:03:28.938264 2026] [security2:error] [pid 643253:tid 643415] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/tx79.php"] [unique_id "amuD4MjqbtjBYzqM1uY0xAAAAB8"]
[Thu Jul 30 12:03:29.260680 2026] [security2:error] [pid 643253:tid 643484] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/motu.php"] [unique_id "amuD4cjqbtjBYzqM1uY0ywAAAGQ"]
[Thu Jul 30 12:03:29.260782 2026] [security2:error] [pid 643253:tid 643484] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/motu.php"] [unique_id "amuD4cjqbtjBYzqM1uY0ywAAAGQ"]
[Thu Jul 30 12:03:29.571264 2026] [security2:error] [pid 643253:tid 643492] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-head.php"] [unique_id "amuD4cjqbtjBYzqM1uY0zAAAAGw"]
[Thu Jul 30 12:03:29.571382 2026] [security2:error] [pid 643253:tid 643492] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-head.php"] [unique_id "amuD4cjqbtjBYzqM1uY0zAAAAGw"]
[Thu Jul 30 12:03:29.596900 2026] [security2:error] [pid 643253:tid 643418] [client 20.100.187.246:59835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/02.php"] [unique_id "amuD4cjqbtjBYzqM1uY0zQAAACI"]
[Thu Jul 30 12:03:29.885447 2026] [security2:error] [pid 643253:tid 643399] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuD4cjqbtjBYzqM1uY01QAAAA8"]
[Thu Jul 30 12:03:29.885572 2026] [security2:error] [pid 643253:tid 643399] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuD4cjqbtjBYzqM1uY01QAAAA8"]
[Thu Jul 30 12:03:29.933331 2026] [security2:error] [pid 643253:tid 643260] [remote 65.181.116.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.116.181.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theaq.global"] [uri "/wp-login.php"] [unique_id "amuD4cjqbtjBYzqM1uY01gAAYAU"]
[Thu Jul 30 12:03:30.198209 2026] [security2:error] [pid 643253:tid 643434] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/60856e3a4findex.php"] [unique_id "amuD4sjqbtjBYzqM1uY01wAAADI"]
[Thu Jul 30 12:03:30.198326 2026] [security2:error] [pid 643253:tid 643434] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/60856e3a4findex.php"] [unique_id "amuD4sjqbtjBYzqM1uY01wAAADI"]
[Thu Jul 30 12:03:30.509476 2026] [security2:error] [pid 643253:tid 643489] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-the.php"] [unique_id "amuD4sjqbtjBYzqM1uY04AAAAGk"]
[Thu Jul 30 12:03:30.509592 2026] [security2:error] [pid 643253:tid 643489] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-the.php"] [unique_id "amuD4sjqbtjBYzqM1uY04AAAAGk"]
[Thu Jul 30 12:03:30.832541 2026] [security2:error] [pid 643253:tid 643494] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp.php"] [unique_id "amuD4sjqbtjBYzqM1uY06QAAAG4"]
[Thu Jul 30 12:03:30.832641 2026] [security2:error] [pid 643253:tid 643494] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp.php"] [unique_id "amuD4sjqbtjBYzqM1uY06QAAAG4"]
[Thu Jul 30 12:03:31.254168 2026] [security2:error] [pid 643253:tid 643498] [client 57.141.0.1:63978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuD4sjqbtjBYzqM1uY07AAAciQ"], referer: https://igetvape-australia.com/product/plus-s3-kit-cherry-pomegranate/
[Thu Jul 30 12:03:31.412755 2026] [security2:error] [pid 643253:tid 643479] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/users.php"] [unique_id "amuD48jqbtjBYzqM1uY09QAAAF8"]
[Thu Jul 30 12:03:31.412850 2026] [security2:error] [pid 643253:tid 643479] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/users.php"] [unique_id "amuD48jqbtjBYzqM1uY09QAAAF8"]
[Thu Jul 30 12:03:31.619740 2026] [proxy:error] [pid 643253:tid 643316] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:31.619801 2026] [proxy_http:error] [pid 643253:tid 643316] [remote 74.7.244.52:48496] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:31.620375 2026] [proxy:error] [pid 643253:tid 643316] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:31.620419 2026] [proxy_http:error] [pid 643253:tid 643316] [remote 74.7.244.52:48496] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:31.758019 2026] [security2:error] [pid 643253:tid 643435] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/tinysd.php"] [unique_id "amuD48jqbtjBYzqM1uY0-AAAADM"]
[Thu Jul 30 12:03:31.758130 2026] [security2:error] [pid 643253:tid 643435] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/tinysd.php"] [unique_id "amuD48jqbtjBYzqM1uY0-AAAADM"]
[Thu Jul 30 12:03:32.066358 2026] [security2:error] [pid 643253:tid 643384] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/ws78.php"] [unique_id "amuD5MjqbtjBYzqM1uY1AAAAAAA"]
[Thu Jul 30 12:03:32.066474 2026] [security2:error] [pid 643253:tid 643384] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/ws78.php"] [unique_id "amuD5MjqbtjBYzqM1uY1AAAAAAA"]
[Thu Jul 30 12:03:32.145593 2026] [security2:error] [pid 643253:tid 643460] [client 57.141.0.10:27530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuD48jqbtjBYzqM1uY0_wAATEA"], referer: https://igetvape-australia.com/product-tag/alibarbar-pandora-blueberry-blast-7000-puffs/
[Thu Jul 30 12:03:32.384804 2026] [security2:error] [pid 643253:tid 643411] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/elp.php"] [unique_id "amuD5MjqbtjBYzqM1uY1BwAAABs"]
[Thu Jul 30 12:03:32.384948 2026] [security2:error] [pid 643253:tid 643411] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/elp.php"] [unique_id "amuD5MjqbtjBYzqM1uY1BwAAABs"]
[Thu Jul 30 12:03:32.569951 2026] [core:error] [pid 643253:tid 643420] [client 74.7.175.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:03:32.569972 2026] [core:error] [pid 643253:tid 643420] [client 74.7.175.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:03:32.570115 2026] [security2:error] [pid 643253:tid 643420] [client 74.7.175.131:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.ldk.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/index.php"] [unique_id "amuD5MjqbtjBYzqM1uY1IwAAACQ"]
[Thu Jul 30 12:03:32.570712 2026] [security2:error] [pid 643253:tid 643446] [client 74.7.175.131:52758] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.ldk.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "amuD5MjqbtjBYzqM1uY1IQAAPls"]
[Thu Jul 30 12:03:32.699144 2026] [security2:error] [pid 643253:tid 643409] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/atomlib.php"] [unique_id "amuD5MjqbtjBYzqM1uY1JAAAABk"]
[Thu Jul 30 12:03:32.699256 2026] [security2:error] [pid 643253:tid 643409] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/atomlib.php"] [unique_id "amuD5MjqbtjBYzqM1uY1JAAAABk"]
[Thu Jul 30 12:03:32.748222 2026] [security2:error] [pid 643253:tid 643438] [client 20.100.187.246:59262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/infos.php"] [unique_id "amuD5MjqbtjBYzqM1uY1JQAAADY"]
[Thu Jul 30 12:03:33.018244 2026] [security2:error] [pid 643253:tid 643509] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wyzer3.php"] [unique_id "amuD5cjqbtjBYzqM1uY1NgAAAH0"]
[Thu Jul 30 12:03:33.018360 2026] [security2:error] [pid 643253:tid 643509] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wyzer3.php"] [unique_id "amuD5cjqbtjBYzqM1uY1NgAAAH0"]
[Thu Jul 30 12:03:33.170509 2026] [core:notice] [pid 643253:tid 643313] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:33.331756 2026] [security2:error] [pid 643253:tid 643491] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/max.php"] [unique_id "amuD5cjqbtjBYzqM1uY1ZwAAAGs"]
[Thu Jul 30 12:03:33.331861 2026] [security2:error] [pid 643253:tid 643491] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/max.php"] [unique_id "amuD5cjqbtjBYzqM1uY1ZwAAAGs"]
[Thu Jul 30 12:03:33.639131 2026] [security2:error] [pid 643253:tid 643435] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/ftde.php"] [unique_id "amuD5cjqbtjBYzqM1uY1bAAAADM"]
[Thu Jul 30 12:03:33.639243 2026] [security2:error] [pid 643253:tid 643435] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/ftde.php"] [unique_id "amuD5cjqbtjBYzqM1uY1bAAAADM"]
[Thu Jul 30 12:03:33.858180 2026] [core:notice] [pid 643253:tid 643401] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:33.862285 2026] [security2:error] [pid 643253:tid 643401] [client 103.215.74.26:51778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD5cjqbtjBYzqM1uY1cQAAABE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:34.547092 2026] [security2:error] [pid 643253:tid 643422] [client 20.100.187.246:63244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/updates.php"] [unique_id "amuD5sjqbtjBYzqM1uY1hQAAACY"]
[Thu Jul 30 12:03:34.592469 2026] [core:notice] [pid 643253:tid 643392] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:34.596903 2026] [security2:error] [pid 643253:tid 643392] [client 103.215.74.26:51792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD5sjqbtjBYzqM1uY1hgAAAAg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:35.117155 2026] [security2:error] [pid 643253:tid 643305] [remote 57.141.0.31:39644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuD58jqbtjBYzqM1uY1lAAAGTI"]
[Thu Jul 30 12:03:35.223005 2026] [security2:error] [pid 643253:tid 643446] [client 20.100.187.246:59811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/user.php"] [unique_id "amuD58jqbtjBYzqM1uY1lQAAAD4"]
[Thu Jul 30 12:03:35.350587 2026] [core:notice] [pid 643253:tid 643497] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:35.357183 2026] [security2:error] [pid 643253:tid 643497] [client 103.215.74.26:51798] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD58jqbtjBYzqM1uY1nAAAAHE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:36.081917 2026] [core:notice] [pid 643253:tid 643503] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:36.089972 2026] [security2:error] [pid 643253:tid 643503] [client 103.215.74.26:51802] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD6MjqbtjBYzqM1uY1rAAAAHc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:36.352500 2026] [security2:error] [pid 643253:tid 643439] [client 223.109.255.168:51308] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/louis-vuitton-lv-trainer-white-brown/"] [unique_id "amuD6MjqbtjBYzqM1uY1rgAAADc"]
[Thu Jul 30 12:03:36.352665 2026] [security2:error] [pid 643253:tid 643439] [client 223.109.255.168:51308] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/product/louis-vuitton-lv-trainer-white-brown/"] [unique_id "amuD6MjqbtjBYzqM1uY1rgAAADc"]
[Thu Jul 30 12:03:36.833798 2026] [core:notice] [pid 643253:tid 643415] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:36.838013 2026] [security2:error] [pid 643253:tid 643415] [client 103.215.74.26:51816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD6MjqbtjBYzqM1uY1ugAAAB8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:37.029407 2026] [security2:error] [pid 643253:tid 643414] [client 20.100.187.246:63746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/admin-ajax.php"] [unique_id "amuD6cjqbtjBYzqM1uY1wAAAAB4"]
[Thu Jul 30 12:03:37.546353 2026] [security2:error] [pid 643253:tid 643318] [remote 190.92.171.214:54624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.171.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-login.php"] [unique_id "amuD6cjqbtjBYzqM1uY1xQAACD8"]
[Thu Jul 30 12:03:37.584621 2026] [core:notice] [pid 643253:tid 643451] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:37.589663 2026] [security2:error] [pid 643253:tid 643451] [client 103.215.74.26:51830] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "767"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD6cjqbtjBYzqM1uY1yQAAAEM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:38.010837 2026] [security2:error] [pid 643253:tid 643490] [client 176.241.66.87:58316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuD6sjqbtjBYzqM1uY1zwAAAGo"]
[Thu Jul 30 12:03:38.011021 2026] [security2:error] [pid 643253:tid 643490] [client 176.241.66.87:58316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuD6sjqbtjBYzqM1uY1zwAAAGo"]
[Thu Jul 30 12:03:38.303795 2026] [core:error] [pid 643253:tid 643413] [client 74.7.228.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:03:38.303815 2026] [core:error] [pid 643253:tid 643413] [client 74.7.228.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:03:38.303931 2026] [security2:error] [pid 643253:tid 643413] [client 74.7.228.59:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.jst.nyx.temporary.site"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amuD6sjqbtjBYzqM1uY11wAAAB0"]
[Thu Jul 30 12:03:38.304550 2026] [security2:error] [pid 643253:tid 643436] [client 74.7.228.59:47812] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.jst.nyx.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuD6sjqbtjBYzqM1uY11QAANEU"]
[Thu Jul 30 12:03:38.310317 2026] [core:notice] [pid 643253:tid 643464] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:38.316702 2026] [security2:error] [pid 643253:tid 643464] [client 103.215.74.26:51842] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD6sjqbtjBYzqM1uY12AAAAFA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:38.829026 2026] [security2:error] [pid 643253:tid 643444] [client 250.49.135.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuD6sjqbtjBYzqM1uY14AAAPEw"]
[Thu Jul 30 12:03:38.876242 2026] [security2:error] [pid 643253:tid 643457] [client 20.100.187.246:63751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/alfa.php"] [unique_id "amuD6sjqbtjBYzqM1uY14QAAAEk"]
[Thu Jul 30 12:03:39.042949 2026] [core:notice] [pid 643253:tid 643496] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:39.047081 2026] [security2:error] [pid 643253:tid 643496] [client 103.215.74.26:51846] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "780"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD68jqbtjBYzqM1uY15AAAAHA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:39.304565 2026] [security2:error] [pid 643253:tid 643332] [remote 57.141.0.51:47876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amuD68jqbtjBYzqM1uY16wAAKU0"]
[Thu Jul 30 12:03:39.789204 2026] [core:notice] [pid 643253:tid 643448] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:39.793204 2026] [security2:error] [pid 643253:tid 643448] [client 103.215.74.26:51862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD68jqbtjBYzqM1uY19AAAAEA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:39.860348 2026] [security2:error] [pid 643253:tid 643468] [client 20.100.187.246:61345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/hehe.php"] [unique_id "amuD68jqbtjBYzqM1uY19QAAAFQ"]
[Thu Jul 30 12:03:40.516001 2026] [core:notice] [pid 643253:tid 643384] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:40.519973 2026] [security2:error] [pid 643253:tid 643384] [client 103.215.74.26:51874] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD7MjqbtjBYzqM1uY1_gAAAAA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:41.215929 2026] [security2:error] [pid 643253:tid 643480] [client 2a03:2880:f800:30:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuD7MjqbtjBYzqM1uY1_QAAYGU"]
[Thu Jul 30 12:03:41.242800 2026] [core:notice] [pid 643253:tid 643407] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:41.247437 2026] [security2:error] [pid 643253:tid 643407] [client 103.215.74.26:51890] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD7cjqbtjBYzqM1uY2DQAAABc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:41.456223 2026] [security2:error] [pid 643253:tid 643462] [client 20.100.187.246:58685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/rk2.php"] [unique_id "amuD7cjqbtjBYzqM1uY2EQAAAE4"]
[Thu Jul 30 12:03:41.767778 2026] [security2:error] [pid 643253:tid 643334] [remote 52.167.144.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/jipkl/article/download/228/222/445"] [unique_id "amuD7cjqbtjBYzqM1uY2EgAAWE8"]
[Thu Jul 30 12:03:42.718023 2026] [security2:error] [pid 643253:tid 643444] [client 20.100.187.246:61331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/setup-config.php"] [unique_id "amuD7sjqbtjBYzqM1uY2IQAAADw"]
[Thu Jul 30 12:03:43.034959 2026] [security2:error] [pid 643253:tid 643479] [client 144.76.32.117:48060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "emmelevate.club"] [uri "/index.php"] [unique_id "amuD7sjqbtjBYzqM1uY2JwAAAF8"]
[Thu Jul 30 12:03:43.503164 2026] [security2:error] [pid 643253:tid 643450] [client 20.100.187.246:35914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/a7.php"] [unique_id "amuD78jqbtjBYzqM1uY2NQAAAEI"]
[Thu Jul 30 12:03:45.647852 2026] [security2:error] [pid 643253:tid 643476] [client 20.100.187.246:57421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/f7.php"] [unique_id "amuD8cjqbtjBYzqM1uY2UgAAAFw"]
[Thu Jul 30 12:03:46.382650 2026] [security2:error] [pid 643253:tid 643506] [client 20.100.187.246:35926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/nw.php"] [unique_id "amuD8sjqbtjBYzqM1uY2WwAAAHo"]
[Thu Jul 30 12:03:46.970025 2026] [core:notice] [pid 643253:tid 643503] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:46.975142 2026] [security2:error] [pid 643253:tid 643503] [client 103.215.74.26:6242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD8sjqbtjBYzqM1uY2aAAAAHc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:47.436161 2026] [security2:error] [pid 643253:tid 643458] [client 20.100.187.246:58654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/ova.php"] [unique_id "amuD88jqbtjBYzqM1uY2cQAAAEo"]
[Thu Jul 30 12:03:47.733677 2026] [core:notice] [pid 643253:tid 643489] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:47.740691 2026] [security2:error] [pid 643253:tid 643489] [client 103.215.74.26:6274] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD88jqbtjBYzqM1uY2dQAAAGk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:47.742940 2026] [security2:error] [pid 643253:tid 643375] [remote 74.7.241.60:45136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/content/article.php"] [unique_id "amuD88jqbtjBYzqM1uY2dgAAQXg"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/content/1784123347_ed%20inclusive.jpg
[Thu Jul 30 12:03:47.887989 2026] [core:notice] [pid 643253:tid 643259] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:47.968341 2026] [core:notice] [pid 643253:tid 643370] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:48.221060 2026] [security2:error] [pid 643253:tid 643460] [client 20.100.187.246:59196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/robots.php"] [unique_id "amuD9MjqbtjBYzqM1uY2hQAAAEw"]
[Thu Jul 30 12:03:48.495701 2026] [core:notice] [pid 643253:tid 643438] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:48.499725 2026] [security2:error] [pid 643253:tid 643438] [client 103.215.74.26:6294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD9MjqbtjBYzqM1uY2iwAAADY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:48.652082 2026] [core:notice] [pid 643253:tid 643263] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:48.808717 2026] [core:notice] [pid 643253:tid 643348] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:49.222212 2026] [core:notice] [pid 643253:tid 643447] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:49.226613 2026] [security2:error] [pid 643253:tid 643447] [client 103.215.74.26:6302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD9cjqbtjBYzqM1uY2nQAAAD8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:49.945804 2026] [core:notice] [pid 643253:tid 643406] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:49.950315 2026] [security2:error] [pid 643253:tid 643406] [client 103.215.74.26:6310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD9cjqbtjBYzqM1uY2rgAAABY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:50.670077 2026] [core:notice] [pid 643253:tid 643443] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:50.674890 2026] [security2:error] [pid 643253:tid 643443] [client 103.215.74.26:6320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD9sjqbtjBYzqM1uY2vQAAADs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:51.007872 2026] [security2:error] [pid 643253:tid 643490] [client 127.0.0.1:19848] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuD9sjqbtjBYzqM1uY2wAAAAGo"]
[Thu Jul 30 12:03:51.007949 2026] [security2:error] [pid 643253:tid 643496] [client 74.7.244.41:51272] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.alsafwafurnituremovers.cc"] [uri "/robots.txt"] [unique_id "amuD9sjqbtjBYzqM1uY2vwAAcHs"]
[Thu Jul 30 12:03:51.412834 2026] [core:notice] [pid 643253:tid 643499] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:51.417346 2026] [security2:error] [pid 643253:tid 643499] [client 103.215.74.26:6326] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD98jqbtjBYzqM1uY2yQAAAHM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:51.934272 2026] [security2:error] [pid 643253:tid 643473] [client 2a03:2880:f800:3:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuD98jqbtjBYzqM1uY2yAAAWRA"]
[Thu Jul 30 12:03:52.182082 2026] [core:notice] [pid 643253:tid 643422] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:52.187498 2026] [security2:error] [pid 643253:tid 643422] [client 103.215.74.26:6340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD-MjqbtjBYzqM1uY22QAAACY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:52.907460 2026] [core:notice] [pid 643253:tid 643413] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:52.912710 2026] [security2:error] [pid 643253:tid 643413] [client 103.215.74.26:6342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD-MjqbtjBYzqM1uY25QAAAB0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:53.160824 2026] [security2:error] [pid 643253:tid 643470] [client 20.100.187.246:35170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/alf.php"] [unique_id "amuD-cjqbtjBYzqM1uY26QAAAFY"]
[Thu Jul 30 12:03:53.640722 2026] [core:notice] [pid 643253:tid 643489] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:53.645889 2026] [security2:error] [pid 643253:tid 643489] [client 103.215.74.26:9760] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD-cjqbtjBYzqM1uY28wAAAGk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:53.835534 2026] [security2:error] [pid 643253:tid 643392] [client 4.223.71.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.71.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mshstrategic.com"] [uri "/.well-known/about.php"] [unique_id "amuD-cjqbtjBYzqM1uY2-QAAAAg"]
[Thu Jul 30 12:03:53.835694 2026] [security2:error] [pid 643253:tid 643392] [client 4.223.71.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mshstrategic.com"] [uri "/.well-known/about.php"] [unique_id "amuD-cjqbtjBYzqM1uY2-QAAAAg"]
[Thu Jul 30 12:03:54.362846 2026] [core:notice] [pid 643253:tid 643460] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:54.367307 2026] [security2:error] [pid 643253:tid 643460] [client 103.215.74.26:9762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD-sjqbtjBYzqM1uY3BwAAAEw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:55.120692 2026] [core:notice] [pid 643253:tid 643471] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:55.125830 2026] [security2:error] [pid 643253:tid 643471] [client 103.215.74.26:9766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD-8jqbtjBYzqM1uY3GAAAAFc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:55.857877 2026] [core:notice] [pid 643253:tid 643413] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:55.861820 2026] [security2:error] [pid 643253:tid 643413] [client 103.215.74.26:9782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD-8jqbtjBYzqM1uY3IwAAAB0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:56.120524 2026] [security2:error] [pid 643253:tid 643426] [client 20.100.187.246:59151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/feedback.php"] [unique_id "amuD_MjqbtjBYzqM1uY3KQAAACo"]
[Thu Jul 30 12:03:56.585708 2026] [core:notice] [pid 643253:tid 643506] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:56.589698 2026] [security2:error] [pid 643253:tid 643506] [client 103.215.74.26:9786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD_MjqbtjBYzqM1uY3MAAAAHo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:57.310527 2026] [core:notice] [pid 643253:tid 643490] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:57.317414 2026] [security2:error] [pid 643253:tid 643490] [client 103.215.74.26:9792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD_cjqbtjBYzqM1uY3UwAAAGo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:58.037682 2026] [core:notice] [pid 643253:tid 643429] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:58.042093 2026] [security2:error] [pid 643253:tid 643429] [client 103.215.74.26:9794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD_sjqbtjBYzqM1uY3YwAAAC0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:58.778246 2026] [core:notice] [pid 643253:tid 643458] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:58.785824 2026] [security2:error] [pid 643253:tid 643458] [client 103.215.74.26:9800] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD_sjqbtjBYzqM1uY3dgAAAEo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:59.334479 2026] [security2:error] [pid 643253:tid 643469] [client 172.236.9.101:37653] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3QwAAAFU"]
[Thu Jul 30 12:03:59.348371 2026] [security2:error] [pid 643253:tid 643462] [client 172.236.9.101:22513] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3SQAAAE4"]
[Thu Jul 30 12:03:59.352384 2026] [security2:error] [pid 643253:tid 643484] [client 172.236.9.101:32471] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3PwAAAGQ"]
[Thu Jul 30 12:03:59.368527 2026] [security2:error] [pid 643253:tid 643445] [client 172.236.9.101:39339] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3RwAAAD0"]
[Thu Jul 30 12:03:59.368713 2026] [security2:error] [pid 643253:tid 643442] [client 172.236.9.101:2718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3TQAAADo"]
[Thu Jul 30 12:03:59.368912 2026] [security2:error] [pid 643253:tid 643500] [client 172.236.9.101:5252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3RAAAAHQ"]
[Thu Jul 30 12:03:59.372814 2026] [security2:error] [pid 643253:tid 643487] [client 172.236.9.101:3423] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3QgAAAGc"]
[Thu Jul 30 12:03:59.375819 2026] [security2:error] [pid 643253:tid 643464] [client 172.236.9.101:22465] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3UQAAAFA"]
[Thu Jul 30 12:03:59.384726 2026] [security2:error] [pid 643253:tid 643499] [client 172.236.9.101:30153] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3SAAAAHM"]
[Thu Jul 30 12:03:59.387560 2026] [security2:error] [pid 643253:tid 643459] [client 172.236.9.101:7433] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3SwAAAEs"]
[Thu Jul 30 12:03:59.392244 2026] [security2:error] [pid 643253:tid 643504] [client 172.236.9.101:51727] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3RgAAAHg"]
[Thu Jul 30 12:03:59.401185 2026] [security2:error] [pid 643253:tid 643455] [client 172.236.9.101:31350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3UAAAAEc"]
[Thu Jul 30 12:03:59.404227 2026] [security2:error] [pid 643253:tid 643420] [client 172.236.9.101:13648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3RQAAACQ"]
[Thu Jul 30 12:03:59.415695 2026] [security2:error] [pid 643253:tid 643394] [client 172.236.9.101:64185] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3QQAAAAo"]
[Thu Jul 30 12:03:59.425787 2026] [security2:error] [pid 643253:tid 643389] [client 172.236.9.101:26054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3TAAAAAU"]
[Thu Jul 30 12:03:59.447745 2026] [security2:error] [pid 643253:tid 643480] [client 172.236.9.101:2613] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3QAAAAGA"]
[Thu Jul 30 12:03:59.452630 2026] [security2:error] [pid 643253:tid 643482] [client 172.236.9.101:38906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3SgAAAGI"]
[Thu Jul 30 12:03:59.469869 2026] [security2:error] [pid 643253:tid 643497] [client 172.236.9.101:1135] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3TwAAAHE"]
[Thu Jul 30 12:03:59.520119 2026] [core:notice] [pid 643253:tid 643415] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:59.527608 2026] [security2:error] [pid 643253:tid 643415] [client 103.215.74.26:9806] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD_8jqbtjBYzqM1uY3jAAAAB8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:59.549550 2026] [security2:error] [pid 643253:tid 643446] [client 172.236.9.101:54375] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3TgAAAD4"]
[Thu Jul 30 12:03:59.601622 2026] [security2:error] [pid 643253:tid 643472] [client 172.236.9.101:11082] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3UgAAAFg"]
[Thu Jul 30 12:03:59.679378 2026] [security2:error] [pid 643253:tid 643450] [client 155.254.34.253:36023] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuD_8jqbtjBYzqM1uY3gQAAAEI"], referer: https://cnpinyin.com/login/?redirect_to=https%3A%2F%2Fcnpinyin.com
[Thu Jul 30 12:04:00.248449 2026] [security2:error] [pid 643253:tid 643467] [client 20.100.187.246:59179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/gettest.php"] [unique_id "amuEAMjqbtjBYzqM1uY3lwAAAFM"]
[Thu Jul 30 12:04:00.248917 2026] [core:notice] [pid 643253:tid 643419] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:00.255688 2026] [security2:error] [pid 643253:tid 643419] [client 103.215.74.26:9808] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEAMjqbtjBYzqM1uY3lgAAACM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:00.732256 2026] [security2:error] [pid 643253:tid 643506] [client 35.238.83.104:59422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.progroupdoha.com"] [uri "/.env"] [unique_id "amuEAMjqbtjBYzqM1uY3wgAAAHo"]
[Thu Jul 30 12:04:00.961446 2026] [security2:error] [pid 643253:tid 643491] [client 57.141.0.40:22800] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuEAMjqbtjBYzqM1uY3owAAa04"], referer: https://igetvape-australia.com/store/?product-page=8&add-to-cart=426
[Thu Jul 30 12:04:00.987894 2026] [core:notice] [pid 643253:tid 643505] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:00.992900 2026] [security2:error] [pid 643253:tid 643505] [client 103.215.74.26:9824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "766"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEAMjqbtjBYzqM1uY3yAAAAHk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:01.153218 2026] [security2:error] [pid 643253:tid 643500] [client 20.100.187.246:35173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/maint.php"] [unique_id "amuEAcjqbtjBYzqM1uY35AAAAHQ"]
[Thu Jul 30 12:04:01.710156 2026] [core:notice] [pid 643253:tid 643407] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:01.718424 2026] [security2:error] [pid 643253:tid 643407] [client 103.215.74.26:9840] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEAcjqbtjBYzqM1uY37wAAABc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:02.294903 2026] [security2:error] [pid 643253:tid 643486] [client 50.6.43.217:46040] ModSecurity: Warning. Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "1439"] [id "9009999"] [msg "8 char spam"] [hostname "pkf.jo"] [uri "/wp-content/plugins/burst-statistics/endpoint.php"] [unique_id "amuEAsjqbtjBYzqM1uY3_QAAAGY"]
[Thu Jul 30 12:04:02.442327 2026] [core:notice] [pid 643253:tid 643404] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:02.446336 2026] [security2:error] [pid 643253:tid 643404] [client 103.215.74.26:9844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "779"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEAsjqbtjBYzqM1uY4BAAAABQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:02.820457 2026] [security2:error] [pid 643253:tid 643413] [client 85.208.96.201:40960] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/05/28/joao-azevedo-inaugura-e-autoriza-novas-obras-em-mais-seis-municipios-do-interior-da-paraiba-neste-sabado/"] [unique_id "amuEAsjqbtjBYzqM1uY4CwAAAB0"]
[Thu Jul 30 12:04:02.820615 2026] [security2:error] [pid 643253:tid 643413] [client 85.208.96.201:40960] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/05/28/joao-azevedo-inaugura-e-autoriza-novas-obras-em-mais-seis-municipios-do-interior-da-paraiba-neste-sabado/"] [unique_id "amuEAsjqbtjBYzqM1uY4CwAAAB0"]
[Thu Jul 30 12:04:03.175618 2026] [core:notice] [pid 643253:tid 643435] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:03.179636 2026] [security2:error] [pid 643253:tid 643435] [client 103.215.74.26:8628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEA8jqbtjBYzqM1uY4FQAAADM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:03.369697 2026] [security2:error] [pid 643253:tid 643400] [client 155.254.34.253:57617] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "cnpinyin.com"] [uri "/wp-comments-post.php"] [unique_id "amuEAsjqbtjBYzqM1uY4CAAAABA"], referer: https://cnpinyin.com/%e5%a5%87%e6%80%aa%e7%9a%84%e4%b8%ad%e8%8d%af%e8%8d%af%e9%85%92strange-brew/
[Thu Jul 30 12:04:03.486521 2026] [security2:error] [pid 643253:tid 643400] [client 155.254.34.253:57617] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "cnpinyin.com"] [uri "/wp-comments-post.php"] [unique_id "amuEAsjqbtjBYzqM1uY4CAAAABA"], referer: https://cnpinyin.com/%e5%a5%87%e6%80%aa%e7%9a%84%e4%b8%ad%e8%8d%af%e8%8d%af%e9%85%92strange-brew/
[Thu Jul 30 12:04:03.486589 2026] [security2:error] [pid 643253:tid 643400] [client 155.254.34.253:57617] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "cnpinyin.com"] [uri "/wp-comments-post.php"] [unique_id "amuEAsjqbtjBYzqM1uY4CAAAABA"], referer: https://cnpinyin.com/%e5%a5%87%e6%80%aa%e7%9a%84%e4%b8%ad%e8%8d%af%e8%8d%af%e9%85%92strange-brew/
[Thu Jul 30 12:04:03.908866 2026] [core:notice] [pid 643253:tid 643480] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:03.912999 2026] [security2:error] [pid 643253:tid 643480] [client 103.215.74.26:8632] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEA8jqbtjBYzqM1uY4HQAAAGA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:04.628177 2026] [core:notice] [pid 643253:tid 643393] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:04.633098 2026] [security2:error] [pid 643253:tid 643393] [client 103.215.74.26:8646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "761"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEBMjqbtjBYzqM1uY4LwAAAAk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:04.908695 2026] [security2:error] [pid 643253:tid 643414] [client 2a03:2880:f800:15:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEBMjqbtjBYzqM1uY4KAAAHhA"]
[Thu Jul 30 12:04:05.360755 2026] [core:notice] [pid 643253:tid 643503] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:05.365148 2026] [security2:error] [pid 643253:tid 643503] [client 103.215.74.26:8662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEBcjqbtjBYzqM1uY4QgAAAHc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:05.446191 2026] [core:error] [pid 643253:tid 643467] [client 74.7.230.63:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:04:05.446214 2026] [core:error] [pid 643253:tid 643467] [client 74.7.230.63:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:04:05.446333 2026] [security2:error] [pid 643253:tid 643467] [client 74.7.230.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.elitegaragedoorrepairservices.us"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "amuEBcjqbtjBYzqM1uY4UAAAAFM"]
[Thu Jul 30 12:04:05.447060 2026] [security2:error] [pid 643253:tid 643441] [client 74.7.230.63:41788] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.elitegaragedoorrepairservices.us"] [uri "/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "amuEBcjqbtjBYzqM1uY4TQAAORM"]
[Thu Jul 30 12:04:05.807739 2026] [security2:error] [pid 643253:tid 643502] [client 57.141.0.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuEBcjqbtjBYzqM1uY4OAAAAHY"]
[Thu Jul 30 12:04:06.106479 2026] [core:notice] [pid 643253:tid 643463] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:06.110632 2026] [security2:error] [pid 643253:tid 643463] [client 103.215.74.26:8664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEBsjqbtjBYzqM1uY4aAAAAE8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:06.463109 2026] [core:notice] [pid 643253:tid 643302] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:06.833242 2026] [core:notice] [pid 643253:tid 643467] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:06.837218 2026] [security2:error] [pid 643253:tid 643467] [client 103.215.74.26:8676] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEBsjqbtjBYzqM1uY4oAAAAFM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:07.151448 2026] [core:notice] [pid 643253:tid 643319] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:07.151512 2026] [core:notice] [pid 643253:tid 643318] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:07.151848 2026] [core:notice] [pid 643253:tid 643324] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:07.403494 2026] [core:notice] [pid 643253:tid 643337] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:07.569570 2026] [core:notice] [pid 643253:tid 643510] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:07.574150 2026] [security2:error] [pid 643253:tid 643510] [client 103.215.74.26:8680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEB8jqbtjBYzqM1uY4vAAAAH4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:07.663404 2026] [core:notice] [pid 643253:tid 643461] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:07.679219 2026] [core:notice] [pid 643253:tid 643336] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:07.679223 2026] [core:notice] [pid 643253:tid 643332] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:07.679355 2026] [core:notice] [pid 643253:tid 643339] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:07.679541 2026] [core:notice] [pid 643253:tid 643335] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:07.679712 2026] [core:notice] [pid 643253:tid 643331] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:08.192471 2026] [core:notice] [pid 643253:tid 643343] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:08.195321 2026] [security2:error] [pid 643253:tid 643439] [client 250.49.135.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuECMjqbtjBYzqM1uY40QAAN2U"]
[Thu Jul 30 12:04:08.294426 2026] [core:notice] [pid 643253:tid 643429] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:08.298704 2026] [security2:error] [pid 643253:tid 643429] [client 103.215.74.26:8686] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuECMjqbtjBYzqM1uY42QAAAC0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:08.304191 2026] [security2:error] [pid 643253:tid 643434] [client 20.100.187.246:35913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/files.php"] [unique_id "amuECMjqbtjBYzqM1uY42wAAADI"]
[Thu Jul 30 12:04:08.886662 2026] [core:notice] [pid 643253:tid 643328] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:09.035698 2026] [core:notice] [pid 643253:tid 643397] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:09.040251 2026] [security2:error] [pid 643253:tid 643397] [client 103.215.74.26:8698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuECcjqbtjBYzqM1uY48QAAAA0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:09.767074 2026] [core:notice] [pid 643253:tid 643358] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:09.767627 2026] [core:notice] [pid 643253:tid 643497] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:09.771677 2026] [security2:error] [pid 643253:tid 643497] [client 103.215.74.26:8714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuECcjqbtjBYzqM1uY5AgAAAHE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:10.027639 2026] [core:notice] [pid 643253:tid 643345] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:10.027639 2026] [core:notice] [pid 643253:tid 643368] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:10.027639 2026] [core:notice] [pid 643253:tid 643346] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:10.027885 2026] [core:notice] [pid 643253:tid 643354] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:10.064046 2026] [autoindex:error] [pid 643253:tid 643417] [client 66.132.172.129:0] AH01276: Cannot serve directory /home1/mthgzjte/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:04:10.282910 2026] [core:notice] [pid 643253:tid 643350] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:10.282910 2026] [core:notice] [pid 643253:tid 643344] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:10.282910 2026] [core:notice] [pid 643253:tid 643374] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:10.283071 2026] [core:notice] [pid 643253:tid 643366] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:10.511319 2026] [core:notice] [pid 643253:tid 643433] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:10.516717 2026] [security2:error] [pid 643253:tid 643433] [client 103.215.74.26:8718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuECsjqbtjBYzqM1uY5HgAAADE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:10.548178 2026] [core:notice] [pid 643253:tid 643369] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:10.548179 2026] [core:notice] [pid 643253:tid 643347] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:10.548179 2026] [core:notice] [pid 643253:tid 643333] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:10.867299 2026] [core:error] [pid 643253:tid 643367] [remote 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:04:10.867332 2026] [core:error] [pid 643253:tid 643367] [remote 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:04:10.938730 2026] [core:error] [pid 643253:tid 643381] [remote 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:04:10.938752 2026] [core:error] [pid 643253:tid 643381] [remote 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:04:10.993718 2026] [security2:error] [pid 643253:tid 643481] [client 136.70.70.191:62827] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "billsnap.fiyan.co"] [uri "/billsnap-ai-receipt-splitter//wp-includes/wlwmanifest.xml"] [unique_id "amuECsjqbtjBYzqM1uY5LAAAAGE"]
[Thu Jul 30 12:04:11.006595 2026] [core:notice] [pid 643253:tid 643364] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:11.106446 2026] [security2:error] [pid 643253:tid 643268] [remote 74.7.241.59:38904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuEC8jqbtjBYzqM1uY5LgAARQ0"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/premium-addons-for-elementor/modules/woocommerce/templates
[Thu Jul 30 12:04:11.259439 2026] [core:notice] [pid 643253:tid 643489] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:11.263689 2026] [security2:error] [pid 643253:tid 643489] [client 103.215.74.26:8732] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEC8jqbtjBYzqM1uY5NQAAAGk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:11.583438 2026] [core:notice] [pid 643253:tid 643352] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:11.816026 2026] [security2:error] [pid 643253:tid 643428] [client 20.100.187.246:59226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/gecko.php"] [unique_id "amuEC8jqbtjBYzqM1uY5QQAAACw"]
[Thu Jul 30 12:04:11.831288 2026] [core:notice] [pid 643253:tid 643264] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:11.831288 2026] [core:notice] [pid 643253:tid 643375] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:11.831288 2026] [core:notice] [pid 643253:tid 643349] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:11.853013 2026] [security2:error] [pid 643253:tid 643496] [client 172.202.44.182:4347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/chosen.php"] [unique_id "amuEC8jqbtjBYzqM1uY5RQAAAHA"]
[Thu Jul 30 12:04:12.007833 2026] [core:notice] [pid 643253:tid 643394] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:12.008338 2026] [security2:error] [pid 643253:tid 643502] [client 136.70.70.191:56782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.70.70.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "billsnap.fiyan.co"] [uri "/billsnap-ai-receipt-splitter//xmlrpc.php"] [unique_id "amuEDMjqbtjBYzqM1uY5TAAAAHY"]
[Thu Jul 30 12:04:12.012247 2026] [security2:error] [pid 643253:tid 643394] [client 103.215.74.26:8748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEDMjqbtjBYzqM1uY5TQAAAAo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:12.092199 2026] [core:notice] [pid 643253:tid 643277] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:12.092358 2026] [core:notice] [pid 643253:tid 643370] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:12.343130 2026] [core:notice] [pid 643253:tid 643316] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:12.595516 2026] [core:notice] [pid 643253:tid 643269] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:12.747276 2026] [core:notice] [pid 643253:tid 643417] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:12.754642 2026] [security2:error] [pid 643253:tid 643417] [client 103.215.74.26:8756] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEDMjqbtjBYzqM1uY5YQAAACE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:12.834721 2026] [security2:error] [pid 643253:tid 643466] [client 74.7.228.48:37132] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "happyspree.app.gxj.udi.temporary.site"] [uri "/index.php"] [unique_id "amuEDMjqbtjBYzqM1uY5WAAAUgY"]
[Thu Jul 30 12:04:12.886819 2026] [core:notice] [pid 643253:tid 643267] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:12.886995 2026] [core:notice] [pid 643253:tid 643256] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:13.026318 2026] [security2:error] [pid 643253:tid 643473] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEDMjqbtjBYzqM1uY5VwAAWXQ"]
[Thu Jul 30 12:04:13.348597 2026] [security2:error] [pid 643253:tid 643457] [client 57.141.0.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuEDMjqbtjBYzqM1uY5YAAAAEk"]
[Thu Jul 30 12:04:13.450664 2026] [core:notice] [pid 643253:tid 643286] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:13.482510 2026] [core:notice] [pid 643253:tid 643398] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:13.486896 2026] [security2:error] [pid 643253:tid 643398] [client 103.215.74.26:47048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEDcjqbtjBYzqM1uY5fQAAAA4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:13.510092 2026] [security2:error] [pid 643253:tid 643420] [client 20.100.187.246:62850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/zwso.php"] [unique_id "amuEDcjqbtjBYzqM1uY5fgAAACQ"]
[Thu Jul 30 12:04:14.211059 2026] [core:notice] [pid 643253:tid 643442] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:14.218711 2026] [security2:error] [pid 643253:tid 643442] [client 103.215.74.26:47052] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEDsjqbtjBYzqM1uY5kgAAADo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:14.219172 2026] [security2:error] [pid 643253:tid 643415] [client 172.202.44.182:4236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/xleet.php"] [unique_id "amuEDsjqbtjBYzqM1uY5kwAAAB8"]
[Thu Jul 30 12:04:14.236593 2026] [security2:error] [pid 643253:tid 643476] [client 20.100.187.246:58746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/13.php"] [unique_id "amuEDsjqbtjBYzqM1uY5lAAAAFw"]
[Thu Jul 30 12:04:14.302454 2026] [core:notice] [pid 643253:tid 643410] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:14.338241 2026] [core:notice] [pid 643253:tid 643273] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:14.474729 2026] [core:error] [pid 643253:tid 643401] [client 74.7.241.165:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:04:14.474753 2026] [core:error] [pid 643253:tid 643401] [client 74.7.241.165:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:04:14.474886 2026] [security2:error] [pid 643253:tid 643401] [client 74.7.241.165:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.muu.udi.temporary.site"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amuEDsjqbtjBYzqM1uY5nAAAABE"]
[Thu Jul 30 12:04:14.476662 2026] [security2:error] [pid 643253:tid 643502] [client 74.7.241.165:52430] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.muu.udi.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuEDsjqbtjBYzqM1uY5mgAAdhE"]
[Thu Jul 30 12:04:14.600987 2026] [core:notice] [pid 643253:tid 643297] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:15.538728 2026] [security2:error] [pid 643253:tid 643505] [client 172.202.44.182:43842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/ds.php"] [unique_id "amuED8jqbtjBYzqM1uY5rwAAAHk"]
[Thu Jul 30 12:04:16.001156 2026] [core:notice] [pid 643253:tid 643293] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:16.005017 2026] [security2:error] [pid 643253:tid 643458] [client 23.112.95.228:35027] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/2045"] [unique_id "amuED8jqbtjBYzqM1uY5sgAASiY"], referer: https://ejournalugj.com/
[Thu Jul 30 12:04:16.464683 2026] [core:notice] [pid 643253:tid 643288] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:16.712839 2026] [core:notice] [pid 643253:tid 643305] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:16.777942 2026] [security2:error] [pid 643253:tid 643462] [client 64.233.173.96:38045] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEEMjqbtjBYzqM1uY5wgAAAE4"]
[Thu Jul 30 12:04:18.413640 2026] [security2:error] [pid 643253:tid 643387] [client 136.70.70.191:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "billsnap.fiyan.co"] [uri "/index.php"] [unique_id "amuEEsjqbtjBYzqM1uY55QAAAAM"]
[Thu Jul 30 12:04:18.503235 2026] [security2:error] [pid 643253:tid 643405] [client 20.203.148.31:20193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/--wp-lgj.php"] [unique_id "amuEEsjqbtjBYzqM1uY56gAAABU"]
[Thu Jul 30 12:04:18.635862 2026] [security2:error] [pid 643253:tid 643423] [client 172.202.44.182:44270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/f5.php"] [unique_id "amuEEsjqbtjBYzqM1uY57wAAACc"]
[Thu Jul 30 12:04:18.814775 2026] [core:notice] [pid 643253:tid 643314] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:19.331221 2026] [security2:error] [pid 643253:tid 643318] [remote 207.46.13.92:8863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.13.46.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/sistema-erp-totvs-protheus/valuef.php"] [unique_id "amuEE8jqbtjBYzqM1uY5_AAADj8"]
[Thu Jul 30 12:04:19.603069 2026] [security2:error] [pid 643253:tid 643483] [client 20.203.148.31:20184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.well-known/autoload_classmap.php"] [unique_id "amuEE8jqbtjBYzqM1uY6AAAAAGM"]
[Thu Jul 30 12:04:19.937155 2026] [core:notice] [pid 643253:tid 643464] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:19.941288 2026] [security2:error] [pid 643253:tid 643464] [client 103.215.74.26:47054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "752"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEE8jqbtjBYzqM1uY6CAAAAFA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:20.329132 2026] [security2:error] [pid 643253:tid 643397] [client 136.70.70.191:60166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "billsnap.fiyan.co"] [uri "/index.php"] [unique_id "amuEFMjqbtjBYzqM1uY6CgAAAA0"]
[Thu Jul 30 12:04:20.396030 2026] [security2:error] [pid 643253:tid 643462] [client 20.203.148.31:25156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.well-known/flower.php"] [unique_id "amuEFMjqbtjBYzqM1uY6EQAAAE4"]
[Thu Jul 30 12:04:20.616217 2026] [security2:error] [pid 643253:tid 643440] [client 172.202.44.182:4346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/god4m.php"] [unique_id "amuEFMjqbtjBYzqM1uY6FgAAADg"]
[Thu Jul 30 12:04:20.665048 2026] [core:notice] [pid 643253:tid 643386] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:20.669354 2026] [security2:error] [pid 643253:tid 643386] [client 103.215.74.26:47068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEFMjqbtjBYzqM1uY6FwAAAAI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:20.723403 2026] [security2:error] [pid 643253:tid 643472] [client 136.70.70.191:60166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "billsnap.fiyan.co"] [uri "/index.php"] [unique_id "amuEFMjqbtjBYzqM1uY6FQAAAFg"]
[Thu Jul 30 12:04:20.960221 2026] [security2:error] [pid 643253:tid 643401] [client 57.141.0.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuEFMjqbtjBYzqM1uY6HwAAABE"]
[Thu Jul 30 12:04:20.977202 2026] [security2:error] [pid 643253:tid 643454] [client 136.70.70.191:60166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.70.70.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "billsnap.fiyan.co"] [uri "/billsnap-ai-receipt-splitter//xmlrpc.php"] [unique_id "amuEFMjqbtjBYzqM1uY6JQAAAEY"]
[Thu Jul 30 12:04:20.977337 2026] [security2:error] [pid 643253:tid 643454] [client 136.70.70.191:60166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "billsnap.fiyan.co"] [uri "/billsnap-ai-receipt-splitter//xmlrpc.php"] [unique_id "amuEFMjqbtjBYzqM1uY6JQAAAEY"]
[Thu Jul 30 12:04:21.121456 2026] [security2:error] [pid 643253:tid 643423] [client 162.216.148.0:22657] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "aptlaw.kr"] [uri "/robots.txt"] [unique_id "amuEFcjqbtjBYzqM1uY6JgAAACc"]
[Thu Jul 30 12:04:21.391896 2026] [security2:error] [pid 643253:tid 643425] [client 57.141.0.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuEFMjqbtjBYzqM1uY6IAAAACk"]
[Thu Jul 30 12:04:21.395925 2026] [core:notice] [pid 643253:tid 643426] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:21.400391 2026] [security2:error] [pid 643253:tid 643426] [client 103.215.74.26:47078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEFcjqbtjBYzqM1uY6NQAAACo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:21.630380 2026] [core:notice] [pid 643253:tid 643309] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:21.634945 2026] [security2:error] [pid 643253:tid 643430] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/site/pageHeaderTitleImage_id_ID.jpg"] [unique_id "amuEFcjqbtjBYzqM1uY6NAAALjY"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:21.636481 2026] [core:notice] [pid 643253:tid 643317] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:21.638788 2026] [core:notice] [pid 643253:tid 643301] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:21.640316 2026] [security2:error] [pid 643253:tid 643430] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/index_php/index/---call---/page/page/css-name-font.css"] [unique_id "amuEFcjqbtjBYzqM1uY6MQAALj4"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:21.642265 2026] [core:notice] [pid 643253:tid 643341] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:21.642832 2026] [security2:error] [pid 643253:tid 643430] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/index_php/index/---call---/page/page/css-name-stylesheet.css"] [unique_id "amuEFcjqbtjBYzqM1uY6MwAALi4"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:21.646031 2026] [security2:error] [pid 643253:tid 643430] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/lib/pkp/styles/fontawesome/fontawesome_v-3.3.0.17.css"] [unique_id "amuEFcjqbtjBYzqM1uY6MgAALlY"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:21.659868 2026] [security2:error] [pid 643253:tid 643419] [client 172.202.44.182:4234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/info.php"] [unique_id "amuEFcjqbtjBYzqM1uY6NgAAACM"]
[Thu Jul 30 12:04:21.711043 2026] [security2:error] [pid 643253:tid 643503] [client 20.203.148.31:13808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.well-known/xleet.php"] [unique_id "amuEFcjqbtjBYzqM1uY6NwAAAHc"]
[Thu Jul 30 12:04:22.010430 2026] [core:notice] [pid 643253:tid 643351] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.010430 2026] [core:notice] [pid 643253:tid 643329] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.010477 2026] [core:notice] [pid 643253:tid 643342] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.010632 2026] [core:notice] [pid 643253:tid 643355] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.010685 2026] [core:notice] [pid 643253:tid 643334] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.010708 2026] [core:notice] [pid 643253:tid 643338] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.010729 2026] [core:notice] [pid 643253:tid 643361] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.010744 2026] [core:notice] [pid 643253:tid 643326] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.014155 2026] [security2:error] [pid 643253:tid 643484] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/17/journalThumbnail_en_US.png"] [unique_id "amuEFsjqbtjBYzqM1uY6QQAAZGA"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.014520 2026] [security2:error] [pid 643253:tid 643484] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/11/journalThumbnail_id_ID.jpg"] [unique_id "amuEFsjqbtjBYzqM1uY6QgAAZEo"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.014999 2026] [security2:error] [pid 643253:tid 643484] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/site/images/apranolo/Crossref_Logo_Stacked_RGB_SMALL.png"] [unique_id "amuEFsjqbtjBYzqM1uY6RgAAZFM"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.015219 2026] [security2:error] [pid 643253:tid 643484] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/33/journalThumbnail_id_ID.jpg"] [unique_id "amuEFsjqbtjBYzqM1uY6RQAAZFc"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.015478 2026] [security2:error] [pid 643253:tid 643484] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/19/journalThumbnail_id_ID.jpg"] [unique_id "amuEFsjqbtjBYzqM1uY6RwAAZEc"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.015613 2026] [security2:error] [pid 643253:tid 643484] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/22/journalThumbnail_en_US.jpg"] [unique_id "amuEFsjqbtjBYzqM1uY6SAAAZGQ"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.016827 2026] [security2:error] [pid 643253:tid 643484] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/32/journalThumbnail_id_ID.jpg"] [unique_id "amuEFsjqbtjBYzqM1uY6QwAAZE8"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.017114 2026] [security2:error] [pid 643253:tid 643484] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/44/journalThumbnail_id_ID.png"] [unique_id "amuEFsjqbtjBYzqM1uY6RAAAZGo"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.039388 2026] [security2:error] [pid 643253:tid 643477] [client 37.120.155.179:45060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.155.120.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuEFsjqbtjBYzqM1uY6SQAAAF0"]
[Thu Jul 30 12:04:22.039479 2026] [security2:error] [pid 643253:tid 643477] [client 37.120.155.179:45060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuEFsjqbtjBYzqM1uY6SQAAAF0"]
[Thu Jul 30 12:04:22.119703 2026] [core:notice] [pid 643253:tid 643483] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.130878 2026] [security2:error] [pid 643253:tid 643483] [client 103.215.74.26:47080] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEFsjqbtjBYzqM1uY6SgAAAGM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:22.264129 2026] [core:notice] [pid 643253:tid 643363] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.264134 2026] [core:notice] [pid 643253:tid 643346] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.264193 2026] [core:notice] [pid 643253:tid 643344] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.264195 2026] [core:notice] [pid 643253:tid 643354] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.264240 2026] [core:notice] [pid 643253:tid 643368] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.264444 2026] [core:notice] [pid 643253:tid 643345] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.264444 2026] [core:notice] [pid 643253:tid 643358] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.264548 2026] [core:notice] [pid 643253:tid 643365] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.267802 2026] [security2:error] [pid 643253:tid 643451] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/10/journalThumbnail_id_ID.jpg"] [unique_id "amuEFsjqbtjBYzqM1uY6UQAAQ2w"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.268181 2026] [security2:error] [pid 643253:tid 643451] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/21/journalThumbnail_id_ID.jpg"] [unique_id "amuEFsjqbtjBYzqM1uY6VQAAQ2M"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.269798 2026] [security2:error] [pid 643253:tid 643451] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/14/journalThumbnail_id_ID.jpg"] [unique_id "amuEFsjqbtjBYzqM1uY6VgAAQ1k"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.270132 2026] [security2:error] [pid 643253:tid 643451] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/39/journalThumbnail_en_US.png"] [unique_id "amuEFsjqbtjBYzqM1uY6TwAAQ24"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.270251 2026] [security2:error] [pid 643253:tid 643451] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/8/journalThumbnail_id_ID.jpg"] [unique_id "amuEFsjqbtjBYzqM1uY6UAAAQ2c"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.270472 2026] [security2:error] [pid 643253:tid 643451] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/20/journalThumbnail_en_US.jpg"] [unique_id "amuEFsjqbtjBYzqM1uY6UgAAQ3E"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.270662 2026] [security2:error] [pid 643253:tid 643451] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/7/journalThumbnail_id_ID.png"] [unique_id "amuEFsjqbtjBYzqM1uY6VAAAQ1s"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.270885 2026] [security2:error] [pid 643253:tid 643451] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/24/journalThumbnail_id_ID.jpg"] [unique_id "amuEFsjqbtjBYzqM1uY6UwAAQ1o"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.516077 2026] [core:notice] [pid 643253:tid 643340] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.516077 2026] [core:notice] [pid 643253:tid 643377] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.516078 2026] [core:notice] [pid 643253:tid 643333] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.516077 2026] [core:notice] [pid 643253:tid 643366] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.516184 2026] [core:notice] [pid 643253:tid 643373] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.516205 2026] [core:notice] [pid 643253:tid 643347] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.516411 2026] [core:notice] [pid 643253:tid 643369] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.516411 2026] [core:notice] [pid 643253:tid 643313] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.519686 2026] [security2:error] [pid 643253:tid 643499] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/6/journalThumbnail_en_US.jpg"] [unique_id "amuEFsjqbtjBYzqM1uY6XgAAc28"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.519852 2026] [security2:error] [pid 643253:tid 643499] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/29/journalThumbnail_id_ID.jpg"] [unique_id "amuEFsjqbtjBYzqM1uY6YAAAc1U"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.519951 2026] [security2:error] [pid 643253:tid 643499] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/3/journalThumbnail_en_US.jpg"] [unique_id "amuEFsjqbtjBYzqM1uY6XwAAc3o"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.520249 2026] [security2:error] [pid 643253:tid 643499] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/4/journalThumbnail_id_ID.jpg"] [unique_id "amuEFsjqbtjBYzqM1uY6ZAAAczo"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.520409 2026] [security2:error] [pid 643253:tid 643499] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/1/journalThumbnail_id_ID.jpg"] [unique_id "amuEFsjqbtjBYzqM1uY6YQAAc3Y"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.520502 2026] [security2:error] [pid 643253:tid 643499] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/2/journalThumbnail_id_ID.png"] [unique_id "amuEFsjqbtjBYzqM1uY6YwAAc1w"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.520662 2026] [security2:error] [pid 643253:tid 643499] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/35/journalThumbnail_id_ID.jpg"] [unique_id "amuEFsjqbtjBYzqM1uY6YgAAc04"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.520889 2026] [security2:error] [pid 643253:tid 643499] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/25/journalThumbnail_id_ID.jpg"] [unique_id "amuEFsjqbtjBYzqM1uY6ZQAAc3I"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.733244 2026] [core:notice] [pid 643253:tid 643367] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.733244 2026] [core:notice] [pid 643253:tid 643359] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.736730 2026] [security2:error] [pid 643253:tid 643495] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/13/journalThumbnail_id_ID.jpg"] [unique_id "amuEFsjqbtjBYzqM1uY6ZwAAb2g"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.736894 2026] [security2:error] [pid 643253:tid 643495] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/templates/images/ojs_brand.png"] [unique_id "amuEFsjqbtjBYzqM1uY6ZgAAb3A"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.854785 2026] [core:notice] [pid 643253:tid 643397] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.861574 2026] [security2:error] [pid 643253:tid 643397] [client 103.215.74.26:47082] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEFsjqbtjBYzqM1uY6awAAAA0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:23.176701 2026] [security2:error] [pid 643253:tid 643401] [client 172.202.44.182:62018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/.__info.php"] [unique_id "amuEF8jqbtjBYzqM1uY6cwAAABE"]
[Thu Jul 30 12:04:23.395776 2026] [security2:error] [pid 643253:tid 643388] [client 20.203.148.31:19632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.well-known/acme-challenge/flower.php"] [unique_id "amuEF8jqbtjBYzqM1uY6eAAAAAQ"]
[Thu Jul 30 12:04:23.595013 2026] [core:notice] [pid 643253:tid 643482] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:23.599398 2026] [security2:error] [pid 643253:tid 643482] [client 103.215.74.26:9436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEF8jqbtjBYzqM1uY6fwAAAGI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:24.323873 2026] [core:notice] [pid 643253:tid 643494] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:24.328951 2026] [security2:error] [pid 643253:tid 643494] [client 103.215.74.26:9442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "768"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEGMjqbtjBYzqM1uY6jAAAAG4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:24.437108 2026] [security2:error] [pid 643253:tid 643395] [client 20.203.148.31:31475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.well-known/acme-challenge/xleet.php"] [unique_id "amuEGMjqbtjBYzqM1uY6kwAAAAs"]
[Thu Jul 30 12:04:24.532770 2026] [security2:error] [pid 643253:tid 643427] [client 20.100.187.246:63188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/ava.php"] [unique_id "amuEGMjqbtjBYzqM1uY6lwAAACs"]
[Thu Jul 30 12:04:24.584604 2026] [security2:error] [pid 643253:tid 643509] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEGMjqbtjBYzqM1uY6iAAAfQI"]
[Thu Jul 30 12:04:24.589353 2026] [security2:error] [pid 643253:tid 643503] [client 172.202.44.182:4226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/0.php"] [unique_id "amuEGMjqbtjBYzqM1uY6mQAAAHc"]
[Thu Jul 30 12:04:25.002337 2026] [security2:error] [pid 643253:tid 643399] [client 20.203.148.31:35333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amuEGcjqbtjBYzqM1uY6pAAAAA8"]
[Thu Jul 30 12:04:25.054319 2026] [core:notice] [pid 643253:tid 643507] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:25.061321 2026] [security2:error] [pid 643253:tid 643507] [client 103.215.74.26:9454] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEGcjqbtjBYzqM1uY6pQAAAHs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:25.106826 2026] [security2:error] [pid 643253:tid 643462] [client 88.99.80.227:44438] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuEGcjqbtjBYzqM1uY6pgAAAE4"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:04:25.476841 2026] [security2:error] [pid 643253:tid 643415] [client 116.179.37.217:2146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/ELTERA/$$$call$$$/page/page/css"] [unique_id "amuEGcjqbtjBYzqM1uY6pwAAAB8"], referer: https://ejournalugj.com/index.php/ELTERA/login
[Thu Jul 30 12:04:25.491531 2026] [security2:error] [pid 643253:tid 643407] [client 116.179.37.88:40214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/ELTERA/$$$call$$$/page/page/css"] [unique_id "amuEGcjqbtjBYzqM1uY6qAAAABc"], referer: https://ejournalugj.com/index.php/ELTERA/login
[Thu Jul 30 12:04:25.497796 2026] [core:notice] [pid 643253:tid 643414] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:25.502164 2026] [security2:error] [pid 643253:tid 643414] [client 88.99.80.227:44452] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEGcjqbtjBYzqM1uY6rwAAAB4"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:04:25.794028 2026] [core:notice] [pid 643253:tid 643471] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:25.798114 2026] [security2:error] [pid 643253:tid 643471] [client 103.215.74.26:9470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "781"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEGcjqbtjBYzqM1uY6sAAAAFc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:25.850167 2026] [security2:error] [pid 643253:tid 643409] [client 172.202.44.182:44247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/07.php"] [unique_id "amuEGcjqbtjBYzqM1uY6sQAAABk"]
[Thu Jul 30 12:04:25.954494 2026] [security2:error] [pid 643253:tid 643459] [client 88.99.80.227:44460] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuEGcjqbtjBYzqM1uY6sgAAAEs"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:04:26.552832 2026] [core:notice] [pid 643253:tid 643481] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:26.556728 2026] [security2:error] [pid 643253:tid 643481] [client 103.215.74.26:9476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEGsjqbtjBYzqM1uY6vwAAAGE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:26.790319 2026] [security2:error] [pid 643253:tid 643385] [client 172.202.44.182:44284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/dropdown.php"] [unique_id "amuEGsjqbtjBYzqM1uY6xAAAAAE"]
[Thu Jul 30 12:04:27.290087 2026] [core:notice] [pid 643253:tid 643419] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:27.292172 2026] [security2:error] [pid 643253:tid 643498] [client 213.152.187.225:39902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.187.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuEG8jqbtjBYzqM1uY6zgAAAHI"]
[Thu Jul 30 12:04:27.292268 2026] [security2:error] [pid 643253:tid 643498] [client 213.152.187.225:39902] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuEG8jqbtjBYzqM1uY6zgAAAHI"]
[Thu Jul 30 12:04:27.294051 2026] [security2:error] [pid 643253:tid 643419] [client 103.215.74.26:9482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEG8jqbtjBYzqM1uY6zwAAACM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:27.937426 2026] [security2:error] [pid 643253:tid 643402] [client 151.245.32.125:38232] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.248"] [uri "/"] [unique_id "amuEG8jqbtjBYzqM1uY62QAAABI"]
[Thu Jul 30 12:04:28.026434 2026] [core:notice] [pid 643253:tid 643505] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:28.030533 2026] [security2:error] [pid 643253:tid 643505] [client 103.215.74.26:9488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEHMjqbtjBYzqM1uY63gAAAHk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:28.123023 2026] [security2:error] [pid 643253:tid 643437] [client 172.202.44.182:4249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/makeasmtp.php"] [unique_id "amuEHMjqbtjBYzqM1uY65QAAADU"]
[Thu Jul 30 12:04:28.281033 2026] [security2:error] [pid 643253:tid 643478] [client 151.245.32.125:35778] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.248"] [uri "/"] [unique_id "amuEHMjqbtjBYzqM1uY67QAAAF4"]
[Thu Jul 30 12:04:28.745413 2026] [core:notice] [pid 643253:tid 643474] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:28.750703 2026] [security2:error] [pid 643253:tid 643474] [client 103.215.74.26:9502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEHMjqbtjBYzqM1uY68gAAAFo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:28.882334 2026] [security2:error] [pid 643253:tid 643271] [remote 57.141.0.52:26282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "thdinfinity.com"] [uri "/search/407345907/feed/rss2/"] [unique_id "amuEHMjqbtjBYzqM1uY6-QAAERA"]
[Thu Jul 30 12:04:29.495029 2026] [core:notice] [pid 643253:tid 643441] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:29.498953 2026] [security2:error] [pid 643253:tid 643441] [client 103.215.74.26:9510] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEHcjqbtjBYzqM1uY7AwAAADk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:30.183680 2026] [core:notice] [pid 643253:tid 643484] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:30.228922 2026] [core:notice] [pid 643253:tid 643465] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:30.232860 2026] [security2:error] [pid 643253:tid 643465] [client 103.215.74.26:9522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEHsjqbtjBYzqM1uY7DwAAAFE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:30.299079 2026] [security2:error] [pid 643253:tid 643457] [client 20.100.187.246:59212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/main.php"] [unique_id "amuEHsjqbtjBYzqM1uY7EAAAAEk"]
[Thu Jul 30 12:04:30.532519 2026] [security2:error] [pid 643253:tid 643494] [client 66.249.73.228:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mjsnailspa.com"] [uri "/index.php"] [unique_id "amuEHcjqbtjBYzqM1uY7BAAAAG4"]
[Thu Jul 30 12:04:30.680933 2026] [core:notice] [pid 643253:tid 643404] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:30.942962 2026] [core:notice] [pid 643253:tid 643490] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:30.947346 2026] [security2:error] [pid 643253:tid 643490] [client 103.215.74.26:9538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEHsjqbtjBYzqM1uY7IwAAAGo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:31.047532 2026] [security2:error] [pid 643253:tid 643472] [client 172.202.44.182:62056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/wp-sigunq.php"] [unique_id "amuEH8jqbtjBYzqM1uY7OAAAAFg"]
[Thu Jul 30 12:04:31.587721 2026] [core:notice] [pid 643253:tid 643493] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:31.670294 2026] [core:notice] [pid 643253:tid 643510] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:31.674717 2026] [security2:error] [pid 643253:tid 643510] [client 103.215.74.26:9552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEH8jqbtjBYzqM1uY7SgAAAH4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:32.092061 2026] [security2:error] [pid 643253:tid 643441] [client 172.202.44.182:4533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/wso112233.php"] [unique_id "amuEIMjqbtjBYzqM1uY7UQAAADk"]
[Thu Jul 30 12:04:32.175406 2026] [security2:error] [pid 643253:tid 643475] [client 20.100.187.246:63481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/wp-file.php"] [unique_id "amuEIMjqbtjBYzqM1uY7UgAAAFs"]
[Thu Jul 30 12:04:32.418884 2026] [security2:error] [pid 643253:tid 643421] [client 172.237.109.114:21395] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEHsjqbtjBYzqM1uY7JgAAACU"]
[Thu Jul 30 12:04:32.423878 2026] [security2:error] [pid 643253:tid 643511] [client 172.237.109.114:52115] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEHsjqbtjBYzqM1uY7JwAAAH8"]
[Thu Jul 30 12:04:32.426751 2026] [core:notice] [pid 643253:tid 643485] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:32.429481 2026] [security2:error] [pid 643253:tid 643435] [client 172.237.109.114:39381] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEHsjqbtjBYzqM1uY7MAAAADM"]
[Thu Jul 30 12:04:32.434250 2026] [security2:error] [pid 643253:tid 643470] [client 172.237.109.114:43320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEHsjqbtjBYzqM1uY7KgAAAFY"]
[Thu Jul 30 12:04:32.437392 2026] [security2:error] [pid 643253:tid 643485] [client 103.215.74.26:9562] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEIMjqbtjBYzqM1uY7VQAAAGU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:32.437709 2026] [security2:error] [pid 643253:tid 643459] [client 172.237.109.114:62814] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEH8jqbtjBYzqM1uY7NAAAAEs"]
[Thu Jul 30 12:04:32.448284 2026] [security2:error] [pid 643253:tid 643414] [client 172.237.109.114:18084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEHsjqbtjBYzqM1uY7JQAAAB4"]
[Thu Jul 30 12:04:32.459253 2026] [security2:error] [pid 643253:tid 643474] [client 172.237.109.114:13182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEHsjqbtjBYzqM1uY7LQAAAFo"]
[Thu Jul 30 12:04:32.466028 2026] [security2:error] [pid 643253:tid 643400] [client 172.237.109.114:2957] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEH8jqbtjBYzqM1uY7MQAAABA"]
[Thu Jul 30 12:04:32.485244 2026] [security2:error] [pid 643253:tid 643391] [client 172.237.109.114:15268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEH8jqbtjBYzqM1uY7MwAAAAc"]
[Thu Jul 30 12:04:32.504246 2026] [security2:error] [pid 643253:tid 643423] [client 172.237.109.114:28368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEH8jqbtjBYzqM1uY7NQAAACc"]
[Thu Jul 30 12:04:32.532039 2026] [security2:error] [pid 643253:tid 643389] [client 172.237.109.114:32860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEHsjqbtjBYzqM1uY7LwAAAAU"]
[Thu Jul 30 12:04:32.536729 2026] [security2:error] [pid 643253:tid 643388] [client 172.237.109.114:36672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEH8jqbtjBYzqM1uY7MgAAAAQ"]
[Thu Jul 30 12:04:32.537070 2026] [security2:error] [pid 643253:tid 643496] [client 172.237.109.114:55908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEHsjqbtjBYzqM1uY7LgAAAHA"]
[Thu Jul 30 12:04:32.558129 2026] [security2:error] [pid 643253:tid 643433] [client 172.237.109.114:1584] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEH8jqbtjBYzqM1uY7NgAAADE"]
[Thu Jul 30 12:04:32.565511 2026] [security2:error] [pid 643253:tid 643445] [client 172.237.109.114:18770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEHsjqbtjBYzqM1uY7LAAAAD0"]
[Thu Jul 30 12:04:32.579733 2026] [security2:error] [pid 643253:tid 643409] [client 172.237.109.114:49083] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEH8jqbtjBYzqM1uY7NwAAABk"]
[Thu Jul 30 12:04:32.582438 2026] [security2:error] [pid 643253:tid 643405] [client 172.237.109.114:2894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEHsjqbtjBYzqM1uY7KwAAABU"]
[Thu Jul 30 12:04:32.599869 2026] [security2:error] [pid 643253:tid 643392] [client 172.237.109.114:58081] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEHsjqbtjBYzqM1uY7KAAAAAg"]
[Thu Jul 30 12:04:32.615512 2026] [security2:error] [pid 643253:tid 643499] [client 172.237.109.114:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEHsjqbtjBYzqM1uY7JAAAAHM"]
[Thu Jul 30 12:04:32.633464 2026] [security2:error] [pid 643253:tid 643507] [client 172.237.109.114:29980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEHsjqbtjBYzqM1uY7KQAAAHs"]
[Thu Jul 30 12:04:33.162346 2026] [core:notice] [pid 643253:tid 643466] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:33.167715 2026] [security2:error] [pid 643253:tid 643466] [client 103.215.74.26:18056] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEIcjqbtjBYzqM1uY7ZQAAAFI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:33.400030 2026] [security2:error] [pid 643253:tid 643386] [client 172.202.44.182:44228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/alfanew.php"] [unique_id "amuEIcjqbtjBYzqM1uY7awAAAAI"]
[Thu Jul 30 12:04:33.423771 2026] [core:notice] [pid 643253:tid 643454] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:33.451615 2026] [security2:error] [pid 643253:tid 643444] [client 20.203.148.31:35350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.well-known/pki-validation/autoload_classmap.php"] [unique_id "amuEIcjqbtjBYzqM1uY7cQAAADw"]
[Thu Jul 30 12:04:33.906595 2026] [core:notice] [pid 643253:tid 643510] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:33.911281 2026] [security2:error] [pid 643253:tid 643510] [client 103.215.74.26:18066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEIcjqbtjBYzqM1uY7fAAAAH4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:34.132483 2026] [core:error] [pid 643253:tid 643414] [client 158.173.25.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://appliancerepairservice.one/
[Thu Jul 30 12:04:34.132516 2026] [core:error] [pid 643253:tid 643414] [client 158.173.25.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://appliancerepairservice.one/
[Thu Jul 30 12:04:34.328365 2026] [security2:error] [pid 643253:tid 643427] [client 20.203.148.31:9188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.well-known/pki-validation/flower.php"] [unique_id "amuEIsjqbtjBYzqM1uY7iQAAACs"]
[Thu Jul 30 12:04:34.457509 2026] [security2:error] [pid 643253:tid 643432] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEIcjqbtjBYzqM1uY7ewAAMC8"]
[Thu Jul 30 12:04:34.646507 2026] [core:notice] [pid 643253:tid 643387] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:34.650949 2026] [security2:error] [pid 643253:tid 643387] [client 103.215.74.26:18076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEIsjqbtjBYzqM1uY7kQAAAAM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:34.779986 2026] [security2:error] [pid 643253:tid 643423] [client 172.202.44.182:44225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/fw.php"] [unique_id "amuEIsjqbtjBYzqM1uY7kwAAACc"]
[Thu Jul 30 12:04:35.031863 2026] [security2:error] [pid 643253:tid 643402] [client 20.203.148.31:21464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.well-known/pki-validation/xleet.php"] [unique_id "amuEI8jqbtjBYzqM1uY7lwAAABI"]
[Thu Jul 30 12:04:35.394003 2026] [core:notice] [pid 643253:tid 643413] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:35.398388 2026] [security2:error] [pid 643253:tid 643413] [client 103.215.74.26:18082] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEI8jqbtjBYzqM1uY7ogAAAB0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:35.637006 2026] [security2:error] [pid 643253:tid 643439] [client 20.203.148.31:28999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.wp-cli/autoload_classmap.php"] [unique_id "amuEI8jqbtjBYzqM1uY7pgAAADc"]
[Thu Jul 30 12:04:36.133101 2026] [core:notice] [pid 643253:tid 643478] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:36.137458 2026] [security2:error] [pid 643253:tid 643478] [client 103.215.74.26:18090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEJMjqbtjBYzqM1uY7rwAAAF4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:36.163576 2026] [security2:error] [pid 643253:tid 643384] [client 172.202.44.182:4541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/wp-login.php"] [unique_id "amuEJMjqbtjBYzqM1uY7sAAAAAA"]
[Thu Jul 30 12:04:36.316477 2026] [security2:error] [pid 643253:tid 643453] [client 20.203.148.31:22908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.wp-cli/flower.php"] [unique_id "amuEJMjqbtjBYzqM1uY7tQAAAEU"]
[Thu Jul 30 12:04:36.651030 2026] [security2:error] [pid 643253:tid 643452] [client 85.208.96.199:30368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/07/08/fortaleza-e-dominado-perde-para-o-estudiantes-e-esta-eliminado-da-libertadores/"] [unique_id "amuEJMjqbtjBYzqM1uY7uQAAAEQ"]
[Thu Jul 30 12:04:36.651167 2026] [security2:error] [pid 643253:tid 643452] [client 85.208.96.199:30368] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/07/08/fortaleza-e-dominado-perde-para-o-estudiantes-e-esta-eliminado-da-libertadores/"] [unique_id "amuEJMjqbtjBYzqM1uY7uQAAAEQ"]
[Thu Jul 30 12:04:36.689390 2026] [security2:error] [pid 643253:tid 643467] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuEJMjqbtjBYzqM1uY7sQAAAFM"]
[Thu Jul 30 12:04:36.878011 2026] [core:notice] [pid 643253:tid 643477] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:36.881674 2026] [security2:error] [pid 643253:tid 643331] [remote 82.130.249.15:57994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.249.130.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.fireworkskenya.co.ke"] [uri "/wp-login.php"] [unique_id "amuEJMjqbtjBYzqM1uY7vQAAZUw"]
[Thu Jul 30 12:04:36.882532 2026] [security2:error] [pid 643253:tid 643477] [client 103.215.74.26:18094] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEJMjqbtjBYzqM1uY7vgAAAF0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:37.046822 2026] [core:notice] [pid 643253:tid 643417] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:37.349832 2026] [security2:error] [pid 643253:tid 643406] [client 20.203.148.31:19681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.wp-cli/xleet.php"] [unique_id "amuEJcjqbtjBYzqM1uY7ygAAABY"]
[Thu Jul 30 12:04:37.384025 2026] [security2:error] [pid 643253:tid 643498] [client 172.202.44.182:62064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/simple.php"] [unique_id "amuEJcjqbtjBYzqM1uY7ywAAAHI"]
[Thu Jul 30 12:04:37.548557 2026] [security2:error] [pid 643253:tid 643405] [client 20.100.187.246:63679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/wp-signin.php"] [unique_id "amuEJcjqbtjBYzqM1uY7zAAAABU"]
[Thu Jul 30 12:04:37.613075 2026] [core:notice] [pid 643253:tid 643492] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:37.616843 2026] [security2:error] [pid 643253:tid 643492] [client 103.215.74.26:18102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEJcjqbtjBYzqM1uY7zgAAAGw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:37.670434 2026] [security2:error] [pid 643253:tid 643483] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuEJcjqbtjBYzqM1uY7wwAAAGM"]
[Thu Jul 30 12:04:38.307945 2026] [access_compat:error] [pid 643253:tid 643453] [client 207.154.212.47:0] AH01797: client denied by server configuration: /home1/glbnyxte/public_html/website_bcd72044/server-status
[Thu Jul 30 12:04:38.323722 2026] [security2:error] [pid 643253:tid 643394] [client 172.202.44.182:4101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/classsmtps.php"] [unique_id "amuEJsjqbtjBYzqM1uY77AAAAAo"]
[Thu Jul 30 12:04:38.354344 2026] [core:notice] [pid 643253:tid 643408] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:38.361621 2026] [security2:error] [pid 643253:tid 643408] [client 103.215.74.26:18106] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEJsjqbtjBYzqM1uY77wAAABg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:38.364644 2026] [security2:error] [pid 643253:tid 643411] [client 20.203.148.31:22503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amuEJsjqbtjBYzqM1uY78AAAABs"]
[Thu Jul 30 12:04:38.663579 2026] [security2:error] [pid 643253:tid 643476] [client 185.191.171.3:64600] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/05/20/presidente-do-pdt-se-reune-com-cicero-avanca-em-dialogo-e-diz-que-vai-se-encontrar-com-joao-azevedo/"] [unique_id "amuEJsjqbtjBYzqM1uY8CgAAAFw"]
[Thu Jul 30 12:04:38.663692 2026] [security2:error] [pid 643253:tid 643476] [client 185.191.171.3:64600] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/05/20/presidente-do-pdt-se-reune-com-cicero-avanca-em-dialogo-e-diz-que-vai-se-encontrar-com-joao-azevedo/"] [unique_id "amuEJsjqbtjBYzqM1uY8CgAAAFw"]
[Thu Jul 30 12:04:38.872285 2026] [security2:error] [pid 643253:tid 643407] [client 2a03:2880:f800:2e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEJsjqbtjBYzqM1uY75wAAF1g"]
[Thu Jul 30 12:04:38.928383 2026] [security2:error] [pid 643253:tid 643469] [client 192.82.55.10:16808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "hris.rgserve.ph"] [uri "/time_mobile.php"] [unique_id "amuEJsjqbtjBYzqM1uY8FQAAVUk"], referer: https://hris.rgserve.ph/time_mobile.php
[Thu Jul 30 12:04:39.036474 2026] [security2:error] [pid 643253:tid 643419] [client 192.82.55.10:16808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "hris.rgserve.ph"] [uri "/login.php"] [unique_id "amuEJ8jqbtjBYzqM1uY8GQAAI0s"], referer: https://hris.rgserve.ph/time_mobile.php
[Thu Jul 30 12:04:39.090520 2026] [core:notice] [pid 643253:tid 643471] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:39.094570 2026] [security2:error] [pid 643253:tid 643471] [client 103.215.74.26:18120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "741"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEJ8jqbtjBYzqM1uY8GgAAAFc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:39.406930 2026] [security2:error] [pid 643253:tid 643506] [client 2a03:2880:f800:1:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEJsjqbtjBYzqM1uY8BgAAemQ"]
[Thu Jul 30 12:04:39.816286 2026] [core:notice] [pid 643253:tid 643500] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:39.818110 2026] [security2:error] [pid 643253:tid 643508] [client 20.203.148.31:24411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/network/flower.php"] [unique_id "amuEJ8jqbtjBYzqM1uY8OAAAAHw"]
[Thu Jul 30 12:04:39.820655 2026] [security2:error] [pid 643253:tid 643500] [client 103.215.74.26:18122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEJ8jqbtjBYzqM1uY8NwAAAHQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:40.126118 2026] [security2:error] [pid 643253:tid 643501] [client 20.100.187.246:59253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/simi.php"] [unique_id "amuEKMjqbtjBYzqM1uY8QwAAAHU"]
[Thu Jul 30 12:04:40.530006 2026] [security2:error] [pid 643253:tid 643466] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuEJ8jqbtjBYzqM1uY8QgAAAFI"]
[Thu Jul 30 12:04:40.549066 2026] [core:notice] [pid 643253:tid 643398] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:40.555230 2026] [security2:error] [pid 643253:tid 643398] [client 103.215.74.26:18138] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEKMjqbtjBYzqM1uY8TwAAAA4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:41.011315 2026] [security2:error] [pid 643253:tid 643403] [client 172.202.44.182:4516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/wp-blog-header.php"] [unique_id "amuEKcjqbtjBYzqM1uY8XgAAABM"]
[Thu Jul 30 12:04:41.302419 2026] [core:notice] [pid 643253:tid 643451] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:41.310054 2026] [security2:error] [pid 643253:tid 643451] [client 103.215.74.26:18144] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEKcjqbtjBYzqM1uY8awAAAEM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:41.692609 2026] [security2:error] [pid 643253:tid 643430] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuEKcjqbtjBYzqM1uY8XwAAAC4"]
[Thu Jul 30 12:04:41.939956 2026] [security2:error] [pid 643253:tid 643386] [client 172.202.44.182:62058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/wp-trackback.php"] [unique_id "amuEKcjqbtjBYzqM1uY8fAAAAAI"]
[Thu Jul 30 12:04:42.048020 2026] [core:notice] [pid 643253:tid 643501] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:42.052008 2026] [security2:error] [pid 643253:tid 643501] [client 103.215.74.26:18146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEKsjqbtjBYzqM1uY8fQAAAHU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:42.231920 2026] [security2:error] [pid 643253:tid 643437] [client 185.191.171.5:18232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/08/31/senado-aprova-indicacoes-para-o-conselho-da-republica/"] [unique_id "amuEKsjqbtjBYzqM1uY8fgAAADU"]
[Thu Jul 30 12:04:42.232068 2026] [security2:error] [pid 643253:tid 643437] [client 185.191.171.5:18232] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/08/31/senado-aprova-indicacoes-para-o-conselho-da-republica/"] [unique_id "amuEKsjqbtjBYzqM1uY8fgAAADU"]
[Thu Jul 30 12:04:42.496015 2026] [security2:error] [pid 643253:tid 643460] [client 20.100.187.246:63693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/wp-conf.php"] [unique_id "amuEKsjqbtjBYzqM1uY8jwAAAEw"]
[Thu Jul 30 12:04:42.789448 2026] [core:notice] [pid 643253:tid 643429] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:42.796286 2026] [security2:error] [pid 643253:tid 643429] [client 103.215.74.26:18160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEKsjqbtjBYzqM1uY8lQAAAC0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:42.881042 2026] [security2:error] [pid 643253:tid 643463] [client 20.203.148.31:9458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/network/xleet.php/wp-content/flower.php"] [unique_id "amuEKsjqbtjBYzqM1uY8mgAAAE8"]
[Thu Jul 30 12:04:43.523882 2026] [core:notice] [pid 643253:tid 643425] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:43.530533 2026] [security2:error] [pid 643253:tid 643425] [client 103.215.74.26:5592] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEK8jqbtjBYzqM1uY8qgAAACk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:43.584588 2026] [security2:error] [pid 643253:tid 643443] [client 20.100.187.246:59207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/WZGHHra0r3.php"] [unique_id "amuEK8jqbtjBYzqM1uY8rAAAADs"]
[Thu Jul 30 12:04:43.777643 2026] [security2:error] [pid 643253:tid 643409] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuEK8jqbtjBYzqM1uY8ogAAABk"]
[Thu Jul 30 12:04:44.079781 2026] [security2:error] [pid 643253:tid 643412] [client 172.202.44.182:4156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/wp-signup.php"] [unique_id "amuELMjqbtjBYzqM1uY8vgAAABw"]
[Thu Jul 30 12:04:44.250079 2026] [core:notice] [pid 643253:tid 643458] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:44.254258 2026] [security2:error] [pid 643253:tid 643458] [client 103.215.74.26:5596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "773"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuELMjqbtjBYzqM1uY8wAAAAEo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:44.298542 2026] [security2:error] [pid 643253:tid 643506] [client 20.100.187.246:63632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/bala.php"] [unique_id "amuELMjqbtjBYzqM1uY8wgAAAHo"]
[Thu Jul 30 12:04:44.667864 2026] [security2:error] [pid 643253:tid 643447] [client 2a03:2880:f800:43:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEK8jqbtjBYzqM1uY8tgAAPwg"]
[Thu Jul 30 12:04:44.897266 2026] [security2:error] [pid 643253:tid 643489] [client 250.49.135.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuELMjqbtjBYzqM1uY8ugAAaQk"]
[Thu Jul 30 12:04:44.913485 2026] [security2:error] [pid 643253:tid 643460] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuELMjqbtjBYzqM1uY8xwAAAEw"]
[Thu Jul 30 12:04:45.083861 2026] [security2:error] [pid 643253:tid 643450] [client 57.141.0.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuELMjqbtjBYzqM1uY8ygAAAEI"]
[Thu Jul 30 12:04:45.196283 2026] [security2:error] [pid 643253:tid 643405] [client 172.202.44.182:62020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/wp-comments-post.php"] [unique_id "amuELcjqbtjBYzqM1uY82QAAABU"]
[Thu Jul 30 12:04:45.257660 2026] [security2:error] [pid 643253:tid 643400] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuELMjqbtjBYzqM1uY8wQAAEHg"]
[Thu Jul 30 12:04:45.802283 2026] [security2:error] [pid 643253:tid 643421] [client 20.100.187.246:61949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/bk.php"] [unique_id "amuELcjqbtjBYzqM1uY8-AAAACU"]
[Thu Jul 30 12:04:46.209942 2026] [security2:error] [pid 643253:tid 643427] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuELcjqbtjBYzqM1uY89wAAACs"]
[Thu Jul 30 12:04:46.331754 2026] [security2:error] [pid 643253:tid 643447] [client 2a03:2880:f800:41:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuELMjqbtjBYzqM1uY80QAAP3M"]
[Thu Jul 30 12:04:46.381121 2026] [core:notice] [pid 643253:tid 643265] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:46.411042 2026] [security2:error] [pid 643253:tid 643426] [client 20.203.148.31:17156] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.revolutionary-technologies.com"] [uri "/1.php"] [unique_id "amuELsjqbtjBYzqM1uY9BgAAACo"]
[Thu Jul 30 12:04:46.411200 2026] [security2:error] [pid 643253:tid 643426] [client 20.203.148.31:17156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/1.php"] [unique_id "amuELsjqbtjBYzqM1uY9BgAAACo"]
[Thu Jul 30 12:04:46.587279 2026] [core:notice] [pid 643253:tid 643418] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:46.594129 2026] [security2:error] [pid 643253:tid 643418] [client 103.215.74.26:5606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuELsjqbtjBYzqM1uY9EAAAACI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:47.062726 2026] [security2:error] [pid 643253:tid 643490] [client 20.203.148.31:13295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/admin.php"] [unique_id "amuEL8jqbtjBYzqM1uY9FwAAAGo"]
[Thu Jul 30 12:04:47.092837 2026] [security2:error] [pid 643253:tid 643476] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuELsjqbtjBYzqM1uY9DwAAAFw"]
[Thu Jul 30 12:04:47.394574 2026] [security2:error] [pid 643253:tid 643454] [client 2a03:2880:f800:3e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuELsjqbtjBYzqM1uY9AgAARns"]
[Thu Jul 30 12:04:47.551216 2026] [security2:error] [pid 643253:tid 643428] [client 207.154.212.47:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.echomemoversalain.casa"] [uri "/.env"] [unique_id "amuEL8jqbtjBYzqM1uY9HwAAACw"]
[Thu Jul 30 12:04:48.095533 2026] [security2:error] [pid 643253:tid 643414] [client 20.203.148.31:17165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/as.php"] [unique_id "amuEMMjqbtjBYzqM1uY9KAAAAB4"]
[Thu Jul 30 12:04:48.680324 2026] [core:notice] [pid 643253:tid 643282] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:49.013778 2026] [security2:error] [pid 643253:tid 643421] [client 20.100.187.246:61926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/ahax.php"] [unique_id "amuEMcjqbtjBYzqM1uY9PAAAACU"]
[Thu Jul 30 12:04:49.224738 2026] [security2:error] [pid 643253:tid 643307] [remote 57.141.0.33:60728] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "thdinfinity.com"] [uri "/search/358522518/feed/rss2/"] [unique_id "amuEMcjqbtjBYzqM1uY9QAAAfDQ"]
[Thu Jul 30 12:04:49.307716 2026] [security2:error] [pid 643253:tid 643485] [client 20.203.148.31:9542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/autoload_classmap.php"] [unique_id "amuEMcjqbtjBYzqM1uY9RQAAAGU"]
[Thu Jul 30 12:04:49.376343 2026] [security2:error] [pid 643253:tid 643458] [client 172.202.44.182:62022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/wp-mail.php"] [unique_id "amuEMcjqbtjBYzqM1uY9RgAAAEo"]
[Thu Jul 30 12:04:49.955347 2026] [security2:error] [pid 643253:tid 643505] [client 20.203.148.31:17234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/back.php"] [unique_id "amuEMcjqbtjBYzqM1uY9WAAAAHk"]
[Thu Jul 30 12:04:50.052139 2026] [security2:error] [pid 643253:tid 643287] [remote 57.141.0.65:56776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuEMcjqbtjBYzqM1uY9VAAAVCA"]
[Thu Jul 30 12:04:50.137992 2026] [security2:error] [pid 643253:tid 643396] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuEMcjqbtjBYzqM1uY9TgAAAAw"]
[Thu Jul 30 12:04:50.674144 2026] [security2:error] [pid 643253:tid 643298] [remote 74.7.241.60:49134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/article.php"] [unique_id "amuEMsjqbtjBYzqM1uY9XwAAASs"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/main_image_6a3229a631e84.jpg
[Thu Jul 30 12:04:50.846949 2026] [security2:error] [pid 643253:tid 643487] [client 172.202.44.182:44258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/wp-activate.php"] [unique_id "amuEMsjqbtjBYzqM1uY9ZgAAAGc"]
[Thu Jul 30 12:04:51.256892 2026] [security2:error] [pid 643253:tid 643509] [client 20.203.148.31:23487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/c/autoload_classmap.php"] [unique_id "amuEM8jqbtjBYzqM1uY9awAAAH0"]
[Thu Jul 30 12:04:52.251949 2026] [security2:error] [pid 643253:tid 643489] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuEM8jqbtjBYzqM1uY9bwAAAGk"]
[Thu Jul 30 12:04:52.343322 2026] [security2:error] [pid 643253:tid 643425] [client 213.152.161.219:36954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuENMjqbtjBYzqM1uY9fQAAACk"]
[Thu Jul 30 12:04:52.343457 2026] [security2:error] [pid 643253:tid 643425] [client 213.152.161.219:36954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuENMjqbtjBYzqM1uY9fQAAACk"]
[Thu Jul 30 12:04:52.353047 2026] [security2:error] [pid 643253:tid 643427] [client 57.141.0.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuEM8jqbtjBYzqM1uY9cgAAACs"]
[Thu Jul 30 12:04:52.385125 2026] [core:notice] [pid 643253:tid 643508] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:52.389805 2026] [security2:error] [pid 643253:tid 643508] [client 103.215.74.26:5614] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuENMjqbtjBYzqM1uY9gAAAAHw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:52.848925 2026] [security2:error] [pid 643253:tid 643393] [client 20.203.148.31:17177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/c/flower.php"] [unique_id "amuENMjqbtjBYzqM1uY9iQAAAAk"]
[Thu Jul 30 12:04:53.080558 2026] [core:notice] [pid 643253:tid 643385] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:53.088638 2026] [security2:error] [pid 643253:tid 643490] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuENMjqbtjBYzqM1uY9hQAAAGo"]
[Thu Jul 30 12:04:53.092611 2026] [core:notice] [pid 643253:tid 643493] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:53.112677 2026] [core:notice] [pid 643253:tid 643391] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:53.123129 2026] [core:notice] [pid 643253:tid 643473] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:53.126919 2026] [security2:error] [pid 643253:tid 643473] [client 103.215.74.26:48954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuENcjqbtjBYzqM1uY9kwAAAFk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:53.438402 2026] [security2:error] [pid 643253:tid 643477] [client 20.203.148.31:9520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/c/xleet.php"] [unique_id "amuENcjqbtjBYzqM1uY9nAAAAF0"]
[Thu Jul 30 12:04:53.455004 2026] [security2:error] [pid 643253:tid 643466] [client 172.202.44.182:4307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/post.php"] [unique_id "amuENcjqbtjBYzqM1uY9nQAAAFI"]
[Thu Jul 30 12:04:53.973649 2026] [core:notice] [pid 643253:tid 643392] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:53.987589 2026] [core:notice] [pid 643253:tid 643451] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:54.020472 2026] [security2:error] [pid 643253:tid 643435] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuENcjqbtjBYzqM1uY9ngAAADM"]
[Thu Jul 30 12:04:54.102521 2026] [security2:error] [pid 643253:tid 643499] [client 20.203.148.31:14782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/classwithtostring.php"] [unique_id "amuENsjqbtjBYzqM1uY9qwAAAHM"]
[Thu Jul 30 12:04:54.148697 2026] [core:notice] [pid 643253:tid 643324] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:54.228392 2026] [core:notice] [pid 643253:tid 643327] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:54.237375 2026] [core:notice] [pid 643253:tid 643300] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:54.893395 2026] [security2:error] [pid 643253:tid 643397] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuENsjqbtjBYzqM1uY9rwAAAA0"]
[Thu Jul 30 12:04:55.386345 2026] [core:notice] [pid 643253:tid 643278] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:55.386621 2026] [core:notice] [pid 643253:tid 643317] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:55.460357 2026] [security2:error] [pid 643253:tid 643402] [client 20.203.148.31:23466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/content.php"] [unique_id "amuEN8jqbtjBYzqM1uY9ywAAABI"]
[Thu Jul 30 12:04:55.570199 2026] [security2:error] [pid 643253:tid 643476] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEN8jqbtjBYzqM1uY9wAAAXFE"]
[Thu Jul 30 12:04:55.745037 2026] [security2:error] [pid 643253:tid 643390] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuEN8jqbtjBYzqM1uY9xAAAAAY"]
[Thu Jul 30 12:04:56.733705 2026] [security2:error] [pid 643253:tid 643435] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuEOMjqbtjBYzqM1uY93QAAADM"]
[Thu Jul 30 12:04:56.801282 2026] [core:notice] [pid 643253:tid 643395] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:57.328557 2026] [security2:error] [pid 643253:tid 643493] [client 20.203.148.31:23459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/doc.php"] [unique_id "amuEOcjqbtjBYzqM1uY97gAAAG0"]
[Thu Jul 30 12:04:57.617625 2026] [security2:error] [pid 643253:tid 643401] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuEOcjqbtjBYzqM1uY97AAAABE"]
[Thu Jul 30 12:04:57.910803 2026] [security2:error] [pid 643253:tid 643447] [client 172.202.44.182:4538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/wp-2019.php"] [unique_id "amuEOcjqbtjBYzqM1uY99wAAAD8"]
[Thu Jul 30 12:04:58.745118 2026] [security2:error] [pid 643253:tid 643459] [client 172.202.44.182:4531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/hoot.php"] [unique_id "amuEOsjqbtjBYzqM1uY-CAAAAEs"]
[Thu Jul 30 12:04:58.875329 2026] [security2:error] [pid 643253:tid 643478] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuEOsjqbtjBYzqM1uY9_gAAAF4"]
[Thu Jul 30 12:04:58.923053 2026] [security2:error] [pid 643253:tid 643390] [client 20.203.148.31:23431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/dropdown.php"] [unique_id "amuEOsjqbtjBYzqM1uY-DAAAAAY"]
[Thu Jul 30 12:04:58.936348 2026] [core:notice] [pid 643253:tid 643511] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:58.940291 2026] [security2:error] [pid 643253:tid 643511] [client 103.215.74.26:48970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEOsjqbtjBYzqM1uY-DQAAAH8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:59.654586 2026] [core:notice] [pid 643253:tid 643494] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:59.658397 2026] [security2:error] [pid 643253:tid 643494] [client 103.215.74.26:48984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEO8jqbtjBYzqM1uY-GgAAAG4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:59.745620 2026] [security2:error] [pid 643253:tid 643420] [client 172.202.44.182:44229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/log.php"] [unique_id "amuEO8jqbtjBYzqM1uY-JAAAACQ"]
[Thu Jul 30 12:05:00.382334 2026] [core:notice] [pid 643253:tid 643377] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:00.386333 2026] [security2:error] [pid 643253:tid 643444] [client 66.249.74.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/view/33/59"] [unique_id "amuEPMjqbtjBYzqM1uY-KAAAPHo"]
[Thu Jul 30 12:05:00.387100 2026] [core:notice] [pid 643253:tid 643469] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:00.391022 2026] [security2:error] [pid 643253:tid 643469] [client 103.215.74.26:48996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEPMjqbtjBYzqM1uY-MAAAAFU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:00.620669 2026] [security2:error] [pid 643253:tid 643406] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuEPMjqbtjBYzqM1uY-KQAAABY"]
[Thu Jul 30 12:05:00.645945 2026] [autoindex:error] [pid 643253:tid 643402] [client 54.173.131.118:0] AH01276: Cannot serve directory /home2/mbmudite/koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:05:00.757254 2026] [autoindex:error] [pid 643253:tid 643393] [client 3.217.141.132:0] AH01276: Cannot serve directory /home2/mbmudite/otbola.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:05:00.873456 2026] [security2:error] [pid 643253:tid 643410] [client 20.203.148.31:13264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/ee.php"] [unique_id "amuEPMjqbtjBYzqM1uY-OgAAABo"]
[Thu Jul 30 12:05:00.976543 2026] [security2:error] [pid 643253:tid 643510] [client 172.202.44.182:62067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/bak.php"] [unique_id "amuEPMjqbtjBYzqM1uY-QAAAAH4"]
[Thu Jul 30 12:05:01.124151 2026] [core:notice] [pid 643253:tid 643490] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:01.128122 2026] [security2:error] [pid 643253:tid 643490] [client 103.215.74.26:49004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEPcjqbtjBYzqM1uY-QQAAAGo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:01.448282 2026] [security2:error] [pid 643253:tid 643478] [client 207.154.212.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.212.154.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/info.php"] [unique_id "amuEPcjqbtjBYzqM1uY-RQAAAF4"]
[Thu Jul 30 12:05:01.852893 2026] [core:notice] [pid 643253:tid 643460] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:01.856848 2026] [security2:error] [pid 643253:tid 643460] [client 103.215.74.26:49008] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEPcjqbtjBYzqM1uY-VAAAAEw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:02.519906 2026] [security2:error] [pid 643253:tid 643421] [client 172.202.44.182:62047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/content.php"] [unique_id "amuEPsjqbtjBYzqM1uY-YQAAACU"]
[Thu Jul 30 12:05:02.579434 2026] [core:notice] [pid 643253:tid 643411] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:02.585029 2026] [security2:error] [pid 643253:tid 643411] [client 103.215.74.26:49020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEPsjqbtjBYzqM1uY-YgAAABs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:02.907351 2026] [autoindex:error] [pid 643253:tid 643444] [client 43.130.60.195:52814] AH01276: Cannot serve directory /home2/lgggplte/brianhpark.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:05:03.064505 2026] [security2:error] [pid 643253:tid 643488] [client 74.7.244.60:43008] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ajakholding.net"] [uri "/index.php"] [unique_id "amuEPcjqbtjBYzqM1uY-UAAAaGI"]
[Thu Jul 30 12:05:03.315629 2026] [core:notice] [pid 643253:tid 643384] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:03.320576 2026] [security2:error] [pid 643253:tid 643384] [client 103.215.74.26:30224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEP8jqbtjBYzqM1uY-bgAAAAA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:03.407051 2026] [security2:error] [pid 643253:tid 643441] [client 172.202.44.182:4190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/upfile.php"] [unique_id "amuEP8jqbtjBYzqM1uY-dgAAADk"]
[Thu Jul 30 12:05:03.786378 2026] [security2:error] [pid 643253:tid 643263] [remote 216.73.216.152:11159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuEP8jqbtjBYzqM1uY-ewAAWwg"]
[Thu Jul 30 12:05:03.801755 2026] [security2:error] [pid 643253:tid 643479] [client 20.203.148.31:23478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/flower.php"] [unique_id "amuEP8jqbtjBYzqM1uY-fQAAAF8"]
[Thu Jul 30 12:05:04.056688 2026] [core:notice] [pid 643253:tid 643452] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:04.060661 2026] [security2:error] [pid 643253:tid 643452] [client 103.215.74.26:30228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEQMjqbtjBYzqM1uY-hQAAAEQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:04.103248 2026] [security2:error] [pid 643253:tid 643470] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuEP8jqbtjBYzqM1uY-egAAAFY"]
[Thu Jul 30 12:05:04.111713 2026] [security2:error] [pid 643253:tid 643485] [client 57.141.18.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laduchessecollections.com"] [uri "/index.php"] [unique_id "amuEPsjqbtjBYzqM1uY-YAAAZQ0"]
[Thu Jul 30 12:05:04.323064 2026] [security2:error] [pid 643253:tid 643432] [client 172.202.44.182:4164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/bypass.php"] [unique_id "amuEQMjqbtjBYzqM1uY-igAAADA"]
[Thu Jul 30 12:05:04.359893 2026] [core:notice] [pid 643253:tid 643459] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:04.773747 2026] [core:notice] [pid 643253:tid 643415] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:04.778091 2026] [security2:error] [pid 643253:tid 643415] [client 103.215.74.26:30238] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEQMjqbtjBYzqM1uY-kQAAAB8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:05.242590 2026] [security2:error] [pid 643253:tid 643462] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuEQMjqbtjBYzqM1uY-kAAAAE4"]
[Thu Jul 30 12:05:05.244518 2026] [security2:error] [pid 643253:tid 643460] [client 20.52.125.110:14914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/011i.php"] [unique_id "amuEQcjqbtjBYzqM1uY-pAAAAEw"]
[Thu Jul 30 12:05:05.499615 2026] [core:notice] [pid 643253:tid 643501] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:05.506165 2026] [security2:error] [pid 643253:tid 643501] [client 103.215.74.26:30240] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEQcjqbtjBYzqM1uY-sAAAAHU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:05.569713 2026] [core:notice] [pid 643253:tid 643469] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:05.751943 2026] [security2:error] [pid 643253:tid 643399] [client 20.203.148.31:16683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/gecko-new.php"] [unique_id "amuEQcjqbtjBYzqM1uY-swAAAA8"]
[Thu Jul 30 12:05:05.864017 2026] [security2:error] [pid 643253:tid 643480] [client 20.52.125.110:14293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/03a005685d.php"] [unique_id "amuEQcjqbtjBYzqM1uY-vAAAAGA"]
[Thu Jul 30 12:05:06.136106 2026] [security2:error] [pid 643253:tid 643481] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEQcjqbtjBYzqM1uY-sgAAYXQ"]
[Thu Jul 30 12:05:06.224778 2026] [core:notice] [pid 643253:tid 643453] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:06.232102 2026] [security2:error] [pid 643253:tid 643453] [client 103.215.74.26:30246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEQsjqbtjBYzqM1uY-zQAAAEU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:06.425498 2026] [security2:error] [pid 643253:tid 643457] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuEQcjqbtjBYzqM1uY-vQAAAEk"]
[Thu Jul 30 12:05:06.467839 2026] [security2:error] [pid 643253:tid 643443] [client 2a03:2880:f800:18:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEQcjqbtjBYzqM1uY-uwAAOx8"]
[Thu Jul 30 12:05:06.630065 2026] [security2:error] [pid 643253:tid 643434] [client 20.52.125.110:14331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/403.php"] [unique_id "amuEQsjqbtjBYzqM1uY-3wAAADI"]
[Thu Jul 30 12:05:06.642594 2026] [security2:error] [pid 643253:tid 643392] [client 20.203.148.31:23427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/m.php"] [unique_id "amuEQsjqbtjBYzqM1uY-4AAAAAg"]
[Thu Jul 30 12:05:06.994053 2026] [core:notice] [pid 643253:tid 643415] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:06.998521 2026] [security2:error] [pid 643253:tid 643415] [client 103.215.74.26:30260] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEQsjqbtjBYzqM1uY-5QAAAB8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:07.729820 2026] [core:notice] [pid 643253:tid 643488] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:07.734654 2026] [security2:error] [pid 643253:tid 643488] [client 103.215.74.26:30272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEQ8jqbtjBYzqM1uY_BAAAAGg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:07.812321 2026] [security2:error] [pid 643253:tid 643420] [client 2a03:2880:f800:6:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEQsjqbtjBYzqM1uY-4QAAJCg"]
[Thu Jul 30 12:05:07.908031 2026] [security2:error] [pid 643253:tid 643447] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY--AAAAD8"]
[Thu Jul 30 12:05:08.077837 2026] [security2:error] [pid 643253:tid 643449] [client 20.52.125.110:14926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/404.php"] [unique_id "amuERMjqbtjBYzqM1uY_BwAAAEE"]
[Thu Jul 30 12:05:08.465241 2026] [core:notice] [pid 643253:tid 643410] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:08.474292 2026] [security2:error] [pid 643253:tid 643410] [client 103.215.74.26:30286] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuERMjqbtjBYzqM1uY_DQAAABo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:08.765147 2026] [security2:error] [pid 643253:tid 643468] [client 20.203.148.31:9457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/mah/autoload_classmap.php"] [unique_id "amuERMjqbtjBYzqM1uY_FAAAAFQ"]
[Thu Jul 30 12:05:08.787705 2026] [security2:error] [pid 643253:tid 643323] [remote 216.73.216.152:11159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuERMjqbtjBYzqM1uY_FQAAUkQ"]
[Thu Jul 30 12:05:08.890300 2026] [security2:error] [pid 643253:tid 643510] [client 172.202.44.182:4105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/updates.php"] [unique_id "amuERMjqbtjBYzqM1uY_FgAAAH4"]
[Thu Jul 30 12:05:09.200247 2026] [core:notice] [pid 643253:tid 643511] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:09.204607 2026] [security2:error] [pid 643253:tid 643511] [client 103.215.74.26:30292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuERcjqbtjBYzqM1uY_IgAAAH8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:09.323028 2026] [security2:error] [pid 643253:tid 643471] [client 172.236.9.101:37907] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY-8AAAAFc"]
[Thu Jul 30 12:05:09.325858 2026] [security2:error] [pid 643253:tid 643401] [client 172.236.9.101:4320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY-6wAAABE"]
[Thu Jul 30 12:05:09.342513 2026] [security2:error] [pid 643253:tid 643455] [client 172.236.9.101:45328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY-7wAAAEc"]
[Thu Jul 30 12:05:09.344440 2026] [security2:error] [pid 643253:tid 643403] [client 172.236.9.101:60479] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY-8gAAABM"]
[Thu Jul 30 12:05:09.348422 2026] [security2:error] [pid 643253:tid 643431] [client 172.236.9.101:2004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY-8QAAAC8"]
[Thu Jul 30 12:05:09.356557 2026] [security2:error] [pid 643253:tid 643493] [client 172.236.9.101:16721] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY-6gAAAG0"]
[Thu Jul 30 12:05:09.359676 2026] [security2:error] [pid 643253:tid 643389] [client 172.236.9.101:5947] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY-7AAAAAU"]
[Thu Jul 30 12:05:09.364117 2026] [security2:error] [pid 643253:tid 643424] [client 172.236.9.101:19948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY-7QAAACg"]
[Thu Jul 30 12:05:09.364409 2026] [security2:error] [pid 643253:tid 643505] [client 172.236.9.101:2622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY--wAAAHk"]
[Thu Jul 30 12:05:09.379598 2026] [security2:error] [pid 643253:tid 643407] [client 172.236.9.101:20164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY--QAAABc"]
[Thu Jul 30 12:05:09.387272 2026] [security2:error] [pid 643253:tid 643504] [client 172.236.9.101:54700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY-6QAAAHg"]
[Thu Jul 30 12:05:09.389713 2026] [security2:error] [pid 643253:tid 643460] [client 172.236.9.101:9059] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY-9QAAAEw"]
[Thu Jul 30 12:05:09.397744 2026] [security2:error] [pid 643253:tid 643462] [client 172.236.9.101:10833] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY-9AAAAE4"]
[Thu Jul 30 12:05:09.418045 2026] [security2:error] [pid 643253:tid 643486] [client 172.236.9.101:45205] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY-9gAAAGY"]
[Thu Jul 30 12:05:09.431175 2026] [security2:error] [pid 643253:tid 643482] [client 172.236.9.101:43397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY-7gAAAGI"]
[Thu Jul 30 12:05:09.445062 2026] [security2:error] [pid 643253:tid 643385] [client 172.236.9.101:17746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY-9wAAAAE"]
[Thu Jul 30 12:05:09.475286 2026] [security2:error] [pid 643253:tid 643444] [client 172.236.9.101:10634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY--gAAADw"]
[Thu Jul 30 12:05:09.502548 2026] [security2:error] [pid 643253:tid 643433] [client 172.236.9.101:20484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY-_QAAADE"]
[Thu Jul 30 12:05:09.514006 2026] [security2:error] [pid 643253:tid 643461] [client 172.236.9.101:62663] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY-8wAAAE0"]
[Thu Jul 30 12:05:09.552284 2026] [security2:error] [pid 643253:tid 643438] [client 172.236.9.101:64613] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY-_AAAADY"]
[Thu Jul 30 12:05:09.618264 2026] [security2:error] [pid 643253:tid 643484] [client 57.141.0.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuERcjqbtjBYzqM1uY_GgAAAGQ"]
[Thu Jul 30 12:05:09.933987 2026] [core:notice] [pid 643253:tid 643422] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:09.938519 2026] [security2:error] [pid 643253:tid 643422] [client 103.215.74.26:30296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuERcjqbtjBYzqM1uY_LgAAACY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:10.117462 2026] [security2:error] [pid 643253:tid 643502] [client 20.52.125.110:14288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/aa.php"] [unique_id "amuERsjqbtjBYzqM1uY_MgAAAHY"]
[Thu Jul 30 12:05:10.133257 2026] [security2:error] [pid 643253:tid 643497] [client 172.202.44.182:4362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/xmrlpc.php"] [unique_id "amuERsjqbtjBYzqM1uY_NAAAAHE"]
[Thu Jul 30 12:05:10.205176 2026] [security2:error] [pid 643253:tid 643474] [client 57.141.0.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuERcjqbtjBYzqM1uY_KAAAAFo"]
[Thu Jul 30 12:05:10.661854 2026] [core:notice] [pid 643253:tid 643473] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:10.666104 2026] [security2:error] [pid 643253:tid 643473] [client 103.215.74.26:30308] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuERsjqbtjBYzqM1uY_PAAAAFk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:11.387213 2026] [core:notice] [pid 643253:tid 643453] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:11.391207 2026] [security2:error] [pid 643253:tid 643453] [client 103.215.74.26:30320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuER8jqbtjBYzqM1uY_SAAAAEU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:11.654786 2026] [security2:error] [pid 643253:tid 643390] [client 20.52.125.110:14916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/aafewc0k.php"] [unique_id "amuER8jqbtjBYzqM1uY_SQAAAAY"]
[Thu Jul 30 12:05:11.689731 2026] [security2:error] [pid 643253:tid 643452] [client 172.202.44.182:4408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/ae.php"] [unique_id "amuER8jqbtjBYzqM1uY_TQAAAEQ"]
[Thu Jul 30 12:05:12.093547 2026] [security2:error] [pid 643253:tid 643435] [client 20.203.148.31:21973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/mah/flower.php"] [unique_id "amuESMjqbtjBYzqM1uY_UwAAADM"]
[Thu Jul 30 12:05:12.126831 2026] [core:notice] [pid 643253:tid 643385] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:12.130909 2026] [security2:error] [pid 643253:tid 643385] [client 103.215.74.26:30334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuESMjqbtjBYzqM1uY_VAAAAAE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:12.223603 2026] [security2:error] [pid 643253:tid 643427] [client 35.221.246.130:57902] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.gbq.rty.temporary.site"] [uri "/.git/config"] [unique_id "amuESMjqbtjBYzqM1uY_WwAAACs"]
[Thu Jul 30 12:05:12.223709 2026] [security2:error] [pid 643253:tid 643427] [client 35.221.246.130:57902] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.gbq.rty.temporary.site"] [uri "/.git/config"] [unique_id "amuESMjqbtjBYzqM1uY_WwAAACs"]
[Thu Jul 30 12:05:12.342282 2026] [security2:error] [pid 643253:tid 643450] [client 35.221.246.130:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "gbq.rty.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuESMjqbtjBYzqM1uY_YgAAAEI"]
[Thu Jul 30 12:05:12.342771 2026] [security2:error] [pid 643253:tid 643405] [client 35.221.246.130:57906] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "gbq.rty.temporary.site"] [uri "/.git/config"] [unique_id "amuESMjqbtjBYzqM1uY_YAAAABU"]
[Thu Jul 30 12:05:12.484938 2026] [security2:error] [pid 643253:tid 643507] [client 35.221.246.130:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cpcontacts.gbq.rty.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/404.html"] [unique_id "amuESMjqbtjBYzqM1uY_ZQAAAHs"]
[Thu Jul 30 12:05:12.485504 2026] [security2:error] [pid 643253:tid 643465] [client 35.221.246.130:57886] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cpcontacts.gbq.rty.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/.git/config"] [unique_id "amuESMjqbtjBYzqM1uY_YwAAAFE"]
[Thu Jul 30 12:05:12.684542 2026] [security2:error] [pid 643253:tid 643442] [client 20.203.148.31:17277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/mah/xleet.php"] [unique_id "amuESMjqbtjBYzqM1uY_ZgAAADo"]
[Thu Jul 30 12:05:12.844950 2026] [security2:error] [pid 643253:tid 643414] [client 20.52.125.110:14929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/abcd.php"] [unique_id "amuESMjqbtjBYzqM1uY_bQAAAB4"]
[Thu Jul 30 12:05:12.852398 2026] [core:notice] [pid 643253:tid 643420] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:12.856424 2026] [security2:error] [pid 643253:tid 643420] [client 103.215.74.26:30338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuESMjqbtjBYzqM1uY_bgAAACQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:12.887411 2026] [security2:error] [pid 643253:tid 643430] [client 35.221.246.130:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cpcalendars.gbq.rty.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/404.html"] [unique_id "amuESMjqbtjBYzqM1uY_cQAAAC4"]
[Thu Jul 30 12:05:12.887905 2026] [security2:error] [pid 643253:tid 643437] [client 35.221.246.130:57908] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cpcalendars.gbq.rty.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/.git/config"] [unique_id "amuESMjqbtjBYzqM1uY_bwAAADU"]
[Thu Jul 30 12:05:13.373177 2026] [security2:error] [pid 643253:tid 643387] [client 86.128.158.166:50630] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEScjqbtjBYzqM1uY_cwAAAAM"], referer: http://pkf.jo
[Thu Jul 30 12:05:13.425566 2026] [security2:error] [pid 643253:tid 643490] [client 20.203.148.31:9329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/mini.php"] [unique_id "amuEScjqbtjBYzqM1uY_fQAAAGo"]
[Thu Jul 30 12:05:13.551223 2026] [security2:error] [pid 643253:tid 643469] [client 172.202.44.182:4114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/moon.php"] [unique_id "amuEScjqbtjBYzqM1uY_hgAAAFU"]
[Thu Jul 30 12:05:13.592876 2026] [security2:error] [pid 643253:tid 643466] [client 91.73.21.151:26273] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEScjqbtjBYzqM1uY_dAAAAFI"], referer: http://pkf.jo
[Thu Jul 30 12:05:13.592997 2026] [core:notice] [pid 643253:tid 643470] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:13.598385 2026] [security2:error] [pid 643253:tid 643470] [client 103.215.74.26:34914] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEScjqbtjBYzqM1uY_iAAAAFY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:14.112802 2026] [core:notice] [pid 643253:tid 643500] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:14.120909 2026] [security2:error] [pid 643253:tid 643415] [client 66.249.73.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuESsjqbtjBYzqM1uY_mAAAAB8"]
[Thu Jul 30 12:05:14.321463 2026] [core:notice] [pid 643253:tid 643445] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:14.328015 2026] [security2:error] [pid 643253:tid 643445] [client 103.215.74.26:34924] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuESsjqbtjBYzqM1uY_ngAAAD0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:14.338143 2026] [security2:error] [pid 643253:tid 643411] [client 20.52.125.110:14328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/about.php"] [unique_id "amuESsjqbtjBYzqM1uY_nwAAABs"]
[Thu Jul 30 12:05:14.350573 2026] [core:notice] [pid 643253:tid 643355] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:14.742914 2026] [security2:error] [pid 643253:tid 643447] [client 20.203.148.31:16681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/moon.php"] [unique_id "amuESsjqbtjBYzqM1uY_pgAAAD8"]
[Thu Jul 30 12:05:14.905577 2026] [security2:error] [pid 643253:tid 643410] [client 37.120.155.179:55654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.155.120.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuESsjqbtjBYzqM1uY_rAAAABo"]
[Thu Jul 30 12:05:14.905667 2026] [security2:error] [pid 643253:tid 643410] [client 37.120.155.179:55654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuESsjqbtjBYzqM1uY_rAAAABo"]
[Thu Jul 30 12:05:15.024262 2026] [security2:error] [pid 643253:tid 643436] [client 20.52.125.110:14312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/admin.php"] [unique_id "amuES8jqbtjBYzqM1uY_sgAAADQ"]
[Thu Jul 30 12:05:15.057245 2026] [core:notice] [pid 643253:tid 643393] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:15.066403 2026] [security2:error] [pid 643253:tid 643393] [client 103.215.74.26:34940] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuES8jqbtjBYzqM1uY_swAAAAk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:15.140237 2026] [core:notice] [pid 643253:tid 643474] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:15.239961 2026] [security2:error] [pid 643253:tid 643483] [client 35.221.246.130:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.riyadhprinter.com"] [uri "/index.php"] [unique_id "amuEScjqbtjBYzqM1uY_iwAAAGM"]
[Thu Jul 30 12:05:15.240021 2026] [security2:error] [pid 643253:tid 643483] [client 35.221.246.130:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.riyadhprinter.com"] [uri "/index.php"] [unique_id "amuEScjqbtjBYzqM1uY_iwAAAGM"]
[Thu Jul 30 12:05:15.240745 2026] [security2:error] [pid 643253:tid 643476] [client 35.221.246.130:57910] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.riyadhprinter.com"] [uri "/.git/config"] [unique_id "amuEScjqbtjBYzqM1uY_iQAAAFw"]
[Thu Jul 30 12:05:15.263126 2026] [security2:error] [pid 643253:tid 643392] [client 35.221.246.130:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.riyadhprinter.com"] [uri "/index.php"] [unique_id "amuESMjqbtjBYzqM1uY_WAAAAAg"]
[Thu Jul 30 12:05:15.263148 2026] [security2:error] [pid 643253:tid 643392] [client 35.221.246.130:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.riyadhprinter.com"] [uri "/index.php"] [unique_id "amuESMjqbtjBYzqM1uY_WAAAAAg"]
[Thu Jul 30 12:05:15.263877 2026] [security2:error] [pid 643253:tid 643460] [client 35.221.246.130:57860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.riyadhprinter.com"] [uri "/.git/config"] [unique_id "amuESMjqbtjBYzqM1uY_VgAAAEw"]
[Thu Jul 30 12:05:15.725081 2026] [security2:error] [pid 643253:tid 643485] [client 20.203.148.31:14722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/new.php"] [unique_id "amuES8jqbtjBYzqM1uY_wQAAAGU"]
[Thu Jul 30 12:05:15.826796 2026] [core:notice] [pid 643253:tid 643482] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:15.830806 2026] [security2:error] [pid 643253:tid 643482] [client 103.215.74.26:34950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuES8jqbtjBYzqM1uY_wgAAAGI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:15.964533 2026] [core:notice] [pid 643253:tid 643486] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:16.159408 2026] [security2:error] [pid 643253:tid 643495] [client 20.52.125.110:14290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/adminfuns.php"] [unique_id "amuETMjqbtjBYzqM1uY_zgAAAG8"]
[Thu Jul 30 12:05:16.203283 2026] [security2:error] [pid 643253:tid 643389] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuES8jqbtjBYzqM1uY_wAAABXc"]
[Thu Jul 30 12:05:16.429349 2026] [security2:error] [pid 643253:tid 643498] [client 37.120.155.179:55656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.155.120.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuETMjqbtjBYzqM1uY_0gAAAHI"]
[Thu Jul 30 12:05:16.429457 2026] [security2:error] [pid 643253:tid 643498] [client 37.120.155.179:55656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuETMjqbtjBYzqM1uY_0gAAAHI"]
[Thu Jul 30 12:05:16.595190 2026] [security2:error] [pid 643253:tid 643401] [client 172.202.44.182:4397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/blog.php"] [unique_id "amuETMjqbtjBYzqM1uY_1wAAABE"]
[Thu Jul 30 12:05:16.614436 2026] [core:notice] [pid 643253:tid 643487] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:16.618422 2026] [security2:error] [pid 643253:tid 643487] [client 103.215.74.26:34954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "767"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuETMjqbtjBYzqM1uY_2AAAAGc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:16.633570 2026] [security2:error] [pid 643253:tid 643491] [client 74.7.241.154:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thdinfinity.com"] [uri "/robots.txt"] [unique_id "amuETMjqbtjBYzqM1uY_2wAAAGs"]
[Thu Jul 30 12:05:16.634260 2026] [security2:error] [pid 643253:tid 643472] [client 74.7.241.154:48378] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thdinfinity.com"] [uri "/robots.txt"] [unique_id "amuETMjqbtjBYzqM1uY_2QAAWHI"]
[Thu Jul 30 12:05:16.888832 2026] [security2:error] [pid 643253:tid 643440] [client 20.203.148.31:9869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/radio.php"] [unique_id "amuETMjqbtjBYzqM1uY_3wAAADg"]
[Thu Jul 30 12:05:17.001655 2026] [security2:error] [pid 643253:tid 643429] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuETMjqbtjBYzqM1uY_1gAAAC0"]
[Thu Jul 30 12:05:17.118043 2026] [security2:error] [pid 643253:tid 643405] [client 20.52.125.110:14913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/albin.php"] [unique_id "amuETcjqbtjBYzqM1uY_5wAAABU"]
[Thu Jul 30 12:05:17.345893 2026] [core:notice] [pid 643253:tid 643481] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:17.353334 2026] [security2:error] [pid 643253:tid 643481] [client 103.215.74.26:34956] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuETcjqbtjBYzqM1uY_6AAAAGE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:17.465387 2026] [core:notice] [pid 643253:tid 643393] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:17.512425 2026] [security2:error] [pid 643253:tid 643408] [client 20.203.148.31:21987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/s.php"] [unique_id "amuETcjqbtjBYzqM1uY_9AAAABg"]
[Thu Jul 30 12:05:17.700224 2026] [security2:error] [pid 643253:tid 643455] [client 74.7.175.157:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mhh.zzt.temporary.site"] [uri "/index.php"] [unique_id "amuES8jqbtjBYzqM1uY_zAAAAEc"]
[Thu Jul 30 12:05:17.701107 2026] [security2:error] [pid 643253:tid 643428] [client 74.7.175.157:36014] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mhh.zzt.temporary.site"] [uri "/robots.txt"] [unique_id "amuES8jqbtjBYzqM1uY_ygAALHo"]
[Thu Jul 30 12:05:17.774128 2026] [security2:error] [pid 643253:tid 643423] [client 20.52.125.110:14283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/amfsqvgv.php"] [unique_id "amuETcjqbtjBYzqM1uY_-QAAACc"]
[Thu Jul 30 12:05:18.021515 2026] [security2:error] [pid 643253:tid 643499] [client 2a03:2880:f800:45:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuETcjqbtjBYzqM1uY_6QAAc34"]
[Thu Jul 30 12:05:18.049229 2026] [core:notice] [pid 643253:tid 643470] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:18.078371 2026] [core:notice] [pid 643253:tid 643466] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:18.082351 2026] [security2:error] [pid 643253:tid 643466] [client 103.215.74.26:34960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "780"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuETsjqbtjBYzqM1uZABAAAAFI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:18.093511 2026] [security2:error] [pid 643253:tid 643425] [client 172.202.44.182:4160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/ini.php"] [unique_id "amuETsjqbtjBYzqM1uZABQAAACk"]
[Thu Jul 30 12:05:18.394779 2026] [security2:error] [pid 643253:tid 643435] [client 74.7.241.168:46750] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "stunningtouchcleaning.com"] [uri "/robots.txt"] [unique_id "amuETsjqbtjBYzqM1uZACQAAM2k"]
[Thu Jul 30 12:05:18.421320 2026] [security2:error] [pid 643253:tid 643461] [client 20.203.148.31:16692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/sim.php"] [unique_id "amuETsjqbtjBYzqM1uZACwAAAE0"]
[Thu Jul 30 12:05:18.458622 2026] [security2:error] [pid 643253:tid 643486] [client 20.52.125.110:14309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/ant.php"] [unique_id "amuETsjqbtjBYzqM1uZADAAAAGY"]
[Thu Jul 30 12:05:18.807042 2026] [core:notice] [pid 643253:tid 643411] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:18.811025 2026] [security2:error] [pid 643253:tid 643411] [client 103.215.74.26:34976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuETsjqbtjBYzqM1uZAFwAAABs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:18.995962 2026] [security2:error] [pid 643253:tid 643472] [client 190.6.14.187:10956] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuETsjqbtjBYzqM1uZAFQAAAFg"], referer: http://pkf.jo
[Thu Jul 30 12:05:19.090117 2026] [security2:error] [pid 643253:tid 643396] [client 172.202.44.182:46815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/admin-ajax.php"] [unique_id "amuET8jqbtjBYzqM1uZAHwAAAAw"]
[Thu Jul 30 12:05:19.218054 2026] [security2:error] [pid 643253:tid 643437] [client 20.52.125.110:14322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/appreciators.php"] [unique_id "amuET8jqbtjBYzqM1uZAIwAAADU"]
[Thu Jul 30 12:05:19.252774 2026] [core:notice] [pid 643253:tid 643488] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:19.536984 2026] [core:notice] [pid 643253:tid 643476] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:19.540945 2026] [security2:error] [pid 643253:tid 643476] [client 103.215.74.26:34988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuET8jqbtjBYzqM1uZAJQAAAFw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:20.272596 2026] [core:notice] [pid 643253:tid 643469] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:20.276601 2026] [security2:error] [pid 643253:tid 643469] [client 103.215.74.26:34996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEUMjqbtjBYzqM1uZANQAAAFU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:20.324214 2026] [security2:error] [pid 643253:tid 643459] [client 20.52.125.110:14928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/archive.php"] [unique_id "amuEUMjqbtjBYzqM1uZANwAAAEs"]
[Thu Jul 30 12:05:20.483660 2026] [security2:error] [pid 643253:tid 643428] [client 172.202.44.182:62068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/akc.php"] [unique_id "amuEUMjqbtjBYzqM1uZAOwAAACw"]
[Thu Jul 30 12:05:20.532487 2026] [security2:error] [pid 643253:tid 643265] [remote 74.7.242.7:52036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.242.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/"] [unique_id "amuEUMjqbtjBYzqM1uZANgAASQo"], referer: https://www.thdinfinity.com/
[Thu Jul 30 12:05:21.082690 2026] [security2:error] [pid 643253:tid 643498] [client 20.203.148.31:26370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/text.php"] [unique_id "amuEUcjqbtjBYzqM1uZASwAAAHI"]
[Thu Jul 30 12:05:21.093322 2026] [security2:error] [pid 643253:tid 643426] [client 57.141.0.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuEUMjqbtjBYzqM1uZAOgAAACo"]
[Thu Jul 30 12:05:21.577729 2026] [security2:error] [pid 643253:tid 643394] [client 172.202.44.182:62026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/akcc.php"] [unique_id "amuEUcjqbtjBYzqM1uZAVAAAAAo"]
[Thu Jul 30 12:05:21.786800 2026] [security2:error] [pid 643253:tid 643384] [client 66.249.74.74:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bensecuritylocksmith.site"] [uri "/index.php"] [unique_id "amuEUcjqbtjBYzqM1uZAUgAAABE"]
[Thu Jul 30 12:05:21.938950 2026] [security2:error] [pid 643253:tid 643406] [client 20.203.148.31:21992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/user.php"] [unique_id "amuEUcjqbtjBYzqM1uZAXgAAABY"]
[Thu Jul 30 12:05:22.702280 2026] [security2:error] [pid 643253:tid 643506] [client 20.203.148.31:9414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/webadmin.php"] [unique_id "amuEUsjqbtjBYzqM1uZAaAAAAHo"]
[Thu Jul 30 12:05:22.722516 2026] [core:error] [pid 643253:tid 643453] [client 195.96.139.69:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:05:22.722535 2026] [core:error] [pid 643253:tid 643453] [client 195.96.139.69:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:05:22.959828 2026] [security2:error] [pid 643253:tid 643448] [client 172.202.44.182:4388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/asasx.php"] [unique_id "amuEUsjqbtjBYzqM1uZAbwAAAEA"]
[Thu Jul 30 12:05:23.146498 2026] [security2:error] [pid 643253:tid 643294] [remote 74.7.242.7:52036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.242.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/"] [unique_id "amuEU8jqbtjBYzqM1uZAcAAAcyc"], referer: https://www.thdinfinity.com/
[Thu Jul 30 12:05:23.513091 2026] [security2:error] [pid 643253:tid 643438] [client 20.52.125.110:14321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/as.php"] [unique_id "amuEU8jqbtjBYzqM1uZAeAAAADY"]
[Thu Jul 30 12:05:23.517616 2026] [security2:error] [pid 643253:tid 643509] [client 88.241.169.202:36622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEU8jqbtjBYzqM1uZAcQAAAH0"], referer: http://pkf.jo
[Thu Jul 30 12:05:24.091435 2026] [security2:error] [pid 643253:tid 643464] [client 185.91.192.106:58001] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEU8jqbtjBYzqM1uZAgQAAAFA"], referer: http://pkf.jo
[Thu Jul 30 12:05:24.331642 2026] [security2:error] [pid 643253:tid 643504] [client 172.202.44.182:62031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/axx.php"] [unique_id "amuEVMjqbtjBYzqM1uZAjgAAAHg"]
[Thu Jul 30 12:05:24.846794 2026] [security2:error] [pid 643253:tid 643489] [client 20.203.148.31:26960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wordpress/wp-content/plugins/xcvbx/autoload_classmap.php"] [unique_id "amuEVMjqbtjBYzqM1uZAlQAAAGk"]
[Thu Jul 30 12:05:25.677811 2026] [security2:error] [pid 643253:tid 643406] [client 172.202.44.182:62024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/berax.php"] [unique_id "amuEVcjqbtjBYzqM1uZAnQAAABY"]
[Thu Jul 30 12:05:25.851241 2026] [core:notice] [pid 643253:tid 643454] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:25.916746 2026] [security2:error] [pid 643253:tid 643477] [client 20.52.125.110:14934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/atomlib.php"] [unique_id "amuEVcjqbtjBYzqM1uZApgAAAF0"]
[Thu Jul 30 12:05:26.014502 2026] [core:notice] [pid 643253:tid 643503] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:26.018883 2026] [security2:error] [pid 643253:tid 643503] [client 103.215.74.26:39748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEVsjqbtjBYzqM1uZApwAAAHc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:26.116764 2026] [security2:error] [pid 643253:tid 643387] [client 106.200.13.198:28444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.13.200.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "urwru.club"] [uri "/xmlrpc.php"] [unique_id "amuEVcjqbtjBYzqM1uZAowAAAAM"]
[Thu Jul 30 12:05:26.116960 2026] [security2:error] [pid 643253:tid 643387] [client 106.200.13.198:28444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "urwru.club"] [uri "/xmlrpc.php"] [unique_id "amuEVcjqbtjBYzqM1uZAowAAAAM"]
[Thu Jul 30 12:05:26.615459 2026] [security2:error] [pid 643253:tid 643416] [client 20.52.125.110:14301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/autoload_classmap.php"] [unique_id "amuEVsjqbtjBYzqM1uZAsQAAACA"]
[Thu Jul 30 12:05:26.736581 2026] [core:notice] [pid 643253:tid 643425] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:26.740419 2026] [security2:error] [pid 643253:tid 643425] [client 103.215.74.26:39756] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEVsjqbtjBYzqM1uZAswAAACk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:26.922291 2026] [core:notice] [pid 643253:tid 643461] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:27.473154 2026] [security2:error] [pid 643253:tid 643463] [client 20.52.125.110:14314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/bb.php"] [unique_id "amuEV8jqbtjBYzqM1uZAwgAAAE8"]
[Thu Jul 30 12:05:27.475928 2026] [core:notice] [pid 643253:tid 643445] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:27.479863 2026] [security2:error] [pid 643253:tid 643445] [client 103.215.74.26:39758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEV8jqbtjBYzqM1uZAwwAAAD0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:28.205512 2026] [core:notice] [pid 643253:tid 643484] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:28.209580 2026] [security2:error] [pid 643253:tid 643484] [client 103.215.74.26:39760] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEWMjqbtjBYzqM1uZAywAAAGQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:28.607201 2026] [security2:error] [pid 643253:tid 643422] [client 20.52.125.110:14333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/bnm.php"] [unique_id "amuEWMjqbtjBYzqM1uZA1gAAACY"]
[Thu Jul 30 12:05:28.948275 2026] [core:notice] [pid 643253:tid 643502] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:28.952353 2026] [security2:error] [pid 643253:tid 643502] [client 103.215.74.26:39768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEWMjqbtjBYzqM1uZA2wAAAHY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:29.106691 2026] [security2:error] [pid 643253:tid 643501] [client 172.202.44.182:51783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/build.php"] [unique_id "amuEWcjqbtjBYzqM1uZA4QAAAHU"]
[Thu Jul 30 12:05:29.235437 2026] [security2:error] [pid 643253:tid 643437] [client 20.52.125.110:14332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/bootstrap.php"] [unique_id "amuEWcjqbtjBYzqM1uZA4gAAADU"]
[Thu Jul 30 12:05:29.339229 2026] [security2:error] [pid 643253:tid 643455] [client 250.49.135.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuEWcjqbtjBYzqM1uZA4wAAR0M"]
[Thu Jul 30 12:05:29.664516 2026] [core:notice] [pid 643253:tid 643477] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:29.668872 2026] [security2:error] [pid 643253:tid 643477] [client 103.215.74.26:39776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEWcjqbtjBYzqM1uZA6wAAAF0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:29.953126 2026] [security2:error] [pid 643253:tid 643392] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEWcjqbtjBYzqM1uZA5AAACEI"]
[Thu Jul 30 12:05:29.995219 2026] [security2:error] [pid 643253:tid 643409] [client 20.203.148.31:26966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wordpress/wp-content/plugins/xcvbx/flower.php"] [unique_id "amuEWcjqbtjBYzqM1uZA-wAAABk"]
[Thu Jul 30 12:05:30.004748 2026] [security2:error] [pid 643253:tid 643403] [client 172.202.44.182:4459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/buy.php"] [unique_id "amuEWsjqbtjBYzqM1uZA_gAAABM"]
[Thu Jul 30 12:05:30.384289 2026] [security2:error] [pid 643253:tid 643425] [client 57.141.0.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuEWcjqbtjBYzqM1uZA7gAAACk"]
[Thu Jul 30 12:05:30.415691 2026] [core:notice] [pid 643253:tid 643486] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:30.420001 2026] [security2:error] [pid 643253:tid 643486] [client 103.215.74.26:39782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEWsjqbtjBYzqM1uZBAwAAAGY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:30.869096 2026] [security2:error] [pid 643253:tid 643507] [client 172.202.44.182:4422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/checkbox.php"] [unique_id "amuEWsjqbtjBYzqM1uZBDgAAAHs"]
[Thu Jul 30 12:05:30.926775 2026] [security2:error] [pid 643253:tid 643491] [client 20.203.148.31:33996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wordpress/wp-content/plugins/xcvbx/xleet.php"] [unique_id "amuEWsjqbtjBYzqM1uZBDwAAAGs"]
[Thu Jul 30 12:05:31.151178 2026] [core:notice] [pid 643253:tid 643449] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:31.155560 2026] [security2:error] [pid 643253:tid 643449] [client 103.215.74.26:39798] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEW8jqbtjBYzqM1uZBGgAAAEE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:31.387378 2026] [security2:error] [pid 643253:tid 643428] [client 57.141.0.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuEWsjqbtjBYzqM1uZBDQAAACw"]
[Thu Jul 30 12:05:31.554034 2026] [security2:error] [pid 643253:tid 643429] [client 20.203.148.31:26407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wordpress/wp-content/themes/as/autoload_classmap.php"] [unique_id "amuEW8jqbtjBYzqM1uZBHgAAAC0"]
[Thu Jul 30 12:05:31.699016 2026] [security2:error] [pid 643253:tid 643410] [client 172.202.44.182:51821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/cong.php"] [unique_id "amuEW8jqbtjBYzqM1uZBIgAAABo"]
[Thu Jul 30 12:05:31.873312 2026] [core:notice] [pid 643253:tid 643492] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:31.877633 2026] [security2:error] [pid 643253:tid 643492] [client 103.215.74.26:39804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEW8jqbtjBYzqM1uZBJAAAAGw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:32.583104 2026] [security2:error] [pid 643253:tid 643462] [client 172.202.44.182:46802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/file4.php"] [unique_id "amuEXMjqbtjBYzqM1uZBNgAAAE4"]
[Thu Jul 30 12:05:32.599171 2026] [core:notice] [pid 643253:tid 643477] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:32.602393 2026] [security2:error] [pid 643253:tid 643435] [client 139.28.219.70:40806] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alqimmafurnituremovers.xyz"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuEXMjqbtjBYzqM1uZBOAAAADM"]
[Thu Jul 30 12:05:32.606569 2026] [security2:error] [pid 643253:tid 643477] [client 103.215.74.26:39810] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEXMjqbtjBYzqM1uZBNwAAAF0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:32.689204 2026] [security2:error] [pid 643253:tid 643474] [client 20.203.148.31:23451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wordpress/wp-content/themes/as/flower.php"] [unique_id "amuEXMjqbtjBYzqM1uZBPAAAAFo"]
[Thu Jul 30 12:05:32.877039 2026] [security2:error] [pid 643253:tid 643431] [client 139.28.219.70:40814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alqimmafurnituremovers.xyz"] [uri "/xmlrpc.php"] [unique_id "amuEXMjqbtjBYzqM1uZBPQAAAC8"]
[Thu Jul 30 12:05:33.136455 2026] [security2:error] [pid 643253:tid 643389] [client 139.28.219.70:40820] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alqimmafurnituremovers.xyz"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuEXcjqbtjBYzqM1uZBQgAAAAU"]
[Thu Jul 30 12:05:33.395223 2026] [security2:error] [pid 643253:tid 643485] [client 139.28.219.70:40828] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alqimmafurnituremovers.xyz"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuEXcjqbtjBYzqM1uZBRgAAAGU"]
[Thu Jul 30 12:05:33.522155 2026] [security2:error] [pid 643253:tid 643450] [client 20.203.148.31:16665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wordpress/wp-content/themes/as/xleet.php"] [unique_id "amuEXcjqbtjBYzqM1uZBRwAAAEI"]
[Thu Jul 30 12:05:33.715773 2026] [security2:error] [pid 643253:tid 643451] [client 139.28.219.70:40830] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alqimmafurnituremovers.xyz"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuEXcjqbtjBYzqM1uZBTgAAAEM"]
[Thu Jul 30 12:05:34.073114 2026] [core:notice] [pid 643253:tid 643400] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:34.097834 2026] [security2:error] [pid 643253:tid 643396] [client 139.28.219.70:40842] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alqimmafurnituremovers.xyz"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuEXsjqbtjBYzqM1uZBVQAAAAw"]
[Thu Jul 30 12:05:34.345540 2026] [security2:error] [pid 643253:tid 643428] [client 136.111.185.9:10752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.185.111.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/PBB/issue/current"] [unique_id "amuEXsjqbtjBYzqM1uZBVAAAACw"]
[Thu Jul 30 12:05:34.478628 2026] [security2:error] [pid 643253:tid 643508] [client 139.28.219.70:40854] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alqimmafurnituremovers.xyz"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuEXsjqbtjBYzqM1uZBXgAAAHw"]
[Thu Jul 30 12:05:34.543177 2026] [security2:error] [pid 643253:tid 643452] [client 172.202.44.182:46845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/flower.php"] [unique_id "amuEXsjqbtjBYzqM1uZBXwAAAEQ"]
[Thu Jul 30 12:05:34.739777 2026] [security2:error] [pid 643253:tid 643412] [client 139.28.219.70:40858] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alqimmafurnituremovers.xyz"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuEXsjqbtjBYzqM1uZBZAAAABw"]
[Thu Jul 30 12:05:35.012055 2026] [security2:error] [pid 643253:tid 643448] [client 139.28.219.70:40868] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alqimmafurnituremovers.xyz"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuEX8jqbtjBYzqM1uZBaAAAAEA"]
[Thu Jul 30 12:05:35.168498 2026] [security2:error] [pid 643253:tid 643434] [client 20.203.148.31:9647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "amuEX8jqbtjBYzqM1uZBaQAAADI"]
[Thu Jul 30 12:05:35.349283 2026] [security2:error] [pid 643253:tid 643403] [client 139.28.219.70:40884] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alqimmafurnituremovers.xyz"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuEX8jqbtjBYzqM1uZBcAAAABM"]
[Thu Jul 30 12:05:35.468681 2026] [security2:error] [pid 643253:tid 643473] [client 20.52.125.110:14304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/buy.php"] [unique_id "amuEX8jqbtjBYzqM1uZBcgAAAFk"]
[Thu Jul 30 12:05:35.664375 2026] [security2:error] [pid 643253:tid 643474] [client 139.28.219.70:40900] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alqimmafurnituremovers.xyz"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuEX8jqbtjBYzqM1uZBcwAAAFo"]
[Thu Jul 30 12:05:35.792370 2026] [security2:error] [pid 643253:tid 643458] [client 20.203.148.31:9430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/css/colors/autoload_classmap.php"] [unique_id "amuEX8jqbtjBYzqM1uZBeQAAAEo"]
[Thu Jul 30 12:05:35.847364 2026] [core:error] [pid 643253:tid 643359] [remote 43.140.223.163:53002] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://mahsudtransportandbuildingdemolition.business/robots.txt
[Thu Jul 30 12:05:35.847384 2026] [core:error] [pid 643253:tid 643359] [remote 43.140.223.163:53002] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://mahsudtransportandbuildingdemolition.business/robots.txt
[Thu Jul 30 12:05:35.852083 2026] [core:error] [pid 643253:tid 643348] [remote 120.53.89.23:54390] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://mahsudtransportandbuildingdemolition.business/robots.txt
[Thu Jul 30 12:05:35.852101 2026] [core:error] [pid 643253:tid 643348] [remote 120.53.89.23:54390] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://mahsudtransportandbuildingdemolition.business/robots.txt
[Thu Jul 30 12:05:35.932924 2026] [security2:error] [pid 643253:tid 643479] [client 139.28.219.70:40916] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alqimmafurnituremovers.xyz"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuEX8jqbtjBYzqM1uZBfQAAAF8"]
[Thu Jul 30 12:05:36.267829 2026] [security2:error] [pid 643253:tid 643487] [client 139.28.219.70:40932] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alqimmafurnituremovers.xyz"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuEYMjqbtjBYzqM1uZBgQAAAGc"]
[Thu Jul 30 12:05:36.345535 2026] [security2:error] [pid 643253:tid 643426] [client 20.52.125.110:14282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/chosen.php"] [unique_id "amuEYMjqbtjBYzqM1uZBggAAACo"]
[Thu Jul 30 12:05:36.386239 2026] [security2:error] [pid 643253:tid 643401] [client 20.203.148.31:16685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/css/colors/flower.php"] [unique_id "amuEYMjqbtjBYzqM1uZBhgAAABE"]
[Thu Jul 30 12:05:36.439156 2026] [security2:error] [pid 643253:tid 643409] [client 172.202.44.182:62059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/form.php"] [unique_id "amuEYMjqbtjBYzqM1uZBhwAAABk"]
[Thu Jul 30 12:05:36.551083 2026] [security2:error] [pid 643253:tid 643449] [client 139.28.219.70:40936] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alqimmafurnituremovers.xyz"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuEYMjqbtjBYzqM1uZBiwAAAEE"]
[Thu Jul 30 12:05:36.698274 2026] [security2:error] [pid 643253:tid 643377] [remote 172.232.108.36:42030] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.58"] [uri "/"] [unique_id "amuEYMjqbtjBYzqM1uZBjAAADno"]
[Thu Jul 30 12:05:36.860950 2026] [security2:error] [pid 643253:tid 643436] [client 139.28.219.70:40950] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alqimmafurnituremovers.xyz"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuEYMjqbtjBYzqM1uZBkQAAADQ"]
[Thu Jul 30 12:05:36.990091 2026] [security2:error] [pid 643253:tid 643381] [remote 139.59.102.237:54490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.102.59.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upns.ca"] [uri "/wp-login.php"] [unique_id "amuEYMjqbtjBYzqM1uZBjQAAWH4"]
[Thu Jul 30 12:05:37.136127 2026] [security2:error] [pid 643253:tid 643492] [client 139.28.219.70:40962] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alqimmafurnituremovers.xyz"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuEYcjqbtjBYzqM1uZBlQAAAGw"]
[Thu Jul 30 12:05:37.188541 2026] [security2:error] [pid 643253:tid 643396] [client 20.203.148.31:34021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/css/colors/xleet.php"] [unique_id "amuEYcjqbtjBYzqM1uZBlgAAAAw"]
[Thu Jul 30 12:05:37.478214 2026] [security2:error] [pid 643253:tid 643483] [client 172.202.44.182:51789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/gecko.php"] [unique_id "amuEYcjqbtjBYzqM1uZBnQAAAGM"]
[Thu Jul 30 12:05:37.653545 2026] [security2:error] [pid 643253:tid 643406] [client 20.52.125.110:14311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/class-wp-image.php"] [unique_id "amuEYcjqbtjBYzqM1uZBoAAAABY"]
[Thu Jul 30 12:05:37.952897 2026] [security2:error] [pid 643253:tid 643490] [client 20.203.148.31:17677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/flower.php"] [unique_id "amuEYcjqbtjBYzqM1uZBqQAAAGo"]
[Thu Jul 30 12:05:38.378727 2026] [security2:error] [pid 643253:tid 643466] [client 172.202.44.182:46832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/kyami.php"] [unique_id "amuEYsjqbtjBYzqM1uZBrgAAAFI"]
[Thu Jul 30 12:05:38.411483 2026] [core:notice] [pid 643253:tid 643458] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:38.415720 2026] [security2:error] [pid 643253:tid 643458] [client 103.215.74.26:63838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEYsjqbtjBYzqM1uZBsAAAAEo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:38.589032 2026] [security2:error] [pid 643253:tid 643427] [client 20.52.125.110:14925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/classsmtps.php"] [unique_id "amuEYsjqbtjBYzqM1uZBtAAAACs"]
[Thu Jul 30 12:05:39.042920 2026] [security2:error] [pid 643253:tid 643459] [client 20.203.148.31:33989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/maint/autoload_classmap.php"] [unique_id "amuEY8jqbtjBYzqM1uZBvgAAAEs"]
[Thu Jul 30 12:05:39.142841 2026] [core:notice] [pid 643253:tid 643440] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:39.147233 2026] [security2:error] [pid 643253:tid 643440] [client 103.215.74.26:63840] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEY8jqbtjBYzqM1uZBvwAAADg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:39.534017 2026] [security2:error] [pid 643253:tid 643430] [client 172.202.44.182:62065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/manager.php"] [unique_id "amuEY8jqbtjBYzqM1uZBxwAAAC4"]
[Thu Jul 30 12:05:39.716395 2026] [security2:error] [pid 643253:tid 643390] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEY8jqbtjBYzqM1uZBwAAABgw"]
[Thu Jul 30 12:05:39.869798 2026] [core:notice] [pid 643253:tid 643429] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:39.873888 2026] [security2:error] [pid 643253:tid 643429] [client 103.215.74.26:63846] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEY8jqbtjBYzqM1uZByQAAAC0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:40.275571 2026] [core:notice] [pid 643253:tid 643510] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:40.462732 2026] [security2:error] [pid 643253:tid 643391] [client 172.202.44.182:4439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/mari.php"] [unique_id "amuEZMjqbtjBYzqM1uZB1QAAAAc"]
[Thu Jul 30 12:05:40.591389 2026] [core:notice] [pid 643253:tid 643508] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:40.595511 2026] [security2:error] [pid 643253:tid 643508] [client 103.215.74.26:63850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEZMjqbtjBYzqM1uZB3AAAAHw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:41.327247 2026] [core:notice] [pid 643253:tid 643496] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:41.331365 2026] [security2:error] [pid 643253:tid 643496] [client 103.215.74.26:63860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEZcjqbtjBYzqM1uZB6AAAAHA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:41.518637 2026] [security2:error] [pid 643253:tid 643475] [client 172.202.44.182:4453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/nc4.php"] [unique_id "amuEZcjqbtjBYzqM1uZB6QAAAFs"]
[Thu Jul 30 12:05:41.657498 2026] [security2:error] [pid 643253:tid 643297] [remote 97.74.93.24:43452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/wp-login.php"] [unique_id "amuEZcjqbtjBYzqM1uZB8wAAPCo"]
[Thu Jul 30 12:05:42.063955 2026] [core:notice] [pid 643253:tid 643425] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:42.067796 2026] [security2:error] [pid 643253:tid 643467] [client 20.52.125.110:14948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/classwithtostring.php"] [unique_id "amuEZsjqbtjBYzqM1uZB9gAAAFM"]
[Thu Jul 30 12:05:42.068465 2026] [security2:error] [pid 643253:tid 643425] [client 103.215.74.26:63866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEZsjqbtjBYzqM1uZB9AAAACk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:42.800317 2026] [core:notice] [pid 643253:tid 643451] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:42.807781 2026] [security2:error] [pid 643253:tid 643451] [client 103.215.74.26:63868] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEZsjqbtjBYzqM1uZCBAAAAEM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:42.850204 2026] [cgid:error] [pid 643253:tid 643401] [client 172.202.44.182:57998] AH01265: stderr from /home2/xjjgzjte/public_html/cgi-bin/: attempt to invoke directory as script
[Thu Jul 30 12:05:42.855572 2026] [security2:error] [pid 643253:tid 643388] [client 57.141.0.68:36022] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuEZsjqbtjBYzqM1uZB_AAABHQ"], referer: https://igetvape-australia.com/product-tag/iget-moon-passion-fruit-lychee-5000-puffs/
[Thu Jul 30 12:05:42.871068 2026] [security2:error] [pid 643253:tid 643423] [client 20.52.125.110:14922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/config.php"] [unique_id "amuEZsjqbtjBYzqM1uZCBgAAACc"]
[Thu Jul 30 12:05:43.452801 2026] [core:notice] [pid 643253:tid 643287] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:43.534473 2026] [core:notice] [pid 643253:tid 643396] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:43.541084 2026] [security2:error] [pid 643253:tid 643396] [client 103.215.74.26:55852] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEZ8jqbtjBYzqM1uZCFwAAAAw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:43.797148 2026] [security2:error] [pid 643253:tid 643419] [client 34.86.95.193:58940] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kev.udi.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuEZ8jqbtjBYzqM1uZCGAAAACM"]
[Thu Jul 30 12:05:44.203239 2026] [security2:error] [pid 643253:tid 643492] [client 20.52.125.110:14299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/core.php"] [unique_id "amuEaMjqbtjBYzqM1uZCIwAAAGw"]
[Thu Jul 30 12:05:44.333833 2026] [core:notice] [pid 643253:tid 643305] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:44.556968 2026] [security2:error] [pid 643253:tid 643438] [client 113.191.118.192:48921] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEaMjqbtjBYzqM1uZCJAAAADY"], referer: http://pkf.jo
[Thu Jul 30 12:05:44.663684 2026] [security2:error] [pid 643253:tid 643392] [client 114.119.147.113:57799] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jwcpartners.org"] [uri "/robots.txt"] [unique_id "amuEaMjqbtjBYzqM1uZCNAAAAAg"], referer: https://jwcpartners.org/robots.txt
[Thu Jul 30 12:05:44.922631 2026] [core:notice] [pid 643253:tid 643312] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:44.936829 2026] [security2:error] [pid 643253:tid 643424] [client 20.203.148.31:17241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/maint/flower.php"] [unique_id "amuEaMjqbtjBYzqM1uZCOQAAACg"]
[Thu Jul 30 12:05:45.045316 2026] [security2:error] [pid 643253:tid 643425] [client 20.52.125.110:14401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/css.php"] [unique_id "amuEacjqbtjBYzqM1uZCPgAAACk"]
[Thu Jul 30 12:05:45.212444 2026] [core:notice] [pid 643253:tid 643323] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:45.421271 2026] [security2:error] [pid 643253:tid 643507] [client 106.214.131.239:48812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEacjqbtjBYzqM1uZCQgAAAHs"], referer: http://pkf.jo
[Thu Jul 30 12:05:45.595552 2026] [security2:error] [pid 643253:tid 643411] [client 20.52.125.110:14289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/database.php"] [unique_id "amuEacjqbtjBYzqM1uZCTAAAABs"]
[Thu Jul 30 12:05:46.114995 2026] [security2:error] [pid 643253:tid 643506] [client 107.175.212.202:39102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.212.175.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.northyorksheridanmall.com"] [uri "/wp-comments-post.php"] [unique_id "amuEasjqbtjBYzqM1uZCVAAAAHo"], referer: http://www.northyorksheridanmall.com/?p=26
[Thu Jul 30 12:05:46.115104 2026] [security2:error] [pid 643253:tid 643506] [client 107.175.212.202:39102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.northyorksheridanmall.com"] [uri "/wp-comments-post.php"] [unique_id "amuEasjqbtjBYzqM1uZCVAAAAHo"], referer: http://www.northyorksheridanmall.com/?p=26
[Thu Jul 30 12:05:46.458989 2026] [core:notice] [pid 643253:tid 643488] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:46.708394 2026] [security2:error] [pid 643253:tid 643472] [client 34.86.95.193:61436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kev.udi.temporary.site"] [uri "/index.php"] [unique_id "amuEasjqbtjBYzqM1uZCXQAAAFg"]
[Thu Jul 30 12:05:46.956792 2026] [security2:error] [pid 643253:tid 643478] [client 34.86.95.193:61436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.95.86.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kev.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuEasjqbtjBYzqM1uZCYQAAAF4"]
[Thu Jul 30 12:05:46.956923 2026] [security2:error] [pid 643253:tid 643478] [client 34.86.95.193:61436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kev.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuEasjqbtjBYzqM1uZCYQAAAF4"]
[Thu Jul 30 12:05:47.374275 2026] [core:notice] [pid 643253:tid 643456] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:47.432344 2026] [security2:error] [pid 643253:tid 643511] [client 20.52.125.110:14285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/db.php"] [unique_id "amuEa8jqbtjBYzqM1uZCbAAAAH8"]
[Thu Jul 30 12:05:47.724698 2026] [core:notice] [pid 643253:tid 643401] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:47.876544 2026] [security2:error] [pid 643253:tid 643500] [client 74.7.230.14:34946] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.ajg.zzt.temporary.site"] [uri "/robots.txt"] [unique_id "amuEa8jqbtjBYzqM1uZCdgAAAHQ"]
[Thu Jul 30 12:05:48.025895 2026] [security2:error] [pid 643253:tid 643395] [client 20.52.125.110:14919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/default.php"] [unique_id "amuEbMjqbtjBYzqM1uZCdwAAAAs"]
[Thu Jul 30 12:05:49.021230 2026] [security2:error] [pid 643253:tid 643418] [client 202.21.121.117:53949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.121.21.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vertexfurnituretransport.site"] [uri "/xmlrpc.php"] [unique_id "amuEbMjqbtjBYzqM1uZCggAAACI"]
[Thu Jul 30 12:05:49.021454 2026] [security2:error] [pid 643253:tid 643418] [client 202.21.121.117:53949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vertexfurnituretransport.site"] [uri "/xmlrpc.php"] [unique_id "amuEbMjqbtjBYzqM1uZCggAAACI"]
[Thu Jul 30 12:05:49.209480 2026] [security2:error] [pid 643253:tid 643398] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEbMjqbtjBYzqM1uZCgQAADlY"]
[Thu Jul 30 12:05:49.270358 2026] [core:notice] [pid 643253:tid 643391] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:49.274273 2026] [security2:error] [pid 643253:tid 643391] [client 103.215.74.26:55856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEbcjqbtjBYzqM1uZCkAAAAAc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:50.030540 2026] [core:notice] [pid 643253:tid 643478] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:50.034579 2026] [security2:error] [pid 643253:tid 643478] [client 103.215.74.26:55860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "767"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEbsjqbtjBYzqM1uZCmwAAAF4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:50.479033 2026] [security2:error] [pid 643253:tid 643449] [client 20.52.125.110:14975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/dropdown.php"] [unique_id "amuEbsjqbtjBYzqM1uZCowAAAEE"]
[Thu Jul 30 12:05:50.797705 2026] [core:notice] [pid 643253:tid 643498] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:50.804390 2026] [security2:error] [pid 643253:tid 643498] [client 103.215.74.26:55866] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEbsjqbtjBYzqM1uZCqQAAAHI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:51.311145 2026] [security2:error] [pid 643253:tid 643331] [remote 74.7.241.60:56584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/content/article.php"] [unique_id "amuEb8jqbtjBYzqM1uZCsAAAOkw"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/content/1784123347_ed%20inclusive.jpg
[Thu Jul 30 12:05:51.541347 2026] [core:notice] [pid 643253:tid 643414] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:51.545405 2026] [security2:error] [pid 643253:tid 643414] [client 103.215.74.26:55876] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "780"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEb8jqbtjBYzqM1uZCtQAAAB4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:51.650799 2026] [security2:error] [pid 643253:tid 643463] [client 186.114.235.94:50215] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEb8jqbtjBYzqM1uZCsQAAAE8"], referer: http://pkf.jo
[Thu Jul 30 12:05:52.096317 2026] [security2:error] [pid 643253:tid 643511] [client 20.203.148.31:26415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/maint/xleet.php"] [unique_id "amuEcMjqbtjBYzqM1uZCvwAAAH8"]
[Thu Jul 30 12:05:52.289816 2026] [core:notice] [pid 643253:tid 643430] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:52.294000 2026] [security2:error] [pid 643253:tid 643430] [client 103.215.74.26:55882] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEcMjqbtjBYzqM1uZCwwAAAC4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:53.030377 2026] [core:notice] [pid 643253:tid 643454] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:53.034286 2026] [security2:error] [pid 643253:tid 643454] [client 103.215.74.26:36000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEccjqbtjBYzqM1uZCzgAAAEY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:53.817378 2026] [security2:error] [pid 643253:tid 643460] [client 47.128.24.232:14544] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "shop-mevius.com"] [uri "/robots.txt"] [unique_id "amuEccjqbtjBYzqM1uZC4wAAAEw"]
[Thu Jul 30 12:05:53.851523 2026] [security2:error] [pid 643253:tid 643478] [client 74.7.241.130:42460] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.ajakholding.net"] [uri "/index.php"] [unique_id "amuEccjqbtjBYzqM1uZC3gAAXjo"]
[Thu Jul 30 12:05:54.253037 2026] [security2:error] [pid 643253:tid 643456] [client 20.203.148.31:13705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amuEcsjqbtjBYzqM1uZC7wAAAEg"]
[Thu Jul 30 12:05:54.605590 2026] [security2:error] [pid 643253:tid 643494] [client 20.52.125.110:14946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/edit.php"] [unique_id "amuEcsjqbtjBYzqM1uZC9gAAAG4"]
[Thu Jul 30 12:05:55.318952 2026] [security2:error] [pid 643253:tid 643405] [client 117.207.246.107:58378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEc8jqbtjBYzqM1uZC-wAAABU"], referer: http://pkf.jo
[Thu Jul 30 12:05:55.454075 2026] [security2:error] [pid 643253:tid 643507] [client 2a03:2880:f800:9:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEcsjqbtjBYzqM1uZC9wAAe2g"]
[Thu Jul 30 12:05:55.685462 2026] [security2:error] [pid 643253:tid 643390] [client 2a03:2880:f800:27:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEc8jqbtjBYzqM1uZC_AAABmE"]
[Thu Jul 30 12:05:56.141115 2026] [core:error] [pid 643253:tid 643428] [client 144.76.32.236:30484] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:05:56.141139 2026] [core:error] [pid 643253:tid 643428] [client 144.76.32.236:30484] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:05:56.277121 2026] [security2:error] [pid 643253:tid 643408] [client 20.52.125.110:14417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/f35.php"] [unique_id "amuEdMjqbtjBYzqM1uZDDgAAABg"]
[Thu Jul 30 12:05:56.298737 2026] [security2:error] [pid 643253:tid 643480] [client 152.59.143.78:35611] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEdMjqbtjBYzqM1uZDCQAAAGA"], referer: http://pkf.jo
[Thu Jul 30 12:05:56.354953 2026] [security2:error] [pid 643253:tid 643429] [client 20.203.148.31:16689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/network/flower.php"] [unique_id "amuEdMjqbtjBYzqM1uZDDwAAAC0"]
[Thu Jul 30 12:05:56.509945 2026] [autoindex:error] [pid 643253:tid 643419] [client 144.76.32.236:30492] AH01276: Cannot serve directory /home2/ubphmute/public_html/website_da8a69f1/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:05:57.106241 2026] [security2:error] [pid 643253:tid 643406] [client 20.203.148.31:26414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/network/xleet.php"] [unique_id "amuEdcjqbtjBYzqM1uZDGwAAABY"]
[Thu Jul 30 12:05:57.495041 2026] [security2:error] [pid 643253:tid 643277] [remote 74.7.242.7:58618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.242.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/"] [unique_id "amuEdcjqbtjBYzqM1uZDIAAAShY"], referer: https://www.thdinfinity.com/
[Thu Jul 30 12:05:57.718724 2026] [security2:error] [pid 643253:tid 643457] [client 20.52.125.110:14923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/f7.php"] [unique_id "amuEdcjqbtjBYzqM1uZDKwAAAEk"]
[Thu Jul 30 12:05:58.752583 2026] [core:notice] [pid 643253:tid 643463] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:58.756649 2026] [security2:error] [pid 643253:tid 643463] [client 103.215.74.26:36008] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEdsjqbtjBYzqM1uZDOgAAAE8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:58.824796 2026] [proxy:error] [pid 643253:tid 643370] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:05:58.824850 2026] [proxy_http:error] [pid 643253:tid 643370] [remote 74.7.228.46:52504] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:05:58.825555 2026] [proxy:error] [pid 643253:tid 643370] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:05:58.825601 2026] [proxy_http:error] [pid 643253:tid 643370] [remote 74.7.228.46:52504] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:05:59.488254 2026] [core:notice] [pid 643253:tid 643510] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:59.492578 2026] [security2:error] [pid 643253:tid 643510] [client 103.215.74.26:36012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEd8jqbtjBYzqM1uZDSAAAAH4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:59.604150 2026] [security2:error] [pid 643253:tid 643400] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEd8jqbtjBYzqM1uZDQAAAEBA"]
[Thu Jul 30 12:06:00.219806 2026] [core:notice] [pid 643253:tid 643503] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:00.223813 2026] [security2:error] [pid 643253:tid 643503] [client 103.215.74.26:36016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEeMjqbtjBYzqM1uZDUwAAAHc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:00.958128 2026] [core:notice] [pid 643253:tid 643461] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:00.962178 2026] [security2:error] [pid 643253:tid 643461] [client 103.215.74.26:36026] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEeMjqbtjBYzqM1uZDXgAAAE0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:01.257672 2026] [security2:error] [pid 643253:tid 643438] [client 20.203.148.31:25537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/user/autoload_classmap.php"] [unique_id "amuEecjqbtjBYzqM1uZDZAAAADY"]
[Thu Jul 30 12:06:01.711702 2026] [core:notice] [pid 643253:tid 643487] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:01.716073 2026] [security2:error] [pid 643253:tid 643487] [client 103.215.74.26:36028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEecjqbtjBYzqM1uZDawAAAGc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:02.291612 2026] [security2:error] [pid 643253:tid 643411] [client 20.203.148.31:13716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/user/flower.php"] [unique_id "amuEesjqbtjBYzqM1uZDdgAAABs"]
[Thu Jul 30 12:06:02.463325 2026] [core:notice] [pid 643253:tid 643402] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:02.467578 2026] [security2:error] [pid 643253:tid 643402] [client 103.215.74.26:36030] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEesjqbtjBYzqM1uZDeQAAABI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:03.205833 2026] [core:notice] [pid 643253:tid 643390] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:03.211501 2026] [security2:error] [pid 643253:tid 643390] [client 103.215.74.26:21834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEe8jqbtjBYzqM1uZDggAAAAY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:03.938857 2026] [core:notice] [pid 643253:tid 643448] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:03.943374 2026] [security2:error] [pid 643253:tid 643448] [client 103.215.74.26:21844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEe8jqbtjBYzqM1uZDjwAAAEA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:04.636245 2026] [proxy:error] [pid 643253:tid 643287] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:06:04.636299 2026] [proxy_http:error] [pid 643253:tid 643287] [remote 74.7.175.149:46874] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:06:04.636906 2026] [proxy:error] [pid 643253:tid 643287] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:06:04.636948 2026] [proxy_http:error] [pid 643253:tid 643287] [remote 74.7.175.149:46874] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:06:04.683124 2026] [core:notice] [pid 643253:tid 643469] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:04.687449 2026] [security2:error] [pid 643253:tid 643469] [client 103.215.74.26:21846] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEfMjqbtjBYzqM1uZDmgAAAFU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:05.075936 2026] [security2:error] [pid 643253:tid 643394] [client 20.203.148.31:9450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/user/xleet.php"] [unique_id "amuEfcjqbtjBYzqM1uZDowAAAAo"]
[Thu Jul 30 12:06:05.436782 2026] [core:notice] [pid 643253:tid 643434] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:05.441171 2026] [security2:error] [pid 643253:tid 643434] [client 103.215.74.26:21856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEfcjqbtjBYzqM1uZDqwAAADI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:06.157211 2026] [core:notice] [pid 643253:tid 643447] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:06.161655 2026] [security2:error] [pid 643253:tid 643447] [client 103.215.74.26:21864] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEfsjqbtjBYzqM1uZDswAAAD8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:06.894022 2026] [core:notice] [pid 643253:tid 643502] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:06.898467 2026] [security2:error] [pid 643253:tid 643502] [client 103.215.74.26:21870] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEfsjqbtjBYzqM1uZDvgAAAHY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:07.218007 2026] [security2:error] [pid 643253:tid 643470] [client 2a03:2880:f800:1:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEfsjqbtjBYzqM1uZDugAAVi8"]
[Thu Jul 30 12:06:07.621552 2026] [core:notice] [pid 643253:tid 643455] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:07.625958 2026] [security2:error] [pid 643253:tid 643455] [client 103.215.74.26:21876] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEf8jqbtjBYzqM1uZDywAAAEc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:08.357421 2026] [core:notice] [pid 643253:tid 643387] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:08.361496 2026] [security2:error] [pid 643253:tid 643387] [client 103.215.74.26:21882] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEgMjqbtjBYzqM1uZD6gAAAAM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:08.377199 2026] [security2:error] [pid 643253:tid 643398] [client 20.203.148.31:14776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/xleet.php"] [unique_id "amuEgMjqbtjBYzqM1uZD6wAAAA4"]
[Thu Jul 30 12:06:09.085078 2026] [core:notice] [pid 643253:tid 643442] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:09.089070 2026] [security2:error] [pid 643253:tid 643442] [client 103.215.74.26:21896] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEgcjqbtjBYzqM1uZD9gAAADo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:09.777970 2026] [security2:error] [pid 643253:tid 643447] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEgcjqbtjBYzqM1uZD-gAAP1Y"]
[Thu Jul 30 12:06:09.823585 2026] [core:notice] [pid 643253:tid 643405] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:09.827571 2026] [security2:error] [pid 643253:tid 643405] [client 103.215.74.26:21908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEgcjqbtjBYzqM1uZEAgAAABU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:10.557866 2026] [core:notice] [pid 643253:tid 643463] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:10.562265 2026] [security2:error] [pid 643253:tid 643463] [client 103.215.74.26:21918] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEgsjqbtjBYzqM1uZEEAAAAE8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:10.724533 2026] [security2:error] [pid 643253:tid 643510] [client 54.164.106.236:14520] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2019/09/24b803c5-4f4b-4cc4-9562-0e95a621eaee-300x300.jpg"] [unique_id "amuEgsjqbtjBYzqM1uZEFAAAAH4"]
[Thu Jul 30 12:06:10.861434 2026] [security2:error] [pid 643253:tid 643477] [client 20.203.148.31:9251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-config-sample.php"] [unique_id "amuEgsjqbtjBYzqM1uZEFQAAAF0"]
[Thu Jul 30 12:06:11.184231 2026] [lsapi:error] [pid 642360:tid 642455] [remote 102.209.111.62:0] [host flixon.net] Error receiving response: ReceiveResponse: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1009; user ID 1009), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://flixon.net/video/shall-we-dance-vj-junior/
[Thu Jul 30 12:06:11.278538 2026] [core:notice] [pid 643253:tid 643449] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:11.285084 2026] [security2:error] [pid 643253:tid 643449] [client 103.215.74.26:21926] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEg8jqbtjBYzqM1uZEHQAAAEE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:11.324499 2026] [security2:error] [pid 643253:tid 643363] [remote 57.141.0.52:26638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/7399102667/feed/rss2/"] [unique_id "amuEg8jqbtjBYzqM1uZEHgAAWWw"]
[Thu Jul 30 12:06:12.027973 2026] [core:notice] [pid 643253:tid 643398] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:12.034615 2026] [security2:error] [pid 643253:tid 643398] [client 103.215.74.26:21934] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEhMjqbtjBYzqM1uZEKAAAAA4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:12.761469 2026] [core:notice] [pid 643253:tid 643464] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:12.765513 2026] [security2:error] [pid 643253:tid 643464] [client 103.215.74.26:21940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEhMjqbtjBYzqM1uZENAAAAFA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:13.495546 2026] [core:notice] [pid 643253:tid 643384] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:13.499549 2026] [security2:error] [pid 643253:tid 643384] [client 103.215.74.26:56728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "766"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEhcjqbtjBYzqM1uZEPwAAAAA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:13.749997 2026] [security2:error] [pid 643253:tid 643413] [client 57.141.0.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuEhcjqbtjBYzqM1uZEOgAAAB0"]
[Thu Jul 30 12:06:13.824318 2026] [security2:error] [pid 643253:tid 643369] [remote 47.128.125.87:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "fantasynamelist.com"] [uri "/robots.txt"] [unique_id "amuEhcjqbtjBYzqM1uZERwAAdXI"]
[Thu Jul 30 12:06:13.960184 2026] [security2:error] [pid 643253:tid 643412] [client 57.141.0.34:23156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuEhcjqbtjBYzqM1uZERQAAHFw"], referer: https://igetvape-australia.com/product/alibarbar-rich-8000-puffs-8/
[Thu Jul 30 12:06:14.236419 2026] [core:notice] [pid 643253:tid 643420] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:14.247346 2026] [security2:error] [pid 643253:tid 643420] [client 103.215.74.26:56738] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEhsjqbtjBYzqM1uZEUQAAACQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:14.457960 2026] [security2:error] [pid 643253:tid 643505] [client 18.214.186.220:43202] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2015/03/20150321053259-300x168.jpg"] [unique_id "amuEhsjqbtjBYzqM1uZEUwAAAHk"]
[Thu Jul 30 12:06:14.981391 2026] [core:notice] [pid 643253:tid 643421] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:14.985350 2026] [security2:error] [pid 643253:tid 643421] [client 103.215.74.26:56740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "779"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEhsjqbtjBYzqM1uZEXgAAACU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:15.730884 2026] [core:notice] [pid 643253:tid 643450] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:15.735897 2026] [security2:error] [pid 643253:tid 643450] [client 103.215.74.26:56748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEh8jqbtjBYzqM1uZEaQAAAEI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:15.937084 2026] [security2:error] [pid 643253:tid 643434] [client 57.141.0.39:32550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuEh8jqbtjBYzqM1uZEaAAAMl4"], referer: https://igetvape-australia.com/product/alibarbar-ingot-strawberry-lychee-ice-9000-puffs/?add-to-cart=940
[Thu Jul 30 12:06:16.394792 2026] [security2:error] [pid 643253:tid 643431] [client 191.232.199.39:20310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/chosen.php"] [unique_id "amuEiMjqbtjBYzqM1uZEdwAAAC8"]
[Thu Jul 30 12:06:16.523696 2026] [security2:error] [pid 643253:tid 643442] [client 57.141.0.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuEh8jqbtjBYzqM1uZEcAAAADo"]
[Thu Jul 30 12:06:16.995519 2026] [security2:error] [pid 643253:tid 643404] [client 186.148.85.50:37998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEiMjqbtjBYzqM1uZEfAAAABQ"], referer: http://pkf.jo
[Thu Jul 30 12:06:17.282225 2026] [core:notice] [pid 643253:tid 643453] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:17.897971 2026] [security2:error] [pid 643253:tid 643455] [client 2a03:2880:f800:3c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEicjqbtjBYzqM1uZEhAAARxY"]
[Thu Jul 30 12:06:17.933868 2026] [security2:error] [pid 643253:tid 643419] [client 190.12.153.11:44082] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEicjqbtjBYzqM1uZEigAAACM"], referer: http://pkf.jo
[Thu Jul 30 12:06:18.713084 2026] [security2:error] [pid 643253:tid 643490] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEisjqbtjBYzqM1uZEkwAAagI"]
[Thu Jul 30 12:06:18.776078 2026] [security2:error] [pid 643253:tid 643412] [client 191.232.199.39:19628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/xleet.php"] [unique_id "amuEisjqbtjBYzqM1uZEoAAAABw"]
[Thu Jul 30 12:06:19.633871 2026] [security2:error] [pid 643253:tid 643280] [remote 5.182.209.54:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.209.182.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "santaclaraimports.com"] [uri "/xmlrpc.php"] [unique_id "amuEi8jqbtjBYzqM1uZErwAAKRk"]
[Thu Jul 30 12:06:19.634088 2026] [security2:error] [pid 643253:tid 643425] [client 5.182.209.54:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "santaclaraimports.com"] [uri "/xmlrpc.php"] [unique_id "amuEi8jqbtjBYzqM1uZErwAAKRk"]
[Thu Jul 30 12:06:19.659841 2026] [security2:error] [pid 643253:tid 643261] [remote 74.7.242.7:53098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.242.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/"] [unique_id "amuEi8jqbtjBYzqM1uZEsAAAZwY"], referer: https://www.thdinfinity.com/
[Thu Jul 30 12:06:20.235987 2026] [security2:error] [pid 643253:tid 643499] [client 191.232.199.39:19587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/ds.php"] [unique_id "amuEjMjqbtjBYzqM1uZEwAAAAHM"]
[Thu Jul 30 12:06:20.280240 2026] [security2:error] [pid 643253:tid 643426] [client 2a03:2880:f800:43:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEi8jqbtjBYzqM1uZErgAAKn0"]
[Thu Jul 30 12:06:20.616502 2026] [security2:error] [pid 643253:tid 643508] [client 20.91.139.111:48717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuEjMjqbtjBYzqM1uZEygAAAHw"]
[Thu Jul 30 12:06:20.616591 2026] [security2:error] [pid 643253:tid 643508] [client 20.91.139.111:48717] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuEjMjqbtjBYzqM1uZEygAAAHw"]
[Thu Jul 30 12:06:20.738635 2026] [security2:error] [pid 643253:tid 643452] [client 74.7.244.8:57910] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "pkfprogroup.com"] [uri "/cgi-sys/404.html"] [unique_id "amuEjMjqbtjBYzqM1uZEzwAARCc"]
[Thu Jul 30 12:06:20.860101 2026] [security2:error] [pid 643253:tid 643481] [client 57.141.0.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuEjMjqbtjBYzqM1uZEwwAAAGE"]
[Thu Jul 30 12:06:21.130020 2026] [security2:error] [pid 643253:tid 643470] [client 74.7.175.155:44616] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.alseermarine.com"] [uri "/index.php"] [unique_id "amuEjMjqbtjBYzqM1uZEzgAAVnQ"]
[Thu Jul 30 12:06:21.130072 2026] [security2:error] [pid 643253:tid 643470] [client 74.7.175.155:44616] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.alseermarine.com"] [uri "/index.php"] [unique_id "amuEjMjqbtjBYzqM1uZEzgAAVnQ"]
[Thu Jul 30 12:06:21.455968 2026] [core:notice] [pid 643253:tid 643505] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:21.460067 2026] [security2:error] [pid 643253:tid 643505] [client 103.215.74.26:56752] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEjcjqbtjBYzqM1uZE2wAAAHk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:21.935286 2026] [security2:error] [pid 643253:tid 643510] [client 250.49.135.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuEjcjqbtjBYzqM1uZE0wAAfiY"]
[Thu Jul 30 12:06:22.098271 2026] [security2:error] [pid 643253:tid 643433] [client 74.7.175.155:44632] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEjcjqbtjBYzqM1uZE5AAAMSM"], referer: https://www.alseermarine.com/robots.txt
[Thu Jul 30 12:06:22.205443 2026] [core:notice] [pid 643253:tid 643392] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:22.212206 2026] [security2:error] [pid 643253:tid 643392] [client 103.215.74.26:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "761"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEjsjqbtjBYzqM1uZE6wAAAAg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:22.941773 2026] [core:notice] [pid 643253:tid 643402] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:22.946239 2026] [security2:error] [pid 643253:tid 643402] [client 103.215.74.26:56774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEjsjqbtjBYzqM1uZE-wAAABI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:23.439053 2026] [security2:error] [pid 643253:tid 643415] [client 81.0.42.156:36646] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEj8jqbtjBYzqM1uZE_AAAAB8"], referer: http://pkf.jo
[Thu Jul 30 12:06:23.441817 2026] [security2:error] [pid 643253:tid 643461] [client 139.28.219.70:34584] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "saifalkhaleejest.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuEj8jqbtjBYzqM1uZFCQAAAE0"]
[Thu Jul 30 12:06:23.670537 2026] [core:notice] [pid 643253:tid 643384] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:23.674561 2026] [security2:error] [pid 643253:tid 643384] [client 103.215.74.26:46488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEj8jqbtjBYzqM1uZFCgAAAAA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:23.760328 2026] [security2:error] [pid 643253:tid 643458] [client 20.91.139.111:36691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuEj8jqbtjBYzqM1uZFEgAAAEo"]
[Thu Jul 30 12:06:23.760439 2026] [security2:error] [pid 643253:tid 643458] [client 20.91.139.111:36691] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuEj8jqbtjBYzqM1uZFEgAAAEo"]
[Thu Jul 30 12:06:24.403029 2026] [core:notice] [pid 643253:tid 643490] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:24.406964 2026] [security2:error] [pid 643253:tid 643490] [client 103.215.74.26:46490] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEkMjqbtjBYzqM1uZFIwAAAGo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:24.455999 2026] [security2:error] [pid 643253:tid 643505] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEj8jqbtjBYzqM1uZFFgAAeTc"]
[Thu Jul 30 12:06:25.150714 2026] [core:notice] [pid 643253:tid 643434] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:25.155250 2026] [security2:error] [pid 643253:tid 643434] [client 103.215.74.26:46492] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEkcjqbtjBYzqM1uZFLgAAADI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:25.877091 2026] [core:notice] [pid 643253:tid 643489] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:25.881146 2026] [security2:error] [pid 643253:tid 643489] [client 103.215.74.26:46494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEkcjqbtjBYzqM1uZFPgAAAGk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:26.050465 2026] [security2:error] [pid 643253:tid 643448] [client 20.91.139.111:59421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/xstelth.php"] [unique_id "amuEksjqbtjBYzqM1uZFPwAAAEA"]
[Thu Jul 30 12:06:26.050615 2026] [security2:error] [pid 643253:tid 643448] [client 20.91.139.111:59421] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/xstelth.php"] [unique_id "amuEksjqbtjBYzqM1uZFPwAAAEA"]
[Thu Jul 30 12:06:26.391514 2026] [security2:error] [pid 643253:tid 643419] [client 14.184.103.235:34227] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEksjqbtjBYzqM1uZFQAAAACM"], referer: http://pkf.jo
[Thu Jul 30 12:06:26.633780 2026] [core:notice] [pid 643253:tid 643473] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:26.638184 2026] [security2:error] [pid 643253:tid 643473] [client 103.215.74.26:46498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEksjqbtjBYzqM1uZFSQAAAFk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:26.725171 2026] [security2:error] [pid 643253:tid 643385] [client 191.232.199.39:41216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/f5.php"] [unique_id "amuEksjqbtjBYzqM1uZFSgAAAAE"]
[Thu Jul 30 12:06:27.145508 2026] [security2:error] [pid 643253:tid 643490] [client 139.28.219.70:34592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/xmlrpc.php"] [unique_id "amuEk8jqbtjBYzqM1uZFUQAAAGo"]
[Thu Jul 30 12:06:27.145632 2026] [security2:error] [pid 643253:tid 643490] [client 139.28.219.70:34592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "saifalkhaleejest.com"] [uri "/xmlrpc.php"] [unique_id "amuEk8jqbtjBYzqM1uZFUQAAAGo"]
[Thu Jul 30 12:06:27.470731 2026] [core:notice] [pid 643253:tid 643505] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:27.475153 2026] [security2:error] [pid 643253:tid 643505] [client 103.215.74.26:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEk8jqbtjBYzqM1uZFVwAAAHk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:27.567426 2026] [security2:error] [pid 643253:tid 643495] [client 20.91.139.111:50534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/584062352875874akp.php"] [unique_id "amuEk8jqbtjBYzqM1uZFWQAAAG8"]
[Thu Jul 30 12:06:27.567531 2026] [security2:error] [pid 643253:tid 643495] [client 20.91.139.111:50534] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/584062352875874akp.php"] [unique_id "amuEk8jqbtjBYzqM1uZFWQAAAG8"]
[Thu Jul 30 12:06:27.820950 2026] [security2:error] [pid 643253:tid 643435] [client 139.28.219.70:34608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/xmlrpc.php"] [unique_id "amuEk8jqbtjBYzqM1uZFWwAAADM"]
[Thu Jul 30 12:06:27.821092 2026] [security2:error] [pid 643253:tid 643435] [client 139.28.219.70:34608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "saifalkhaleejest.com"] [uri "/xmlrpc.php"] [unique_id "amuEk8jqbtjBYzqM1uZFWwAAADM"]
[Thu Jul 30 12:06:28.226679 2026] [core:notice] [pid 643253:tid 643442] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:28.231167 2026] [security2:error] [pid 643253:tid 643442] [client 103.215.74.26:46526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuElMjqbtjBYzqM1uZFZwAAADo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:28.242969 2026] [security2:error] [pid 643253:tid 643465] [client 87.11.104.83:35698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEk8jqbtjBYzqM1uZFXQAAAFE"], referer: http://pkf.jo
[Thu Jul 30 12:06:28.937117 2026] [security2:error] [pid 643253:tid 643448] [client 20.91.139.111:59447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/newfile.php"] [unique_id "amuElMjqbtjBYzqM1uZFdwAAAEA"]
[Thu Jul 30 12:06:28.937261 2026] [security2:error] [pid 643253:tid 643448] [client 20.91.139.111:59447] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/newfile.php"] [unique_id "amuElMjqbtjBYzqM1uZFdwAAAEA"]
[Thu Jul 30 12:06:29.004765 2026] [core:notice] [pid 643253:tid 643443] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:29.009051 2026] [security2:error] [pid 643253:tid 643443] [client 103.215.74.26:46538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuElcjqbtjBYzqM1uZFfgAAADs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:29.034844 2026] [security2:error] [pid 643253:tid 643444] [client 57.141.0.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuElMjqbtjBYzqM1uZFawAAADw"]
[Thu Jul 30 12:06:29.739905 2026] [core:notice] [pid 643253:tid 643501] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:29.744378 2026] [security2:error] [pid 643253:tid 643501] [client 103.215.74.26:46548] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuElcjqbtjBYzqM1uZFiQAAAHU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:30.037379 2026] [security2:error] [pid 643253:tid 643467] [client 20.91.139.111:50611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/tBEZGQz.php"] [unique_id "amuElsjqbtjBYzqM1uZFigAAAFM"]
[Thu Jul 30 12:06:30.037508 2026] [security2:error] [pid 643253:tid 643467] [client 20.91.139.111:50611] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/tBEZGQz.php"] [unique_id "amuElsjqbtjBYzqM1uZFigAAAFM"]
[Thu Jul 30 12:06:30.231529 2026] [security2:error] [pid 643253:tid 643479] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuElcjqbtjBYzqM1uZFiAAAXzY"]
[Thu Jul 30 12:06:30.470932 2026] [core:notice] [pid 643253:tid 643401] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:30.475458 2026] [security2:error] [pid 643253:tid 643401] [client 103.215.74.26:46550] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuElsjqbtjBYzqM1uZFkgAAABE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:31.027863 2026] [security2:error] [pid 643253:tid 643435] [client 20.91.139.111:54585] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.nordeste1.com"] [uri "/___proxy_subdomain_webmail/phpinfo"] [unique_id "amuElsjqbtjBYzqM1uZFmwAAADM"]
[Thu Jul 30 12:06:31.206820 2026] [core:notice] [pid 643253:tid 643423] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:31.211206 2026] [security2:error] [pid 643253:tid 643423] [client 103.215.74.26:46566] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEl8jqbtjBYzqM1uZFowAAACc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:31.595208 2026] [security2:error] [pid 643253:tid 643445] [client 20.91.139.111:54585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/drykl.php"] [unique_id "amuEl8jqbtjBYzqM1uZFpAAAAD0"]
[Thu Jul 30 12:06:31.595364 2026] [security2:error] [pid 643253:tid 643445] [client 20.91.139.111:54585] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/drykl.php"] [unique_id "amuEl8jqbtjBYzqM1uZFpAAAAD0"]
[Thu Jul 30 12:06:31.929424 2026] [core:notice] [pid 643253:tid 643499] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:31.933435 2026] [security2:error] [pid 643253:tid 643499] [client 103.215.74.26:46582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEl8jqbtjBYzqM1uZFrAAAAHM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:32.058412 2026] [core:notice] [pid 643253:tid 643422] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:32.623575 2026] [security2:error] [pid 643253:tid 643403] [client 2a03:2880:f800:7:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEmMjqbtjBYzqM1uZFrQAAE2c"]
[Thu Jul 30 12:06:32.654128 2026] [core:notice] [pid 643253:tid 643475] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:32.655722 2026] [security2:error] [pid 643253:tid 643509] [client 20.91.139.111:27970] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.nordeste1.com"] [uri "/___proxy_subdomain_webmail/wp-admin/css/colors/blue/"] [unique_id "amuEmMjqbtjBYzqM1uZFtQAAAH0"]
[Thu Jul 30 12:06:32.658110 2026] [security2:error] [pid 643253:tid 643475] [client 103.215.74.26:46596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "752"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEmMjqbtjBYzqM1uZFtgAAAFs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:32.973327 2026] [security2:error] [pid 643253:tid 643471] [client 20.91.139.111:27970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/ls.php"] [unique_id "amuEmMjqbtjBYzqM1uZFvgAAAFc"]
[Thu Jul 30 12:06:32.973451 2026] [security2:error] [pid 643253:tid 643471] [client 20.91.139.111:27970] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/ls.php"] [unique_id "amuEmMjqbtjBYzqM1uZFvgAAAFc"]
[Thu Jul 30 12:06:33.411834 2026] [core:notice] [pid 643253:tid 643480] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:33.419141 2026] [security2:error] [pid 643253:tid 643480] [client 103.215.74.26:60758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEmcjqbtjBYzqM1uZFxQAAAGA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:34.139771 2026] [core:notice] [pid 643253:tid 643467] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:34.144112 2026] [security2:error] [pid 643253:tid 643467] [client 103.215.74.26:60766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEmsjqbtjBYzqM1uZFzwAAAFM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:34.283374 2026] [security2:error] [pid 643253:tid 643439] [client 20.91.139.111:53449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/dx.php"] [unique_id "amuEmsjqbtjBYzqM1uZF0wAAADc"]
[Thu Jul 30 12:06:34.283516 2026] [security2:error] [pid 643253:tid 643439] [client 20.91.139.111:53449] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/dx.php"] [unique_id "amuEmsjqbtjBYzqM1uZF0wAAADc"]
[Thu Jul 30 12:06:34.558092 2026] [core:notice] [pid 643253:tid 643389] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:34.874881 2026] [core:notice] [pid 643253:tid 643497] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:34.881410 2026] [security2:error] [pid 643253:tid 643497] [client 103.215.74.26:60772] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEmsjqbtjBYzqM1uZF3wAAAHE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:35.235212 2026] [security2:error] [pid 643253:tid 643495] [client 57.141.18.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sagalandfilms.com"] [uri "/index.php"] [unique_id "amuEm8jqbtjBYzqM1uZF4AAAb20"]
[Thu Jul 30 12:06:35.600205 2026] [core:notice] [pid 643253:tid 643398] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:35.607333 2026] [security2:error] [pid 643253:tid 643398] [client 103.215.74.26:60784] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEm8jqbtjBYzqM1uZF5wAAAA4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:35.754530 2026] [core:error] [pid 643253:tid 643373] [remote 74.7.241.185:40788] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:06:35.754551 2026] [core:error] [pid 643253:tid 643373] [remote 74.7.241.185:40788] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:06:35.754716 2026] [security2:error] [pid 643253:tid 643466] [client 74.7.241.185:40788] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.website-8a52acf5.ubp.hmu.temporary.site"] [uri "/index.php"] [unique_id "amuEm8jqbtjBYzqM1uZF6AAAUnY"]
[Thu Jul 30 12:06:35.760889 2026] [security2:error] [pid 643253:tid 643396] [client 20.91.139.111:50618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/mac.php"] [unique_id "amuEm8jqbtjBYzqM1uZF6QAAAAw"]
[Thu Jul 30 12:06:35.760965 2026] [security2:error] [pid 643253:tid 643396] [client 20.91.139.111:50618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/mac.php"] [unique_id "amuEm8jqbtjBYzqM1uZF6QAAAAw"]
[Thu Jul 30 12:06:35.797198 2026] [core:notice] [pid 643253:tid 643459] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:35.852561 2026] [security2:error] [pid 643253:tid 643386] [client 172.232.108.36:5416] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.217"] [uri "/"] [unique_id "amuEm8jqbtjBYzqM1uZF7gAAAAI"]
[Thu Jul 30 12:06:36.333371 2026] [core:notice] [pid 643253:tid 643412] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:36.337340 2026] [security2:error] [pid 643253:tid 643412] [client 103.215.74.26:60786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEnMjqbtjBYzqM1uZF-QAAABw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:36.474840 2026] [core:notice] [pid 643253:tid 643442] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:36.602639 2026] [security2:error] [pid 643253:tid 643486] [client 20.91.139.111:3888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/485.php"] [unique_id "amuEnMjqbtjBYzqM1uZGBQAAAGY"]
[Thu Jul 30 12:06:36.602744 2026] [security2:error] [pid 643253:tid 643486] [client 20.91.139.111:3888] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/485.php"] [unique_id "amuEnMjqbtjBYzqM1uZGBQAAAGY"]
[Thu Jul 30 12:06:36.833380 2026] [security2:error] [pid 643253:tid 643482] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEnMjqbtjBYzqM1uZF9wAAYn4"]
[Thu Jul 30 12:06:37.078453 2026] [core:notice] [pid 643253:tid 643500] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:37.082248 2026] [security2:error] [pid 643253:tid 643500] [client 103.215.74.26:60800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "768"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEncjqbtjBYzqM1uZGDQAAAHQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:37.094596 2026] [core:notice] [pid 643253:tid 643467] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:37.323405 2026] [security2:error] [pid 643253:tid 643437] [client 20.91.139.111:53443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/gelio1.php"] [unique_id "amuEncjqbtjBYzqM1uZGEQAAADU"]
[Thu Jul 30 12:06:37.323527 2026] [security2:error] [pid 643253:tid 643437] [client 20.91.139.111:53443] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/gelio1.php"] [unique_id "amuEncjqbtjBYzqM1uZGEQAAADU"]
[Thu Jul 30 12:06:37.813225 2026] [core:notice] [pid 643253:tid 643493] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:37.819834 2026] [security2:error] [pid 643253:tid 643493] [client 103.215.74.26:60802] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEncjqbtjBYzqM1uZGGAAAAG0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:37.959327 2026] [security2:error] [pid 643253:tid 643424] [client 191.232.199.39:59777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/god4m.php"] [unique_id "amuEncjqbtjBYzqM1uZGHAAAACg"]
[Thu Jul 30 12:06:38.387024 2026] [security2:error] [pid 643253:tid 643441] [client 20.91.139.111:19603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/lp6.php"] [unique_id "amuEnsjqbtjBYzqM1uZGJAAAADk"]
[Thu Jul 30 12:06:38.387156 2026] [security2:error] [pid 643253:tid 643441] [client 20.91.139.111:19603] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/lp6.php"] [unique_id "amuEnsjqbtjBYzqM1uZGJAAAADk"]
[Thu Jul 30 12:06:38.548137 2026] [core:notice] [pid 643253:tid 643396] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:38.552283 2026] [security2:error] [pid 643253:tid 643396] [client 103.215.74.26:60818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "781"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEnsjqbtjBYzqM1uZGKAAAAAw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:38.615776 2026] [security2:error] [pid 643253:tid 643502] [client 57.141.0.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuEnsjqbtjBYzqM1uZGHwAAAHY"]
[Thu Jul 30 12:06:38.854035 2026] [security2:error] [pid 643253:tid 643476] [client 20.226.5.174:33870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/011i.php"] [unique_id "amuEnsjqbtjBYzqM1uZGLwAAAFw"]
[Thu Jul 30 12:06:39.272854 2026] [core:notice] [pid 643253:tid 643485] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:39.276882 2026] [security2:error] [pid 643253:tid 643485] [client 103.215.74.26:60824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEn8jqbtjBYzqM1uZGOQAAAGU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:39.383887 2026] [security2:error] [pid 643253:tid 643470] [client 191.232.199.39:19735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/info.php"] [unique_id "amuEn8jqbtjBYzqM1uZGOgAAAFY"]
[Thu Jul 30 12:06:39.603128 2026] [core:notice] [pid 643253:tid 643477] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:39.732522 2026] [security2:error] [pid 643253:tid 643475] [client 20.91.139.111:53448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuEn8jqbtjBYzqM1uZGSQAAAFs"]
[Thu Jul 30 12:06:39.732622 2026] [security2:error] [pid 643253:tid 643475] [client 20.91.139.111:53448] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuEn8jqbtjBYzqM1uZGSQAAAFs"]
[Thu Jul 30 12:06:39.882711 2026] [security2:error] [pid 643253:tid 643483] [client 20.226.5.174:34271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/03a005685d.php"] [unique_id "amuEn8jqbtjBYzqM1uZGTQAAAGM"]
[Thu Jul 30 12:06:41.011716 2026] [security2:error] [pid 643253:tid 643488] [client 20.91.139.111:36900] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.nordeste1.com"] [uri "/___proxy_subdomain_webmail/wp-includes/sodium_compat/"] [unique_id "amuEoMjqbtjBYzqM1uZGXwAAAGg"]
[Thu Jul 30 12:06:41.315696 2026] [security2:error] [pid 643253:tid 643435] [client 20.91.139.111:36900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/w3llscc.php"] [unique_id "amuEocjqbtjBYzqM1uZGZgAAADM"]
[Thu Jul 30 12:06:41.315854 2026] [security2:error] [pid 643253:tid 643435] [client 20.91.139.111:36900] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/w3llscc.php"] [unique_id "amuEocjqbtjBYzqM1uZGZgAAADM"]
[Thu Jul 30 12:06:41.687545 2026] [security2:error] [pid 643253:tid 643447] [client 20.226.5.174:33874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/403.php"] [unique_id "amuEocjqbtjBYzqM1uZGcQAAAD8"]
[Thu Jul 30 12:06:41.855561 2026] [security2:error] [pid 643253:tid 643507] [client 20.91.139.111:19638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/miru3.php"] [unique_id "amuEocjqbtjBYzqM1uZGdwAAAHs"]
[Thu Jul 30 12:06:41.855684 2026] [security2:error] [pid 643253:tid 643507] [client 20.91.139.111:19638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/miru3.php"] [unique_id "amuEocjqbtjBYzqM1uZGdwAAAHs"]
[Thu Jul 30 12:06:42.366152 2026] [security2:error] [pid 643253:tid 643391] [client 47.157.71.177:59736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEosjqbtjBYzqM1uZGeQAAAAc"], referer: http://pkf.jo
[Thu Jul 30 12:06:42.855350 2026] [security2:error] [pid 643253:tid 643488] [client 20.91.139.111:27998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/autoload_classmap.php"] [unique_id "amuEosjqbtjBYzqM1uZGjgAAAGg"]
[Thu Jul 30 12:06:42.855458 2026] [security2:error] [pid 643253:tid 643488] [client 20.91.139.111:27998] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/autoload_classmap.php"] [unique_id "amuEosjqbtjBYzqM1uZGjgAAAGg"]
[Thu Jul 30 12:06:43.131714 2026] [security2:error] [pid 643253:tid 643424] [client 20.226.5.174:34300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/404.php"] [unique_id "amuEo8jqbtjBYzqM1uZGkAAAACg"]
[Thu Jul 30 12:06:43.498521 2026] [security2:error] [pid 643253:tid 643466] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEosjqbtjBYzqM1uZGjwAAUjM"]
[Thu Jul 30 12:06:43.665328 2026] [security2:error] [pid 643253:tid 643469] [client 20.91.139.111:39470] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.nordeste1.com"] [uri "/___proxy_subdomain_webmail/wp-content/"] [unique_id "amuEo8jqbtjBYzqM1uZGpAAAAFU"]
[Thu Jul 30 12:06:44.113273 2026] [security2:error] [pid 643253:tid 643439] [client 20.91.139.111:39470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuEpMjqbtjBYzqM1uZGsAAAADc"]
[Thu Jul 30 12:06:44.113467 2026] [security2:error] [pid 643253:tid 643439] [client 20.91.139.111:39470] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuEpMjqbtjBYzqM1uZGsAAAADc"]
[Thu Jul 30 12:06:44.163777 2026] [security2:error] [pid 643253:tid 643498] [client 179.43.134.114:15912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.134.43.179.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-login.php"] [unique_id "amuEpMjqbtjBYzqM1uZGsgAAAHI"]
[Thu Jul 30 12:06:44.424845 2026] [security2:error] [pid 643253:tid 643491] [client 105.245.181.151:37853] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEpMjqbtjBYzqM1uZGsQAAAGs"], referer: http://pkf.jo
[Thu Jul 30 12:06:44.465833 2026] [core:notice] [pid 643253:tid 643429] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:44.574784 2026] [security2:error] [pid 643253:tid 643500] [client 20.226.5.174:34297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/aa.php"] [unique_id "amuEpMjqbtjBYzqM1uZGyAAAAHQ"]
[Thu Jul 30 12:06:44.990448 2026] [core:notice] [pid 643253:tid 643450] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:44.994469 2026] [security2:error] [pid 643253:tid 643450] [client 103.215.74.26:37738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEpMjqbtjBYzqM1uZG0gAAAEI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:45.008387 2026] [security2:error] [pid 643253:tid 643487] [client 213.152.187.215:47688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.187.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuEpMjqbtjBYzqM1uZGywAAAGc"]
[Thu Jul 30 12:06:45.008498 2026] [security2:error] [pid 643253:tid 643487] [client 213.152.187.215:47688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuEpMjqbtjBYzqM1uZGywAAAGc"]
[Thu Jul 30 12:06:45.164055 2026] [security2:error] [pid 643253:tid 643490] [client 57.141.0.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuEpMjqbtjBYzqM1uZGxwAAAGo"]
[Thu Jul 30 12:06:45.467646 2026] [core:error] [pid 643253:tid 643384] [client 179.43.134.114:29250] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:06:45.467668 2026] [core:error] [pid 643253:tid 643384] [client 179.43.134.114:29250] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:06:45.719040 2026] [core:notice] [pid 643253:tid 643471] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:45.723305 2026] [security2:error] [pid 643253:tid 643471] [client 103.215.74.26:37754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEpcjqbtjBYzqM1uZG4AAAAFc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:46.241706 2026] [security2:error] [pid 643253:tid 643492] [client 20.226.5.174:34265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/aafewc0k.php"] [unique_id "amuEpsjqbtjBYzqM1uZG6AAAAGw"]
[Thu Jul 30 12:06:46.450625 2026] [core:notice] [pid 643253:tid 643501] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:46.455027 2026] [security2:error] [pid 643253:tid 643501] [client 103.215.74.26:37760] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEpsjqbtjBYzqM1uZG6gAAAHU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:46.661421 2026] [security2:error] [pid 643253:tid 643505] [client 20.91.139.111:26207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/av.php"] [unique_id "amuEpsjqbtjBYzqM1uZG9AAAAHk"]
[Thu Jul 30 12:06:46.661535 2026] [security2:error] [pid 643253:tid 643505] [client 20.91.139.111:26207] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/av.php"] [unique_id "amuEpsjqbtjBYzqM1uZG9AAAAHk"]
[Thu Jul 30 12:06:46.850659 2026] [security2:error] [pid 643253:tid 643455] [client 191.232.199.39:41220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/.__info.php"] [unique_id "amuEpsjqbtjBYzqM1uZG9wAAAEc"]
[Thu Jul 30 12:06:46.949599 2026] [security2:error] [pid 643253:tid 643477] [client 66.249.64.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuEpsjqbtjBYzqM1uZG8gAAXUw"]
[Thu Jul 30 12:06:47.174319 2026] [core:notice] [pid 643253:tid 643423] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:47.178473 2026] [security2:error] [pid 643253:tid 643423] [client 103.215.74.26:37762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEp8jqbtjBYzqM1uZHAAAAACc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:47.445808 2026] [security2:error] [pid 643253:tid 643493] [client 20.226.5.174:34279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/abcd.php"] [unique_id "amuEp8jqbtjBYzqM1uZHAgAAAG0"]
[Thu Jul 30 12:06:47.901583 2026] [core:notice] [pid 643253:tid 643499] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:47.905591 2026] [security2:error] [pid 643253:tid 643499] [client 103.215.74.26:37770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEp8jqbtjBYzqM1uZHCgAAAHM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:48.353818 2026] [security2:error] [pid 643253:tid 643394] [client 20.91.139.111:42794] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.nordeste1.com"] [uri "/___proxy_subdomain_webmail/wp-includes/l10n/"] [unique_id "amuEqMjqbtjBYzqM1uZHEQAAAAo"]
[Thu Jul 30 12:06:48.624600 2026] [core:notice] [pid 643253:tid 643430] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:48.629186 2026] [security2:error] [pid 643253:tid 643430] [client 103.215.74.26:37784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEqMjqbtjBYzqM1uZHGAAAAC4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:48.692752 2026] [security2:error] [pid 643253:tid 643470] [client 20.91.139.111:42794] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.nordeste1.com"] [uri "/___proxy_subdomain_webmail/wordpress/wp-admin/maint/"] [unique_id "amuEqMjqbtjBYzqM1uZHGwAAAFY"]
[Thu Jul 30 12:06:48.845972 2026] [security2:error] [pid 643253:tid 643463] [client 20.91.139.111:42794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/tiny.php"] [unique_id "amuEqMjqbtjBYzqM1uZHHgAAAE8"]
[Thu Jul 30 12:06:48.846132 2026] [security2:error] [pid 643253:tid 643463] [client 20.91.139.111:42794] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/tiny.php"] [unique_id "amuEqMjqbtjBYzqM1uZHHgAAAE8"]
[Thu Jul 30 12:06:49.347745 2026] [core:notice] [pid 643253:tid 643421] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:49.352063 2026] [security2:error] [pid 643253:tid 643421] [client 103.215.74.26:37786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEqcjqbtjBYzqM1uZHKgAAACU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:49.443007 2026] [security2:error] [pid 643253:tid 643509] [client 191.232.199.39:20328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/0.php"] [unique_id "amuEqcjqbtjBYzqM1uZHKwAAAH0"]
[Thu Jul 30 12:06:49.711888 2026] [security2:error] [pid 643253:tid 643501] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEqcjqbtjBYzqM1uZHKAAAdQM"]
[Thu Jul 30 12:06:49.762006 2026] [security2:error] [pid 643253:tid 643444] [client 20.226.5.174:34249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/about.php"] [unique_id "amuEqcjqbtjBYzqM1uZHMwAAADw"]
[Thu Jul 30 12:06:50.094646 2026] [security2:error] [pid 643253:tid 643511] [client 20.91.139.111:22433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuEqsjqbtjBYzqM1uZHOAAAAH8"]
[Thu Jul 30 12:06:50.094749 2026] [security2:error] [pid 643253:tid 643511] [client 20.91.139.111:22433] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuEqsjqbtjBYzqM1uZHOAAAAH8"]
[Thu Jul 30 12:06:50.105923 2026] [core:notice] [pid 643253:tid 643500] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:50.110257 2026] [security2:error] [pid 643253:tid 643500] [client 103.215.74.26:37792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEqsjqbtjBYzqM1uZHOQAAAHQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:50.783475 2026] [security2:error] [pid 643253:tid 643404] [client 191.232.199.39:19712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/07.php"] [unique_id "amuEqsjqbtjBYzqM1uZHRgAAABQ"]
[Thu Jul 30 12:06:50.783560 2026] [security2:error] [pid 643253:tid 643438] [client 20.226.5.174:33864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/admin.php"] [unique_id "amuEqsjqbtjBYzqM1uZHRwAAADY"]
[Thu Jul 30 12:06:50.881971 2026] [core:notice] [pid 643253:tid 643508] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:50.886379 2026] [security2:error] [pid 643253:tid 643508] [client 103.215.74.26:37806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEqsjqbtjBYzqM1uZHSwAAAHw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:50.965683 2026] [security2:error] [pid 643253:tid 643415] [client 57.141.0.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuEqsjqbtjBYzqM1uZHQgAAAB8"]
[Thu Jul 30 12:06:51.258688 2026] [security2:error] [pid 643253:tid 643485] [client 20.91.139.111:39472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/zrrhj.php"] [unique_id "amuEq8jqbtjBYzqM1uZHXAAAAGU"]
[Thu Jul 30 12:06:51.258826 2026] [security2:error] [pid 643253:tid 643485] [client 20.91.139.111:39472] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/zrrhj.php"] [unique_id "amuEq8jqbtjBYzqM1uZHXAAAAGU"]
[Thu Jul 30 12:06:51.536848 2026] [security2:error] [pid 643253:tid 643445] [client 207.58.142.67:45457] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "jcsgoeastwood.org"] [uri "/index.php"] [unique_id "amuEq8jqbtjBYzqM1uZHYQAAAD0"]
[Thu Jul 30 12:06:51.626747 2026] [security2:error] [pid 643253:tid 643504] [client 172.237.109.114:36180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEqsjqbtjBYzqM1uZHTwAAAHg"]
[Thu Jul 30 12:06:51.645826 2026] [security2:error] [pid 643253:tid 643433] [client 172.237.109.114:55802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEqsjqbtjBYzqM1uZHUQAAADE"]
[Thu Jul 30 12:06:51.649383 2026] [security2:error] [pid 643253:tid 643435] [client 172.237.109.114:22295] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEqsjqbtjBYzqM1uZHTgAAADM"]
[Thu Jul 30 12:06:51.653306 2026] [security2:error] [pid 643253:tid 643442] [client 172.237.109.114:51477] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEq8jqbtjBYzqM1uZHVAAAADo"]
[Thu Jul 30 12:06:51.653352 2026] [security2:error] [pid 643253:tid 643427] [client 172.237.109.114:64796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEqsjqbtjBYzqM1uZHTAAAACs"]
[Thu Jul 30 12:06:51.655412 2026] [security2:error] [pid 643253:tid 643476] [client 172.237.109.114:38830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEqsjqbtjBYzqM1uZHTQAAAFw"]
[Thu Jul 30 12:06:51.665786 2026] [security2:error] [pid 643253:tid 643413] [client 172.237.109.114:14350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEqsjqbtjBYzqM1uZHUAAAAB0"]
[Thu Jul 30 12:06:51.678851 2026] [security2:error] [pid 643253:tid 643446] [client 172.237.109.114:35226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEq8jqbtjBYzqM1uZHVQAAAD4"]
[Thu Jul 30 12:06:51.681401 2026] [security2:error] [pid 643253:tid 643406] [client 172.237.109.114:48409] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEqsjqbtjBYzqM1uZHUgAAABY"]
[Thu Jul 30 12:06:51.696380 2026] [security2:error] [pid 643253:tid 643425] [client 172.237.109.114:8782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEq8jqbtjBYzqM1uZHUwAAACk"]
[Thu Jul 30 12:06:51.886595 2026] [security2:error] [pid 643253:tid 643505] [client 20.91.139.111:32637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuEq8jqbtjBYzqM1uZHbwAAAHk"]
[Thu Jul 30 12:06:51.886739 2026] [security2:error] [pid 643253:tid 643505] [client 20.91.139.111:32637] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuEq8jqbtjBYzqM1uZHbwAAAHk"]
[Thu Jul 30 12:06:52.105869 2026] [core:notice] [pid 643253:tid 643388] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:52.438880 2026] [security2:error] [pid 643253:tid 643444] [client 191.232.199.39:20348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/dropdown.php"] [unique_id "amuErMjqbtjBYzqM1uZHhwAAADw"]
[Thu Jul 30 12:06:52.519098 2026] [security2:error] [pid 643253:tid 643438] [client 20.91.139.111:64173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/wpgum.php"] [unique_id "amuErMjqbtjBYzqM1uZHiQAAADY"]
[Thu Jul 30 12:06:52.519261 2026] [security2:error] [pid 643253:tid 643438] [client 20.91.139.111:64173] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/wpgum.php"] [unique_id "amuErMjqbtjBYzqM1uZHiQAAADY"]
[Thu Jul 30 12:06:52.567766 2026] [security2:error] [pid 643253:tid 643461] [client 74.7.244.34:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.shop-kent.com"] [uri "/index.php"] [unique_id "amuEq8jqbtjBYzqM1uZHZwAAAE0"]
[Thu Jul 30 12:06:52.567816 2026] [security2:error] [pid 643253:tid 643461] [client 74.7.244.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.shop-kent.com"] [uri "/index.php"] [unique_id "amuEq8jqbtjBYzqM1uZHZwAAAE0"]
[Thu Jul 30 12:06:52.568868 2026] [security2:error] [pid 643253:tid 643468] [client 74.7.244.34:36162] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.shop-kent.com"] [uri "/robots.txt"] [unique_id "amuEq8jqbtjBYzqM1uZHYwAAVBY"]
[Thu Jul 30 12:06:52.671120 2026] [security2:error] [pid 643253:tid 643494] [client 172.237.109.114:10093] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEq8jqbtjBYzqM1uZHcwAAAG4"]
[Thu Jul 30 12:06:52.679896 2026] [security2:error] [pid 643253:tid 643464] [client 172.237.109.114:15025] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEq8jqbtjBYzqM1uZHcAAAAFA"]
[Thu Jul 30 12:06:52.687739 2026] [security2:error] [pid 643253:tid 643389] [client 172.237.109.114:7466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEq8jqbtjBYzqM1uZHdgAAAAU"]
[Thu Jul 30 12:06:52.688154 2026] [security2:error] [pid 643253:tid 643405] [client 172.237.109.114:48188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEq8jqbtjBYzqM1uZHcQAAABU"]
[Thu Jul 30 12:06:52.691213 2026] [security2:error] [pid 643253:tid 643434] [client 172.237.109.114:29748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEq8jqbtjBYzqM1uZHdAAAADI"]
[Thu Jul 30 12:06:52.691213 2026] [security2:error] [pid 643253:tid 643402] [client 172.237.109.114:25388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuErMjqbtjBYzqM1uZHeAAAABI"]
[Thu Jul 30 12:06:52.692840 2026] [security2:error] [pid 643253:tid 643391] [client 172.237.109.114:38145] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEq8jqbtjBYzqM1uZHcgAAAAc"]
[Thu Jul 30 12:06:52.711524 2026] [security2:error] [pid 643253:tid 643398] [client 172.237.109.114:42142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuErMjqbtjBYzqM1uZHeQAAAA4"]
[Thu Jul 30 12:06:52.715416 2026] [security2:error] [pid 643253:tid 643397] [client 172.237.109.114:49582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEq8jqbtjBYzqM1uZHdQAAAA0"]
[Thu Jul 30 12:06:52.719556 2026] [security2:error] [pid 643253:tid 643480] [client 172.237.109.114:33698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuErMjqbtjBYzqM1uZHdwAAAGA"]
[Thu Jul 30 12:06:52.768763 2026] [security2:error] [pid 643253:tid 643271] [remote 74.7.241.60:58360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/article.php"] [unique_id "amuErMjqbtjBYzqM1uZHkAAAJhA"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/main_image_6a3229a631e84.jpg
[Thu Jul 30 12:06:52.807873 2026] [security2:error] [pid 643253:tid 643428] [client 181.115.120.79:20944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuErMjqbtjBYzqM1uZHhgAAACw"], referer: http://pkf.jo
[Thu Jul 30 12:06:53.209803 2026] [security2:error] [pid 643253:tid 643506] [client 74.7.244.34:36166] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "shop-kent.com"] [uri "/robots.txt"] [unique_id "amuErcjqbtjBYzqM1uZHmAAAeiI"], referer: https://www.shop-kent.com/robots.txt
[Thu Jul 30 12:06:53.401386 2026] [security2:error] [pid 643253:tid 643408] [client 20.91.139.111:7617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/ywwbf.php"] [unique_id "amuErcjqbtjBYzqM1uZHoAAAABg"]
[Thu Jul 30 12:06:53.401476 2026] [security2:error] [pid 643253:tid 643408] [client 20.91.139.111:7617] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/ywwbf.php"] [unique_id "amuErcjqbtjBYzqM1uZHoAAAABg"]
[Thu Jul 30 12:06:53.647435 2026] [security2:error] [pid 643253:tid 643446] [client 20.226.5.174:34257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/adminfuns.php"] [unique_id "amuErcjqbtjBYzqM1uZHpAAAAD4"]
[Thu Jul 30 12:06:53.724399 2026] [security2:error] [pid 643253:tid 643505] [client 143.198.88.13:54468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.88.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.yardex.ae"] [uri "/xmlrpc.php"] [unique_id "amuErcjqbtjBYzqM1uZHpQAAAHk"], referer: https://ycss.de//wp-login.php
[Thu Jul 30 12:06:54.008472 2026] [security2:error] [pid 643253:tid 643509] [client 191.232.199.39:59835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/makeasmtp.php"] [unique_id "amuErsjqbtjBYzqM1uZHrwAAAH0"]
[Thu Jul 30 12:06:54.216051 2026] [security2:error] [pid 643253:tid 643440] [client 20.91.139.111:32590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/xoldj.php"] [unique_id "amuErsjqbtjBYzqM1uZHtgAAADg"]
[Thu Jul 30 12:06:54.216149 2026] [security2:error] [pid 643253:tid 643440] [client 20.91.139.111:32590] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/xoldj.php"] [unique_id "amuErsjqbtjBYzqM1uZHtgAAADg"]
[Thu Jul 30 12:06:54.795754 2026] [security2:error] [pid 643253:tid 643396] [client 20.226.5.174:34259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/albin.php"] [unique_id "amuErsjqbtjBYzqM1uZHxAAAAAw"]
[Thu Jul 30 12:06:54.979903 2026] [security2:error] [pid 643253:tid 643410] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuErsjqbtjBYzqM1uZHwwAAGgc"]
[Thu Jul 30 12:06:55.326408 2026] [security2:error] [pid 643253:tid 643481] [client 20.91.139.111:12850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/f35.php"] [unique_id "amuEr8jqbtjBYzqM1uZHzQAAAGE"]
[Thu Jul 30 12:06:55.326511 2026] [security2:error] [pid 643253:tid 643481] [client 20.91.139.111:12850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/f35.php"] [unique_id "amuEr8jqbtjBYzqM1uZHzQAAAGE"]
[Thu Jul 30 12:06:55.649908 2026] [security2:error] [pid 643253:tid 643391] [client 47.128.20.58:54642] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "happyspree.app"] [uri "/robots.txt"] [unique_id "amuEr8jqbtjBYzqM1uZH1wAAAAc"]
[Thu Jul 30 12:06:55.723612 2026] [security2:error] [pid 643253:tid 643442] [client 185.189.112.11:40116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.112.189.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuEr8jqbtjBYzqM1uZH2AAAADo"]
[Thu Jul 30 12:06:55.723757 2026] [security2:error] [pid 643253:tid 643442] [client 185.189.112.11:40116] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuEr8jqbtjBYzqM1uZH2AAAADo"]
[Thu Jul 30 12:06:56.025337 2026] [security2:error] [pid 643253:tid 643504] [client 191.232.199.39:59837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-sigunq.php"] [unique_id "amuEsMjqbtjBYzqM1uZH3AAAAHg"]
[Thu Jul 30 12:06:56.289815 2026] [security2:error] [pid 643253:tid 643421] [client 74.7.230.38:35612] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.ad-company.net"] [uri "/index.php"] [unique_id "amuEsMjqbtjBYzqM1uZH4AAAJSc"]
[Thu Jul 30 12:06:56.297469 2026] [core:error] [pid 643253:tid 643483] [client 74.7.230.28:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:06:56.297487 2026] [core:error] [pid 643253:tid 643483] [client 74.7.230.28:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:06:56.297610 2026] [security2:error] [pid 643253:tid 643483] [client 74.7.230.28:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.fud.udi.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "amuEsMjqbtjBYzqM1uZH4wAAAGM"]
[Thu Jul 30 12:06:56.298333 2026] [security2:error] [pid 643253:tid 643435] [client 74.7.230.28:42054] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.fud.udi.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "amuEsMjqbtjBYzqM1uZH4QAAMxs"]
[Thu Jul 30 12:06:56.392361 2026] [security2:error] [pid 643253:tid 643492] [client 20.226.5.174:33866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/amfsqvgv.php"] [unique_id "amuEsMjqbtjBYzqM1uZH6AAAAGw"]
[Thu Jul 30 12:06:56.429617 2026] [security2:error] [pid 643253:tid 643484] [client 20.91.139.111:12862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/gk.php"] [unique_id "amuEsMjqbtjBYzqM1uZH6gAAAGQ"]
[Thu Jul 30 12:06:56.429718 2026] [security2:error] [pid 643253:tid 643484] [client 20.91.139.111:12862] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/gk.php"] [unique_id "amuEsMjqbtjBYzqM1uZH6gAAAGQ"]
[Thu Jul 30 12:06:56.677465 2026] [core:notice] [pid 643253:tid 643455] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:56.681800 2026] [security2:error] [pid 643253:tid 643455] [client 103.215.74.26:35136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEsMjqbtjBYzqM1uZH8gAAAEc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:56.955571 2026] [security2:error] [pid 643253:tid 643444] [client 47.128.121.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuEsMjqbtjBYzqM1uZH9QAAADw"]
[Thu Jul 30 12:06:57.118877 2026] [security2:error] [pid 643253:tid 643482] [client 20.91.139.111:22447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/584062352875874akp.php"] [unique_id "amuEscjqbtjBYzqM1uZH_QAAAGI"]
[Thu Jul 30 12:06:57.118993 2026] [security2:error] [pid 643253:tid 643482] [client 20.91.139.111:22447] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/584062352875874akp.php"] [unique_id "amuEscjqbtjBYzqM1uZH_QAAAGI"]
[Thu Jul 30 12:06:57.411896 2026] [core:notice] [pid 643253:tid 643407] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:57.416366 2026] [security2:error] [pid 643253:tid 643407] [client 103.215.74.26:35142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEscjqbtjBYzqM1uZIBAAAABc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:57.755270 2026] [security2:error] [pid 643253:tid 643428] [client 20.91.139.111:27970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/wper3.php"] [unique_id "amuEscjqbtjBYzqM1uZICwAAACw"]
[Thu Jul 30 12:06:57.755442 2026] [security2:error] [pid 643253:tid 643428] [client 20.91.139.111:27970] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/wper3.php"] [unique_id "amuEscjqbtjBYzqM1uZICwAAACw"]
[Thu Jul 30 12:06:58.078095 2026] [security2:error] [pid 643253:tid 643447] [client 66.249.70.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.widedaddy.com"] [uri "/index.php"] [unique_id "amuEr8jqbtjBYzqM1uZH1gAAAD8"]
[Thu Jul 30 12:06:58.155565 2026] [core:notice] [pid 643253:tid 643463] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:58.159832 2026] [security2:error] [pid 643253:tid 643463] [client 103.215.74.26:35156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEssjqbtjBYzqM1uZIFgAAAE8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:58.527016 2026] [security2:error] [pid 643253:tid 643412] [client 68.221.186.136:34984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/011i.php"] [unique_id "amuEssjqbtjBYzqM1uZIFwAAABw"]
[Thu Jul 30 12:06:58.722948 2026] [security2:error] [pid 643253:tid 643419] [client 20.226.5.174:34290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/ant.php"] [unique_id "amuEssjqbtjBYzqM1uZIHgAAACM"]
[Thu Jul 30 12:06:58.887732 2026] [core:notice] [pid 643253:tid 643414] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:58.892243 2026] [security2:error] [pid 643253:tid 643414] [client 103.215.74.26:35170] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEssjqbtjBYzqM1uZIIQAAAB4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:58.989329 2026] [security2:error] [pid 643253:tid 643457] [client 20.91.139.111:13210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/bthil.php"] [unique_id "amuEssjqbtjBYzqM1uZIJQAAAEk"]
[Thu Jul 30 12:06:58.989439 2026] [security2:error] [pid 643253:tid 643457] [client 20.91.139.111:13210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/bthil.php"] [unique_id "amuEssjqbtjBYzqM1uZIJQAAAEk"]
[Thu Jul 30 12:06:59.136240 2026] [core:notice] [pid 643253:tid 643392] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:59.566138 2026] [security2:error] [pid 643253:tid 643431] [client 191.232.199.39:59825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wso112233.php"] [unique_id "amuEs8jqbtjBYzqM1uZILQAAAC8"]
[Thu Jul 30 12:06:59.651836 2026] [core:notice] [pid 643253:tid 643490] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:59.656381 2026] [security2:error] [pid 643253:tid 643490] [client 103.215.74.26:35176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEs8jqbtjBYzqM1uZILwAAAGo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:59.915377 2026] [security2:error] [pid 643253:tid 643444] [client 68.221.186.136:39406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/03a005685d.php"] [unique_id "amuEs8jqbtjBYzqM1uZINgAAADw"]
[Thu Jul 30 12:07:00.048614 2026] [security2:error] [pid 643253:tid 643458] [client 20.91.139.111:32621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/wyzer1.php"] [unique_id "amuEtMjqbtjBYzqM1uZINwAAAEo"]
[Thu Jul 30 12:07:00.048724 2026] [security2:error] [pid 643253:tid 643458] [client 20.91.139.111:32621] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/wyzer1.php"] [unique_id "amuEtMjqbtjBYzqM1uZINwAAAEo"]
[Thu Jul 30 12:07:00.149027 2026] [security2:error] [pid 643253:tid 643441] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEs8jqbtjBYzqM1uZILgAAOTc"]
[Thu Jul 30 12:07:00.279394 2026] [security2:error] [pid 643253:tid 643495] [client 20.226.5.174:33858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/appreciators.php"] [unique_id "amuEtMjqbtjBYzqM1uZIOwAAAG8"]
[Thu Jul 30 12:07:00.373137 2026] [core:notice] [pid 643253:tid 643438] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:00.376881 2026] [security2:error] [pid 643253:tid 643438] [client 103.215.74.26:35186] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEtMjqbtjBYzqM1uZIPQAAADY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:01.097914 2026] [core:notice] [pid 643253:tid 643454] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:01.104304 2026] [security2:error] [pid 643253:tid 643454] [client 103.215.74.26:35192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEtcjqbtjBYzqM1uZIUAAAAEY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:01.176339 2026] [security2:error] [pid 643253:tid 643504] [client 20.91.139.111:52532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/mh.php"] [unique_id "amuEtcjqbtjBYzqM1uZIUgAAAHg"]
[Thu Jul 30 12:07:01.176432 2026] [security2:error] [pid 643253:tid 643504] [client 20.91.139.111:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/mh.php"] [unique_id "amuEtcjqbtjBYzqM1uZIUgAAAHg"]
[Thu Jul 30 12:07:01.547306 2026] [core:notice] [pid 643253:tid 643351] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:01.849557 2026] [core:notice] [pid 643253:tid 643409] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:01.856512 2026] [security2:error] [pid 643253:tid 643409] [client 103.215.74.26:35206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "741"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEtcjqbtjBYzqM1uZIYgAAABk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:01.930841 2026] [security2:error] [pid 643253:tid 643416] [client 68.221.186.136:25775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/403.php"] [unique_id "amuEtcjqbtjBYzqM1uZIZgAAACA"]
[Thu Jul 30 12:07:02.005986 2026] [security2:error] [pid 643253:tid 643437] [client 57.141.0.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuEtcjqbtjBYzqM1uZIWwAAADU"]
[Thu Jul 30 12:07:02.092059 2026] [security2:error] [pid 643253:tid 643433] [client 57.141.0.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "smoke-tfhk.com"] [uri "/index.php"] [unique_id "amuEtcjqbtjBYzqM1uZITwAAADE"], referer: https://smoke-tfhk.com/product/ark-royal-sweet-chocolate/?add-to-cart=2024
[Thu Jul 30 12:07:02.211106 2026] [security2:error] [pid 643253:tid 643480] [client 191.232.199.39:61071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/alfanew.php"] [unique_id "amuEtsjqbtjBYzqM1uZIaQAAAGA"]
[Thu Jul 30 12:07:02.256401 2026] [security2:error] [pid 643253:tid 643404] [client 20.91.139.111:59344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuEtsjqbtjBYzqM1uZIagAAABQ"]
[Thu Jul 30 12:07:02.256508 2026] [security2:error] [pid 643253:tid 643404] [client 20.91.139.111:59344] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuEtsjqbtjBYzqM1uZIagAAABQ"]
[Thu Jul 30 12:07:02.590175 2026] [core:notice] [pid 643253:tid 643479] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:02.594605 2026] [security2:error] [pid 643253:tid 643479] [client 103.215.74.26:35210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEtsjqbtjBYzqM1uZIcQAAAF8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:02.692860 2026] [core:notice] [pid 643253:tid 643440] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:02.770617 2026] [security2:error] [pid 643253:tid 643335] [remote 157.55.39.58:6630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.39.55.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/ja/login.php"] [unique_id "amuEtsjqbtjBYzqM1uZIcwAAEFA"]
[Thu Jul 30 12:07:02.779036 2026] [security2:error] [pid 643253:tid 643455] [client 20.226.5.174:33868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/archive.php"] [unique_id "amuEtsjqbtjBYzqM1uZIdAAAAEc"]
[Thu Jul 30 12:07:03.343407 2026] [core:notice] [pid 643253:tid 643395] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:03.349971 2026] [security2:error] [pid 643253:tid 643395] [client 103.215.74.26:39164] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEt8jqbtjBYzqM1uZIfwAAAAs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:04.061443 2026] [core:notice] [pid 643253:tid 643399] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:04.067816 2026] [security2:error] [pid 643253:tid 643399] [client 103.215.74.26:39176] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEuMjqbtjBYzqM1uZIjAAAAA8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:04.100541 2026] [security2:error] [pid 643253:tid 643482] [client 68.221.186.136:26183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/404.php"] [unique_id "amuEuMjqbtjBYzqM1uZIjgAAAGI"]
[Thu Jul 30 12:07:04.635278 2026] [security2:error] [pid 643253:tid 643388] [client 68.221.186.136:21877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/aa.php"] [unique_id "amuEuMjqbtjBYzqM1uZIlgAAAAQ"]
[Thu Jul 30 12:07:04.794634 2026] [core:notice] [pid 643253:tid 643510] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:04.798545 2026] [security2:error] [pid 643253:tid 643510] [client 103.215.74.26:39180] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEuMjqbtjBYzqM1uZImQAAAH4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:04.862663 2026] [security2:error] [pid 643253:tid 643504] [client 20.226.5.174:34263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/as.php"] [unique_id "amuEuMjqbtjBYzqM1uZImwAAAHg"]
[Thu Jul 30 12:07:04.961386 2026] [security2:error] [pid 643253:tid 643437] [client 74.7.244.11:51394] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "webdisk.uuv.rty.temporary.site"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuEuMjqbtjBYzqM1uZIoAAAADU"]
[Thu Jul 30 12:07:05.029088 2026] [security2:error] [pid 643253:tid 643502] [client 136.116.113.96:1024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEuMjqbtjBYzqM1uZIlwAAAHY"]
[Thu Jul 30 12:07:05.550899 2026] [core:notice] [pid 643253:tid 643458] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:05.554856 2026] [security2:error] [pid 643253:tid 643458] [client 103.215.74.26:39192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEucjqbtjBYzqM1uZIsAAAAEo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:05.991434 2026] [security2:error] [pid 643253:tid 643400] [client 68.221.186.136:37639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/aafewc0k.php"] [unique_id "amuEucjqbtjBYzqM1uZItwAAABA"]
[Thu Jul 30 12:07:06.284754 2026] [core:notice] [pid 643253:tid 643507] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:06.291370 2026] [security2:error] [pid 643253:tid 643507] [client 103.215.74.26:39196] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEusjqbtjBYzqM1uZIvgAAAHs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:06.314453 2026] [security2:error] [pid 643253:tid 643468] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEucjqbtjBYzqM1uZIpwAAVFk"]
[Thu Jul 30 12:07:06.461203 2026] [security2:error] [pid 643253:tid 643481] [client 20.226.5.174:34302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/atomlib.php"] [unique_id "amuEusjqbtjBYzqM1uZIwgAAAGE"]
[Thu Jul 30 12:07:06.607662 2026] [security2:error] [pid 643253:tid 643384] [client 135.148.195.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "nafmedical.com"] [uri "/index.php"] [unique_id "amuEusjqbtjBYzqM1uZIwQAAAAA"]
[Thu Jul 30 12:07:06.709653 2026] [security2:error] [pid 643253:tid 643454] [client 191.232.199.39:59821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/fw.php"] [unique_id "amuEusjqbtjBYzqM1uZIygAAAEY"]
[Thu Jul 30 12:07:06.861450 2026] [security2:error] [pid 643253:tid 643442] [client 172.236.9.101:12319] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEusjqbtjBYzqM1uZIvAAAADo"]
[Thu Jul 30 12:07:06.863271 2026] [security2:error] [pid 643253:tid 643391] [client 172.236.9.101:38676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEusjqbtjBYzqM1uZIvQAAAAc"]
[Thu Jul 30 12:07:06.890986 2026] [security2:error] [pid 643253:tid 643445] [client 172.236.9.101:46230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEusjqbtjBYzqM1uZIuwAAAD0"]
[Thu Jul 30 12:07:06.910766 2026] [security2:error] [pid 643253:tid 643447] [client 172.236.9.101:34727] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEusjqbtjBYzqM1uZIvwAAAD8"]
[Thu Jul 30 12:07:06.957056 2026] [core:error] [pid 643253:tid 643401] [client 74.7.175.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:07:06.957079 2026] [core:error] [pid 643253:tid 643401] [client 74.7.175.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:07:06.957203 2026] [security2:error] [pid 643253:tid 643401] [client 74.7.175.143:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.ssa.djb.temporary.site"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amuEusjqbtjBYzqM1uZIzwAAABE"]
[Thu Jul 30 12:07:06.957968 2026] [security2:error] [pid 643253:tid 643399] [client 74.7.175.143:45060] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.ssa.djb.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuEusjqbtjBYzqM1uZIzQAADwM"]
[Thu Jul 30 12:07:07.019597 2026] [core:notice] [pid 643253:tid 643506] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:07.023621 2026] [security2:error] [pid 643253:tid 643506] [client 103.215.74.26:39202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "773"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEu8jqbtjBYzqM1uZI0wAAAHo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:07.122045 2026] [security2:error] [pid 643253:tid 643494] [client 66.249.66.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.palison.co"] [uri "/index.php"] [unique_id "amuEucjqbtjBYzqM1uZIsgAAbjo"]
[Thu Jul 30 12:07:07.364439 2026] [security2:error] [pid 643253:tid 643499] [client 20.91.139.111:32622] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.nordeste1.com"] [uri "/1.php"] [unique_id "amuEu8jqbtjBYzqM1uZI6AAAAHM"]
[Thu Jul 30 12:07:07.364613 2026] [security2:error] [pid 643253:tid 643499] [client 20.91.139.111:32622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/1.php"] [unique_id "amuEu8jqbtjBYzqM1uZI6AAAAHM"]
[Thu Jul 30 12:07:07.364739 2026] [security2:error] [pid 643253:tid 643499] [client 20.91.139.111:32622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/1.php"] [unique_id "amuEu8jqbtjBYzqM1uZI6AAAAHM"]
[Thu Jul 30 12:07:07.480099 2026] [security2:error] [pid 643253:tid 643387] [client 68.221.186.136:34563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/abcd.php"] [unique_id "amuEu8jqbtjBYzqM1uZI6QAAAAM"]
[Thu Jul 30 12:07:07.507142 2026] [security2:error] [pid 643253:tid 643393] [client 20.226.5.174:34269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/autoload_classmap.php"] [unique_id "amuEu8jqbtjBYzqM1uZI6gAAAAk"]
[Thu Jul 30 12:07:07.760667 2026] [core:notice] [pid 643253:tid 643502] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:07.765003 2026] [security2:error] [pid 643253:tid 643502] [client 103.215.74.26:39210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEu8jqbtjBYzqM1uZI9gAAAHY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:08.418869 2026] [security2:error] [pid 643253:tid 643478] [client 5.161.194.92:12036] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuEu8jqbtjBYzqM1uZI0AAAAF4"], referer: https://globalmarks.pk/
[Thu Jul 30 12:07:08.470008 2026] [security2:error] [pid 643253:tid 643500] [client 172.236.9.101:18203] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEu8jqbtjBYzqM1uZI2QAAAHQ"]
[Thu Jul 30 12:07:08.482860 2026] [security2:error] [pid 643253:tid 643461] [client 191.232.199.39:19755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-login.php"] [unique_id "amuEvMjqbtjBYzqM1uZI_QAAAE0"]
[Thu Jul 30 12:07:08.488493 2026] [security2:error] [pid 643253:tid 643423] [client 172.236.9.101:48269] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEu8jqbtjBYzqM1uZI2gAAACc"]
[Thu Jul 30 12:07:08.489856 2026] [security2:error] [pid 643253:tid 643508] [client 68.221.186.136:21854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/about.php"] [unique_id "amuEvMjqbtjBYzqM1uZI_gAAAHw"]
[Thu Jul 30 12:07:08.490666 2026] [security2:error] [pid 643253:tid 643504] [client 172.236.9.101:5684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEu8jqbtjBYzqM1uZI2AAAAHg"]
[Thu Jul 30 12:07:08.497816 2026] [security2:error] [pid 643253:tid 643431] [client 172.236.9.101:25743] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEu8jqbtjBYzqM1uZI2wAAAC8"]
[Thu Jul 30 12:07:08.534573 2026] [core:notice] [pid 643253:tid 643430] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:08.540297 2026] [security2:error] [pid 643253:tid 643430] [client 103.215.74.26:39220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEvMjqbtjBYzqM1uZI_wAAAC4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:08.571297 2026] [security2:error] [pid 643253:tid 643437] [client 172.236.9.101:14833] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEu8jqbtjBYzqM1uZI3QAAADU"]
[Thu Jul 30 12:07:08.579229 2026] [security2:error] [pid 643253:tid 643490] [client 172.236.9.101:30396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEu8jqbtjBYzqM1uZI3AAAAGo"]
[Thu Jul 30 12:07:08.580745 2026] [security2:error] [pid 643253:tid 643453] [client 172.236.9.101:36971] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEu8jqbtjBYzqM1uZI3gAAAEU"]
[Thu Jul 30 12:07:08.586545 2026] [security2:error] [pid 643253:tid 643450] [client 172.236.9.101:43740] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEu8jqbtjBYzqM1uZI4wAAAEI"]
[Thu Jul 30 12:07:08.596687 2026] [security2:error] [pid 643253:tid 643392] [client 172.236.9.101:62987] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEu8jqbtjBYzqM1uZI3wAAAAg"]
[Thu Jul 30 12:07:08.598128 2026] [security2:error] [pid 643253:tid 643420] [client 172.236.9.101:24893] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEu8jqbtjBYzqM1uZI5gAAACQ"]
[Thu Jul 30 12:07:08.605277 2026] [security2:error] [pid 643253:tid 643433] [client 172.236.9.101:37554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEu8jqbtjBYzqM1uZI4QAAADE"]
[Thu Jul 30 12:07:08.613623 2026] [security2:error] [pid 643253:tid 643451] [client 172.236.9.101:60538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEu8jqbtjBYzqM1uZI5QAAAEM"]
[Thu Jul 30 12:07:08.613659 2026] [security2:error] [pid 643253:tid 643406] [client 172.236.9.101:59406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEu8jqbtjBYzqM1uZI4gAAABY"]
[Thu Jul 30 12:07:08.616934 2026] [security2:error] [pid 643253:tid 643459] [client 172.236.9.101:10681] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEu8jqbtjBYzqM1uZI5AAAAEs"]
[Thu Jul 30 12:07:08.620747 2026] [security2:error] [pid 643253:tid 643487] [client 172.236.9.101:54555] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEu8jqbtjBYzqM1uZI4AAAAGc"]
[Thu Jul 30 12:07:08.630284 2026] [security2:error] [pid 643253:tid 643477] [client 172.236.9.101:5970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEu8jqbtjBYzqM1uZI5wAAAF0"]
[Thu Jul 30 12:07:09.248243 2026] [security2:error] [pid 643253:tid 643422] [client 20.226.5.174:34252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/bb.php"] [unique_id "amuEvcjqbtjBYzqM1uZJFQAAACY"]
[Thu Jul 30 12:07:09.300505 2026] [core:notice] [pid 643253:tid 643446] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:09.304821 2026] [security2:error] [pid 643253:tid 643446] [client 103.215.74.26:39234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEvcjqbtjBYzqM1uZJFgAAAD4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:09.826628 2026] [core:notice] [pid 643253:tid 643438] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:09.925266 2026] [security2:error] [pid 643253:tid 643439] [client 68.221.186.136:38431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/admin.php"] [unique_id "amuEvcjqbtjBYzqM1uZJKAAAADc"]
[Thu Jul 30 12:07:10.015060 2026] [core:notice] [pid 643253:tid 643400] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:10.019491 2026] [security2:error] [pid 643253:tid 643400] [client 103.215.74.26:39240] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEvsjqbtjBYzqM1uZJKgAAABA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:10.324059 2026] [security2:error] [pid 643253:tid 643470] [client 20.226.5.174:34258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/bnm.php"] [unique_id "amuEvsjqbtjBYzqM1uZJNAAAAFY"]
[Thu Jul 30 12:07:10.503299 2026] [core:notice] [pid 643253:tid 643378] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:10.528955 2026] [security2:error] [pid 643253:tid 643464] [client 2a03:2880:f800:36:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEvcjqbtjBYzqM1uZJJwAAUAw"]
[Thu Jul 30 12:07:10.590597 2026] [core:error] [pid 643253:tid 643456] [client 212.56.53.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://blueskyroofingco.shop/
[Thu Jul 30 12:07:10.590627 2026] [core:error] [pid 643253:tid 643456] [client 212.56.53.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://blueskyroofingco.shop/
[Thu Jul 30 12:07:10.786442 2026] [security2:error] [pid 643253:tid 643424] [client 191.232.199.39:20299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/simple.php"] [unique_id "amuEvsjqbtjBYzqM1uZJQwAAACg"]
[Thu Jul 30 12:07:10.788515 2026] [core:notice] [pid 643253:tid 643483] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:10.792709 2026] [security2:error] [pid 643253:tid 643483] [client 103.215.74.26:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEvsjqbtjBYzqM1uZJRAAAAGM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:11.474548 2026] [security2:error] [pid 643253:tid 643462] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEvsjqbtjBYzqM1uZJTwAAThs"]
[Thu Jul 30 12:07:11.475394 2026] [security2:error] [pid 643253:tid 643388] [client 172.237.109.114:56163] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEvsjqbtjBYzqM1uZJUQAAAAQ"]
[Thu Jul 30 12:07:11.509392 2026] [core:notice] [pid 643253:tid 643465] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:11.513683 2026] [security2:error] [pid 643253:tid 643465] [client 103.215.74.26:39258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEv8jqbtjBYzqM1uZJZQAAAFE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:11.538211 2026] [security2:error] [pid 643253:tid 643308] [remote 74.7.241.59:49048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuEv8jqbtjBYzqM1uZJZgAABjU"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/forms/actions
[Thu Jul 30 12:07:11.580768 2026] [security2:error] [pid 643253:tid 643446] [client 20.226.5.174:33885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/bootstrap.php"] [unique_id "amuEv8jqbtjBYzqM1uZJZwAAAD4"]
[Thu Jul 30 12:07:11.612255 2026] [security2:error] [pid 643253:tid 643402] [client 2a03:2880:f800:2c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEvsjqbtjBYzqM1uZJUgAAEnQ"]
[Thu Jul 30 12:07:11.727359 2026] [security2:error] [pid 643253:tid 643479] [client 43.173.174.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuEv8jqbtjBYzqM1uZJVwAAAF8"]
[Thu Jul 30 12:07:12.240576 2026] [core:notice] [pid 643253:tid 643384] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:12.250859 2026] [security2:error] [pid 643253:tid 643384] [client 103.215.74.26:39266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEwMjqbtjBYzqM1uZJiQAAAAA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:12.378517 2026] [security2:error] [pid 643253:tid 643442] [client 250.49.135.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuEwMjqbtjBYzqM1uZJiAAAOhg"]
[Thu Jul 30 12:07:13.000965 2026] [core:notice] [pid 643253:tid 643427] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:13.005407 2026] [security2:error] [pid 643253:tid 643427] [client 103.215.74.26:39268] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEwMjqbtjBYzqM1uZJpAAAACs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:13.313229 2026] [security2:error] [pid 643253:tid 643481] [client 172.237.109.114:4541] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEv8jqbtjBYzqM1uZJdAAAAGE"]
[Thu Jul 30 12:07:13.336109 2026] [security2:error] [pid 643253:tid 643420] [client 172.237.109.114:35101] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEv8jqbtjBYzqM1uZJcgAAACQ"]
[Thu Jul 30 12:07:13.342193 2026] [security2:error] [pid 643253:tid 643468] [client 172.237.109.114:6106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEv8jqbtjBYzqM1uZJcwAAAFQ"]
[Thu Jul 30 12:07:13.344556 2026] [security2:error] [pid 643253:tid 643463] [client 191.232.199.39:61090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/classsmtps.php"] [unique_id "amuEwcjqbtjBYzqM1uZJrQAAAE8"]
[Thu Jul 30 12:07:13.392966 2026] [security2:error] [pid 643253:tid 643507] [client 172.237.109.114:59606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEv8jqbtjBYzqM1uZJeQAAAHs"]
[Thu Jul 30 12:07:13.396481 2026] [security2:error] [pid 643253:tid 643470] [client 172.237.109.114:54135] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEv8jqbtjBYzqM1uZJdQAAAFY"]
[Thu Jul 30 12:07:13.410111 2026] [security2:error] [pid 643253:tid 643501] [client 172.237.109.114:16386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEv8jqbtjBYzqM1uZJdwAAAHU"]
[Thu Jul 30 12:07:13.419964 2026] [security2:error] [pid 643253:tid 643437] [client 172.237.109.114:11413] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEv8jqbtjBYzqM1uZJeAAAADU"]
[Thu Jul 30 12:07:13.444302 2026] [security2:error] [pid 643253:tid 643486] [client 172.237.109.114:2156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEv8jqbtjBYzqM1uZJfQAAAGY"]
[Thu Jul 30 12:07:13.444379 2026] [security2:error] [pid 643253:tid 643406] [client 172.237.109.114:29294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEv8jqbtjBYzqM1uZJfgAAABY"]
[Thu Jul 30 12:07:13.445167 2026] [security2:error] [pid 643253:tid 643456] [client 172.237.109.114:53776] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEwMjqbtjBYzqM1uZJgwAAAEg"]
[Thu Jul 30 12:07:13.462087 2026] [security2:error] [pid 643253:tid 643454] [client 172.237.109.114:47597] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEwMjqbtjBYzqM1uZJhAAAAEY"]
[Thu Jul 30 12:07:13.462771 2026] [security2:error] [pid 643253:tid 643421] [client 172.237.109.114:18573] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEv8jqbtjBYzqM1uZJfAAAACU"]
[Thu Jul 30 12:07:13.469731 2026] [security2:error] [pid 643253:tid 643460] [client 172.237.109.114:37134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEwMjqbtjBYzqM1uZJgQAAAEw"]
[Thu Jul 30 12:07:13.470203 2026] [security2:error] [pid 643253:tid 643413] [client 172.237.109.114:35855] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEv8jqbtjBYzqM1uZJewAAAB0"]
[Thu Jul 30 12:07:13.478027 2026] [security2:error] [pid 643253:tid 643496] [client 172.237.109.114:31413] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEwMjqbtjBYzqM1uZJggAAAHA"]
[Thu Jul 30 12:07:13.503875 2026] [security2:error] [pid 643253:tid 643469] [client 172.237.109.114:57510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEv8jqbtjBYzqM1uZJegAAAFU"]
[Thu Jul 30 12:07:13.506942 2026] [security2:error] [pid 643253:tid 643436] [client 172.237.109.114:27427] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEv8jqbtjBYzqM1uZJdgAAADQ"]
[Thu Jul 30 12:07:13.555415 2026] [security2:error] [pid 643253:tid 643475] [client 172.237.109.114:1519] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEwMjqbtjBYzqM1uZJhQAAAFs"]
[Thu Jul 30 12:07:13.565587 2026] [security2:error] [pid 643253:tid 643464] [client 172.237.109.114:30043] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEwMjqbtjBYzqM1uZJgAAAAFA"]
[Thu Jul 30 12:07:13.724880 2026] [core:notice] [pid 643253:tid 643430] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:13.729257 2026] [security2:error] [pid 643253:tid 643430] [client 103.215.74.26:13908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEwcjqbtjBYzqM1uZJugAAAC4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:14.438563 2026] [core:notice] [pid 643253:tid 643427] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:14.441000 2026] [security2:error] [pid 643253:tid 643492] [client 197.244.88.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEwcjqbtjBYzqM1uZJuAAAbE0"], referer: https://allmontecristi.com
[Thu Jul 30 12:07:14.447134 2026] [security2:error] [pid 643253:tid 643427] [client 103.215.74.26:13918] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEwsjqbtjBYzqM1uZJ0gAAACs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:14.648339 2026] [security2:error] [pid 643253:tid 643424] [client 20.226.5.174:34254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/buy.php"] [unique_id "amuEwsjqbtjBYzqM1uZJ3QAAACg"]
[Thu Jul 30 12:07:14.753016 2026] [security2:error] [pid 643253:tid 643426] [client 138.97.188.101:19622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEwsjqbtjBYzqM1uZJ0wAAACo"], referer: http://pkf.jo
[Thu Jul 30 12:07:15.022649 2026] [security2:error] [pid 643253:tid 643463] [client 191.232.199.39:59823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-blog-header.php"] [unique_id "amuEw8jqbtjBYzqM1uZJ5gAAAE8"]
[Thu Jul 30 12:07:15.270603 2026] [security2:error] [pid 643253:tid 643443] [client 103.173.162.49:34177] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "agr8story.site"] [uri "/wp-comments-post.php"] [unique_id "amuEwsjqbtjBYzqM1uZJ3wAAADs"]
[Thu Jul 30 12:07:15.412720 2026] [security2:error] [pid 643253:tid 643443] [client 103.173.162.49:34177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "agr8story.site"] [uri "/wp-comments-post.php"] [unique_id "amuEwsjqbtjBYzqM1uZJ3wAAADs"]
[Thu Jul 30 12:07:15.499027 2026] [security2:error] [pid 643253:tid 643258] [remote 40.77.167.57:35546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/tumed/article/download/7529/3035/20005"] [unique_id "amuEw8jqbtjBYzqM1uZJ7gAAeAM"]
[Thu Jul 30 12:07:16.205579 2026] [security2:error] [pid 643253:tid 643384] [client 20.226.5.174:34322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/chosen.php"] [unique_id "amuExMjqbtjBYzqM1uZKAgAAAAA"]
[Thu Jul 30 12:07:17.659504 2026] [security2:error] [pid 643253:tid 643497] [client 191.232.199.39:59779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-trackback.php"] [unique_id "amuExcjqbtjBYzqM1uZKFQAAAHE"]
[Thu Jul 30 12:07:17.673358 2026] [security2:error] [pid 643253:tid 643449] [client 20.203.142.71:4879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuExcjqbtjBYzqM1uZKFgAAAEE"]
[Thu Jul 30 12:07:17.673474 2026] [security2:error] [pid 643253:tid 643449] [client 20.203.142.71:4879] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuExcjqbtjBYzqM1uZKFgAAAEE"]
[Thu Jul 30 12:07:18.112775 2026] [security2:error] [pid 643253:tid 643405] [client 20.226.5.174:34267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/class-wp-image.php"] [unique_id "amuExsjqbtjBYzqM1uZKGgAAABU"]
[Thu Jul 30 12:07:18.850937 2026] [security2:error] [pid 643253:tid 643426] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuExsjqbtjBYzqM1uZKIQAAKj0"]
[Thu Jul 30 12:07:19.097497 2026] [lsapi:error] [pid 642360:tid 642444] [remote 102.209.111.62:0] [host flixon.net] Error receiving response: ReceiveResponse: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1009; user ID 1009), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://flixon.net/video/fall-for-me-vj-junior/
[Thu Jul 30 12:07:19.593964 2026] [security2:error] [pid 643253:tid 643406] [client 191.232.199.39:19728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-signup.php"] [unique_id "amuEx8jqbtjBYzqM1uZKPAAAABY"]
[Thu Jul 30 12:07:20.173373 2026] [core:notice] [pid 643253:tid 643404] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:20.179676 2026] [security2:error] [pid 643253:tid 643404] [client 103.215.74.26:13928] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEyMjqbtjBYzqM1uZKQwAAABQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:20.362756 2026] [security2:error] [pid 643253:tid 643470] [client 68.221.186.136:25420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/adminfuns.php"] [unique_id "amuEyMjqbtjBYzqM1uZKTgAAAFY"]
[Thu Jul 30 12:07:20.857157 2026] [security2:error] [pid 643253:tid 643509] [client 20.226.5.174:34049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/classsmtps.php"] [unique_id "amuEyMjqbtjBYzqM1uZKVgAAAH0"]
[Thu Jul 30 12:07:20.927689 2026] [core:notice] [pid 643253:tid 643389] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:20.932112 2026] [security2:error] [pid 643253:tid 643389] [client 103.215.74.26:13944] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEyMjqbtjBYzqM1uZKWQAAAAU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:21.655301 2026] [core:notice] [pid 643253:tid 643488] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:21.659552 2026] [security2:error] [pid 643253:tid 643488] [client 103.215.74.26:13948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEycjqbtjBYzqM1uZKZwAAAGg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:21.930874 2026] [security2:error] [pid 643253:tid 643398] [client 50.6.43.217:58064] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/1.jpg"] [unique_id "amuEycjqbtjBYzqM1uZKcAAAAA4"]
[Thu Jul 30 12:07:21.941157 2026] [security2:error] [pid 643253:tid 643508] [client 50.6.43.217:58070] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/2.jpg"] [unique_id "amuEycjqbtjBYzqM1uZKcQAAAHw"]
[Thu Jul 30 12:07:21.950355 2026] [security2:error] [pid 643253:tid 643485] [client 50.6.43.217:58086] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/3.jpg"] [unique_id "amuEycjqbtjBYzqM1uZKcgAAAGU"]
[Thu Jul 30 12:07:22.179342 2026] [security2:error] [pid 643253:tid 643504] [client 95.142.47.113:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEycjqbtjBYzqM1uZKZgAAeH0"], referer: https://allmontecristi.com/5-important-characteristics-to-identify-an-export-panama-hat/?srsltid=afmbooobpjslvy1dcritpm3oyoloutbopk2q0t238sboel09-jvs0f2z
[Thu Jul 30 12:07:22.392663 2026] [core:notice] [pid 643253:tid 643386] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:22.398594 2026] [security2:error] [pid 643253:tid 643386] [client 103.215.74.26:13956] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEysjqbtjBYzqM1uZKfwAAAAI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:22.568129 2026] [core:notice] [pid 643253:tid 643305] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:22.658337 2026] [security2:error] [pid 643253:tid 643493] [client 20.203.142.71:42912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuEysjqbtjBYzqM1uZKhgAAAG0"]
[Thu Jul 30 12:07:22.658447 2026] [security2:error] [pid 643253:tid 643493] [client 20.203.142.71:42912] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuEysjqbtjBYzqM1uZKhgAAAG0"]
[Thu Jul 30 12:07:22.926456 2026] [security2:error] [pid 643253:tid 643420] [client 34.86.95.193:64928] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tereashops.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuEysjqbtjBYzqM1uZKjwAAACQ"]
[Thu Jul 30 12:07:23.135922 2026] [core:notice] [pid 643253:tid 643455] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:23.140132 2026] [security2:error] [pid 643253:tid 643455] [client 103.215.74.26:46726] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEy8jqbtjBYzqM1uZKkwAAAEc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:23.207308 2026] [core:notice] [pid 643253:tid 643311] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:23.563508 2026] [security2:error] [pid 643253:tid 643462] [client 95.142.47.113:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEy8jqbtjBYzqM1uZKkQAATig"], referer: https://allmontecristi.com/contact/
[Thu Jul 30 12:07:23.664858 2026] [security2:error] [pid 643253:tid 643449] [client 68.221.186.136:38862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/albin.php"] [unique_id "amuEy8jqbtjBYzqM1uZKngAAAEE"]
[Thu Jul 30 12:07:23.763247 2026] [core:error] [pid 643253:tid 643445] [client 74.7.228.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:07:23.763272 2026] [core:error] [pid 643253:tid 643445] [client 74.7.228.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:07:23.763409 2026] [security2:error] [pid 643253:tid 643445] [client 74.7.228.34:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.dug.nyx.temporary.site"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amuEy8jqbtjBYzqM1uZKoQAAAD0"]
[Thu Jul 30 12:07:23.764028 2026] [security2:error] [pid 643253:tid 643407] [client 74.7.228.34:49470] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.dug.nyx.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuEy8jqbtjBYzqM1uZKnwAAF0g"]
[Thu Jul 30 12:07:23.865280 2026] [core:notice] [pid 643253:tid 643460] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:23.870963 2026] [security2:error] [pid 643253:tid 643460] [client 103.215.74.26:46742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEy8jqbtjBYzqM1uZKowAAAEw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:23.905146 2026] [security2:error] [pid 643253:tid 643405] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEy8jqbtjBYzqM1uZKlQAAFUA"]
[Thu Jul 30 12:07:23.961630 2026] [security2:error] [pid 643253:tid 643421] [client 34.86.95.193:60733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.95.86.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tereashops.com"] [uri "/xmlrpc.php"] [unique_id "amuEy8jqbtjBYzqM1uZKrQAAACU"]
[Thu Jul 30 12:07:24.298031 2026] [security2:error] [pid 643253:tid 643399] [client 20.203.142.71:29368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuEzMjqbtjBYzqM1uZKsgAAAA8"]
[Thu Jul 30 12:07:24.298141 2026] [security2:error] [pid 643253:tid 643399] [client 20.203.142.71:29368] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuEzMjqbtjBYzqM1uZKsgAAAA8"]
[Thu Jul 30 12:07:24.371883 2026] [security2:error] [pid 643253:tid 643456] [client 191.232.199.39:59822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-comments-post.php"] [unique_id "amuEzMjqbtjBYzqM1uZKtAAAAEg"]
[Thu Jul 30 12:07:24.596618 2026] [core:notice] [pid 643253:tid 643442] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:24.600903 2026] [security2:error] [pid 643253:tid 643442] [client 103.215.74.26:46746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEzMjqbtjBYzqM1uZKvQAAADo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:24.795657 2026] [security2:error] [pid 643253:tid 643286] [remote 57.141.0.43:63546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/458216670/feed/rss2/"] [unique_id "amuEzMjqbtjBYzqM1uZKvgAAFB8"]
[Thu Jul 30 12:07:24.800794 2026] [security2:error] [pid 643253:tid 643444] [client 213.152.187.215:59028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.187.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuEzMjqbtjBYzqM1uZKvwAAADw"]
[Thu Jul 30 12:07:24.800867 2026] [security2:error] [pid 643253:tid 643444] [client 213.152.187.215:59028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuEzMjqbtjBYzqM1uZKvwAAADw"]
[Thu Jul 30 12:07:25.135756 2026] [security2:error] [pid 643253:tid 643504] [client 68.221.186.136:37450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/amfsqvgv.php"] [unique_id "amuEzcjqbtjBYzqM1uZKywAAAHg"]
[Thu Jul 30 12:07:25.209205 2026] [security2:error] [pid 643253:tid 643497] [client 20.203.142.71:47234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/err.php"] [unique_id "amuEzcjqbtjBYzqM1uZKzAAAAHE"]
[Thu Jul 30 12:07:25.209346 2026] [security2:error] [pid 643253:tid 643497] [client 20.203.142.71:47234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/err.php"] [unique_id "amuEzcjqbtjBYzqM1uZKzAAAAHE"]
[Thu Jul 30 12:07:25.252337 2026] [security2:error] [pid 643253:tid 643458] [client 181.121.14.41:44894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEzMjqbtjBYzqM1uZKxAAAAEo"], referer: http://pkf.jo
[Thu Jul 30 12:07:25.256415 2026] [security2:error] [pid 643253:tid 643472] [client 46.232.251.191:50438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "deltaedu.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuEzcjqbtjBYzqM1uZKygAAWFE"], referer: https://deltaedu.net/wp-admin/admin-ajax.php?action=tnp&na=s
[Thu Jul 30 12:07:25.630901 2026] [security2:error] [pid 643253:tid 643509] [client 37.111.246.182:31575] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEzcjqbtjBYzqM1uZKzgAAAH0"], referer: http://pkf.jo
[Thu Jul 30 12:07:25.992025 2026] [security2:error] [pid 643253:tid 643465] [client 68.221.186.136:25354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/ant.php"] [unique_id "amuEzcjqbtjBYzqM1uZK2QAAAFE"]
[Thu Jul 30 12:07:26.153233 2026] [security2:error] [pid 643253:tid 643457] [client 20.226.5.174:33944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/classwithtostring.php"] [unique_id "amuEzsjqbtjBYzqM1uZK4AAAAEk"]
[Thu Jul 30 12:07:26.397242 2026] [security2:error] [pid 643253:tid 643503] [client 74.7.244.52:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-ab9d1028.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuEzsjqbtjBYzqM1uZK3AAAAHc"]
[Thu Jul 30 12:07:26.398090 2026] [security2:error] [pid 643253:tid 643413] [client 74.7.244.52:43718] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-ab9d1028.glb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuEzcjqbtjBYzqM1uZK2gAAHU8"]
[Thu Jul 30 12:07:26.414689 2026] [security2:error] [pid 643253:tid 643392] [client 20.203.142.71:25377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/img.php"] [unique_id "amuEzsjqbtjBYzqM1uZK5AAAAAg"]
[Thu Jul 30 12:07:26.414804 2026] [security2:error] [pid 643253:tid 643392] [client 20.203.142.71:25377] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/img.php"] [unique_id "amuEzsjqbtjBYzqM1uZK5AAAAAg"]
[Thu Jul 30 12:07:26.780559 2026] [security2:error] [pid 643253:tid 643418] [client 68.221.186.136:38199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/appreciators.php"] [unique_id "amuEzsjqbtjBYzqM1uZK7gAAACI"]
[Thu Jul 30 12:07:27.324424 2026] [security2:error] [pid 643253:tid 643475] [client 20.226.5.174:35532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/config.php"] [unique_id "amuEz8jqbtjBYzqM1uZK-AAAAFs"]
[Thu Jul 30 12:07:27.587877 2026] [security2:error] [pid 643253:tid 643480] [client 68.221.186.136:38183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/archive.php"] [unique_id "amuEz8jqbtjBYzqM1uZK_QAAAGA"]
[Thu Jul 30 12:07:27.773958 2026] [security2:error] [pid 643253:tid 643420] [client 20.203.142.71:32596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/aa.php"] [unique_id "amuEz8jqbtjBYzqM1uZLBAAAACQ"]
[Thu Jul 30 12:07:27.774088 2026] [security2:error] [pid 643253:tid 643420] [client 20.203.142.71:32596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/aa.php"] [unique_id "amuEz8jqbtjBYzqM1uZLBAAAACQ"]
[Thu Jul 30 12:07:28.507166 2026] [security2:error] [pid 643253:tid 643446] [client 20.226.5.174:35573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/core.php"] [unique_id "amuE0MjqbtjBYzqM1uZLEQAAAD4"]
[Thu Jul 30 12:07:29.387373 2026] [security2:error] [pid 643253:tid 643413] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuE0MjqbtjBYzqM1uZLGQAAHWQ"]
[Thu Jul 30 12:07:29.455137 2026] [security2:error] [pid 643253:tid 643426] [client 68.221.186.136:37472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/as.php"] [unique_id "amuE0cjqbtjBYzqM1uZLJgAAACo"]
[Thu Jul 30 12:07:29.565472 2026] [security2:error] [pid 643253:tid 643477] [client 20.226.5.174:35525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/css.php"] [unique_id "amuE0cjqbtjBYzqM1uZLJwAAAF0"]
[Thu Jul 30 12:07:30.171229 2026] [security2:error] [pid 643253:tid 643344] [remote 57.141.0.28:45862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/404010317/feed/rss2/"] [unique_id "amuE0cjqbtjBYzqM1uZLNAAAGlk"]
[Thu Jul 30 12:07:30.322970 2026] [core:notice] [pid 643253:tid 643389] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:30.328233 2026] [security2:error] [pid 643253:tid 643389] [client 103.215.74.26:46752] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE0sjqbtjBYzqM1uZLPgAAAAU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:30.329915 2026] [security2:error] [pid 643253:tid 643428] [client 191.232.199.39:61115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-mail.php"] [unique_id "amuE0sjqbtjBYzqM1uZLPwAAACw"]
[Thu Jul 30 12:07:30.512784 2026] [security2:error] [pid 643253:tid 643423] [client 34.86.95.193:64639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.95.86.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tereashops.com"] [uri "/xmlrpc.php"] [unique_id "amuE0sjqbtjBYzqM1uZLQAAAACc"]
[Thu Jul 30 12:07:30.512905 2026] [security2:error] [pid 643253:tid 643423] [client 34.86.95.193:64639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tereashops.com"] [uri "/xmlrpc.php"] [unique_id "amuE0sjqbtjBYzqM1uZLQAAAACc"]
[Thu Jul 30 12:07:30.566154 2026] [security2:error] [pid 643253:tid 643502] [client 2a03:2880:f800:2a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuE0cjqbtjBYzqM1uZLNQAAdlw"]
[Thu Jul 30 12:07:30.633890 2026] [security2:error] [pid 643253:tid 643400] [client 173.252.82.52:59958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.innovativefurnituretransportpackagingllc.cc"] [uri "/index.php"] [unique_id "amuE0cjqbtjBYzqM1uZLJAAAEHc"]
[Thu Jul 30 12:07:30.921082 2026] [security2:error] [pid 643253:tid 643450] [client 20.226.5.174:33518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/database.php"] [unique_id "amuE0sjqbtjBYzqM1uZLSgAAAEI"]
[Thu Jul 30 12:07:31.040698 2026] [security2:error] [pid 643253:tid 643441] [client 20.203.142.71:25374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/av.php"] [unique_id "amuE08jqbtjBYzqM1uZLSwAAADk"]
[Thu Jul 30 12:07:31.040819 2026] [security2:error] [pid 643253:tid 643441] [client 20.203.142.71:25374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/av.php"] [unique_id "amuE08jqbtjBYzqM1uZLSwAAADk"]
[Thu Jul 30 12:07:31.950031 2026] [security2:error] [pid 643253:tid 643510] [client 20.226.5.174:33480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/db.php"] [unique_id "amuE08jqbtjBYzqM1uZLYAAAAH4"]
[Thu Jul 30 12:07:32.022860 2026] [security2:error] [pid 643253:tid 643475] [client 191.232.199.39:20302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-activate.php"] [unique_id "amuE1MjqbtjBYzqM1uZLYQAAAFs"]
[Thu Jul 30 12:07:32.381622 2026] [security2:error] [pid 643253:tid 643500] [client 68.221.186.136:39356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/atomlib.php"] [unique_id "amuE1MjqbtjBYzqM1uZLZQAAAHQ"]
[Thu Jul 30 12:07:33.004197 2026] [security2:error] [pid 643253:tid 643426] [client 172.213.232.128:55493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/011i.php"] [unique_id "amuE1cjqbtjBYzqM1uZLcgAAACo"]
[Thu Jul 30 12:07:33.490994 2026] [security2:error] [pid 643253:tid 643482] [client 20.203.142.71:39009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/xa.php"] [unique_id "amuE1cjqbtjBYzqM1uZLewAAAGI"]
[Thu Jul 30 12:07:33.491089 2026] [security2:error] [pid 643253:tid 643482] [client 20.203.142.71:39009] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/xa.php"] [unique_id "amuE1cjqbtjBYzqM1uZLewAAAGI"]
[Thu Jul 30 12:07:33.600138 2026] [security2:error] [pid 643253:tid 643453] [client 136.70.106.31:60104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuE1cjqbtjBYzqM1uZLcwAAAEU"]
[Thu Jul 30 12:07:33.648096 2026] [security2:error] [pid 643253:tid 643434] [client 20.226.5.174:34400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/default.php"] [unique_id "amuE1cjqbtjBYzqM1uZLgAAAADI"]
[Thu Jul 30 12:07:33.675131 2026] [security2:error] [pid 643253:tid 643398] [client 213.152.187.215:33906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.187.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuE1cjqbtjBYzqM1uZLgQAAAA4"]
[Thu Jul 30 12:07:33.675249 2026] [security2:error] [pid 643253:tid 643398] [client 213.152.187.215:33906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuE1cjqbtjBYzqM1uZLgQAAAA4"]
[Thu Jul 30 12:07:34.212412 2026] [security2:error] [pid 643253:tid 643487] [client 57.141.0.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuE1cjqbtjBYzqM1uZLfgAAAGc"]
[Thu Jul 30 12:07:34.343461 2026] [security2:error] [pid 643253:tid 643494] [client 68.221.186.136:39341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/autoload_classmap.php"] [unique_id "amuE1sjqbtjBYzqM1uZLjQAAAG4"]
[Thu Jul 30 12:07:34.490470 2026] [security2:error] [pid 643253:tid 643418] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuE1cjqbtjBYzqM1uZLhQAAIgE"]
[Thu Jul 30 12:07:34.797959 2026] [security2:error] [pid 643253:tid 643477] [client 57.141.0.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuE1sjqbtjBYzqM1uZLjAAAAF0"]
[Thu Jul 30 12:07:34.907750 2026] [security2:error] [pid 643253:tid 643489] [client 20.226.5.174:33479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/dropdown.php"] [unique_id "amuE1sjqbtjBYzqM1uZLoAAAAGk"]
[Thu Jul 30 12:07:34.956649 2026] [security2:error] [pid 643253:tid 643399] [client 191.232.199.39:19744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/post.php"] [unique_id "amuE1sjqbtjBYzqM1uZLpAAAAA8"]
[Thu Jul 30 12:07:34.976849 2026] [security2:error] [pid 643253:tid 643481] [client 20.52.125.110:7143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.tmb/LA.php"] [unique_id "amuE1sjqbtjBYzqM1uZLpQAAAGE"]
[Thu Jul 30 12:07:35.447995 2026] [security2:error] [pid 643253:tid 643379] [remote 216.73.216.152:36206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuE18jqbtjBYzqM1uZLqwAAO3w"]
[Thu Jul 30 12:07:35.479531 2026] [security2:error] [pid 643253:tid 643476] [client 20.52.125.110:7123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.tmb/admin.php"] [unique_id "amuE18jqbtjBYzqM1uZLrAAAAFw"]
[Thu Jul 30 12:07:35.808767 2026] [security2:error] [pid 643253:tid 643386] [client 172.213.232.128:55969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/03a005685d.php"] [unique_id "amuE18jqbtjBYzqM1uZLsAAAAAI"]
[Thu Jul 30 12:07:35.905297 2026] [security2:error] [pid 643253:tid 643459] [client 68.221.186.136:26066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/bb.php"] [unique_id "amuE18jqbtjBYzqM1uZLtAAAAEs"]
[Thu Jul 30 12:07:35.919166 2026] [security2:error] [pid 643253:tid 643478] [client 20.52.125.110:7122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.tmb/class_api.php"] [unique_id "amuE18jqbtjBYzqM1uZLtwAAAF4"]
[Thu Jul 30 12:07:35.956183 2026] [security2:error] [pid 643253:tid 643269] [remote 216.73.216.152:36206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuE18jqbtjBYzqM1uZLuQAAOQ4"]
[Thu Jul 30 12:07:36.042579 2026] [core:notice] [pid 643253:tid 643496] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:36.046818 2026] [security2:error] [pid 643253:tid 643496] [client 103.215.74.26:55008] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE2MjqbtjBYzqM1uZLvQAAAHA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:36.185247 2026] [security2:error] [pid 643253:tid 643457] [client 20.226.5.174:34374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/edit.php"] [unique_id "amuE2MjqbtjBYzqM1uZLvgAAAEk"]
[Thu Jul 30 12:07:36.287042 2026] [security2:error] [pid 643253:tid 643490] [client 20.203.142.71:42907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/media.php"] [unique_id "amuE2MjqbtjBYzqM1uZLwAAAAGo"]
[Thu Jul 30 12:07:36.287157 2026] [security2:error] [pid 643253:tid 643490] [client 20.203.142.71:42907] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/media.php"] [unique_id "amuE2MjqbtjBYzqM1uZLwAAAAGo"]
[Thu Jul 30 12:07:36.343226 2026] [security2:error] [pid 643253:tid 643474] [client 20.52.125.110:7133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.tmb/cpabpkyk.php"] [unique_id "amuE2MjqbtjBYzqM1uZLwQAAAFo"]
[Thu Jul 30 12:07:36.778450 2026] [core:notice] [pid 643253:tid 643464] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:36.784893 2026] [security2:error] [pid 643253:tid 643464] [client 103.215.74.26:55016] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE2MjqbtjBYzqM1uZLzAAAAFA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:36.818266 2026] [security2:error] [pid 643253:tid 643396] [client 20.52.125.110:7120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.tmb/wp-login.php"] [unique_id "amuE2MjqbtjBYzqM1uZLzQAAAAw"]
[Thu Jul 30 12:07:37.241206 2026] [security2:error] [pid 643253:tid 643468] [client 20.52.125.110:7156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known//.well-known/owlmailer.php"] [unique_id "amuE2cjqbtjBYzqM1uZL1wAAAFQ"]
[Thu Jul 30 12:07:37.255816 2026] [security2:error] [pid 643253:tid 643442] [client 85.208.96.204:49520] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/11/23/homem-e-preso-por-porte-ilegal-de-armas-em-guarabira/"] [unique_id "amuE2cjqbtjBYzqM1uZL2QAAADo"]
[Thu Jul 30 12:07:37.255932 2026] [security2:error] [pid 643253:tid 643442] [client 85.208.96.204:49520] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/11/23/homem-e-preso-por-porte-ilegal-de-armas-em-guarabira/"] [unique_id "amuE2cjqbtjBYzqM1uZL2QAAADo"]
[Thu Jul 30 12:07:37.261939 2026] [security2:error] [pid 643253:tid 643414] [client 136.70.106.31:60477] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuE2MjqbtjBYzqM1uZLxAAAHgc"], referer: http://fireworkskenya.co.ke/media/system/js/core.js
[Thu Jul 30 12:07:37.445629 2026] [security2:error] [pid 643253:tid 643411] [client 172.213.232.128:55985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/403.php"] [unique_id "amuE2cjqbtjBYzqM1uZL2gAAABs"]
[Thu Jul 30 12:07:37.677954 2026] [security2:error] [pid 643253:tid 643384] [client 20.52.125.110:7150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/991176.php"] [unique_id "amuE2cjqbtjBYzqM1uZL5gAAAAA"]
[Thu Jul 30 12:07:37.753991 2026] [security2:error] [pid 643253:tid 643415] [client 20.203.142.71:30111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/images.php"] [unique_id "amuE2cjqbtjBYzqM1uZL5wAAAB8"]
[Thu Jul 30 12:07:37.754094 2026] [security2:error] [pid 643253:tid 643415] [client 20.203.142.71:30111] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/images.php"] [unique_id "amuE2cjqbtjBYzqM1uZL5wAAAB8"]
[Thu Jul 30 12:07:37.956118 2026] [core:notice] [pid 643253:tid 643498] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:38.150962 2026] [security2:error] [pid 643253:tid 643434] [client 20.52.125.110:7153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/acme-challenge/adminfuns.php"] [unique_id "amuE2sjqbtjBYzqM1uZL8AAAADI"]
[Thu Jul 30 12:07:38.197295 2026] [security2:error] [pid 643253:tid 643496] [client 172.213.232.128:55952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/404.php"] [unique_id "amuE2sjqbtjBYzqM1uZL9AAAAHA"]
[Thu Jul 30 12:07:38.221791 2026] [security2:error] [pid 643253:tid 643465] [client 50.6.43.217:35072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuE2cjqbtjBYzqM1uZL3gAAAFE"]
[Thu Jul 30 12:07:38.560226 2026] [security2:error] [pid 643253:tid 643511] [client 20.52.125.110:8193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.tmb/LA.php"] [unique_id "amuE2sjqbtjBYzqM1uZL-wAAAH8"]
[Thu Jul 30 12:07:38.593455 2026] [security2:error] [pid 643253:tid 643451] [client 20.52.125.110:7131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "amuE2sjqbtjBYzqM1uZL_QAAAEM"]
[Thu Jul 30 12:07:38.620466 2026] [security2:error] [pid 643253:tid 643303] [remote 40.77.167.47:42964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/2024/10/stafff.php"] [unique_id "amuE2sjqbtjBYzqM1uZMAQAASjA"]
[Thu Jul 30 12:07:38.951281 2026] [security2:error] [pid 643253:tid 643494] [client 50.6.43.217:35074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuE2sjqbtjBYzqM1uZL9QAAAG4"]
[Thu Jul 30 12:07:39.040697 2026] [security2:error] [pid 643253:tid 643472] [client 20.52.125.110:8452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.tmb/admin.php"] [unique_id "amuE28jqbtjBYzqM1uZMCwAAAFg"]
[Thu Jul 30 12:07:39.109221 2026] [security2:error] [pid 643253:tid 643442] [client 20.52.125.110:7116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/acme-challenge/classsmtps.php"] [unique_id "amuE28jqbtjBYzqM1uZMDwAAADo"]
[Thu Jul 30 12:07:39.611022 2026] [security2:error] [pid 643253:tid 643438] [client 57.141.0.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuE28jqbtjBYzqM1uZMCgAAADY"]
[Thu Jul 30 12:07:39.622658 2026] [security2:error] [pid 643253:tid 643508] [client 20.52.125.110:7160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "amuE28jqbtjBYzqM1uZMGwAAAHw"]
[Thu Jul 30 12:07:39.641806 2026] [security2:error] [pid 643253:tid 643432] [client 20.52.125.110:8470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.tmb/class_api.php"] [unique_id "amuE28jqbtjBYzqM1uZMHAAAADA"]
[Thu Jul 30 12:07:40.039049 2026] [security2:error] [pid 643253:tid 643501] [client 20.203.142.71:36048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/gecko.php"] [unique_id "amuE3MjqbtjBYzqM1uZMIwAAAHU"]
[Thu Jul 30 12:07:40.039134 2026] [security2:error] [pid 643253:tid 643501] [client 20.203.142.71:36048] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/gecko.php"] [unique_id "amuE3MjqbtjBYzqM1uZMIwAAAHU"]
[Thu Jul 30 12:07:40.100519 2026] [security2:error] [pid 643253:tid 643441] [client 68.221.186.136:31086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/bnm.php"] [unique_id "amuE3MjqbtjBYzqM1uZMJAAAADk"]
[Thu Jul 30 12:07:40.103849 2026] [security2:error] [pid 643253:tid 643482] [client 20.52.125.110:7149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/acme-challenge/doc.php"] [unique_id "amuE3MjqbtjBYzqM1uZMJgAAAGI"]
[Thu Jul 30 12:07:40.164339 2026] [security2:error] [pid 643253:tid 643419] [client 20.52.125.110:8199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.tmb/cpabpkyk.php"] [unique_id "amuE3MjqbtjBYzqM1uZMKwAAACM"]
[Thu Jul 30 12:07:40.484602 2026] [security2:error] [pid 643253:tid 643470] [client 20.203.142.71:29369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/82.php"] [unique_id "amuE3MjqbtjBYzqM1uZMMQAAAFY"]
[Thu Jul 30 12:07:40.484695 2026] [security2:error] [pid 643253:tid 643470] [client 20.203.142.71:29369] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/82.php"] [unique_id "amuE3MjqbtjBYzqM1uZMMQAAAFY"]
[Thu Jul 30 12:07:40.654727 2026] [security2:error] [pid 643253:tid 643511] [client 20.52.125.110:8205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.tmb/wp-login.php"] [unique_id "amuE3MjqbtjBYzqM1uZMNAAAAH8"]
[Thu Jul 30 12:07:40.745048 2026] [security2:error] [pid 643253:tid 643477] [client 20.52.125.110:7121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/acme-challenge/fond.php"] [unique_id "amuE3MjqbtjBYzqM1uZMOwAAAF0"]
[Thu Jul 30 12:07:40.812642 2026] [security2:error] [pid 643253:tid 643401] [client 68.221.186.136:31069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/bootstrap.php"] [unique_id "amuE3MjqbtjBYzqM1uZMPAAAABE"]
[Thu Jul 30 12:07:40.967195 2026] [security2:error] [pid 643253:tid 643315] [remote 216.73.216.152:36206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuE3MjqbtjBYzqM1uZMPQAANTw"]
[Thu Jul 30 12:07:41.043443 2026] [security2:error] [pid 643253:tid 643494] [client 20.203.142.71:36446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/xstelth.php"] [unique_id "amuE3cjqbtjBYzqM1uZMPgAAAG4"]
[Thu Jul 30 12:07:41.043556 2026] [security2:error] [pid 643253:tid 643494] [client 20.203.142.71:36446] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/xstelth.php"] [unique_id "amuE3cjqbtjBYzqM1uZMPgAAAG4"]
[Thu Jul 30 12:07:41.199408 2026] [security2:error] [pid 643253:tid 643395] [client 20.52.125.110:7130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "amuE3cjqbtjBYzqM1uZMQgAAAAs"]
[Thu Jul 30 12:07:41.379890 2026] [security2:error] [pid 643253:tid 643481] [client 20.52.125.110:8480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known//.well-known/owlmailer.php"] [unique_id "amuE3cjqbtjBYzqM1uZMSQAAAGE"]
[Thu Jul 30 12:07:41.464072 2026] [security2:error] [pid 643253:tid 643424] [client 68.221.186.136:39032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/buy.php"] [unique_id "amuE3cjqbtjBYzqM1uZMSgAAACg"]
[Thu Jul 30 12:07:41.723546 2026] [security2:error] [pid 643253:tid 643438] [client 20.52.125.110:6664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/acme-challenge/license.php"] [unique_id "amuE3cjqbtjBYzqM1uZMTgAAADY"]
[Thu Jul 30 12:07:41.932522 2026] [security2:error] [pid 643253:tid 643498] [client 20.203.142.71:25381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/xp.php"] [unique_id "amuE3cjqbtjBYzqM1uZMVQAAAHI"]
[Thu Jul 30 12:07:41.932634 2026] [security2:error] [pid 643253:tid 643498] [client 20.203.142.71:25381] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/xp.php"] [unique_id "amuE3cjqbtjBYzqM1uZMVQAAAHI"]
[Thu Jul 30 12:07:42.038344 2026] [security2:error] [pid 643253:tid 643433] [client 20.52.125.110:8483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/991176.php"] [unique_id "amuE3sjqbtjBYzqM1uZMWQAAADE"]
[Thu Jul 30 12:07:42.189847 2026] [security2:error] [pid 643253:tid 643394] [client 20.52.125.110:7138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/acme-challenge/mariju.php"] [unique_id "amuE3sjqbtjBYzqM1uZMWwAAAAo"]
[Thu Jul 30 12:07:42.220854 2026] [security2:error] [pid 643253:tid 643459] [client 68.221.186.136:39297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/chosen.php"] [unique_id "amuE3sjqbtjBYzqM1uZMXAAAAEs"]
[Thu Jul 30 12:07:42.347856 2026] [security2:error] [pid 643253:tid 643432] [client 172.213.232.128:55965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/aa.php"] [unique_id "amuE3sjqbtjBYzqM1uZMYwAAADA"]
[Thu Jul 30 12:07:42.422159 2026] [security2:error] [pid 643253:tid 643387] [client 20.226.5.174:33481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/f35.php"] [unique_id "amuE3sjqbtjBYzqM1uZMZwAAAAM"]
[Thu Jul 30 12:07:42.560458 2026] [core:notice] [pid 643253:tid 643397] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:42.566821 2026] [security2:error] [pid 643253:tid 643397] [client 103.215.74.26:55022] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE3sjqbtjBYzqM1uZMawAAAA0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:42.651253 2026] [security2:error] [pid 643253:tid 643465] [client 20.52.125.110:8510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/acme-challenge/adminfuns.php"] [unique_id "amuE3sjqbtjBYzqM1uZMbAAAAFE"]
[Thu Jul 30 12:07:42.690364 2026] [security2:error] [pid 643253:tid 643406] [client 20.52.125.110:6657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/acme-challenge/moon.php"] [unique_id "amuE3sjqbtjBYzqM1uZMbQAAABY"]
[Thu Jul 30 12:07:42.802501 2026] [security2:error] [pid 643253:tid 643470] [client 68.221.186.136:38262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/class-wp-image.php"] [unique_id "amuE3sjqbtjBYzqM1uZMcQAAAFY"]
[Thu Jul 30 12:07:42.949182 2026] [security2:error] [pid 643253:tid 643479] [client 191.232.199.39:61119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-2019.php"] [unique_id "amuE3sjqbtjBYzqM1uZMdQAAAF8"]
[Thu Jul 30 12:07:43.209205 2026] [security2:error] [pid 643253:tid 643504] [client 20.52.125.110:6677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amuE38jqbtjBYzqM1uZMeQAAAHg"]
[Thu Jul 30 12:07:43.266573 2026] [security2:error] [pid 643253:tid 643388] [client 20.52.125.110:8077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "amuE38jqbtjBYzqM1uZMegAAAAQ"]
[Thu Jul 30 12:07:43.277189 2026] [core:notice] [pid 643253:tid 643475] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:43.281426 2026] [security2:error] [pid 643253:tid 643475] [client 103.215.74.26:17058] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE38jqbtjBYzqM1uZMewAAAFs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:43.361624 2026] [security2:error] [pid 643253:tid 643500] [client 68.221.186.136:26089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/classsmtps.php"] [unique_id "amuE38jqbtjBYzqM1uZMgQAAAHQ"]
[Thu Jul 30 12:07:43.630202 2026] [security2:error] [pid 643253:tid 643443] [client 20.203.142.71:35599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/admin.php"] [unique_id "amuE38jqbtjBYzqM1uZMiAAAADs"]
[Thu Jul 30 12:07:43.630305 2026] [security2:error] [pid 643253:tid 643443] [client 20.203.142.71:35599] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/admin.php"] [unique_id "amuE38jqbtjBYzqM1uZMiAAAADs"]
[Thu Jul 30 12:07:43.632479 2026] [security2:error] [pid 643253:tid 643440] [client 20.52.125.110:6981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "amuE38jqbtjBYzqM1uZMiQAAADg"]
[Thu Jul 30 12:07:43.838268 2026] [security2:error] [pid 643253:tid 643389] [client 20.52.125.110:8482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/acme-challenge/classsmtps.php"] [unique_id "amuE38jqbtjBYzqM1uZMjgAAAAU"]
[Thu Jul 30 12:07:44.030891 2026] [core:notice] [pid 643253:tid 643476] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:44.035233 2026] [security2:error] [pid 643253:tid 643476] [client 103.215.74.26:17066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE4MjqbtjBYzqM1uZMlgAAAFw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:44.164278 2026] [security2:error] [pid 643253:tid 643421] [client 20.52.125.110:6704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "amuE4MjqbtjBYzqM1uZMlwAAACU"]
[Thu Jul 30 12:07:44.424693 2026] [security2:error] [pid 643253:tid 643394] [client 20.52.125.110:8508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "amuE4MjqbtjBYzqM1uZMoAAAAAo"]
[Thu Jul 30 12:07:44.654088 2026] [security2:error] [pid 643253:tid 643484] [client 20.52.125.110:7136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/amaxx.php"] [unique_id "amuE4MjqbtjBYzqM1uZMxAAAAGQ"]
[Thu Jul 30 12:07:44.750819 2026] [core:notice] [pid 643253:tid 643427] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:44.756890 2026] [security2:error] [pid 643253:tid 643427] [client 103.215.74.26:17078] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE4MjqbtjBYzqM1uZMxgAAACs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:44.767220 2026] [security2:error] [pid 643253:tid 643451] [client 20.203.142.71:29337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/adminner.php"] [unique_id "amuE4MjqbtjBYzqM1uZMxwAAAEM"]
[Thu Jul 30 12:07:44.767372 2026] [security2:error] [pid 643253:tid 643451] [client 20.203.142.71:29337] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/adminner.php"] [unique_id "amuE4MjqbtjBYzqM1uZMxwAAAEM"]
[Thu Jul 30 12:07:44.994199 2026] [security2:error] [pid 643253:tid 643458] [client 20.52.125.110:8501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/acme-challenge/doc.php"] [unique_id "amuE4MjqbtjBYzqM1uZM0gAAAEo"]
[Thu Jul 30 12:07:45.119147 2026] [security2:error] [pid 643253:tid 643388] [client 20.52.125.110:6682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/bek.php"] [unique_id "amuE4cjqbtjBYzqM1uZM1gAAAAQ"]
[Thu Jul 30 12:07:45.333447 2026] [security2:error] [pid 643253:tid 643492] [client 191.232.199.39:19724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/hoot.php"] [unique_id "amuE4cjqbtjBYzqM1uZM5gAAAGw"]
[Thu Jul 30 12:07:45.396462 2026] [security2:error] [pid 643253:tid 643428] [client 20.226.5.174:33677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/f7.php"] [unique_id "amuE4cjqbtjBYzqM1uZM6gAAACw"]
[Thu Jul 30 12:07:45.480258 2026] [core:notice] [pid 643253:tid 643423] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:45.484531 2026] [security2:error] [pid 643253:tid 643423] [client 103.215.74.26:17080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE4cjqbtjBYzqM1uZM7gAAACc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:45.602120 2026] [security2:error] [pid 643253:tid 643433] [client 20.52.125.110:8478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/acme-challenge/fond.php"] [unique_id "amuE4cjqbtjBYzqM1uZM9QAAADE"]
[Thu Jul 30 12:07:45.659224 2026] [security2:error] [pid 643253:tid 643384] [client 20.52.125.110:6662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/caches.php.suspected"] [unique_id "amuE4cjqbtjBYzqM1uZM9gAAAAA"]
[Thu Jul 30 12:07:46.136328 2026] [security2:error] [pid 643253:tid 643505] [client 20.52.125.110:7113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/class.api.php"] [unique_id "amuE4sjqbtjBYzqM1uZNAwAAAHk"]
[Thu Jul 30 12:07:46.144160 2026] [security2:error] [pid 643253:tid 643501] [client 20.52.125.110:8504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "amuE4sjqbtjBYzqM1uZNBAAAAHU"]
[Thu Jul 30 12:07:46.208191 2026] [security2:error] [pid 643253:tid 643430] [client 14.177.3.227:38137] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuE4cjqbtjBYzqM1uZM-QAAAC4"], referer: http://pkf.jo
[Thu Jul 30 12:07:46.612740 2026] [security2:error] [pid 643253:tid 643447] [client 20.52.125.110:6990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/cong.php"] [unique_id "amuE4sjqbtjBYzqM1uZNEQAAAD8"]
[Thu Jul 30 12:07:46.654245 2026] [security2:error] [pid 643253:tid 643396] [client 20.52.125.110:8214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/acme-challenge/license.php"] [unique_id "amuE4sjqbtjBYzqM1uZNEgAAAAw"]
[Thu Jul 30 12:07:47.025387 2026] [security2:error] [pid 643253:tid 643480] [client 20.52.125.110:7135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/content.php"] [unique_id "amuE48jqbtjBYzqM1uZNGgAAAGA"]
[Thu Jul 30 12:07:47.083460 2026] [security2:error] [pid 643253:tid 643442] [client 20.203.142.71:4329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/a.php"] [unique_id "amuE48jqbtjBYzqM1uZNHgAAADo"]
[Thu Jul 30 12:07:47.083565 2026] [security2:error] [pid 643253:tid 643442] [client 20.203.142.71:4329] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/a.php"] [unique_id "amuE48jqbtjBYzqM1uZNHgAAADo"]
[Thu Jul 30 12:07:47.142210 2026] [security2:error] [pid 643253:tid 643489] [client 20.52.125.110:8208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/acme-challenge/mariju.php"] [unique_id "amuE48jqbtjBYzqM1uZNHwAAAGk"]
[Thu Jul 30 12:07:47.246653 2026] [security2:error] [pid 643253:tid 643495] [client 185.191.171.1:12702] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "online-hope.com"] [uri "/robots.txt"] [unique_id "amuE48jqbtjBYzqM1uZNIAAAAG8"]
[Thu Jul 30 12:07:47.246786 2026] [security2:error] [pid 643253:tid 643495] [client 185.191.171.1:12702] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "online-hope.com"] [uri "/robots.txt"] [unique_id "amuE48jqbtjBYzqM1uZNIAAAAG8"]
[Thu Jul 30 12:07:47.510165 2026] [security2:error] [pid 643253:tid 643486] [client 20.52.125.110:7125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/cwianpri.php"] [unique_id "amuE48jqbtjBYzqM1uZNJwAAAGY"]
[Thu Jul 30 12:07:47.744749 2026] [security2:error] [pid 643253:tid 643386] [client 20.52.125.110:8505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/acme-challenge/moon.php"] [unique_id "amuE48jqbtjBYzqM1uZNLwAAAAI"]
[Thu Jul 30 12:07:47.986625 2026] [security2:error] [pid 643253:tid 643426] [client 20.52.125.110:6659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/elp.php"] [unique_id "amuE48jqbtjBYzqM1uZNMQAAACo"]
[Thu Jul 30 12:07:48.223338 2026] [security2:error] [pid 643253:tid 643457] [client 20.52.125.110:8251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amuE5MjqbtjBYzqM1uZNOwAAAEk"]
[Thu Jul 30 12:07:48.436675 2026] [security2:error] [pid 643253:tid 643419] [client 20.52.125.110:7166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/kwggvpup.php"] [unique_id "amuE5MjqbtjBYzqM1uZNPAAAACM"]
[Thu Jul 30 12:07:48.644432 2026] [security2:error] [pid 643253:tid 643459] [client 185.191.171.2:53894] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "online-hope.com"] [uri "/product-tag/hope-%E5%B8%8C%E6%9C%9B%E9%A6%99%E7%85%9914mg%E6%97%A5%E6%9C%AC%E6%9C%AC%E5%9C%9F%E5%85%8D%E7%A8%85%E9%A6%99%E6%B8%AF%E7%8F%BE%E8%B2%A8/"] [unique_id "amuE5MjqbtjBYzqM1uZNSQAAAEs"]
[Thu Jul 30 12:07:48.644764 2026] [security2:error] [pid 643253:tid 643459] [client 185.191.171.2:53894] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "online-hope.com"] [uri "/product-tag/hope-%E5%B8%8C%E6%9C%9B%E9%A6%99%E7%85%9914mg%E6%97%A5%E6%9C%AC%E6%9C%AC%E5%9C%9F%E5%85%8D%E7%A8%85%E9%A6%99%E6%B8%AF%E7%8F%BE%E8%B2%A8/"] [unique_id "amuE5MjqbtjBYzqM1uZNSQAAAEs"]
[Thu Jul 30 12:07:48.784218 2026] [security2:error] [pid 643253:tid 643444] [client 20.52.125.110:8460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "amuE5MjqbtjBYzqM1uZNSwAAADw"]
[Thu Jul 30 12:07:48.896728 2026] [security2:error] [pid 643253:tid 643484] [client 20.52.125.110:7134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/101d2ae2-f2f3-4977-b35d-b3a0ad74a469.php"] [unique_id "amuE5MjqbtjBYzqM1uZNTAAAAGQ"]
[Thu Jul 30 12:07:48.990600 2026] [security2:error] [pid 643253:tid 643298] [remote 57.141.0.13:48086] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "thdinfinity.com"] [uri "/search/706661964/feed/rss2/"] [unique_id "amuE5MjqbtjBYzqM1uZNTgAAUys"]
[Thu Jul 30 12:07:49.023801 2026] [core:notice] [pid 643253:tid 643260] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:49.271185 2026] [security2:error] [pid 643253:tid 643411] [client 20.52.125.110:8456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "amuE5cjqbtjBYzqM1uZNWgAAABs"]
[Thu Jul 30 12:07:49.463996 2026] [security2:error] [pid 643253:tid 643495] [client 20.52.125.110:7167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/LA.php"] [unique_id "amuE5cjqbtjBYzqM1uZNXwAAAG8"]
[Thu Jul 30 12:07:49.804366 2026] [security2:error] [pid 643253:tid 643445] [client 20.52.125.110:8493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/amaxx.php"] [unique_id "amuE5cjqbtjBYzqM1uZNawAAAD0"]
[Thu Jul 30 12:07:49.813735 2026] [security2:error] [pid 643253:tid 643497] [client 191.232.199.39:61082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/log.php"] [unique_id "amuE5cjqbtjBYzqM1uZNbAAAAHE"]
[Thu Jul 30 12:07:49.968838 2026] [security2:error] [pid 643253:tid 643426] [client 20.52.125.110:7151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/Newsupway.php"] [unique_id "amuE5cjqbtjBYzqM1uZNbQAAACo"]
[Thu Jul 30 12:07:50.362503 2026] [security2:error] [pid 643253:tid 643505] [client 20.52.125.110:8494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/bek.php"] [unique_id "amuE5sjqbtjBYzqM1uZNeAAAAHk"]
[Thu Jul 30 12:07:50.420034 2026] [security2:error] [pid 643253:tid 643503] [client 2a03:2880:f800:1e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuE5cjqbtjBYzqM1uZNagAAd0g"]
[Thu Jul 30 12:07:50.486507 2026] [security2:error] [pid 643253:tid 643408] [client 20.52.125.110:7139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/a.php"] [unique_id "amuE5sjqbtjBYzqM1uZNeQAAABg"]
[Thu Jul 30 12:07:50.790018 2026] [core:notice] [pid 643253:tid 643302] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:50.793788 2026] [security2:error] [pid 643253:tid 643422] [client 47.128.96.150:49434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/HERMENEUTIKA/article/view/9559"] [unique_id "amuE5sjqbtjBYzqM1uZNfQAAJi8"]
[Thu Jul 30 12:07:50.858305 2026] [core:notice] [pid 643253:tid 643434] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:50.924007 2026] [security2:error] [pid 643253:tid 643511] [client 20.52.125.110:8454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/caches.php.suspected"] [unique_id "amuE5sjqbtjBYzqM1uZNhgAAAH8"]
[Thu Jul 30 12:07:50.941414 2026] [security2:error] [pid 643253:tid 643506] [client 20.52.125.110:6694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "amuE5sjqbtjBYzqM1uZNhwAAAHo"]
[Thu Jul 30 12:07:51.096916 2026] [core:notice] [pid 643253:tid 643286] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:51.224834 2026] [core:notice] [pid 643253:tid 643480] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:51.229322 2026] [security2:error] [pid 643253:tid 643480] [client 103.215.74.26:17082] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE58jqbtjBYzqM1uZNjwAAAGA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:51.238438 2026] [core:notice] [pid 643253:tid 643278] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:51.238557 2026] [core:notice] [pid 643253:tid 643276] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:51.389679 2026] [security2:error] [pid 643253:tid 643449] [client 20.52.125.110:6667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/amaxx.php"] [unique_id "amuE58jqbtjBYzqM1uZNlwAAAEE"]
[Thu Jul 30 12:07:51.472405 2026] [security2:error] [pid 643253:tid 643507] [client 20.52.125.110:8206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/class.api.php"] [unique_id "amuE58jqbtjBYzqM1uZNmwAAAHs"]
[Thu Jul 30 12:07:51.794282 2026] [security2:error] [pid 643253:tid 643445] [client 20.52.125.110:7165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/bb.php"] [unique_id "amuE58jqbtjBYzqM1uZNqgAAAD0"]
[Thu Jul 30 12:07:51.864890 2026] [core:error] [pid 643253:tid 643476] [client 66.249.79.199:38810] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:07:51.864910 2026] [core:error] [pid 643253:tid 643476] [client 66.249.79.199:38810] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:07:51.965370 2026] [security2:error] [pid 643253:tid 643478] [client 20.52.125.110:8474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/cong.php"] [unique_id "amuE58jqbtjBYzqM1uZNrQAAAF4"]
[Thu Jul 30 12:07:51.966422 2026] [core:notice] [pid 643253:tid 643498] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:51.970661 2026] [security2:error] [pid 643253:tid 643498] [client 103.215.74.26:17090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE58jqbtjBYzqM1uZNrAAAAHI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:52.181204 2026] [security2:error] [pid 643253:tid 643328] [remote 57.141.0.61:26162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Grageman/announcement"] [unique_id "amuE6MjqbtjBYzqM1uZNsgAAeUk"]
[Thu Jul 30 12:07:52.220486 2026] [security2:error] [pid 643253:tid 643387] [client 20.52.125.110:7119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/cifcxgxm.php"] [unique_id "amuE6MjqbtjBYzqM1uZNswAAAAM"]
[Thu Jul 30 12:07:52.355781 2026] [security2:error] [pid 643253:tid 643493] [client 20.203.142.71:33872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/k.php"] [unique_id "amuE6MjqbtjBYzqM1uZNugAAAG0"]
[Thu Jul 30 12:07:52.355885 2026] [security2:error] [pid 643253:tid 643493] [client 20.203.142.71:33872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/k.php"] [unique_id "amuE6MjqbtjBYzqM1uZNugAAAG0"]
[Thu Jul 30 12:07:52.505047 2026] [security2:error] [pid 643253:tid 643465] [client 20.52.125.110:8491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/content.php"] [unique_id "amuE6MjqbtjBYzqM1uZNuwAAAFE"]
[Thu Jul 30 12:07:52.708403 2026] [security2:error] [pid 643253:tid 643510] [client 20.52.125.110:7126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/ckyocyyp.php"] [unique_id "amuE6MjqbtjBYzqM1uZNvwAAAH4"]
[Thu Jul 30 12:07:52.717356 2026] [core:notice] [pid 643253:tid 643463] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:52.721696 2026] [security2:error] [pid 643253:tid 643463] [client 103.215.74.26:17104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE6MjqbtjBYzqM1uZNwAAAAE8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:52.749764 2026] [security2:error] [pid 643253:tid 643425] [client 191.232.199.39:19718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/bak.php"] [unique_id "amuE6MjqbtjBYzqM1uZNwQAAACk"]
[Thu Jul 30 12:07:53.026647 2026] [security2:error] [pid 643253:tid 643388] [client 20.52.125.110:8500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/cwianpri.php"] [unique_id "amuE6cjqbtjBYzqM1uZNzgAAAAQ"]
[Thu Jul 30 12:07:53.191248 2026] [security2:error] [pid 643253:tid 643480] [client 20.52.125.110:7147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/classwithtostring.php"] [unique_id "amuE6cjqbtjBYzqM1uZNzwAAAGA"]
[Thu Jul 30 12:07:53.261531 2026] [security2:error] [pid 643253:tid 643484] [client 172.213.232.128:55983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/aafewc0k.php"] [unique_id "amuE6cjqbtjBYzqM1uZN0AAAAGQ"]
[Thu Jul 30 12:07:53.484266 2026] [security2:error] [pid 643253:tid 643449] [client 20.52.125.110:8194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/elp.php"] [unique_id "amuE6cjqbtjBYzqM1uZN2AAAAEE"]
[Thu Jul 30 12:07:53.485228 2026] [core:notice] [pid 643253:tid 643431] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:53.489708 2026] [security2:error] [pid 643253:tid 643431] [client 103.215.74.26:54206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE6cjqbtjBYzqM1uZN1wAAAC8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:53.619270 2026] [security2:error] [pid 643253:tid 643433] [client 20.52.125.110:6673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/content.php"] [unique_id "amuE6cjqbtjBYzqM1uZN3gAAADE"]
[Thu Jul 30 12:07:53.984356 2026] [security2:error] [pid 643253:tid 643412] [client 20.52.125.110:8197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/kwggvpup.php"] [unique_id "amuE6cjqbtjBYzqM1uZN5QAAABw"]
[Thu Jul 30 12:07:54.010946 2026] [security2:error] [pid 643253:tid 643347] [remote 216.73.216.152:36206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuE6sjqbtjBYzqM1uZN5gAAClw"]
[Thu Jul 30 12:07:54.146896 2026] [security2:error] [pid 643253:tid 643497] [client 172.213.232.128:55548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/abcd.php"] [unique_id "amuE6sjqbtjBYzqM1uZN6AAAAHE"]
[Thu Jul 30 12:07:54.170546 2026] [security2:error] [pid 643253:tid 643478] [client 20.52.125.110:7199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/content.php.suspected"] [unique_id "amuE6sjqbtjBYzqM1uZN6QAAAF4"]
[Thu Jul 30 12:07:54.219903 2026] [core:notice] [pid 643253:tid 643485] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:54.226378 2026] [security2:error] [pid 643253:tid 643485] [client 103.215.74.26:54210] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE6sjqbtjBYzqM1uZN6wAAAGU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:54.523837 2026] [security2:error] [pid 643253:tid 643461] [client 20.52.125.110:8226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/101d2ae2-f2f3-4977-b35d-b3a0ad74a469.php"] [unique_id "amuE6sjqbtjBYzqM1uZN9AAAAE0"]
[Thu Jul 30 12:07:54.613547 2026] [security2:error] [pid 643253:tid 643429] [client 20.52.125.110:6832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/doc.php"] [unique_id "amuE6sjqbtjBYzqM1uZN9gAAAC0"]
[Thu Jul 30 12:07:54.807070 2026] [security2:error] [pid 643253:tid 643424] [client 2a03:2880:f800:3a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuE6sjqbtjBYzqM1uZN6gAAKFk"]
[Thu Jul 30 12:07:54.983361 2026] [core:notice] [pid 643253:tid 643479] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:54.989848 2026] [security2:error] [pid 643253:tid 643479] [client 103.215.74.26:54214] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE6sjqbtjBYzqM1uZN_QAAAF8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:54.993384 2026] [security2:error] [pid 643253:tid 643465] [client 20.52.125.110:8502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/LA.php"] [unique_id "amuE6sjqbtjBYzqM1uZN_gAAAFE"]
[Thu Jul 30 12:07:55.199747 2026] [security2:error] [pid 643253:tid 643506] [client 20.52.125.110:7185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/fond.php"] [unique_id "amuE68jqbtjBYzqM1uZOBgAAAHo"]
[Thu Jul 30 12:07:55.378745 2026] [security2:error] [pid 643253:tid 643413] [client 172.213.232.128:55530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/about.php"] [unique_id "amuE68jqbtjBYzqM1uZOBwAAAB0"]
[Thu Jul 30 12:07:55.538078 2026] [security2:error] [pid 643253:tid 643388] [client 20.52.125.110:8202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/Newsupway.php"] [unique_id "amuE68jqbtjBYzqM1uZOEAAAAAQ"]
[Thu Jul 30 12:07:55.625485 2026] [security2:error] [pid 643253:tid 643484] [client 20.52.125.110:7173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/gkiliuew.php"] [unique_id "amuE68jqbtjBYzqM1uZOEgAAAGQ"]
[Thu Jul 30 12:07:55.725209 2026] [core:notice] [pid 643253:tid 643481] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:55.729521 2026] [security2:error] [pid 643253:tid 643481] [client 103.215.74.26:54228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE68jqbtjBYzqM1uZOEwAAAGE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:56.029347 2026] [security2:error] [pid 643253:tid 643334] [remote 216.73.216.152:36206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuE7MjqbtjBYzqM1uZOFwAAJU8"]
[Thu Jul 30 12:07:56.126899 2026] [security2:error] [pid 643253:tid 643386] [client 20.52.125.110:6837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/iR7SzrsOUEP.php"] [unique_id "amuE7MjqbtjBYzqM1uZOGwAAAAI"]
[Thu Jul 30 12:07:56.167449 2026] [security2:error] [pid 643253:tid 643390] [client 20.52.125.110:8207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/a.php"] [unique_id "amuE7MjqbtjBYzqM1uZOHAAAAAY"]
[Thu Jul 30 12:07:56.182912 2026] [security2:error] [pid 643253:tid 643392] [client 191.232.199.39:19739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/content.php"] [unique_id "amuE7MjqbtjBYzqM1uZOHQAAAAg"]
[Thu Jul 30 12:07:56.446579 2026] [core:notice] [pid 643253:tid 643412] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:56.450508 2026] [security2:error] [pid 643253:tid 643412] [client 103.215.74.26:54232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE7MjqbtjBYzqM1uZOHgAAABw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:56.567001 2026] [security2:error] [pid 643253:tid 643474] [client 20.52.125.110:6798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/ibkejxnu.php"] [unique_id "amuE7MjqbtjBYzqM1uZOKgAAAFo"]
[Thu Jul 30 12:07:56.625371 2026] [security2:error] [pid 643253:tid 643439] [client 213.152.187.215:44550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.187.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuE7MjqbtjBYzqM1uZOKwAAADc"]
[Thu Jul 30 12:07:56.625453 2026] [security2:error] [pid 643253:tid 643439] [client 213.152.187.215:44550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuE7MjqbtjBYzqM1uZOKwAAADc"]
[Thu Jul 30 12:07:56.676038 2026] [security2:error] [pid 643253:tid 643461] [client 20.52.125.110:8468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "amuE7MjqbtjBYzqM1uZOLAAAAE0"]
[Thu Jul 30 12:07:56.809262 2026] [security2:error] [pid 643253:tid 643387] [client 172.213.232.128:55534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/admin.php"] [unique_id "amuE7MjqbtjBYzqM1uZOLQAAAAM"]
[Thu Jul 30 12:07:57.071997 2026] [security2:error] [pid 643253:tid 643434] [client 20.52.125.110:6838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/install.php"] [unique_id "amuE7cjqbtjBYzqM1uZONQAAADI"]
[Thu Jul 30 12:07:57.117147 2026] [security2:error] [pid 643253:tid 643464] [client 68.221.186.136:34678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/classwithtostring.php"] [unique_id "amuE7cjqbtjBYzqM1uZONwAAAFA"]
[Thu Jul 30 12:07:57.162539 2026] [core:notice] [pid 643253:tid 643511] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:57.169304 2026] [security2:error] [pid 643253:tid 643511] [client 103.215.74.26:54240] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE7cjqbtjBYzqM1uZOOgAAAH8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:57.294361 2026] [security2:error] [pid 643253:tid 643420] [client 20.52.125.110:8497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/amaxx.php"] [unique_id "amuE7cjqbtjBYzqM1uZOOwAAACQ"]
[Thu Jul 30 12:07:57.347068 2026] [security2:error] [pid 643253:tid 643399] [client 14.237.140.74:51685] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuE7cjqbtjBYzqM1uZONAAAAA8"], referer: http://pkf.jo
[Thu Jul 30 12:07:57.529367 2026] [security2:error] [pid 643253:tid 643388] [client 172.213.232.128:55959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/adminfuns.php"] [unique_id "amuE7cjqbtjBYzqM1uZOQAAAAAQ"]
[Thu Jul 30 12:07:57.624337 2026] [security2:error] [pid 643253:tid 643384] [client 20.52.125.110:6795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/lang-load-role.php"] [unique_id "amuE7cjqbtjBYzqM1uZORwAAAAA"]
[Thu Jul 30 12:07:57.771162 2026] [security2:error] [pid 643253:tid 643277] [remote 74.7.241.60:57394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/article.php"] [unique_id "amuE7cjqbtjBYzqM1uZOSQAASBY"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/main_image_6a3229a631e84.jpg
[Thu Jul 30 12:07:57.790529 2026] [security2:error] [pid 643253:tid 643386] [client 20.52.125.110:8103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/bb.php"] [unique_id "amuE7cjqbtjBYzqM1uZOSgAAAAI"]
[Thu Jul 30 12:07:57.894734 2026] [core:notice] [pid 643253:tid 643394] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:57.899161 2026] [security2:error] [pid 643253:tid 643394] [client 103.215.74.26:54244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE7cjqbtjBYzqM1uZOSwAAAAo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:58.027257 2026] [security2:error] [pid 643253:tid 643395] [client 191.232.199.39:61077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/upfile.php"] [unique_id "amuE7sjqbtjBYzqM1uZOTQAAAAs"]
[Thu Jul 30 12:07:58.128587 2026] [security2:error] [pid 643253:tid 643473] [client 20.52.125.110:6826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/link.php"] [unique_id "amuE7sjqbtjBYzqM1uZOVwAAAFk"]
[Thu Jul 30 12:07:58.320863 2026] [security2:error] [pid 643253:tid 643424] [client 20.52.125.110:8511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/cifcxgxm.php"] [unique_id "amuE7sjqbtjBYzqM1uZOWwAAACg"]
[Thu Jul 30 12:07:58.560913 2026] [security2:error] [pid 643253:tid 643432] [client 172.213.232.128:55977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/albin.php"] [unique_id "amuE7sjqbtjBYzqM1uZOYAAAADA"]
[Thu Jul 30 12:07:58.627284 2026] [core:notice] [pid 643253:tid 643393] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:58.632534 2026] [security2:error] [pid 643253:tid 643393] [client 103.215.74.26:54260] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE7sjqbtjBYzqM1uZOZgAAAAk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:58.648749 2026] [security2:error] [pid 643253:tid 643425] [client 20.52.125.110:6834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/mar.php"] [unique_id "amuE7sjqbtjBYzqM1uZOaAAAACk"]
[Thu Jul 30 12:07:58.854949 2026] [security2:error] [pid 643253:tid 643418] [client 20.52.125.110:8484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/ckyocyyp.php"] [unique_id "amuE7sjqbtjBYzqM1uZOaQAAACI"]
[Thu Jul 30 12:07:59.189140 2026] [security2:error] [pid 643253:tid 643504] [client 172.213.232.128:55971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/amfsqvgv.php"] [unique_id "amuE78jqbtjBYzqM1uZObgAAAHg"]
[Thu Jul 30 12:07:59.195347 2026] [security2:error] [pid 643253:tid 643509] [client 20.52.125.110:6817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "amuE78jqbtjBYzqM1uZObwAAAH0"]
[Thu Jul 30 12:07:59.362068 2026] [core:notice] [pid 643253:tid 643502] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:59.366495 2026] [security2:error] [pid 643253:tid 643502] [client 103.215.74.26:54270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE78jqbtjBYzqM1uZOcwAAAHY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:59.445340 2026] [security2:error] [pid 643253:tid 643423] [client 20.52.125.110:8200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/classwithtostring.php"] [unique_id "amuE78jqbtjBYzqM1uZOdgAAACc"]
[Thu Jul 30 12:07:59.630565 2026] [security2:error] [pid 643253:tid 643471] [client 20.52.125.110:7178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "amuE78jqbtjBYzqM1uZOeAAAAFc"]
[Thu Jul 30 12:07:59.837568 2026] [security2:error] [pid 643253:tid 643489] [client 191.232.199.39:61061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/bypass.php"] [unique_id "amuE78jqbtjBYzqM1uZOgAAAAGk"]
[Thu Jul 30 12:08:00.004601 2026] [security2:error] [pid 643253:tid 643392] [client 20.52.125.110:8475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/content.php"] [unique_id "amuE8MjqbtjBYzqM1uZOgQAAAAg"]
[Thu Jul 30 12:08:00.098620 2026] [core:notice] [pid 643253:tid 643437] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:00.103336 2026] [security2:error] [pid 643253:tid 643437] [client 103.215.74.26:54274] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE8MjqbtjBYzqM1uZOgwAAADU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:00.103507 2026] [security2:error] [pid 643253:tid 643476] [client 20.52.125.110:6833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/plugins.php"] [unique_id "amuE8MjqbtjBYzqM1uZOhAAAAFw"]
[Thu Jul 30 12:08:00.188437 2026] [security2:error] [pid 643253:tid 643498] [client 172.213.232.128:55963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/ant.php"] [unique_id "amuE8MjqbtjBYzqM1uZOiAAAAHI"]
[Thu Jul 30 12:08:00.263192 2026] [core:notice] [pid 643253:tid 643449] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:00.317438 2026] [security2:error] [pid 643253:tid 643441] [client 68.221.186.136:34187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/config.php"] [unique_id "amuE8MjqbtjBYzqM1uZOjwAAADk"]
[Thu Jul 30 12:08:00.577094 2026] [security2:error] [pid 643253:tid 643419] [client 20.52.125.110:6808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/post.php"] [unique_id "amuE8MjqbtjBYzqM1uZOkAAAACM"]
[Thu Jul 30 12:08:00.597017 2026] [security2:error] [pid 643253:tid 643444] [client 2.90.102.171:44272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuE8MjqbtjBYzqM1uZOjgAAADw"], referer: http://pkf.jo
[Thu Jul 30 12:08:00.785101 2026] [security2:error] [pid 643253:tid 643446] [client 20.52.125.110:8490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/content.php.suspected"] [unique_id "amuE8MjqbtjBYzqM1uZOmAAAAD4"]
[Thu Jul 30 12:08:00.879238 2026] [core:notice] [pid 643253:tid 643424] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:00.886632 2026] [security2:error] [pid 643253:tid 643424] [client 103.215.74.26:54278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE8MjqbtjBYzqM1uZOmwAAACg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:01.029848 2026] [security2:error] [pid 643253:tid 643479] [client 20.52.125.110:6802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/shell.php"] [unique_id "amuE8cjqbtjBYzqM1uZOnwAAAF8"]
[Thu Jul 30 12:08:01.454592 2026] [security2:error] [pid 643253:tid 643492] [client 20.52.125.110:8455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/doc.php"] [unique_id "amuE8cjqbtjBYzqM1uZOpwAAAGw"]
[Thu Jul 30 12:08:01.512822 2026] [security2:error] [pid 643253:tid 643420] [client 20.52.125.110:6792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/ssl.php"] [unique_id "amuE8cjqbtjBYzqM1uZOqQAAACQ"]
[Thu Jul 30 12:08:01.533059 2026] [security2:error] [pid 643253:tid 643404] [client 172.213.232.128:55972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/appreciators.php"] [unique_id "amuE8cjqbtjBYzqM1uZOqgAAABQ"]
[Thu Jul 30 12:08:01.648361 2026] [core:notice] [pid 643253:tid 643399] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:01.654930 2026] [security2:error] [pid 643253:tid 643399] [client 103.215.74.26:54284] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE8cjqbtjBYzqM1uZOqwAAAA8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:01.683583 2026] [security2:error] [pid 643253:tid 643442] [client 250.49.135.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuE8MjqbtjBYzqM1uZOmQAAOjQ"]
[Thu Jul 30 12:08:01.686517 2026] [security2:error] [pid 643253:tid 643387] [client 68.221.186.136:34220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/core.php"] [unique_id "amuE8cjqbtjBYzqM1uZOrAAAAAM"]
[Thu Jul 30 12:08:02.037264 2026] [security2:error] [pid 643253:tid 643483] [client 20.52.125.110:7184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/sx.php"] [unique_id "amuE8sjqbtjBYzqM1uZOtAAAAGM"]
[Thu Jul 30 12:08:02.078463 2026] [security2:error] [pid 643253:tid 643390] [client 20.52.125.110:8495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/fond.php"] [unique_id "amuE8sjqbtjBYzqM1uZOtQAAAAY"]
[Thu Jul 30 12:08:02.290597 2026] [security2:error] [pid 643253:tid 643448] [client 191.232.199.39:59810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/updates.php"] [unique_id "amuE8sjqbtjBYzqM1uZOuQAAAEA"]
[Thu Jul 30 12:08:02.385409 2026] [core:notice] [pid 643253:tid 643437] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:02.392042 2026] [security2:error] [pid 643253:tid 643437] [client 103.215.74.26:54292] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE8sjqbtjBYzqM1uZOvQAAADU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:02.449794 2026] [security2:error] [pid 643253:tid 643386] [client 68.221.186.136:34197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/css.php"] [unique_id "amuE8sjqbtjBYzqM1uZOvwAAAAI"]
[Thu Jul 30 12:08:02.503290 2026] [security2:error] [pid 643253:tid 643397] [client 20.52.125.110:7175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/themes.php"] [unique_id "amuE8sjqbtjBYzqM1uZOwAAAAA0"]
[Thu Jul 30 12:08:02.711658 2026] [security2:error] [pid 643253:tid 643427] [client 20.52.125.110:8204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/gkiliuew.php"] [unique_id "amuE8sjqbtjBYzqM1uZOwgAAACs"]
[Thu Jul 30 12:08:02.989012 2026] [security2:error] [pid 643253:tid 643385] [client 20.52.125.110:7188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/worksec.php"] [unique_id "amuE8sjqbtjBYzqM1uZOyQAAAAE"]
[Thu Jul 30 12:08:03.096242 2026] [security2:error] [pid 643253:tid 643415] [client 172.213.232.128:55504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/archive.php"] [unique_id "amuE88jqbtjBYzqM1uZOywAAAB8"]
[Thu Jul 30 12:08:03.112275 2026] [core:notice] [pid 643253:tid 643467] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:03.116620 2026] [security2:error] [pid 643253:tid 643467] [client 103.215.74.26:23412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE88jqbtjBYzqM1uZOzAAAAFM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:03.287897 2026] [security2:error] [pid 643253:tid 643425] [client 20.52.125.110:8083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/iR7SzrsOUEP.php"] [unique_id "amuE88jqbtjBYzqM1uZOzgAAACk"]
[Thu Jul 30 12:08:03.470595 2026] [security2:error] [pid 643253:tid 643401] [client 20.52.125.110:6793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/wp-admin/install.php"] [unique_id "amuE88jqbtjBYzqM1uZO2AAAABE"]
[Thu Jul 30 12:08:03.626432 2026] [core:notice] [pid 643253:tid 643486] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:03.643751 2026] [security2:error] [pid 643253:tid 643446] [client 68.221.186.136:25969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/database.php"] [unique_id "amuE88jqbtjBYzqM1uZO3QAAAD4"]
[Thu Jul 30 12:08:03.840496 2026] [core:notice] [pid 643253:tid 643469] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:03.842724 2026] [security2:error] [pid 643253:tid 643423] [client 20.52.125.110:8245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/ibkejxnu.php"] [unique_id "amuE88jqbtjBYzqM1uZO4AAAACc"]
[Thu Jul 30 12:08:03.845371 2026] [security2:error] [pid 643253:tid 643469] [client 103.215.74.26:23428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE88jqbtjBYzqM1uZO3wAAAFU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:03.931120 2026] [security2:error] [pid 643253:tid 643481] [client 20.52.125.110:7177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "amuE88jqbtjBYzqM1uZO5AAAAGE"]
[Thu Jul 30 12:08:04.295494 2026] [security2:error] [pid 643253:tid 643488] [client 20.52.125.110:8477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/install.php"] [unique_id "amuE9MjqbtjBYzqM1uZO7AAAAGg"]
[Thu Jul 30 12:08:04.625595 2026] [core:notice] [pid 643253:tid 643443] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:04.632209 2026] [security2:error] [pid 643253:tid 643443] [client 103.215.74.26:23442] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE9MjqbtjBYzqM1uZO9wAAADs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:04.688917 2026] [security2:error] [pid 643253:tid 643455] [client 191.232.199.39:61087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/xmrlpc.php"] [unique_id "amuE9MjqbtjBYzqM1uZO-AAAAEc"]
[Thu Jul 30 12:08:04.698698 2026] [security2:error] [pid 643253:tid 643511] [client 172.213.232.128:55989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/as.php"] [unique_id "amuE9MjqbtjBYzqM1uZO-QAAAH8"]
[Thu Jul 30 12:08:04.709364 2026] [security2:error] [pid 643253:tid 643460] [client 20.52.125.110:8498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/lang-load-role.php"] [unique_id "amuE9MjqbtjBYzqM1uZO-gAAAEw"]
[Thu Jul 30 12:08:04.793648 2026] [security2:error] [pid 643253:tid 643304] [remote 77.46.136.200:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.136.46.77.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "madeninsabah.com"] [uri "/xmlrpc.php"] [unique_id "amuE9MjqbtjBYzqM1uZO8AAAYzE"]
[Thu Jul 30 12:08:04.793897 2026] [security2:error] [pid 643253:tid 643483] [client 77.46.136.200:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "madeninsabah.com"] [uri "/xmlrpc.php"] [unique_id "amuE9MjqbtjBYzqM1uZO8AAAYzE"]
[Thu Jul 30 12:08:05.190293 2026] [security2:error] [pid 643253:tid 643415] [client 20.52.125.110:8451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/link.php"] [unique_id "amuE9cjqbtjBYzqM1uZPBgAAAB8"]
[Thu Jul 30 12:08:05.370068 2026] [core:notice] [pid 643253:tid 643464] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:05.374455 2026] [security2:error] [pid 643253:tid 643464] [client 103.215.74.26:23450] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE9cjqbtjBYzqM1uZPCAAAAFA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:05.472088 2026] [security2:error] [pid 643253:tid 643456] [client 68.221.186.136:35057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/db.php"] [unique_id "amuE9cjqbtjBYzqM1uZPCQAAAEg"]
[Thu Jul 30 12:08:05.612080 2026] [security2:error] [pid 643253:tid 643419] [client 172.213.232.128:55992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/atomlib.php"] [unique_id "amuE9cjqbtjBYzqM1uZPGwAAACM"]
[Thu Jul 30 12:08:05.768261 2026] [security2:error] [pid 643253:tid 643486] [client 20.52.125.110:8008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/mar.php"] [unique_id "amuE9cjqbtjBYzqM1uZPHAAAAGY"]
[Thu Jul 30 12:08:05.949310 2026] [security2:error] [pid 643253:tid 643418] [client 191.232.199.39:59826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/ae.php"] [unique_id "amuE9cjqbtjBYzqM1uZPIwAAACI"]
[Thu Jul 30 12:08:06.114137 2026] [core:notice] [pid 643253:tid 643469] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:06.115300 2026] [security2:error] [pid 643253:tid 643411] [client 57.141.0.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuE9cjqbtjBYzqM1uZPDwAAABs"]
[Thu Jul 30 12:08:06.119071 2026] [security2:error] [pid 643253:tid 643469] [client 103.215.74.26:23464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE9sjqbtjBYzqM1uZPLQAAAFU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:06.141931 2026] [security2:error] [pid 643253:tid 643492] [client 57.141.0.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuE9cjqbtjBYzqM1uZPFgAAAGw"]
[Thu Jul 30 12:08:06.189073 2026] [security2:error] [pid 643253:tid 643508] [client 68.221.186.136:39670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/011i.php"] [unique_id "amuE9sjqbtjBYzqM1uZPLgAAAHw"]
[Thu Jul 30 12:08:06.233878 2026] [security2:error] [pid 643253:tid 643384] [client 20.52.125.110:8220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "amuE9sjqbtjBYzqM1uZPLwAAAAA"]
[Thu Jul 30 12:08:06.513853 2026] [core:notice] [pid 643253:tid 643408] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:06.540087 2026] [security2:error] [pid 643253:tid 643448] [client 68.221.186.136:38550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/default.php"] [unique_id "amuE9sjqbtjBYzqM1uZPMQAAAEA"]
[Thu Jul 30 12:08:06.758218 2026] [security2:error] [pid 643253:tid 643493] [client 20.52.125.110:8066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "amuE9sjqbtjBYzqM1uZPPQAAAG0"]
[Thu Jul 30 12:08:06.852251 2026] [core:notice] [pid 643253:tid 643403] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:06.856592 2026] [security2:error] [pid 643253:tid 643403] [client 103.215.74.26:23474] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE9sjqbtjBYzqM1uZPQQAAABM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:07.298348 2026] [security2:error] [pid 643253:tid 643447] [client 172.213.232.128:55499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/autoload_classmap.php"] [unique_id "amuE98jqbtjBYzqM1uZPTAAAAD8"]
[Thu Jul 30 12:08:07.298472 2026] [security2:error] [pid 643253:tid 643389] [client 20.52.125.110:8215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/plugins.php"] [unique_id "amuE98jqbtjBYzqM1uZPTQAAAAU"]
[Thu Jul 30 12:08:07.577348 2026] [core:notice] [pid 643253:tid 643417] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:07.581664 2026] [security2:error] [pid 643253:tid 643417] [client 103.215.74.26:23482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE98jqbtjBYzqM1uZPVgAAACE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:07.605746 2026] [security2:error] [pid 643253:tid 643496] [client 185.189.112.11:43884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.112.189.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuE98jqbtjBYzqM1uZPWAAAAHA"]
[Thu Jul 30 12:08:07.605868 2026] [security2:error] [pid 643253:tid 643496] [client 185.189.112.11:43884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuE98jqbtjBYzqM1uZPWAAAAHA"]
[Thu Jul 30 12:08:07.632684 2026] [security2:error] [pid 643253:tid 643398] [client 191.232.199.39:41229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/moon.php"] [unique_id "amuE98jqbtjBYzqM1uZPWQAAAA4"]
[Thu Jul 30 12:08:07.814525 2026] [security2:error] [pid 643253:tid 643392] [client 20.52.125.110:8212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/post.php"] [unique_id "amuE98jqbtjBYzqM1uZPYAAAAAg"]
[Thu Jul 30 12:08:07.877196 2026] [security2:error] [pid 643253:tid 643428] [client 172.213.232.128:55527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/bb.php"] [unique_id "amuE98jqbtjBYzqM1uZPYgAAACw"]
[Thu Jul 30 12:08:08.157175 2026] [security2:error] [pid 643253:tid 643435] [client 50.6.43.217:12776] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuE-MjqbtjBYzqM1uZPbAAAADM"]
[Thu Jul 30 12:08:08.181950 2026] [security2:error] [pid 643253:tid 643409] [client 50.6.43.217:12788] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuE-MjqbtjBYzqM1uZPbQAAABk"]
[Thu Jul 30 12:08:08.216043 2026] [security2:error] [pid 643253:tid 643391] [client 57.141.0.64:58368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuE98jqbtjBYzqM1uZPYQAAB0Y"], referer: https://igetvape-australia.com/product-tag/alibarbar-ice-adjust-12000-puffs-blueberry-blast/
[Thu Jul 30 12:08:08.316004 2026] [core:notice] [pid 643253:tid 643397] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:08.320318 2026] [security2:error] [pid 643253:tid 643397] [client 103.215.74.26:23496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE-MjqbtjBYzqM1uZPcQAAAA0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:08.401863 2026] [security2:error] [pid 643253:tid 643459] [client 20.52.125.110:8067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/shell.php"] [unique_id "amuE-MjqbtjBYzqM1uZPcgAAAEs"]
[Thu Jul 30 12:08:08.692310 2026] [core:error] [pid 643253:tid 643396] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:08:08.692338 2026] [core:error] [pid 643253:tid 643396] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:08:08.712800 2026] [security2:error] [pid 643253:tid 643386] [client 127.0.0.1:29556] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuE-MjqbtjBYzqM1uZPfQAAAAI"]
[Thu Jul 30 12:08:08.712833 2026] [security2:error] [pid 643253:tid 643468] [client 74.7.175.158:56174] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.aaapropertiesph.com"] [uri "/robots.txt"] [unique_id "amuE-MjqbtjBYzqM1uZPewAAAFQ"]
[Thu Jul 30 12:08:08.731489 2026] [security2:error] [pid 643253:tid 643463] [client 68.221.186.136:31297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/03a005685d.php"] [unique_id "amuE-MjqbtjBYzqM1uZPggAAAE8"]
[Thu Jul 30 12:08:08.871854 2026] [security2:error] [pid 643253:tid 643475] [client 191.232.199.39:61094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/blog.php"] [unique_id "amuE-MjqbtjBYzqM1uZPgwAAAFs"]
[Thu Jul 30 12:08:08.898623 2026] [security2:error] [pid 643253:tid 643456] [client 20.52.125.110:8229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/ssl.php"] [unique_id "amuE-MjqbtjBYzqM1uZPhAAAAEg"]
[Thu Jul 30 12:08:09.103613 2026] [core:notice] [pid 643253:tid 643438] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:09.110374 2026] [security2:error] [pid 643253:tid 643438] [client 103.215.74.26:23502] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE-cjqbtjBYzqM1uZPiQAAADY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:09.162689 2026] [security2:error] [pid 643253:tid 643419] [client 212.193.3.94:65525] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "deltaedu.net"] [uri "/"] [unique_id "amuE-cjqbtjBYzqM1uZPigAAACM"]
[Thu Jul 30 12:08:09.307446 2026] [security2:error] [pid 643253:tid 643418] [client 172.213.232.128:55567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/bnm.php"] [unique_id "amuE-cjqbtjBYzqM1uZPkgAAACI"]
[Thu Jul 30 12:08:09.340246 2026] [security2:error] [pid 643253:tid 643482] [client 50.6.43.217:55976] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuE-cjqbtjBYzqM1uZPkwAAAGI"]
[Thu Jul 30 12:08:09.353990 2026] [security2:error] [pid 643253:tid 643457] [client 20.52.125.110:8223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/sx.php"] [unique_id "amuE-cjqbtjBYzqM1uZPlAAAAEk"]
[Thu Jul 30 12:08:09.485744 2026] [security2:error] [pid 643253:tid 643496] [client 68.221.186.136:40663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/403.php"] [unique_id "amuE-cjqbtjBYzqM1uZPlgAAAHA"]
[Thu Jul 30 12:08:09.572481 2026] [security2:error] [pid 643253:tid 643388] [client 212.193.3.94:49212] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "deltaedu.net"] [uri "/wp-json/batch/v1"] [unique_id "amuE-cjqbtjBYzqM1uZPmgAAAAQ"]
[Thu Jul 30 12:08:09.576866 2026] [security2:error] [pid 643253:tid 643374] [remote 216.73.216.152:25440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuE-cjqbtjBYzqM1uZPmwAAWnc"]
[Thu Jul 30 12:08:09.747263 2026] [security2:error] [pid 643253:tid 643431] [client 68.221.186.136:34207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/dropdown.php"] [unique_id "amuE-cjqbtjBYzqM1uZPowAAAC8"]
[Thu Jul 30 12:08:09.844535 2026] [core:notice] [pid 643253:tid 643392] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:09.851019 2026] [security2:error] [pid 643253:tid 643392] [client 103.215.74.26:23508] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE-cjqbtjBYzqM1uZPpQAAAAg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:09.968042 2026] [security2:error] [pid 643253:tid 643449] [client 20.52.125.110:8248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/themes.php"] [unique_id "amuE-cjqbtjBYzqM1uZPpgAAAEE"]
[Thu Jul 30 12:08:10.003396 2026] [security2:error] [pid 643253:tid 643505] [client 212.193.3.94:49256] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "deltaedu.net"] [uri "/"] [unique_id "amuE-cjqbtjBYzqM1uZPpwAAAHk"]
[Thu Jul 30 12:08:10.460920 2026] [security2:error] [pid 643253:tid 643413] [client 20.52.125.110:8072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/worksec.php"] [unique_id "amuE-sjqbtjBYzqM1uZPtgAAAB0"]
[Thu Jul 30 12:08:10.573156 2026] [core:notice] [pid 643253:tid 643479] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:10.580242 2026] [security2:error] [pid 643253:tid 643479] [client 103.215.74.26:23514] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE-sjqbtjBYzqM1uZPtwAAAF8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:10.756192 2026] [security2:error] [pid 643253:tid 643503] [client 172.213.232.128:55563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/bootstrap.php"] [unique_id "amuE-sjqbtjBYzqM1uZPwgAAAHc"]
[Thu Jul 30 12:08:10.759392 2026] [security2:error] [pid 643253:tid 643430] [client 50.6.43.217:55988] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuE-sjqbtjBYzqM1uZPwQAAAC4"]
[Thu Jul 30 12:08:10.978700 2026] [security2:error] [pid 643253:tid 643500] [client 20.52.125.110:8496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/wp-admin/install.php"] [unique_id "amuE-sjqbtjBYzqM1uZPxAAAAHQ"]
[Thu Jul 30 12:08:11.324973 2026] [core:notice] [pid 643253:tid 643485] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:11.329423 2026] [security2:error] [pid 643253:tid 643485] [client 103.215.74.26:23518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE-8jqbtjBYzqM1uZP0QAAAGU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:11.427995 2026] [security2:error] [pid 643253:tid 643388] [client 68.221.186.136:30152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/404.php"] [unique_id "amuE-8jqbtjBYzqM1uZP0gAAAAQ"]
[Thu Jul 30 12:08:11.470701 2026] [security2:error] [pid 643253:tid 643510] [client 20.52.125.110:8485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "amuE-8jqbtjBYzqM1uZP0wAAAH4"]
[Thu Jul 30 12:08:11.879520 2026] [security2:error] [pid 643253:tid 643506] [client 172.213.232.128:55590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/buy.php"] [unique_id "amuE-8jqbtjBYzqM1uZP4QAAAHo"]
[Thu Jul 30 12:08:11.902219 2026] [security2:error] [pid 643253:tid 643490] [client 20.52.125.110:12225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/json.php"] [unique_id "amuE-8jqbtjBYzqM1uZP4gAAAGo"]
[Thu Jul 30 12:08:11.905502 2026] [security2:error] [pid 643253:tid 643424] [client 68.221.186.136:46103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/aa.php"] [unique_id "amuE-8jqbtjBYzqM1uZP4wAAACg"]
[Thu Jul 30 12:08:12.059736 2026] [core:notice] [pid 643253:tid 643422] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:12.066301 2026] [security2:error] [pid 643253:tid 643422] [client 103.215.74.26:23528] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE_MjqbtjBYzqM1uZP6AAAACY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:12.600688 2026] [security2:error] [pid 643253:tid 643403] [client 50.6.43.217:59592] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuE_MjqbtjBYzqM1uZP9QAAABM"]
[Thu Jul 30 12:08:12.675650 2026] [security2:error] [pid 643253:tid 643503] [client 172.213.232.128:55571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/chosen.php"] [unique_id "amuE_MjqbtjBYzqM1uZP-AAAAHc"]
[Thu Jul 30 12:08:12.754345 2026] [security2:error] [pid 643253:tid 643468] [client 50.6.43.217:59600] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuE_MjqbtjBYzqM1uZP-QAAAFQ"]
[Thu Jul 30 12:08:12.790831 2026] [core:notice] [pid 643253:tid 643417] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:12.795025 2026] [security2:error] [pid 643253:tid 643417] [client 103.215.74.26:23542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE_MjqbtjBYzqM1uZP_AAAACE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:12.929152 2026] [security2:error] [pid 643253:tid 643478] [client 191.232.199.39:61098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/ini.php"] [unique_id "amuE_MjqbtjBYzqM1uZQAQAAAF4"]
[Thu Jul 30 12:08:13.377660 2026] [security2:error] [pid 643253:tid 643401] [client 68.221.186.136:23762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/aafewc0k.php"] [unique_id "amuE_cjqbtjBYzqM1uZQCwAAABE"]
[Thu Jul 30 12:08:13.409115 2026] [security2:error] [pid 643253:tid 643492] [client 172.213.232.128:55552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/class-wp-image.php"] [unique_id "amuE_cjqbtjBYzqM1uZQDAAAAGw"]
[Thu Jul 30 12:08:13.482198 2026] [security2:error] [pid 643253:tid 643443] [client 50.6.43.217:58480] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/1.jpg"] [unique_id "amuE_cjqbtjBYzqM1uZQDgAAADs"]
[Thu Jul 30 12:08:13.492669 2026] [security2:error] [pid 643253:tid 643429] [client 50.6.43.217:58492] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/2.jpg"] [unique_id "amuE_cjqbtjBYzqM1uZQEQAAAC0"]
[Thu Jul 30 12:08:13.502871 2026] [security2:error] [pid 643253:tid 643449] [client 50.6.43.217:58500] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/3.jpg"] [unique_id "amuE_cjqbtjBYzqM1uZQEwAAAEE"]
[Thu Jul 30 12:08:13.506554 2026] [core:notice] [pid 643253:tid 643400] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:13.514380 2026] [security2:error] [pid 643253:tid 643400] [client 103.215.74.26:59912] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE_cjqbtjBYzqM1uZQFAAAABA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:14.228765 2026] [security2:error] [pid 643253:tid 643456] [client 50.6.43.217:59612] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuE_sjqbtjBYzqM1uZQKAAAAEg"]
[Thu Jul 30 12:08:14.252549 2026] [core:notice] [pid 643253:tid 643422] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:14.259559 2026] [security2:error] [pid 643253:tid 643422] [client 103.215.74.26:59918] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE_sjqbtjBYzqM1uZQKQAAACY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:14.373958 2026] [security2:error] [pid 643253:tid 643438] [client 50.6.43.217:59618] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuE_sjqbtjBYzqM1uZQLQAAADY"]
[Thu Jul 30 12:08:14.659285 2026] [security2:error] [pid 643253:tid 643404] [client 172.213.232.128:55553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/classsmtps.php"] [unique_id "amuE_sjqbtjBYzqM1uZQNQAAABQ"]
[Thu Jul 30 12:08:14.685770 2026] [security2:error] [pid 643253:tid 643423] [client 20.52.125.110:12203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/mini.php"] [unique_id "amuE_sjqbtjBYzqM1uZQNgAAACc"]
[Thu Jul 30 12:08:14.895816 2026] [security2:error] [pid 643253:tid 643477] [client 68.221.186.136:46109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/abcd.php"] [unique_id "amuE_sjqbtjBYzqM1uZQOgAAAF0"]
[Thu Jul 30 12:08:14.967479 2026] [security2:error] [pid 643253:tid 643386] [client 79.106.125.194:42358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuE_sjqbtjBYzqM1uZQIQAAAAI"], referer: http://pkf.jo
[Thu Jul 30 12:08:15.007486 2026] [security2:error] [pid 643253:tid 643458] [client 47.128.22.17:42546] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "moswey.com"] [uri "/robots.txt"] [unique_id "amuE_8jqbtjBYzqM1uZQQAAAAEo"]
[Thu Jul 30 12:08:15.008419 2026] [core:notice] [pid 643253:tid 643407] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:15.014825 2026] [security2:error] [pid 643253:tid 643407] [client 103.215.74.26:59922] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE_8jqbtjBYzqM1uZQPwAAABc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:15.481120 2026] [security2:error] [pid 643253:tid 643505] [client 172.213.232.128:55519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/classwithtostring.php"] [unique_id "amuE_8jqbtjBYzqM1uZQTgAAAHk"]
[Thu Jul 30 12:08:15.746244 2026] [core:notice] [pid 643253:tid 643385] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:15.752797 2026] [security2:error] [pid 643253:tid 643385] [client 103.215.74.26:59938] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE_8jqbtjBYzqM1uZQUwAAAAE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:15.772355 2026] [security2:error] [pid 643253:tid 643467] [client 50.6.43.217:59634] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuE_8jqbtjBYzqM1uZQVAAAAFM"]
[Thu Jul 30 12:08:15.812470 2026] [security2:error] [pid 643253:tid 643429] [client 68.221.186.136:33047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/about.php"] [unique_id "amuE_8jqbtjBYzqM1uZQVQAAAC0"]
[Thu Jul 30 12:08:15.843669 2026] [security2:error] [pid 643253:tid 643399] [client 191.232.199.39:61096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/admin-ajax.php"] [unique_id "amuE_8jqbtjBYzqM1uZQWAAAAA8"]
[Thu Jul 30 12:08:15.932779 2026] [security2:error] [pid 643253:tid 643498] [client 50.6.43.217:59642] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuE_8jqbtjBYzqM1uZQWgAAAHI"]
[Thu Jul 30 12:08:16.042139 2026] [autoindex:error] [pid 643253:tid 643292] [remote 172.239.144.164:51038] AH01276: Cannot serve directory /home2/ubphmute/public_html/website_da8a69f1/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:08:16.460370 2026] [security2:error] [pid 643253:tid 643438] [client 103.76.47.160:41148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuFAMjqbtjBYzqM1uZQZAAAADY"], referer: http://pkf.jo
[Thu Jul 30 12:08:16.479397 2026] [core:notice] [pid 643253:tid 643455] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:16.489972 2026] [security2:error] [pid 643253:tid 643455] [client 103.215.74.26:59952] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFAMjqbtjBYzqM1uZQawAAAEc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:16.886966 2026] [security2:error] [pid 643253:tid 643468] [client 68.221.186.136:33031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/admin.php"] [unique_id "amuFAMjqbtjBYzqM1uZQdAAAAFQ"]
[Thu Jul 30 12:08:17.212705 2026] [core:notice] [pid 643253:tid 643457] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:17.213396 2026] [security2:error] [pid 643253:tid 643404] [client 20.52.125.110:12195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/chosen.php"] [unique_id "amuFAcjqbtjBYzqM1uZQfAAAABQ"]
[Thu Jul 30 12:08:17.218964 2026] [security2:error] [pid 643253:tid 643457] [client 103.215.74.26:59956] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFAcjqbtjBYzqM1uZQewAAAEk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:17.462614 2026] [security2:error] [pid 643253:tid 643508] [client 191.232.199.39:59795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/akc.php"] [unique_id "amuFAcjqbtjBYzqM1uZQhgAAAHw"]
[Thu Jul 30 12:08:17.933728 2026] [core:notice] [pid 643253:tid 643429] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:17.939457 2026] [security2:error] [pid 643253:tid 643429] [client 103.215.74.26:59960] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFAcjqbtjBYzqM1uZQjgAAAC0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:18.000929 2026] [security2:error] [pid 643253:tid 643480] [client 68.221.186.136:33028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/adminfuns.php"] [unique_id "amuFAsjqbtjBYzqM1uZQkgAAAGA"]
[Thu Jul 30 12:08:18.195796 2026] [security2:error] [pid 643253:tid 643413] [client 68.221.186.136:38614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/edit.php"] [unique_id "amuFAsjqbtjBYzqM1uZQmAAAAB0"]
[Thu Jul 30 12:08:18.509747 2026] [core:notice] [pid 643253:tid 643324] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:18.700832 2026] [security2:error] [pid 643253:tid 643493] [client 20.52.125.110:12194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/kj.php"] [unique_id "amuFAsjqbtjBYzqM1uZQowAAAG0"]
[Thu Jul 30 12:08:18.720837 2026] [core:notice] [pid 643253:tid 643430] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:18.727219 2026] [security2:error] [pid 643253:tid 643430] [client 103.215.74.26:59966] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFAsjqbtjBYzqM1uZQpAAAAC4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:19.006896 2026] [security2:error] [pid 643253:tid 643503] [client 68.221.186.136:37974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/f35.php"] [unique_id "amuFA8jqbtjBYzqM1uZQqQAAAHc"]
[Thu Jul 30 12:08:19.043019 2026] [core:notice] [pid 643253:tid 643302] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:19.377465 2026] [security2:error] [pid 643253:tid 643386] [client 20.52.125.110:12212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/wp-files.php"] [unique_id "amuFA8jqbtjBYzqM1uZQsQAAAAI"]
[Thu Jul 30 12:08:19.987749 2026] [security2:error] [pid 643253:tid 643457] [client 185.191.171.3:40544] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2021/04/27/bolsonaro-sanciona-com-vetos-criacao-do-programa-pro-leitos/"] [unique_id "amuFA8jqbtjBYzqM1uZQvAAAAEk"]
[Thu Jul 30 12:08:19.987874 2026] [security2:error] [pid 643253:tid 643457] [client 185.191.171.3:40544] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2021/04/27/bolsonaro-sanciona-com-vetos-criacao-do-programa-pro-leitos/"] [unique_id "amuFA8jqbtjBYzqM1uZQvAAAAEk"]
[Thu Jul 30 12:08:20.239084 2026] [security2:error] [pid 643253:tid 643471] [client 20.52.125.110:12214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/wp-setup.php"] [unique_id "amuFBMjqbtjBYzqM1uZQxgAAAFc"]
[Thu Jul 30 12:08:20.622183 2026] [security2:error] [pid 643253:tid 643309] [remote 216.73.216.152:25440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuFBMjqbtjBYzqM1uZQzgAAWjY"]
[Thu Jul 30 12:08:20.727156 2026] [security2:error] [pid 643253:tid 643437] [client 68.221.186.136:33034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/albin.php"] [unique_id "amuFBMjqbtjBYzqM1uZQzwAAADU"]
[Thu Jul 30 12:08:20.987171 2026] [security2:error] [pid 643253:tid 643482] [client 68.221.186.136:39493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/f7.php"] [unique_id "amuFBMjqbtjBYzqM1uZQ0QAAAGI"]
[Thu Jul 30 12:08:21.033137 2026] [security2:error] [pid 643253:tid 643413] [client 20.52.125.110:12184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/defaults.php"] [unique_id "amuFBcjqbtjBYzqM1uZQ0gAAAB0"]
[Thu Jul 30 12:08:21.253359 2026] [security2:error] [pid 643253:tid 643509] [client 191.232.199.39:20327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/akcc.php"] [unique_id "amuFBcjqbtjBYzqM1uZQ3AAAAH0"]
[Thu Jul 30 12:08:21.631790 2026] [security2:error] [pid 643253:tid 643330] [remote 216.73.216.152:25440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuFBcjqbtjBYzqM1uZQ3wAAVEs"]
[Thu Jul 30 12:08:21.693110 2026] [security2:error] [pid 643253:tid 643486] [client 20.52.125.110:12230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/gtc.php"] [unique_id "amuFBcjqbtjBYzqM1uZQ5QAAAGY"]
[Thu Jul 30 12:08:22.134475 2026] [security2:error] [pid 643253:tid 643321] [remote 216.73.216.152:25440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuFBsjqbtjBYzqM1uZQ6gAATEI"]
[Thu Jul 30 12:08:22.588233 2026] [security2:error] [pid 643253:tid 643439] [client 191.232.199.39:61109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/asasx.php"] [unique_id "amuFBsjqbtjBYzqM1uZQ7wAAADc"]
[Thu Jul 30 12:08:22.941780 2026] [security2:error] [pid 643253:tid 643485] [client 20.52.125.110:12182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/import.php"] [unique_id "amuFBsjqbtjBYzqM1uZQ-QAAAGU"]
[Thu Jul 30 12:08:23.341768 2026] [security2:error] [pid 643253:tid 643471] [client 68.221.186.136:40645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/amfsqvgv.php"] [unique_id "amuFB8jqbtjBYzqM1uZRBwAAAFc"]
[Thu Jul 30 12:08:23.693364 2026] [security2:error] [pid 643253:tid 643358] [remote 57.141.0.60:52958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/83915116186/feed/rss2/"] [unique_id "amuFB8jqbtjBYzqM1uZRDAAAYmc"]
[Thu Jul 30 12:08:24.077855 2026] [security2:error] [pid 643253:tid 643374] [remote 20.54.134.42:2185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.134.54.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/wp-login.php"] [unique_id "amuFCMjqbtjBYzqM1uZRFgAAHXc"]
[Thu Jul 30 12:08:24.152926 2026] [security2:error] [pid 643253:tid 643416] [client 103.134.1.54:21991] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuFB8jqbtjBYzqM1uZRFAAAACA"], referer: http://pkf.jo
[Thu Jul 30 12:08:24.172817 2026] [security2:error] [pid 643253:tid 643466] [client 191.232.199.39:59800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/axx.php"] [unique_id "amuFCMjqbtjBYzqM1uZRGgAAAFI"]
[Thu Jul 30 12:08:24.235671 2026] [security2:error] [pid 643253:tid 643468] [client 20.52.125.110:12247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/lufix.php"] [unique_id "amuFCMjqbtjBYzqM1uZRHgAAAFQ"]
[Thu Jul 30 12:08:24.470159 2026] [core:notice] [pid 643253:tid 643428] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:24.477461 2026] [security2:error] [pid 643253:tid 643428] [client 103.215.74.26:21108] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFCMjqbtjBYzqM1uZRJgAAACw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:25.079581 2026] [security2:error] [pid 643253:tid 643467] [client 20.52.125.110:12241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/Geforce.php"] [unique_id "amuFCcjqbtjBYzqM1uZRRwAAAFM"]
[Thu Jul 30 12:08:25.196503 2026] [core:notice] [pid 643253:tid 643434] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:25.203237 2026] [security2:error] [pid 643253:tid 643434] [client 103.215.74.26:21122] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFCcjqbtjBYzqM1uZRSwAAADI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:25.371788 2026] [security2:error] [pid 643253:tid 643429] [client 191.232.199.39:20324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/berax.php"] [unique_id "amuFCcjqbtjBYzqM1uZRUgAAAC0"]
[Thu Jul 30 12:08:25.774280 2026] [security2:error] [pid 643253:tid 643289] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "amuFCcjqbtjBYzqM1uZRVwAATiI"]
[Thu Jul 30 12:08:25.860553 2026] [security2:error] [pid 643253:tid 643491] [client 20.52.125.110:12211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/a4.php"] [unique_id "amuFCcjqbtjBYzqM1uZRXgAAAGs"]
[Thu Jul 30 12:08:25.911380 2026] [core:notice] [pid 643253:tid 643469] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:25.917926 2026] [security2:error] [pid 643253:tid 643469] [client 103.215.74.26:21134] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFCcjqbtjBYzqM1uZRYgAAAFU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:26.034249 2026] [security2:error] [pid 643253:tid 643397] [client 2a03:2880:f800:33:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuFCcjqbtjBYzqM1uZRUwAADRA"]
[Thu Jul 30 12:08:26.147788 2026] [security2:error] [pid 643253:tid 643395] [client 185.189.112.11:45326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.112.189.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuFCsjqbtjBYzqM1uZRZwAAAAs"]
[Thu Jul 30 12:08:26.147885 2026] [security2:error] [pid 643253:tid 643395] [client 185.189.112.11:45326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuFCsjqbtjBYzqM1uZRZwAAAAs"]
[Thu Jul 30 12:08:26.252641 2026] [security2:error] [pid 643253:tid 643433] [client 68.221.186.136:37233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/ant.php"] [unique_id "amuFCsjqbtjBYzqM1uZRagAAADE"]
[Thu Jul 30 12:08:26.562891 2026] [security2:error] [pid 643253:tid 643510] [client 20.52.125.110:12237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/accueil.php"] [unique_id "amuFCsjqbtjBYzqM1uZRdgAAAH4"]
[Thu Jul 30 12:08:26.573595 2026] [security2:error] [pid 643253:tid 643372] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/404.php"] [unique_id "amuFCsjqbtjBYzqM1uZRdwAAXHU"]
[Thu Jul 30 12:08:26.684623 2026] [core:notice] [pid 643253:tid 643458] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:26.691331 2026] [security2:error] [pid 643253:tid 643458] [client 103.215.74.26:21144] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFCsjqbtjBYzqM1uZRfwAAAEo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:26.785413 2026] [security2:error] [pid 643253:tid 643487] [client 191.232.199.39:61058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/build.php"] [unique_id "amuFCsjqbtjBYzqM1uZRggAAAGc"]
[Thu Jul 30 12:08:26.936624 2026] [security2:error] [pid 643253:tid 643294] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-configs.php"] [unique_id "amuFCsjqbtjBYzqM1uZRiwAAZSc"]
[Thu Jul 30 12:08:27.243116 2026] [security2:error] [pid 643253:tid 643297] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/simple.php"] [unique_id "amuFC8jqbtjBYzqM1uZRkQAAbio"]
[Thu Jul 30 12:08:27.249818 2026] [security2:error] [pid 643253:tid 643500] [client 20.52.125.110:12188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/dashboard.php"] [unique_id "amuFC8jqbtjBYzqM1uZRkgAAAHQ"]
[Thu Jul 30 12:08:27.452741 2026] [core:notice] [pid 643253:tid 643437] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:27.459836 2026] [security2:error] [pid 643253:tid 643437] [client 103.215.74.26:21156] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFC8jqbtjBYzqM1uZRmgAAADU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:27.552435 2026] [security2:error] [pid 643253:tid 643282] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/themes.php"] [unique_id "amuFC8jqbtjBYzqM1uZRmwAAaxs"]
[Thu Jul 30 12:08:27.858766 2026] [security2:error] [pid 643253:tid 643287] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/ini.php"] [unique_id "amuFC8jqbtjBYzqM1uZRowAAdyA"]
[Thu Jul 30 12:08:28.125965 2026] [security2:error] [pid 643253:tid 643465] [client 154.66.167.97:45156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuFC8jqbtjBYzqM1uZRnwAAAFE"], referer: http://pkf.jo
[Thu Jul 30 12:08:28.166829 2026] [security2:error] [pid 643253:tid 643371] [remote 216.73.216.152:25440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuFDMjqbtjBYzqM1uZRqQAABnQ"]
[Thu Jul 30 12:08:28.169097 2026] [security2:error] [pid 643253:tid 643270] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/autoload_classmap.php"] [unique_id "amuFDMjqbtjBYzqM1uZRqgAAYw8"]
[Thu Jul 30 12:08:28.190160 2026] [core:notice] [pid 643253:tid 643477] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:28.196776 2026] [security2:error] [pid 643253:tid 643477] [client 103.215.74.26:21160] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFDMjqbtjBYzqM1uZRqwAAAF0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:28.499032 2026] [security2:error] [pid 643253:tid 643311] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/as.php"] [unique_id "amuFDMjqbtjBYzqM1uZRtwAABDg"]
[Thu Jul 30 12:08:28.843002 2026] [security2:error] [pid 643253:tid 643279] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/admin/upload/css.php"] [unique_id "amuFDMjqbtjBYzqM1uZRvAAAKRg"]
[Thu Jul 30 12:08:28.939646 2026] [core:notice] [pid 643253:tid 643424] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:28.946228 2026] [security2:error] [pid 643253:tid 643424] [client 103.215.74.26:21164] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFDMjqbtjBYzqM1uZRwwAAACg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:28.980151 2026] [security2:error] [pid 643253:tid 643451] [client 68.221.186.136:31632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/appreciators.php"] [unique_id "amuFDMjqbtjBYzqM1uZRxAAAAEM"]
[Thu Jul 30 12:08:29.103470 2026] [security2:error] [pid 643253:tid 643432] [client 102.64.161.35:15676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuFDMjqbtjBYzqM1uZRuwAAADA"], referer: http://pkf.jo
[Thu Jul 30 12:08:29.141791 2026] [security2:error] [pid 643253:tid 643319] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/pki-validation/afnew.php"] [unique_id "amuFDcjqbtjBYzqM1uZRyAAAUEA"]
[Thu Jul 30 12:08:29.222410 2026] [security2:error] [pid 643253:tid 643408] [client 191.232.199.39:59817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/buy.php"] [unique_id "amuFDcjqbtjBYzqM1uZRyQAAABg"]
[Thu Jul 30 12:08:29.246012 2026] [security2:error] [pid 643253:tid 643490] [client 20.52.125.110:12186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/radio.php"] [unique_id "amuFDcjqbtjBYzqM1uZRygAAAGo"]
[Thu Jul 30 12:08:29.453724 2026] [security2:error] [pid 643253:tid 643324] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/lufix.php"] [unique_id "amuFDcjqbtjBYzqM1uZR0AAANEU"]
[Thu Jul 30 12:08:29.668321 2026] [core:notice] [pid 643253:tid 643384] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:29.674626 2026] [security2:error] [pid 643253:tid 643384] [client 103.215.74.26:21166] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFDcjqbtjBYzqM1uZR1AAAAAA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:29.820467 2026] [security2:error] [pid 643253:tid 643322] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/media.php"] [unique_id "amuFDcjqbtjBYzqM1uZR1QAATUM"]
[Thu Jul 30 12:08:29.947364 2026] [security2:error] [pid 643253:tid 643426] [client 68.221.186.136:31642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/archive.php"] [unique_id "amuFDcjqbtjBYzqM1uZR1wAAACo"]
[Thu Jul 30 12:08:30.126832 2026] [security2:error] [pid 643253:tid 643337] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/simple.php"] [unique_id "amuFDsjqbtjBYzqM1uZR3gAAIFI"]
[Thu Jul 30 12:08:30.276434 2026] [core:notice] [pid 643253:tid 643395] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:30.404667 2026] [core:notice] [pid 643253:tid 643465] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:30.410794 2026] [security2:error] [pid 643253:tid 643465] [client 103.215.74.26:21170] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFDsjqbtjBYzqM1uZR4gAAAFE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:30.436610 2026] [security2:error] [pid 643253:tid 643300] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/contact.php"] [unique_id "amuFDsjqbtjBYzqM1uZR4wAADi0"]
[Thu Jul 30 12:08:30.532764 2026] [security2:error] [pid 643253:tid 643417] [client 191.232.199.39:61056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/checkbox.php"] [unique_id "amuFDsjqbtjBYzqM1uZR5wAAACE"]
[Thu Jul 30 12:08:30.656625 2026] [security2:error] [pid 643253:tid 643419] [client 20.52.125.110:12187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/wpsml-sys.php"] [unique_id "amuFDsjqbtjBYzqM1uZR7gAAACM"]
[Thu Jul 30 12:08:30.747385 2026] [security2:error] [pid 643253:tid 643276] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/byp.php"] [unique_id "amuFDsjqbtjBYzqM1uZR7wAAbxU"]
[Thu Jul 30 12:08:30.910707 2026] [security2:error] [pid 643253:tid 643385] [client 185.200.117.131:56146] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuFDsjqbtjBYzqM1uZR8AAAAAE"]
[Thu Jul 30 12:08:30.910811 2026] [security2:error] [pid 643253:tid 643385] [client 185.200.117.131:56146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuFDsjqbtjBYzqM1uZR8AAAAAE"]
[Thu Jul 30 12:08:31.050103 2026] [security2:error] [pid 643253:tid 643335] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/upload.php"] [unique_id "amuFD8jqbtjBYzqM1uZR9QAAWFA"]
[Thu Jul 30 12:08:31.150427 2026] [core:notice] [pid 643253:tid 643441] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:31.156523 2026] [security2:error] [pid 643253:tid 643441] [client 103.215.74.26:21176] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFD8jqbtjBYzqM1uZR-gAAADk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:31.199412 2026] [security2:error] [pid 643253:tid 643428] [client 68.221.186.136:37195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/as.php"] [unique_id "amuFD8jqbtjBYzqM1uZR-wAAACw"]
[Thu Jul 30 12:08:31.349716 2026] [security2:error] [pid 643253:tid 643341] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/themes/sketch/404.php"] [unique_id "amuFD8jqbtjBYzqM1uZSAwAALlY"]
[Thu Jul 30 12:08:31.667454 2026] [security2:error] [pid 643253:tid 643361] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/cong.php"] [unique_id "amuFD8jqbtjBYzqM1uZSDAAAOGo"]
[Thu Jul 30 12:08:31.918720 2026] [core:notice] [pid 643253:tid 643500] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:31.925012 2026] [security2:error] [pid 643253:tid 643500] [client 103.215.74.26:21188] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFD8jqbtjBYzqM1uZSDgAAAHQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:31.976955 2026] [security2:error] [pid 643253:tid 643321] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/about/function.php"] [unique_id "amuFD8jqbtjBYzqM1uZSDwAAW0I"]
[Thu Jul 30 12:08:32.325911 2026] [security2:error] [pid 643253:tid 643362] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/filemanager/dialog.php"] [unique_id "amuFEMjqbtjBYzqM1uZSGAAAAGs"]
[Thu Jul 30 12:08:32.343619 2026] [security2:error] [pid 643253:tid 643438] [client 191.232.199.39:59811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/cong.php"] [unique_id "amuFEMjqbtjBYzqM1uZSGQAAADY"]
[Thu Jul 30 12:08:32.634945 2026] [security2:error] [pid 643253:tid 643460] [client 68.221.186.136:40703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/atomlib.php"] [unique_id "amuFEMjqbtjBYzqM1uZSHgAAAEw"]
[Thu Jul 30 12:08:32.661301 2026] [security2:error] [pid 643253:tid 643368] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/bak.php"] [unique_id "amuFEMjqbtjBYzqM1uZSIQAAOnE"]
[Thu Jul 30 12:08:32.666413 2026] [core:notice] [pid 643253:tid 643461] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:32.672464 2026] [security2:error] [pid 643253:tid 643461] [client 103.215.74.26:21196] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFEMjqbtjBYzqM1uZSIwAAAE0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:33.007725 2026] [security2:error] [pid 643253:tid 643329] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-info.php"] [unique_id "amuFEcjqbtjBYzqM1uZSJQAAZko"]
[Thu Jul 30 12:08:33.355200 2026] [security2:error] [pid 643253:tid 643374] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/files/index.php"] [unique_id "amuFEcjqbtjBYzqM1uZSMgAAcHc"]
[Thu Jul 30 12:08:33.402403 2026] [core:notice] [pid 643253:tid 643404] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:33.408122 2026] [security2:error] [pid 643253:tid 643404] [client 103.215.74.26:58470] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFEcjqbtjBYzqM1uZSNQAAABQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:33.659358 2026] [security2:error] [pid 643253:tid 643340] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/css.php"] [unique_id "amuFEcjqbtjBYzqM1uZSPgAAZVU"]
[Thu Jul 30 12:08:33.695919 2026] [core:notice] [pid 643253:tid 643413] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:33.799783 2026] [security2:error] [pid 643253:tid 643444] [client 68.221.186.136:36410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/autoload_classmap.php"] [unique_id "amuFEcjqbtjBYzqM1uZSRQAAADw"]
[Thu Jul 30 12:08:34.023659 2026] [security2:error] [pid 643253:tid 643348] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/css/index.php"] [unique_id "amuFEsjqbtjBYzqM1uZSSAAAGF0"]
[Thu Jul 30 12:08:34.139216 2026] [core:notice] [pid 643253:tid 643463] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:34.145262 2026] [security2:error] [pid 643253:tid 643463] [client 103.215.74.26:58472] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFEsjqbtjBYzqM1uZSSgAAAE8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:34.340644 2026] [security2:error] [pid 643253:tid 643268] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/bak.php"] [unique_id "amuFEsjqbtjBYzqM1uZSUQAANA0"]
[Thu Jul 30 12:08:34.344519 2026] [core:notice] [pid 643253:tid 643490] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:34.344519 2026] [core:notice] [pid 643253:tid 643432] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:34.346629 2026] [core:notice] [pid 643253:tid 643429] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:34.648034 2026] [security2:error] [pid 643253:tid 643375] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/alfa-rex.php7"] [unique_id "amuFEsjqbtjBYzqM1uZSVwAAdXg"]
[Thu Jul 30 12:08:34.872542 2026] [core:notice] [pid 643253:tid 643437] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:34.879170 2026] [security2:error] [pid 643253:tid 643437] [client 103.215.74.26:58478] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFEsjqbtjBYzqM1uZSYAAAADU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:34.921970 2026] [security2:error] [pid 643253:tid 643453] [client 20.52.125.110:12244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/02.php"] [unique_id "amuFEsjqbtjBYzqM1uZSZAAAAEU"]
[Thu Jul 30 12:08:35.218007 2026] [security2:error] [pid 643253:tid 643384] [client 191.232.199.39:61067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/file4.php"] [unique_id "amuFE8jqbtjBYzqM1uZSaQAAAAA"]
[Thu Jul 30 12:08:35.223686 2026] [security2:error] [pid 643253:tid 643277] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/wp-login.php"] [unique_id "amuFEsjqbtjBYzqM1uZSZQAAQhY"]
[Thu Jul 30 12:08:35.582788 2026] [security2:error] [pid 643253:tid 643263] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/cloud.php"] [unique_id "amuFE8jqbtjBYzqM1uZSdAAAYwg"]
[Thu Jul 30 12:08:35.629098 2026] [core:notice] [pid 643253:tid 643511] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:35.635396 2026] [security2:error] [pid 643253:tid 643511] [client 103.215.74.26:58482] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFE8jqbtjBYzqM1uZSdQAAAH8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:35.669516 2026] [security2:error] [pid 643253:tid 643473] [client 68.221.186.136:23437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/bb.php"] [unique_id "amuFE8jqbtjBYzqM1uZSdgAAAFk"]
[Thu Jul 30 12:08:35.803995 2026] [security2:error] [pid 643253:tid 643477] [client 20.52.125.110:12178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/infos.php"] [unique_id "amuFE8jqbtjBYzqM1uZSewAAAF0"]
[Thu Jul 30 12:08:35.911531 2026] [security2:error] [pid 643253:tid 643379] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/index.php"] [unique_id "amuFE8jqbtjBYzqM1uZSfwAAHnw"]
[Thu Jul 30 12:08:36.002228 2026] [security2:error] [pid 643253:tid 643428] [client 157.15.46.53:46360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuFE8jqbtjBYzqM1uZSdwAAACw"], referer: http://pkf.jo
[Thu Jul 30 12:08:36.223099 2026] [security2:error] [pid 643253:tid 643261] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/readme.php"] [unique_id "amuFFMjqbtjBYzqM1uZSggAAdAY"]
[Thu Jul 30 12:08:36.374758 2026] [core:notice] [pid 643253:tid 643391] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:36.381172 2026] [security2:error] [pid 643253:tid 643391] [client 103.215.74.26:58494] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFFMjqbtjBYzqM1uZShgAAAAc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:36.437165 2026] [security2:error] [pid 643253:tid 643459] [client 20.52.125.110:12238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/updates.php"] [unique_id "amuFFMjqbtjBYzqM1uZShwAAAEs"]
[Thu Jul 30 12:08:36.548305 2026] [security2:error] [pid 643253:tid 643264] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/about.php"] [unique_id "amuFFMjqbtjBYzqM1uZSiwAAdwk"]
[Thu Jul 30 12:08:37.109946 2026] [core:notice] [pid 643253:tid 643387] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:37.116268 2026] [security2:error] [pid 643253:tid 643387] [client 103.215.74.26:58498] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFFcjqbtjBYzqM1uZSlAAAAAM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:37.574329 2026] [security2:error] [pid 643253:tid 643478] [client 68.221.186.136:36413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/bnm.php"] [unique_id "amuFFcjqbtjBYzqM1uZSowAAAF4"]
[Thu Jul 30 12:08:37.674835 2026] [security2:error] [pid 643253:tid 643487] [client 45.4.230.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuFFcjqbtjBYzqM1uZSogAAAGc"]
[Thu Jul 30 12:08:37.678182 2026] [security2:error] [pid 643253:tid 643316] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/themes/404.php"] [unique_id "amuFFcjqbtjBYzqM1uZSpgAAXT0"]
[Thu Jul 30 12:08:37.753001 2026] [security2:error] [pid 643253:tid 643467] [client 103.141.175.162:59016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuFFcjqbtjBYzqM1uZSnwAAAFM"], referer: http://pkf.jo
[Thu Jul 30 12:08:37.837234 2026] [core:notice] [pid 643253:tid 643455] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:37.843686 2026] [security2:error] [pid 643253:tid 643455] [client 103.215.74.26:58504] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFFcjqbtjBYzqM1uZSqQAAAEc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:38.109438 2026] [security2:error] [pid 643253:tid 643272] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/index.php"] [unique_id "amuFFsjqbtjBYzqM1uZStAAAOBE"]
[Thu Jul 30 12:08:38.150726 2026] [security2:error] [pid 643253:tid 643457] [client 20.203.156.12:50012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/wp-login.php"] [unique_id "amuFFcjqbtjBYzqM1uZSpAAAAEk"]
[Thu Jul 30 12:08:38.150859 2026] [security2:error] [pid 643253:tid 643457] [client 20.203.156.12:50012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/wp-login.php"] [unique_id "amuFFcjqbtjBYzqM1uZSpAAAAEk"]
[Thu Jul 30 12:08:38.231716 2026] [security2:error] [pid 643253:tid 643446] [client 191.232.199.39:59806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/flower.php"] [unique_id "amuFFsjqbtjBYzqM1uZSuQAAAD4"]
[Thu Jul 30 12:08:38.416246 2026] [security2:error] [pid 643253:tid 643285] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/themes.php"] [unique_id "amuFFsjqbtjBYzqM1uZSvAAALR4"]
[Thu Jul 30 12:08:38.571629 2026] [core:notice] [pid 643253:tid 643490] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:38.577849 2026] [security2:error] [pid 643253:tid 643490] [client 103.215.74.26:58518] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFFsjqbtjBYzqM1uZSwwAAAGo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:38.639846 2026] [security2:error] [pid 643253:tid 643461] [client 43.130.9.111:49106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.9.130.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/rreportf.php"] [unique_id "amuFFsjqbtjBYzqM1uZSxAAAAE0"]
[Thu Jul 30 12:08:38.763505 2026] [security2:error] [pid 643253:tid 643287] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/dropdown.php"] [unique_id "amuFFsjqbtjBYzqM1uZSxQAAVSA"]
[Thu Jul 30 12:08:39.086012 2026] [security2:error] [pid 643253:tid 643270] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/404.php"] [unique_id "amuFF8jqbtjBYzqM1uZSzgAAAw8"]
[Thu Jul 30 12:08:39.316077 2026] [core:notice] [pid 643253:tid 643489] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:39.322326 2026] [security2:error] [pid 643253:tid 643489] [client 103.215.74.26:58520] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFF8jqbtjBYzqM1uZS0gAAAGk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:39.438380 2026] [security2:error] [pid 643253:tid 643382] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "amuFF8jqbtjBYzqM1uZS1AAAZX8"]
[Thu Jul 30 12:08:39.512541 2026] [security2:error] [pid 643253:tid 643392] [client 191.232.199.39:61081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/form.php"] [unique_id "amuFF8jqbtjBYzqM1uZS1gAAAAg"]
[Thu Jul 30 12:08:39.786151 2026] [security2:error] [pid 643253:tid 643260] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/cgi-bin/file.php"] [unique_id "amuFF8jqbtjBYzqM1uZS3AAAFQU"]
[Thu Jul 30 12:08:39.909034 2026] [security2:error] [pid 643253:tid 643468] [client 68.221.186.136:37193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/bootstrap.php"] [unique_id "amuFF8jqbtjBYzqM1uZS3gAAAFQ"]
[Thu Jul 30 12:08:40.052489 2026] [core:notice] [pid 643253:tid 643455] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:40.058269 2026] [security2:error] [pid 643253:tid 643455] [client 103.215.74.26:58526] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFGMjqbtjBYzqM1uZS5QAAAEc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:40.096217 2026] [security2:error] [pid 643253:tid 643291] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/index.php"] [unique_id "amuFGMjqbtjBYzqM1uZS5gAASSQ"]
[Thu Jul 30 12:08:40.420695 2026] [security2:error] [pid 643253:tid 643304] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/cloud.php"] [unique_id "amuFGMjqbtjBYzqM1uZS6wAAEjE"]
[Thu Jul 30 12:08:40.527117 2026] [security2:error] [pid 643253:tid 643506] [client 20.52.125.110:12245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/user.php"] [unique_id "amuFGMjqbtjBYzqM1uZS7AAAAHo"]
[Thu Jul 30 12:08:40.745422 2026] [security2:error] [pid 643253:tid 643322] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "amuFGMjqbtjBYzqM1uZS8wAAVUM"]
[Thu Jul 30 12:08:40.784777 2026] [core:notice] [pid 643253:tid 643474] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:40.791119 2026] [security2:error] [pid 643253:tid 643474] [client 103.215.74.26:58534] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFGMjqbtjBYzqM1uZS9AAAAFo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:41.063797 2026] [security2:error] [pid 643253:tid 643315] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/cgi-bin/404.php"] [unique_id "amuFGcjqbtjBYzqM1uZS9QAADDw"]
[Thu Jul 30 12:08:41.191851 2026] [security2:error] [pid 643253:tid 643493] [client 191.232.199.39:59815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/gecko.php"] [unique_id "amuFGcjqbtjBYzqM1uZS_AAAAG0"]
[Thu Jul 30 12:08:41.399148 2026] [security2:error] [pid 643253:tid 643302] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/function.php"] [unique_id "amuFGcjqbtjBYzqM1uZS_gAAcC8"]
[Thu Jul 30 12:08:41.513745 2026] [core:notice] [pid 643253:tid 643486] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:41.520171 2026] [security2:error] [pid 643253:tid 643486] [client 103.215.74.26:58550] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFGcjqbtjBYzqM1uZS_wAAAGY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:41.648618 2026] [security2:error] [pid 643253:tid 643436] [client 68.221.186.136:46049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/buy.php"] [unique_id "amuFGcjqbtjBYzqM1uZTAQAAADQ"]
[Thu Jul 30 12:08:41.717695 2026] [security2:error] [pid 643253:tid 643276] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/file.php"] [unique_id "amuFGcjqbtjBYzqM1uZTBQAAKBU"]
[Thu Jul 30 12:08:42.023516 2026] [security2:error] [pid 643253:tid 643318] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/acme-challenge/autoload_classmap.php"] [unique_id "amuFGsjqbtjBYzqM1uZTDgAAOz8"]
[Thu Jul 30 12:08:42.231602 2026] [security2:error] [pid 643253:tid 643451] [client 20.52.125.110:12200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/admin-ajax.php"] [unique_id "amuFGsjqbtjBYzqM1uZTDwAAAEM"]
[Thu Jul 30 12:08:42.254097 2026] [core:notice] [pid 643253:tid 643498] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:42.263533 2026] [security2:error] [pid 643253:tid 643498] [client 103.215.74.26:58558] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFGsjqbtjBYzqM1uZTFQAAAHI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:42.338477 2026] [security2:error] [pid 643253:tid 643317] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/themes.php"] [unique_id "amuFGsjqbtjBYzqM1uZTFwAAVz4"]
[Thu Jul 30 12:08:42.425932 2026] [security2:error] [pid 643253:tid 643444] [client 57.141.0.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuFGcjqbtjBYzqM1uZTDAAAADw"]
[Thu Jul 30 12:08:42.666569 2026] [security2:error] [pid 643253:tid 643342] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/wp-login.php"] [unique_id "amuFGsjqbtjBYzqM1uZTGgAAS1c"]
[Thu Jul 30 12:08:42.802214 2026] [security2:error] [pid 643253:tid 643391] [client 46.29.29.113:57362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuFGsjqbtjBYzqM1uZTGQAAAAc"], referer: http://pkf.jo
[Thu Jul 30 12:08:42.993665 2026] [security2:error] [pid 643253:tid 643320] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/file.php"] [unique_id "amuFGsjqbtjBYzqM1uZTIwAAOkE"]
[Thu Jul 30 12:08:43.006704 2026] [core:notice] [pid 643253:tid 643482] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:43.013090 2026] [security2:error] [pid 643253:tid 643482] [client 103.215.74.26:58560] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFG8jqbtjBYzqM1uZTJAAAAGI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:43.263905 2026] [security2:error] [pid 643253:tid 643400] [client 68.221.186.136:23458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/chosen.php"] [unique_id "amuFG8jqbtjBYzqM1uZTKQAAABA"]
[Thu Jul 30 12:08:43.350890 2026] [security2:error] [pid 643253:tid 643332] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-trackback.php"] [unique_id "amuFG8jqbtjBYzqM1uZTLwAAFE0"]
[Thu Jul 30 12:08:43.384499 2026] [security2:error] [pid 643253:tid 643509] [client 20.52.125.110:12227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/alfa.php"] [unique_id "amuFG8jqbtjBYzqM1uZTMAAAAH0"]
[Thu Jul 30 12:08:43.523432 2026] [security2:error] [pid 643253:tid 643330] [remote 40.77.167.67:5122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/tumed/article/view/7021"] [unique_id "amuFG8jqbtjBYzqM1uZTKgAAfks"]
[Thu Jul 30 12:08:43.659764 2026] [security2:error] [pid 643253:tid 643362] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/SimplePie/wp-login.php"] [unique_id "amuFG8jqbtjBYzqM1uZTMgAAfGs"]
[Thu Jul 30 12:08:43.738497 2026] [core:notice] [pid 643253:tid 643479] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:43.744716 2026] [security2:error] [pid 643253:tid 643479] [client 103.215.74.26:50032] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFG8jqbtjBYzqM1uZTMwAAAF8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:43.980672 2026] [security2:error] [pid 643253:tid 643329] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/cgi-bin/index.php"] [unique_id "amuFG8jqbtjBYzqM1uZTPgAASEo"]
[Thu Jul 30 12:08:44.285366 2026] [security2:error] [pid 643253:tid 643347] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/themes.php"] [unique_id "amuFHMjqbtjBYzqM1uZTQAAAGlw"]
[Thu Jul 30 12:08:44.494827 2026] [core:notice] [pid 643253:tid 643498] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:44.501040 2026] [security2:error] [pid 643253:tid 643498] [client 103.215.74.26:50034] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFHMjqbtjBYzqM1uZTSAAAAHI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:44.586482 2026] [core:notice] [pid 643253:tid 643325] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:44.596530 2026] [core:notice] [pid 643253:tid 643374] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:44.598441 2026] [security2:error] [pid 643253:tid 643356] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/cloud.php"] [unique_id "amuFHMjqbtjBYzqM1uZTSwAAI2U"]
[Thu Jul 30 12:08:44.616130 2026] [security2:error] [pid 643253:tid 643424] [client 68.221.186.136:46076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/class-wp-image.php"] [unique_id "amuFHMjqbtjBYzqM1uZTTAAAACg"]
[Thu Jul 30 12:08:44.818848 2026] [security2:error] [pid 643253:tid 643340] [remote 57.141.0.9:39870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuFHMjqbtjBYzqM1uZTUQAAdlU"]
[Thu Jul 30 12:08:44.859186 2026] [core:notice] [pid 643253:tid 643369] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:44.871000 2026] [core:notice] [pid 643253:tid 643345] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:44.902395 2026] [security2:error] [pid 643253:tid 643366] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/wp-load.php"] [unique_id "amuFHMjqbtjBYzqM1uZTVwAAG28"]
[Thu Jul 30 12:08:45.209485 2026] [security2:error] [pid 643253:tid 643348] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/file.php"] [unique_id "amuFHcjqbtjBYzqM1uZTWQAAQl0"]
[Thu Jul 30 12:08:45.522104 2026] [security2:error] [pid 643253:tid 643268] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/makeasmtp.php"] [unique_id "amuFHcjqbtjBYzqM1uZTZgAAeQ0"]
[Thu Jul 30 12:08:45.574964 2026] [security2:error] [pid 643253:tid 643397] [client 68.221.186.136:37207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/classsmtps.php"] [unique_id "amuFHcjqbtjBYzqM1uZTZwAAAA0"]
[Thu Jul 30 12:08:45.606487 2026] [core:notice] [pid 643253:tid 643386] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:45.837452 2026] [security2:error] [pid 643253:tid 643375] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/index.php"] [unique_id "amuFHcjqbtjBYzqM1uZTbAAAZXg"]
[Thu Jul 30 12:08:46.166151 2026] [security2:error] [pid 643253:tid 643277] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "amuFHsjqbtjBYzqM1uZTcwAAfxY"]
[Thu Jul 30 12:08:46.507881 2026] [security2:error] [pid 643253:tid 643259] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/404.php"] [unique_id "amuFHsjqbtjBYzqM1uZTgAAASQQ"]
[Thu Jul 30 12:08:46.640136 2026] [security2:error] [pid 643253:tid 643406] [client 68.221.186.136:46059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/classwithtostring.php"] [unique_id "amuFHsjqbtjBYzqM1uZTgQAAABY"]
[Thu Jul 30 12:08:46.818465 2026] [security2:error] [pid 643253:tid 643381] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/acme-challenge/makeasmtp.php"] [unique_id "amuFHsjqbtjBYzqM1uZTgwAAI34"]
[Thu Jul 30 12:08:46.968666 2026] [security2:error] [pid 643253:tid 643497] [client 20.52.125.110:12253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/hehe.php"] [unique_id "amuFHsjqbtjBYzqM1uZTigAAAHE"]
[Thu Jul 30 12:08:47.168911 2026] [security2:error] [pid 643253:tid 643360] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/radio.php"] [unique_id "amuFH8jqbtjBYzqM1uZTiwAANWk"]
[Thu Jul 30 12:08:47.223655 2026] [security2:error] [pid 643253:tid 643499] [client 2a03:2880:f800:3a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuFHcjqbtjBYzqM1uZTaQAAcxw"]
[Thu Jul 30 12:08:47.557857 2026] [security2:error] [pid 643253:tid 643334] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuFH8jqbtjBYzqM1uZTkgAAA08"]
[Thu Jul 30 12:08:47.608500 2026] [security2:error] [pid 643253:tid 643449] [client 191.232.199.39:59820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/kyami.php"] [unique_id "amuFH8jqbtjBYzqM1uZTkwAAAEE"]
[Thu Jul 30 12:08:47.711311 2026] [core:notice] [pid 643253:tid 643416] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:47.753208 2026] [security2:error] [pid 643253:tid 643438] [client 20.52.125.110:12228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/rk2.php"] [unique_id "amuFH8jqbtjBYzqM1uZTlgAAADY"]
[Thu Jul 30 12:08:47.909062 2026] [security2:error] [pid 643253:tid 643266] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/admin.php"] [unique_id "amuFH8jqbtjBYzqM1uZTmAAAFAs"]
[Thu Jul 30 12:08:48.218945 2026] [security2:error] [pid 643253:tid 643264] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/system_log.php"] [unique_id "amuFIMjqbtjBYzqM1uZToQAAeQk"]
[Thu Jul 30 12:08:48.538641 2026] [security2:error] [pid 643253:tid 643271] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/wp-activate.php"] [unique_id "amuFIMjqbtjBYzqM1uZTqAAAHxA"]
[Thu Jul 30 12:08:48.759730 2026] [security2:error] [pid 643253:tid 643397] [client 20.52.125.110:12180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/setup-config.php"] [unique_id "amuFIMjqbtjBYzqM1uZTqQAAAA0"]
[Thu Jul 30 12:08:48.854265 2026] [security2:error] [pid 643253:tid 643274] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/makeasmtp.php"] [unique_id "amuFIMjqbtjBYzqM1uZTqwAAGBM"]
[Thu Jul 30 12:08:49.194910 2026] [security2:error] [pid 643253:tid 643267] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/user/index.php"] [unique_id "amuFIcjqbtjBYzqM1uZTtQAAFgw"]
[Thu Jul 30 12:08:49.505919 2026] [security2:error] [pid 643253:tid 643255] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/link.php"] [unique_id "amuFIcjqbtjBYzqM1uZTtgAADwA"]
[Thu Jul 30 12:08:49.508329 2026] [security2:error] [pid 643253:tid 643498] [client 68.221.186.136:38375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/config.php"] [unique_id "amuFIcjqbtjBYzqM1uZTtwAAAHI"]
[Thu Jul 30 12:08:49.550035 2026] [security2:error] [pid 643253:tid 643433] [client 191.232.199.39:59794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/manager.php"] [unique_id "amuFIcjqbtjBYzqM1uZTuwAAADE"]
[Thu Jul 30 12:08:49.824046 2026] [security2:error] [pid 643253:tid 643294] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/autoload_classmap.php"] [unique_id "amuFIcjqbtjBYzqM1uZTvwAAdyc"]
[Thu Jul 30 12:08:49.890117 2026] [core:notice] [pid 643253:tid 643441] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:50.172782 2026] [security2:error] [pid 643253:tid 643297] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/cgi-bin/themes.php"] [unique_id "amuFIsjqbtjBYzqM1uZTyQAAAyo"]
[Thu Jul 30 12:08:50.256576 2026] [core:notice] [pid 643253:tid 643442] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:50.263435 2026] [security2:error] [pid 643253:tid 643442] [client 103.215.74.26:50040] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFIsjqbtjBYzqM1uZT0gAAADo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:50.475772 2026] [security2:error] [pid 643253:tid 643308] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuFIsjqbtjBYzqM1uZT0wAAeDU"]
[Thu Jul 30 12:08:50.838399 2026] [security2:error] [pid 643253:tid 643311] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuFIsjqbtjBYzqM1uZT2wAACDg"]
[Thu Jul 30 12:08:50.992784 2026] [core:notice] [pid 643253:tid 643489] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:50.999482 2026] [security2:error] [pid 643253:tid 643489] [client 103.215.74.26:50042] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFIsjqbtjBYzqM1uZT3AAAAGk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:51.061117 2026] [security2:error] [pid 643253:tid 643509] [client 85.208.96.205:59834] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/02/21/apostas-de-guarabira-e-joao-pessoa-acertam-quina-da-mega-sena-e-cada-uma-leva-mais-de-r-76-mil/"] [unique_id "amuFI8jqbtjBYzqM1uZT3QAAAH0"]
[Thu Jul 30 12:08:51.061246 2026] [security2:error] [pid 643253:tid 643509] [client 85.208.96.205:59834] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/02/21/apostas-de-guarabira-e-joao-pessoa-acertam-quina-da-mega-sena-e-cada-uma-leva-mais-de-r-76-mil/"] [unique_id "amuFI8jqbtjBYzqM1uZT3QAAAH0"]
[Thu Jul 30 12:08:51.085646 2026] [security2:error] [pid 643253:tid 643474] [client 20.52.125.110:12183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/a7.php"] [unique_id "amuFI8jqbtjBYzqM1uZT3gAAAFo"]
[Thu Jul 30 12:08:51.184222 2026] [security2:error] [pid 643253:tid 643260] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/function.php"] [unique_id "amuFI8jqbtjBYzqM1uZT4gAABQU"]
[Thu Jul 30 12:08:51.290067 2026] [security2:error] [pid 643253:tid 643401] [client 2a03:2880:f800:29:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuFIsjqbtjBYzqM1uZT2AAAEX8"]
[Thu Jul 30 12:08:51.504261 2026] [security2:error] [pid 643253:tid 643279] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/images/wp-login.php"] [unique_id "amuFI8jqbtjBYzqM1uZT5gAAWxg"]
[Thu Jul 30 12:08:51.723179 2026] [core:notice] [pid 643253:tid 643456] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:51.729233 2026] [security2:error] [pid 643253:tid 643456] [client 103.215.74.26:50058] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFI8jqbtjBYzqM1uZT6gAAAEg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:51.812601 2026] [security2:error] [pid 643253:tid 643291] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/log.php"] [unique_id "amuFI8jqbtjBYzqM1uZT7gAAEyQ"]
[Thu Jul 30 12:08:51.825396 2026] [security2:error] [pid 643253:tid 643468] [client 20.52.125.110:12558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/f7.php"] [unique_id "amuFI8jqbtjBYzqM1uZT7wAAAFQ"]
[Thu Jul 30 12:08:52.080068 2026] [security2:error] [pid 643253:tid 643470] [client 191.232.199.39:59818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/mari.php"] [unique_id "amuFJMjqbtjBYzqM1uZT8AAAAFY"]
[Thu Jul 30 12:08:52.118325 2026] [security2:error] [pid 643253:tid 643319] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/wp-signup.php"] [unique_id "amuFJMjqbtjBYzqM1uZT8QAAckA"]
[Thu Jul 30 12:08:52.408892 2026] [security2:error] [pid 643253:tid 643462] [client 250.49.135.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuFJMjqbtjBYzqM1uZT-QAATkM"]
[Thu Jul 30 12:08:52.427340 2026] [security2:error] [pid 643253:tid 643310] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/themes/themes.php"] [unique_id "amuFJMjqbtjBYzqM1uZT-gAAczc"]
[Thu Jul 30 12:08:52.460725 2026] [core:notice] [pid 643253:tid 643411] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:52.466989 2026] [security2:error] [pid 643253:tid 643411] [client 103.215.74.26:50074] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFJMjqbtjBYzqM1uZT-wAAABs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:52.764559 2026] [security2:error] [pid 643253:tid 643306] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/radio.php"] [unique_id "amuFJMjqbtjBYzqM1uZUBQAAdDM"]
[Thu Jul 30 12:08:53.082534 2026] [security2:error] [pid 643253:tid 643336] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-mail.php"] [unique_id "amuFJcjqbtjBYzqM1uZUCgAAUlE"]
[Thu Jul 30 12:08:53.158813 2026] [security2:error] [pid 643253:tid 643339] [remote 57.141.0.39:30608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3390535976/feed/rss2/"] [unique_id "amuFJcjqbtjBYzqM1uZUCwAAAVQ"]
[Thu Jul 30 12:08:53.212659 2026] [core:notice] [pid 643253:tid 643486] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:53.218923 2026] [security2:error] [pid 643253:tid 643486] [client 103.215.74.26:51716] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFJcjqbtjBYzqM1uZUDQAAAGY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:53.436918 2026] [security2:error] [pid 643253:tid 643317] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "amuFJcjqbtjBYzqM1uZUFQAAaD4"]
[Thu Jul 30 12:08:53.751232 2026] [security2:error] [pid 643253:tid 643506] [client 20.52.125.110:12544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/nw.php"] [unique_id "amuFJcjqbtjBYzqM1uZUGAAAAHo"]
[Thu Jul 30 12:08:53.756104 2026] [security2:error] [pid 643253:tid 643342] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/admin.php"] [unique_id "amuFJcjqbtjBYzqM1uZUGQAADVc"]
[Thu Jul 30 12:08:53.818489 2026] [security2:error] [pid 643253:tid 643483] [client 2a03:2880:f800:9:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuFJcjqbtjBYzqM1uZUDgAAYz8"]
[Thu Jul 30 12:08:53.967537 2026] [core:notice] [pid 643253:tid 643413] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:53.973891 2026] [security2:error] [pid 643253:tid 643413] [client 103.215.74.26:51726] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFJcjqbtjBYzqM1uZUHwAAAB0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:53.976569 2026] [security2:error] [pid 643253:tid 643301] [remote 57.141.0.2:22316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/706661964/feed/rss2/"] [unique_id "amuFJcjqbtjBYzqM1uZUIAAAby4"]
[Thu Jul 30 12:08:54.072239 2026] [security2:error] [pid 643253:tid 643361] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "amuFJsjqbtjBYzqM1uZUJQAAJmo"]
[Thu Jul 30 12:08:54.425814 2026] [security2:error] [pid 643253:tid 643321] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-links-opml.php"] [unique_id "amuFJsjqbtjBYzqM1uZULAAAD0I"]
[Thu Jul 30 12:08:54.463953 2026] [security2:error] [pid 643253:tid 643446] [client 20.52.125.110:12165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/ova.php"] [unique_id "amuFJsjqbtjBYzqM1uZULgAAAD4"]
[Thu Jul 30 12:08:54.538949 2026] [security2:error] [pid 643253:tid 643437] [client 68.221.186.136:34832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/core.php"] [unique_id "amuFJsjqbtjBYzqM1uZUMAAAADU"]
[Thu Jul 30 12:08:54.727367 2026] [core:notice] [pid 643253:tid 643501] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:54.733680 2026] [security2:error] [pid 643253:tid 643501] [client 103.215.74.26:51734] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFJsjqbtjBYzqM1uZUMwAAAHU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:54.795858 2026] [security2:error] [pid 643253:tid 643354] [remote 57.141.0.32:49300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3390535976/feed/rss2/"] [unique_id "amuFJsjqbtjBYzqM1uZUNwAAcWM"]
[Thu Jul 30 12:08:54.801121 2026] [security2:error] [pid 643253:tid 643331] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/acme-challenge/radio.php"] [unique_id "amuFJsjqbtjBYzqM1uZUOAAATkw"]
[Thu Jul 30 12:08:54.830824 2026] [security2:error] [pid 643253:tid 643463] [client 191.232.199.39:61103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/nc4.php"] [unique_id "amuFJsjqbtjBYzqM1uZUOgAAAE8"]
[Thu Jul 30 12:08:55.151555 2026] [security2:error] [pid 643253:tid 643368] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/images/file.php"] [unique_id "amuFJ8jqbtjBYzqM1uZUQAAAbXE"]
[Thu Jul 30 12:08:55.455481 2026] [core:notice] [pid 643253:tid 643409] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:55.461810 2026] [security2:error] [pid 643253:tid 643409] [client 103.215.74.26:51740] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFJ8jqbtjBYzqM1uZURwAAABk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:55.470823 2026] [security2:error] [pid 643253:tid 643343] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/upgrade/function.php"] [unique_id "amuFJ8jqbtjBYzqM1uZUSAAAeVg"]
[Thu Jul 30 12:08:55.590836 2026] [security2:error] [pid 643253:tid 643418] [client 68.221.186.136:23205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/css.php"] [unique_id "amuFJ8jqbtjBYzqM1uZUSgAAACI"]
[Thu Jul 30 12:08:55.717248 2026] [security2:error] [pid 643253:tid 643385] [client 20.52.125.110:12175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/robots.php"] [unique_id "amuFJ8jqbtjBYzqM1uZUSwAAAAE"]
[Thu Jul 30 12:08:55.773499 2026] [security2:error] [pid 643253:tid 643358] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/user/themes.php"] [unique_id "amuFJ8jqbtjBYzqM1uZUTAAAX2c"]
[Thu Jul 30 12:08:56.100826 2026] [security2:error] [pid 643253:tid 643356] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/cgi-bin/radio.php"] [unique_id "amuFKMjqbtjBYzqM1uZUWwAAL2U"]
[Thu Jul 30 12:08:56.202164 2026] [core:notice] [pid 643253:tid 643434] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:56.208529 2026] [security2:error] [pid 643253:tid 643434] [client 103.215.74.26:51752] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFKMjqbtjBYzqM1uZUXAAAADI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:56.216647 2026] [security2:error] [pid 643253:tid 643483] [client 68.221.186.136:23210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/database.php"] [unique_id "amuFKMjqbtjBYzqM1uZUXQAAAGM"]
[Thu Jul 30 12:08:56.305696 2026] [security2:error] [pid 643253:tid 643475] [client 52.167.144.210:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuFJsjqbtjBYzqM1uZUIwAAAFs"]
[Thu Jul 30 12:08:56.413341 2026] [security2:error] [pid 643253:tid 643366] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/css/license.php"] [unique_id "amuFKMjqbtjBYzqM1uZUZgAAI28"]
[Thu Jul 30 12:08:56.849202 2026] [security2:error] [pid 643253:tid 643348] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/radio.php"] [unique_id "amuFKMjqbtjBYzqM1uZUbQAAB10"]
[Thu Jul 30 12:08:56.941916 2026] [core:notice] [pid 643253:tid 643437] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:56.948439 2026] [security2:error] [pid 643253:tid 643437] [client 103.215.74.26:51760] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFKMjqbtjBYzqM1uZUcQAAADU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:57.187560 2026] [security2:error] [pid 643253:tid 643323] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/plugins/about.php"] [unique_id "amuFKcjqbtjBYzqM1uZUcwAAA0Q"]
[Thu Jul 30 12:08:57.233359 2026] [security2:error] [pid 643253:tid 643459] [client 68.221.186.136:34879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/db.php"] [unique_id "amuFKcjqbtjBYzqM1uZUdAAAAEs"]
[Thu Jul 30 12:08:57.323615 2026] [security2:error] [pid 643253:tid 643491] [client 20.52.125.110:12181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/alf.php"] [unique_id "amuFKcjqbtjBYzqM1uZUdQAAAGs"]
[Thu Jul 30 12:08:57.509106 2026] [security2:error] [pid 643253:tid 643265] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "amuFKcjqbtjBYzqM1uZUfAAAdgo"]
[Thu Jul 30 12:08:57.664072 2026] [core:notice] [pid 643253:tid 643441] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:57.670488 2026] [security2:error] [pid 643253:tid 643441] [client 103.215.74.26:51776] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFKcjqbtjBYzqM1uZUfgAAADk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:57.815585 2026] [security2:error] [pid 643253:tid 643373] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/wp-login.php"] [unique_id "amuFKcjqbtjBYzqM1uZUgwAAInY"]
[Thu Jul 30 12:08:58.020772 2026] [security2:error] [pid 643253:tid 643426] [client 52.167.144.210:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuFKcjqbtjBYzqM1uZUgAAAACo"]
[Thu Jul 30 12:08:58.061373 2026] [security2:error] [pid 643253:tid 643429] [client 20.52.125.110:12261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/feedback.php"] [unique_id "amuFKsjqbtjBYzqM1uZUiwAAAC0"]
[Thu Jul 30 12:08:58.161711 2026] [security2:error] [pid 643253:tid 643333] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/wp-load.php"] [unique_id "amuFKsjqbtjBYzqM1uZUjAAAAk4"]
[Thu Jul 30 12:08:58.378040 2026] [security2:error] [pid 643253:tid 643394] [client 68.221.186.136:36782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/default.php"] [unique_id "amuFKsjqbtjBYzqM1uZUjQAAAAo"]
[Thu Jul 30 12:08:58.396067 2026] [core:notice] [pid 643253:tid 643472] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:58.402423 2026] [security2:error] [pid 643253:tid 643472] [client 103.215.74.26:51786] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFKsjqbtjBYzqM1uZUjgAAAFg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:58.466268 2026] [security2:error] [pid 643253:tid 643381] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/file.php"] [unique_id "amuFKsjqbtjBYzqM1uZUlQAAbH4"]
[Thu Jul 30 12:08:58.596271 2026] [security2:error] [pid 643253:tid 643467] [client 74.7.175.190:56454] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cpanel.bah.djb.temporary.site"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amuFKsjqbtjBYzqM1uZUlgAAAFM"]
[Thu Jul 30 12:08:58.725514 2026] [security2:error] [pid 643253:tid 643458] [client 20.52.125.110:12170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/gettest.php"] [unique_id "amuFKsjqbtjBYzqM1uZUmgAAAEo"]
[Thu Jul 30 12:08:58.791088 2026] [security2:error] [pid 643253:tid 643364] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/dropdown.php"] [unique_id "amuFKsjqbtjBYzqM1uZUnAAARG0"]
[Thu Jul 30 12:08:59.146512 2026] [security2:error] [pid 643253:tid 643263] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/plugins/dropdown.php"] [unique_id "amuFK8jqbtjBYzqM1uZUpgAAdQg"]
[Thu Jul 30 12:08:59.262972 2026] [security2:error] [pid 643253:tid 643470] [client 20.52.125.110:12216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/maint.php"] [unique_id "amuFK8jqbtjBYzqM1uZUpwAAAFY"]
[Thu Jul 30 12:08:59.307570 2026] [security2:error] [pid 643253:tid 643484] [client 57.141.0.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuFKsjqbtjBYzqM1uZUmQAAAGQ"]
[Thu Jul 30 12:08:59.467381 2026] [security2:error] [pid 643253:tid 643379] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/includes/index.php"] [unique_id "amuFK8jqbtjBYzqM1uZUqwAAIXw"]
[Thu Jul 30 12:08:59.797581 2026] [security2:error] [pid 643253:tid 643289] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-signup.php"] [unique_id "amuFK8jqbtjBYzqM1uZUrwAACyI"]
[Thu Jul 30 12:09:00.137156 2026] [security2:error] [pid 643253:tid 643284] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/images/css.php"] [unique_id "amuFLMjqbtjBYzqM1uZUtwAAKR0"]
[Thu Jul 30 12:09:00.484616 2026] [security2:error] [pid 643253:tid 643271] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/chosen.php"] [unique_id "amuFLMjqbtjBYzqM1uZUuAAAARA"]
[Thu Jul 30 12:09:00.701859 2026] [security2:error] [pid 643253:tid 643459] [client 20.52.125.110:12196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/files.php"] [unique_id "amuFLMjqbtjBYzqM1uZUwgAAAEs"]
[Thu Jul 30 12:09:00.796860 2026] [security2:error] [pid 643253:tid 643372] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/cong.php"] [unique_id "amuFLMjqbtjBYzqM1uZUwwAAZnU"]
[Thu Jul 30 12:09:00.832082 2026] [security2:error] [pid 643253:tid 643316] [remote 74.7.241.60:57284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/article.php"] [unique_id "amuFLMjqbtjBYzqM1uZUxAAAED0"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/main_image_6a3229a631e84.jpg
[Thu Jul 30 12:09:01.105355 2026] [security2:error] [pid 643253:tid 643296] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/mah.php"] [unique_id "amuFLcjqbtjBYzqM1uZUywAAWyk"]
[Thu Jul 30 12:09:01.208445 2026] [security2:error] [pid 643253:tid 643498] [client 68.221.186.136:23181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/dropdown.php"] [unique_id "amuFLcjqbtjBYzqM1uZUzQAAAHI"]
[Thu Jul 30 12:09:01.423242 2026] [security2:error] [pid 643253:tid 643293] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amuFLcjqbtjBYzqM1uZUzwAAIyY"]
[Thu Jul 30 12:09:01.567025 2026] [security2:error] [pid 643253:tid 643421] [client 20.52.125.110:12246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/gecko.php"] [unique_id "amuFLcjqbtjBYzqM1uZU0AAAACU"]
[Thu Jul 30 12:09:01.736023 2026] [security2:error] [pid 643253:tid 643307] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/ova-tools.php"] [unique_id "amuFLcjqbtjBYzqM1uZU1wAABzQ"]
[Thu Jul 30 12:09:02.026958 2026] [security2:error] [pid 643253:tid 643417] [client 68.221.186.136:37861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/edit.php"] [unique_id "amuFLsjqbtjBYzqM1uZU2gAAACE"]
[Thu Jul 30 12:09:02.083373 2026] [security2:error] [pid 643253:tid 643297] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "amuFLsjqbtjBYzqM1uZU2wAAQio"]
[Thu Jul 30 12:09:02.159032 2026] [security2:error] [pid 643253:tid 643469] [client 20.52.125.110:12242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/zwso.php"] [unique_id "amuFLsjqbtjBYzqM1uZU4AAAAFU"]
[Thu Jul 30 12:09:02.414673 2026] [security2:error] [pid 643253:tid 643292] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/style-engine/about.php"] [unique_id "amuFLsjqbtjBYzqM1uZU5wAAACU"]
[Thu Jul 30 12:09:02.747808 2026] [security2:error] [pid 643253:tid 643371] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "amuFLsjqbtjBYzqM1uZU8QAAKnQ"]
[Thu Jul 30 12:09:02.951160 2026] [security2:error] [pid 643253:tid 643385] [client 68.221.186.136:33669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/f35.php"] [unique_id "amuFLsjqbtjBYzqM1uZU9QAAAAE"]
[Thu Jul 30 12:09:03.118955 2026] [security2:error] [pid 643253:tid 643279] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuFL8jqbtjBYzqM1uZU9wAABBg"]
[Thu Jul 30 12:09:03.236755 2026] [security2:error] [pid 643253:tid 643505] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFLsjqbtjBYzqM1uZU9AAAeX8"]
[Thu Jul 30 12:09:03.400325 2026] [core:notice] [pid 643253:tid 643390] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:03.472496 2026] [security2:error] [pid 643253:tid 643291] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/banners/about.php"] [unique_id "amuFL8jqbtjBYzqM1uZU_wAAciQ"]
[Thu Jul 30 12:09:03.537042 2026] [autoindex:error] [pid 643253:tid 643319] [remote 27.124.10.134:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:09:03.691230 2026] [security2:error] [pid 643253:tid 643435] [client 68.221.186.136:31992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/f7.php"] [unique_id "amuFL8jqbtjBYzqM1uZVAgAAADM"]
[Thu Jul 30 12:09:03.833030 2026] [security2:error] [pid 643253:tid 643300] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/license.php"] [unique_id "amuFL8jqbtjBYzqM1uZVCgAAdS0"]
[Thu Jul 30 12:09:03.967924 2026] [core:notice] [pid 643253:tid 643484] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:04.136409 2026] [core:notice] [pid 643253:tid 643428] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:04.142789 2026] [security2:error] [pid 643253:tid 643428] [client 103.215.74.26:21540] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFMMjqbtjBYzqM1uZVDwAAACw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:04.153937 2026] [security2:error] [pid 643253:tid 643278] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/about.php"] [unique_id "amuFMMjqbtjBYzqM1uZVEAAABxc"]
[Thu Jul 30 12:09:04.327278 2026] [security2:error] [pid 643253:tid 643471] [client 2a03:2880:f800:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuFL8jqbtjBYzqM1uZVAwAAV0U"]
[Thu Jul 30 12:09:04.460414 2026] [security2:error] [pid 643253:tid 643327] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/about.php"] [unique_id "amuFMMjqbtjBYzqM1uZVGAAAVUg"]
[Thu Jul 30 12:09:04.805590 2026] [security2:error] [pid 643253:tid 643351] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuFMMjqbtjBYzqM1uZVHwAAa2A"]
[Thu Jul 30 12:09:04.895597 2026] [core:notice] [pid 643253:tid 643493] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:04.906178 2026] [security2:error] [pid 643253:tid 643493] [client 103.215.74.26:21554] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFMMjqbtjBYzqM1uZVJgAAAG0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:05.318506 2026] [security2:error] [pid 643253:tid 643342] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/schema-markup-rich-snippets/readme.txt"] [unique_id "amuFMcjqbtjBYzqM1uZVKgAAZVc"]
[Thu Jul 30 12:09:05.553381 2026] [security2:error] [pid 643253:tid 643318] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuFMcjqbtjBYzqM1uZVLgAAJz8"]
[Thu Jul 30 12:09:05.628735 2026] [core:notice] [pid 643253:tid 643459] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:05.634960 2026] [security2:error] [pid 643253:tid 643459] [client 103.215.74.26:21562] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFMcjqbtjBYzqM1uZVMAAAAEs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:05.874110 2026] [security2:error] [pid 643253:tid 643301] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/img/about.php"] [unique_id "amuFMcjqbtjBYzqM1uZVNQAARy4"]
[Thu Jul 30 12:09:05.945643 2026] [security2:error] [pid 643253:tid 643385] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFMcjqbtjBYzqM1uZVLwAAAUc"]
[Thu Jul 30 12:09:06.237644 2026] [security2:error] [pid 643253:tid 643355] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/languages/about.php"] [unique_id "amuFMsjqbtjBYzqM1uZVOQAAJWQ"]
[Thu Jul 30 12:09:06.327408 2026] [security2:error] [pid 643253:tid 643495] [client 20.52.125.110:12236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/13.php"] [unique_id "amuFMsjqbtjBYzqM1uZVOgAAAG8"]
[Thu Jul 30 12:09:06.362528 2026] [core:notice] [pid 643253:tid 643468] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:06.369291 2026] [security2:error] [pid 643253:tid 643468] [client 103.215.74.26:21572] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFMsjqbtjBYzqM1uZVPwAAAFQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:06.637454 2026] [security2:error] [pid 643253:tid 643328] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/customize/about.php"] [unique_id "amuFMsjqbtjBYzqM1uZVRgAATkk"]
[Thu Jul 30 12:09:06.752662 2026] [security2:error] [pid 643253:tid 643429] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFMsjqbtjBYzqM1uZVOwAALU0"], referer: https://www.spececigarette.com/wp-content/plugins/schema-markup-rich-snippets/Readme.txt
[Thu Jul 30 12:09:06.792336 2026] [core:notice] [pid 643253:tid 643431] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:06.942902 2026] [security2:error] [pid 643253:tid 643453] [client 20.52.125.110:12162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/ava.php"] [unique_id "amuFMsjqbtjBYzqM1uZVTQAAAEU"]
[Thu Jul 30 12:09:06.957742 2026] [security2:error] [pid 643253:tid 643346] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes.bak/html-api/about.php"] [unique_id "amuFMsjqbtjBYzqM1uZVTgAAJFs"]
[Thu Jul 30 12:09:07.110794 2026] [core:notice] [pid 643253:tid 643450] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:07.116970 2026] [security2:error] [pid 643253:tid 643450] [client 103.215.74.26:21580] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFM8jqbtjBYzqM1uZVUgAAAEI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:07.307233 2026] [security2:error] [pid 643253:tid 643347] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/widgets/about.php"] [unique_id "amuFM8jqbtjBYzqM1uZVVQAAT1w"]
[Thu Jul 30 12:09:07.501398 2026] [security2:error] [pid 643253:tid 643396] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFM8jqbtjBYzqM1uZVUwAADHE"]
[Thu Jul 30 12:09:07.667683 2026] [security2:error] [pid 643253:tid 643350] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/IXR/about.php"] [unique_id "amuFM8jqbtjBYzqM1uZVXAAAfV8"]
[Thu Jul 30 12:09:07.849034 2026] [core:notice] [pid 643253:tid 643436] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:07.855461 2026] [security2:error] [pid 643253:tid 643436] [client 103.215.74.26:21590] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFM8jqbtjBYzqM1uZVXQAAADQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:07.905830 2026] [security2:error] [pid 643253:tid 643397] [client 20.52.125.110:17588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/main.php"] [unique_id "amuFM8jqbtjBYzqM1uZVXwAAAA0"]
[Thu Jul 30 12:09:07.986625 2026] [security2:error] [pid 643253:tid 643325] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/js/about.php"] [unique_id "amuFM8jqbtjBYzqM1uZVYwAAbEY"]
[Thu Jul 30 12:09:08.272659 2026] [security2:error] [pid 643253:tid 643388] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFM8jqbtjBYzqM1uZVXgAABGc"], referer: https://www.spececigarette.com/wp-content/plugins/schema-markup-rich-snippets/README.txt
[Thu Jul 30 12:09:08.292446 2026] [security2:error] [pid 643253:tid 643341] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amuFNMjqbtjBYzqM1uZVaAAAHVY"]
[Thu Jul 30 12:09:08.318475 2026] [core:notice] [pid 643253:tid 643376] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:08.417706 2026] [security2:error] [pid 643253:tid 643476] [client 74.7.244.30:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.kamiliacademy.com"] [uri "/index.php"] [unique_id "amuFMMjqbtjBYzqM1uZVGwAAAFw"]
[Thu Jul 30 12:09:08.418680 2026] [security2:error] [pid 643253:tid 643442] [client 74.7.244.30:54000] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.kamiliacademy.com"] [uri "/robots.txt"] [unique_id "amuFMMjqbtjBYzqM1uZVGQAAOlE"]
[Thu Jul 30 12:09:08.598841 2026] [security2:error] [pid 643253:tid 643366] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/pomo/about.php"] [unique_id "amuFNMjqbtjBYzqM1uZVdAAALm8"]
[Thu Jul 30 12:09:08.603645 2026] [core:notice] [pid 643253:tid 643418] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:08.610165 2026] [security2:error] [pid 643253:tid 643418] [client 103.215.74.26:21598] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFNMjqbtjBYzqM1uZVdQAAACI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:08.643273 2026] [security2:error] [pid 643253:tid 643369] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/automattic-for-agencies-client/readme.txt"] [unique_id "amuFNMjqbtjBYzqM1uZVdgAAc3I"]
[Thu Jul 30 12:09:08.906622 2026] [security2:error] [pid 643253:tid 643345] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/block-patterns/about.php"] [unique_id "amuFNMjqbtjBYzqM1uZVegAAQVo"]
[Thu Jul 30 12:09:09.246819 2026] [security2:error] [pid 643253:tid 643256] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/updraft/about.php"] [unique_id "amuFNcjqbtjBYzqM1uZVggAATwE"]
[Thu Jul 30 12:09:09.274447 2026] [security2:error] [pid 643253:tid 643500] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFNMjqbtjBYzqM1uZVewAAdGg"]
[Thu Jul 30 12:09:09.335094 2026] [core:notice] [pid 643253:tid 643409] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:09.341568 2026] [security2:error] [pid 643253:tid 643409] [client 103.215.74.26:21600] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFNcjqbtjBYzqM1uZVgwAAABk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:09.427470 2026] [security2:error] [pid 643253:tid 643480] [client 20.52.125.110:17597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/wp-file.php"] [unique_id "amuFNcjqbtjBYzqM1uZVhQAAAGA"]
[Thu Jul 30 12:09:09.558214 2026] [security2:error] [pid 643253:tid 643265] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "amuFNcjqbtjBYzqM1uZViQAAFwo"]
[Thu Jul 30 12:09:09.868659 2026] [security2:error] [pid 643253:tid 643373] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/themes/about.php"] [unique_id "amuFNcjqbtjBYzqM1uZVjgAAOXY"]
[Thu Jul 30 12:09:10.022447 2026] [security2:error] [pid 643253:tid 643397] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFNcjqbtjBYzqM1uZVjQAADWI"], referer: https://www.spececigarette.com/wp-content/plugins/automattic-for-agencies-client/Readme.txt
[Thu Jul 30 12:09:10.069712 2026] [core:notice] [pid 643253:tid 643492] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:10.075739 2026] [security2:error] [pid 643253:tid 643492] [client 103.215.74.26:21608] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFNsjqbtjBYzqM1uZVkwAAAGw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:10.233672 2026] [security2:error] [pid 643253:tid 643349] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/includes/about.php"] [unique_id "amuFNsjqbtjBYzqM1uZVmAAAXl4"]
[Thu Jul 30 12:09:10.262824 2026] [security2:error] [pid 643253:tid 643381] [remote 74.7.241.59:44542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuFNsjqbtjBYzqM1uZVmQAAXX4"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/forms/actions
[Thu Jul 30 12:09:10.527137 2026] [security2:error] [pid 643253:tid 643405] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFNsjqbtjBYzqM1uZVlwAAFU4"]
[Thu Jul 30 12:09:10.562491 2026] [security2:error] [pid 643253:tid 643365] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/images/about.php"] [unique_id "amuFNsjqbtjBYzqM1uZVmwAACW4"]
[Thu Jul 30 12:09:10.580602 2026] [lsapi:error] [pid 643253:tid 643357] [remote 102.209.111.62:0] [host flixon.net] Error receiving response: ReceiveResponse: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1009; user ID 1009), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://flixon.net/video/love-hurts-vj-junior/
[Thu Jul 30 12:09:10.751087 2026] [security2:error] [pid 643253:tid 643403] [client 20.52.125.110:17561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/wp-signin.php"] [unique_id "amuFNsjqbtjBYzqM1uZVpAAAABM"]
[Thu Jul 30 12:09:10.796621 2026] [core:notice] [pid 643253:tid 643456] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:10.803083 2026] [security2:error] [pid 643253:tid 643456] [client 103.215.74.26:21620] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFNsjqbtjBYzqM1uZVpQAAAEg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:11.209932 2026] [security2:error] [pid 643253:tid 643489] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFNsjqbtjBYzqM1uZVpgAAaQg"], referer: https://www.spececigarette.com/wp-content/plugins/automattic-for-agencies-client/README.txt
[Thu Jul 30 12:09:11.761341 2026] [security2:error] [pid 643253:tid 643417] [client 172.236.9.101:61203] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFN8jqbtjBYzqM1uZVrgAAACE"]
[Thu Jul 30 12:09:11.838467 2026] [security2:error] [pid 643253:tid 643448] [client 172.236.9.101:60436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFN8jqbtjBYzqM1uZVsAAAAEA"]
[Thu Jul 30 12:09:11.864853 2026] [security2:error] [pid 643253:tid 643449] [client 172.236.9.101:1230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFN8jqbtjBYzqM1uZVsgAAAEE"]
[Thu Jul 30 12:09:11.865568 2026] [security2:error] [pid 643253:tid 643404] [client 172.236.9.101:35736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFN8jqbtjBYzqM1uZVsQAAABQ"]
[Thu Jul 30 12:09:11.899995 2026] [security2:error] [pid 643253:tid 643281] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/blogs.dir/about.php"] [unique_id "amuFN8jqbtjBYzqM1uZVwQAAZRo"]
[Thu Jul 30 12:09:11.962589 2026] [security2:error] [pid 643253:tid 643398] [client 20.52.125.110:12164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/simi.php"] [unique_id "amuFN8jqbtjBYzqM1uZV0QAAAA4"]
[Thu Jul 30 12:09:12.307630 2026] [security2:error] [pid 643253:tid 643279] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/images/about.php"] [unique_id "amuFOMjqbtjBYzqM1uZV8wAASRg"]
[Thu Jul 30 12:09:12.462427 2026] [security2:error] [pid 643253:tid 643406] [client 20.52.125.110:12199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/wp-conf.php"] [unique_id "amuFOMjqbtjBYzqM1uZV9AAAABY"]
[Thu Jul 30 12:09:12.631992 2026] [security2:error] [pid 643253:tid 643303] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/about.php"] [unique_id "amuFOMjqbtjBYzqM1uZV9QAALDA"]
[Thu Jul 30 12:09:12.649687 2026] [security2:error] [pid 643253:tid 643490] [client 213.152.187.215:50668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.187.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuFOMjqbtjBYzqM1uZV9gAAAGo"]
[Thu Jul 30 12:09:12.649879 2026] [security2:error] [pid 643253:tid 643490] [client 213.152.187.215:50668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuFOMjqbtjBYzqM1uZV9gAAAGo"]
[Thu Jul 30 12:09:12.962148 2026] [security2:error] [pid 643253:tid 643291] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/cgi-bin/about.php"] [unique_id "amuFOMjqbtjBYzqM1uZV_gAAaSQ"]
[Thu Jul 30 12:09:13.195758 2026] [security2:error] [pid 643253:tid 643432] [client 20.52.125.110:12172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/WZGHHra0r3.php"] [unique_id "amuFOcjqbtjBYzqM1uZWBwAAADA"]
[Thu Jul 30 12:09:13.291727 2026] [security2:error] [pid 643253:tid 643315] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/gallery/about.php"] [unique_id "amuFOcjqbtjBYzqM1uZWDgAAADw"]
[Thu Jul 30 12:09:13.473862 2026] [security2:error] [pid 643253:tid 643459] [client 172.236.9.101:12679] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFOMjqbtjBYzqM1uZV4gAAAEs"]
[Thu Jul 30 12:09:13.503283 2026] [security2:error] [pid 643253:tid 643401] [client 172.236.9.101:48577] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFOMjqbtjBYzqM1uZV4AAAABE"]
[Thu Jul 30 12:09:13.503457 2026] [security2:error] [pid 643253:tid 643472] [client 172.236.9.101:43412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFOMjqbtjBYzqM1uZV4QAAAFg"]
[Thu Jul 30 12:09:13.507475 2026] [security2:error] [pid 643253:tid 643498] [client 172.236.9.101:35838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFOMjqbtjBYzqM1uZV4wAAAHI"]
[Thu Jul 30 12:09:13.573306 2026] [security2:error] [pid 643253:tid 643444] [client 172.236.9.101:46072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFOMjqbtjBYzqM1uZV7gAAADw"]
[Thu Jul 30 12:09:13.577092 2026] [security2:error] [pid 643253:tid 643506] [client 172.236.9.101:6827] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFOMjqbtjBYzqM1uZV5QAAAHo"]
[Thu Jul 30 12:09:13.579752 2026] [security2:error] [pid 643253:tid 643385] [client 172.236.9.101:65117] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFOMjqbtjBYzqM1uZV5AAAAAE"]
[Thu Jul 30 12:09:13.597615 2026] [security2:error] [pid 643253:tid 643390] [client 172.236.9.101:22679] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFOMjqbtjBYzqM1uZV5gAAAAY"]
[Thu Jul 30 12:09:13.598311 2026] [security2:error] [pid 643253:tid 643466] [client 172.236.9.101:23710] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFOMjqbtjBYzqM1uZV5wAAAFI"]
[Thu Jul 30 12:09:13.602678 2026] [security2:error] [pid 643253:tid 643439] [client 172.236.9.101:51232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFOMjqbtjBYzqM1uZV6AAAADc"]
[Thu Jul 30 12:09:13.603871 2026] [security2:error] [pid 643253:tid 643478] [client 172.236.9.101:58755] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFOMjqbtjBYzqM1uZV6gAAAF4"]
[Thu Jul 30 12:09:13.606706 2026] [security2:error] [pid 643253:tid 643452] [client 172.236.9.101:31987] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFOMjqbtjBYzqM1uZV7QAAAEQ"]
[Thu Jul 30 12:09:13.608614 2026] [security2:error] [pid 643253:tid 643413] [client 172.236.9.101:60570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFOMjqbtjBYzqM1uZV7AAAAB0"]
[Thu Jul 30 12:09:13.619930 2026] [security2:error] [pid 643253:tid 643405] [client 172.236.9.101:28160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFOMjqbtjBYzqM1uZV8AAAABU"]
[Thu Jul 30 12:09:13.621202 2026] [security2:error] [pid 643253:tid 643393] [client 172.236.9.101:60318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFOMjqbtjBYzqM1uZV8gAAAAk"]
[Thu Jul 30 12:09:13.624827 2026] [security2:error] [pid 643253:tid 643476] [client 172.236.9.101:44506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFOMjqbtjBYzqM1uZV8QAAAFw"]
[Thu Jul 30 12:09:13.638306 2026] [security2:error] [pid 643253:tid 643339] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuFOcjqbtjBYzqM1uZWEwAAaFQ"]
[Thu Jul 30 12:09:13.857262 2026] [security2:error] [pid 643253:tid 643317] [remote 216.73.216.152:2913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuFOcjqbtjBYzqM1uZWGgAARz4"]
[Thu Jul 30 12:09:13.974635 2026] [security2:error] [pid 643253:tid 643335] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/css/about.php"] [unique_id "amuFOcjqbtjBYzqM1uZWGwAAFlA"]
[Thu Jul 30 12:09:14.281267 2026] [security2:error] [pid 643253:tid 643301] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/images/about.php"] [unique_id "amuFOsjqbtjBYzqM1uZWHwAAai4"]
[Thu Jul 30 12:09:15.082415 2026] [security2:error] [pid 643253:tid 643346] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/pki-validation/cloud.php"] [unique_id "amuFO8jqbtjBYzqM1uZWNAAAC1s"]
[Thu Jul 30 12:09:15.388179 2026] [security2:error] [pid 643253:tid 643347] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/acme-challenge/cloud.php"] [unique_id "amuFO8jqbtjBYzqM1uZWOwAAS1w"]
[Thu Jul 30 12:09:15.739943 2026] [security2:error] [pid 643253:tid 643376] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/network/cloud.php"] [unique_id "amuFO8jqbtjBYzqM1uZWSgAAHXk"]
[Thu Jul 30 12:09:15.924415 2026] [security2:error] [pid 643253:tid 643385] [client 144.124.193.168:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amuFO8jqbtjBYzqM1uZWRgAAAAE"], referer: https://tereashops.com/product/ploom-x-aura-evo-tropical-berry-crystal-%E7%86%B1%E5%B8%B6%E8%8E%93%E6%9E%9C%E8%8A%92%E6%9E%9C%E7%88%86%E7%8F%A0%E7%85%99%E5%BD%88/
[Thu Jul 30 12:09:15.948537 2026] [security2:error] [pid 643253:tid 643452] [client 20.52.125.110:17554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/bala.php"] [unique_id "amuFO8jqbtjBYzqM1uZWUwAAAEQ"]
[Thu Jul 30 12:09:16.061606 2026] [security2:error] [pid 643253:tid 643340] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/cloud.php"] [unique_id "amuFPMjqbtjBYzqM1uZWVAAAW1U"]
[Thu Jul 30 12:09:16.379356 2026] [security2:error] [pid 643253:tid 643377] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/cgi-bin/cloud.php"] [unique_id "amuFPMjqbtjBYzqM1uZWVQAAAno"]
[Thu Jul 30 12:09:16.527501 2026] [core:notice] [pid 643253:tid 643477] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:16.534073 2026] [security2:error] [pid 643253:tid 643477] [client 103.215.74.26:14510] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFPMjqbtjBYzqM1uZWXQAAAF0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:16.599691 2026] [security2:error] [pid 643253:tid 643348] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/op-kassa-for-woocommerce/readme.txt"] [unique_id "amuFPMjqbtjBYzqM1uZWXgAAal0"]
[Thu Jul 30 12:09:16.705821 2026] [security2:error] [pid 643253:tid 643323] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/updates.php"] [unique_id "amuFPMjqbtjBYzqM1uZWXwAAd0Q"]
[Thu Jul 30 12:09:16.825069 2026] [core:notice] [pid 643253:tid 643428] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:17.939523 2026] [http2:info] [pid 703393:tid 703393] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 12:09:17.999193 2026] [security2:error] [pid 643253:tid 643467] [client 20.52.125.110:12185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/bk.php"] [unique_id "amuFPcjqbtjBYzqM1uZWbAAAAFM"]
[Thu Jul 30 12:09:18.110633 2026] [core:notice] [pid 703393:tid 703525] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:18.200448 2026] [security2:error] [pid 703393:tid 703395] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/css/cloud.php"] [unique_id "amuFPs637Arlr6Yb1EfnyQAAiQE"]
[Thu Jul 30 12:09:18.202354 2026] [core:notice] [pid 703393:tid 703523] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:18.211173 2026] [security2:error] [pid 703393:tid 703523] [client 103.215.74.26:14516] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFPs637Arlr6Yb1EfnyAAAAIU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:18.381064 2026] [security2:error] [pid 703393:tid 703533] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFPs637Arlr6Yb1EfnwgAAj38"]
[Thu Jul 30 12:09:18.515372 2026] [security2:error] [pid 703393:tid 703457] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/user/cloud.php"] [unique_id "amuFPs637Arlr6Yb1EfoBwAAsz8"]
[Thu Jul 30 12:09:18.932902 2026] [security2:error] [pid 703393:tid 703462] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/img/cloud.php"] [unique_id "amuFPs637Arlr6Yb1EfoEgAAxkQ"]
[Thu Jul 30 12:09:18.937029 2026] [core:notice] [pid 703393:tid 703580] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:18.944673 2026] [security2:error] [pid 703393:tid 703580] [client 103.215.74.26:14530] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFPs637Arlr6Yb1EfoEwAAAL4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:19.282395 2026] [security2:error] [pid 703393:tid 703481] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "amuFP8637Arlr6Yb1EfoLAAA4Vc"]
[Thu Jul 30 12:09:19.460638 2026] [security2:error] [pid 703393:tid 703586] [client 20.52.125.110:17548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/ahax.php"] [unique_id "amuFP8637Arlr6Yb1EfoNAAAAMQ"]
[Thu Jul 30 12:09:19.612346 2026] [security2:error] [pid 703393:tid 703489] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/images/cloud.php"] [unique_id "amuFP8637Arlr6Yb1EfoOQAA8V8"]
[Thu Jul 30 12:09:19.665669 2026] [core:notice] [pid 703393:tid 703622] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:19.673260 2026] [security2:error] [pid 703393:tid 703622] [client 103.215.74.26:14540] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFP8637Arlr6Yb1EfoOwAAAOg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:19.776801 2026] [security2:error] [pid 703393:tid 703626] [client 52.167.144.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuFP8637Arlr6Yb1EfoMwAAAOw"]
[Thu Jul 30 12:09:19.946040 2026] [security2:error] [pid 703393:tid 703493] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/avaa.php"] [unique_id "amuFP8637Arlr6Yb1EfoQQAA_2M"]
[Thu Jul 30 12:09:20.174672 2026] [security2:error] [pid 703393:tid 703634] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFP8637Arlr6Yb1EfoPQAA9GE"], referer: https://www.spececigarette.com/wp-content/plugins/op-kassa-for-woocommerce/Readme.txt
[Thu Jul 30 12:09:20.274710 2026] [security2:error] [pid 703393:tid 703495] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/images/cloud.php"] [unique_id "amuFQM637Arlr6Yb1EfoRQAAjWU"]
[Thu Jul 30 12:09:20.390833 2026] [core:notice] [pid 703393:tid 703649] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:20.397628 2026] [security2:error] [pid 703393:tid 703649] [client 103.215.74.26:14556] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFQM637Arlr6Yb1EfoSgAAAQM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:20.585677 2026] [security2:error] [pid 703393:tid 703500] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/js/widgets/cloud.php"] [unique_id "amuFQM637Arlr6Yb1EfoTwAAo2o"]
[Thu Jul 30 12:09:20.686081 2026] [security2:error] [pid 703393:tid 703523] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFQM637Arlr6Yb1EfoSQAAhWc"]
[Thu Jul 30 12:09:20.895639 2026] [security2:error] [pid 703393:tid 703504] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/Requests/Text/admin.php"] [unique_id "amuFQM637Arlr6Yb1EfoWQAAsG4"]
[Thu Jul 30 12:09:21.129136 2026] [core:notice] [pid 703393:tid 703565] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:21.136665 2026] [security2:error] [pid 703393:tid 703565] [client 103.215.74.26:14562] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFQc637Arlr6Yb1EfoWgAAAK8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:21.223050 2026] [security2:error] [pid 703393:tid 703508] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "amuFQc637Arlr6Yb1EfoYAAAwnI"]
[Thu Jul 30 12:09:21.547062 2026] [security2:error] [pid 703393:tid 703510] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/includes/cloud.php"] [unique_id "amuFQc637Arlr6Yb1EfoZAAAmHQ"]
[Thu Jul 30 12:09:21.575789 2026] [security2:error] [pid 703393:tid 703572] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFQc637Arlr6Yb1EfoXQAAtnA"], referer: https://www.spececigarette.com/wp-content/plugins/op-kassa-for-woocommerce/README.txt
[Thu Jul 30 12:09:21.891432 2026] [core:notice] [pid 703393:tid 703589] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:21.896358 2026] [security2:error] [pid 703393:tid 703516] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/css/colors/blue/cloud.php"] [unique_id "amuFQc637Arlr6Yb1EfobQAA1Xo"]
[Thu Jul 30 12:09:21.898396 2026] [security2:error] [pid 703393:tid 703589] [client 103.215.74.26:14564] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFQc637Arlr6Yb1EfoawAAAMc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:22.240068 2026] [security2:error] [pid 703393:tid 703518] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/cloud.php"] [unique_id "amuFQs637Arlr6Yb1EfoeAAA4Hw"]
[Thu Jul 30 12:09:22.507386 2026] [security2:error] [pid 703393:tid 703579] [client 172.237.109.114:22745] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFQc637Arlr6Yb1EfocAAAAL0"]
[Thu Jul 30 12:09:22.550553 2026] [security2:error] [pid 703393:tid 703606] [client 172.237.109.114:27831] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFQc637Arlr6Yb1EfocQAAANg"]
[Thu Jul 30 12:09:22.554063 2026] [security2:error] [pid 703393:tid 703577] [client 172.237.109.114:58560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFQc637Arlr6Yb1EfocgAAALs"]
[Thu Jul 30 12:09:22.570661 2026] [security2:error] [pid 703393:tid 703395] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/updates.php"] [unique_id "amuFQs637Arlr6Yb1EfofQAAxAE"]
[Thu Jul 30 12:09:22.582719 2026] [security2:error] [pid 703393:tid 703607] [client 172.237.109.114:35668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFQs637Arlr6Yb1EfocwAAANk"]
[Thu Jul 30 12:09:22.583729 2026] [security2:error] [pid 703393:tid 703608] [client 172.237.109.114:3417] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFQs637Arlr6Yb1EfodAAAANo"]
[Thu Jul 30 12:09:22.622336 2026] [core:notice] [pid 703393:tid 703619] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:22.629101 2026] [security2:error] [pid 703393:tid 703619] [client 103.215.74.26:14576] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFQs637Arlr6Yb1EfofgAAAOU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:22.905539 2026] [security2:error] [pid 703393:tid 703399] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/libraries/legacy/updates.php"] [unique_id "amuFQs637Arlr6Yb1EfoggAA7AU"]
[Thu Jul 30 12:09:23.216917 2026] [security2:error] [pid 703393:tid 703402] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/libraries/phpmailer/updates.php"] [unique_id "amuFQ8637Arlr6Yb1EfohwAA-gg"]
[Thu Jul 30 12:09:23.356031 2026] [core:notice] [pid 703393:tid 703641] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:23.362685 2026] [security2:error] [pid 703393:tid 703641] [client 103.215.74.26:20014] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFQ8637Arlr6Yb1EfoiwAAAPs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:23.550779 2026] [security2:error] [pid 703393:tid 703405] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/libraries/vendor/updates.php"] [unique_id "amuFQ8637Arlr6Yb1EfojwAAjQs"]
[Thu Jul 30 12:09:23.874091 2026] [security2:error] [pid 703393:tid 703415] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/alfa-rex.php7"] [unique_id "amuFQ8637Arlr6Yb1EfomgAApBU"]
[Thu Jul 30 12:09:24.060440 2026] [security2:error] [pid 703393:tid 703417] [remote 74.7.242.7:46426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.242.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/"] [unique_id "amuFRM637Arlr6Yb1EfonwAAhhc"], referer: https://www.thdinfinity.com/
[Thu Jul 30 12:09:24.084470 2026] [core:notice] [pid 703393:tid 703649] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:24.092022 2026] [security2:error] [pid 703393:tid 703649] [client 103.215.74.26:20026] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFRM637Arlr6Yb1EfooAAAAQM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:24.193726 2026] [security2:error] [pid 703393:tid 703418] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/alfanew.php"] [unique_id "amuFRM637Arlr6Yb1EfooQAArBg"]
[Thu Jul 30 12:09:24.510139 2026] [security2:error] [pid 703393:tid 703429] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/plugins/Cache/Cache.php"] [unique_id "amuFRM637Arlr6Yb1EfoqwAAwyM"]
[Thu Jul 30 12:09:24.816115 2026] [core:notice] [pid 703393:tid 703568] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:24.818960 2026] [security2:error] [pid 703393:tid 703430] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/js/widgets/about.php7"] [unique_id "amuFRM637Arlr6Yb1EforQAAtCQ"]
[Thu Jul 30 12:09:24.822870 2026] [security2:error] [pid 703393:tid 703568] [client 103.215.74.26:20034] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFRM637Arlr6Yb1EforAAAALI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:24.937876 2026] [core:notice] [pid 703393:tid 703536] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:25.141529 2026] [security2:error] [pid 703393:tid 703439] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-p.php7"] [unique_id "amuFRc637Arlr6Yb1EfowAAA2y0"]
[Thu Jul 30 12:09:25.401942 2026] [security2:error] [pid 703393:tid 703615] [client 52.167.144.147:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuFRc637Arlr6Yb1EfovgAAAOE"]
[Thu Jul 30 12:09:25.504411 2026] [security2:error] [pid 703393:tid 703421] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/repeater.php"] [unique_id "amuFRc637Arlr6Yb1EfoyAAA6xs"]
[Thu Jul 30 12:09:25.824244 2026] [security2:error] [pid 703393:tid 703453] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/repeater.php"] [unique_id "amuFRc637Arlr6Yb1EfozQABAjs"]
[Thu Jul 30 12:09:26.169835 2026] [security2:error] [pid 703393:tid 703444] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/repeater.php"] [unique_id "amuFRs637Arlr6Yb1Efo1wAAnjI"]
[Thu Jul 30 12:09:26.494135 2026] [security2:error] [pid 703393:tid 703452] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wsoyanz.php"] [unique_id "amuFRs637Arlr6Yb1Efo3wAAiDo"]
[Thu Jul 30 12:09:26.722165 2026] [security2:error] [pid 703393:tid 703457] [remote 47.128.21.210:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "intelprocess.net"] [uri "/robots.txt"] [unique_id "amuFRs637Arlr6Yb1Efo4wAAuT8"]
[Thu Jul 30 12:09:26.839148 2026] [security2:error] [pid 703393:tid 703422] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/yanz.php"] [unique_id "amuFRs637Arlr6Yb1Efo5AAAtBw"]
[Thu Jul 30 12:09:26.937370 2026] [security2:error] [pid 703393:tid 703409] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/wc-rest-payment/readme.txt"] [unique_id "amuFRs637Arlr6Yb1Efo5QAAxQ8"]
[Thu Jul 30 12:09:27.185956 2026] [security2:error] [pid 703393:tid 703458] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/plugins/seoo/wsoyanz.php"] [unique_id "amuFR8637Arlr6Yb1Efo7QAAvkA"]
[Thu Jul 30 12:09:27.260005 2026] [security2:error] [pid 703393:tid 703592] [client 85.208.96.210:55394] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/10/30/joao-azevedo-e-reeleito-governador-da-paraiba/"] [unique_id "amuFR8637Arlr6Yb1Efo7gAAAMo"]
[Thu Jul 30 12:09:27.260147 2026] [security2:error] [pid 703393:tid 703592] [client 85.208.96.210:55394] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/10/30/joao-azevedo-e-reeleito-governador-da-paraiba/"] [unique_id "amuFR8637Arlr6Yb1Efo7gAAAMo"]
[Thu Jul 30 12:09:27.530814 2026] [security2:error] [pid 703393:tid 703448] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/plugins/seoo/wsoyanz1.php"] [unique_id "amuFR8637Arlr6Yb1Efo9gAA2TY"]
[Thu Jul 30 12:09:27.633545 2026] [security2:error] [pid 703393:tid 703593] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFR8637Arlr6Yb1Efo7wAAyxo"]
[Thu Jul 30 12:09:27.843183 2026] [security2:error] [pid 703393:tid 703463] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/cache-compat.php"] [unique_id "amuFR8637Arlr6Yb1EfpAwAA60U"]
[Thu Jul 30 12:09:28.142637 2026] [security2:error] [pid 703393:tid 703468] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/ajax-actions.php"] [unique_id "amuFSM637Arlr6Yb1EfpCgAAi0o"]
[Thu Jul 30 12:09:28.223966 2026] [security2:error] [pid 703393:tid 703469] [remote 103.77.162.29:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.162.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "madeninsabah.com"] [uri "/xmlrpc.php"] [unique_id "amuFSM637Arlr6Yb1EfpDwABAEs"]
[Thu Jul 30 12:09:28.224149 2026] [security2:error] [pid 703393:tid 703646] [client 103.77.162.29:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "madeninsabah.com"] [uri "/xmlrpc.php"] [unique_id "amuFSM637Arlr6Yb1EfpDwABAEs"]
[Thu Jul 30 12:09:28.507561 2026] [security2:error] [pid 703393:tid 703473] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/ajax-actions.php"] [unique_id "amuFSM637Arlr6Yb1EfpEgAAlk8"]
[Thu Jul 30 12:09:28.525339 2026] [autoindex:error] [pid 703393:tid 703475] [remote 45.33.74.9:57306] AH01276: Cannot serve directory /home1/vdbnyxte/public_html/website_19d94cc7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:09:28.817649 2026] [security2:error] [pid 703393:tid 703476] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-consar.php"] [unique_id "amuFSM637Arlr6Yb1EfpGgAA-1I"]
[Thu Jul 30 12:09:29.164932 2026] [security2:error] [pid 703393:tid 703459] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/repeater.php"] [unique_id "amuFSc637Arlr6Yb1EfpHwAAnUE"]
[Thu Jul 30 12:09:29.497573 2026] [security2:error] [pid 703393:tid 703479] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/admin-post.php"] [unique_id "amuFSc637Arlr6Yb1EfpJgAAnFU"]
[Thu Jul 30 12:09:29.842510 2026] [security2:error] [pid 703393:tid 703487] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/maint/maint/ajax-actions.php"] [unique_id "amuFSc637Arlr6Yb1EfpLgAA0l0"]
[Thu Jul 30 12:09:29.914437 2026] [security2:error] [pid 703393:tid 703549] [client 110.54.151.244:29556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "hris.rgserve.ph"] [uri "/my_attendance_mobile.php"] [unique_id "amuFSc637Arlr6Yb1EfpHgAAn0w"], referer: https://hris.rgserve.ph/time_mobile.php
[Thu Jul 30 12:09:29.930962 2026] [core:notice] [pid 703393:tid 703572] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:29.962701 2026] [security2:error] [pid 703393:tid 703601] [client 110.54.151.244:29556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "hris.rgserve.ph"] [uri "/my_attendance_mobile.php"] [unique_id "amuFSc637Arlr6Yb1EfpMAAA018"], referer: https://hris.rgserve.ph/time_mobile.php
[Thu Jul 30 12:09:30.105029 2026] [security2:error] [pid 703393:tid 703605] [client 110.54.151.244:29556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "hris.rgserve.ph"] [uri "/login.php"] [unique_id "amuFSs637Arlr6Yb1EfpMgAA114"], referer: https://hris.rgserve.ph/time_mobile.php
[Thu Jul 30 12:09:30.181657 2026] [security2:error] [pid 703393:tid 703492] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/dropdown.php"] [unique_id "amuFSs637Arlr6Yb1EfpNAAA2WI"]
[Thu Jul 30 12:09:30.481818 2026] [core:notice] [pid 703393:tid 703619] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:30.491457 2026] [fcgid:warn] [pid 703393:tid 703628] (70014)End of file found: [client 199.45.155.108:42640] mod_fcgid: can't get data from http client
[Thu Jul 30 12:09:30.544950 2026] [security2:error] [pid 703393:tid 703494] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/css/index.php"] [unique_id "amuFSs637Arlr6Yb1EfpQAAAz2Q"]
[Thu Jul 30 12:09:30.603864 2026] [core:notice] [pid 703393:tid 703610] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:30.611261 2026] [security2:error] [pid 703393:tid 703610] [client 103.215.74.26:20040] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFSs637Arlr6Yb1EfpQwAAANw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:30.882946 2026] [security2:error] [pid 703393:tid 703478] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/dropdown.php"] [unique_id "amuFSs637Arlr6Yb1EfpSgAAlVQ"]
[Thu Jul 30 12:09:31.200655 2026] [security2:error] [pid 703393:tid 703499] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/about.php"] [unique_id "amuFS8637Arlr6Yb1EfpTQAA72k"]
[Thu Jul 30 12:09:31.331478 2026] [core:notice] [pid 703393:tid 703638] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:31.339075 2026] [security2:error] [pid 703393:tid 703638] [client 103.215.74.26:20054] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFS8637Arlr6Yb1EfpUQAAAPg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:31.568948 2026] [security2:error] [pid 703393:tid 703502] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/about.php7"] [unique_id "amuFS8637Arlr6Yb1EfpVQAAm2w"]
[Thu Jul 30 12:09:31.786569 2026] [security2:error] [pid 703393:tid 703556] [client 18.192.166.72:64022] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuFS8637Arlr6Yb1EfpVgAAAKY"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:09:31.886463 2026] [security2:error] [pid 703393:tid 703504] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/alfanew.php7"] [unique_id "amuFS8637Arlr6Yb1EfpXQAAqm4"]
[Thu Jul 30 12:09:32.064308 2026] [core:notice] [pid 703393:tid 703559] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:32.071795 2026] [security2:error] [pid 703393:tid 703559] [client 103.215.74.26:20064] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFTM637Arlr6Yb1EfpXgAAAKk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:32.174420 2026] [core:notice] [pid 703393:tid 703583] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:32.178955 2026] [security2:error] [pid 703393:tid 703583] [client 18.192.166.72:64038] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFTM637Arlr6Yb1EfpXwAAAME"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:09:32.260750 2026] [security2:error] [pid 703393:tid 703503] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/adminfuns.php7"] [unique_id "amuFTM637Arlr6Yb1EfpYAAAsG0"]
[Thu Jul 30 12:09:32.600336 2026] [security2:error] [pid 703393:tid 703508] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/ebs.php7"] [unique_id "amuFTM637Arlr6Yb1EfpaAAAtnI"]
[Thu Jul 30 12:09:32.691790 2026] [security2:error] [pid 703393:tid 703549] [client 18.192.166.72:64040] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuFTM637Arlr6Yb1EfpagAAAJ8"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:09:32.799340 2026] [core:notice] [pid 703393:tid 703604] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:32.806123 2026] [security2:error] [pid 703393:tid 703604] [client 103.215.74.26:20072] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFTM637Arlr6Yb1EfpbQAAANY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:32.812487 2026] [security2:error] [pid 703393:tid 703588] [client 20.203.156.12:54936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/wp-load.php"] [unique_id "amuFTM637Arlr6Yb1EfpbgAAAMY"]
[Thu Jul 30 12:09:32.812644 2026] [security2:error] [pid 703393:tid 703588] [client 20.203.156.12:54936] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/wp-load.php"] [unique_id "amuFTM637Arlr6Yb1EfpbgAAAMY"]
[Thu Jul 30 12:09:32.950514 2026] [security2:error] [pid 703393:tid 703511] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/ws.php7"] [unique_id "amuFTM637Arlr6Yb1EfpdQAA8XU"]
[Thu Jul 30 12:09:33.291602 2026] [security2:error] [pid 703393:tid 703513] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/alfanew2.php7"] [unique_id "amuFTc637Arlr6Yb1EfpfAAAjXc"]
[Thu Jul 30 12:09:33.526008 2026] [security2:error] [pid 703393:tid 703512] [remote 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFTc637Arlr6Yb1EfpeQAAz3Y"], referer: https://www.spececigarette.com/wp-content/plugins/wc-rest-payment/Readme.txt
[Thu Jul 30 12:09:33.548526 2026] [core:notice] [pid 703393:tid 703646] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:33.555963 2026] [security2:error] [pid 703393:tid 703646] [client 103.215.74.26:54852] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFTc637Arlr6Yb1EfphgAAAQA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:33.632728 2026] [security2:error] [pid 703393:tid 703517] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/alfa-rex2.php7"] [unique_id "amuFTc637Arlr6Yb1EfphwAApns"]
[Thu Jul 30 12:09:33.675133 2026] [core:notice] [pid 703393:tid 703638] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:33.939312 2026] [security2:error] [pid 703393:tid 703400] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/images/index.php"] [unique_id "amuFTc637Arlr6Yb1EfpmQAA1QY"]
[Thu Jul 30 12:09:34.220426 2026] [security2:error] [pid 703393:tid 703584] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFTc637Arlr6Yb1EfplwAAwgA"]
[Thu Jul 30 12:09:34.277635 2026] [security2:error] [pid 703393:tid 703402] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "amuFTs637Arlr6Yb1EfpogAA2wg"]
[Thu Jul 30 12:09:34.286111 2026] [core:notice] [pid 703393:tid 703605] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:34.293661 2026] [security2:error] [pid 703393:tid 703605] [client 103.215.74.26:54860] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFTs637Arlr6Yb1EfpowAAANc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:34.590165 2026] [security2:error] [pid 703393:tid 703415] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "amuFTs637Arlr6Yb1EfpsgAA6RU"]
[Thu Jul 30 12:09:34.887708 2026] [security2:error] [pid 703393:tid 703414] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/plugins/seoplugins/mar.php"] [unique_id "amuFTs637Arlr6Yb1EfpwAAAohQ"]
[Thu Jul 30 12:09:34.928088 2026] [security2:error] [pid 703393:tid 703529] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFTs637Arlr6Yb1EfprQAAi38"], referer: https://www.spececigarette.com/wp-content/plugins/wc-rest-payment/README.txt
[Thu Jul 30 12:09:35.196623 2026] [security2:error] [pid 703393:tid 703424] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "amuFT8637Arlr6Yb1EfpywAAuR4"]
[Thu Jul 30 12:09:35.312793 2026] [security2:error] [pid 703393:tid 703411] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/woocommerce/readme.txt"] [unique_id "amuFT8637Arlr6Yb1Efp0QAAshE"]
[Thu Jul 30 12:09:35.513955 2026] [security2:error] [pid 703393:tid 703430] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/acme-challenge/xmrlpc.php"] [unique_id "amuFT8637Arlr6Yb1Efp2QAAjCQ"]
[Thu Jul 30 12:09:35.566311 2026] [core:notice] [pid 703393:tid 703523] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:35.831804 2026] [security2:error] [pid 703393:tid 703433] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/network/xmrlpc.php"] [unique_id "amuFT8637Arlr6Yb1Efp4QAA9yc"]
[Thu Jul 30 12:09:35.943392 2026] [security2:error] [pid 703393:tid 703613] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFT8637Arlr6Yb1Efp3QAA3yY"]
[Thu Jul 30 12:09:36.174026 2026] [security2:error] [pid 703393:tid 703437] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/xmrlpc.php"] [unique_id "amuFUM637Arlr6Yb1Efp7QAApCs"]
[Thu Jul 30 12:09:36.493380 2026] [security2:error] [pid 703393:tid 703623] [client 41.210.146.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuFUM637Arlr6Yb1Efp6gAA6Sw"], referer: https://flixon.net/free-movies/
[Thu Jul 30 12:09:36.497066 2026] [security2:error] [pid 703393:tid 703436] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "amuFUM637Arlr6Yb1Efp_wAAsCo"]
[Thu Jul 30 12:09:36.653224 2026] [security2:error] [pid 703393:tid 703527] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFUM637Arlr6Yb1Efp-gAAiS0"], referer: https://www.spececigarette.com/wp-content/plugins/woocommerce/Readme.txt
[Thu Jul 30 12:09:36.772241 2026] [security2:error] [pid 703393:tid 703632] [client 65.109.100.157:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amuFT8637Arlr6Yb1Efp4AAAAPI"]
[Thu Jul 30 12:09:36.822705 2026] [security2:error] [pid 703393:tid 703421] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/css/xmrlpc.php"] [unique_id "amuFUM637Arlr6Yb1EfqCQAAwBs"]
[Thu Jul 30 12:09:37.148277 2026] [security2:error] [pid 703393:tid 703454] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "amuFUc637Arlr6Yb1EfqEAAA1zw"]
[Thu Jul 30 12:09:37.188199 2026] [security2:error] [pid 703393:tid 703601] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFUM637Arlr6Yb1EfqCgAA0zA"]
[Thu Jul 30 12:09:37.452380 2026] [security2:error] [pid 703393:tid 703447] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/img/xmrlpc.php"] [unique_id "amuFUc637Arlr6Yb1EfqFgAA3DU"]
[Thu Jul 30 12:09:37.772826 2026] [security2:error] [pid 703393:tid 703425] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/css/colors/coffee/xmrlpc.php"] [unique_id "amuFUc637Arlr6Yb1EfqHgAA-R8"]
[Thu Jul 30 12:09:37.794819 2026] [security2:error] [pid 703393:tid 703592] [client 41.210.146.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuFUc637Arlr6Yb1EfqDAAAyi4"], referer: https://flixon.net/free-movies/
[Thu Jul 30 12:09:38.088771 2026] [security2:error] [pid 703393:tid 703451] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/images/xmrlpc.php"] [unique_id "amuFUs637Arlr6Yb1EfqKgAAozk"]
[Thu Jul 30 12:09:38.414535 2026] [security2:error] [pid 703393:tid 703404] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/images/xmrlpc.php"] [unique_id "amuFUs637Arlr6Yb1EfqMQAA-Ao"]
[Thu Jul 30 12:09:38.768699 2026] [security2:error] [pid 703393:tid 703449] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/js/widgets/xmrlpc.php"] [unique_id "amuFUs637Arlr6Yb1EfqPQAAtTc"]
[Thu Jul 30 12:09:39.154692 2026] [security2:error] [pid 703393:tid 703427] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/css/colors/xmrlpc.php"] [unique_id "amuFU8637Arlr6Yb1EfqSgAA1yE"]
[Thu Jul 30 12:09:39.503556 2026] [security2:error] [pid 703393:tid 703412] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/includes/xmrlpc.php"] [unique_id "amuFU8637Arlr6Yb1EfqVwAApBI"]
[Thu Jul 30 12:09:39.847941 2026] [security2:error] [pid 703393:tid 703462] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/css/colors/blue/xmrlpc.php"] [unique_id "amuFU8637Arlr6Yb1EfqYwABAEQ"]
[Thu Jul 30 12:09:40.095357 2026] [core:notice] [pid 703393:tid 703531] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:40.102679 2026] [security2:error] [pid 703393:tid 703531] [client 103.215.74.26:54868] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFVM637Arlr6Yb1EfqZAAAAI0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:40.629672 2026] [security2:error] [pid 703393:tid 703472] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/xmrlpc.php"] [unique_id "amuFVM637Arlr6Yb1EfqhAAAsU4"]
[Thu Jul 30 12:09:40.787701 2026] [core:notice] [pid 703393:tid 703459] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:40.821486 2026] [core:notice] [pid 703393:tid 703612] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:40.833344 2026] [security2:error] [pid 703393:tid 703612] [client 103.215.74.26:54870] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFVM637Arlr6Yb1EfqkQAAAN4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:40.934270 2026] [security2:error] [pid 703393:tid 703481] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/text.php"] [unique_id "amuFVM637Arlr6Yb1EfqkwAA3Vc"]
[Thu Jul 30 12:09:41.237488 2026] [security2:error] [pid 703393:tid 703484] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/network/index.php"] [unique_id "amuFVc637Arlr6Yb1EfqmwAAlVo"]
[Thu Jul 30 12:09:41.292126 2026] [core:notice] [pid 703393:tid 703487] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:41.523884 2026] [security2:error] [pid 703393:tid 703553] [client 172.237.109.114:60489] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFVc637Arlr6Yb1EfqlAAAAKM"]
[Thu Jul 30 12:09:41.565614 2026] [core:notice] [pid 703393:tid 703583] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:41.572679 2026] [security2:error] [pid 703393:tid 703583] [client 103.215.74.26:54872] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFVc637Arlr6Yb1EfqpgAAAME"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:41.579907 2026] [security2:error] [pid 703393:tid 703492] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/makeasmtp.php"] [unique_id "amuFVc637Arlr6Yb1EfqpwAAzGI"]
[Thu Jul 30 12:09:42.328351 2026] [core:notice] [pid 703393:tid 703569] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:42.335645 2026] [security2:error] [pid 703393:tid 703569] [client 103.215.74.26:54884] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFVs637Arlr6Yb1EfqtgAAALM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:42.387267 2026] [autoindex:error] [pid 703393:tid 703599] [client 54.173.131.118:0] AH01276: Cannot serve directory /home2/mbmudite/koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:09:42.529803 2026] [security2:error] [pid 703393:tid 703533] [client 2a03:2880:f800:6:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuFVc637Arlr6Yb1EfqsQAAj2M"]
[Thu Jul 30 12:09:42.896502 2026] [security2:error] [pid 703393:tid 703581] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFVs637Arlr6Yb1EfqvAAAv2A"], referer: https://www.spececigarette.com/wp-content/plugins/woocommerce/README.txt
[Thu Jul 30 12:09:43.052870 2026] [autoindex:error] [pid 703393:tid 703541] [client 54.173.131.118:0] AH01276: Cannot serve directory /home2/mbmudite/otbola.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:09:43.112143 2026] [core:notice] [pid 703393:tid 703622] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:43.124667 2026] [security2:error] [pid 703393:tid 703622] [client 103.215.74.26:59936] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFV8637Arlr6Yb1Efq2gAAAOg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:43.722383 2026] [security2:error] [pid 703393:tid 703502] [remote 20.16.180.61:58684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.180.16.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "emmelevate.club"] [uri "/wp-login.php"] [unique_id "amuFV8637Arlr6Yb1Efq5wAAtWw"]
[Thu Jul 30 12:09:43.852128 2026] [core:notice] [pid 703393:tid 703614] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:43.861256 2026] [security2:error] [pid 703393:tid 703614] [client 103.215.74.26:59952] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFV8637Arlr6Yb1Efq6AAAAOA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:44.339830 2026] [security2:error] [pid 703393:tid 703564] [client 172.237.109.114:26336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFVs637Arlr6Yb1EfqxwAAAK4"]
[Thu Jul 30 12:09:44.357723 2026] [security2:error] [pid 703393:tid 703613] [client 172.237.109.114:33511] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFVs637Arlr6Yb1EfqxgAAAN8"]
[Thu Jul 30 12:09:44.417653 2026] [security2:error] [pid 703393:tid 703611] [client 172.237.109.114:50086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFVs637Arlr6Yb1Efq0AAAAN0"]
[Thu Jul 30 12:09:44.421217 2026] [security2:error] [pid 703393:tid 703626] [client 172.237.109.114:62967] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFVs637Arlr6Yb1EfqywAAAOw"]
[Thu Jul 30 12:09:44.429030 2026] [security2:error] [pid 703393:tid 703593] [client 172.237.109.114:45408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFVs637Arlr6Yb1EfqzQAAAMs"]
[Thu Jul 30 12:09:44.452360 2026] [security2:error] [pid 703393:tid 703636] [client 172.237.109.114:64606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFVs637Arlr6Yb1EfqzAAAAPY"]
[Thu Jul 30 12:09:44.458723 2026] [security2:error] [pid 703393:tid 703579] [client 172.237.109.114:1626] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFVs637Arlr6Yb1Efq0gAAAL0"]
[Thu Jul 30 12:09:44.461189 2026] [security2:error] [pid 703393:tid 703590] [client 172.237.109.114:5827] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFVs637Arlr6Yb1Efq1QAAAMg"]
[Thu Jul 30 12:09:44.461435 2026] [security2:error] [pid 703393:tid 703526] [client 172.237.109.114:60289] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFVs637Arlr6Yb1Efq1gAAAIg"]
[Thu Jul 30 12:09:44.464350 2026] [security2:error] [pid 703393:tid 703628] [client 172.237.109.114:6649] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFVs637Arlr6Yb1EfqygAAAO4"]
[Thu Jul 30 12:09:44.465865 2026] [security2:error] [pid 703393:tid 703650] [client 172.237.109.114:46585] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFVs637Arlr6Yb1EfqyAAAAQQ"]
[Thu Jul 30 12:09:44.472813 2026] [security2:error] [pid 703393:tid 703603] [client 172.237.109.114:9050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFVs637Arlr6Yb1EfqzwAAANU"]
[Thu Jul 30 12:09:44.473454 2026] [security2:error] [pid 703393:tid 703625] [client 172.237.109.114:30972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFVs637Arlr6Yb1EfqzgAAAOs"]
[Thu Jul 30 12:09:44.486396 2026] [security2:error] [pid 703393:tid 703604] [client 172.237.109.114:30216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFVs637Arlr6Yb1Efq0wAAANY"]
[Thu Jul 30 12:09:44.487732 2026] [security2:error] [pid 703393:tid 703543] [client 172.237.109.114:8470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFVs637Arlr6Yb1EfqyQAAAJk"]
[Thu Jul 30 12:09:44.491139 2026] [security2:error] [pid 703393:tid 703532] [client 172.237.109.114:28188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFVs637Arlr6Yb1Efq1AAAAI4"]
[Thu Jul 30 12:09:44.496625 2026] [security2:error] [pid 703393:tid 703606] [client 172.237.109.114:41957] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFV8637Arlr6Yb1Efq2AAAANg"]
[Thu Jul 30 12:09:44.502411 2026] [security2:error] [pid 703393:tid 703528] [client 172.237.109.114:25686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFVs637Arlr6Yb1Efq1wAAAIo"]
[Thu Jul 30 12:09:44.502631 2026] [security2:error] [pid 703393:tid 703534] [client 172.237.109.114:40503] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFVs637Arlr6Yb1Efq0QAAAJA"]
[Thu Jul 30 12:09:44.593617 2026] [core:notice] [pid 703393:tid 703581] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:44.601230 2026] [security2:error] [pid 703393:tid 703581] [client 103.215.74.26:59966] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFWM637Arlr6Yb1EfrCwAAAL8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:44.762679 2026] [security2:error] [pid 703393:tid 703535] [client 41.210.146.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuFWM637Arlr6Yb1EfrBwAAkWs"], referer: https://flixon.net/wp-content/uploads/2025/11/FlixOn-Movhref=https:/flixon.net/wp-content/uploads/2026/02/Flix-On-Movies_V1.apkies.apk
[Thu Jul 30 12:09:44.929404 2026] [security2:error] [pid 703393:tid 703533] [client 121.229.156.67:40298] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "azureskyfilms.com"] [uri "/"] [unique_id "amuFWM637Arlr6Yb1EfrEAAAAI8"]
[Thu Jul 30 12:09:44.929532 2026] [security2:error] [pid 703393:tid 703533] [client 121.229.156.67:40298] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "azureskyfilms.com"] [uri "/"] [unique_id "amuFWM637Arlr6Yb1EfrEAAAAI8"]
[Thu Jul 30 12:09:45.323102 2026] [core:notice] [pid 703393:tid 703601] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:45.334080 2026] [security2:error] [pid 703393:tid 703601] [client 103.215.74.26:59968] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFWc637Arlr6Yb1EfrGgAAANM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:46.008070 2026] [security2:error] [pid 703393:tid 703627] [client 213.152.187.215:48904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.187.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuFWs637Arlr6Yb1EfrJwAAAO0"]
[Thu Jul 30 12:09:46.008182 2026] [security2:error] [pid 703393:tid 703627] [client 213.152.187.215:48904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuFWs637Arlr6Yb1EfrJwAAAO0"]
[Thu Jul 30 12:09:46.030381 2026] [security2:error] [pid 703393:tid 703561] [client 41.210.146.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuFWc637Arlr6Yb1EfrGQAAq3Q"], referer: https://flixon.net/wp-content/uploads/2025/11/FlixOn-Movhref=https:/flixon.net/wp-content/uploads/2026/02/Flix-On-Movies_V1.apkies.apk
[Thu Jul 30 12:09:46.081464 2026] [core:notice] [pid 703393:tid 703607] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:46.089362 2026] [security2:error] [pid 703393:tid 703607] [client 103.215.74.26:59970] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFWs637Arlr6Yb1EfrKwAAANk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:46.820102 2026] [core:notice] [pid 703393:tid 703559] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:46.827269 2026] [security2:error] [pid 703393:tid 703559] [client 103.215.74.26:59974] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFWs637Arlr6Yb1EfrOQAAAKk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:47.454666 2026] [security2:error] [pid 703393:tid 703576] [client 185.189.112.11:39756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.112.189.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuFW8637Arlr6Yb1EfrRgAAALo"]
[Thu Jul 30 12:09:47.454776 2026] [security2:error] [pid 703393:tid 703576] [client 185.189.112.11:39756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuFW8637Arlr6Yb1EfrRgAAALo"]
[Thu Jul 30 12:09:47.556099 2026] [core:notice] [pid 703393:tid 703600] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:47.566740 2026] [security2:error] [pid 703393:tid 703600] [client 103.215.74.26:59988] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFW8637Arlr6Yb1EfrSgAAANI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:47.740206 2026] [security2:error] [pid 703393:tid 703529] [client 2a03:2880:f800:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuFW8637Arlr6Yb1EfrQwAAi30"]
[Thu Jul 30 12:09:48.298884 2026] [security2:error] [pid 703393:tid 703413] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/mainichi-shopify-products-connect/readme.txt"] [unique_id "amuFXM637Arlr6Yb1EfrVwABAhM"]
[Thu Jul 30 12:09:48.301379 2026] [core:notice] [pid 703393:tid 703562] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:48.309305 2026] [security2:error] [pid 703393:tid 703562] [client 103.215.74.26:59990] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFXM637Arlr6Yb1EfrWAAAAKw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:48.971712 2026] [security2:error] [pid 703393:tid 703611] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFXM637Arlr6Yb1EfrXgAA3Qs"]
[Thu Jul 30 12:09:49.015218 2026] [security2:error] [pid 703393:tid 703592] [client 250.49.135.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuFXM637Arlr6Yb1EfrXQAAygU"]
[Thu Jul 30 12:09:49.036078 2026] [core:notice] [pid 703393:tid 703551] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:49.042957 2026] [security2:error] [pid 703393:tid 703551] [client 103.215.74.26:60006] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFXc637Arlr6Yb1EfrbAAAAKE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:49.771605 2026] [core:notice] [pid 703393:tid 703553] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:49.778868 2026] [security2:error] [pid 703393:tid 703553] [client 103.215.74.26:60008] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFXc637Arlr6Yb1EfrfQAAAKM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:50.504291 2026] [core:notice] [pid 703393:tid 703600] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:50.511013 2026] [security2:error] [pid 703393:tid 703600] [client 103.215.74.26:60020] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFXs637Arlr6Yb1EfrhgAAANI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:50.734278 2026] [security2:error] [pid 703393:tid 703566] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFXs637Arlr6Yb1EfrhQAAsCg"], referer: https://www.spececigarette.com/wp-content/plugins/mainichi-shopify-products-connect/Readme.txt
[Thu Jul 30 12:09:51.247346 2026] [core:notice] [pid 703393:tid 703595] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:51.248814 2026] [security2:error] [pid 703393:tid 703640] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFXs637Arlr6Yb1EfrjwAA-io"]
[Thu Jul 30 12:09:51.253875 2026] [security2:error] [pid 703393:tid 703595] [client 103.215.74.26:60032] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFX8637Arlr6Yb1EfrkgAAAM0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:51.990391 2026] [core:notice] [pid 703393:tid 703607] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:51.998010 2026] [security2:error] [pid 703393:tid 703607] [client 103.215.74.26:60044] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFX8637Arlr6Yb1EfrpQAAANk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:52.212854 2026] [security2:error] [pid 703393:tid 703560] [client 65.55.210.161:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuFYM637Arlr6Yb1EfrqAAAAKo"]
[Thu Jul 30 12:09:52.314325 2026] [security2:error] [pid 703393:tid 703539] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFX8637Arlr6Yb1EfrpAAAlTA"], referer: https://www.spececigarette.com/wp-content/plugins/mainichi-shopify-products-connect/README.txt
[Thu Jul 30 12:09:52.657277 2026] [core:error] [pid 703393:tid 703444] [remote 74.7.175.163:39466] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:09:52.657304 2026] [core:error] [pid 703393:tid 703444] [remote 74.7.175.163:39466] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:09:52.657563 2026] [security2:error] [pid 703393:tid 703643] [client 74.7.175.163:39466] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "riisesolution.com.nxt.udi.temporary.site"] [uri "/index.php"] [unique_id "amuFYM637Arlr6Yb1EfrswAA_TI"]
[Thu Jul 30 12:09:52.705262 2026] [security2:error] [pid 703393:tid 703425] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/fuse-social-floating-sidebar/readme.txt"] [unique_id "amuFYM637Arlr6Yb1EfrtAAAzB8"]
[Thu Jul 30 12:09:54.163146 2026] [security2:error] [pid 703393:tid 703608] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFYc637Arlr6Yb1EfryAAA2j8"]
[Thu Jul 30 12:09:54.891663 2026] [security2:error] [pid 703393:tid 703561] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFYs637Arlr6Yb1Efr1wAAqzc"], referer: https://www.spececigarette.com/wp-content/plugins/fuse-social-floating-sidebar/Readme.txt
[Thu Jul 30 12:09:55.398992 2026] [security2:error] [pid 703393:tid 703559] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFY8637Arlr6Yb1Efr6AAAqTY"]
[Thu Jul 30 12:09:57.781704 2026] [core:notice] [pid 703393:tid 703578] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:57.790144 2026] [security2:error] [pid 703393:tid 703578] [client 103.215.74.26:13364] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFZc637Arlr6Yb1EfsQAAAALw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:58.517246 2026] [core:notice] [pid 703393:tid 703646] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:58.524184 2026] [security2:error] [pid 703393:tid 703646] [client 103.215.74.26:13378] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFZs637Arlr6Yb1EfsTQAAAQA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:59.249665 2026] [core:notice] [pid 703393:tid 703531] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:59.256005 2026] [security2:error] [pid 703393:tid 703531] [client 103.215.74.26:13388] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFZ8637Arlr6Yb1EfsXwAAAI0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:59.537681 2026] [security2:error] [pid 703393:tid 703541] [client 66.249.66.76:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dapperdangolf.com"] [uri "/index.php"] [unique_id "amuFZc637Arlr6Yb1EfsLgAAl1A"]
[Thu Jul 30 12:09:59.985893 2026] [core:notice] [pid 703393:tid 703634] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:59.992763 2026] [security2:error] [pid 703393:tid 703634] [client 103.215.74.26:13396] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFZ8637Arlr6Yb1EfscAAAAPQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:00.713961 2026] [core:notice] [pid 703393:tid 703628] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:00.721136 2026] [security2:error] [pid 703393:tid 703628] [client 103.215.74.26:13406] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFaM637Arlr6Yb1EfslwAAAO4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:01.135724 2026] [security2:error] [pid 703393:tid 703592] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFaM637Arlr6Yb1EfslAAAynA"], referer: https://www.spececigarette.com/wp-content/plugins/fuse-social-floating-sidebar/README.txt
[Thu Jul 30 12:10:01.269051 2026] [security2:error] [pid 703393:tid 703591] [client 41.210.146.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuFaM637Arlr6Yb1EfsjwAAyXE"], referer: https://flixon.net/wp-content/uploads/2025/11/FlixOn-Movhref=https:/flixon.net/wp-content/uploads/2026/02/Flix-On-Movies_V1.apkies.apk
[Thu Jul 30 12:10:01.462717 2026] [core:notice] [pid 703393:tid 703612] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:01.470283 2026] [security2:error] [pid 703393:tid 703612] [client 103.215.74.26:13414] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFac637Arlr6Yb1EfsxAAAAN4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:01.488414 2026] [security2:error] [pid 703393:tid 703437] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/slick-popup/readme.txt"] [unique_id "amuFac637Arlr6Yb1EfsxQAAoys"]
[Thu Jul 30 12:10:02.192424 2026] [security2:error] [pid 703393:tid 703582] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFac637Arlr6Yb1EfszwAAwC8"]
[Thu Jul 30 12:10:02.916296 2026] [security2:error] [pid 703393:tid 703599] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFas637Arlr6Yb1Efs4AAA0RA"], referer: https://www.spececigarette.com/wp-content/plugins/slick-popup/Readme.txt
[Thu Jul 30 12:10:03.460608 2026] [security2:error] [pid 703393:tid 703594] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFa8637Arlr6Yb1Efs7QAAzC4"]
[Thu Jul 30 12:10:03.997882 2026] [security2:error] [pid 703393:tid 703601] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFa8637Arlr6Yb1EftAgAA0zg"], referer: https://www.spececigarette.com/wp-content/plugins/slick-popup/README.txt
[Thu Jul 30 12:10:04.306059 2026] [security2:error] [pid 703393:tid 703455] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/rishi-checkout-for-woocommerce/readme.txt"] [unique_id "amuFbM637Arlr6Yb1EftEgAAiD0"]
[Thu Jul 30 12:10:04.927910 2026] [security2:error] [pid 703393:tid 703420] [remote 74.7.241.59:36728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuFbM637Arlr6Yb1EftJwAAhxo"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/forms/actions
[Thu Jul 30 12:10:05.064049 2026] [core:notice] [pid 703393:tid 703462] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:05.379790 2026] [security2:error] [pid 703393:tid 703580] [client 41.210.146.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuFbM637Arlr6Yb1EftIgAAvjY"], referer: https://flixon.net/wp-content/uploads/2025/11/FlixOn-Movhref=https:/flixon.net/wp-content/uploads/2026/02/Flix-On-Movies_V1.apkies.apk
[Thu Jul 30 12:10:05.499914 2026] [core:notice] [pid 703393:tid 703556] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:06.110476 2026] [security2:error] [pid 703393:tid 703536] [client 185.189.112.11:46434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.112.189.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuFbs637Arlr6Yb1EftQQAAAJI"]
[Thu Jul 30 12:10:06.110556 2026] [security2:error] [pid 703393:tid 703536] [client 185.189.112.11:46434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuFbs637Arlr6Yb1EftQQAAAJI"]
[Thu Jul 30 12:10:06.116678 2026] [security2:error] [pid 703393:tid 703544] [client 41.210.146.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuFbc637Arlr6Yb1EftNwAAmks"], referer: https://flixon.net/wp-content/uploads/2025/11/FlixOn-Movhref=https:/flixon.net/wp-content/uploads/2026/02/Flix-On-Movies_V1.apkies.apk
[Thu Jul 30 12:10:06.161746 2026] [security2:error] [pid 703393:tid 703540] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFbc637Arlr6Yb1EftOQAAlk8"]
[Thu Jul 30 12:10:06.294644 2026] [security2:error] [pid 703393:tid 703477] [remote 74.7.241.60:59776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/content/article.php"] [unique_id "amuFbs637Arlr6Yb1EftRgAA0FM"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/content/1784123347_ed%20inclusive.jpg
[Thu Jul 30 12:10:06.556296 2026] [core:notice] [pid 703393:tid 703564] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:06.678765 2026] [security2:error] [pid 703393:tid 703530] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFbs637Arlr6Yb1EftRAAAjEY"], referer: https://www.spececigarette.com/wp-content/plugins/rishi-checkout-for-woocommerce/Readme.txt
[Thu Jul 30 12:10:07.099949 2026] [security2:error] [pid 703393:tid 703609] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFbs637Arlr6Yb1EftVwAA214"]
[Thu Jul 30 12:10:07.194406 2026] [core:notice] [pid 703393:tid 703596] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:07.201481 2026] [security2:error] [pid 703393:tid 703596] [client 103.215.74.26:35514] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFb8637Arlr6Yb1EftYQAAAM4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:07.790823 2026] [security2:error] [pid 703393:tid 703528] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFb8637Arlr6Yb1EftZwAAimE"], referer: https://www.spececigarette.com/wp-content/plugins/rishi-checkout-for-woocommerce/README.txt
[Thu Jul 30 12:10:07.928262 2026] [core:notice] [pid 703393:tid 703531] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:07.934610 2026] [security2:error] [pid 703393:tid 703531] [client 103.215.74.26:35528] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFb8637Arlr6Yb1EftcAAAAI0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:08.170639 2026] [security2:error] [pid 703393:tid 703501] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/worth-the-read/readme.txt"] [unique_id "amuFcM637Arlr6Yb1EfteQAAzGs"]
[Thu Jul 30 12:10:08.681005 2026] [core:notice] [pid 703393:tid 703598] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:08.689456 2026] [security2:error] [pid 703393:tid 703598] [client 103.215.74.26:35530] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFcM637Arlr6Yb1EftgwAAANA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:08.952568 2026] [core:notice] [pid 703393:tid 703650] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:09.345609 2026] [security2:error] [pid 703393:tid 703509] [remote 216.73.216.152:62630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuFcc637Arlr6Yb1EftkgAA6HM"]
[Thu Jul 30 12:10:09.418517 2026] [core:notice] [pid 703393:tid 703579] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:09.425403 2026] [security2:error] [pid 703393:tid 703579] [client 103.215.74.26:35536] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFcc637Arlr6Yb1EftlQAAAL0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:09.623825 2026] [security2:error] [pid 703393:tid 703539] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFcc637Arlr6Yb1EftjgAAlXI"]
[Thu Jul 30 12:10:10.139467 2026] [security2:error] [pid 703393:tid 703611] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFcc637Arlr6Yb1EftngAA3Xo"], referer: https://www.spececigarette.com/wp-content/plugins/worth-the-read/Readme.txt
[Thu Jul 30 12:10:10.151708 2026] [core:notice] [pid 703393:tid 703646] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:10.158044 2026] [security2:error] [pid 703393:tid 703646] [client 103.215.74.26:35550] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFcs637Arlr6Yb1EftoQAAAQA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:10.546338 2026] [security2:error] [pid 703393:tid 703632] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFcs637Arlr6Yb1EftqAAA8nw"]
[Thu Jul 30 12:10:10.884572 2026] [core:notice] [pid 703393:tid 703571] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:10.891116 2026] [security2:error] [pid 703393:tid 703571] [client 103.215.74.26:35554] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFcs637Arlr6Yb1EftsgAAALU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:11.163036 2026] [core:notice] [pid 703393:tid 703636] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:11.459511 2026] [security2:error] [pid 703393:tid 703633] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFcs637Arlr6Yb1EftsQAApns"], referer: https://www.spececigarette.com/wp-content/plugins/worth-the-read/README.txt
[Thu Jul 30 12:10:11.465718 2026] [security2:error] [pid 703393:tid 703519] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/spec-theme-options/readme.txt"] [unique_id "amuFc8637Arlr6Yb1EftuwABBH0"]
[Thu Jul 30 12:10:11.632188 2026] [core:notice] [pid 703393:tid 703624] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:11.639809 2026] [security2:error] [pid 703393:tid 703624] [client 103.215.74.26:35562] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFc8637Arlr6Yb1EftvQAAAOo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:11.773231 2026] [security2:error] [pid 703393:tid 703649] [client 185.200.117.131:53994] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuFc8637Arlr6Yb1EftvAAAAQM"]
[Thu Jul 30 12:10:11.773382 2026] [security2:error] [pid 703393:tid 703649] [client 185.200.117.131:53994] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuFc8637Arlr6Yb1EftvAAAAQM"]
[Thu Jul 30 12:10:12.419015 2026] [core:notice] [pid 703393:tid 703525] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:12.425041 2026] [security2:error] [pid 703393:tid 703525] [client 103.215.74.26:35578] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFdM637Arlr6Yb1EftyQAAAIc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:13.153054 2026] [core:notice] [pid 703393:tid 703600] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:13.160400 2026] [security2:error] [pid 703393:tid 703600] [client 103.215.74.26:34976] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFdc637Arlr6Yb1Eft2AAAANI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:13.880125 2026] [core:notice] [pid 703393:tid 703584] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:13.887602 2026] [security2:error] [pid 703393:tid 703584] [client 103.215.74.26:34978] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFdc637Arlr6Yb1Eft6wAAAMI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:14.045256 2026] [security2:error] [pid 703393:tid 703598] [client 57.141.0.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuFdc637Arlr6Yb1Eft4gAAANA"]
[Thu Jul 30 12:10:14.615255 2026] [core:notice] [pid 703393:tid 703542] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:14.624299 2026] [security2:error] [pid 703393:tid 703542] [client 103.215.74.26:34994] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFds637Arlr6Yb1Eft_AAAAJg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:15.053205 2026] [core:notice] [pid 703393:tid 703553] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:15.343378 2026] [core:notice] [pid 703393:tid 703576] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:15.347548 2026] [security2:error] [pid 703393:tid 703646] [client 57.141.0.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuFds637Arlr6Yb1EfuAAAAAQA"]
[Thu Jul 30 12:10:15.350897 2026] [security2:error] [pid 703393:tid 703576] [client 103.215.74.26:34996] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFd8637Arlr6Yb1EfuEQAAALo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:15.386933 2026] [core:notice] [pid 703393:tid 703571] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:15.522395 2026] [security2:error] [pid 703393:tid 703570] [client 2a03:2880:f800:20:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuFds637Arlr6Yb1EfuAQAAtCU"]
[Thu Jul 30 12:10:15.727768 2026] [security2:error] [pid 703393:tid 703618] [client 74.7.175.180:57232] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "arabian-tours.com"] [uri "/cgi-sys/404.html"] [unique_id "amuFd8637Arlr6Yb1EfuHwAA5DU"]
[Thu Jul 30 12:10:16.088335 2026] [core:notice] [pid 703393:tid 703537] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:16.095805 2026] [security2:error] [pid 703393:tid 703537] [client 103.215.74.26:35002] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFeM637Arlr6Yb1EfuJAAAAJM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:16.215529 2026] [core:notice] [pid 703393:tid 703442] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:16.220285 2026] [security2:error] [pid 703393:tid 703607] [client 87.250.224.116:44656] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Signal/article/view/1316"] [unique_id "amuFd8637Arlr6Yb1EfuIAAA2TA"]
[Thu Jul 30 12:10:16.825919 2026] [core:notice] [pid 703393:tid 703589] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:16.832904 2026] [security2:error] [pid 703393:tid 703589] [client 103.215.74.26:35016] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFeM637Arlr6Yb1EfuMwAAAMc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:17.087042 2026] [core:notice] [pid 703393:tid 703422] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:17.105939 2026] [security2:error] [pid 703393:tid 703609] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFeM637Arlr6Yb1EfuMgAA2w0"]
[Thu Jul 30 12:10:17.343423 2026] [security2:error] [pid 703393:tid 703547] [client 41.210.146.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuFeM637Arlr6Yb1EfuMQAAnRA"], referer: https://flixon.net/v/ideo_tag/vj-ice-p
[Thu Jul 30 12:10:17.565640 2026] [core:notice] [pid 703393:tid 703587] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:17.573184 2026] [security2:error] [pid 703393:tid 703587] [client 103.215.74.26:35018] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFec637Arlr6Yb1EfuQgAAAMU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:17.799285 2026] [security2:error] [pid 703393:tid 703445] [remote 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFec637Arlr6Yb1EfuQQAApTM"], referer: https://www.spececigarette.com/wp-content/plugins/spec-theme-options/Readme.txt
[Thu Jul 30 12:10:18.296562 2026] [core:notice] [pid 703393:tid 703581] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:18.302677 2026] [security2:error] [pid 703393:tid 703581] [client 103.215.74.26:35022] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFes637Arlr6Yb1EfuVgAAAL8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:18.310189 2026] [security2:error] [pid 703393:tid 703572] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFec637Arlr6Yb1EfuTAAAtjc"]
[Thu Jul 30 12:10:18.387331 2026] [security2:error] [pid 703393:tid 703600] [client 41.210.146.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuFec637Arlr6Yb1EfuSQAA0j0"], referer: https://flixon.net/v/ideo_tag/vj-ice-p
[Thu Jul 30 12:10:19.034499 2026] [core:notice] [pid 703393:tid 703603] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:19.043013 2026] [security2:error] [pid 703393:tid 703603] [client 103.215.74.26:35034] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFe8637Arlr6Yb1EfuYwAAANU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:19.775382 2026] [core:notice] [pid 703393:tid 703532] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:19.782238 2026] [security2:error] [pid 703393:tid 703532] [client 103.215.74.26:35050] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFe8637Arlr6Yb1EfudAAAAI4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:19.820091 2026] [core:notice] [pid 703393:tid 703567] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:19.824542 2026] [security2:error] [pid 703393:tid 703567] [client 74.0.19.12:37825] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Konstruksi/article/download/3849/1891/10502"] [unique_id "amuFe8637Arlr6Yb1EfucAAAALE"]
[Thu Jul 30 12:10:20.512785 2026] [core:notice] [pid 703393:tid 703619] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:20.519304 2026] [security2:error] [pid 703393:tid 703619] [client 103.215.74.26:35052] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFfM637Arlr6Yb1EfuiQAAAOU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:20.781813 2026] [security2:error] [pid 703393:tid 703562] [client 172.236.9.101:6411] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFfM637Arlr6Yb1EfugQAAAKw"]
[Thu Jul 30 12:10:20.850231 2026] [security2:error] [pid 703393:tid 703531] [client 172.236.9.101:59950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFfM637Arlr6Yb1EfugwAAAI0"]
[Thu Jul 30 12:10:20.857895 2026] [security2:error] [pid 703393:tid 703529] [client 172.236.9.101:1278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFfM637Arlr6Yb1EfuhAAAAIs"]
[Thu Jul 30 12:10:20.859940 2026] [security2:error] [pid 703393:tid 703614] [client 172.236.9.101:57009] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFfM637Arlr6Yb1EfuhQAAAOA"]
[Thu Jul 30 12:10:21.031282 2026] [core:notice] [pid 703393:tid 703535] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:21.246434 2026] [core:notice] [pid 703393:tid 703650] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:21.254218 2026] [security2:error] [pid 703393:tid 703650] [client 103.215.74.26:35062] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFfc637Arlr6Yb1EfulwAAAQQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:21.771230 2026] [security2:error] [pid 703393:tid 703635] [client 172.236.9.101:57650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFfc637Arlr6Yb1EfumAAAAPU"]
[Thu Jul 30 12:10:21.771381 2026] [security2:error] [pid 703393:tid 703565] [client 172.236.9.101:60608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFfc637Arlr6Yb1EfumQAAAK8"]
[Thu Jul 30 12:10:21.776399 2026] [security2:error] [pid 703393:tid 703607] [client 172.236.9.101:17080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFfc637Arlr6Yb1EfumgAAANk"]
[Thu Jul 30 12:10:21.794166 2026] [security2:error] [pid 703393:tid 703525] [client 172.236.9.101:24470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFfc637Arlr6Yb1EfumwAAAIc"]
[Thu Jul 30 12:10:21.868070 2026] [security2:error] [pid 703393:tid 703604] [client 172.236.9.101:46239] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFfc637Arlr6Yb1EfunAAAANY"]
[Thu Jul 30 12:10:21.981168 2026] [core:notice] [pid 703393:tid 703534] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:21.988792 2026] [security2:error] [pid 703393:tid 703534] [client 103.215.74.26:35076] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFfc637Arlr6Yb1EfupwAAAJA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:22.764044 2026] [security2:error] [pid 703393:tid 703600] [client 20.100.187.180:57294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.milfordauto.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuFfs637Arlr6Yb1EfuuQAAANI"]
[Thu Jul 30 12:10:22.764183 2026] [security2:error] [pid 703393:tid 703600] [client 20.100.187.180:57294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.milfordauto.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuFfs637Arlr6Yb1EfuuQAAANI"]
[Thu Jul 30 12:10:23.395908 2026] [security2:error] [pid 703393:tid 703548] [client 74.7.175.180:40164] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "webdisk.openspacelab.tech"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuFf8637Arlr6Yb1EfuxAAAAJ4"]
[Thu Jul 30 12:10:23.938717 2026] [security2:error] [pid 703393:tid 703544] [client 20.203.156.12:12988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/index.php"] [unique_id "amuFf8637Arlr6Yb1EfuzAAAAJo"]
[Thu Jul 30 12:10:23.938829 2026] [security2:error] [pid 703393:tid 703544] [client 20.203.156.12:12988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/index.php"] [unique_id "amuFf8637Arlr6Yb1EfuzAAAAJo"]
[Thu Jul 30 12:10:24.050096 2026] [security2:error] [pid 703393:tid 703626] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFf8637Arlr6Yb1EfuyAAA7E0"], referer: https://www.spececigarette.com/wp-content/plugins/spec-theme-options/README.txt
[Thu Jul 30 12:10:24.434019 2026] [core:notice] [pid 703393:tid 703537] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:25.413421 2026] [security2:error] [pid 703393:tid 703504] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/stacks-mobile-app-builder/readme.txt"] [unique_id "amuFgc637Arlr6Yb1Efu5wAAjG4"]
[Thu Jul 30 12:10:26.089116 2026] [security2:error] [pid 703393:tid 703569] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFgc637Arlr6Yb1Efu7gAAs2o"]
[Thu Jul 30 12:10:27.765786 2026] [core:notice] [pid 703393:tid 703612] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:27.776691 2026] [security2:error] [pid 703393:tid 703612] [client 103.215.74.26:60848] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFg8637Arlr6Yb1EfvEgAAAN4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:28.505511 2026] [core:notice] [pid 703393:tid 703537] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:28.512697 2026] [security2:error] [pid 703393:tid 703537] [client 103.215.74.26:60850] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFhM637Arlr6Yb1EfvHQAAAJM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:28.530059 2026] [security2:error] [pid 703393:tid 703586] [client 41.210.146.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuFg8637Arlr6Yb1EfvEwAAxAE"], referer: https://flixon.net/wp-content/uploads/2025/11/FlixOn-Movhref=https:/flixon.net/wp-content/uploads/2026/02/Flix-On-Movies_V1.apkies.apk
[Thu Jul 30 12:10:28.995824 2026] [security2:error] [pid 703393:tid 703557] [client 20.100.187.180:59988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.milfordauto.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuFhM637Arlr6Yb1EfvLgAAAKc"]
[Thu Jul 30 12:10:28.995920 2026] [security2:error] [pid 703393:tid 703557] [client 20.100.187.180:59988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.milfordauto.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuFhM637Arlr6Yb1EfvLgAAAKc"]
[Thu Jul 30 12:10:29.232400 2026] [core:notice] [pid 703393:tid 703621] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:29.238858 2026] [security2:error] [pid 703393:tid 703621] [client 103.215.74.26:60862] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFhc637Arlr6Yb1EfvNQAAAOc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:29.459202 2026] [security2:error] [pid 703393:tid 703591] [client 41.210.146.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuFhM637Arlr6Yb1EfvKAAAyQg"], referer: https://flixon.net/wp-content/uploads/2025/11/FlixOn-Movhref=https:/flixon.net/wp-content/uploads/2026/02/Flix-On-Movies_V1.apkies.apk
[Thu Jul 30 12:10:29.980626 2026] [core:notice] [pid 703393:tid 703628] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:29.987349 2026] [security2:error] [pid 703393:tid 703628] [client 103.215.74.26:60874] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFhc637Arlr6Yb1EfvQwAAAO4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:30.706142 2026] [core:notice] [pid 703393:tid 703602] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:30.714408 2026] [security2:error] [pid 703393:tid 703602] [client 103.215.74.26:60878] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFhs637Arlr6Yb1EfvVQAAANQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:30.889792 2026] [core:notice] [pid 703393:tid 703539] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:30.920288 2026] [security2:error] [pid 703393:tid 703573] [client 41.210.146.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuFhs637Arlr6Yb1EfvRQAAtxU"], referer: https://flixon.net/free-movies/
[Thu Jul 30 12:10:31.394299 2026] [core:notice] [pid 703393:tid 703605] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:31.421430 2026] [core:notice] [pid 703393:tid 703647] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:31.428793 2026] [security2:error] [pid 703393:tid 703647] [client 103.215.74.26:60886] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFh8637Arlr6Yb1EfvZgAAAQE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:31.549965 2026] [core:notice] [pid 703393:tid 703418] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:31.608622 2026] [security2:error] [pid 703393:tid 703587] [client 20.100.187.180:60014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.milfordauto.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuFh8637Arlr6Yb1EfvawAAAMU"]
[Thu Jul 30 12:10:31.608737 2026] [security2:error] [pid 703393:tid 703587] [client 20.100.187.180:60014] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.milfordauto.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuFh8637Arlr6Yb1EfvawAAAMU"]
[Thu Jul 30 12:10:31.808915 2026] [core:notice] [pid 703393:tid 703506] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:31.817172 2026] [security2:error] [pid 703393:tid 703635] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFh8637Arlr6Yb1EfvZQAA9Qs"], referer: https://www.spececigarette.com/wp-content/plugins/stacks-mobile-app-builder/Readme.txt
[Thu Jul 30 12:10:32.193132 2026] [core:notice] [pid 703393:tid 703600] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:32.203913 2026] [security2:error] [pid 703393:tid 703600] [client 103.215.74.26:60890] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFiM637Arlr6Yb1EfveQAAANI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:32.540249 2026] [security2:error] [pid 703393:tid 703636] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFiM637Arlr6Yb1EfvegAA9iw"]
[Thu Jul 30 12:10:32.940127 2026] [core:notice] [pid 703393:tid 703576] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:32.946726 2026] [security2:error] [pid 703393:tid 703576] [client 103.215.74.26:60896] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFiM637Arlr6Yb1EfvhgAAALo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:33.218929 2026] [security2:error] [pid 703393:tid 703622] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFiM637Arlr6Yb1EfvggAA6C0"], referer: https://www.spececigarette.com/wp-content/plugins/stacks-mobile-app-builder/README.txt
[Thu Jul 30 12:10:33.667748 2026] [core:notice] [pid 703393:tid 703606] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:33.674399 2026] [security2:error] [pid 703393:tid 703606] [client 103.215.74.26:8264] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFic637Arlr6Yb1EfvkgAAANg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:34.419838 2026] [security2:error] [pid 703393:tid 703425] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/popup-maker/readme.txt"] [unique_id "amuFis637Arlr6Yb1EfvoQAAtB8"]
[Thu Jul 30 12:10:35.047943 2026] [security2:error] [pid 703393:tid 703607] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFis637Arlr6Yb1EfvqAAA2TE"]
[Thu Jul 30 12:10:35.088554 2026] [security2:error] [pid 703393:tid 703409] [remote 57.141.0.33:50878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amuFi8637Arlr6Yb1EfvsQAApw8"]
[Thu Jul 30 12:10:35.591340 2026] [security2:error] [pid 703393:tid 703536] [client 2a03:2880:f800:1e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuFis637Arlr6Yb1EfvrwAAkj8"]
[Thu Jul 30 12:10:35.745301 2026] [security2:error] [pid 703393:tid 703531] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFi8637Arlr6Yb1EfvtwAAjS4"], referer: https://www.spececigarette.com/wp-content/plugins/popup-maker/Readme.txt
[Thu Jul 30 12:10:36.249108 2026] [security2:error] [pid 703393:tid 703548] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFi8637Arlr6Yb1EfvvwAAnjc"]
[Thu Jul 30 12:10:36.626027 2026] [core:notice] [pid 703393:tid 703601] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:36.720375 2026] [security2:error] [pid 703393:tid 703584] [client 20.100.187.180:37070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.milfordauto.com"] [uri "/err.php"] [unique_id "amuFjM637Arlr6Yb1EfvywAAAMI"]
[Thu Jul 30 12:10:36.720473 2026] [security2:error] [pid 703393:tid 703584] [client 20.100.187.180:37070] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.milfordauto.com"] [uri "/err.php"] [unique_id "amuFjM637Arlr6Yb1EfvywAAAMI"]
[Thu Jul 30 12:10:37.201663 2026] [core:notice] [pid 703393:tid 703539] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:37.929685 2026] [security2:error] [pid 703393:tid 703542] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFjc637Arlr6Yb1Efv1wAAmA4"], referer: https://www.spececigarette.com/wp-content/plugins/popup-maker/README.txt
[Thu Jul 30 12:10:39.338580 2026] [security2:error] [pid 703393:tid 703540] [client 20.100.187.180:60029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.milfordauto.com"] [uri "/img.php"] [unique_id "amuFj8637Arlr6Yb1Efv8wAAAJY"]
[Thu Jul 30 12:10:39.338695 2026] [security2:error] [pid 703393:tid 703540] [client 20.100.187.180:60029] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.milfordauto.com"] [uri "/img.php"] [unique_id "amuFj8637Arlr6Yb1Efv8wAAAJY"]
[Thu Jul 30 12:10:39.456872 2026] [core:notice] [pid 703393:tid 703581] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:39.463366 2026] [security2:error] [pid 703393:tid 703581] [client 103.215.74.26:8278] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFj8637Arlr6Yb1Efv-AAAAL8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:40.165372 2026] [core:notice] [pid 703393:tid 703600] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:40.186136 2026] [core:notice] [pid 703393:tid 703574] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:40.192898 2026] [security2:error] [pid 703393:tid 703574] [client 103.215.74.26:8294] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFkM637Arlr6Yb1EfwAwAAALg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:40.925848 2026] [core:notice] [pid 703393:tid 703545] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:40.936719 2026] [security2:error] [pid 703393:tid 703545] [client 103.215.74.26:8302] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFkM637Arlr6Yb1EfwFQAAAJs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:41.170333 2026] [security2:error] [pid 703393:tid 703592] [client 2.51.55.76:52433] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFkM637Arlr6Yb1EfwDQAAykY"]
[Thu Jul 30 12:10:41.349585 2026] [security2:error] [pid 703393:tid 703592] [client 2.51.55.76:52433] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFkM637Arlr6Yb1EfwDAAAylw"]
[Thu Jul 30 12:10:41.350069 2026] [security2:error] [pid 703393:tid 703592] [client 2.51.55.76:52433] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFkM637Arlr6Yb1EfwCwAAykw"]
[Thu Jul 30 12:10:41.489224 2026] [security2:error] [pid 703393:tid 703580] [client 20.100.187.180:23450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.milfordauto.com"] [uri "/aa.php"] [unique_id "amuFkc637Arlr6Yb1EfwHwAAAL4"]
[Thu Jul 30 12:10:41.489368 2026] [security2:error] [pid 703393:tid 703580] [client 20.100.187.180:23450] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.milfordauto.com"] [uri "/aa.php"] [unique_id "amuFkc637Arlr6Yb1EfwHwAAAL4"]
[Thu Jul 30 12:10:41.640816 2026] [security2:error] [pid 703393:tid 703627] [client 250.49.135.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuFkc637Arlr6Yb1EfwIAAA7V4"]
[Thu Jul 30 12:10:41.678483 2026] [core:notice] [pid 703393:tid 703533] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:41.684641 2026] [security2:error] [pid 703393:tid 703533] [client 103.215.74.26:8304] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFkc637Arlr6Yb1EfwJgAAAI8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:42.109545 2026] [security2:error] [pid 703393:tid 703639] [client 35.204.157.49:49152] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "ad-company.net"] [uri "/"] [unique_id "amuFks637Arlr6Yb1EfwNAAAAPk"]
[Thu Jul 30 12:10:42.109658 2026] [security2:error] [pid 703393:tid 703639] [client 35.204.157.49:49152] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ad-company.net"] [uri "/"] [unique_id "amuFks637Arlr6Yb1EfwNAAAAPk"]
[Thu Jul 30 12:10:42.406139 2026] [core:notice] [pid 703393:tid 703561] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:42.413553 2026] [security2:error] [pid 703393:tid 703561] [client 103.215.74.26:8316] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFks637Arlr6Yb1EfwNgAAAKs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:42.858694 2026] [core:notice] [pid 703393:tid 703497] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:43.026749 2026] [proxy:error] [pid 703393:tid 703478] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:10:43.026803 2026] [proxy_http:error] [pid 703393:tid 703478] [remote 74.7.230.40:44910] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:10:43.027380 2026] [proxy:error] [pid 703393:tid 703478] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:10:43.027425 2026] [proxy_http:error] [pid 703393:tid 703478] [remote 74.7.230.40:44910] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:10:43.093524 2026] [core:notice] [pid 703393:tid 703505] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:43.141655 2026] [core:notice] [pid 703393:tid 703527] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:43.149163 2026] [security2:error] [pid 703393:tid 703527] [client 103.215.74.26:21190] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFk8637Arlr6Yb1EfwSAAAAIk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:43.156172 2026] [core:notice] [pid 703393:tid 703540] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:43.310600 2026] [security2:error] [pid 703393:tid 703511] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/wp-store-lite/readme.txt"] [unique_id "amuFk8637Arlr6Yb1EfwTAAA2HU"]
[Thu Jul 30 12:10:43.436494 2026] [security2:error] [pid 703393:tid 703546] [client 20.104.18.253:32345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/011i.php"] [unique_id "amuFk8637Arlr6Yb1EfwTgAAAJw"]
[Thu Jul 30 12:10:43.937678 2026] [security2:error] [pid 703393:tid 703602] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFk8637Arlr6Yb1EfwTwAA1GQ"]
[Thu Jul 30 12:10:44.381064 2026] [security2:error] [pid 703393:tid 703611] [client 20.104.18.253:25473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/03a005685d.php"] [unique_id "amuFlM637Arlr6Yb1EfwWQAAAN0"]
[Thu Jul 30 12:10:44.629035 2026] [security2:error] [pid 703393:tid 703566] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFlM637Arlr6Yb1EfwUQAAsHQ"], referer: https://www.spececigarette.com/wp-content/plugins/wp-store-lite/Readme.txt
[Thu Jul 30 12:10:45.129404 2026] [security2:error] [pid 703393:tid 703572] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFlM637Arlr6Yb1EfwYAAAtgY"]
[Thu Jul 30 12:10:45.825327 2026] [security2:error] [pid 703393:tid 703562] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFlc637Arlr6Yb1EfwdAAArBQ"], referer: https://www.spececigarette.com/wp-content/plugins/wp-store-lite/README.txt
[Thu Jul 30 12:10:46.230044 2026] [security2:error] [pid 703393:tid 703416] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/c4d-plugin-manager/readme.txt"] [unique_id "amuFls637Arlr6Yb1EfwfwAApBY"]
[Thu Jul 30 12:10:46.311410 2026] [security2:error] [pid 703393:tid 703582] [client 2a03:2880:f800:1f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuFlc637Arlr6Yb1EfweAAAwBE"]
[Thu Jul 30 12:10:46.474787 2026] [security2:error] [pid 703393:tid 703617] [client 74.7.244.35:46402] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "rgserve.ph.qnj.gzj.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuFls637Arlr6Yb1EfwhQAA4yA"]
[Thu Jul 30 12:10:46.515740 2026] [security2:error] [pid 703393:tid 703625] [client 20.100.187.180:16421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.milfordauto.com"] [uri "/av.php"] [unique_id "amuFls637Arlr6Yb1EfwiAAAAOs"]
[Thu Jul 30 12:10:46.515866 2026] [security2:error] [pid 703393:tid 703625] [client 20.100.187.180:16421] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.milfordauto.com"] [uri "/av.php"] [unique_id "amuFls637Arlr6Yb1EfwiAAAAOs"]
[Thu Jul 30 12:10:46.592441 2026] [core:error] [pid 703393:tid 703424] [remote 74.7.230.49:53410] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:10:46.592463 2026] [core:error] [pid 703393:tid 703424] [remote 74.7.230.49:53410] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:10:46.592697 2026] [security2:error] [pid 703393:tid 703601] [client 74.7.230.49:53410] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "mail.ampcloudku.com"] [uri "/index.php"] [unique_id "amuFls637Arlr6Yb1EfwiQAA0x4"]
[Thu Jul 30 12:10:46.673791 2026] [security2:error] [pid 703393:tid 703574] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFls637Arlr6Yb1EfwgAAAuCQ"]
[Thu Jul 30 12:10:47.219168 2026] [security2:error] [pid 703393:tid 703636] [client 43.161.224.78:36278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.224.161.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/agrijati"] [unique_id "amuFl8637Arlr6Yb1EfwkAAAAPY"], referer: https://ejournalugj.com/index_php/agrijati
[Thu Jul 30 12:10:47.819767 2026] [security2:error] [pid 703393:tid 703586] [client 43.173.174.105:49568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.174.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/12/06/noel-2015-idees-cadeaux-cosmetiques-bio/"] [unique_id "amuFl8637Arlr6Yb1EfwmwAAAMQ"]
[Thu Jul 30 12:10:47.923160 2026] [security2:error] [pid 703393:tid 703523] [client 57.141.0.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuFl8637Arlr6Yb1EfwkwAAAIU"]
[Thu Jul 30 12:10:48.292721 2026] [core:notice] [pid 703393:tid 703528] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:48.297580 2026] [security2:error] [pid 703393:tid 703528] [client 43.173.174.105:49580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/12/06/noel-2015-idees-cadeaux-cosmetiques-bio/"] [unique_id "amuFmM637Arlr6Yb1EfwqgAAAIo"], referer: https://carnetdeshopping.com/index.php/2015/12/06/noel-2015-idees-cadeaux-cosmetiques-bio/
[Thu Jul 30 12:10:48.402766 2026] [security2:error] [pid 703393:tid 703594] [client 20.104.18.253:38941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/403.php"] [unique_id "amuFmM637Arlr6Yb1EfwqwAAAMw"]
[Thu Jul 30 12:10:48.980080 2026] [core:notice] [pid 703393:tid 703649] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:48.986800 2026] [security2:error] [pid 703393:tid 703649] [client 103.215.74.26:21198] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFmM637Arlr6Yb1EfwswAAAQM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:49.597249 2026] [security2:error] [pid 703393:tid 703573] [client 20.100.187.180:56990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.milfordauto.com"] [uri "/xa.php"] [unique_id "amuFmc637Arlr6Yb1EfwwQAAALc"]
[Thu Jul 30 12:10:49.597348 2026] [security2:error] [pid 703393:tid 703573] [client 20.100.187.180:56990] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.milfordauto.com"] [uri "/xa.php"] [unique_id "amuFmc637Arlr6Yb1EfwwQAAALc"]
[Thu Jul 30 12:10:49.707275 2026] [core:notice] [pid 703393:tid 703617] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:49.713714 2026] [security2:error] [pid 703393:tid 703617] [client 103.215.74.26:21200] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFmc637Arlr6Yb1EfwxQAAAOM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:50.463855 2026] [core:notice] [pid 703393:tid 703616] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:50.470295 2026] [security2:error] [pid 703393:tid 703616] [client 103.215.74.26:21210] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFms637Arlr6Yb1EfwzgAAAOI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:51.165449 2026] [security2:error] [pid 703393:tid 703534] [client 20.104.18.253:35205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/404.php"] [unique_id "amuFm8637Arlr6Yb1Efw2QAAAJA"]
[Thu Jul 30 12:10:51.186390 2026] [core:notice] [pid 703393:tid 703635] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:51.193581 2026] [security2:error] [pid 703393:tid 703635] [client 103.215.74.26:21226] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFm8637Arlr6Yb1Efw2gAAAPU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:51.747010 2026] [core:notice] [pid 703393:tid 703567] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:51.909243 2026] [core:notice] [pid 703393:tid 703650] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:51.915556 2026] [security2:error] [pid 703393:tid 703650] [client 103.215.74.26:21238] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFm8637Arlr6Yb1Efw6wAAAQQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:52.075275 2026] [security2:error] [pid 703393:tid 703527] [client 20.100.187.180:16425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.milfordauto.com"] [uri "/media.php"] [unique_id "amuFnM637Arlr6Yb1Efw7AAAAIk"]
[Thu Jul 30 12:10:52.075401 2026] [security2:error] [pid 703393:tid 703527] [client 20.100.187.180:16425] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.milfordauto.com"] [uri "/media.php"] [unique_id "amuFnM637Arlr6Yb1Efw7AAAAIk"]
[Thu Jul 30 12:10:52.635757 2026] [core:notice] [pid 703393:tid 703640] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:52.638834 2026] [security2:error] [pid 703393:tid 703625] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFnM637Arlr6Yb1Efw8AAA6w8"], referer: https://www.spececigarette.com/wp-content/plugins/c4d-plugin-manager/Readme.txt
[Thu Jul 30 12:10:52.642411 2026] [security2:error] [pid 703393:tid 703640] [client 103.215.74.26:21248] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFnM637Arlr6Yb1Efw9gAAAPo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:52.797063 2026] [security2:error] [pid 703393:tid 703544] [client 20.104.18.253:42452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/aa.php"] [unique_id "amuFnM637Arlr6Yb1Efw_QAAAJo"]
[Thu Jul 30 12:10:53.334456 2026] [security2:error] [pid 703393:tid 703558] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFnc637Arlr6Yb1Efw_gAAqC4"]
[Thu Jul 30 12:10:53.363127 2026] [core:notice] [pid 703393:tid 703618] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:53.369455 2026] [security2:error] [pid 703393:tid 703618] [client 103.215.74.26:28150] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFnc637Arlr6Yb1EfxBQAAAOQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:53.571233 2026] [security2:error] [pid 703393:tid 703579] [client 20.100.187.180:37112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.milfordauto.com"] [uri "/images.php"] [unique_id "amuFnc637Arlr6Yb1EfxBgAAAL0"]
[Thu Jul 30 12:10:53.571367 2026] [security2:error] [pid 703393:tid 703579] [client 20.100.187.180:37112] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.milfordauto.com"] [uri "/images.php"] [unique_id "amuFnc637Arlr6Yb1EfxBgAAAL0"]
[Thu Jul 30 12:10:54.037612 2026] [security2:error] [pid 703393:tid 703616] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFnc637Arlr6Yb1EfxBwAA4jc"], referer: https://www.spececigarette.com/wp-content/plugins/c4d-plugin-manager/README.txt
[Thu Jul 30 12:10:54.095525 2026] [core:notice] [pid 703393:tid 703646] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:54.103815 2026] [security2:error] [pid 703393:tid 703646] [client 103.215.74.26:28154] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFns637Arlr6Yb1EfxEAAAAQA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:54.424555 2026] [security2:error] [pid 703393:tid 703461] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/blaze-ads/readme.txt"] [unique_id "amuFns637Arlr6Yb1EfxGwAAlEM"]
[Thu Jul 30 12:10:54.727517 2026] [security2:error] [pid 703393:tid 703631] [client 20.104.18.253:32361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/aafewc0k.php"] [unique_id "amuFns637Arlr6Yb1EfxHQAAAPE"]
[Thu Jul 30 12:10:54.860370 2026] [security2:error] [pid 703393:tid 703578] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFns637Arlr6Yb1EfxHAAAvA4"]
[Thu Jul 30 12:10:55.567810 2026] [security2:error] [pid 703393:tid 703554] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFn8637Arlr6Yb1EfxJAAApDQ"], referer: https://www.spececigarette.com/wp-content/plugins/blaze-ads/Readme.txt
[Thu Jul 30 12:10:55.739608 2026] [security2:error] [pid 703393:tid 703601] [client 20.100.187.180:23487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.milfordauto.com"] [uri "/gecko.php"] [unique_id "amuFn8637Arlr6Yb1EfxLgAAANM"]
[Thu Jul 30 12:10:55.739727 2026] [security2:error] [pid 703393:tid 703601] [client 20.100.187.180:23487] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.milfordauto.com"] [uri "/gecko.php"] [unique_id "amuFn8637Arlr6Yb1EfxLgAAANM"]
[Thu Jul 30 12:10:56.118822 2026] [security2:error] [pid 703393:tid 703525] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFn8637Arlr6Yb1EfxLwAAh0c"]
[Thu Jul 30 12:10:56.145119 2026] [security2:error] [pid 703393:tid 703640] [client 20.52.125.110:8471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.tmb/LA.php"] [unique_id "amuFoM637Arlr6Yb1EfxNwAAAPo"]
[Thu Jul 30 12:10:56.347509 2026] [security2:error] [pid 703393:tid 703598] [client 20.104.18.253:44407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/abcd.php"] [unique_id "amuFoM637Arlr6Yb1EfxOAAAANA"]
[Thu Jul 30 12:10:56.815094 2026] [security2:error] [pid 703393:tid 703539] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFoM637Arlr6Yb1EfxOgAAlVE"], referer: https://www.spececigarette.com/wp-content/plugins/blaze-ads/README.txt
[Thu Jul 30 12:10:56.825570 2026] [security2:error] [pid 703393:tid 703629] [client 20.52.125.110:8247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.tmb/admin.php"] [unique_id "amuFoM637Arlr6Yb1EfxQAAAAO8"]
[Thu Jul 30 12:10:57.149642 2026] [security2:error] [pid 703393:tid 703647] [client 47.128.122.130:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuFoc637Arlr6Yb1EfxSAAAAQE"]
[Thu Jul 30 12:10:57.374278 2026] [security2:error] [pid 703393:tid 703556] [client 20.52.125.110:8082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.tmb/class_api.php"] [unique_id "amuFoc637Arlr6Yb1EfxSgAAAKY"]
[Thu Jul 30 12:10:57.424298 2026] [security2:error] [pid 703393:tid 703648] [client 20.104.18.253:44390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/about.php"] [unique_id "amuFoc637Arlr6Yb1EfxSwAAAQI"]
[Thu Jul 30 12:10:57.586376 2026] [security2:error] [pid 703393:tid 703633] [client 185.189.112.11:40228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.112.189.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuFoc637Arlr6Yb1EfxUgAAAPM"]
[Thu Jul 30 12:10:57.586461 2026] [security2:error] [pid 703393:tid 703633] [client 185.189.112.11:40228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuFoc637Arlr6Yb1EfxUgAAAPM"]
[Thu Jul 30 12:10:57.848916 2026] [security2:error] [pid 703393:tid 703616] [client 20.52.125.110:8230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.tmb/cpabpkyk.php"] [unique_id "amuFoc637Arlr6Yb1EfxVAAAAOI"]
[Thu Jul 30 12:10:58.645707 2026] [security2:error] [pid 703393:tid 703628] [client 20.52.125.110:8236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.tmb/wp-login.php"] [unique_id "amuFos637Arlr6Yb1EfxWwAAAO4"]
[Thu Jul 30 12:10:59.384004 2026] [security2:error] [pid 703393:tid 703492] [remote 216.73.216.152:23332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuFo8637Arlr6Yb1EfxbAAAwmI"]
[Thu Jul 30 12:10:59.418079 2026] [security2:error] [pid 703393:tid 703559] [client 20.52.125.110:8217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known//.well-known/owlmailer.php"] [unique_id "amuFo8637Arlr6Yb1EfxbQAAAKk"]
[Thu Jul 30 12:10:59.461417 2026] [security2:error] [pid 703393:tid 703595] [client 191.232.199.39:54106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/chosen.php"] [unique_id "amuFo8637Arlr6Yb1EfxbgAAAM0"]
[Thu Jul 30 12:10:59.816503 2026] [core:notice] [pid 703393:tid 703596] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:59.823714 2026] [security2:error] [pid 703393:tid 703596] [client 103.215.74.26:28168] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFo8637Arlr6Yb1EfxdgAAAM4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:59.963000 2026] [security2:error] [pid 703393:tid 703626] [client 20.52.125.110:8449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/991176.php"] [unique_id "amuFo8637Arlr6Yb1EfxeQAAAOw"]
[Thu Jul 30 12:11:00.004753 2026] [security2:error] [pid 703393:tid 703641] [client 20.104.18.253:32329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/admin.php"] [unique_id "amuFpM637Arlr6Yb1EfxegAAAPs"]
[Thu Jul 30 12:11:00.176542 2026] [security2:error] [pid 703393:tid 703471] [remote 57.141.0.63:21252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuFpM637Arlr6Yb1EfxfwAAy00"]
[Thu Jul 30 12:11:00.618846 2026] [security2:error] [pid 703393:tid 703580] [client 20.52.125.110:8222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/acme-challenge/adminfuns.php"] [unique_id "amuFpM637Arlr6Yb1EfxjAAAAL4"]
[Thu Jul 30 12:11:00.658158 2026] [security2:error] [pid 703393:tid 703591] [client 20.100.187.180:37101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.milfordauto.com"] [uri "/82.php"] [unique_id "amuFpM637Arlr6Yb1EfxjwAAAMk"]
[Thu Jul 30 12:11:00.658265 2026] [security2:error] [pid 703393:tid 703591] [client 20.100.187.180:37101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.milfordauto.com"] [uri "/82.php"] [unique_id "amuFpM637Arlr6Yb1EfxjwAAAMk"]
[Thu Jul 30 12:11:01.093536 2026] [security2:error] [pid 703393:tid 703564] [client 20.52.125.110:8503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "amuFpc637Arlr6Yb1EfxlgAAAK4"]
[Thu Jul 30 12:11:01.633574 2026] [security2:error] [pid 703393:tid 703536] [client 191.232.199.39:54100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/xleet.php"] [unique_id "amuFpc637Arlr6Yb1EfxnwAAAJI"]
[Thu Jul 30 12:11:01.739851 2026] [security2:error] [pid 703393:tid 703631] [client 20.52.125.110:8210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/acme-challenge/classsmtps.php"] [unique_id "amuFpc637Arlr6Yb1EfxpAAAAPE"]
[Thu Jul 30 12:11:02.215421 2026] [security2:error] [pid 703393:tid 703511] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/suyool-payment/readme.txt"] [unique_id "amuFps637Arlr6Yb1EfxsAAAzXU"]
[Thu Jul 30 12:11:02.321770 2026] [security2:error] [pid 703393:tid 703602] [client 20.52.125.110:8096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "amuFps637Arlr6Yb1EfxswAAANQ"]
[Thu Jul 30 12:11:02.527690 2026] [security2:error] [pid 703393:tid 703545] [client 20.100.187.180:16405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.milfordauto.com"] [uri "/xstelth.php"] [unique_id "amuFps637Arlr6Yb1EfxuwAAAJs"]
[Thu Jul 30 12:11:02.527796 2026] [security2:error] [pid 703393:tid 703545] [client 20.100.187.180:16405] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.milfordauto.com"] [uri "/xstelth.php"] [unique_id "amuFps637Arlr6Yb1EfxuwAAAJs"]
[Thu Jul 30 12:11:02.603798 2026] [security2:error] [pid 703393:tid 703614] [client 2a03:2880:f800:17:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuFpc637Arlr6Yb1EfxqwAA4Gc"]
[Thu Jul 30 12:11:02.815644 2026] [security2:error] [pid 703393:tid 703569] [client 20.104.18.253:52727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/adminfuns.php"] [unique_id "amuFps637Arlr6Yb1EfxwwAAALM"]
[Thu Jul 30 12:11:02.870713 2026] [security2:error] [pid 703393:tid 703608] [client 20.52.125.110:8198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/acme-challenge/doc.php"] [unique_id "amuFps637Arlr6Yb1EfxxAAAANo"]
[Thu Jul 30 12:11:02.911572 2026] [security2:error] [pid 703393:tid 703525] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFps637Arlr6Yb1EfxugAAh2o"]
[Thu Jul 30 12:11:03.089966 2026] [security2:error] [pid 703393:tid 703641] [client 57.141.0.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuFps637Arlr6Yb1EfxuQAAAPs"]
[Thu Jul 30 12:11:03.342161 2026] [security2:error] [pid 703393:tid 703611] [client 57.141.0.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuFps637Arlr6Yb1EfxwQAAAN0"]
[Thu Jul 30 12:11:03.570973 2026] [security2:error] [pid 703393:tid 703607] [client 57.141.0.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuFps637Arlr6Yb1EfxywAAANk"]
[Thu Jul 30 12:11:03.572710 2026] [security2:error] [pid 703393:tid 703627] [client 20.52.125.110:14914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/011i.php"] [unique_id "amuFp8637Arlr6Yb1Efx8QAAAO0"]
[Thu Jul 30 12:11:03.580309 2026] [security2:error] [pid 703393:tid 703577] [client 20.52.125.110:8252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/acme-challenge/fond.php"] [unique_id "amuFp8637Arlr6Yb1Efx8gAAALs"]
[Thu Jul 30 12:11:04.109393 2026] [security2:error] [pid 703393:tid 703567] [client 20.52.125.110:8238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "amuFqM637Arlr6Yb1EfyBQAAALE"]
[Thu Jul 30 12:11:04.591111 2026] [security2:error] [pid 703393:tid 703560] [client 191.232.199.39:54105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/ds.php"] [unique_id "amuFqM637Arlr6Yb1EfyFQAAAKo"]
[Thu Jul 30 12:11:04.629152 2026] [security2:error] [pid 703393:tid 703540] [client 2a03:2880:f800:3c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuFp8637Arlr6Yb1Efx-QAAlig"]
[Thu Jul 30 12:11:04.666338 2026] [security2:error] [pid 703393:tid 703565] [client 20.52.125.110:8086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/acme-challenge/license.php"] [unique_id "amuFqM637Arlr6Yb1EfyFwAAAK8"]
[Thu Jul 30 12:11:04.774830 2026] [security2:error] [pid 703393:tid 703545] [client 20.104.18.253:25760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/albin.php"] [unique_id "amuFqM637Arlr6Yb1EfyGQAAAJs"]
[Thu Jul 30 12:11:04.777548 2026] [security2:error] [pid 703393:tid 703612] [client 20.52.125.110:14306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/03a005685d.php"] [unique_id "amuFqM637Arlr6Yb1EfyGgAAAN4"]
[Thu Jul 30 12:11:05.246508 2026] [security2:error] [pid 703393:tid 703647] [client 20.52.125.110:8088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/acme-challenge/mariju.php"] [unique_id "amuFqc637Arlr6Yb1EfyJQAAAQE"]
[Thu Jul 30 12:11:05.551669 2026] [core:notice] [pid 703393:tid 703531] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:05.558164 2026] [security2:error] [pid 703393:tid 703531] [client 103.215.74.26:63894] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFqc637Arlr6Yb1EfyLQAAAI0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:05.664842 2026] [security2:error] [pid 703393:tid 703586] [client 20.100.187.180:16407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.milfordauto.com"] [uri "/xp.php"] [unique_id "amuFqc637Arlr6Yb1EfyLgAAAMQ"]
[Thu Jul 30 12:11:05.664997 2026] [security2:error] [pid 703393:tid 703586] [client 20.100.187.180:16407] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.milfordauto.com"] [uri "/xp.php"] [unique_id "amuFqc637Arlr6Yb1EfyLgAAAMQ"]
[Thu Jul 30 12:11:05.796442 2026] [core:notice] [pid 703393:tid 703412] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:05.953684 2026] [security2:error] [pid 703393:tid 703627] [client 20.52.125.110:8463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/acme-challenge/moon.php"] [unique_id "amuFqc637Arlr6Yb1EfyNgAAAO0"]
[Thu Jul 30 12:11:05.955170 2026] [security2:error] [pid 703393:tid 703607] [client 191.232.199.39:54109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/f5.php"] [unique_id "amuFqc637Arlr6Yb1EfyNwAAANk"]
[Thu Jul 30 12:11:06.054906 2026] [core:notice] [pid 703393:tid 703460] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:06.275245 2026] [core:notice] [pid 703393:tid 703557] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:06.282580 2026] [security2:error] [pid 703393:tid 703557] [client 103.215.74.26:63914] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFqs637Arlr6Yb1EfyPAAAAKc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:06.309093 2026] [security2:error] [pid 703393:tid 703551] [client 20.226.5.174:28164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/011i.php"] [unique_id "amuFqs637Arlr6Yb1EfyPQAAAKE"]
[Thu Jul 30 12:11:06.315706 2026] [security2:error] [pid 703393:tid 703526] [client 20.52.125.110:14276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/403.php"] [unique_id "amuFqs637Arlr6Yb1EfyPgAAAIg"]
[Thu Jul 30 12:11:06.474125 2026] [security2:error] [pid 703393:tid 703606] [client 20.52.125.110:8467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amuFqs637Arlr6Yb1EfyRgAAANg"]
[Thu Jul 30 12:11:06.622002 2026] [security2:error] [pid 703393:tid 703629] [client 191.232.199.39:6866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/chosen.php"] [unique_id "amuFqs637Arlr6Yb1EfyRwAAAO8"]
[Thu Jul 30 12:11:07.006715 2026] [core:notice] [pid 703393:tid 703626] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:07.012685 2026] [security2:error] [pid 703393:tid 703626] [client 103.215.74.26:63926] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFq8637Arlr6Yb1EfyTQAAAOw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:07.139871 2026] [security2:error] [pid 703393:tid 703602] [client 20.52.125.110:8241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "amuFq8637Arlr6Yb1EfyUAAAANQ"]
[Thu Jul 30 12:11:07.255050 2026] [security2:error] [pid 703393:tid 703540] [client 20.104.18.253:25529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/amfsqvgv.php"] [unique_id "amuFq8637Arlr6Yb1EfyUQAAAJY"]
[Thu Jul 30 12:11:07.402541 2026] [security2:error] [pid 703393:tid 703566] [client 20.100.187.180:57281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.milfordauto.com"] [uri "/admin.php"] [unique_id "amuFq8637Arlr6Yb1EfyUgAAALA"]
[Thu Jul 30 12:11:07.402667 2026] [security2:error] [pid 703393:tid 703566] [client 20.100.187.180:57281] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.milfordauto.com"] [uri "/admin.php"] [unique_id "amuFq8637Arlr6Yb1EfyUgAAALA"]
[Thu Jul 30 12:11:07.524449 2026] [security2:error] [pid 703393:tid 703593] [client 20.226.5.174:27396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/03a005685d.php"] [unique_id "amuFq8637Arlr6Yb1EfyWgAAAMs"]
[Thu Jul 30 12:11:07.620711 2026] [security2:error] [pid 703393:tid 703558] [client 20.52.125.110:8235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "amuFq8637Arlr6Yb1EfyXgAAAKg"]
[Thu Jul 30 12:11:07.739521 2026] [core:notice] [pid 703393:tid 703580] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:07.750284 2026] [security2:error] [pid 703393:tid 703580] [client 103.215.74.26:63940] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFq8637Arlr6Yb1EfyYAAAAL4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:07.826215 2026] [security2:error] [pid 703393:tid 703523] [client 191.232.199.39:6865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/xleet.php"] [unique_id "amuFq8637Arlr6Yb1EfyYQAAAIU"]
[Thu Jul 30 12:11:08.034066 2026] [core:notice] [pid 703393:tid 703466] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:08.102624 2026] [security2:error] [pid 703393:tid 703636] [client 191.232.199.39:54114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/god4m.php"] [unique_id "amuFrM637Arlr6Yb1EfyaQAAAPY"]
[Thu Jul 30 12:11:08.170106 2026] [security2:error] [pid 703393:tid 703564] [client 20.52.125.110:8211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/amaxx.php"] [unique_id "amuFrM637Arlr6Yb1EfyagAAAK4"]
[Thu Jul 30 12:11:08.466298 2026] [core:notice] [pid 703393:tid 703571] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:08.472199 2026] [security2:error] [pid 703393:tid 703571] [client 103.215.74.26:63964] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFrM637Arlr6Yb1EfycAAAALU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:08.564500 2026] [security2:error] [pid 703393:tid 703527] [client 20.100.187.180:57003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.milfordauto.com"] [uri "/adminner.php"] [unique_id "amuFrM637Arlr6Yb1EfydAAAAIk"]
[Thu Jul 30 12:11:08.564624 2026] [security2:error] [pid 703393:tid 703527] [client 20.100.187.180:57003] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.milfordauto.com"] [uri "/adminner.php"] [unique_id "amuFrM637Arlr6Yb1EfydAAAAIk"]
[Thu Jul 30 12:11:08.634450 2026] [security2:error] [pid 703393:tid 703615] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFrM637Arlr6Yb1EfyawAA4Vc"], referer: https://www.spececigarette.com/wp-content/plugins/suyool-payment/Readme.txt
[Thu Jul 30 12:11:08.967495 2026] [security2:error] [pid 703393:tid 703567] [client 20.52.125.110:8102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/bek.php"] [unique_id "amuFrM637Arlr6Yb1EfyegAAALE"]
[Thu Jul 30 12:11:09.022944 2026] [security2:error] [pid 703393:tid 703534] [client 20.104.18.253:35211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/ant.php"] [unique_id "amuFrc637Arlr6Yb1EfyfAAAAJA"]
[Thu Jul 30 12:11:09.033285 2026] [security2:error] [pid 703393:tid 703562] [client 57.141.0.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuFrM637Arlr6Yb1EfybwAAAKw"]
[Thu Jul 30 12:11:09.046520 2026] [security2:error] [pid 703393:tid 703600] [client 20.226.5.174:28179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/403.php"] [unique_id "amuFrc637Arlr6Yb1EfygAAAANI"]
[Thu Jul 30 12:11:09.142479 2026] [security2:error] [pid 703393:tid 703487] [remote 47.128.27.69:62486] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/nike-wmns-air-jordan-1-low-barb-white-black-green/"] [unique_id "amuFrc637Arlr6Yb1EfyhAAAmF0"]
[Thu Jul 30 12:11:09.193011 2026] [core:notice] [pid 703393:tid 703629] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:09.199628 2026] [security2:error] [pid 703393:tid 703629] [client 103.215.74.26:63974] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFrc637Arlr6Yb1EfyhQAAAO8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:09.280644 2026] [security2:error] [pid 703393:tid 703554] [client 191.232.199.39:6854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/ds.php"] [unique_id "amuFrc637Arlr6Yb1EfyiQAAAKQ"]
[Thu Jul 30 12:11:09.325661 2026] [security2:error] [pid 703393:tid 703625] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFrc637Arlr6Yb1EfyewAA61I"]
[Thu Jul 30 12:11:09.353870 2026] [security2:error] [pid 703393:tid 703601] [client 191.232.199.39:54092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/info.php"] [unique_id "amuFrc637Arlr6Yb1EfyiwAAANM"]
[Thu Jul 30 12:11:09.390647 2026] [security2:error] [pid 703393:tid 703470] [remote 216.73.216.152:57269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuFrc637Arlr6Yb1EfyjQAAtEw"]
[Thu Jul 30 12:11:09.493425 2026] [autoindex:error] [pid 703393:tid 703579] [client 43.166.136.24:44312] AH01276: Cannot serve directory /home2/ubphmute/public_html/website_da8a69f1/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:11:09.555007 2026] [security2:error] [pid 703393:tid 703569] [client 20.52.125.110:8488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/caches.php.suspected"] [unique_id "amuFrc637Arlr6Yb1EfyjwAAALM"]
[Thu Jul 30 12:11:09.936734 2026] [core:notice] [pid 703393:tid 703539] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:09.942932 2026] [security2:error] [pid 703393:tid 703539] [client 103.215.74.26:63990] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFrc637Arlr6Yb1EfymwAAAJU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:10.013139 2026] [security2:error] [pid 703393:tid 703641] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFrc637Arlr6Yb1EfykwAA-1s"], referer: https://www.spececigarette.com/wp-content/plugins/suyool-payment/README.txt
[Thu Jul 30 12:11:10.263597 2026] [security2:error] [pid 703393:tid 703523] [client 20.52.125.110:14315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/404.php"] [unique_id "amuFrs637Arlr6Yb1EfyogAAAIU"]
[Thu Jul 30 12:11:10.384690 2026] [security2:error] [pid 703393:tid 703502] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/station-pro/readme.txt"] [unique_id "amuFrs637Arlr6Yb1EfypAAAzGw"]
[Thu Jul 30 12:11:10.487103 2026] [security2:error] [pid 703393:tid 703604] [client 43.159.145.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "legalsnaps.info"] [uri "/index.php"] [unique_id "amuFrc637Arlr6Yb1EfyiAAAANY"]
[Thu Jul 30 12:11:10.594457 2026] [security2:error] [pid 703393:tid 703576] [client 20.52.125.110:8195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/class.api.php"] [unique_id "amuFrs637Arlr6Yb1EfyqAAAALo"]
[Thu Jul 30 12:11:10.665469 2026] [core:notice] [pid 703393:tid 703636] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:10.676017 2026] [security2:error] [pid 703393:tid 703636] [client 103.215.74.26:64002] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFrs637Arlr6Yb1EfyrQAAAPY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:10.805674 2026] [security2:error] [pid 703393:tid 703538] [client 191.232.199.39:6887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/f5.php"] [unique_id "amuFrs637Arlr6Yb1EfysAAAAJQ"]
[Thu Jul 30 12:11:10.818956 2026] [security2:error] [pid 703393:tid 703619] [client 20.226.5.174:27405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/404.php"] [unique_id "amuFrs637Arlr6Yb1EfysQAAAOU"]
[Thu Jul 30 12:11:10.825526 2026] [security2:error] [pid 703393:tid 703535] [client 20.52.125.110:14310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/aa.php"] [unique_id "amuFrs637Arlr6Yb1EfysgAAAJE"]
[Thu Jul 30 12:11:10.915747 2026] [security2:error] [pid 703393:tid 703496] [remote 74.7.241.60:50878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/content/article.php"] [unique_id "amuFrs637Arlr6Yb1EfyswAA7mY"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/content/1784123347_ed%20inclusive.jpg
[Thu Jul 30 12:11:10.929141 2026] [core:notice] [pid 703393:tid 703549] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:11.027823 2026] [security2:error] [pid 703393:tid 703573] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFrs637Arlr6Yb1EfyrgAAt2E"]
[Thu Jul 30 12:11:11.418622 2026] [core:notice] [pid 703393:tid 703596] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:11.428355 2026] [security2:error] [pid 703393:tid 703596] [client 103.215.74.26:64008] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFr8637Arlr6Yb1EfywAAAAM4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:11.462316 2026] [security2:error] [pid 703393:tid 703607] [client 20.52.125.110:8506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/cong.php"] [unique_id "amuFr8637Arlr6Yb1EfywgAAANk"]
[Thu Jul 30 12:11:11.563763 2026] [security2:error] [pid 703393:tid 703567] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFr8637Arlr6Yb1EfyuwAAsVg"], referer: https://www.spececigarette.com/wp-content/plugins/station-pro/Readme.txt
[Thu Jul 30 12:11:11.661877 2026] [security2:error] [pid 703393:tid 703525] [client 20.104.18.253:39942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/appreciators.php"] [unique_id "amuFr8637Arlr6Yb1EfyxwAAAIc"]
[Thu Jul 30 12:11:11.668497 2026] [security2:error] [pid 703393:tid 703626] [client 20.52.125.110:14280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/aafewc0k.php"] [unique_id "amuFr8637Arlr6Yb1EfyyQAAAOw"]
[Thu Jul 30 12:11:11.982441 2026] [security2:error] [pid 703393:tid 703554] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFr8637Arlr6Yb1EfyyAAApG0"]
[Thu Jul 30 12:11:12.065011 2026] [security2:error] [pid 703393:tid 703597] [client 2a03:2880:f800:3:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuFr8637Arlr6Yb1EfywQAAz3U"]
[Thu Jul 30 12:11:12.086226 2026] [security2:error] [pid 703393:tid 703533] [client 20.52.125.110:8065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/content.php"] [unique_id "amuFsM637Arlr6Yb1EfyzgAAAI8"]
[Thu Jul 30 12:11:12.237773 2026] [security2:error] [pid 703393:tid 703642] [client 20.226.5.174:28171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/aa.php"] [unique_id "amuFsM637Arlr6Yb1Efy1QAAAPw"]
[Thu Jul 30 12:11:12.365091 2026] [autoindex:error] [pid 703393:tid 703641] [client 119.45.7.86:47742] AH01276: Cannot serve directory /home1/yqegzjte/fintn.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:11:12.497242 2026] [security2:error] [pid 703393:tid 703645] [client 20.52.125.110:14920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/abcd.php"] [unique_id "amuFsM637Arlr6Yb1Efy2wAAAP8"]
[Thu Jul 30 12:11:12.572280 2026] [security2:error] [pid 703393:tid 703610] [client 191.232.199.39:6849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/god4m.php"] [unique_id "amuFsM637Arlr6Yb1Efy3AAAANw"]
[Thu Jul 30 12:11:12.708396 2026] [security2:error] [pid 703393:tid 703556] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFsM637Arlr6Yb1Efy1gAApmo"], referer: https://www.spececigarette.com/wp-content/plugins/station-pro/README.txt
[Thu Jul 30 12:11:12.854680 2026] [security2:error] [pid 703393:tid 703633] [client 20.52.125.110:8007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/cwianpri.php"] [unique_id "amuFsM637Arlr6Yb1Efy4wAAAPM"]
[Thu Jul 30 12:11:13.255145 2026] [proxy:error] [pid 703393:tid 703623] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:11:13.255197 2026] [proxy_http:error] [pid 703393:tid 703623] [client 191.232.199.39:54098] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:11:13.255773 2026] [proxy:error] [pid 703393:tid 703623] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:11:13.255814 2026] [proxy_http:error] [pid 703393:tid 703623] [client 191.232.199.39:54098] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:11:13.317151 2026] [security2:error] [pid 703393:tid 703555] [client 62.238.42.130:15180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "happyspree.app"] [uri "/index.php"] [unique_id "amuFrs637Arlr6Yb1EfyowAAAKU"]
[Thu Jul 30 12:11:13.400147 2026] [security2:error] [pid 703393:tid 703618] [client 20.52.125.110:14279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/about.php"] [unique_id "amuFsc637Arlr6Yb1Efy7gAAAOQ"]
[Thu Jul 30 12:11:13.412130 2026] [security2:error] [pid 703393:tid 703527] [client 20.52.125.110:8004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/elp.php"] [unique_id "amuFsc637Arlr6Yb1Efy7wAAAIk"]
[Thu Jul 30 12:11:13.741491 2026] [security2:error] [pid 703393:tid 703622] [client 191.232.199.39:6870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/info.php"] [unique_id "amuFsc637Arlr6Yb1Efy8AAAAOg"]
[Thu Jul 30 12:11:13.961311 2026] [core:notice] [pid 703393:tid 703567] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:14.327926 2026] [security2:error] [pid 703393:tid 703583] [client 20.52.125.110:8092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/kwggvpup.php"] [unique_id "amuFss637Arlr6Yb1Efy_AAAAME"]
[Thu Jul 30 12:11:14.503598 2026] [security2:error] [pid 703393:tid 703625] [client 20.52.125.110:14286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/admin.php"] [unique_id "amuFss637Arlr6Yb1EfzAQAAAOs"]
[Thu Jul 30 12:11:14.932139 2026] [security2:error] [pid 703393:tid 703513] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/storeman/readme.txt"] [unique_id "amuFss637Arlr6Yb1EfzCwAA4nc"]
[Thu Jul 30 12:11:14.951178 2026] [security2:error] [pid 703393:tid 703552] [client 20.52.125.110:8209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/101d2ae2-f2f3-4977-b35d-b3a0ad74a469.php"] [unique_id "amuFss637Arlr6Yb1EfzDAAAAKI"]
[Thu Jul 30 12:11:15.039377 2026] [security2:error] [pid 703393:tid 703611] [client 20.63.98.115:20662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/gmo.php"] [unique_id "amuFs8637Arlr6Yb1EfzDgAAAN0"]
[Thu Jul 30 12:11:15.346885 2026] [security2:error] [pid 703393:tid 703612] [client 213.152.187.215:60558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.187.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuFs8637Arlr6Yb1EfzGAAAAN4"]
[Thu Jul 30 12:11:15.347001 2026] [security2:error] [pid 703393:tid 703612] [client 213.152.187.215:60558] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuFs8637Arlr6Yb1EfzGAAAAN4"]
[Thu Jul 30 12:11:15.604118 2026] [security2:error] [pid 703393:tid 703529] [client 20.52.125.110:8192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/LA.php"] [unique_id "amuFs8637Arlr6Yb1EfzHAAAAIs"]
[Thu Jul 30 12:11:15.695511 2026] [security2:error] [pid 703393:tid 703591] [client 191.232.199.39:54088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/.__info.php"] [unique_id "amuFs8637Arlr6Yb1EfzHQAAAMk"]
[Thu Jul 30 12:11:15.711722 2026] [security2:error] [pid 703393:tid 703433] [remote 57.141.0.21:38718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/628583096/feed/rss2/"] [unique_id "amuFs8637Arlr6Yb1EfzHgAApyc"]
[Thu Jul 30 12:11:15.985239 2026] [core:notice] [pid 703393:tid 703415] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:16.053569 2026] [security2:error] [pid 703393:tid 703586] [client 20.52.125.110:14291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/adminfuns.php"] [unique_id "amuFtM637Arlr6Yb1EfzJgAAAMQ"]
[Thu Jul 30 12:11:16.108750 2026] [proxy:error] [pid 703393:tid 703623] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:11:16.108798 2026] [proxy_http:error] [pid 703393:tid 703623] [client 191.232.199.39:6876] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:11:16.109362 2026] [proxy:error] [pid 703393:tid 703623] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:11:16.109406 2026] [proxy_http:error] [pid 703393:tid 703623] [client 191.232.199.39:6876] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:11:16.499393 2026] [security2:error] [pid 703393:tid 703598] [client 20.52.125.110:8459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/Newsupway.php"] [unique_id "amuFtM637Arlr6Yb1EfzMwAAANA"]
[Thu Jul 30 12:11:16.723743 2026] [security2:error] [pid 703393:tid 703582] [client 2a03:2880:f800:1a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuFtM637Arlr6Yb1EfzKQAAwCM"]
[Thu Jul 30 12:11:17.092012 2026] [security2:error] [pid 703393:tid 703614] [client 20.52.125.110:14285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/albin.php"] [unique_id "amuFtc637Arlr6Yb1EfzPwAAAOA"]
[Thu Jul 30 12:11:17.115150 2026] [security2:error] [pid 703393:tid 703550] [client 20.52.125.110:8464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/a.php"] [unique_id "amuFtc637Arlr6Yb1EfzQAAAAKA"]
[Thu Jul 30 12:11:17.153205 2026] [security2:error] [pid 703393:tid 703600] [client 20.104.18.253:32383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/archive.php"] [unique_id "amuFtc637Arlr6Yb1EfzQQAAANI"]
[Thu Jul 30 12:11:17.168615 2026] [security2:error] [pid 703393:tid 703615] [client 20.63.98.115:39059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/nakrip.php"] [unique_id "amuFtc637Arlr6Yb1EfzQgAAAOE"]
[Thu Jul 30 12:11:17.171478 2026] [core:notice] [pid 703393:tid 703632] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:17.177925 2026] [security2:error] [pid 703393:tid 703632] [client 103.215.74.26:17632] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFtc637Arlr6Yb1EfzQwAAAPI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:17.243381 2026] [security2:error] [pid 703393:tid 703626] [client 191.232.199.39:54084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/0.php"] [unique_id "amuFtc637Arlr6Yb1EfzRgAAAOw"]
[Thu Jul 30 12:11:17.597817 2026] [security2:error] [pid 703393:tid 703643] [client 20.52.125.110:8242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "amuFtc637Arlr6Yb1EfzTQAAAP0"]
[Thu Jul 30 12:11:17.853475 2026] [security2:error] [pid 703393:tid 703609] [client 20.91.208.34:55074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuFtc637Arlr6Yb1EfzTgAAANs"]
[Thu Jul 30 12:11:17.853632 2026] [security2:error] [pid 703393:tid 703609] [client 20.91.208.34:55074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuFtc637Arlr6Yb1EfzTgAAANs"]
[Thu Jul 30 12:11:17.915160 2026] [core:notice] [pid 703393:tid 703576] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:17.922416 2026] [security2:error] [pid 703393:tid 703576] [client 103.215.74.26:17634] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFtc637Arlr6Yb1EfzUgAAALo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:18.031048 2026] [security2:error] [pid 703393:tid 703524] [client 20.104.18.253:38900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/as.php"] [unique_id "amuFts637Arlr6Yb1EfzVgAAAIY"]
[Thu Jul 30 12:11:18.104236 2026] [security2:error] [pid 703393:tid 703636] [client 20.63.98.115:42949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/radio.php"] [unique_id "amuFts637Arlr6Yb1EfzVwAAAPY"]
[Thu Jul 30 12:11:18.111515 2026] [security2:error] [pid 703393:tid 703628] [client 20.52.125.110:8239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/amaxx.php"] [unique_id "amuFts637Arlr6Yb1EfzWAAAAO4"]
[Thu Jul 30 12:11:18.647117 2026] [core:notice] [pid 703393:tid 703644] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:18.655087 2026] [security2:error] [pid 703393:tid 703644] [client 103.215.74.26:17638] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFts637Arlr6Yb1EfzYQAAAP4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:18.670262 2026] [security2:error] [pid 703393:tid 703562] [client 20.52.125.110:8458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/bb.php"] [unique_id "amuFts637Arlr6Yb1EfzYgAAAKw"]
[Thu Jul 30 12:11:18.780162 2026] [security2:error] [pid 703393:tid 703560] [client 20.91.208.34:24107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuFts637Arlr6Yb1EfzYwAAAKo"]
[Thu Jul 30 12:11:18.780275 2026] [security2:error] [pid 703393:tid 703560] [client 20.91.208.34:24107] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuFts637Arlr6Yb1EfzYwAAAKo"]
[Thu Jul 30 12:11:18.967213 2026] [security2:error] [pid 703393:tid 703638] [client 20.104.18.253:45861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/atomlib.php"] [unique_id "amuFts637Arlr6Yb1EfzZQAAAPg"]
[Thu Jul 30 12:11:19.080495 2026] [security2:error] [pid 703393:tid 703542] [client 20.63.98.115:39095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-singin.php"] [unique_id "amuFt8637Arlr6Yb1EfzagAAAJg"]
[Thu Jul 30 12:11:19.265451 2026] [security2:error] [pid 703393:tid 703634] [client 20.52.125.110:8219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/cifcxgxm.php"] [unique_id "amuFt8637Arlr6Yb1EfzcAAAAPQ"]
[Thu Jul 30 12:11:19.382908 2026] [core:notice] [pid 703393:tid 703592] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:19.389424 2026] [security2:error] [pid 703393:tid 703592] [client 103.215.74.26:17648] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFt8637Arlr6Yb1EfzcgAAAMo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:19.399147 2026] [security2:error] [pid 703393:tid 703579] [client 20.91.208.34:58576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/x.php"] [unique_id "amuFt8637Arlr6Yb1EfzcwAAAL0"]
[Thu Jul 30 12:11:19.399305 2026] [security2:error] [pid 703393:tid 703579] [client 20.91.208.34:58576] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/x.php"] [unique_id "amuFt8637Arlr6Yb1EfzcwAAAL0"]
[Thu Jul 30 12:11:19.538970 2026] [security2:error] [pid 703393:tid 703647] [client 57.141.0.20:52328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuFtc637Arlr6Yb1EfzRAABAQY"], referer: https://igetvape-australia.com/product-tag/alibarbar-ingot-cool-mint-9000-puffs/
[Thu Jul 30 12:11:19.573972 2026] [security2:error] [pid 703393:tid 703602] [client 20.52.125.110:14324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/amfsqvgv.php"] [unique_id "amuFt8637Arlr6Yb1EfzhAAAANQ"]
[Thu Jul 30 12:11:19.910576 2026] [security2:error] [pid 703393:tid 703569] [client 20.52.125.110:8476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/ckyocyyp.php"] [unique_id "amuFt8637Arlr6Yb1EfzhQAAALM"]
[Thu Jul 30 12:11:19.946484 2026] [security2:error] [pid 703393:tid 703594] [client 20.91.208.34:10047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/mgrr.php"] [unique_id "amuFt8637Arlr6Yb1EfzhgAAAMw"]
[Thu Jul 30 12:11:19.946572 2026] [security2:error] [pid 703393:tid 703594] [client 20.91.208.34:10047] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/mgrr.php"] [unique_id "amuFt8637Arlr6Yb1EfzhgAAAMw"]
[Thu Jul 30 12:11:19.963764 2026] [security2:error] [pid 703393:tid 703617] [client 20.63.98.115:21056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/as.php"] [unique_id "amuFt8637Arlr6Yb1EfzhwAAAOM"]
[Thu Jul 30 12:11:20.022705 2026] [security2:error] [pid 703393:tid 703543] [client 20.104.18.253:39963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/autoload_classmap.php"] [unique_id "amuFuM637Arlr6Yb1EfziwAAAJk"]
[Thu Jul 30 12:11:20.072357 2026] [lsapi:error] [pid 643253:tid 643370] [remote 102.209.111.62:0] [host flixon.net] Error receiving response: ReceiveResponse: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1009; user ID 1009), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://flixon.net/video/shall-we-dance-vj-junior/
[Thu Jul 30 12:11:20.111993 2026] [core:error] [pid 703393:tid 703630] [client 98.85.223.94:44886] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:11:20.112014 2026] [core:error] [pid 703393:tid 703630] [client 98.85.223.94:44886] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:11:20.141900 2026] [core:notice] [pid 703393:tid 703577] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:20.148059 2026] [security2:error] [pid 703393:tid 703577] [client 103.215.74.26:17662] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFuM637Arlr6Yb1EfzkAAAALs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:20.406024 2026] [security2:error] [pid 703393:tid 703636] [client 20.91.208.34:55044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/domvf.php"] [unique_id "amuFuM637Arlr6Yb1EfzlAAAAPY"]
[Thu Jul 30 12:11:20.406135 2026] [security2:error] [pid 703393:tid 703636] [client 20.91.208.34:55044] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/domvf.php"] [unique_id "amuFuM637Arlr6Yb1EfzlAAAAPY"]
[Thu Jul 30 12:11:20.429872 2026] [security2:error] [pid 703393:tid 703535] [client 191.232.199.39:54087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/07.php"] [unique_id "amuFuM637Arlr6Yb1EfzlQAAAJE"]
[Thu Jul 30 12:11:20.497684 2026] [security2:error] [pid 703393:tid 703549] [client 20.52.125.110:8216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/classwithtostring.php"] [unique_id "amuFuM637Arlr6Yb1EfzmgAAAJ8"]
[Thu Jul 30 12:11:20.501461 2026] [autoindex:error] [pid 703393:tid 703559] [client 98.85.223.94:44888] AH01276: Cannot serve directory /home2/dovdtnte/public_html/rodneyleesmith/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:11:20.578713 2026] [security2:error] [pid 703393:tid 703633] [client 20.52.125.110:14553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/ant.php"] [unique_id "amuFuM637Arlr6Yb1EfzngAAAPM"]
[Thu Jul 30 12:11:20.819226 2026] [security2:error] [pid 703393:tid 703541] [client 2a03:2880:f800:1b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuFuM637Arlr6Yb1EfzkgAAlxA"]
[Thu Jul 30 12:11:20.878024 2026] [core:notice] [pid 703393:tid 703644] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:20.885718 2026] [security2:error] [pid 703393:tid 703644] [client 103.215.74.26:17674] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFuM637Arlr6Yb1EfzoAAAAP4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:21.044662 2026] [security2:error] [pid 703393:tid 703608] [client 20.91.208.34:55069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/yup.php"] [unique_id "amuFuc637Arlr6Yb1EfzpQAAANo"]
[Thu Jul 30 12:11:21.044869 2026] [security2:error] [pid 703393:tid 703608] [client 20.91.208.34:55069] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/yup.php"] [unique_id "amuFuc637Arlr6Yb1EfzpQAAANo"]
[Thu Jul 30 12:11:21.156571 2026] [security2:error] [pid 703393:tid 703570] [client 20.52.125.110:8084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/content.php"] [unique_id "amuFuc637Arlr6Yb1EfzqQAAALQ"]
[Thu Jul 30 12:11:21.597698 2026] [security2:error] [pid 703393:tid 703571] [client 20.226.5.174:28223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/aafewc0k.php"] [unique_id "amuFuc637Arlr6Yb1EfzsgAAALU"]
[Thu Jul 30 12:11:21.680519 2026] [security2:error] [pid 703393:tid 703580] [client 20.52.125.110:14317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/appreciators.php"] [unique_id "amuFuc637Arlr6Yb1EfztAAAAL4"]
[Thu Jul 30 12:11:21.795478 2026] [security2:error] [pid 703393:tid 703614] [client 20.52.125.110:8085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/content.php.suspected"] [unique_id "amuFuc637Arlr6Yb1EfztQAAAOA"]
[Thu Jul 30 12:11:21.917573 2026] [security2:error] [pid 703393:tid 703568] [client 20.91.208.34:24118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/X.php"] [unique_id "amuFuc637Arlr6Yb1EfztgAAALI"]
[Thu Jul 30 12:11:21.917685 2026] [security2:error] [pid 703393:tid 703568] [client 20.91.208.34:24118] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/X.php"] [unique_id "amuFuc637Arlr6Yb1EfztgAAALI"]
[Thu Jul 30 12:11:22.307656 2026] [security2:error] [pid 703393:tid 703581] [client 20.52.125.110:14575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/archive.php"] [unique_id "amuFus637Arlr6Yb1EfzvwAAAL8"]
[Thu Jul 30 12:11:22.331358 2026] [security2:error] [pid 703393:tid 703649] [client 20.52.125.110:8075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/doc.php"] [unique_id "amuFus637Arlr6Yb1EfzwAAAAQM"]
[Thu Jul 30 12:11:22.765860 2026] [security2:error] [pid 703393:tid 703567] [client 20.104.18.253:25737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/bb.php"] [unique_id "amuFus637Arlr6Yb1EfzyQAAALE"]
[Thu Jul 30 12:11:22.940065 2026] [security2:error] [pid 703393:tid 703573] [client 20.52.125.110:8087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/fond.php"] [unique_id "amuFus637Arlr6Yb1EfzzwAAALc"]
[Thu Jul 30 12:11:22.951196 2026] [security2:error] [pid 703393:tid 703591] [client 20.52.125.110:14540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/as.php"] [unique_id "amuFus637Arlr6Yb1Efz0AAAAMk"]
[Thu Jul 30 12:11:23.292882 2026] [core:notice] [pid 703393:tid 703618] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:23.475755 2026] [security2:error] [pid 703393:tid 703595] [client 20.52.125.110:8000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/gkiliuew.php"] [unique_id "amuFu8637Arlr6Yb1Efz2gAAAM0"]
[Thu Jul 30 12:11:23.480177 2026] [security2:error] [pid 703393:tid 703623] [client 191.232.199.39:54108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/dropdown.php"] [unique_id "amuFu8637Arlr6Yb1Efz2wAAAOk"]
[Thu Jul 30 12:11:23.816381 2026] [security2:error] [pid 703393:tid 703583] [client 20.52.125.110:14560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/atomlib.php"] [unique_id "amuFu8637Arlr6Yb1Efz4wAAAME"]
[Thu Jul 30 12:11:23.837786 2026] [security2:error] [pid 703393:tid 703526] [client 20.63.98.115:39090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/x.php"] [unique_id "amuFu8637Arlr6Yb1Efz5AAAAIg"]
[Thu Jul 30 12:11:24.017686 2026] [security2:error] [pid 703393:tid 703612] [client 20.226.5.174:28195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/abcd.php"] [unique_id "amuFvM637Arlr6Yb1Efz5QAAAN4"]
[Thu Jul 30 12:11:24.071159 2026] [security2:error] [pid 703393:tid 703582] [client 20.52.125.110:8100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/iR7SzrsOUEP.php"] [unique_id "amuFvM637Arlr6Yb1Efz5gAAAMA"]
[Thu Jul 30 12:11:24.080517 2026] [security2:error] [pid 703393:tid 703625] [client 20.91.208.34:9999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amuFvM637Arlr6Yb1Efz5wAAAOs"]
[Thu Jul 30 12:11:24.080611 2026] [security2:error] [pid 703393:tid 703625] [client 20.91.208.34:9999] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amuFvM637Arlr6Yb1Efz5wAAAOs"]
[Thu Jul 30 12:11:24.403417 2026] [security2:error] [pid 703393:tid 703475] [remote 216.73.216.152:49487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuFvM637Arlr6Yb1Efz7wAA1FE"]
[Thu Jul 30 12:11:24.662370 2026] [security2:error] [pid 703393:tid 703588] [client 20.52.125.110:8115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/ibkejxnu.php"] [unique_id "amuFvM637Arlr6Yb1Efz8AAAAMY"]
[Thu Jul 30 12:11:25.195692 2026] [security2:error] [pid 703393:tid 703556] [client 191.232.199.39:6863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/.__info.php"] [unique_id "amuFvc637Arlr6Yb1Ef0AAAAAKY"]
[Thu Jul 30 12:11:25.241180 2026] [security2:error] [pid 703393:tid 703550] [client 20.226.5.174:28206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/about.php"] [unique_id "amuFvc637Arlr6Yb1Ef0BQAAAKA"]
[Thu Jul 30 12:11:25.256441 2026] [security2:error] [pid 703393:tid 703543] [client 20.52.125.110:8196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/install.php"] [unique_id "amuFvc637Arlr6Yb1Ef0BgAAAJk"]
[Thu Jul 30 12:11:25.353928 2026] [security2:error] [pid 703393:tid 703617] [client 191.232.199.39:54117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/makeasmtp.php"] [unique_id "amuFvc637Arlr6Yb1Ef0CgAAAOM"]
[Thu Jul 30 12:11:25.420797 2026] [security2:error] [pid 703393:tid 703531] [client 185.191.171.4:27346] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/10/22/fachin-rejeita-pedido-da-pgr-contra-norma-que-amplia-poder-do-tse/"] [unique_id "amuFvc637Arlr6Yb1Ef0CwAAAI0"]
[Thu Jul 30 12:11:25.421015 2026] [security2:error] [pid 703393:tid 703531] [client 185.191.171.4:27346] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/10/22/fachin-rejeita-pedido-da-pgr-contra-norma-que-amplia-poder-do-tse/"] [unique_id "amuFvc637Arlr6Yb1Ef0CwAAAI0"]
[Thu Jul 30 12:11:25.450676 2026] [security2:error] [pid 703393:tid 703585] [client 2a03:2880:f800:43:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuFvM637Arlr6Yb1Efz-gAAw0w"]
[Thu Jul 30 12:11:25.558643 2026] [security2:error] [pid 703393:tid 703564] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFvc637Arlr6Yb1Ef0AwAArlw"]
[Thu Jul 30 12:11:25.593375 2026] [security2:error] [pid 703393:tid 703563] [client 20.52.125.110:14582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/autoload_classmap.php"] [unique_id "amuFvc637Arlr6Yb1Ef0DgAAAK0"]
[Thu Jul 30 12:11:25.861089 2026] [security2:error] [pid 703393:tid 703636] [client 20.63.98.115:65431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/item.php"] [unique_id "amuFvc637Arlr6Yb1Ef0FQAAAPY"]
[Thu Jul 30 12:11:25.962870 2026] [security2:error] [pid 703393:tid 703628] [client 20.52.125.110:8079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/lang-load-role.php"] [unique_id "amuFvc637Arlr6Yb1Ef0FgAAAO4"]
[Thu Jul 30 12:11:25.985862 2026] [security2:error] [pid 703393:tid 703631] [client 20.91.208.34:58590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/gec.php"] [unique_id "amuFvc637Arlr6Yb1Ef0FwAAAPE"]
[Thu Jul 30 12:11:25.985950 2026] [security2:error] [pid 703393:tid 703631] [client 20.91.208.34:58590] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/gec.php"] [unique_id "amuFvc637Arlr6Yb1Ef0FwAAAPE"]
[Thu Jul 30 12:11:26.155525 2026] [security2:error] [pid 703393:tid 703596] [client 20.104.18.253:42523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/bnm.php"] [unique_id "amuFvs637Arlr6Yb1Ef0GgAAAM4"]
[Thu Jul 30 12:11:26.357881 2026] [security2:error] [pid 703393:tid 703537] [client 20.226.5.174:28204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/admin.php"] [unique_id "amuFvs637Arlr6Yb1Ef0HgAAAJM"]
[Thu Jul 30 12:11:26.479749 2026] [security2:error] [pid 703393:tid 703562] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFvs637Arlr6Yb1Ef0GQAArGE"], referer: https://www.spececigarette.com/wp-content/plugins/storeman/README.txt
[Thu Jul 30 12:11:26.563532 2026] [security2:error] [pid 703393:tid 703551] [client 20.52.125.110:8487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/link.php"] [unique_id "amuFvs637Arlr6Yb1Ef0IgAAAKE"]
[Thu Jul 30 12:11:26.617340 2026] [security2:error] [pid 703393:tid 703637] [client 191.232.199.39:54104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/wp-sigunq.php"] [unique_id "amuFvs637Arlr6Yb1Ef0JAAAAPc"]
[Thu Jul 30 12:11:26.630715 2026] [core:notice] [pid 703393:tid 703534] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:26.637703 2026] [security2:error] [pid 703393:tid 703534] [client 103.215.74.26:4906] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFvs637Arlr6Yb1Ef0JQAAAJA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:26.860201 2026] [security2:error] [pid 703393:tid 703490] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/floating-icons/readme.txt"] [unique_id "amuFvs637Arlr6Yb1Ef0KwAApGA"]
[Thu Jul 30 12:11:27.238364 2026] [security2:error] [pid 703393:tid 703648] [client 20.63.98.115:21069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/app.php"] [unique_id "amuFv8637Arlr6Yb1Ef0MwAAAQI"]
[Thu Jul 30 12:11:27.244149 2026] [security2:error] [pid 703393:tid 703593] [client 20.52.125.110:8081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/mar.php"] [unique_id "amuFv8637Arlr6Yb1Ef0NAAAAMs"]
[Thu Jul 30 12:11:27.383788 2026] [core:notice] [pid 703393:tid 703645] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:27.390298 2026] [security2:error] [pid 703393:tid 703645] [client 103.215.74.26:4922] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFv8637Arlr6Yb1Ef0OgAAAP8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:27.481273 2026] [security2:error] [pid 703393:tid 703614] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFv8637Arlr6Yb1Ef0MAAA4HU"]
[Thu Jul 30 12:11:27.513706 2026] [security2:error] [pid 703393:tid 703579] [client 191.232.199.39:6859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/0.php"] [unique_id "amuFv8637Arlr6Yb1Ef0PAAAAL0"]
[Thu Jul 30 12:11:27.880607 2026] [security2:error] [pid 703393:tid 703536] [client 20.52.125.110:8031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "amuFv8637Arlr6Yb1Ef0RgAAAJI"]
[Thu Jul 30 12:11:27.931030 2026] [security2:error] [pid 703393:tid 703567] [client 20.91.208.34:22690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/sky.php"] [unique_id "amuFv8637Arlr6Yb1Ef0RwAAALE"]
[Thu Jul 30 12:11:27.931138 2026] [security2:error] [pid 703393:tid 703567] [client 20.91.208.34:22690] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/sky.php"] [unique_id "amuFv8637Arlr6Yb1Ef0RwAAALE"]
[Thu Jul 30 12:11:27.948096 2026] [security2:error] [pid 703393:tid 703611] [client 191.232.199.39:54107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/wso112233.php"] [unique_id "amuFv8637Arlr6Yb1Ef0SAAAAN0"]
[Thu Jul 30 12:11:28.168107 2026] [security2:error] [pid 703393:tid 703643] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFv8637Arlr6Yb1Ef0PwAA_QQ"], referer: https://www.spececigarette.com/wp-content/plugins/floating-icons/Readme.txt
[Thu Jul 30 12:11:28.285158 2026] [security2:error] [pid 703393:tid 703580] [client 20.226.5.174:28168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/adminfuns.php"] [unique_id "amuFwM637Arlr6Yb1Ef0TQAAAL4"]
[Thu Jul 30 12:11:28.290143 2026] [proxy:error] [pid 703393:tid 703573] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:11:28.290221 2026] [proxy_http:error] [pid 703393:tid 703573] [client 94.154.43.229:63240] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:11:28.290799 2026] [proxy:error] [pid 703393:tid 703573] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:11:28.290841 2026] [proxy_http:error] [pid 703393:tid 703573] [client 94.154.43.229:63240] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:11:28.494495 2026] [security2:error] [pid 703393:tid 703586] [client 20.52.125.110:8469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "amuFwM637Arlr6Yb1Ef0VgAAAMQ"]
[Thu Jul 30 12:11:28.594222 2026] [security2:error] [pid 703393:tid 703546] [client 74.7.244.17:38368] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "mail.jpm.tqa.temporary.site"] [uri "/robots.txt"] [unique_id "amuFwM637Arlr6Yb1Ef0VwAAAJw"]
[Thu Jul 30 12:11:28.678313 2026] [security2:error] [pid 703393:tid 703631] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFwM637Arlr6Yb1Ef0UgAA8Xw"]
[Thu Jul 30 12:11:28.744096 2026] [core:notice] [pid 703393:tid 703589] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:28.789411 2026] [security2:error] [pid 703393:tid 703532] [client 191.232.199.39:6858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/07.php"] [unique_id "amuFwM637Arlr6Yb1Ef0WgAAAI4"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Thu Jul 30 12:11:28.833605 2026] [security2:error] [pid 703393:tid 703562] [client 74.7.244.17:38368] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.jpm.tqa.temporary.site"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "amuFwM637Arlr6Yb1Ef0WwAAAKw"], referer: https://mail.jpm.tqa.temporary.site/robots.txt
[Thu Jul 30 12:11:28.862168 2026] [security2:error] [pid 703393:tid 703566] [client 20.91.208.34:55097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/fffm.php"] [unique_id "amuFwM637Arlr6Yb1Ef0YAAAALA"]
[Thu Jul 30 12:11:28.862265 2026] [security2:error] [pid 703393:tid 703566] [client 20.91.208.34:55097] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/fffm.php"] [unique_id "amuFwM637Arlr6Yb1Ef0YAAAALA"]
[Thu Jul 30 12:11:28.863315 2026] [security2:error] [pid 703393:tid 703595] [client 35.221.246.130:35438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ahk.tqa.temporary.site"] [uri "/index.php"] [unique_id "amuFvs637Arlr6Yb1Ef0KgAAAM0"]
[Thu Jul 30 12:11:28.863355 2026] [security2:error] [pid 703393:tid 703595] [client 35.221.246.130:35438] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.ahk.tqa.temporary.site"] [uri "/index.php"] [unique_id "amuFvs637Arlr6Yb1Ef0KgAAAM0"]
[Thu Jul 30 12:11:28.935738 2026] [security2:error] [pid 703393:tid 703621] [client 20.52.125.110:14554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/bb.php"] [unique_id "amuFwM637Arlr6Yb1Ef0ZAAAAOc"]
[Thu Jul 30 12:11:28.988597 2026] [security2:error] [pid 703393:tid 703551] [client 20.52.125.110:8080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/plugins.php"] [unique_id "amuFwM637Arlr6Yb1Ef0ZQAAAKE"]
[Thu Jul 30 12:11:29.210081 2026] [security2:error] [pid 703393:tid 703540] [client 191.232.199.39:54020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/alfanew.php"] [unique_id "amuFwc637Arlr6Yb1Ef0ZwAAAJY"]
[Thu Jul 30 12:11:29.432181 2026] [security2:error] [pid 703393:tid 703554] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFwM637Arlr6Yb1Ef0ZgAApAE"], referer: https://www.spececigarette.com/wp-content/plugins/floating-icons/README.txt
[Thu Jul 30 12:11:29.509708 2026] [security2:error] [pid 703393:tid 703402] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/saber-commerce/readme.txt"] [unique_id "amuFwc637Arlr6Yb1Ef0bwAAhwg"]
[Thu Jul 30 12:11:29.511352 2026] [security2:error] [pid 703393:tid 703624] [client 20.52.125.110:8095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/post.php"] [unique_id "amuFwc637Arlr6Yb1Ef0cAAAAOo"]
[Thu Jul 30 12:11:29.609897 2026] [security2:error] [pid 703393:tid 703645] [client 20.91.208.34:22692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/sixxis.php"] [unique_id "amuFwc637Arlr6Yb1Ef0cQAAAP8"]
[Thu Jul 30 12:11:29.610020 2026] [security2:error] [pid 703393:tid 703645] [client 20.91.208.34:22692] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/sixxis.php"] [unique_id "amuFwc637Arlr6Yb1Ef0cQAAAP8"]
[Thu Jul 30 12:11:29.621999 2026] [security2:error] [pid 703393:tid 703571] [client 20.226.5.174:27872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/albin.php"] [unique_id "amuFwc637Arlr6Yb1Ef0cgAAALU"]
[Thu Jul 30 12:11:29.776931 2026] [security2:error] [pid 703393:tid 703626] [client 20.63.98.115:42994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/k.php"] [unique_id "amuFwc637Arlr6Yb1Ef0dQAAAOw"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Thu Jul 30 12:11:29.948542 2026] [security2:error] [pid 703393:tid 703572] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFwc637Arlr6Yb1Ef0cwAAthQ"]
[Thu Jul 30 12:11:30.192971 2026] [security2:error] [pid 703393:tid 703529] [client 20.91.208.34:24122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/yj09.php"] [unique_id "amuFws637Arlr6Yb1Ef0gAAAAIs"]
[Thu Jul 30 12:11:30.193094 2026] [security2:error] [pid 703393:tid 703529] [client 20.91.208.34:24122] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/yj09.php"] [unique_id "amuFws637Arlr6Yb1Ef0gAAAAIs"]
[Thu Jul 30 12:11:30.198149 2026] [security2:error] [pid 703393:tid 703630] [client 20.52.125.110:8479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/shell.php"] [unique_id "amuFws637Arlr6Yb1Ef0gQAAAPA"]
[Thu Jul 30 12:11:30.331481 2026] [security2:error] [pid 703393:tid 703564] [client 20.52.125.110:14533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/bnm.php"] [unique_id "amuFws637Arlr6Yb1Ef0iQAAAK4"]
[Thu Jul 30 12:11:30.515402 2026] [security2:error] [pid 703393:tid 703563] [client 43.154.250.181:47990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.250.154.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/theme/darm_theme_basic01/page_html/privacy.php"] [unique_id "amuFws637Arlr6Yb1Ef0hgAAAK0"]
[Thu Jul 30 12:11:30.616315 2026] [security2:error] [pid 703393:tid 703608] [client 20.91.208.34:22715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/k.php"] [unique_id "amuFws637Arlr6Yb1Ef0lAAAANo"]
[Thu Jul 30 12:11:30.616447 2026] [security2:error] [pid 703393:tid 703608] [client 20.91.208.34:22715] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/k.php"] [unique_id "amuFws637Arlr6Yb1Ef0lAAAANo"]
[Thu Jul 30 12:11:30.722756 2026] [security2:error] [pid 703393:tid 703585] [client 191.232.199.39:54096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/fw.php"] [unique_id "amuFws637Arlr6Yb1Ef0lwAAAMM"]
[Thu Jul 30 12:11:30.869593 2026] [security2:error] [pid 703393:tid 703590] [client 20.52.125.110:14590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/bootstrap.php"] [unique_id "amuFws637Arlr6Yb1Ef0mgAAAMg"]
[Thu Jul 30 12:11:30.879679 2026] [security2:error] [pid 703393:tid 703638] [client 20.52.125.110:8126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/ssl.php"] [unique_id "amuFws637Arlr6Yb1Ef0mwAAAPg"]
[Thu Jul 30 12:11:31.080616 2026] [security2:error] [pid 703393:tid 703582] [client 20.104.18.253:30149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/bootstrap.php"] [unique_id "amuFw8637Arlr6Yb1Ef0pAAAAMA"]
[Thu Jul 30 12:11:31.091637 2026] [security2:error] [pid 703393:tid 703642] [client 20.91.208.34:58572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/k2.php"] [unique_id "amuFw8637Arlr6Yb1Ef0pQAAAPw"]
[Thu Jul 30 12:11:31.091737 2026] [security2:error] [pid 703393:tid 703642] [client 20.91.208.34:58572] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/k2.php"] [unique_id "amuFw8637Arlr6Yb1Ef0pQAAAPw"]
[Thu Jul 30 12:11:31.258889 2026] [security2:error] [pid 703393:tid 703596] [client 20.226.5.174:27897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/amfsqvgv.php"] [unique_id "amuFw8637Arlr6Yb1Ef0qQAAAM4"]
[Thu Jul 30 12:11:31.307538 2026] [security2:error] [pid 703393:tid 703643] [client 182.239.122.251:4200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shop-kent.com"] [uri "/index.php"] [unique_id "amuFws637Arlr6Yb1Ef0jgAA_SM"]
[Thu Jul 30 12:11:31.361883 2026] [security2:error] [pid 703393:tid 703643] [client 182.239.122.251:4200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shop-kent.com"] [uri "/index.php"] [unique_id "amuFws637Arlr6Yb1Ef0jwAA_RE"]
[Thu Jul 30 12:11:31.452787 2026] [security2:error] [pid 703393:tid 703632] [client 20.52.125.110:8509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/sx.php"] [unique_id "amuFw8637Arlr6Yb1Ef0uwAAAPI"]
[Thu Jul 30 12:11:31.482159 2026] [security2:error] [pid 703393:tid 703615] [client 20.52.125.110:14591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/buy.php"] [unique_id "amuFw8637Arlr6Yb1Ef0vgAAAOE"]
[Thu Jul 30 12:11:31.659661 2026] [security2:error] [pid 703393:tid 703530] [client 191.232.199.39:6878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/dropdown.php"] [unique_id "amuFw8637Arlr6Yb1Ef02wAAAIw"]
[Thu Jul 30 12:11:31.755924 2026] [security2:error] [pid 703393:tid 703542] [client 20.63.98.115:61378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-fmfile.php"] [unique_id "amuFw8637Arlr6Yb1Ef03gAAAJg"]
[Thu Jul 30 12:11:31.960298 2026] [security2:error] [pid 703393:tid 703527] [client 20.52.125.110:8233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/themes.php"] [unique_id "amuFw8637Arlr6Yb1Ef05wAAAIk"]
[Thu Jul 30 12:11:31.995462 2026] [security2:error] [pid 703393:tid 703611] [client 20.104.18.253:41083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/buy.php"] [unique_id "amuFw8637Arlr6Yb1Ef06QAAAN0"]
[Thu Jul 30 12:11:32.064775 2026] [security2:error] [pid 703393:tid 703619] [client 20.91.208.34:10040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/w.php"] [unique_id "amuFxM637Arlr6Yb1Ef07wAAAOU"]
[Thu Jul 30 12:11:32.064920 2026] [security2:error] [pid 703393:tid 703619] [client 20.91.208.34:10040] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/w.php"] [unique_id "amuFxM637Arlr6Yb1Ef07wAAAOU"]
[Thu Jul 30 12:11:32.104821 2026] [security2:error] [pid 703393:tid 703650] [client 2a03:2880:f800:3f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuFw8637Arlr6Yb1Ef0ugABBDk"]
[Thu Jul 30 12:11:32.248950 2026] [security2:error] [pid 703393:tid 703477] [remote 97.74.93.24:51154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dov.dtn.temporary.site"] [uri "/wp-login.php"] [unique_id "amuFxM637Arlr6Yb1Ef09AAA7lM"]
[Thu Jul 30 12:11:32.546581 2026] [security2:error] [pid 703393:tid 703597] [client 20.52.125.110:8249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/worksec.php"] [unique_id "amuFxM637Arlr6Yb1Ef0-wAAAM8"]
[Thu Jul 30 12:11:32.656756 2026] [security2:error] [pid 703393:tid 703638] [client 20.226.5.174:27856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/ant.php"] [unique_id "amuFxM637Arlr6Yb1Ef0_wAAAPg"]
[Thu Jul 30 12:11:32.714823 2026] [security2:error] [pid 703393:tid 703629] [client 20.63.98.115:60280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wi.php"] [unique_id "amuFxM637Arlr6Yb1Ef1AAAAAO8"]
[Thu Jul 30 12:11:33.104783 2026] [core:notice] [pid 703393:tid 703538] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:33.111595 2026] [security2:error] [pid 703393:tid 703538] [client 103.215.74.26:48958] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFxc637Arlr6Yb1Ef1BwAAAJQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:33.120536 2026] [security2:error] [pid 703393:tid 703639] [client 20.52.125.110:8098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/wp-admin/install.php"] [unique_id "amuFxc637Arlr6Yb1Ef1CQAAAPk"]
[Thu Jul 30 12:11:33.127698 2026] [security2:error] [pid 703393:tid 703601] [client 57.141.0.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuFxM637Arlr6Yb1Ef09wAAANM"]
[Thu Jul 30 12:11:33.184446 2026] [security2:error] [pid 703393:tid 703600] [client 20.52.125.110:14529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/chosen.php"] [unique_id "amuFxc637Arlr6Yb1Ef1DQAAANI"]
[Thu Jul 30 12:11:33.294086 2026] [security2:error] [pid 703393:tid 703553] [client 191.232.199.39:6857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/makeasmtp.php"] [unique_id "amuFxc637Arlr6Yb1Ef1DgAAAKM"]
[Thu Jul 30 12:11:33.637808 2026] [core:notice] [pid 703393:tid 703627] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:33.789195 2026] [security2:error] [pid 703393:tid 703572] [client 20.63.98.115:44109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/php8.php"] [unique_id "amuFxc637Arlr6Yb1Ef1GQAAALY"]
[Thu Jul 30 12:11:33.893967 2026] [core:notice] [pid 703393:tid 703536] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:33.900425 2026] [security2:error] [pid 703393:tid 703536] [client 103.215.74.26:48970] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFxc637Arlr6Yb1Ef1GgAAAJI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:33.946912 2026] [security2:error] [pid 703393:tid 703557] [client 20.52.125.110:14282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/class-wp-image.php"] [unique_id "amuFxc637Arlr6Yb1Ef1GwAAAKc"]
[Thu Jul 30 12:11:34.175683 2026] [security2:error] [pid 703393:tid 703618] [client 20.91.208.34:22703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/fpwch.php"] [unique_id "amuFxs637Arlr6Yb1Ef1IAAAAOQ"]
[Thu Jul 30 12:11:34.175824 2026] [security2:error] [pid 703393:tid 703618] [client 20.91.208.34:22703] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/fpwch.php"] [unique_id "amuFxs637Arlr6Yb1Ef1IAAAAOQ"]
[Thu Jul 30 12:11:34.424077 2026] [security2:error] [pid 703393:tid 703564] [client 20.226.5.174:27844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/appreciators.php"] [unique_id "amuFxs637Arlr6Yb1Ef1KAAAAK4"]
[Thu Jul 30 12:11:34.645410 2026] [core:notice] [pid 703393:tid 703631] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:34.651511 2026] [security2:error] [pid 703393:tid 703631] [client 103.215.74.26:48982] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFxs637Arlr6Yb1Ef1LAAAAPE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:34.714379 2026] [security2:error] [pid 703393:tid 703636] [client 191.232.199.39:6869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-sigunq.php"] [unique_id "amuFxs637Arlr6Yb1Ef1LQAAAPY"]
[Thu Jul 30 12:11:34.797691 2026] [security2:error] [pid 703393:tid 703597] [client 20.104.18.253:42510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/chosen.php"] [unique_id "amuFxs637Arlr6Yb1Ef1MgAAAM8"]
[Thu Jul 30 12:11:34.806248 2026] [security2:error] [pid 703393:tid 703585] [client 191.232.199.39:54140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/wp-login.php"] [unique_id "amuFxs637Arlr6Yb1Ef1MQAAAMM"]
[Thu Jul 30 12:11:35.038028 2026] [security2:error] [pid 703393:tid 703623] [client 20.63.98.115:20600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/tes.php"] [unique_id "amuFx8637Arlr6Yb1Ef1MwAAAOk"]
[Thu Jul 30 12:11:35.084554 2026] [security2:error] [pid 703393:tid 703544] [client 20.52.125.110:14548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/classsmtps.php"] [unique_id "amuFx8637Arlr6Yb1Ef1NAAAAJo"]
[Thu Jul 30 12:11:35.403459 2026] [core:notice] [pid 703393:tid 703648] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:35.410101 2026] [security2:error] [pid 703393:tid 703648] [client 103.215.74.26:48984] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFx8637Arlr6Yb1Ef1PQAAAQI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:35.498414 2026] [security2:error] [pid 703393:tid 703601] [client 20.52.125.110:8472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "amuFx8637Arlr6Yb1Ef1PgAAANM"]
[Thu Jul 30 12:11:35.535396 2026] [security2:error] [pid 703393:tid 703632] [client 20.91.208.34:24098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/w2025.php"] [unique_id "amuFx8637Arlr6Yb1Ef1PwAAAPI"]
[Thu Jul 30 12:11:35.535537 2026] [security2:error] [pid 703393:tid 703632] [client 20.91.208.34:24098] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/w2025.php"] [unique_id "amuFx8637Arlr6Yb1Ef1PwAAAPI"]
[Thu Jul 30 12:11:35.601111 2026] [security2:error] [pid 703393:tid 703626] [client 20.104.18.253:32992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/class-wp-image.php"] [unique_id "amuFx8637Arlr6Yb1Ef1QAAAAOw"]
[Thu Jul 30 12:11:35.641564 2026] [security2:error] [pid 703393:tid 703624] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFx8637Arlr6Yb1Ef1OAAA6mU"], referer: https://www.spececigarette.com/wp-content/plugins/saber-commerce/Readme.txt
[Thu Jul 30 12:11:35.779789 2026] [security2:error] [pid 703393:tid 703643] [client 20.52.125.110:14918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/classwithtostring.php"] [unique_id "amuFx8637Arlr6Yb1Ef1RwAAAP0"]
[Thu Jul 30 12:11:35.976959 2026] [security2:error] [pid 703393:tid 703525] [client 20.226.5.174:27979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/archive.php"] [unique_id "amuFx8637Arlr6Yb1Ef1TAAAAIc"]
[Thu Jul 30 12:11:36.125710 2026] [core:notice] [pid 703393:tid 703609] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:36.132527 2026] [security2:error] [pid 703393:tid 703609] [client 103.215.74.26:48994] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFyM637Arlr6Yb1Ef1TwAAANs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:36.164541 2026] [security2:error] [pid 703393:tid 703496] [remote 57.141.0.54:54078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/626900273/feed/rss2/"] [unique_id "amuFyM637Arlr6Yb1Ef1UAAAsWY"]
[Thu Jul 30 12:11:36.205736 2026] [security2:error] [pid 703393:tid 703555] [client 20.63.98.115:20597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/about.php"] [unique_id "amuFyM637Arlr6Yb1Ef1UgAAAKU"]
[Thu Jul 30 12:11:36.358404 2026] [core:error] [pid 703393:tid 703536] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:11:36.358429 2026] [core:error] [pid 703393:tid 703536] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:11:36.380704 2026] [security2:error] [pid 703393:tid 703641] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFyM637Arlr6Yb1Ef1TQAA-18"]
[Thu Jul 30 12:11:36.472616 2026] [security2:error] [pid 703393:tid 703629] [client 2a03:2880:f800:39:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuFx8637Arlr6Yb1Ef1SAAA72w"]
[Thu Jul 30 12:11:36.478181 2026] [security2:error] [pid 703393:tid 703565] [client 20.52.125.110:14289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/config.php"] [unique_id "amuFyM637Arlr6Yb1Ef1WgAAAK8"]
[Thu Jul 30 12:11:36.908722 2026] [security2:error] [pid 703393:tid 703532] [client 20.91.208.34:58578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/FWAZ.php"] [unique_id "amuFyM637Arlr6Yb1Ef1YgAAAI4"]
[Thu Jul 30 12:11:36.908843 2026] [security2:error] [pid 703393:tid 703532] [client 20.91.208.34:58578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/FWAZ.php"] [unique_id "amuFyM637Arlr6Yb1Ef1YgAAAI4"]
[Thu Jul 30 12:11:37.054447 2026] [security2:error] [pid 703393:tid 703611] [client 20.104.18.253:41089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/classsmtps.php"] [unique_id "amuFyc637Arlr6Yb1Ef1ZQAAAN0"]
[Thu Jul 30 12:11:37.205032 2026] [security2:error] [pid 703393:tid 703631] [client 89.238.167.166:43404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuFyc637Arlr6Yb1Ef1ZgAAAPE"]
[Thu Jul 30 12:11:37.205162 2026] [security2:error] [pid 703393:tid 703631] [client 89.238.167.166:43404] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuFyc637Arlr6Yb1Ef1ZgAAAPE"]
[Thu Jul 30 12:11:37.225612 2026] [security2:error] [pid 703393:tid 703584] [client 57.141.0.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuFyM637Arlr6Yb1Ef1XQAAAMI"]
[Thu Jul 30 12:11:37.407700 2026] [security2:error] [pid 703393:tid 703592] [client 20.91.208.34:55075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/qterm.php"] [unique_id "amuFyc637Arlr6Yb1Ef1agAAAMo"]
[Thu Jul 30 12:11:37.407807 2026] [security2:error] [pid 703393:tid 703592] [client 20.91.208.34:55075] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/qterm.php"] [unique_id "amuFyc637Arlr6Yb1Ef1agAAAMo"]
[Thu Jul 30 12:11:37.786659 2026] [security2:error] [pid 703393:tid 703571] [client 20.91.208.34:55076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/blurbs.php"] [unique_id "amuFyc637Arlr6Yb1Ef1dgAAALU"]
[Thu Jul 30 12:11:37.786746 2026] [security2:error] [pid 703393:tid 703571] [client 20.91.208.34:55076] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/blurbs.php"] [unique_id "amuFyc637Arlr6Yb1Ef1dgAAALU"]
[Thu Jul 30 12:11:37.972793 2026] [security2:error] [pid 703393:tid 703523] [client 20.104.18.253:31191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/classwithtostring.php"] [unique_id "amuFyc637Arlr6Yb1Ef1ewAAAIU"]
[Thu Jul 30 12:11:38.404606 2026] [security2:error] [pid 703393:tid 703600] [client 20.91.208.34:55087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/wp-ws68.php"] [unique_id "amuFys637Arlr6Yb1Ef1gAAAANI"]
[Thu Jul 30 12:11:38.404717 2026] [security2:error] [pid 703393:tid 703600] [client 20.91.208.34:55087] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/wp-ws68.php"] [unique_id "amuFys637Arlr6Yb1Ef1gAAAANI"]
[Thu Jul 30 12:11:38.501335 2026] [security2:error] [pid 703393:tid 703606] [client 20.52.125.110:14541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/core.php"] [unique_id "amuFys637Arlr6Yb1Ef1hAAAANg"]
[Thu Jul 30 12:11:38.749432 2026] [security2:error] [pid 703393:tid 703511] [remote 250.49.135.140:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuFys637Arlr6Yb1Ef1fAAAoHU"]
[Thu Jul 30 12:11:38.749660 2026] [security2:error] [pid 703393:tid 703550] [client 250.49.135.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuFys637Arlr6Yb1Ef1fAAAoHU"]
[Thu Jul 30 12:11:38.837196 2026] [security2:error] [pid 703393:tid 703580] [client 20.91.208.34:58621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/xyn.php"] [unique_id "amuFys637Arlr6Yb1Ef1iAAAAL4"]
[Thu Jul 30 12:11:38.837275 2026] [security2:error] [pid 703393:tid 703580] [client 20.91.208.34:58621] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/xyn.php"] [unique_id "amuFys637Arlr6Yb1Ef1iAAAAL4"]
[Thu Jul 30 12:11:38.950480 2026] [security2:error] [pid 703393:tid 703649] [client 20.63.98.115:44146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/headers.php"] [unique_id "amuFys637Arlr6Yb1Ef1iwAAAQM"]
[Thu Jul 30 12:11:39.129537 2026] [security2:error] [pid 703393:tid 703577] [client 20.104.18.253:42535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/config.php"] [unique_id "amuFy8637Arlr6Yb1Ef1jwAAALs"]
[Thu Jul 30 12:11:39.240616 2026] [security2:error] [pid 703393:tid 703567] [client 213.163.206.91:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuFys637Arlr6Yb1Ef1iQAAALE"]
[Thu Jul 30 12:11:39.324356 2026] [security2:error] [pid 703393:tid 703564] [client 20.226.5.174:28231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/as.php"] [unique_id "amuFy8637Arlr6Yb1Ef1kwAAAK4"]
[Thu Jul 30 12:11:39.336713 2026] [security2:error] [pid 703393:tid 703650] [client 20.91.208.34:56128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/ccc.php"] [unique_id "amuFy8637Arlr6Yb1Ef1lAAAAQQ"]
[Thu Jul 30 12:11:39.336799 2026] [security2:error] [pid 703393:tid 703650] [client 20.91.208.34:56128] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/ccc.php"] [unique_id "amuFy8637Arlr6Yb1Ef1lAAAAQQ"]
[Thu Jul 30 12:11:39.373249 2026] [security2:error] [pid 703393:tid 703603] [client 191.232.199.39:54111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/simple.php"] [unique_id "amuFy8637Arlr6Yb1Ef1lQAAANU"]
[Thu Jul 30 12:11:39.486597 2026] [core:notice] [pid 703393:tid 703517] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:39.803038 2026] [security2:error] [pid 703393:tid 703637] [client 20.52.125.110:14278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/css.php"] [unique_id "amuFy8637Arlr6Yb1Ef1oAAAAPc"]
[Thu Jul 30 12:11:39.925509 2026] [security2:error] [pid 703393:tid 703595] [client 20.91.208.34:10017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/get.php"] [unique_id "amuFy8637Arlr6Yb1Ef1pAAAAM0"]
[Thu Jul 30 12:11:39.925612 2026] [security2:error] [pid 703393:tid 703595] [client 20.91.208.34:10017] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/get.php"] [unique_id "amuFy8637Arlr6Yb1Ef1pAAAAM0"]
[Thu Jul 30 12:11:40.101891 2026] [security2:error] [pid 703393:tid 703533] [client 20.104.18.253:36809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/core.php"] [unique_id "amuFzM637Arlr6Yb1Ef1qAAAAI8"]
[Thu Jul 30 12:11:40.437628 2026] [security2:error] [pid 703393:tid 703596] [client 20.91.208.34:55103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/images.php"] [unique_id "amuFzM637Arlr6Yb1Ef1rAAAAM4"]
[Thu Jul 30 12:11:40.437770 2026] [security2:error] [pid 703393:tid 703596] [client 20.91.208.34:55103] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/images.php"] [unique_id "amuFzM637Arlr6Yb1Ef1rAAAAM4"]
[Thu Jul 30 12:11:40.618591 2026] [security2:error] [pid 703393:tid 703568] [client 20.226.5.174:28233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/atomlib.php"] [unique_id "amuFzM637Arlr6Yb1Ef1sgAAALI"]
[Thu Jul 30 12:11:40.765067 2026] [security2:error] [pid 703393:tid 703594] [client 213.163.206.91:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuFzM637Arlr6Yb1Ef1rQAAAMw"]
[Thu Jul 30 12:11:40.851400 2026] [security2:error] [pid 703393:tid 703624] [client 20.91.208.34:55086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/alls.php"] [unique_id "amuFzM637Arlr6Yb1Ef1tQAAAOo"]
[Thu Jul 30 12:11:40.851503 2026] [security2:error] [pid 703393:tid 703624] [client 20.91.208.34:55086] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/alls.php"] [unique_id "amuFzM637Arlr6Yb1Ef1tQAAAOo"]
[Thu Jul 30 12:11:41.494386 2026] [security2:error] [pid 703393:tid 703649] [client 20.91.208.34:24096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/coffexium.php"] [unique_id "amuFzc637Arlr6Yb1Ef1vwAAAQM"]
[Thu Jul 30 12:11:41.494505 2026] [security2:error] [pid 703393:tid 703649] [client 20.91.208.34:24096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/coffexium.php"] [unique_id "amuFzc637Arlr6Yb1Ef1vwAAAQM"]
[Thu Jul 30 12:11:41.684408 2026] [security2:error] [pid 703393:tid 703643] [client 20.226.5.174:28248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/autoload_classmap.php"] [unique_id "amuFzc637Arlr6Yb1Ef1xQAAAP0"]
[Thu Jul 30 12:11:41.760461 2026] [security2:error] [pid 703393:tid 703639] [client 191.232.199.39:54081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/classsmtps.php"] [unique_id "amuFzc637Arlr6Yb1Ef1xgAAAPk"]
[Thu Jul 30 12:11:41.862146 2026] [core:notice] [pid 703393:tid 703641] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:41.869266 2026] [security2:error] [pid 703393:tid 703641] [client 103.215.74.26:49006] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFzc637Arlr6Yb1Ef1xwAAAPs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:42.060684 2026] [security2:error] [pid 703393:tid 703578] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFzc637Arlr6Yb1Ef1xAAAvH8"], referer: https://www.spececigarette.com/wp-content/plugins/saber-commerce/README.txt
[Thu Jul 30 12:11:42.174600 2026] [security2:error] [pid 703393:tid 703537] [client 20.91.208.34:10044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/red.php"] [unique_id "amuFzs637Arlr6Yb1Ef1zgAAAJM"]
[Thu Jul 30 12:11:42.174710 2026] [security2:error] [pid 703393:tid 703537] [client 20.91.208.34:10044] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/red.php"] [unique_id "amuFzs637Arlr6Yb1Ef1zgAAAJM"]
[Thu Jul 30 12:11:42.472815 2026] [security2:error] [pid 703393:tid 703426] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/sellbery/readme.txt"] [unique_id "amuFzs637Arlr6Yb1Ef11QAA7iA"]
[Thu Jul 30 12:11:42.611838 2026] [core:notice] [pid 703393:tid 703607] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:42.618689 2026] [security2:error] [pid 703393:tid 703607] [client 103.215.74.26:49018] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFzs637Arlr6Yb1Ef11gAAANk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:42.759163 2026] [security2:error] [pid 703393:tid 703622] [client 20.226.5.174:28234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/bb.php"] [unique_id "amuFzs637Arlr6Yb1Ef12wAAAOg"]
[Thu Jul 30 12:11:42.993923 2026] [security2:error] [pid 703393:tid 703583] [client 20.63.98.115:65416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/admin.php"] [unique_id "amuFzs637Arlr6Yb1Ef13wAAAME"]
[Thu Jul 30 12:11:43.028101 2026] [security2:error] [pid 703393:tid 703548] [client 20.91.208.34:58608] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "alshateeintl.com"] [uri "/cgi-sys/404.html"] [unique_id "amuFz8637Arlr6Yb1Ef14AAAAJ4"]
[Thu Jul 30 12:11:43.060738 2026] [security2:error] [pid 703393:tid 703642] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFzs637Arlr6Yb1Ef12gAA_H0"]
[Thu Jul 30 12:11:43.186407 2026] [security2:error] [pid 703393:tid 703588] [client 20.91.208.34:58608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amuFz8637Arlr6Yb1Ef14gAAAMY"]
[Thu Jul 30 12:11:43.186533 2026] [security2:error] [pid 703393:tid 703588] [client 20.91.208.34:58608] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amuFz8637Arlr6Yb1Ef14gAAAMY"]
[Thu Jul 30 12:11:43.371208 2026] [core:notice] [pid 703393:tid 703562] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:43.377899 2026] [security2:error] [pid 703393:tid 703562] [client 103.215.74.26:32958] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFz8637Arlr6Yb1Ef15gAAAKw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:43.845055 2026] [security2:error] [pid 703393:tid 703646] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFz8637Arlr6Yb1Ef15wABAHY"], referer: https://www.spececigarette.com/wp-content/plugins/sellbery/Readme.txt
[Thu Jul 30 12:11:43.885840 2026] [security2:error] [pid 703393:tid 703584] [client 20.52.125.110:14581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/database.php"] [unique_id "amuFz8637Arlr6Yb1Ef18QAAAMI"]
[Thu Jul 30 12:11:44.011377 2026] [security2:error] [pid 703393:tid 703606] [client 20.91.208.34:22699] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "alshateeintl.com"] [uri "/cgi-sys/404.html"] [unique_id "amuF0M637Arlr6Yb1Ef19QAAANg"]
[Thu Jul 30 12:11:44.090942 2026] [core:notice] [pid 703393:tid 703535] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:44.098207 2026] [security2:error] [pid 703393:tid 703535] [client 103.215.74.26:32972] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF0M637Arlr6Yb1Ef19wAAAJE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:44.120145 2026] [security2:error] [pid 703393:tid 703648] [client 20.63.98.115:20734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/flower.php"] [unique_id "amuF0M637Arlr6Yb1Ef1-AAAAQI"]
[Thu Jul 30 12:11:44.173792 2026] [security2:error] [pid 703393:tid 703529] [client 20.91.208.34:22699] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "alshateeintl.com"] [uri "/cgi-sys/404.html"] [unique_id "amuF0M637Arlr6Yb1Ef1-QAAAIs"]
[Thu Jul 30 12:11:44.255834 2026] [security2:error] [pid 703393:tid 703563] [client 191.232.199.39:6892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wso112233.php"] [unique_id "amuF0M637Arlr6Yb1Ef1-gAAAK0"]
[Thu Jul 30 12:11:44.328469 2026] [security2:error] [pid 703393:tid 703573] [client 20.91.208.34:22699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/wp-content/index.php"] [unique_id "amuF0M637Arlr6Yb1Ef1_gAAALc"]
[Thu Jul 30 12:11:44.328576 2026] [security2:error] [pid 703393:tid 703573] [client 20.91.208.34:22699] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/wp-content/index.php"] [unique_id "amuF0M637Arlr6Yb1Ef1_gAAALc"]
[Thu Jul 30 12:11:44.332686 2026] [security2:error] [pid 703393:tid 703605] [client 20.226.5.174:28265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/bnm.php"] [unique_id "amuF0M637Arlr6Yb1Ef1_wAAANc"]
[Thu Jul 30 12:11:44.356522 2026] [security2:error] [pid 703393:tid 703604] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuF0M637Arlr6Yb1Ef19gAA1hY"]
[Thu Jul 30 12:11:44.538699 2026] [security2:error] [pid 703393:tid 703568] [client 191.232.199.39:54112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/wp-blog-header.php"] [unique_id "amuF0M637Arlr6Yb1Ef2BgAAALI"]
[Thu Jul 30 12:11:44.754616 2026] [security2:error] [pid 703393:tid 703643] [client 20.52.125.110:14550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/db.php"] [unique_id "amuF0M637Arlr6Yb1Ef2CAAAAP0"]
[Thu Jul 30 12:11:44.857882 2026] [core:notice] [pid 703393:tid 703546] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:44.865199 2026] [security2:error] [pid 703393:tid 703546] [client 103.215.74.26:32974] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF0M637Arlr6Yb1Ef2DQAAAJw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:45.112650 2026] [security2:error] [pid 703393:tid 703575] [client 20.91.208.34:22683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/admin.php"] [unique_id "amuF0c637Arlr6Yb1Ef2EQAAALk"]
[Thu Jul 30 12:11:45.112751 2026] [security2:error] [pid 703393:tid 703575] [client 20.91.208.34:22683] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/admin.php"] [unique_id "amuF0c637Arlr6Yb1Ef2EQAAALk"]
[Thu Jul 30 12:11:45.122079 2026] [security2:error] [pid 703393:tid 703507] [remote 65.181.111.156:49562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.111.181.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-login.php"] [unique_id "amuF0c637Arlr6Yb1Ef2EgAA2nE"]
[Thu Jul 30 12:11:45.241204 2026] [security2:error] [pid 703393:tid 703650] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuF0M637Arlr6Yb1Ef2DAABBBk"], referer: https://www.spececigarette.com/wp-content/plugins/sellbery/README.txt
[Thu Jul 30 12:11:45.337466 2026] [security2:error] [pid 703393:tid 703443] [remote 175.157.35.242:34875] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/etc/httpd/modsecurity.d/01_asl_content.conf"] [line "64"] [id "391213"] [msg "Atomicorp.com WAF Rules: Request content type is not allowed by policy"] [data "application/http.wbxml"] [severity "WARNING"] [hostname "mail.nimna.lk"] [uri "/outlookgatewayb2/hxservice/getiploc"] [unique_id "amuF0c637Arlr6Yb1Ef2FgAAwzE"]
[Thu Jul 30 12:11:45.342621 2026] [core:error] [pid 703393:tid 703423] [remote 175.157.35.242:22054] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:11:45.342644 2026] [core:error] [pid 703393:tid 703423] [remote 175.157.35.242:22054] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:11:45.405848 2026] [security2:error] [pid 703393:tid 703439] [remote 175.157.35.242:34875] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/etc/httpd/modsecurity.d/01_asl_content.conf"] [line "64"] [id "391213"] [msg "Atomicorp.com WAF Rules: Request content type is not allowed by policy"] [data "application/http.wbxml"] [severity "WARNING"] [hostname "mail.nimna.lk"] [uri "/outlookgatewayb2/hxservice/getiploc"] [unique_id "amuF0c637Arlr6Yb1Ef2GgAA_i0"]
[Thu Jul 30 12:11:45.452384 2026] [security2:error] [pid 703393:tid 703447] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/jetpack/readme.txt"] [unique_id "amuF0c637Arlr6Yb1Ef2GwAApDU"]
[Thu Jul 30 12:11:45.473325 2026] [security2:error] [pid 703393:tid 703400] [remote 175.157.35.242:34875] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/etc/httpd/modsecurity.d/01_asl_content.conf"] [line "64"] [id "391213"] [msg "Atomicorp.com WAF Rules: Request content type is not allowed by policy"] [data "application/http.wbxml"] [severity "WARNING"] [hostname "mail.nimna.lk"] [uri "/outlookgatewayb2/hxservice/getiploc"] [unique_id "amuF0c637Arlr6Yb1Ef2HAAA9gY"]
[Thu Jul 30 12:11:45.537244 2026] [security2:error] [pid 703393:tid 703422] [remote 175.157.35.242:34875] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/etc/httpd/modsecurity.d/01_asl_content.conf"] [line "64"] [id "391213"] [msg "Atomicorp.com WAF Rules: Request content type is not allowed by policy"] [data "application/http.wbxml"] [severity "WARNING"] [hostname "mail.nimna.lk"] [uri "/outlookgatewayb2/hxservice/getiploc"] [unique_id "amuF0c637Arlr6Yb1Ef2IAAAlBw"]
[Thu Jul 30 12:11:45.842233 2026] [security2:error] [pid 703393:tid 703611] [client 191.232.199.39:6881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/alfanew.php"] [unique_id "amuF0c637Arlr6Yb1Ef2IgAAAN0"]
[Thu Jul 30 12:11:45.942186 2026] [security2:error] [pid 703393:tid 703588] [client 191.232.199.39:51798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/wp-trackback.php"] [unique_id "amuF0c637Arlr6Yb1Ef2JgAAAMY"]
[Thu Jul 30 12:11:46.074341 2026] [security2:error] [pid 703393:tid 703571] [client 20.104.18.253:45746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/css.php"] [unique_id "amuF0s637Arlr6Yb1Ef2KAAAALU"]
[Thu Jul 30 12:11:46.423162 2026] [security2:error] [pid 703393:tid 703607] [client 20.226.5.174:27981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/bootstrap.php"] [unique_id "amuF0s637Arlr6Yb1Ef2LgAAANk"]
[Thu Jul 30 12:11:46.815489 2026] [security2:error] [pid 703393:tid 703591] [client 20.91.208.34:55080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/177.php"] [unique_id "amuF0s637Arlr6Yb1Ef2NQAAAMk"]
[Thu Jul 30 12:11:46.815601 2026] [security2:error] [pid 703393:tid 703591] [client 20.91.208.34:55080] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/177.php"] [unique_id "amuF0s637Arlr6Yb1Ef2NQAAAMk"]
[Thu Jul 30 12:11:46.964517 2026] [security2:error] [pid 703393:tid 703579] [client 57.141.0.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuF0s637Arlr6Yb1Ef2LQAAAL0"]
[Thu Jul 30 12:11:47.042765 2026] [core:error] [pid 703393:tid 703457] [remote 175.157.35.242:22054] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:11:47.042809 2026] [core:error] [pid 703393:tid 703457] [remote 175.157.35.242:22054] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:11:47.071711 2026] [security2:error] [pid 703393:tid 703573] [client 191.232.199.39:6855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/fw.php"] [unique_id "amuF08637Arlr6Yb1Ef2PQAAALc"]
[Thu Jul 30 12:11:47.904942 2026] [security2:error] [pid 703393:tid 703553] [client 20.52.125.110:14283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/default.php"] [unique_id "amuF08637Arlr6Yb1Ef2RAAAAKM"]
[Thu Jul 30 12:11:47.952022 2026] [security2:error] [pid 703393:tid 703546] [client 20.91.208.34:22710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/199.php"] [unique_id "amuF08637Arlr6Yb1Ef2RQAAAJw"]
[Thu Jul 30 12:11:47.952116 2026] [security2:error] [pid 703393:tid 703546] [client 20.91.208.34:22710] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/199.php"] [unique_id "amuF08637Arlr6Yb1Ef2RQAAAJw"]
[Thu Jul 30 12:11:48.111964 2026] [security2:error] [pid 703393:tid 703545] [client 20.226.5.174:27790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/buy.php"] [unique_id "amuF1M637Arlr6Yb1Ef2TAAAAJs"]
[Thu Jul 30 12:11:48.452377 2026] [security2:error] [pid 703393:tid 703589] [client 191.232.199.39:6867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-login.php"] [unique_id "amuF1M637Arlr6Yb1Ef2TQAAAMc"]
[Thu Jul 30 12:11:48.543871 2026] [security2:error] [pid 703393:tid 703649] [client 20.63.98.115:21393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "amuF1M637Arlr6Yb1Ef2UAAAAQM"]
[Thu Jul 30 12:11:48.649257 2026] [security2:error] [pid 703393:tid 703568] [client 20.104.18.253:45825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/database.php"] [unique_id "amuF1M637Arlr6Yb1Ef2VgAAALI"]
[Thu Jul 30 12:11:48.715940 2026] [security2:error] [pid 703393:tid 703587] [client 20.91.208.34:55041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/file52.php"] [unique_id "amuF1M637Arlr6Yb1Ef2VwAAAMU"]
[Thu Jul 30 12:11:48.716102 2026] [security2:error] [pid 703393:tid 703587] [client 20.91.208.34:55041] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/file52.php"] [unique_id "amuF1M637Arlr6Yb1Ef2VwAAAMU"]
[Thu Jul 30 12:11:48.933805 2026] [security2:error] [pid 703393:tid 703640] [client 20.52.125.110:14564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/dropdown.php"] [unique_id "amuF1M637Arlr6Yb1Ef2WAAAAPo"]
[Thu Jul 30 12:11:49.350010 2026] [security2:error] [pid 703393:tid 703544] [client 20.226.5.174:27813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/chosen.php"] [unique_id "amuF1c637Arlr6Yb1Ef2XwAAAJo"]
[Thu Jul 30 12:11:49.771352 2026] [security2:error] [pid 703393:tid 703625] [client 20.52.125.110:14583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/edit.php"] [unique_id "amuF1c637Arlr6Yb1Ef2aQAAAOs"]
[Thu Jul 30 12:11:50.053440 2026] [security2:error] [pid 703393:tid 703636] [client 191.232.199.39:54089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/wp-signup.php"] [unique_id "amuF1s637Arlr6Yb1Ef2agAAAPY"]
[Thu Jul 30 12:11:50.135270 2026] [security2:error] [pid 703393:tid 703615] [client 20.63.98.115:65432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content.php"] [unique_id "amuF1s637Arlr6Yb1Ef2awAAAOE"]
[Thu Jul 30 12:11:50.276393 2026] [security2:error] [pid 703393:tid 703594] [client 20.104.18.253:54810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/db.php"] [unique_id "amuF1s637Arlr6Yb1Ef2dgAAAMw"]
[Thu Jul 30 12:11:50.357083 2026] [security2:error] [pid 703393:tid 703563] [client 20.226.5.174:28236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/class-wp-image.php"] [unique_id "amuF1s637Arlr6Yb1Ef2dwAAAK0"]
[Thu Jul 30 12:11:50.392429 2026] [security2:error] [pid 703393:tid 703525] [client 20.52.125.110:14537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/f35.php"] [unique_id "amuF1s637Arlr6Yb1Ef2eAAAAIc"]
[Thu Jul 30 12:11:50.655018 2026] [core:notice] [pid 703393:tid 703573] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:50.661533 2026] [security2:error] [pid 703393:tid 703573] [client 103.215.74.26:32978] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF1s637Arlr6Yb1Ef2egAAALc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:50.957923 2026] [proxy:error] [pid 703393:tid 703448] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:11:50.957995 2026] [proxy_http:error] [pid 703393:tid 703448] [remote 74.7.175.147:51390] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:11:50.958672 2026] [proxy:error] [pid 703393:tid 703448] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:11:50.958716 2026] [proxy_http:error] [pid 703393:tid 703448] [remote 74.7.175.147:51390] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:11:51.173616 2026] [security2:error] [pid 703393:tid 703619] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuF1s637Arlr6Yb1Ef2gQAA5UU"]
[Thu Jul 30 12:11:51.392355 2026] [core:notice] [pid 703393:tid 703628] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:51.398724 2026] [security2:error] [pid 703393:tid 703628] [client 103.215.74.26:32984] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF18637Arlr6Yb1Ef2igAAAO4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:51.405919 2026] [security2:error] [pid 703393:tid 703545] [client 20.226.5.174:27793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/classsmtps.php"] [unique_id "amuF18637Arlr6Yb1Ef2iwAAAJs"]
[Thu Jul 30 12:11:51.633430 2026] [security2:error] [pid 703393:tid 703595] [client 20.52.125.110:14536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/f7.php"] [unique_id "amuF18637Arlr6Yb1Ef2jgAAAM0"]
[Thu Jul 30 12:11:51.689357 2026] [security2:error] [pid 703393:tid 703592] [client 20.104.18.253:26323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/default.php"] [unique_id "amuF18637Arlr6Yb1Ef2kQAAAMo"]
[Thu Jul 30 12:11:51.721407 2026] [core:error] [pid 703393:tid 703562] [client 191.96.227.82:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://airevoduct.ltd/
[Thu Jul 30 12:11:51.721431 2026] [core:error] [pid 703393:tid 703562] [client 191.96.227.82:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://airevoduct.ltd/
[Thu Jul 30 12:11:51.740828 2026] [security2:error] [pid 703393:tid 703566] [client 20.63.98.115:20569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/function.php"] [unique_id "amuF18637Arlr6Yb1Ef2mQAAALA"]
[Thu Jul 30 12:11:51.923281 2026] [security2:error] [pid 703393:tid 703469] [remote 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuF18637Arlr6Yb1Ef2jQAAsks"], referer: https://www.spececigarette.com/wp-content/plugins/jetpack/Readme.txt
[Thu Jul 30 12:11:52.111633 2026] [security2:error] [pid 703393:tid 703598] [client 2a03:2880:f800:27:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuF18637Arlr6Yb1Ef2jAAA0AI"]
[Thu Jul 30 12:11:52.122948 2026] [core:notice] [pid 703393:tid 703543] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:52.129530 2026] [security2:error] [pid 703393:tid 703543] [client 103.215.74.26:32992] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF2M637Arlr6Yb1Ef2nQAAAJk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:52.199202 2026] [security2:error] [pid 703393:tid 703540] [client 191.232.199.39:54132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/wp-comments-post.php"] [unique_id "amuF2M637Arlr6Yb1Ef2nwAAAJY"]
[Thu Jul 30 12:11:52.252282 2026] [security2:error] [pid 703393:tid 703648] [client 20.91.208.34:10046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/geck.php"] [unique_id "amuF2M637Arlr6Yb1Ef2owAAAQI"]
[Thu Jul 30 12:11:52.252416 2026] [security2:error] [pid 703393:tid 703648] [client 20.91.208.34:10046] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/geck.php"] [unique_id "amuF2M637Arlr6Yb1Ef2owAAAQI"]
[Thu Jul 30 12:11:52.446855 2026] [security2:error] [pid 703393:tid 703571] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuF2M637Arlr6Yb1Ef2ngAAtUc"]
[Thu Jul 30 12:11:52.453951 2026] [security2:error] [pid 703393:tid 703584] [client 20.226.5.174:27789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/classwithtostring.php"] [unique_id "amuF2M637Arlr6Yb1Ef2qAAAAMI"]
[Thu Jul 30 12:11:52.768470 2026] [security2:error] [pid 703393:tid 703591] [client 20.104.18.253:54819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/dropdown.php"] [unique_id "amuF2M637Arlr6Yb1Ef2qwAAAMk"]
[Thu Jul 30 12:11:52.895403 2026] [core:notice] [pid 703393:tid 703549] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:52.902786 2026] [security2:error] [pid 703393:tid 703549] [client 103.215.74.26:33002] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF2M637Arlr6Yb1Ef2swAAAJ8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:52.959449 2026] [security2:error] [pid 703393:tid 703524] [client 20.91.208.34:58610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/biufile.php"] [unique_id "amuF2M637Arlr6Yb1Ef2tAAAAIY"]
[Thu Jul 30 12:11:52.959566 2026] [security2:error] [pid 703393:tid 703524] [client 20.91.208.34:58610] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/biufile.php"] [unique_id "amuF2M637Arlr6Yb1Ef2tAAAAIY"]
[Thu Jul 30 12:11:53.192851 2026] [security2:error] [pid 703393:tid 703528] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuF2M637Arlr6Yb1Ef2rAAAikg"], referer: https://www.spececigarette.com/wp-content/plugins/jetpack/README.txt
[Thu Jul 30 12:11:53.592494 2026] [security2:error] [pid 703393:tid 703630] [client 20.104.18.253:26064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/edit.php"] [unique_id "amuF2c637Arlr6Yb1Ef2xAAAAPA"]
[Thu Jul 30 12:11:53.625832 2026] [security2:error] [pid 703393:tid 703534] [client 20.226.5.174:28109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/config.php"] [unique_id "amuF2c637Arlr6Yb1Ef2xQAAAJA"]
[Thu Jul 30 12:11:53.636235 2026] [core:notice] [pid 703393:tid 703532] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:53.642551 2026] [security2:error] [pid 703393:tid 703532] [client 103.215.74.26:17402] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF2c637Arlr6Yb1Ef2xgAAAI4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:53.785096 2026] [security2:error] [pid 703393:tid 703575] [client 74.7.230.6:35660] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-e66db2d4.sby.gzj.temporary.site"] [uri "/robots.txt"] [unique_id "amuF2c637Arlr6Yb1Ef2xwAAALk"]
[Thu Jul 30 12:11:53.842963 2026] [security2:error] [pid 703393:tid 703495] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/deepcore/readme.txt"] [unique_id "amuF2c637Arlr6Yb1Ef2zQABA2U"]
[Thu Jul 30 12:11:54.047863 2026] [security2:error] [pid 703393:tid 703523] [client 20.91.208.34:58613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/dejavu.php"] [unique_id "amuF2s637Arlr6Yb1Ef20wAAAIU"]
[Thu Jul 30 12:11:54.047966 2026] [security2:error] [pid 703393:tid 703523] [client 20.91.208.34:58613] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/dejavu.php"] [unique_id "amuF2s637Arlr6Yb1Ef20wAAAIU"]
[Thu Jul 30 12:11:54.315244 2026] [security2:error] [pid 703393:tid 703538] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuF2c637Arlr6Yb1Ef2zgAAlEw"]
[Thu Jul 30 12:11:54.355062 2026] [security2:error] [pid 703393:tid 703622] [client 20.104.18.253:30542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/f35.php"] [unique_id "amuF2s637Arlr6Yb1Ef22QAAAOg"]
[Thu Jul 30 12:11:54.752830 2026] [security2:error] [pid 703393:tid 703625] [client 20.91.208.34:55073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/aaf.php"] [unique_id "amuF2s637Arlr6Yb1Ef27wAAAOs"]
[Thu Jul 30 12:11:54.753010 2026] [security2:error] [pid 703393:tid 703625] [client 20.91.208.34:55073] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/aaf.php"] [unique_id "amuF2s637Arlr6Yb1Ef27wAAAOs"]
[Thu Jul 30 12:11:54.939170 2026] [security2:error] [pid 703393:tid 703581] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuF2s637Arlr6Yb1Ef24AAAv18"], referer: https://www.spececigarette.com/wp-content/plugins/deepcore/Readme.txt
[Thu Jul 30 12:11:55.176457 2026] [security2:error] [pid 703393:tid 703564] [client 20.104.18.253:26063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/f7.php"] [unique_id "amuF28637Arlr6Yb1Ef2-gAAAK4"]
[Thu Jul 30 12:11:55.210322 2026] [security2:error] [pid 703393:tid 703604] [client 20.63.98.115:21413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/chosen.php"] [unique_id "amuF28637Arlr6Yb1Ef2-wAAANY"]
[Thu Jul 30 12:11:55.254404 2026] [security2:error] [pid 703393:tid 703590] [client 20.203.156.12:33785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/anonsec.php"] [unique_id "amuF28637Arlr6Yb1Ef2_AAAAMg"]
[Thu Jul 30 12:11:55.254534 2026] [security2:error] [pid 703393:tid 703590] [client 20.203.156.12:33785] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/anonsec.php"] [unique_id "amuF28637Arlr6Yb1Ef2_AAAAMg"]
[Thu Jul 30 12:11:55.373354 2026] [security2:error] [pid 703393:tid 703634] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuF28637Arlr6Yb1Ef29wAA9Go"]
[Thu Jul 30 12:11:55.485484 2026] [security2:error] [pid 703393:tid 703548] [client 20.91.208.34:10043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/ha.php"] [unique_id "amuF28637Arlr6Yb1Ef3BAAAAJ4"]
[Thu Jul 30 12:11:55.485623 2026] [security2:error] [pid 703393:tid 703548] [client 20.91.208.34:10043] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/ha.php"] [unique_id "amuF28637Arlr6Yb1Ef3BAAAAJ4"]
[Thu Jul 30 12:11:55.710717 2026] [security2:error] [pid 703393:tid 703636] [client 20.226.5.174:28127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/core.php"] [unique_id "amuF28637Arlr6Yb1Ef3BwAAAPY"]
[Thu Jul 30 12:11:56.025189 2026] [security2:error] [pid 703393:tid 703624] [client 191.232.199.39:6895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/simple.php"] [unique_id "amuF3M637Arlr6Yb1Ef3DwAAAOo"]
[Thu Jul 30 12:11:56.129587 2026] [security2:error] [pid 703393:tid 703574] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuF28637Arlr6Yb1Ef3BgAAuHU"], referer: https://www.spececigarette.com/wp-content/plugins/deepcore/README.txt
[Thu Jul 30 12:11:56.178771 2026] [security2:error] [pid 703393:tid 703561] [client 146.190.89.220:34966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuF28637Arlr6Yb1Ef3CAAAAKs"], referer: https://dlr.djb.temporary.site/
[Thu Jul 30 12:11:57.033675 2026] [security2:error] [pid 703393:tid 703588] [client 146.190.89.220:34982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuF3M637Arlr6Yb1Ef3IQAAAMY"], referer: https://dlr.djb.temporary.site/
[Thu Jul 30 12:11:57.238050 2026] [security2:error] [pid 703393:tid 703591] [client 191.232.199.39:60748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/classsmtps.php"] [unique_id "amuF3c637Arlr6Yb1Ef3LQAAAMk"]
[Thu Jul 30 12:11:57.264992 2026] [security2:error] [pid 703393:tid 703631] [client 20.91.208.34:24086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/hur.php"] [unique_id "amuF3c637Arlr6Yb1Ef3LgAAAPE"]
[Thu Jul 30 12:11:57.265129 2026] [security2:error] [pid 703393:tid 703631] [client 20.91.208.34:24086] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/hur.php"] [unique_id "amuF3c637Arlr6Yb1Ef3LgAAAPE"]
[Thu Jul 30 12:11:57.609213 2026] [security2:error] [pid 703393:tid 703532] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuF3c637Arlr6Yb1Ef3OQAAAI4"]
[Thu Jul 30 12:11:57.609347 2026] [security2:error] [pid 703393:tid 703532] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuF3c637Arlr6Yb1Ef3OQAAAI4"]
[Thu Jul 30 12:11:57.709138 2026] [security2:error] [pid 703393:tid 703557] [client 191.232.199.39:54110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/wp-mail.php"] [unique_id "amuF3c637Arlr6Yb1Ef3PQAAAKc"]
[Thu Jul 30 12:11:57.748904 2026] [security2:error] [pid 703393:tid 703553] [client 85.208.96.195:52588] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/05/25/joao-inaugura-obras-e-participa-de-plenaria-do-orcamento-democratico-no-sertao/"] [unique_id "amuF3c637Arlr6Yb1Ef3PgAAAKM"]
[Thu Jul 30 12:11:57.749113 2026] [security2:error] [pid 703393:tid 703553] [client 85.208.96.195:52588] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/05/25/joao-inaugura-obras-e-participa-de-plenaria-do-orcamento-democratico-no-sertao/"] [unique_id "amuF3c637Arlr6Yb1Ef3PgAAAKM"]
[Thu Jul 30 12:11:58.106010 2026] [security2:error] [pid 703393:tid 703600] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuF3s637Arlr6Yb1Ef3RwAAANI"]
[Thu Jul 30 12:11:58.106152 2026] [security2:error] [pid 703393:tid 703600] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuF3s637Arlr6Yb1Ef3RwAAANI"]
[Thu Jul 30 12:11:58.632162 2026] [security2:error] [pid 703393:tid 703630] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wicked.php"] [unique_id "amuF3s637Arlr6Yb1Ef3VAAAAPA"]
[Thu Jul 30 12:11:58.632313 2026] [security2:error] [pid 703393:tid 703630] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wicked.php"] [unique_id "amuF3s637Arlr6Yb1Ef3VAAAAPA"]
[Thu Jul 30 12:11:59.015230 2026] [security2:error] [pid 703393:tid 703526] [client 20.91.208.34:58619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/h02ugyh.php"] [unique_id "amuF38637Arlr6Yb1Ef3WQAAAIg"]
[Thu Jul 30 12:11:59.015370 2026] [security2:error] [pid 703393:tid 703526] [client 20.91.208.34:58619] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/h02ugyh.php"] [unique_id "amuF38637Arlr6Yb1Ef3WQAAAIg"]
[Thu Jul 30 12:11:59.067753 2026] [security2:error] [pid 703393:tid 703589] [client 20.226.5.174:28096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/css.php"] [unique_id "amuF38637Arlr6Yb1Ef3WgAAAMc"]
[Thu Jul 30 12:11:59.155225 2026] [security2:error] [pid 703393:tid 703601] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wpx.php"] [unique_id "amuF38637Arlr6Yb1Ef3XgAAANM"]
[Thu Jul 30 12:11:59.155341 2026] [security2:error] [pid 703393:tid 703601] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wpx.php"] [unique_id "amuF38637Arlr6Yb1Ef3XgAAANM"]
[Thu Jul 30 12:11:59.360557 2026] [core:notice] [pid 703393:tid 703523] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:59.368072 2026] [security2:error] [pid 703393:tid 703523] [client 103.215.74.26:17412] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF38637Arlr6Yb1Ef3YgAAAIU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:59.491997 2026] [security2:error] [pid 703393:tid 703568] [client 20.91.208.34:58579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/155.php"] [unique_id "amuF38637Arlr6Yb1Ef3YwAAALI"]
[Thu Jul 30 12:11:59.492107 2026] [security2:error] [pid 703393:tid 703568] [client 20.91.208.34:58579] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/155.php"] [unique_id "amuF38637Arlr6Yb1Ef3YwAAALI"]
[Thu Jul 30 12:11:59.694775 2026] [security2:error] [pid 703393:tid 703529] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/images.php"] [unique_id "amuF38637Arlr6Yb1Ef3aQAAAIs"]
[Thu Jul 30 12:11:59.694872 2026] [security2:error] [pid 703393:tid 703529] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/images.php"] [unique_id "amuF38637Arlr6Yb1Ef3aQAAAIs"]
[Thu Jul 30 12:12:00.091171 2026] [security2:error] [pid 703393:tid 703619] [client 20.91.208.34:24088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/ops.php"] [unique_id "amuF4M637Arlr6Yb1Ef3bAAAAOU"]
[Thu Jul 30 12:12:00.091268 2026] [security2:error] [pid 703393:tid 703619] [client 20.91.208.34:24088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/ops.php"] [unique_id "amuF4M637Arlr6Yb1Ef3bAAAAOU"]
[Thu Jul 30 12:12:00.114278 2026] [core:notice] [pid 703393:tid 703607] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:00.120991 2026] [security2:error] [pid 703393:tid 703607] [client 103.215.74.26:17420] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF4M637Arlr6Yb1Ef3bQAAANk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:00.174035 2026] [security2:error] [pid 703393:tid 703598] [client 191.232.199.39:54101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/wp-activate.php"] [unique_id "amuF4M637Arlr6Yb1Ef3bwAAANA"]
[Thu Jul 30 12:12:00.210411 2026] [security2:error] [pid 703393:tid 703550] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/1xmomo.php"] [unique_id "amuF4M637Arlr6Yb1Ef3dQAAAKA"]
[Thu Jul 30 12:12:00.210516 2026] [security2:error] [pid 703393:tid 703550] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/1xmomo.php"] [unique_id "amuF4M637Arlr6Yb1Ef3dQAAAKA"]
[Thu Jul 30 12:12:00.493106 2026] [security2:error] [pid 703393:tid 703628] [client 20.91.208.34:10006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/ingfo.php"] [unique_id "amuF4M637Arlr6Yb1Ef3eQAAAO4"]
[Thu Jul 30 12:12:00.493200 2026] [security2:error] [pid 703393:tid 703628] [client 20.91.208.34:10006] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/ingfo.php"] [unique_id "amuF4M637Arlr6Yb1Ef3eQAAAO4"]
[Thu Jul 30 12:12:00.718281 2026] [security2:error] [pid 703393:tid 703613] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/1revo.php"] [unique_id "amuF4M637Arlr6Yb1Ef3fQAAAN8"]
[Thu Jul 30 12:12:00.718413 2026] [security2:error] [pid 703393:tid 703613] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/1revo.php"] [unique_id "amuF4M637Arlr6Yb1Ef3fQAAAN8"]
[Thu Jul 30 12:12:00.780092 2026] [security2:error] [pid 703393:tid 703576] [client 20.226.5.174:28108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/database.php"] [unique_id "amuF4M637Arlr6Yb1Ef3gQAAALo"]
[Thu Jul 30 12:12:00.860688 2026] [core:notice] [pid 703393:tid 703612] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:00.867760 2026] [security2:error] [pid 703393:tid 703612] [client 103.215.74.26:17428] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF4M637Arlr6Yb1Ef3ggAAAN4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:00.963396 2026] [security2:error] [pid 703393:tid 703533] [client 20.63.98.115:20862] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "jesus.claims"] [uri "/1.php"] [unique_id "amuF4M637Arlr6Yb1Ef3gwAAAI8"]
[Thu Jul 30 12:12:00.963524 2026] [security2:error] [pid 703393:tid 703533] [client 20.63.98.115:20862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/1.php"] [unique_id "amuF4M637Arlr6Yb1Ef3gwAAAI8"]
[Thu Jul 30 12:12:01.231275 2026] [security2:error] [pid 703393:tid 703622] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/cong.php"] [unique_id "amuF4c637Arlr6Yb1Ef3igAAAOg"]
[Thu Jul 30 12:12:01.231408 2026] [security2:error] [pid 703393:tid 703622] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/cong.php"] [unique_id "amuF4c637Arlr6Yb1Ef3igAAAOg"]
[Thu Jul 30 12:12:01.358278 2026] [security2:error] [pid 703393:tid 703566] [client 191.232.199.39:54094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/post.php"] [unique_id "amuF4c637Arlr6Yb1Ef3jwAAALA"]
[Thu Jul 30 12:12:01.508829 2026] [security2:error] [pid 703393:tid 703428] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/jetpack-search/readme.txt"] [unique_id "amuF4c637Arlr6Yb1Ef3kAAAviI"]
[Thu Jul 30 12:12:01.596725 2026] [core:notice] [pid 703393:tid 703584] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:01.603777 2026] [security2:error] [pid 703393:tid 703584] [client 103.215.74.26:17434] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF4c637Arlr6Yb1Ef3kQAAAMI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:01.736206 2026] [security2:error] [pid 703393:tid 703586] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/a.php"] [unique_id "amuF4c637Arlr6Yb1Ef3kwAAAMQ"]
[Thu Jul 30 12:12:01.736324 2026] [security2:error] [pid 703393:tid 703586] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/a.php"] [unique_id "amuF4c637Arlr6Yb1Ef3kwAAAMQ"]
[Thu Jul 30 12:12:01.940966 2026] [security2:error] [pid 703393:tid 703648] [client 20.63.98.115:36828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/lv.php"] [unique_id "amuF4c637Arlr6Yb1Ef3nQAAAQI"]
[Thu Jul 30 12:12:01.959822 2026] [security2:error] [pid 703393:tid 703620] [client 20.226.5.174:27908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/db.php"] [unique_id "amuF4c637Arlr6Yb1Ef3ngAAAOY"]
[Thu Jul 30 12:12:02.207293 2026] [security2:error] [pid 703393:tid 703639] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuF4c637Arlr6Yb1Ef3mQAA-S0"]
[Thu Jul 30 12:12:02.216805 2026] [security2:error] [pid 703393:tid 703549] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/srontol.php"] [unique_id "amuF4s637Arlr6Yb1Ef3oQAAAJ8"]
[Thu Jul 30 12:12:02.216910 2026] [security2:error] [pid 703393:tid 703549] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/srontol.php"] [unique_id "amuF4s637Arlr6Yb1Ef3oQAAAJ8"]
[Thu Jul 30 12:12:02.349452 2026] [core:notice] [pid 703393:tid 703525] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:02.355933 2026] [security2:error] [pid 703393:tid 703525] [client 103.215.74.26:17438] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF4s637Arlr6Yb1Ef3qAAAAIc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:02.459092 2026] [security2:error] [pid 703393:tid 703623] [client 191.232.199.39:6873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-blog-header.php"] [unique_id "amuF4s637Arlr6Yb1Ef3qQAAAOk"]
[Thu Jul 30 12:12:02.703381 2026] [security2:error] [pid 703393:tid 703560] [client 20.91.208.34:55078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/error_log.php"] [unique_id "amuF4s637Arlr6Yb1Ef3rAAAAKo"]
[Thu Jul 30 12:12:02.703525 2026] [security2:error] [pid 703393:tid 703560] [client 20.91.208.34:55078] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/error_log.php"] [unique_id "amuF4s637Arlr6Yb1Ef3rAAAAKo"]
[Thu Jul 30 12:12:02.707937 2026] [security2:error] [pid 703393:tid 703608] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/reop3.php"] [unique_id "amuF4s637Arlr6Yb1Ef3rQAAANo"]
[Thu Jul 30 12:12:02.708056 2026] [security2:error] [pid 703393:tid 703608] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/reop3.php"] [unique_id "amuF4s637Arlr6Yb1Ef3rQAAANo"]
[Thu Jul 30 12:12:02.715705 2026] [security2:error] [pid 703393:tid 703583] [client 20.63.98.115:32902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/css.php"] [unique_id "amuF4s637Arlr6Yb1Ef3rgAAAME"]
[Thu Jul 30 12:12:02.757204 2026] [security2:error] [pid 703393:tid 703541] [client 191.232.199.39:54116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/wp-2019.php"] [unique_id "amuF4s637Arlr6Yb1Ef3sAAAAJc"]
[Thu Jul 30 12:12:03.086642 2026] [core:notice] [pid 703393:tid 703640] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:03.093436 2026] [security2:error] [pid 703393:tid 703640] [client 103.215.74.26:21654] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF48637Arlr6Yb1Ef3twAAAPo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:03.219897 2026] [security2:error] [pid 703393:tid 703596] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/file5.php"] [unique_id "amuF48637Arlr6Yb1Ef3uQAAAM4"]
[Thu Jul 30 12:12:03.220016 2026] [security2:error] [pid 703393:tid 703596] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/file5.php"] [unique_id "amuF48637Arlr6Yb1Ef3uQAAAM4"]
[Thu Jul 30 12:12:03.259868 2026] [security2:error] [pid 703393:tid 703457] [remote 20.54.134.42:2238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.134.54.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-login.php"] [unique_id "amuF48637Arlr6Yb1Ef3ugAArD8"]
[Thu Jul 30 12:12:03.313945 2026] [security2:error] [pid 703393:tid 703409] [remote 57.141.0.19:21950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/7514146397/feed/rss2/"] [unique_id "amuF48637Arlr6Yb1Ef3uwAA_A8"]
[Thu Jul 30 12:12:03.356679 2026] [security2:error] [pid 703393:tid 703649] [client 20.226.5.174:27966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/default.php"] [unique_id "amuF48637Arlr6Yb1Ef3vwAAAQM"]
[Thu Jul 30 12:12:03.727827 2026] [security2:error] [pid 703393:tid 703609] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/domvf.php"] [unique_id "amuF48637Arlr6Yb1Ef3xAAAANs"]
[Thu Jul 30 12:12:03.727938 2026] [security2:error] [pid 703393:tid 703609] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/domvf.php"] [unique_id "amuF48637Arlr6Yb1Ef3xAAAANs"]
[Thu Jul 30 12:12:03.782751 2026] [security2:error] [pid 703393:tid 703598] [client 185.189.112.11:59580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.112.189.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuF48637Arlr6Yb1Ef3xgAAANA"]
[Thu Jul 30 12:12:03.782841 2026] [security2:error] [pid 703393:tid 703598] [client 185.189.112.11:59580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuF48637Arlr6Yb1Ef3xgAAANA"]
[Thu Jul 30 12:12:03.795842 2026] [security2:error] [pid 703393:tid 703599] [client 191.232.199.39:6882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-trackback.php"] [unique_id "amuF48637Arlr6Yb1Ef3xwAAANE"]
[Thu Jul 30 12:12:03.830591 2026] [core:notice] [pid 703393:tid 703542] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:03.836911 2026] [security2:error] [pid 703393:tid 703542] [client 103.215.74.26:21658] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF48637Arlr6Yb1Ef3yAAAAJg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:03.874359 2026] [security2:error] [pid 703393:tid 703605] [client 20.91.208.34:22662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/koala.php"] [unique_id "amuF48637Arlr6Yb1Ef3ywAAANc"]
[Thu Jul 30 12:12:03.874451 2026] [security2:error] [pid 703393:tid 703605] [client 20.91.208.34:22662] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/koala.php"] [unique_id "amuF48637Arlr6Yb1Ef3ywAAANc"]
[Thu Jul 30 12:12:04.207121 2026] [security2:error] [pid 703393:tid 703590] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/zero.php"] [unique_id "amuF5M637Arlr6Yb1Ef30QAAAMg"]
[Thu Jul 30 12:12:04.207227 2026] [security2:error] [pid 703393:tid 703590] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/zero.php"] [unique_id "amuF5M637Arlr6Yb1Ef30QAAAMg"]
[Thu Jul 30 12:12:04.471025 2026] [security2:error] [pid 703393:tid 703602] [client 20.63.98.115:21200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/gecko.php"] [unique_id "amuF5M637Arlr6Yb1Ef32wAAANQ"]
[Thu Jul 30 12:12:04.490334 2026] [security2:error] [pid 703393:tid 703595] [client 20.91.208.34:22674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/mac.php"] [unique_id "amuF5M637Arlr6Yb1Ef33QAAAM0"]
[Thu Jul 30 12:12:04.490470 2026] [security2:error] [pid 703393:tid 703595] [client 20.91.208.34:22674] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/mac.php"] [unique_id "amuF5M637Arlr6Yb1Ef33QAAAM0"]
[Thu Jul 30 12:12:04.571790 2026] [core:notice] [pid 703393:tid 703604] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:04.578552 2026] [security2:error] [pid 703393:tid 703604] [client 103.215.74.26:21676] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF5M637Arlr6Yb1Ef33gAAANY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:04.717124 2026] [security2:error] [pid 703393:tid 703532] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/002.php"] [unique_id "amuF5M637Arlr6Yb1Ef34AAAAI4"]
[Thu Jul 30 12:12:04.717231 2026] [security2:error] [pid 703393:tid 703532] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/002.php"] [unique_id "amuF5M637Arlr6Yb1Ef34AAAAI4"]
[Thu Jul 30 12:12:04.863553 2026] [security2:error] [pid 703393:tid 703552] [client 20.91.208.34:55051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/wefile.php"] [unique_id "amuF5M637Arlr6Yb1Ef36gAAAKI"]
[Thu Jul 30 12:12:04.863638 2026] [security2:error] [pid 703393:tid 703552] [client 20.91.208.34:55051] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/wefile.php"] [unique_id "amuF5M637Arlr6Yb1Ef36gAAAKI"]
[Thu Jul 30 12:12:04.959868 2026] [security2:error] [pid 703393:tid 703549] [client 191.232.199.39:54133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/hoot.php"] [unique_id "amuF5M637Arlr6Yb1Ef38AAAAJ8"]
[Thu Jul 30 12:12:05.184497 2026] [security2:error] [pid 703393:tid 703557] [client 119.157.28.214:53864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuF5M637Arlr6Yb1Ef37wAAAKc"], referer: https://dlr.djb.temporary.site/
[Thu Jul 30 12:12:05.224129 2026] [security2:error] [pid 703393:tid 703559] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/thoms.php"] [unique_id "amuF5c637Arlr6Yb1Ef39gAAAKk"]
[Thu Jul 30 12:12:05.224297 2026] [security2:error] [pid 703393:tid 703559] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/thoms.php"] [unique_id "amuF5c637Arlr6Yb1Ef39gAAAKk"]
[Thu Jul 30 12:12:05.310532 2026] [core:notice] [pid 703393:tid 703558] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:05.317907 2026] [security2:error] [pid 703393:tid 703558] [client 103.215.74.26:21728] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF5c637Arlr6Yb1Ef39wAAAKg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:05.348591 2026] [security2:error] [pid 703393:tid 703586] [client 20.91.208.34:55102] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "alshateeintl.com"] [uri "/cgi-sys/404.html"] [unique_id "amuF5c637Arlr6Yb1Ef3-QAAAMQ"]
[Thu Jul 30 12:12:05.387087 2026] [security2:error] [pid 703393:tid 703541] [client 191.232.199.39:6875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-signup.php"] [unique_id "amuF5c637Arlr6Yb1Ef3-gAAAJc"]
[Thu Jul 30 12:12:05.494606 2026] [security2:error] [pid 703393:tid 703610] [client 20.226.5.174:28153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/dropdown.php"] [unique_id "amuF5c637Arlr6Yb1Ef3_wAAANw"]
[Thu Jul 30 12:12:05.553305 2026] [security2:error] [pid 703393:tid 703629] [client 20.91.208.34:55102] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "alshateeintl.com"] [uri "/cgi-sys/404.html"] [unique_id "amuF5c637Arlr6Yb1Ef4BAAAAO8"]
[Thu Jul 30 12:12:05.583878 2026] [security2:error] [pid 703393:tid 703627] [client 20.63.98.115:20827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/xmlrpc.php"] [unique_id "amuF5c637Arlr6Yb1Ef3-AAAAO0"]
[Thu Jul 30 12:12:05.707144 2026] [security2:error] [pid 703393:tid 703617] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/fi22.php"] [unique_id "amuF5c637Arlr6Yb1Ef4BQAAAOM"]
[Thu Jul 30 12:12:05.707243 2026] [security2:error] [pid 703393:tid 703617] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/fi22.php"] [unique_id "amuF5c637Arlr6Yb1Ef4BQAAAOM"]
[Thu Jul 30 12:12:05.721260 2026] [security2:error] [pid 703393:tid 703537] [client 20.91.208.34:55102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/makeasmtp.php"] [unique_id "amuF5c637Arlr6Yb1Ef4BgAAAJM"]
[Thu Jul 30 12:12:05.721350 2026] [security2:error] [pid 703393:tid 703537] [client 20.91.208.34:55102] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/makeasmtp.php"] [unique_id "amuF5c637Arlr6Yb1Ef4BgAAAJM"]
[Thu Jul 30 12:12:06.056644 2026] [security2:error] [pid 703393:tid 703552] [client 20.91.208.34:24064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/2P.php"] [unique_id "amuF5s637Arlr6Yb1Ef4FgAAAKI"]
[Thu Jul 30 12:12:06.056732 2026] [security2:error] [pid 703393:tid 703552] [client 20.91.208.34:24064] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/2P.php"] [unique_id "amuF5s637Arlr6Yb1Ef4FgAAAKI"]
[Thu Jul 30 12:12:06.220206 2026] [security2:error] [pid 703393:tid 703620] [client 185.191.171.16:31308] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/02/14/ministro-do-stf-proibe-uso-do-disque-100-para-denuncias-contra-passaporte-da-vacina/"] [unique_id "amuF5s637Arlr6Yb1Ef4HQAAAOY"]
[Thu Jul 30 12:12:06.220312 2026] [security2:error] [pid 703393:tid 703620] [client 185.191.171.16:31308] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/02/14/ministro-do-stf-proibe-uso-do-disque-100-para-denuncias-contra-passaporte-da-vacina/"] [unique_id "amuF5s637Arlr6Yb1Ef4HQAAAOY"]
[Thu Jul 30 12:12:06.414822 2026] [security2:error] [pid 703393:tid 703626] [client 20.91.208.34:9991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/.well-known/about.php"] [unique_id "amuF5s637Arlr6Yb1Ef4IAAAAOw"]
[Thu Jul 30 12:12:06.414927 2026] [security2:error] [pid 703393:tid 703626] [client 20.91.208.34:9991] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/.well-known/about.php"] [unique_id "amuF5s637Arlr6Yb1Ef4IAAAAOw"]
[Thu Jul 30 12:12:06.760411 2026] [security2:error] [pid 703393:tid 703568] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "reviewbyjook.com"] [uri "/index.cgi"] [unique_id "amuF5s637Arlr6Yb1Ef4HAAAALI"]
[Thu Jul 30 12:12:06.830589 2026] [security2:error] [pid 703393:tid 703587] [client 20.63.98.115:32919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/f35.php"] [unique_id "amuF5s637Arlr6Yb1Ef4LAAAAMU"]
[Thu Jul 30 12:12:06.852920 2026] [security2:error] [pid 703393:tid 703607] [client 20.91.208.34:55101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuF5s637Arlr6Yb1Ef4LQAAANk"]
[Thu Jul 30 12:12:06.853045 2026] [security2:error] [pid 703393:tid 703607] [client 20.91.208.34:55101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuF5s637Arlr6Yb1Ef4LQAAANk"]
[Thu Jul 30 12:12:07.031604 2026] [security2:error] [pid 703393:tid 703592] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/82.php"] [unique_id "amuF58637Arlr6Yb1Ef4OgAAAMo"]
[Thu Jul 30 12:12:07.031689 2026] [security2:error] [pid 703393:tid 703592] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/82.php"] [unique_id "amuF58637Arlr6Yb1Ef4OgAAAMo"]
[Thu Jul 30 12:12:07.495686 2026] [security2:error] [pid 703393:tid 703565] [client 20.226.5.174:27924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/edit.php"] [unique_id "amuF58637Arlr6Yb1Ef4SgAAAK8"]
[Thu Jul 30 12:12:07.534881 2026] [security2:error] [pid 703393:tid 703636] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/sx.php"] [unique_id "amuF58637Arlr6Yb1Ef4TgAAAPY"]
[Thu Jul 30 12:12:07.535016 2026] [security2:error] [pid 703393:tid 703636] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/sx.php"] [unique_id "amuF58637Arlr6Yb1Ef4TgAAAPY"]
[Thu Jul 30 12:12:07.583174 2026] [security2:error] [pid 703393:tid 703545] [client 20.91.208.34:24110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/system_log.php"] [unique_id "amuF58637Arlr6Yb1Ef4UAAAAJs"]
[Thu Jul 30 12:12:07.583296 2026] [security2:error] [pid 703393:tid 703545] [client 20.91.208.34:24110] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/system_log.php"] [unique_id "amuF58637Arlr6Yb1Ef4UAAAAJs"]
[Thu Jul 30 12:12:07.702206 2026] [security2:error] [pid 703393:tid 703628] [client 191.232.199.39:6904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-comments-post.php"] [unique_id "amuF58637Arlr6Yb1Ef4XwAAAO4"]
[Thu Jul 30 12:12:07.880970 2026] [security2:error] [pid 703393:tid 703535] [client 191.232.199.39:54121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/log.php"] [unique_id "amuF58637Arlr6Yb1Ef4eQAAAJE"]
[Thu Jul 30 12:12:08.036595 2026] [security2:error] [pid 703393:tid 703521] [remote 208.122.213.225:60874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.213.122.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jgp.fxh.temporary.site"] [uri "/wp-login.php"] [unique_id "amuF6M637Arlr6Yb1Ef4fgAAvn8"]
[Thu Jul 30 12:12:08.047562 2026] [security2:error] [pid 703393:tid 703571] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/dex.php"] [unique_id "amuF6M637Arlr6Yb1Ef4lAAAALU"]
[Thu Jul 30 12:12:08.047644 2026] [security2:error] [pid 703393:tid 703571] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/dex.php"] [unique_id "amuF6M637Arlr6Yb1Ef4lAAAALU"]
[Thu Jul 30 12:12:08.226746 2026] [core:notice] [pid 703393:tid 703419] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:08.446163 2026] [security2:error] [pid 703393:tid 703542] [client 20.91.208.34:24087] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "alshateeintl.com"] [uri "/cgi-sys/404.html"] [unique_id "amuF6M637Arlr6Yb1Ef4owAAAJg"]
[Thu Jul 30 12:12:08.480485 2026] [security2:error] [pid 703393:tid 703551] [client 172.237.109.114:10147] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuF58637Arlr6Yb1Ef4egAAAKE"]
[Thu Jul 30 12:12:08.527120 2026] [security2:error] [pid 703393:tid 703534] [client 20.226.5.174:27956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/f35.php"] [unique_id "amuF6M637Arlr6Yb1Ef4pwAAAJA"]
[Thu Jul 30 12:12:08.582861 2026] [security2:error] [pid 703393:tid 703617] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/fpwch.php"] [unique_id "amuF6M637Arlr6Yb1Ef4qgAAAOM"]
[Thu Jul 30 12:12:08.582960 2026] [security2:error] [pid 703393:tid 703617] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/fpwch.php"] [unique_id "amuF6M637Arlr6Yb1Ef4qgAAAOM"]
[Thu Jul 30 12:12:08.597057 2026] [security2:error] [pid 703393:tid 703644] [client 20.63.98.115:36839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/autoload_classmap.php"] [unique_id "amuF6M637Arlr6Yb1Ef4rQAAAP4"]
[Thu Jul 30 12:12:08.744526 2026] [security2:error] [pid 703393:tid 703623] [client 20.91.208.34:24087] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "alshateeintl.com"] [uri "/cgi-sys/404.html"] [unique_id "amuF6M637Arlr6Yb1Ef4sgAAAOk"]
[Thu Jul 30 12:12:08.950333 2026] [security2:error] [pid 703393:tid 703527] [client 191.232.199.39:60738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-mail.php"] [unique_id "amuF6M637Arlr6Yb1Ef4uQAAAIk"]
[Thu Jul 30 12:12:08.997239 2026] [security2:error] [pid 703393:tid 703614] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuF6M637Arlr6Yb1Ef4qAAA4DU"], referer: https://www.spececigarette.com/wp-content/plugins/jetpack-search/Readme.txt
[Thu Jul 30 12:12:09.113693 2026] [security2:error] [pid 703393:tid 703605] [client 187.208.91.78:47318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuF6M637Arlr6Yb1Ef4tAAAANc"], referer: https://dlr.djb.temporary.site/
[Thu Jul 30 12:12:09.115282 2026] [security2:error] [pid 703393:tid 703606] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/black.php"] [unique_id "amuF6c637Arlr6Yb1Ef4wQAAANg"]
[Thu Jul 30 12:12:09.115376 2026] [security2:error] [pid 703393:tid 703606] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/black.php"] [unique_id "amuF6c637Arlr6Yb1Ef4wQAAANg"]
[Thu Jul 30 12:12:09.121010 2026] [security2:error] [pid 703393:tid 703533] [client 20.91.208.34:24087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/crgio.php"] [unique_id "amuF6c637Arlr6Yb1Ef4wgAAAI8"]
[Thu Jul 30 12:12:09.121107 2026] [security2:error] [pid 703393:tid 703533] [client 20.91.208.34:24087] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/crgio.php"] [unique_id "amuF6c637Arlr6Yb1Ef4wgAAAI8"]
[Thu Jul 30 12:12:09.471354 2026] [security2:error] [pid 703393:tid 703553] [client 191.232.199.39:54113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/bak.php"] [unique_id "amuF6c637Arlr6Yb1Ef40QAAAKM"]
[Thu Jul 30 12:12:09.540943 2026] [security2:error] [pid 703393:tid 703549] [client 172.237.109.114:41359] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuF6M637Arlr6Yb1Ef4ugAAAJ8"]
[Thu Jul 30 12:12:09.595738 2026] [security2:error] [pid 703393:tid 703592] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/loader.php"] [unique_id "amuF6c637Arlr6Yb1Ef40gAAAMo"]
[Thu Jul 30 12:12:09.595857 2026] [security2:error] [pid 703393:tid 703592] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/loader.php"] [unique_id "amuF6c637Arlr6Yb1Ef40gAAAMo"]
[Thu Jul 30 12:12:09.603164 2026] [security2:error] [pid 703393:tid 703640] [client 172.237.109.114:23523] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuF6M637Arlr6Yb1Ef4uwAAAPo"]
[Thu Jul 30 12:12:09.603996 2026] [security2:error] [pid 703393:tid 703642] [client 172.237.109.114:44166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuF6c637Arlr6Yb1Ef4vQAAAPw"]
[Thu Jul 30 12:12:09.624031 2026] [security2:error] [pid 703393:tid 703562] [client 172.237.109.114:29276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuF6M637Arlr6Yb1Ef4vAAAAKw"]
[Thu Jul 30 12:12:09.697034 2026] [security2:error] [pid 703393:tid 703611] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuF6c637Arlr6Yb1Ef4ywAA3T4"]
[Thu Jul 30 12:12:09.768164 2026] [security2:error] [pid 703393:tid 703581] [client 20.226.5.174:28113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/f7.php"] [unique_id "amuF6c637Arlr6Yb1Ef42QAAAL8"]
[Thu Jul 30 12:12:10.052837 2026] [security2:error] [pid 703393:tid 703635] [client 20.91.208.34:10014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/pucci.php"] [unique_id "amuF6s637Arlr6Yb1Ef43gAAAPU"]
[Thu Jul 30 12:12:10.052989 2026] [security2:error] [pid 703393:tid 703635] [client 20.91.208.34:10014] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/pucci.php"] [unique_id "amuF6s637Arlr6Yb1Ef43gAAAPU"]
[Thu Jul 30 12:12:10.086312 2026] [security2:error] [pid 703393:tid 703630] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/file61.php"] [unique_id "amuF6s637Arlr6Yb1Ef43wAAAPA"]
[Thu Jul 30 12:12:10.086473 2026] [security2:error] [pid 703393:tid 703630] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/file61.php"] [unique_id "amuF6s637Arlr6Yb1Ef43wAAAPA"]
[Thu Jul 30 12:12:10.143073 2026] [security2:error] [pid 703393:tid 703608] [client 74.7.241.168:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.club4.au"] [uri "/index.php"] [unique_id "amuF58637Arlr6Yb1Ef4VwAAANo"]
[Thu Jul 30 12:12:10.143112 2026] [security2:error] [pid 703393:tid 703608] [client 74.7.241.168:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.club4.au"] [uri "/index.php"] [unique_id "amuF58637Arlr6Yb1Ef4VwAAANo"]
[Thu Jul 30 12:12:10.143736 2026] [security2:error] [pid 703393:tid 703585] [client 74.7.241.168:56588] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.club4.au"] [uri "/robots.txt"] [unique_id "amuF58637Arlr6Yb1Ef4UwAAw2E"]
[Thu Jul 30 12:12:10.255037 2026] [security2:error] [pid 703393:tid 703607] [client 57.141.0.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "smoke-tfhk.com"] [uri "/index.php"] [unique_id "amuF6c637Arlr6Yb1Ef4ygAAANk"], referer: https://smoke-tfhk.com/seven-stars-ruanbai-vs-heibiao/
[Thu Jul 30 12:12:10.418611 2026] [security2:error] [pid 703393:tid 703639] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuF6c637Arlr6Yb1Ef43AAA-RA"], referer: https://www.spececigarette.com/wp-content/plugins/jetpack-search/README.txt
[Thu Jul 30 12:12:10.442464 2026] [security2:error] [pid 703393:tid 703578] [client 185.191.171.4:48760] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/11/16/copa-do-catar-tera-a-cerveja-mais-cara-da-historia-r-73-o-copo-de-meio-litro/"] [unique_id "amuF6s637Arlr6Yb1Ef46AAAALw"]
[Thu Jul 30 12:12:10.442601 2026] [security2:error] [pid 703393:tid 703578] [client 185.191.171.4:48760] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/11/16/copa-do-catar-tera-a-cerveja-mais-cara-da-historia-r-73-o-copo-de-meio-litro/"] [unique_id "amuF6s637Arlr6Yb1Ef46AAAALw"]
[Thu Jul 30 12:12:10.581213 2026] [security2:error] [pid 703393:tid 703649] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-css.php"] [unique_id "amuF6s637Arlr6Yb1Ef46gAAAQM"]
[Thu Jul 30 12:12:10.581347 2026] [security2:error] [pid 703393:tid 703649] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-css.php"] [unique_id "amuF6s637Arlr6Yb1Ef46gAAAQM"]
[Thu Jul 30 12:12:10.638634 2026] [security2:error] [pid 703393:tid 703533] [client 20.91.208.34:10022] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "alshateeintl.com"] [uri "/cgi-sys/404.html"] [unique_id "amuF6s637Arlr6Yb1Ef46wAAAI8"]
[Thu Jul 30 12:12:10.795802 2026] [security2:error] [pid 703393:tid 703650] [client 20.91.208.34:10022] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "alshateeintl.com"] [uri "/cgi-sys/404.html"] [unique_id "amuF6s637Arlr6Yb1Ef48gAAAQQ"]
[Thu Jul 30 12:12:10.804205 2026] [security2:error] [pid 703393:tid 703421] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/contact-form-7/readme.txt"] [unique_id "amuF6s637Arlr6Yb1Ef49QAA7hs"]
[Thu Jul 30 12:12:10.950925 2026] [security2:error] [pid 703393:tid 703619] [client 20.91.208.34:10022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/wp-temp.php"] [unique_id "amuF6s637Arlr6Yb1Ef4-AAAAOU"]
[Thu Jul 30 12:12:10.951057 2026] [security2:error] [pid 703393:tid 703619] [client 20.91.208.34:10022] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/wp-temp.php"] [unique_id "amuF6s637Arlr6Yb1Ef4-AAAAOU"]
[Thu Jul 30 12:12:11.026005 2026] [security2:error] [pid 703393:tid 703557] [client 74.7.241.168:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "club4.au"] [uri "/index.php"] [unique_id "amuF6s637Arlr6Yb1Ef49wAAAKc"], referer: https://www.club4.au/robots.txt
[Thu Jul 30 12:12:11.027067 2026] [security2:error] [pid 703393:tid 703605] [client 74.7.241.168:56590] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "club4.au"] [uri "/robots.txt"] [unique_id "amuF6s637Arlr6Yb1Ef49AAA10A"], referer: https://www.club4.au/robots.txt
[Thu Jul 30 12:12:11.048116 2026] [core:notice] [pid 703393:tid 703616] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:11.054434 2026] [security2:error] [pid 703393:tid 703616] [client 103.215.74.26:21844] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF68637Arlr6Yb1Ef4-gAAAOI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:11.090090 2026] [security2:error] [pid 703393:tid 703629] [client 191.232.199.39:60747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-activate.php"] [unique_id "amuF68637Arlr6Yb1Ef4_AAAAO8"]
[Thu Jul 30 12:12:11.111614 2026] [security2:error] [pid 703393:tid 703574] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-blink.php"] [unique_id "amuF68637Arlr6Yb1Ef4_gAAALg"]
[Thu Jul 30 12:12:11.111719 2026] [security2:error] [pid 703393:tid 703574] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-blink.php"] [unique_id "amuF68637Arlr6Yb1Ef4_gAAALg"]
[Thu Jul 30 12:12:11.135674 2026] [security2:error] [pid 703393:tid 703524] [client 20.63.98.115:36861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/NewFile.php"] [unique_id "amuF68637Arlr6Yb1Ef4_wAAAIY"]
[Thu Jul 30 12:12:11.264730 2026] [security2:error] [pid 703393:tid 703448] [remote 74.7.241.60:43672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/article.php"] [unique_id "amuF68637Arlr6Yb1Ef5BQAAsTY"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/main_image_6a3229a631e84.jpg
[Thu Jul 30 12:12:11.416832 2026] [security2:error] [pid 703393:tid 703577] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuF68637Arlr6Yb1Ef4-wAAu0I"]
[Thu Jul 30 12:12:11.544744 2026] [security2:error] [pid 703393:tid 703554] [client 20.91.208.34:58594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuF68637Arlr6Yb1Ef5CQAAAKQ"]
[Thu Jul 30 12:12:11.544876 2026] [security2:error] [pid 703393:tid 703554] [client 20.91.208.34:58594] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuF68637Arlr6Yb1Ef5CQAAAKQ"]
[Thu Jul 30 12:12:11.602428 2026] [security2:error] [pid 703393:tid 703526] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/txets.php"] [unique_id "amuF68637Arlr6Yb1Ef5CwAAAIg"]
[Thu Jul 30 12:12:11.602540 2026] [security2:error] [pid 703393:tid 703526] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/txets.php"] [unique_id "amuF68637Arlr6Yb1Ef5CwAAAIg"]
[Thu Jul 30 12:12:11.699005 2026] [security2:error] [pid 703393:tid 703570] [client 2a03:2880:f800:38:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuF68637Arlr6Yb1Ef4_QAAtCE"]
[Thu Jul 30 12:12:11.798818 2026] [core:notice] [pid 703393:tid 703609] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:11.805088 2026] [security2:error] [pid 703393:tid 703609] [client 103.215.74.26:21860] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF68637Arlr6Yb1Ef5EAAAANs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:11.971275 2026] [security2:error] [pid 703393:tid 703613] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuF68637Arlr6Yb1Ef5CAAA30U"], referer: https://www.spececigarette.com/wp-content/plugins/contact-form-7/Readme.txt
[Thu Jul 30 12:12:12.088774 2026] [security2:error] [pid 703393:tid 703558] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/pucci.php"] [unique_id "amuF7M637Arlr6Yb1Ef5GAAAAKg"]
[Thu Jul 30 12:12:12.088873 2026] [security2:error] [pid 703393:tid 703558] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/pucci.php"] [unique_id "amuF7M637Arlr6Yb1Ef5GAAAAKg"]
[Thu Jul 30 12:12:12.106791 2026] [security2:error] [pid 703393:tid 703468] [remote 74.7.241.59:58120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuF7M637Arlr6Yb1Ef5GQAAnUo"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/forms/actions
[Thu Jul 30 12:12:12.184178 2026] [security2:error] [pid 703393:tid 703634] [client 20.91.208.34:55058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/puc.php"] [unique_id "amuF7M637Arlr6Yb1Ef5HAAAAPQ"]
[Thu Jul 30 12:12:12.184277 2026] [security2:error] [pid 703393:tid 703634] [client 20.91.208.34:55058] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/puc.php"] [unique_id "amuF7M637Arlr6Yb1Ef5HAAAAPQ"]
[Thu Jul 30 12:12:12.411057 2026] [security2:error] [pid 703393:tid 703571] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuF7M637Arlr6Yb1Ef5FwAAtU8"]
[Thu Jul 30 12:12:12.435827 2026] [security2:error] [pid 703393:tid 703626] [client 191.232.199.39:6851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/post.php"] [unique_id "amuF7M637Arlr6Yb1Ef5JAAAAOw"]
[Thu Jul 30 12:12:12.534560 2026] [core:notice] [pid 703393:tid 703624] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:12.544527 2026] [security2:error] [pid 703393:tid 703624] [client 103.215.74.26:21878] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF7M637Arlr6Yb1Ef5JgAAAOo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:12.573844 2026] [security2:error] [pid 703393:tid 703641] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/xwpg.php"] [unique_id "amuF7M637Arlr6Yb1Ef5JwAAAPs"]
[Thu Jul 30 12:12:12.573940 2026] [security2:error] [pid 703393:tid 703641] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/xwpg.php"] [unique_id "amuF7M637Arlr6Yb1Ef5JwAAAPs"]
[Thu Jul 30 12:12:13.067430 2026] [security2:error] [pid 703393:tid 703552] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/ops.php"] [unique_id "amuF7c637Arlr6Yb1Ef5MQAAAKI"]
[Thu Jul 30 12:12:13.067553 2026] [security2:error] [pid 703393:tid 703552] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/ops.php"] [unique_id "amuF7c637Arlr6Yb1Ef5MQAAAKI"]
[Thu Jul 30 12:12:13.090686 2026] [security2:error] [pid 703393:tid 703527] [client 20.91.208.34:10027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/dx.php"] [unique_id "amuF7c637Arlr6Yb1Ef5MgAAAIk"]
[Thu Jul 30 12:12:13.090788 2026] [security2:error] [pid 703393:tid 703527] [client 20.91.208.34:10027] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/dx.php"] [unique_id "amuF7c637Arlr6Yb1Ef5MgAAAIk"]
[Thu Jul 30 12:12:13.214837 2026] [security2:error] [pid 703393:tid 703532] [client 94.154.43.187:56250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "fireworkskenya.co.ke"] [uri "/.env"] [unique_id "amuF7c637Arlr6Yb1Ef5NAAAAI4"]
[Thu Jul 30 12:12:13.220160 2026] [security2:error] [pid 703393:tid 703599] [client 2a03:2880:f800:e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuF7M637Arlr6Yb1Ef5KAAA0VU"]
[Thu Jul 30 12:12:13.290301 2026] [security2:error] [pid 703393:tid 703595] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuF7M637Arlr6Yb1Ef5MAAAzUY"], referer: https://www.spececigarette.com/wp-content/plugins/contact-form-7/README.txt
[Thu Jul 30 12:12:13.572283 2026] [security2:error] [pid 703393:tid 703547] [client 20.48.234.177:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "reviewbyjook.com"] [uri "/1.php"] [unique_id "amuF7c637Arlr6Yb1Ef5PgAAAJ0"]
[Thu Jul 30 12:12:13.572420 2026] [security2:error] [pid 703393:tid 703547] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/1.php"] [unique_id "amuF7c637Arlr6Yb1Ef5PgAAAJ0"]
[Thu Jul 30 12:12:13.572534 2026] [security2:error] [pid 703393:tid 703547] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/1.php"] [unique_id "amuF7c637Arlr6Yb1Ef5PgAAAJ0"]
[Thu Jul 30 12:12:14.097175 2026] [security2:error] [pid 703393:tid 703621] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/mac.php"] [unique_id "amuF7s637Arlr6Yb1Ef5SwAAAOc"]
[Thu Jul 30 12:12:14.097303 2026] [security2:error] [pid 703393:tid 703621] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/mac.php"] [unique_id "amuF7s637Arlr6Yb1Ef5SwAAAOc"]
[Thu Jul 30 12:12:14.116609 2026] [security2:error] [pid 703393:tid 703605] [client 191.232.199.39:51779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/content.php"] [unique_id "amuF7s637Arlr6Yb1Ef5TAAAANc"]
[Thu Jul 30 12:12:14.252095 2026] [security2:error] [pid 703393:tid 703569] [client 216.244.66.243:41108] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabiandubaisafari.com"] [uri "/slmh4f/gloria-williams-demetress-bell-mother"] [unique_id "amuF7s637Arlr6Yb1Ef5TQAAALM"]
[Thu Jul 30 12:12:14.252210 2026] [security2:error] [pid 703393:tid 703569] [client 216.244.66.243:41108] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "arabiandubaisafari.com"] [uri "/slmh4f/gloria-williams-demetress-bell-mother"] [unique_id "amuF7s637Arlr6Yb1Ef5TQAAALM"]
[Thu Jul 30 12:12:14.438421 2026] [security2:error] [pid 703393:tid 703600] [client 5.161.113.195:41918] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuF7c637Arlr6Yb1Ef5MwAAANI"], referer: https://globalmarks.pk/
[Thu Jul 30 12:12:14.651341 2026] [security2:error] [pid 703393:tid 703543] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuF7s637Arlr6Yb1Ef5VgAAAJk"]
[Thu Jul 30 12:12:14.651433 2026] [security2:error] [pid 703393:tid 703543] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuF7s637Arlr6Yb1Ef5VgAAAJk"]
[Thu Jul 30 12:12:14.774413 2026] [core:notice] [pid 703393:tid 703499] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:15.094209 2026] [core:notice] [pid 703393:tid 703570] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:15.103838 2026] [security2:error] [pid 703393:tid 703628] [client 191.232.199.39:6860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-2019.php"] [unique_id "amuF78637Arlr6Yb1Ef5aQAAAO4"]
[Thu Jul 30 12:12:15.193730 2026] [security2:error] [pid 703393:tid 703592] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/aa.php"] [unique_id "amuF78637Arlr6Yb1Ef5awAAAMo"]
[Thu Jul 30 12:12:15.193842 2026] [security2:error] [pid 703393:tid 703592] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/aa.php"] [unique_id "amuF78637Arlr6Yb1Ef5awAAAMo"]
[Thu Jul 30 12:12:15.654428 2026] [security2:error] [pid 703393:tid 703572] [client 191.232.199.39:51669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/upfile.php"] [unique_id "amuF78637Arlr6Yb1Ef5fgAAALY"]
[Thu Jul 30 12:12:15.709022 2026] [security2:error] [pid 703393:tid 703585] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/xyn.php"] [unique_id "amuF78637Arlr6Yb1Ef5gQAAAMM"]
[Thu Jul 30 12:12:15.709168 2026] [security2:error] [pid 703393:tid 703585] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/xyn.php"] [unique_id "amuF78637Arlr6Yb1Ef5gQAAAMM"]
[Thu Jul 30 12:12:16.229200 2026] [security2:error] [pid 703393:tid 703632] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-wp.php"] [unique_id "amuF8M637Arlr6Yb1Ef5jAAAAPI"]
[Thu Jul 30 12:12:16.229323 2026] [security2:error] [pid 703393:tid 703632] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-wp.php"] [unique_id "amuF8M637Arlr6Yb1Ef5jAAAAPI"]
[Thu Jul 30 12:12:16.739252 2026] [security2:error] [pid 703393:tid 703553] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/aw.php"] [unique_id "amuF8M637Arlr6Yb1Ef5rAAAAKM"]
[Thu Jul 30 12:12:16.739350 2026] [security2:error] [pid 703393:tid 703553] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/aw.php"] [unique_id "amuF8M637Arlr6Yb1Ef5rAAAAKM"]
[Thu Jul 30 12:12:17.239019 2026] [security2:error] [pid 703393:tid 703584] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/classwithtostring.php"] [unique_id "amuF8c637Arlr6Yb1Ef5uwAAAMI"]
[Thu Jul 30 12:12:17.239146 2026] [security2:error] [pid 703393:tid 703584] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/classwithtostring.php"] [unique_id "amuF8c637Arlr6Yb1Ef5uwAAAMI"]
[Thu Jul 30 12:12:17.463519 2026] [security2:error] [pid 703393:tid 703563] [client 191.232.199.39:54103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/bypass.php"] [unique_id "amuF8c637Arlr6Yb1Ef5vQAAAK0"]
[Thu Jul 30 12:12:17.725825 2026] [security2:error] [pid 703393:tid 703650] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/yawa.php"] [unique_id "amuF8c637Arlr6Yb1Ef6BQAAAQQ"]
[Thu Jul 30 12:12:17.725918 2026] [security2:error] [pid 703393:tid 703650] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/yawa.php"] [unique_id "amuF8c637Arlr6Yb1Ef6BQAAAQQ"]
[Thu Jul 30 12:12:18.246510 2026] [security2:error] [pid 703393:tid 703552] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/sym403.php"] [unique_id "amuF8s637Arlr6Yb1Ef6LQAAAKI"]
[Thu Jul 30 12:12:18.246610 2026] [security2:error] [pid 703393:tid 703552] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/sym403.php"] [unique_id "amuF8s637Arlr6Yb1Ef6LQAAAKI"]
[Thu Jul 30 12:12:18.311888 2026] [core:notice] [pid 703393:tid 703610] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:18.318564 2026] [security2:error] [pid 703393:tid 703610] [client 103.215.74.26:45336] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF8s637Arlr6Yb1Ef6MgAAANw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:18.593262 2026] [security2:error] [pid 703393:tid 703553] [client 20.63.98.115:21441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/xx.php"] [unique_id "amuF8s637Arlr6Yb1Ef6OAAAAKM"]
[Thu Jul 30 12:12:19.091899 2026] [core:notice] [pid 703393:tid 703616] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:19.098371 2026] [security2:error] [pid 703393:tid 703616] [client 103.215.74.26:45352] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF88637Arlr6Yb1Ef6RwAAAOI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:19.314791 2026] [security2:error] [pid 703393:tid 703628] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "reviewbyjook.com"] [uri "/index.cgi"] [unique_id "amuF8s637Arlr6Yb1Ef6PgAAAO4"]
[Thu Jul 30 12:12:19.592631 2026] [security2:error] [pid 703393:tid 703561] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/adminner.php"] [unique_id "amuF88637Arlr6Yb1Ef6XgAAAKs"]
[Thu Jul 30 12:12:19.592735 2026] [security2:error] [pid 703393:tid 703561] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/adminner.php"] [unique_id "amuF88637Arlr6Yb1Ef6XgAAAKs"]
[Thu Jul 30 12:12:19.629312 2026] [security2:error] [pid 703393:tid 703608] [client 191.232.199.39:45074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/updates.php"] [unique_id "amuF88637Arlr6Yb1Ef6XwAAANo"]
[Thu Jul 30 12:12:19.863536 2026] [core:notice] [pid 703393:tid 703573] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:19.869934 2026] [security2:error] [pid 703393:tid 703573] [client 103.215.74.26:45364] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF88637Arlr6Yb1Ef6ZwAAALc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:19.898457 2026] [security2:error] [pid 703393:tid 703489] [remote 100.42.191.181:46322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.191.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-login.php"] [unique_id "amuF88637Arlr6Yb1Ef6aQAAnl8"]
[Thu Jul 30 12:12:20.117271 2026] [security2:error] [pid 703393:tid 703551] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/yup.php"] [unique_id "amuF9M637Arlr6Yb1Ef6cgAAAKE"]
[Thu Jul 30 12:12:20.117376 2026] [security2:error] [pid 703393:tid 703551] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/yup.php"] [unique_id "amuF9M637Arlr6Yb1Ef6cgAAAKE"]
[Thu Jul 30 12:12:20.124855 2026] [security2:error] [pid 703393:tid 703521] [remote 208.109.9.173:59842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.9.109.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-login.php"] [unique_id "amuF9M637Arlr6Yb1Ef6dQAAxn8"]
[Thu Jul 30 12:12:20.208677 2026] [security2:error] [pid 703393:tid 703617] [client 20.63.98.115:20800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/plugins.php"] [unique_id "amuF9M637Arlr6Yb1Ef6fQAAAOM"]
[Thu Jul 30 12:12:20.599395 2026] [core:notice] [pid 703393:tid 703585] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:20.605877 2026] [security2:error] [pid 703393:tid 703585] [client 103.215.74.26:45376] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF9M637Arlr6Yb1Ef6hAAAAMM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:20.627868 2026] [security2:error] [pid 703393:tid 703546] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/config.json.php"] [unique_id "amuF9M637Arlr6Yb1Ef6hQAAAJw"]
[Thu Jul 30 12:12:20.627991 2026] [security2:error] [pid 703393:tid 703546] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/config.json.php"] [unique_id "amuF9M637Arlr6Yb1Ef6hQAAAJw"]
[Thu Jul 30 12:12:20.797557 2026] [security2:error] [pid 703393:tid 703643] [client 191.232.199.39:45070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/xmrlpc.php"] [unique_id "amuF9M637Arlr6Yb1Ef6kgAAAP0"]
[Thu Jul 30 12:12:20.819816 2026] [security2:error] [pid 703393:tid 703541] [client 127.0.0.1:27552] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuF9M637Arlr6Yb1Ef6kAAAAJc"]
[Thu Jul 30 12:12:20.819860 2026] [security2:error] [pid 703393:tid 703604] [client 127.0.0.1:27536] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.plumbingplumb.com"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuF9M637Arlr6Yb1Ef6jwAAANY"]
[Thu Jul 30 12:12:20.819942 2026] [security2:error] [pid 703393:tid 703561] [client 74.7.228.58:37716] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.plumbingplumb.com"] [uri "/robots.txt"] [unique_id "amuF9M637Arlr6Yb1Ef6jgAAqzs"]
[Thu Jul 30 12:12:21.327910 2026] [core:notice] [pid 703393:tid 703562] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:21.335448 2026] [security2:error] [pid 703393:tid 703562] [client 103.215.74.26:45382] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF9c637Arlr6Yb1Ef6oAAAAKw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:21.603550 2026] [security2:error] [pid 703393:tid 703611] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "reviewbyjook.com"] [uri "/index.cgi"] [unique_id "amuF9c637Arlr6Yb1Ef6mQAAAN0"]
[Thu Jul 30 12:12:21.850432 2026] [security2:error] [pid 703393:tid 703583] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/2.php"] [unique_id "amuF9c637Arlr6Yb1Ef6qAAAAME"]
[Thu Jul 30 12:12:21.850534 2026] [security2:error] [pid 703393:tid 703583] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/2.php"] [unique_id "amuF9c637Arlr6Yb1Ef6qAAAAME"]
[Thu Jul 30 12:12:22.072679 2026] [core:notice] [pid 703393:tid 703624] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:22.079264 2026] [security2:error] [pid 703393:tid 703624] [client 103.215.74.26:45384] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF9s637Arlr6Yb1Ef6qgAAAOo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:22.330150 2026] [security2:error] [pid 703393:tid 703553] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/f35.update.php"] [unique_id "amuF9s637Arlr6Yb1Ef6sgAAAKM"]
[Thu Jul 30 12:12:22.330265 2026] [security2:error] [pid 703393:tid 703553] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/f35.update.php"] [unique_id "amuF9s637Arlr6Yb1Ef6sgAAAKM"]
[Thu Jul 30 12:12:22.487843 2026] [security2:error] [pid 703393:tid 703564] [client 191.232.199.39:45092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/ae.php"] [unique_id "amuF9s637Arlr6Yb1Ef6swAAAK4"]
[Thu Jul 30 12:12:22.719946 2026] [security2:error] [pid 703393:tid 703635] [client 20.63.98.115:20749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/xxx.php"] [unique_id "amuF9s637Arlr6Yb1Ef6twAAAPU"]
[Thu Jul 30 12:12:22.841135 2026] [security2:error] [pid 703393:tid 703570] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/k.php"] [unique_id "amuF9s637Arlr6Yb1Ef6uQAAALQ"]
[Thu Jul 30 12:12:22.841242 2026] [security2:error] [pid 703393:tid 703570] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/k.php"] [unique_id "amuF9s637Arlr6Yb1Ef6uQAAALQ"]
[Thu Jul 30 12:12:22.870255 2026] [security2:error] [pid 703393:tid 703525] [client 191.232.199.39:6868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/hoot.php"] [unique_id "amuF9s637Arlr6Yb1Ef6uwAAAIc"]
[Thu Jul 30 12:12:23.194246 2026] [core:notice] [pid 703393:tid 703398] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:23.863831 2026] [security2:error] [pid 703393:tid 703637] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "reviewbyjook.com"] [uri "/index.cgi"] [unique_id "amuF98637Arlr6Yb1Ef6wgAAAPc"]
[Thu Jul 30 12:12:24.109012 2026] [security2:error] [pid 703393:tid 703549] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/spadex.php"] [unique_id "amuF-M637Arlr6Yb1Ef6zwAAAJ8"]
[Thu Jul 30 12:12:24.109125 2026] [security2:error] [pid 703393:tid 703549] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/spadex.php"] [unique_id "amuF-M637Arlr6Yb1Ef6zwAAAJ8"]
[Thu Jul 30 12:12:24.410284 2026] [security2:error] [pid 703393:tid 703555] [client 20.63.98.115:39174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/css.php"] [unique_id "amuF-M637Arlr6Yb1Ef61AAAAKU"]
[Thu Jul 30 12:12:24.593770 2026] [security2:error] [pid 703393:tid 703634] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/mg.php"] [unique_id "amuF-M637Arlr6Yb1Ef62gAAAPQ"]
[Thu Jul 30 12:12:24.593880 2026] [security2:error] [pid 703393:tid 703634] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/mg.php"] [unique_id "amuF-M637Arlr6Yb1Ef62gAAAPQ"]
[Thu Jul 30 12:12:24.688660 2026] [security2:error] [pid 703393:tid 703609] [client 191.232.199.39:45088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/moon.php"] [unique_id "amuF-M637Arlr6Yb1Ef62wAAANs"]
[Thu Jul 30 12:12:25.105800 2026] [security2:error] [pid 703393:tid 703594] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/fnstall.php"] [unique_id "amuF-c637Arlr6Yb1Ef65gAAAMw"]
[Thu Jul 30 12:12:25.105914 2026] [security2:error] [pid 703393:tid 703594] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/fnstall.php"] [unique_id "amuF-c637Arlr6Yb1Ef65gAAAMw"]
[Thu Jul 30 12:12:25.498829 2026] [security2:error] [pid 703393:tid 703625] [client 20.63.98.115:32937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "amuF-c637Arlr6Yb1Ef67QAAAOs"]
[Thu Jul 30 12:12:25.617804 2026] [security2:error] [pid 703393:tid 703556] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/ortasekerli1.php"] [unique_id "amuF-c637Arlr6Yb1Ef67gAAAKY"]
[Thu Jul 30 12:12:25.617962 2026] [security2:error] [pid 703393:tid 703556] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/ortasekerli1.php"] [unique_id "amuF-c637Arlr6Yb1Ef67gAAAKY"]
[Thu Jul 30 12:12:25.920844 2026] [security2:error] [pid 703393:tid 703572] [client 66.249.73.98:40113] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuF-c637Arlr6Yb1Ef67wAAALY"]
[Thu Jul 30 12:12:26.102512 2026] [security2:error] [pid 703393:tid 703552] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/sump1.php"] [unique_id "amuF-s637Arlr6Yb1Ef6-QAAAKI"]
[Thu Jul 30 12:12:26.102633 2026] [security2:error] [pid 703393:tid 703552] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/sump1.php"] [unique_id "amuF-s637Arlr6Yb1Ef6-QAAAKI"]
[Thu Jul 30 12:12:26.585619 2026] [security2:error] [pid 703393:tid 703601] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/ops.php"] [unique_id "amuF-s637Arlr6Yb1Ef7AwAAANM"]
[Thu Jul 30 12:12:26.585706 2026] [security2:error] [pid 703393:tid 703601] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/ops.php"] [unique_id "amuF-s637Arlr6Yb1Ef7AwAAANM"]
[Thu Jul 30 12:12:26.688346 2026] [security2:error] [pid 703393:tid 703540] [client 191.232.199.39:6852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/log.php"] [unique_id "amuF-s637Arlr6Yb1Ef7BAAAAJY"]
[Thu Jul 30 12:12:26.815459 2026] [security2:error] [pid 703393:tid 703649] [client 20.63.98.115:39190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuF-s637Arlr6Yb1Ef7CAAAAQM"]
[Thu Jul 30 12:12:27.108051 2026] [security2:error] [pid 703393:tid 703627] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-post-data.php"] [unique_id "amuF-8637Arlr6Yb1Ef7DwAAAO0"]
[Thu Jul 30 12:12:27.108149 2026] [security2:error] [pid 703393:tid 703627] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-post-data.php"] [unique_id "amuF-8637Arlr6Yb1Ef7DwAAAO0"]
[Thu Jul 30 12:12:27.114079 2026] [security2:error] [pid 703393:tid 703555] [client 2a03:2880:f800:15:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuF-s637Arlr6Yb1Ef6_gAApQ0"]
[Thu Jul 30 12:12:27.177122 2026] [security2:error] [pid 703393:tid 703523] [client 66.249.73.97:41860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuF-s637Arlr6Yb1Ef7BgAAAIU"]
[Thu Jul 30 12:12:27.399908 2026] [security2:error] [pid 703393:tid 703583] [client 191.232.199.39:45078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/blog.php"] [unique_id "amuF-8637Arlr6Yb1Ef7EAAAAME"]
[Thu Jul 30 12:12:27.607539 2026] [security2:error] [pid 703393:tid 703543] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/root.php"] [unique_id "amuF-8637Arlr6Yb1Ef7GAAAAJk"]
[Thu Jul 30 12:12:27.607651 2026] [security2:error] [pid 703393:tid 703543] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/root.php"] [unique_id "amuF-8637Arlr6Yb1Ef7GAAAAJk"]
[Thu Jul 30 12:12:27.794723 2026] [core:notice] [pid 703393:tid 703563] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:27.802099 2026] [security2:error] [pid 703393:tid 703563] [client 103.215.74.26:13632] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF-8637Arlr6Yb1Ef7GQAAAK0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:28.112712 2026] [security2:error] [pid 703393:tid 703525] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/v543.php"] [unique_id "amuF_M637Arlr6Yb1Ef7HQAAAIc"]
[Thu Jul 30 12:12:28.113078 2026] [security2:error] [pid 703393:tid 703525] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/v543.php"] [unique_id "amuF_M637Arlr6Yb1Ef7HQAAAIc"]
[Thu Jul 30 12:12:28.328245 2026] [security2:error] [pid 703393:tid 703591] [client 185.189.112.11:58628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.112.189.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuF_M637Arlr6Yb1Ef7KQAAAMk"]
[Thu Jul 30 12:12:28.328347 2026] [security2:error] [pid 703393:tid 703591] [client 185.189.112.11:58628] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuF_M637Arlr6Yb1Ef7KQAAAMk"]
[Thu Jul 30 12:12:28.527094 2026] [core:notice] [pid 703393:tid 703603] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:28.533261 2026] [security2:error] [pid 703393:tid 703603] [client 103.215.74.26:13646] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF_M637Arlr6Yb1Ef7LQAAANU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:28.574810 2026] [security2:error] [pid 703393:tid 703632] [client 191.232.199.39:6850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/bak.php"] [unique_id "amuF_M637Arlr6Yb1Ef7LgAAAPI"]
[Thu Jul 30 12:12:28.592075 2026] [security2:error] [pid 703393:tid 703556] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/sixxis.php"] [unique_id "amuF_M637Arlr6Yb1Ef7MAAAAKY"]
[Thu Jul 30 12:12:28.592187 2026] [security2:error] [pid 703393:tid 703556] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/sixxis.php"] [unique_id "amuF_M637Arlr6Yb1Ef7MAAAAKY"]
[Thu Jul 30 12:12:28.868661 2026] [security2:error] [pid 703393:tid 703648] [client 20.63.98.115:49785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/images/index.php"] [unique_id "amuF_M637Arlr6Yb1Ef7NAAAAQI"]
[Thu Jul 30 12:12:29.075343 2026] [security2:error] [pid 703393:tid 703557] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/ip.php"] [unique_id "amuF_c637Arlr6Yb1Ef7OQAAAKc"]
[Thu Jul 30 12:12:29.075435 2026] [security2:error] [pid 703393:tid 703557] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/ip.php"] [unique_id "amuF_c637Arlr6Yb1Ef7OQAAAKc"]
[Thu Jul 30 12:12:29.174070 2026] [core:error] [pid 703393:tid 703563] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:12:29.174095 2026] [core:error] [pid 703393:tid 703563] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:12:29.256681 2026] [core:notice] [pid 703393:tid 703639] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:29.264122 2026] [security2:error] [pid 703393:tid 703639] [client 103.215.74.26:13660] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF_c637Arlr6Yb1Ef7RAAAAPk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:29.606123 2026] [security2:error] [pid 703393:tid 703616] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/kq1.php"] [unique_id "amuF_c637Arlr6Yb1Ef7TwAAAOI"]
[Thu Jul 30 12:12:29.606245 2026] [security2:error] [pid 703393:tid 703616] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/kq1.php"] [unique_id "amuF_c637Arlr6Yb1Ef7TwAAAOI"]
[Thu Jul 30 12:12:29.811183 2026] [security2:error] [pid 703393:tid 703420] [remote 47.128.60.153:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tuwaiq-sa.tech"] [uri "/robots.txt"] [unique_id "amuF_c637Arlr6Yb1Ef7VAAAmBo"]
[Thu Jul 30 12:12:30.022926 2026] [core:notice] [pid 703393:tid 703649] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:30.029200 2026] [security2:error] [pid 703393:tid 703649] [client 103.215.74.26:13676] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF_s637Arlr6Yb1Ef7WgAAAQM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:30.121266 2026] [security2:error] [pid 703393:tid 703555] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/fw/faiyy.php"] [unique_id "amuF_s637Arlr6Yb1Ef7XgAAAKU"]
[Thu Jul 30 12:12:30.121399 2026] [security2:error] [pid 703393:tid 703555] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/fw/faiyy.php"] [unique_id "amuF_s637Arlr6Yb1Ef7XgAAAKU"]
[Thu Jul 30 12:12:30.213299 2026] [security2:error] [pid 703393:tid 703613] [client 85.204.70.116:37764] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.zmr.gpl.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuF_s637Arlr6Yb1Ef7XwAAAN8"]
[Thu Jul 30 12:12:30.213610 2026] [security2:error] [pid 703393:tid 703531] [client 191.232.199.39:45077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/ini.php"] [unique_id "amuF_s637Arlr6Yb1Ef7YAAAAI0"]
[Thu Jul 30 12:12:30.473375 2026] [security2:error] [pid 703393:tid 703526] [client 85.204.70.116:47849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.zmr.gpl.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuF_s637Arlr6Yb1Ef7ZAAAAIg"]
[Thu Jul 30 12:12:30.630062 2026] [security2:error] [pid 703393:tid 703639] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/h02ugyh.php"] [unique_id "amuF_s637Arlr6Yb1Ef7awAAAPk"]
[Thu Jul 30 12:12:30.630198 2026] [security2:error] [pid 703393:tid 703639] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/h02ugyh.php"] [unique_id "amuF_s637Arlr6Yb1Ef7awAAAPk"]
[Thu Jul 30 12:12:30.793190 2026] [core:notice] [pid 703393:tid 703579] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:30.800929 2026] [security2:error] [pid 703393:tid 703579] [client 103.215.74.26:13688] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF_s637Arlr6Yb1Ef7bgAAAL0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:31.119686 2026] [security2:error] [pid 703393:tid 703540] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-temp.php"] [unique_id "amuF_8637Arlr6Yb1Ef7cwAAAJY"]
[Thu Jul 30 12:12:31.119793 2026] [security2:error] [pid 703393:tid 703540] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-temp.php"] [unique_id "amuF_8637Arlr6Yb1Ef7cwAAAJY"]
[Thu Jul 30 12:12:31.527077 2026] [core:notice] [pid 703393:tid 703588] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:31.533612 2026] [security2:error] [pid 703393:tid 703588] [client 103.215.74.26:13692] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF_8637Arlr6Yb1Ef7eQAAAMY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:31.607253 2026] [security2:error] [pid 703393:tid 703632] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-content/cong.php"] [unique_id "amuF_8637Arlr6Yb1Ef7fQAAAPI"]
[Thu Jul 30 12:12:31.607361 2026] [security2:error] [pid 703393:tid 703632] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-content/cong.php"] [unique_id "amuF_8637Arlr6Yb1Ef7fQAAAPI"]
[Thu Jul 30 12:12:31.693113 2026] [security2:error] [pid 703393:tid 703636] [client 85.204.70.116:37780] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.zmr.gpl.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuF_8637Arlr6Yb1Ef7gwAAAPY"]
[Thu Jul 30 12:12:31.778954 2026] [security2:error] [pid 703393:tid 703562] [client 191.232.199.39:45063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/admin-ajax.php"] [unique_id "amuF_8637Arlr6Yb1Ef7hAAAAKw"]
[Thu Jul 30 12:12:31.864570 2026] [security2:error] [pid 703393:tid 703592] [client 178.205.100.18:41350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toscanamall.com"] [uri "/administrator/index.php"] [unique_id "amuF_8637Arlr6Yb1Ef7egAAAMo"], referer: https://www.toscanamall.com/administrator/
[Thu Jul 30 12:12:31.959677 2026] [security2:error] [pid 703393:tid 703607] [client 85.204.70.116:37782] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.zmr.gpl.temporary.site"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuF_8637Arlr6Yb1Ef7hQAAANk"]
[Thu Jul 30 12:12:32.230691 2026] [security2:error] [pid 703393:tid 703602] [client 85.204.70.116:37786] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.zmr.gpl.temporary.site"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuGAM637Arlr6Yb1Ef7jAAAANQ"]
[Thu Jul 30 12:12:32.297486 2026] [core:notice] [pid 703393:tid 703530] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:32.303850 2026] [security2:error] [pid 703393:tid 703530] [client 103.215.74.26:13706] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGAM637Arlr6Yb1Ef7jwAAAIw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:32.539467 2026] [security2:error] [pid 703393:tid 703579] [client 85.204.70.116:57510] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.zmr.gpl.temporary.site"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuGAM637Arlr6Yb1Ef7kAAAAL0"]
[Thu Jul 30 12:12:32.600917 2026] [security2:error] [pid 703393:tid 703553] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "reviewbyjook.com"] [uri "/index.cgi"] [unique_id "amuGAM637Arlr6Yb1Ef7hgAAAKM"]
[Thu Jul 30 12:12:32.706142 2026] [security2:error] [pid 703393:tid 703571] [client 178.205.100.18:41356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toscanamall.com"] [uri "/wp-login.php"] [unique_id "amuGAM637Arlr6Yb1Ef7lAAAALU"]
[Thu Jul 30 12:12:32.807267 2026] [security2:error] [pid 703393:tid 703631] [client 85.204.70.116:57520] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.zmr.gpl.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuGAM637Arlr6Yb1Ef7mAAAAPE"]
[Thu Jul 30 12:12:32.841037 2026] [security2:error] [pid 703393:tid 703625] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-includes/css/index.php"] [unique_id "amuGAM637Arlr6Yb1Ef7mQAAAOs"]
[Thu Jul 30 12:12:32.841138 2026] [security2:error] [pid 703393:tid 703625] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-includes/css/index.php"] [unique_id "amuGAM637Arlr6Yb1Ef7mQAAAOs"]
[Thu Jul 30 12:12:32.940077 2026] [security2:error] [pid 703393:tid 703606] [client 191.232.199.39:6901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/content.php"] [unique_id "amuGAM637Arlr6Yb1Ef7mwAAANg"]
[Thu Jul 30 12:12:33.052073 2026] [core:notice] [pid 703393:tid 703623] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:33.062078 2026] [security2:error] [pid 703393:tid 703623] [client 103.215.74.26:8746] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGAc637Arlr6Yb1Ef7nAAAAOk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:33.096263 2026] [security2:error] [pid 703393:tid 703555] [client 85.204.70.116:57524] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.zmr.gpl.temporary.site"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuGAc637Arlr6Yb1Ef7nQAAAKU"]
[Thu Jul 30 12:12:33.167660 2026] [security2:error] [pid 703393:tid 703551] [client 191.232.199.39:45058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/akc.php"] [unique_id "amuGAc637Arlr6Yb1Ef7ngAAAKE"]
[Thu Jul 30 12:12:33.311368 2026] [security2:error] [pid 703393:tid 703545] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/jj.php"] [unique_id "amuGAc637Arlr6Yb1Ef7pQAAAJs"]
[Thu Jul 30 12:12:33.311456 2026] [security2:error] [pid 703393:tid 703545] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/jj.php"] [unique_id "amuGAc637Arlr6Yb1Ef7pQAAAJs"]
[Thu Jul 30 12:12:33.408845 2026] [security2:error] [pid 703393:tid 703593] [client 85.204.70.116:57526] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.zmr.gpl.temporary.site"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuGAc637Arlr6Yb1Ef7pgAAAMs"]
[Thu Jul 30 12:12:33.542993 2026] [security2:error] [pid 703393:tid 703531] [client 20.63.98.115:32936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/network/about.php"] [unique_id "amuGAc637Arlr6Yb1Ef7pwAAAI0"]
[Thu Jul 30 12:12:33.713075 2026] [security2:error] [pid 703393:tid 703580] [client 85.204.70.116:1681] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.zmr.gpl.temporary.site"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuGAc637Arlr6Yb1Ef7qAAAAL4"]
[Thu Jul 30 12:12:33.801970 2026] [core:notice] [pid 703393:tid 703596] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:33.802929 2026] [security2:error] [pid 703393:tid 703560] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/class-walker-footer-dev.php"] [unique_id "amuGAc637Arlr6Yb1Ef7rQAAAKo"]
[Thu Jul 30 12:12:33.803064 2026] [security2:error] [pid 703393:tid 703560] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/class-walker-footer-dev.php"] [unique_id "amuGAc637Arlr6Yb1Ef7rQAAAKo"]
[Thu Jul 30 12:12:33.808262 2026] [security2:error] [pid 703393:tid 703596] [client 103.215.74.26:8750] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGAc637Arlr6Yb1Ef7rAAAAM4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:33.813756 2026] [security2:error] [pid 703393:tid 703473] [remote 250.49.135.140:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuGAc637Arlr6Yb1Ef7rwAAqE8"]
[Thu Jul 30 12:12:33.813897 2026] [security2:error] [pid 703393:tid 703558] [client 250.49.135.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuGAc637Arlr6Yb1Ef7rwAAqE8"]
[Thu Jul 30 12:12:34.009091 2026] [security2:error] [pid 703393:tid 703605] [client 85.204.70.116:57542] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.zmr.gpl.temporary.site"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuGAs637Arlr6Yb1Ef7tAAAANc"]
[Thu Jul 30 12:12:34.163287 2026] [security2:error] [pid 703393:tid 703563] [client 191.232.199.39:6903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/upfile.php"] [unique_id "amuGAs637Arlr6Yb1Ef7tgAAAK0"]
[Thu Jul 30 12:12:34.306811 2026] [security2:error] [pid 703393:tid 703535] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/xpwer1.php"] [unique_id "amuGAs637Arlr6Yb1Ef7ugAAAJE"]
[Thu Jul 30 12:12:34.306913 2026] [security2:error] [pid 703393:tid 703535] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/xpwer1.php"] [unique_id "amuGAs637Arlr6Yb1Ef7ugAAAJE"]
[Thu Jul 30 12:12:34.319785 2026] [security2:error] [pid 703393:tid 703630] [client 85.204.70.116:8511] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.zmr.gpl.temporary.site"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuGAs637Arlr6Yb1Ef7vAAAAPA"]
[Thu Jul 30 12:12:34.412289 2026] [autoindex:error] [pid 703393:tid 703552] [client 66.132.186.204:58184] AH01276: Cannot serve directory /home2/ubphmute/public_html/website_170cb886/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:12:34.619469 2026] [security2:error] [pid 703393:tid 703592] [client 85.204.70.116:57560] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.zmr.gpl.temporary.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuGAs637Arlr6Yb1Ef7xgAAAMo"]
[Thu Jul 30 12:12:34.799679 2026] [security2:error] [pid 703393:tid 703614] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/flox.php"] [unique_id "amuGAs637Arlr6Yb1Ef7xwAAAOA"]
[Thu Jul 30 12:12:34.799775 2026] [security2:error] [pid 703393:tid 703614] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/flox.php"] [unique_id "amuGAs637Arlr6Yb1Ef7xwAAAOA"]
[Thu Jul 30 12:12:34.816628 2026] [security2:error] [pid 703393:tid 703603] [client 20.63.98.115:21444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/xpw.php"] [unique_id "amuGAs637Arlr6Yb1Ef7yQAAANU"]
[Thu Jul 30 12:12:34.916196 2026] [security2:error] [pid 703393:tid 703531] [client 85.204.70.116:40850] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.zmr.gpl.temporary.site"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuGAs637Arlr6Yb1Ef7zwAAAI0"]
[Thu Jul 30 12:12:35.084830 2026] [security2:error] [pid 703393:tid 703633] [client 178.205.100.18:41362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toscanamall.com"] [uri "/admin.php"] [unique_id "amuGA8637Arlr6Yb1Ef70AAAAPM"]
[Thu Jul 30 12:12:35.213309 2026] [security2:error] [pid 703393:tid 703596] [client 85.204.70.116:57576] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.zmr.gpl.temporary.site"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuGA8637Arlr6Yb1Ef70QAAAM4"]
[Thu Jul 30 12:12:35.294529 2026] [security2:error] [pid 703393:tid 703544] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/popo.php"] [unique_id "amuGA8637Arlr6Yb1Ef70gAAAJo"]
[Thu Jul 30 12:12:35.294632 2026] [security2:error] [pid 703393:tid 703544] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/popo.php"] [unique_id "amuGA8637Arlr6Yb1Ef70gAAAJo"]
[Thu Jul 30 12:12:35.331372 2026] [security2:error] [pid 703393:tid 703634] [client 103.82.26.211:50080] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.saifalkhaleejest.com"] [uri "/"] [unique_id "amuGA8637Arlr6Yb1Ef71QAAAPQ"]
[Thu Jul 30 12:12:35.511733 2026] [security2:error] [pid 703393:tid 703570] [client 85.204.70.116:49491] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.zmr.gpl.temporary.site"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuGA8637Arlr6Yb1Ef73AAAALQ"]
[Thu Jul 30 12:12:35.658302 2026] [security2:error] [pid 703393:tid 703586] [client 103.82.26.211:50119] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.saifalkhaleejest.com"] [uri "/wp-json/batch/v1"] [unique_id "amuGA8637Arlr6Yb1Ef73gAAAMQ"]
[Thu Jul 30 12:12:35.774936 2026] [security2:error] [pid 703393:tid 703590] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/yas.php"] [unique_id "amuGA8637Arlr6Yb1Ef73wAAAMg"]
[Thu Jul 30 12:12:35.775058 2026] [security2:error] [pid 703393:tid 703590] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/yas.php"] [unique_id "amuGA8637Arlr6Yb1Ef73wAAAMg"]
[Thu Jul 30 12:12:35.882167 2026] [security2:error] [pid 703393:tid 703622] [client 191.232.199.39:45091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/akcc.php"] [unique_id "amuGA8637Arlr6Yb1Ef74wAAAOg"]
[Thu Jul 30 12:12:36.098255 2026] [security2:error] [pid 703393:tid 703646] [client 20.63.98.115:39182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-cron.php"] [unique_id "amuGBM637Arlr6Yb1Ef75wAAAQA"]
[Thu Jul 30 12:12:36.260583 2026] [security2:error] [pid 703393:tid 703607] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/water.php"] [unique_id "amuGBM637Arlr6Yb1Ef76QAAANk"]
[Thu Jul 30 12:12:36.260688 2026] [security2:error] [pid 703393:tid 703607] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/water.php"] [unique_id "amuGBM637Arlr6Yb1Ef76QAAANk"]
[Thu Jul 30 12:12:36.779900 2026] [core:notice] [pid 703393:tid 703478] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:36.779937 2026] [security2:error] [pid 703393:tid 703601] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/nano.php"] [unique_id "amuGBM637Arlr6Yb1Ef79QAAANM"]
[Thu Jul 30 12:12:36.780072 2026] [security2:error] [pid 703393:tid 703601] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/nano.php"] [unique_id "amuGBM637Arlr6Yb1Ef79QAAANM"]
[Thu Jul 30 12:12:37.276198 2026] [security2:error] [pid 703393:tid 703554] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/moon.php"] [unique_id "amuGBc637Arlr6Yb1Ef7_gAAAKQ"]
[Thu Jul 30 12:12:37.276306 2026] [security2:error] [pid 703393:tid 703554] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/moon.php"] [unique_id "amuGBc637Arlr6Yb1Ef7_gAAAKQ"]
[Thu Jul 30 12:12:37.715275 2026] [security2:error] [pid 703393:tid 703536] [client 191.232.199.39:45082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/asasx.php"] [unique_id "amuGBc637Arlr6Yb1Ef8BgAAAJI"]
[Thu Jul 30 12:12:37.723776 2026] [security2:error] [pid 703393:tid 703560] [client 54.183.198.160:14188] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "lilyinspires.com"] [uri "/wp-comments-post.php"] [unique_id "amuGBc637Arlr6Yb1Ef7_QAAAKo"]
[Thu Jul 30 12:12:37.793692 2026] [security2:error] [pid 703393:tid 703532] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-info.php"] [unique_id "amuGBc637Arlr6Yb1Ef8BwAAAI4"]
[Thu Jul 30 12:12:37.793801 2026] [security2:error] [pid 703393:tid 703532] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-info.php"] [unique_id "amuGBc637Arlr6Yb1Ef8BwAAAI4"]
[Thu Jul 30 12:12:37.836309 2026] [security2:error] [pid 703393:tid 703560] [client 54.183.198.160:14188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "lilyinspires.com"] [uri "/wp-comments-post.php"] [unique_id "amuGBc637Arlr6Yb1Ef7_QAAAKo"]
[Thu Jul 30 12:12:37.836387 2026] [security2:error] [pid 703393:tid 703560] [client 54.183.198.160:14188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lilyinspires.com"] [uri "/wp-comments-post.php"] [unique_id "amuGBc637Arlr6Yb1Ef7_QAAAKo"]
[Thu Jul 30 12:12:38.238178 2026] [security2:error] [pid 703393:tid 703553] [client 20.63.98.115:39207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/cah.php"] [unique_id "amuGBs637Arlr6Yb1Ef8EAAAAKM"]
[Thu Jul 30 12:12:38.288964 2026] [security2:error] [pid 703393:tid 703603] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/file5.php"] [unique_id "amuGBs637Arlr6Yb1Ef8EQAAANU"]
[Thu Jul 30 12:12:38.289112 2026] [security2:error] [pid 703393:tid 703603] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/file5.php"] [unique_id "amuGBs637Arlr6Yb1Ef8EQAAANU"]
[Thu Jul 30 12:12:38.521859 2026] [core:notice] [pid 703393:tid 703511] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:38.718664 2026] [security2:error] [pid 703393:tid 703500] [remote 179.43.134.114:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.134.43.179.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-login.php"] [unique_id "amuGBs637Arlr6Yb1Ef8FQAA1Go"]
[Thu Jul 30 12:12:38.777597 2026] [security2:error] [pid 703393:tid 703540] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/2000.php"] [unique_id "amuGBs637Arlr6Yb1Ef8GwAAAJY"]
[Thu Jul 30 12:12:38.777692 2026] [security2:error] [pid 703393:tid 703540] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/2000.php"] [unique_id "amuGBs637Arlr6Yb1Ef8GwAAAJY"]
[Thu Jul 30 12:12:39.121127 2026] [security2:error] [pid 703393:tid 703520] [remote 220.181.108.159:17800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.108.181.220.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2009/06/25/soldes-ete-2009/"] [unique_id "amuGB8637Arlr6Yb1Ef8IwAAmH4"]
[Thu Jul 30 12:12:39.258185 2026] [security2:error] [pid 703393:tid 703576] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/122.php"] [unique_id "amuGB8637Arlr6Yb1Ef8JAAAALo"]
[Thu Jul 30 12:12:39.258345 2026] [security2:error] [pid 703393:tid 703576] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/122.php"] [unique_id "amuGB8637Arlr6Yb1Ef8JAAAALo"]
[Thu Jul 30 12:12:39.287389 2026] [security2:error] [pid 703393:tid 703535] [client 20.203.156.12:46994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/bypas.php"] [unique_id "amuGB8637Arlr6Yb1Ef8JgAAAJE"]
[Thu Jul 30 12:12:39.287476 2026] [security2:error] [pid 703393:tid 703535] [client 20.203.156.12:46994] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/bypas.php"] [unique_id "amuGB8637Arlr6Yb1Ef8JgAAAJE"]
[Thu Jul 30 12:12:39.465035 2026] [security2:error] [pid 703393:tid 703525] [client 20.63.98.115:21220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/cong.php"] [unique_id "amuGB8637Arlr6Yb1Ef8KAAAAIc"]
[Thu Jul 30 12:12:39.519129 2026] [core:notice] [pid 703393:tid 703565] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:39.525220 2026] [security2:error] [pid 703393:tid 703565] [client 103.215.74.26:8764] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGB8637Arlr6Yb1Ef8LAAAAK8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:39.735795 2026] [security2:error] [pid 703393:tid 703579] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/mds.php"] [unique_id "amuGB8637Arlr6Yb1Ef8NQAAAL0"]
[Thu Jul 30 12:12:39.735879 2026] [security2:error] [pid 703393:tid 703579] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/mds.php"] [unique_id "amuGB8637Arlr6Yb1Ef8NQAAAL0"]
[Thu Jul 30 12:12:39.761965 2026] [core:notice] [pid 703393:tid 703492] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:39.896409 2026] [security2:error] [pid 703393:tid 703560] [client 20.203.156.12:50019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/ucen.php"] [unique_id "amuGB8637Arlr6Yb1Ef8OQAAAKo"]
[Thu Jul 30 12:12:39.896540 2026] [security2:error] [pid 703393:tid 703560] [client 20.203.156.12:50019] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/ucen.php"] [unique_id "amuGB8637Arlr6Yb1Ef8OQAAAKo"]
[Thu Jul 30 12:12:40.225229 2026] [security2:error] [pid 703393:tid 703642] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/zc-208.php"] [unique_id "amuGCM637Arlr6Yb1Ef8QQAAAPw"]
[Thu Jul 30 12:12:40.225357 2026] [security2:error] [pid 703393:tid 703642] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/zc-208.php"] [unique_id "amuGCM637Arlr6Yb1Ef8QQAAAPw"]
[Thu Jul 30 12:12:40.252894 2026] [security2:error] [pid 703393:tid 703608] [client 20.203.156.12:58213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/miya.php"] [unique_id "amuGCM637Arlr6Yb1Ef8QgAAANo"]
[Thu Jul 30 12:12:40.253004 2026] [security2:error] [pid 703393:tid 703608] [client 20.203.156.12:58213] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/miya.php"] [unique_id "amuGCM637Arlr6Yb1Ef8QgAAANo"]
[Thu Jul 30 12:12:40.276263 2026] [core:notice] [pid 703393:tid 703595] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:40.282609 2026] [security2:error] [pid 703393:tid 703595] [client 103.215.74.26:8766] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGCM637Arlr6Yb1Ef8QwAAAM0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:40.329438 2026] [security2:error] [pid 703393:tid 703611] [client 20.63.98.115:21260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/Sanskrit.php"] [unique_id "amuGCM637Arlr6Yb1Ef8RAAAAN0"]
[Thu Jul 30 12:12:40.342645 2026] [core:notice] [pid 703393:tid 703417] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:40.508733 2026] [core:notice] [pid 703393:tid 703515] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:40.513239 2026] [core:notice] [pid 703393:tid 703471] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:40.619251 2026] [security2:error] [pid 703393:tid 703548] [client 20.203.156.12:35768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/error.php"] [unique_id "amuGCM637Arlr6Yb1Ef8SwAAAJ4"]
[Thu Jul 30 12:12:40.619338 2026] [security2:error] [pid 703393:tid 703548] [client 20.203.156.12:35768] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/error.php"] [unique_id "amuGCM637Arlr6Yb1Ef8SwAAAJ4"]
[Thu Jul 30 12:12:40.716067 2026] [security2:error] [pid 703393:tid 703616] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/sid4.php"] [unique_id "amuGCM637Arlr6Yb1Ef8UQAAAOI"]
[Thu Jul 30 12:12:40.716203 2026] [security2:error] [pid 703393:tid 703616] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/sid4.php"] [unique_id "amuGCM637Arlr6Yb1Ef8UQAAAOI"]
[Thu Jul 30 12:12:41.006951 2026] [core:notice] [pid 703393:tid 703644] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:41.013305 2026] [security2:error] [pid 703393:tid 703644] [client 103.215.74.26:8778] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGCc637Arlr6Yb1Ef8UgAAAP4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:41.026888 2026] [security2:error] [pid 703393:tid 703604] [client 20.203.156.12:40216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/alfav.php"] [unique_id "amuGCc637Arlr6Yb1Ef8UwAAANY"]
[Thu Jul 30 12:12:41.026999 2026] [security2:error] [pid 703393:tid 703604] [client 20.203.156.12:40216] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/alfav.php"] [unique_id "amuGCc637Arlr6Yb1Ef8UwAAANY"]
[Thu Jul 30 12:12:41.347013 2026] [security2:error] [pid 703393:tid 703576] [client 20.203.156.12:53229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/alpas.php"] [unique_id "amuGCc637Arlr6Yb1Ef8WwAAALo"]
[Thu Jul 30 12:12:41.347164 2026] [security2:error] [pid 703393:tid 703576] [client 20.203.156.12:53229] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/alpas.php"] [unique_id "amuGCc637Arlr6Yb1Ef8WwAAALo"]
[Thu Jul 30 12:12:41.396399 2026] [core:notice] [pid 703393:tid 703405] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:41.670266 2026] [security2:error] [pid 703393:tid 703640] [client 20.63.98.115:49790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/ms-edit.php"] [unique_id "amuGCc637Arlr6Yb1Ef8YQAAAPo"]
[Thu Jul 30 12:12:41.729910 2026] [core:notice] [pid 703393:tid 703632] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:41.730044 2026] [security2:error] [pid 703393:tid 703568] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "reviewbyjook.com"] [uri "/index.cgi"] [unique_id "amuGCc637Arlr6Yb1Ef8WgAAALI"]
[Thu Jul 30 12:12:41.736093 2026] [security2:error] [pid 703393:tid 703632] [client 103.215.74.26:8792] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGCc637Arlr6Yb1Ef8ZQAAAPI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:41.833298 2026] [security2:error] [pid 703393:tid 703631] [client 20.203.156.12:40196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/alfa.php"] [unique_id "amuGCc637Arlr6Yb1Ef8ZgAAAPE"]
[Thu Jul 30 12:12:41.833407 2026] [security2:error] [pid 703393:tid 703631] [client 20.203.156.12:40196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/alfa.php"] [unique_id "amuGCc637Arlr6Yb1Ef8ZgAAAPE"]
[Thu Jul 30 12:12:42.010839 2026] [security2:error] [pid 703393:tid 703592] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wmore1.php"] [unique_id "amuGCs637Arlr6Yb1Ef8ZwAAAMo"]
[Thu Jul 30 12:12:42.010943 2026] [security2:error] [pid 703393:tid 703592] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wmore1.php"] [unique_id "amuGCs637Arlr6Yb1Ef8ZwAAAMo"]
[Thu Jul 30 12:12:42.191250 2026] [security2:error] [pid 703393:tid 703545] [client 20.203.156.12:52702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/0byte.php"] [unique_id "amuGCs637Arlr6Yb1Ef8awAAAJs"]
[Thu Jul 30 12:12:42.191373 2026] [security2:error] [pid 703393:tid 703545] [client 20.203.156.12:52702] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/0byte.php"] [unique_id "amuGCs637Arlr6Yb1Ef8awAAAJs"]
[Thu Jul 30 12:12:42.231366 2026] [core:notice] [pid 703393:tid 703509] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:42.254377 2026] [core:notice] [pid 703393:tid 703415] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:42.503814 2026] [security2:error] [pid 703393:tid 703634] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/solo1.php"] [unique_id "amuGCs637Arlr6Yb1Ef8cwAAAPQ"]
[Thu Jul 30 12:12:42.503943 2026] [security2:error] [pid 703393:tid 703634] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/solo1.php"] [unique_id "amuGCs637Arlr6Yb1Ef8cwAAAPQ"]
[Thu Jul 30 12:12:42.597692 2026] [security2:error] [pid 703393:tid 703530] [client 20.63.98.115:58062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/function.php"] [unique_id "amuGCs637Arlr6Yb1Ef8dAAAAIw"]
[Thu Jul 30 12:12:42.637036 2026] [security2:error] [pid 703393:tid 703558] [client 20.203.156.12:35757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/index3.php"] [unique_id "amuGCs637Arlr6Yb1Ef8dQAAAKg"]
[Thu Jul 30 12:12:42.637127 2026] [security2:error] [pid 703393:tid 703558] [client 20.203.156.12:35757] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/index3.php"] [unique_id "amuGCs637Arlr6Yb1Ef8dQAAAKg"]
[Thu Jul 30 12:12:43.001672 2026] [security2:error] [pid 703393:tid 703540] [client 20.203.156.12:52693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/index2.php"] [unique_id "amuGC8637Arlr6Yb1Ef8fQAAAJY"]
[Thu Jul 30 12:12:43.001768 2026] [security2:error] [pid 703393:tid 703540] [client 20.203.156.12:52693] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/index2.php"] [unique_id "amuGC8637Arlr6Yb1Ef8fQAAAJY"]
[Thu Jul 30 12:12:43.136214 2026] [core:notice] [pid 703393:tid 703621] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:43.390624 2026] [security2:error] [pid 703393:tid 703613] [client 20.203.156.12:52711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/index1.php"] [unique_id "amuGC8637Arlr6Yb1Ef8hQAAAN8"]
[Thu Jul 30 12:12:43.390720 2026] [security2:error] [pid 703393:tid 703613] [client 20.203.156.12:52711] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/index1.php"] [unique_id "amuGC8637Arlr6Yb1Ef8hQAAAN8"]
[Thu Jul 30 12:12:43.488988 2026] [security2:error] [pid 703393:tid 703554] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "reviewbyjook.com"] [uri "/index.cgi"] [unique_id "amuGCs637Arlr6Yb1Ef8fAAAAKQ"]
[Thu Jul 30 12:12:43.507513 2026] [security2:error] [pid 703393:tid 703622] [client 20.63.98.115:39173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/ee.php"] [unique_id "amuGC8637Arlr6Yb1Ef8hgAAAOg"]
[Thu Jul 30 12:12:43.639402 2026] [security2:error] [pid 703393:tid 703524] [client 191.232.199.39:45107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/axx.php"] [unique_id "amuGC8637Arlr6Yb1Ef8hwAAAIY"]
[Thu Jul 30 12:12:43.841070 2026] [security2:error] [pid 703393:tid 703627] [client 20.203.156.12:50045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/303.php"] [unique_id "amuGC8637Arlr6Yb1Ef8kAAAAO0"]
[Thu Jul 30 12:12:43.841202 2026] [security2:error] [pid 703393:tid 703627] [client 20.203.156.12:50045] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/303.php"] [unique_id "amuGC8637Arlr6Yb1Ef8kAAAAO0"]
[Thu Jul 30 12:12:43.849297 2026] [security2:error] [pid 703393:tid 703600] [client 191.232.199.39:6894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/bypass.php"] [unique_id "amuGC8637Arlr6Yb1Ef8kQAAANI"]
[Thu Jul 30 12:12:44.238044 2026] [security2:error] [pid 703393:tid 703614] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "reviewbyjook.com"] [uri "/index.cgi"] [unique_id "amuGC8637Arlr6Yb1Ef8iQAAAOA"]
[Thu Jul 30 12:12:44.257507 2026] [security2:error] [pid 703393:tid 703558] [client 20.203.156.12:52680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/505.php"] [unique_id "amuGDM637Arlr6Yb1Ef8lAAAAKg"]
[Thu Jul 30 12:12:44.257598 2026] [security2:error] [pid 703393:tid 703558] [client 20.203.156.12:52680] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/505.php"] [unique_id "amuGDM637Arlr6Yb1Ef8lAAAAKg"]
[Thu Jul 30 12:12:44.422274 2026] [security2:error] [pid 703393:tid 703631] [client 2a03:2880:f800:4:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuGC8637Arlr6Yb1Ef8iAAA8QU"]
[Thu Jul 30 12:12:44.484217 2026] [security2:error] [pid 703393:tid 703630] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/public/css.php"] [unique_id "amuGDM637Arlr6Yb1Ef8ngAAAPA"]
[Thu Jul 30 12:12:44.484329 2026] [security2:error] [pid 703393:tid 703630] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/public/css.php"] [unique_id "amuGDM637Arlr6Yb1Ef8ngAAAPA"]
[Thu Jul 30 12:12:44.751128 2026] [security2:error] [pid 703393:tid 703643] [client 20.203.156.12:52684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/500.php"] [unique_id "amuGDM637Arlr6Yb1Ef8oAAAAP0"]
[Thu Jul 30 12:12:44.751244 2026] [security2:error] [pid 703393:tid 703643] [client 20.203.156.12:52684] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/500.php"] [unique_id "amuGDM637Arlr6Yb1Ef8oAAAAP0"]
[Thu Jul 30 12:12:44.976348 2026] [security2:error] [pid 703393:tid 703645] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/output.php"] [unique_id "amuGDM637Arlr6Yb1Ef8xwAAAP8"]
[Thu Jul 30 12:12:44.976445 2026] [security2:error] [pid 703393:tid 703645] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/output.php"] [unique_id "amuGDM637Arlr6Yb1Ef8xwAAAP8"]
[Thu Jul 30 12:12:44.994673 2026] [security2:error] [pid 703393:tid 703525] [client 20.63.98.115:58079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/new.php"] [unique_id "amuGDM637Arlr6Yb1Ef8yAAAAIc"]
[Thu Jul 30 12:12:45.223864 2026] [security2:error] [pid 703393:tid 703592] [client 20.203.156.12:40218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/77.php"] [unique_id "amuGDc637Arlr6Yb1Ef8yQAAAMo"]
[Thu Jul 30 12:12:45.223971 2026] [security2:error] [pid 703393:tid 703592] [client 20.203.156.12:40218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/77.php"] [unique_id "amuGDc637Arlr6Yb1Ef8yQAAAMo"]
[Thu Jul 30 12:12:45.465242 2026] [security2:error] [pid 703393:tid 703608] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-file-120.php"] [unique_id "amuGDc637Arlr6Yb1Ef81AAAANo"]
[Thu Jul 30 12:12:45.465352 2026] [security2:error] [pid 703393:tid 703608] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-file-120.php"] [unique_id "amuGDc637Arlr6Yb1Ef81AAAANo"]
[Thu Jul 30 12:12:45.556817 2026] [security2:error] [pid 703393:tid 703615] [client 20.203.156.12:52673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/76.php"] [unique_id "amuGDc637Arlr6Yb1Ef81QAAAOE"]
[Thu Jul 30 12:12:45.556959 2026] [security2:error] [pid 703393:tid 703615] [client 20.203.156.12:52673] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/76.php"] [unique_id "amuGDc637Arlr6Yb1Ef81QAAAOE"]
[Thu Jul 30 12:12:45.949253 2026] [security2:error] [pid 703393:tid 703602] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/special.php"] [unique_id "amuGDc637Arlr6Yb1Ef83gAAANQ"]
[Thu Jul 30 12:12:45.949390 2026] [security2:error] [pid 703393:tid 703602] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/special.php"] [unique_id "amuGDc637Arlr6Yb1Ef83gAAANQ"]
[Thu Jul 30 12:12:46.000245 2026] [security2:error] [pid 703393:tid 703537] [client 20.203.156.12:35770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/74.php"] [unique_id "amuGDc637Arlr6Yb1Ef84QAAAJM"]
[Thu Jul 30 12:12:46.000392 2026] [security2:error] [pid 703393:tid 703537] [client 20.203.156.12:35770] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/74.php"] [unique_id "amuGDc637Arlr6Yb1Ef84QAAAJM"]
[Thu Jul 30 12:12:46.103479 2026] [security2:error] [pid 703393:tid 703529] [client 191.232.199.39:6879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/updates.php"] [unique_id "amuGDs637Arlr6Yb1Ef84gAAAIs"]
[Thu Jul 30 12:12:46.362888 2026] [security2:error] [pid 703393:tid 703631] [client 20.203.156.12:43429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/wp-config.php"] [unique_id "amuGDs637Arlr6Yb1Ef85QAAAPE"]
[Thu Jul 30 12:12:46.362998 2026] [security2:error] [pid 703393:tid 703631] [client 20.203.156.12:43429] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/wp-config.php"] [unique_id "amuGDs637Arlr6Yb1Ef85QAAAPE"]
[Thu Jul 30 12:12:46.450933 2026] [security2:error] [pid 703393:tid 703625] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/as.php"] [unique_id "amuGDs637Arlr6Yb1Ef87AAAAOs"]
[Thu Jul 30 12:12:46.451065 2026] [security2:error] [pid 703393:tid 703625] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/as.php"] [unique_id "amuGDs637Arlr6Yb1Ef87AAAAOs"]
[Thu Jul 30 12:12:46.574810 2026] [security2:error] [pid 703393:tid 703448] [remote 57.141.0.48:32126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/407345907/feed/rss2/"] [unique_id "amuGDs637Arlr6Yb1Ef87gAA8jY"]
[Thu Jul 30 12:12:46.630771 2026] [security2:error] [pid 703393:tid 703573] [client 20.63.98.115:21408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-config.php"] [unique_id "amuGDs637Arlr6Yb1Ef88AAAALc"]
[Thu Jul 30 12:12:46.658840 2026] [security2:error] [pid 703393:tid 703579] [client 20.203.156.12:58238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/75.php"] [unique_id "amuGDs637Arlr6Yb1Ef88QAAAL0"]
[Thu Jul 30 12:12:46.658924 2026] [security2:error] [pid 703393:tid 703579] [client 20.203.156.12:58238] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/75.php"] [unique_id "amuGDs637Arlr6Yb1Ef88QAAAL0"]
[Thu Jul 30 12:12:46.925146 2026] [security2:error] [pid 703393:tid 703566] [client 185.193.49.79:61966] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/etc/httpd/modsecurity.d/01_asl_content.conf"] [line "64"] [id "391213"] [msg "Atomicorp.com WAF Rules: Request content type is not allowed by policy"] [data "application/zip"] [severity "WARNING"] [hostname "deltaedu.net"] [uri "/"] [unique_id "amuGDs637Arlr6Yb1Ef8_wAAALA"]
[Thu Jul 30 12:12:46.925249 2026] [security2:error] [pid 703393:tid 703566] [client 185.193.49.79:61966] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "deltaedu.net"] [uri "/"] [unique_id "amuGDs637Arlr6Yb1Ef8_wAAALA"]
[Thu Jul 30 12:12:46.936477 2026] [security2:error] [pid 703393:tid 703531] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/cgi-bin/index.php"] [unique_id "amuGDs637Arlr6Yb1Ef9AQAAAI0"]
[Thu Jul 30 12:12:46.936600 2026] [security2:error] [pid 703393:tid 703531] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/cgi-bin/index.php"] [unique_id "amuGDs637Arlr6Yb1Ef9AQAAAI0"]
[Thu Jul 30 12:12:47.043527 2026] [security2:error] [pid 703393:tid 703641] [client 191.232.199.39:45075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/berax.php"] [unique_id "amuGD8637Arlr6Yb1Ef9DgAAAPs"]
[Thu Jul 30 12:12:47.053549 2026] [security2:error] [pid 703393:tid 703526] [client 20.203.156.12:58185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/71.php"] [unique_id "amuGD8637Arlr6Yb1Ef9DwAAAIg"]
[Thu Jul 30 12:12:47.053622 2026] [security2:error] [pid 703393:tid 703526] [client 20.203.156.12:58185] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/71.php"] [unique_id "amuGD8637Arlr6Yb1Ef9DwAAAIg"]
[Thu Jul 30 12:12:47.203837 2026] [security2:error] [pid 703393:tid 703464] [remote 34.62.86.130:53116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jwcpartners.org"] [uri "/index.php"] [unique_id "amuGDs637Arlr6Yb1Ef8-QAA-EY"], referer: http://jwcpartners.org/
[Thu Jul 30 12:12:47.368551 2026] [security2:error] [pid 703393:tid 703455] [remote 34.62.86.130:53116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jwcpartners.org"] [uri "/index.php"] [unique_id "amuGDM637Arlr6Yb1Ef8vQAAiT0"], referer: http://jwcpartners.org/
[Thu Jul 30 12:12:47.375267 2026] [security2:error] [pid 703393:tid 703601] [client 20.203.156.12:58239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/72.php"] [unique_id "amuGD8637Arlr6Yb1Ef9GgAAANM"]
[Thu Jul 30 12:12:47.375372 2026] [security2:error] [pid 703393:tid 703601] [client 20.203.156.12:58239] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/72.php"] [unique_id "amuGD8637Arlr6Yb1Ef9GgAAANM"]
[Thu Jul 30 12:12:47.452568 2026] [security2:error] [pid 703393:tid 703619] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/w1px.php"] [unique_id "amuGD8637Arlr6Yb1Ef9GwAAAOU"]
[Thu Jul 30 12:12:47.452673 2026] [security2:error] [pid 703393:tid 703619] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/w1px.php"] [unique_id "amuGD8637Arlr6Yb1Ef9GwAAAOU"]
[Thu Jul 30 12:12:47.457156 2026] [security2:error] [pid 703393:tid 703548] [client 20.63.98.115:20779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-conflg.php"] [unique_id "amuGD8637Arlr6Yb1Ef9HQAAAJ4"]
[Thu Jul 30 12:12:47.512869 2026] [core:notice] [pid 703393:tid 703539] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:47.522539 2026] [security2:error] [pid 703393:tid 703539] [client 103.215.74.26:57890] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGD8637Arlr6Yb1Ef9IAAAAJU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:47.679515 2026] [security2:error] [pid 703393:tid 703649] [client 191.232.199.39:6899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/xmrlpc.php"] [unique_id "amuGD8637Arlr6Yb1Ef9LAAAAQM"]
[Thu Jul 30 12:12:47.752196 2026] [security2:error] [pid 703393:tid 703623] [client 20.203.156.12:39650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/70.php"] [unique_id "amuGD8637Arlr6Yb1Ef9LgAAAOk"]
[Thu Jul 30 12:12:47.752323 2026] [security2:error] [pid 703393:tid 703623] [client 20.203.156.12:39650] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/70.php"] [unique_id "amuGD8637Arlr6Yb1Ef9LgAAAOk"]
[Thu Jul 30 12:12:47.965909 2026] [security2:error] [pid 703393:tid 703584] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/js.php"] [unique_id "amuGD8637Arlr6Yb1Ef9NAAAAMI"]
[Thu Jul 30 12:12:47.966025 2026] [security2:error] [pid 703393:tid 703584] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/js.php"] [unique_id "amuGD8637Arlr6Yb1Ef9NAAAAMI"]
[Thu Jul 30 12:12:48.246004 2026] [core:notice] [pid 703393:tid 703562] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:48.252168 2026] [security2:error] [pid 703393:tid 703562] [client 103.215.74.26:57900] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGEM637Arlr6Yb1Ef9RwAAAKw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:48.263865 2026] [security2:error] [pid 703393:tid 703615] [client 20.203.156.12:51826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/69.php"] [unique_id "amuGEM637Arlr6Yb1Ef9SAAAAOE"]
[Thu Jul 30 12:12:48.263946 2026] [security2:error] [pid 703393:tid 703615] [client 20.203.156.12:51826] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/69.php"] [unique_id "amuGEM637Arlr6Yb1Ef9SAAAAOE"]
[Thu Jul 30 12:12:48.413689 2026] [security2:error] [pid 703393:tid 703573] [client 66.249.65.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuGD8637Arlr6Yb1Ef9MQAAALc"]
[Thu Jul 30 12:12:48.496660 2026] [security2:error] [pid 703393:tid 703634] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/core.php"] [unique_id "amuGEM637Arlr6Yb1Ef9TQAAAPQ"]
[Thu Jul 30 12:12:48.496760 2026] [security2:error] [pid 703393:tid 703634] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/core.php"] [unique_id "amuGEM637Arlr6Yb1Ef9TQAAAPQ"]
[Thu Jul 30 12:12:48.631793 2026] [security2:error] [pid 703393:tid 703609] [client 20.203.156.12:39618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/68.php"] [unique_id "amuGEM637Arlr6Yb1Ef9VQAAANs"]
[Thu Jul 30 12:12:48.631908 2026] [security2:error] [pid 703393:tid 703609] [client 20.203.156.12:39618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/68.php"] [unique_id "amuGEM637Arlr6Yb1Ef9VQAAANs"]
[Thu Jul 30 12:12:48.657277 2026] [lsapi:error] [pid 643253:tid 643275] [remote 102.209.111.62:0] [host flixon.net] Error receiving response: ReceiveResponse: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1009; user ID 1009), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://flixon.net/video/about-time-vj-junior/
[Thu Jul 30 12:12:49.002065 2026] [security2:error] [pid 703393:tid 703550] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/fffm.php"] [unique_id "amuGEc637Arlr6Yb1Ef9VwAAAKA"]
[Thu Jul 30 12:12:49.002206 2026] [security2:error] [pid 703393:tid 703550] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/fffm.php"] [unique_id "amuGEc637Arlr6Yb1Ef9VwAAAKA"]
[Thu Jul 30 12:12:49.137630 2026] [security2:error] [pid 703393:tid 703565] [client 20.203.156.12:51816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/66.php"] [unique_id "amuGEc637Arlr6Yb1Ef9XwAAAK8"]
[Thu Jul 30 12:12:49.137759 2026] [security2:error] [pid 703393:tid 703565] [client 20.203.156.12:51816] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/66.php"] [unique_id "amuGEc637Arlr6Yb1Ef9XwAAAK8"]
[Thu Jul 30 12:12:49.288863 2026] [security2:error] [pid 703393:tid 703553] [client 2a03:2880:f800:2:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuGEM637Arlr6Yb1Ef9VAAAo38"]
[Thu Jul 30 12:12:49.480107 2026] [security2:error] [pid 703393:tid 703569] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/ww.php"] [unique_id "amuGEc637Arlr6Yb1Ef9YAAAALM"]
[Thu Jul 30 12:12:49.480244 2026] [security2:error] [pid 703393:tid 703569] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/ww.php"] [unique_id "amuGEc637Arlr6Yb1Ef9YAAAALM"]
[Thu Jul 30 12:12:49.577209 2026] [security2:error] [pid 703393:tid 703618] [client 20.203.156.12:40243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/67.php"] [unique_id "amuGEc637Arlr6Yb1Ef9YQAAAOQ"]
[Thu Jul 30 12:12:49.577361 2026] [security2:error] [pid 703393:tid 703618] [client 20.203.156.12:40243] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/67.php"] [unique_id "amuGEc637Arlr6Yb1Ef9YQAAAOQ"]
[Thu Jul 30 12:12:49.818148 2026] [security2:error] [pid 703393:tid 703625] [client 191.232.199.39:45104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/build.php"] [unique_id "amuGEc637Arlr6Yb1Ef9aAAAAOs"]
[Thu Jul 30 12:12:49.820812 2026] [security2:error] [pid 703393:tid 703587] [client 191.232.199.39:6853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/ae.php"] [unique_id "amuGEc637Arlr6Yb1Ef9aQAAAMU"]
[Thu Jul 30 12:12:49.962021 2026] [security2:error] [pid 703393:tid 703580] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/domvf.php"] [unique_id "amuGEc637Arlr6Yb1Ef9awAAAL4"]
[Thu Jul 30 12:12:49.962183 2026] [security2:error] [pid 703393:tid 703580] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/domvf.php"] [unique_id "amuGEc637Arlr6Yb1Ef9awAAAL4"]
[Thu Jul 30 12:12:50.149542 2026] [security2:error] [pid 703393:tid 703530] [client 20.203.156.12:40249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/65.php"] [unique_id "amuGEs637Arlr6Yb1Ef9bQAAAIw"]
[Thu Jul 30 12:12:50.149646 2026] [security2:error] [pid 703393:tid 703530] [client 20.203.156.12:40249] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/65.php"] [unique_id "amuGEs637Arlr6Yb1Ef9bQAAAIw"]
[Thu Jul 30 12:12:50.451744 2026] [security2:error] [pid 703393:tid 703535] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/echkm.php"] [unique_id "amuGEs637Arlr6Yb1Ef9dgAAAJE"]
[Thu Jul 30 12:12:50.451864 2026] [security2:error] [pid 703393:tid 703535] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/echkm.php"] [unique_id "amuGEs637Arlr6Yb1Ef9dgAAAJE"]
[Thu Jul 30 12:12:50.575886 2026] [security2:error] [pid 703393:tid 703590] [client 20.203.156.12:55579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/64.php"] [unique_id "amuGEs637Arlr6Yb1Ef9eAAAAMg"]
[Thu Jul 30 12:12:50.576014 2026] [security2:error] [pid 703393:tid 703590] [client 20.203.156.12:55579] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/64.php"] [unique_id "amuGEs637Arlr6Yb1Ef9eAAAAMg"]
[Thu Jul 30 12:12:50.935719 2026] [security2:error] [pid 703393:tid 703612] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/ano.php"] [unique_id "amuGEs637Arlr6Yb1Ef9hAAAAN4"]
[Thu Jul 30 12:12:50.935829 2026] [security2:error] [pid 703393:tid 703612] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/ano.php"] [unique_id "amuGEs637Arlr6Yb1Ef9hAAAAN4"]
[Thu Jul 30 12:12:50.999915 2026] [security2:error] [pid 703393:tid 703646] [client 20.203.156.12:53187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/63.php"] [unique_id "amuGEs637Arlr6Yb1Ef9hQAAAQA"]
[Thu Jul 30 12:12:51.000052 2026] [security2:error] [pid 703393:tid 703646] [client 20.203.156.12:53187] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/63.php"] [unique_id "amuGEs637Arlr6Yb1Ef9hQAAAQA"]
[Thu Jul 30 12:12:51.065526 2026] [security2:error] [pid 703393:tid 703555] [client 191.232.199.39:6896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/moon.php"] [unique_id "amuGE8637Arlr6Yb1Ef9hwAAAKU"]
[Thu Jul 30 12:12:51.262841 2026] [security2:error] [pid 703393:tid 703595] [client 127.0.0.1:33986] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuGE8637Arlr6Yb1Ef9jAAAAM0"]
[Thu Jul 30 12:12:51.262927 2026] [security2:error] [pid 703393:tid 703553] [client 74.7.175.147:53796] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.aptlaw.kr"] [uri "/robots.txt"] [unique_id "amuGE8637Arlr6Yb1Ef9iwAAoyQ"]
[Thu Jul 30 12:12:51.345376 2026] [security2:error] [pid 703393:tid 703647] [client 20.203.156.12:48718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/62.php"] [unique_id "amuGE8637Arlr6Yb1Ef9kAAAAQE"]
[Thu Jul 30 12:12:51.345479 2026] [security2:error] [pid 703393:tid 703647] [client 20.203.156.12:48718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/62.php"] [unique_id "amuGE8637Arlr6Yb1Ef9kAAAAQE"]
[Thu Jul 30 12:12:51.418857 2026] [security2:error] [pid 703393:tid 703557] [client 20.63.98.115:39202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "amuGE8637Arlr6Yb1Ef9kQAAAKc"]
[Thu Jul 30 12:12:51.420507 2026] [security2:error] [pid 703393:tid 703625] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/ah25.php"] [unique_id "amuGE8637Arlr6Yb1Ef9kgAAAOs"]
[Thu Jul 30 12:12:51.420578 2026] [security2:error] [pid 703393:tid 703625] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/ah25.php"] [unique_id "amuGE8637Arlr6Yb1Ef9kgAAAOs"]
[Thu Jul 30 12:12:51.728156 2026] [security2:error] [pid 703393:tid 703534] [client 20.203.156.12:52335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/61.php"] [unique_id "amuGE8637Arlr6Yb1Ef9lQAAAJA"]
[Thu Jul 30 12:12:51.728254 2026] [security2:error] [pid 703393:tid 703534] [client 20.203.156.12:52335] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/61.php"] [unique_id "amuGE8637Arlr6Yb1Ef9lQAAAJA"]
[Thu Jul 30 12:12:51.913769 2026] [security2:error] [pid 703393:tid 703631] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/term.php"] [unique_id "amuGE8637Arlr6Yb1Ef9mgAAAPE"]
[Thu Jul 30 12:12:51.913876 2026] [security2:error] [pid 703393:tid 703631] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/term.php"] [unique_id "amuGE8637Arlr6Yb1Ef9mgAAAPE"]
[Thu Jul 30 12:12:52.217303 2026] [security2:error] [pid 703393:tid 703576] [client 20.203.156.12:54473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/60.php"] [unique_id "amuGFM637Arlr6Yb1Ef9nwAAALo"]
[Thu Jul 30 12:12:52.217405 2026] [security2:error] [pid 703393:tid 703576] [client 20.203.156.12:54473] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/60.php"] [unique_id "amuGFM637Arlr6Yb1Ef9nwAAALo"]
[Thu Jul 30 12:12:52.316826 2026] [security2:error] [pid 703393:tid 703597] [client 191.232.199.39:46467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/buy.php"] [unique_id "amuGFM637Arlr6Yb1Ef9pAAAAM8"]
[Thu Jul 30 12:12:52.399572 2026] [security2:error] [pid 703393:tid 703596] [client 20.63.98.115:21339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/customize/chosen.php"] [unique_id "amuGFM637Arlr6Yb1Ef9pQAAAM4"]
[Thu Jul 30 12:12:52.415905 2026] [security2:error] [pid 703393:tid 703646] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/we.php"] [unique_id "amuGFM637Arlr6Yb1Ef9pgAAAQA"]
[Thu Jul 30 12:12:52.416021 2026] [security2:error] [pid 703393:tid 703646] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/we.php"] [unique_id "amuGFM637Arlr6Yb1Ef9pgAAAQA"]
[Thu Jul 30 12:12:52.527823 2026] [security2:error] [pid 703393:tid 703524] [client 20.203.156.12:26033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/58.php"] [unique_id "amuGFM637Arlr6Yb1Ef9pwAAAIY"]
[Thu Jul 30 12:12:52.527924 2026] [security2:error] [pid 703393:tid 703524] [client 20.203.156.12:26033] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/58.php"] [unique_id "amuGFM637Arlr6Yb1Ef9pwAAAIY"]
[Thu Jul 30 12:12:52.845694 2026] [security2:error] [pid 703393:tid 703600] [client 20.203.156.12:40198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/59.php"] [unique_id "amuGFM637Arlr6Yb1Ef9swAAANI"]
[Thu Jul 30 12:12:52.845846 2026] [security2:error] [pid 703393:tid 703600] [client 20.203.156.12:40198] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/59.php"] [unique_id "amuGFM637Arlr6Yb1Ef9swAAANI"]
[Thu Jul 30 12:12:52.915324 2026] [security2:error] [pid 703393:tid 703580] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/zip-onee.php"] [unique_id "amuGFM637Arlr6Yb1Ef9twAAAL4"]
[Thu Jul 30 12:12:52.915444 2026] [security2:error] [pid 703393:tid 703580] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/zip-onee.php"] [unique_id "amuGFM637Arlr6Yb1Ef9twAAAL4"]
[Thu Jul 30 12:12:53.185855 2026] [security2:error] [pid 703393:tid 703602] [client 20.203.156.12:58180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/57.php/56.php"] [unique_id "amuGFc637Arlr6Yb1Ef9uQAAANQ"]
[Thu Jul 30 12:12:53.185970 2026] [security2:error] [pid 703393:tid 703602] [client 20.203.156.12:58180] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/57.php/56.php"] [unique_id "amuGFc637Arlr6Yb1Ef9uQAAANQ"]
[Thu Jul 30 12:12:53.403930 2026] [security2:error] [pid 703393:tid 703636] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/il.php"] [unique_id "amuGFc637Arlr6Yb1Ef9wAAAAPY"]
[Thu Jul 30 12:12:53.404028 2026] [security2:error] [pid 703393:tid 703636] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/il.php"] [unique_id "amuGFc637Arlr6Yb1Ef9wAAAAPY"]
[Thu Jul 30 12:12:53.707950 2026] [security2:error] [pid 703393:tid 703597] [client 20.203.156.12:26047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/55.php"] [unique_id "amuGFc637Arlr6Yb1Ef9wQAAAM8"]
[Thu Jul 30 12:12:53.708067 2026] [security2:error] [pid 703393:tid 703597] [client 20.203.156.12:26047] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/55.php"] [unique_id "amuGFc637Arlr6Yb1Ef9wQAAAM8"]
[Thu Jul 30 12:12:53.887765 2026] [security2:error] [pid 703393:tid 703527] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/one.php"] [unique_id "amuGFc637Arlr6Yb1Ef9xQAAAIk"]
[Thu Jul 30 12:12:53.887875 2026] [security2:error] [pid 703393:tid 703527] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/one.php"] [unique_id "amuGFc637Arlr6Yb1Ef9xQAAAIk"]
[Thu Jul 30 12:12:53.967885 2026] [core:notice] [pid 703393:tid 703613] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:53.974050 2026] [security2:error] [pid 703393:tid 703613] [client 103.215.74.26:50194] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGFc637Arlr6Yb1Ef9yQAAAN8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:54.141086 2026] [security2:error] [pid 703393:tid 703642] [client 20.203.156.12:26027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/54.php"] [unique_id "amuGFs637Arlr6Yb1Ef9zQAAAPw"]
[Thu Jul 30 12:12:54.141188 2026] [security2:error] [pid 703393:tid 703642] [client 20.203.156.12:26027] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/54.php"] [unique_id "amuGFs637Arlr6Yb1Ef9zQAAAPw"]
[Thu Jul 30 12:12:54.332570 2026] [security2:error] [pid 703393:tid 703590] [client 20.63.98.115:43905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/js/autoload_classmap.php"] [unique_id "amuGFs637Arlr6Yb1Ef9zgAAAMg"]
[Thu Jul 30 12:12:54.399374 2026] [security2:error] [pid 703393:tid 703559] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/002.php"] [unique_id "amuGFs637Arlr6Yb1Ef90wAAAKk"]
[Thu Jul 30 12:12:54.399469 2026] [security2:error] [pid 703393:tid 703559] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/002.php"] [unique_id "amuGFs637Arlr6Yb1Ef90wAAAKk"]
[Thu Jul 30 12:12:54.513033 2026] [security2:error] [pid 703393:tid 703548] [client 20.203.156.12:37022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/53.php"] [unique_id "amuGFs637Arlr6Yb1Ef91gAAAJ4"]
[Thu Jul 30 12:12:54.513153 2026] [security2:error] [pid 703393:tid 703548] [client 20.203.156.12:37022] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/53.php"] [unique_id "amuGFs637Arlr6Yb1Ef91gAAAJ4"]
[Thu Jul 30 12:12:54.695508 2026] [core:notice] [pid 703393:tid 703604] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:54.701851 2026] [security2:error] [pid 703393:tid 703604] [client 103.215.74.26:50198] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGFs637Arlr6Yb1Ef91wAAANY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:54.929338 2026] [security2:error] [pid 703393:tid 703577] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/file1.php"] [unique_id "amuGFs637Arlr6Yb1Ef93gAAALs"]
[Thu Jul 30 12:12:54.929449 2026] [security2:error] [pid 703393:tid 703577] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/file1.php"] [unique_id "amuGFs637Arlr6Yb1Ef93gAAALs"]
[Thu Jul 30 12:12:55.059082 2026] [security2:error] [pid 703393:tid 703607] [client 20.203.156.12:48726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/52.php"] [unique_id "amuGF8637Arlr6Yb1Ef94wAAANk"]
[Thu Jul 30 12:12:55.059180 2026] [security2:error] [pid 703393:tid 703607] [client 20.203.156.12:48726] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/52.php"] [unique_id "amuGF8637Arlr6Yb1Ef94wAAANk"]
[Thu Jul 30 12:12:55.372621 2026] [security2:error] [pid 703393:tid 703643] [client 20.63.98.115:43965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/Text/autoload_classmap.php"] [unique_id "amuGF8637Arlr6Yb1Ef95QAAAP0"]
[Thu Jul 30 12:12:55.410943 2026] [security2:error] [pid 703393:tid 703565] [client 191.232.199.39:46484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/checkbox.php"] [unique_id "amuGF8637Arlr6Yb1Ef96QAAAK8"]
[Thu Jul 30 12:12:55.443473 2026] [security2:error] [pid 703393:tid 703568] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/akimet.php"] [unique_id "amuGF8637Arlr6Yb1Ef96gAAALI"]
[Thu Jul 30 12:12:55.443557 2026] [security2:error] [pid 703393:tid 703568] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/akimet.php"] [unique_id "amuGF8637Arlr6Yb1Ef96gAAALI"]
[Thu Jul 30 12:12:55.506180 2026] [security2:error] [pid 703393:tid 703587] [client 20.203.156.12:40203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/51.php"] [unique_id "amuGF8637Arlr6Yb1Ef97gAAAMU"]
[Thu Jul 30 12:12:55.506266 2026] [security2:error] [pid 703393:tid 703587] [client 20.203.156.12:40203] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/51.php"] [unique_id "amuGF8637Arlr6Yb1Ef97gAAAMU"]
[Thu Jul 30 12:12:55.863550 2026] [security2:error] [pid 703393:tid 703533] [client 20.203.156.12:52349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/50.php"] [unique_id "amuGF8637Arlr6Yb1Ef98gAAAI8"]
[Thu Jul 30 12:12:55.863670 2026] [security2:error] [pid 703393:tid 703533] [client 20.203.156.12:52349] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/50.php"] [unique_id "amuGF8637Arlr6Yb1Ef98gAAAI8"]
[Thu Jul 30 12:12:55.923122 2026] [security2:error] [pid 703393:tid 703561] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/reop3.php"] [unique_id "amuGF8637Arlr6Yb1Ef99gAAAKs"]
[Thu Jul 30 12:12:55.923246 2026] [security2:error] [pid 703393:tid 703561] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/reop3.php"] [unique_id "amuGF8637Arlr6Yb1Ef99gAAAKs"]
[Thu Jul 30 12:12:56.059966 2026] [security2:error] [pid 703393:tid 703626] [client 191.232.199.39:6877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/blog.php"] [unique_id "amuGGM637Arlr6Yb1Ef9-gAAAOw"]
[Thu Jul 30 12:12:56.368870 2026] [security2:error] [pid 703393:tid 703628] [client 172.236.9.101:38196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.env.bak"] [unique_id "amuGGM637Arlr6Yb1Ef9_gAAAO4"]
[Thu Jul 30 12:12:56.385294 2026] [security2:error] [pid 703393:tid 703622] [client 172.236.9.101:25133] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.env.backup"] [unique_id "amuGGM637Arlr6Yb1Ef-BAAAAOg"]
[Thu Jul 30 12:12:56.403047 2026] [security2:error] [pid 703393:tid 703550] [client 172.236.9.101:50835] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.env"] [unique_id "amuGGM637Arlr6Yb1Ef-BgAAAKA"]
[Thu Jul 30 12:12:56.406029 2026] [security2:error] [pid 703393:tid 703585] [client 172.236.9.101:64909] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.env.old"] [unique_id "amuGGM637Arlr6Yb1Ef-CQAAAMM"]
[Thu Jul 30 12:12:56.435150 2026] [security2:error] [pid 703393:tid 703543] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/h.php"] [unique_id "amuGGM637Arlr6Yb1Ef-DwAAAJk"]
[Thu Jul 30 12:12:56.435256 2026] [security2:error] [pid 703393:tid 703543] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/h.php"] [unique_id "amuGGM637Arlr6Yb1Ef-DwAAAJk"]
[Thu Jul 30 12:12:56.440484 2026] [security2:error] [pid 703393:tid 703545] [client 20.203.156.12:54465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/49.php"] [unique_id "amuGGM637Arlr6Yb1Ef-EAAAAJs"]
[Thu Jul 30 12:12:56.440670 2026] [security2:error] [pid 703393:tid 703545] [client 20.203.156.12:54465] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/49.php"] [unique_id "amuGGM637Arlr6Yb1Ef-EAAAAJs"]
[Thu Jul 30 12:12:56.576100 2026] [core:error] [pid 703393:tid 703562] [client 74.7.175.183:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:12:56.576135 2026] [core:error] [pid 703393:tid 703562] [client 74.7.175.183:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:12:56.576358 2026] [security2:error] [pid 703393:tid 703562] [client 74.7.175.183:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.pkv.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amuGGM637Arlr6Yb1Ef-GQAAAKw"]
[Thu Jul 30 12:12:56.577146 2026] [security2:error] [pid 703393:tid 703524] [client 74.7.175.183:34786] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.pkv.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amuGGM637Arlr6Yb1Ef-FwAAhmE"]
[Thu Jul 30 12:12:56.713398 2026] [security2:error] [pid 703393:tid 703623] [client 191.232.199.39:46495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/cong.php"] [unique_id "amuGGM637Arlr6Yb1Ef-GgAAAOk"]
[Thu Jul 30 12:12:56.883606 2026] [security2:error] [pid 703393:tid 703590] [client 20.203.156.12:52719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/48.php"] [unique_id "amuGGM637Arlr6Yb1Ef-GwAAAMg"]
[Thu Jul 30 12:12:56.883710 2026] [security2:error] [pid 703393:tid 703590] [client 20.203.156.12:52719] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/48.php"] [unique_id "amuGGM637Arlr6Yb1Ef-GwAAAMg"]
[Thu Jul 30 12:12:56.988986 2026] [security2:error] [pid 703393:tid 703601] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/2x.php"] [unique_id "amuGGM637Arlr6Yb1Ef-HQAAANM"]
[Thu Jul 30 12:12:56.989130 2026] [security2:error] [pid 703393:tid 703601] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/2x.php"] [unique_id "amuGGM637Arlr6Yb1Ef-HQAAANM"]
[Thu Jul 30 12:12:57.371363 2026] [security2:error] [pid 703393:tid 703631] [client 20.203.156.12:41580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/47.php"] [unique_id "amuGGc637Arlr6Yb1Ef-KAAAAPE"]
[Thu Jul 30 12:12:57.371600 2026] [security2:error] [pid 703393:tid 703631] [client 20.203.156.12:41580] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/47.php"] [unique_id "amuGGc637Arlr6Yb1Ef-KAAAAPE"]
[Thu Jul 30 12:12:57.506629 2026] [security2:error] [pid 703393:tid 703640] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/petx.php"] [unique_id "amuGGc637Arlr6Yb1Ef-LAAAAPo"]
[Thu Jul 30 12:12:57.506821 2026] [security2:error] [pid 703393:tid 703640] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/petx.php"] [unique_id "amuGGc637Arlr6Yb1Ef-LAAAAPo"]
[Thu Jul 30 12:12:57.564564 2026] [security2:error] [pid 703393:tid 703632] [client 172.236.9.101:5953] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGGM637Arlr6Yb1Ef9-wAAAPI"]
[Thu Jul 30 12:12:57.567030 2026] [security2:error] [pid 703393:tid 703535] [client 172.236.9.101:37057] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGGM637Arlr6Yb1Ef9_AAAAJE"]
[Thu Jul 30 12:12:57.567030 2026] [security2:error] [pid 703393:tid 703547] [client 172.236.9.101:28685] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGGM637Arlr6Yb1Ef-AQAAAJ0"]
[Thu Jul 30 12:12:57.581704 2026] [security2:error] [pid 703393:tid 703584] [client 172.236.9.101:22765] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGGM637Arlr6Yb1Ef-AwAAAMI"]
[Thu Jul 30 12:12:57.587358 2026] [security2:error] [pid 703393:tid 703583] [client 172.236.9.101:2014] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGGM637Arlr6Yb1Ef9_wAAAME"]
[Thu Jul 30 12:12:57.595707 2026] [security2:error] [pid 703393:tid 703586] [client 172.236.9.101:65064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGGM637Arlr6Yb1Ef9_QAAAMQ"]
[Thu Jul 30 12:12:57.599763 2026] [security2:error] [pid 703393:tid 703637] [client 172.236.9.101:25293] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGGM637Arlr6Yb1Ef-AgAAAPc"]
[Thu Jul 30 12:12:57.600663 2026] [security2:error] [pid 703393:tid 703552] [client 172.236.9.101:57331] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGGM637Arlr6Yb1Ef-AAAAAKI"]
[Thu Jul 30 12:12:57.611070 2026] [security2:error] [pid 703393:tid 703579] [client 172.236.9.101:21877] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGGM637Arlr6Yb1Ef-BwAAAL0"]
[Thu Jul 30 12:12:57.616583 2026] [security2:error] [pid 703393:tid 703617] [client 172.236.9.101:54969] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGGM637Arlr6Yb1Ef-BQAAAOM"]
[Thu Jul 30 12:12:57.626678 2026] [security2:error] [pid 703393:tid 703560] [client 172.236.9.101:31783] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGGM637Arlr6Yb1Ef-CAAAAKo"]
[Thu Jul 30 12:12:57.651356 2026] [security2:error] [pid 703393:tid 703555] [client 172.236.9.101:37981] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGGM637Arlr6Yb1Ef-DQAAAKU"]
[Thu Jul 30 12:12:57.652705 2026] [security2:error] [pid 703393:tid 703553] [client 172.236.9.101:22041] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGGM637Arlr6Yb1Ef-DAAAAKM"]
[Thu Jul 30 12:12:57.657112 2026] [security2:error] [pid 703393:tid 703612] [client 172.236.9.101:62889] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGGM637Arlr6Yb1Ef-CgAAAN4"]
[Thu Jul 30 12:12:57.668516 2026] [security2:error] [pid 703393:tid 703596] [client 172.236.9.101:22581] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGGM637Arlr6Yb1Ef-CwAAAM4"]
[Thu Jul 30 12:12:57.679708 2026] [security2:error] [pid 703393:tid 703645] [client 172.236.9.101:40809] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGGM637Arlr6Yb1Ef-DgAAAP8"]
[Thu Jul 30 12:12:57.767213 2026] [security2:error] [pid 703393:tid 703646] [client 20.203.156.12:40234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/46.php"] [unique_id "amuGGc637Arlr6Yb1Ef-MQAAAQA"]
[Thu Jul 30 12:12:57.767345 2026] [security2:error] [pid 703393:tid 703646] [client 20.203.156.12:40234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/46.php"] [unique_id "amuGGc637Arlr6Yb1Ef-MQAAAQA"]
[Thu Jul 30 12:12:57.991273 2026] [security2:error] [pid 703393:tid 703563] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/zxz.php"] [unique_id "amuGGc637Arlr6Yb1Ef-MgAAAK0"]
[Thu Jul 30 12:12:57.991386 2026] [security2:error] [pid 703393:tid 703563] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/zxz.php"] [unique_id "amuGGc637Arlr6Yb1Ef-MgAAAK0"]
[Thu Jul 30 12:12:58.172550 2026] [security2:error] [pid 703393:tid 703572] [client 20.203.156.12:52289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/44.php"] [unique_id "amuGGs637Arlr6Yb1Ef-OgAAALY"]
[Thu Jul 30 12:12:58.172652 2026] [security2:error] [pid 703393:tid 703572] [client 20.203.156.12:52289] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/44.php"] [unique_id "amuGGs637Arlr6Yb1Ef-OgAAALY"]
[Thu Jul 30 12:12:58.220091 2026] [security2:error] [pid 703393:tid 703633] [client 154.57.218.68:44211] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuGGs637Arlr6Yb1Ef-NgAA8zo"], referer: https://trello.com/
[Thu Jul 30 12:12:58.238681 2026] [autoindex:error] [pid 703393:tid 703605] [client 64.69.216.78:59076] AH01276: Cannot serve directory /home1/khwnyxte/arabiantourz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:12:58.376381 2026] [security2:error] [pid 703393:tid 703456] [remote 157.66.26.183:35136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "exploringchanges.com"] [uri "/wp-login.php"] [unique_id "amuGGs637Arlr6Yb1Ef-PQAAyj4"]
[Thu Jul 30 12:12:58.400532 2026] [security2:error] [pid 703393:tid 703634] [client 20.63.98.115:39206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/manager.php"] [unique_id "amuGGs637Arlr6Yb1Ef-PgAAAPQ"]
[Thu Jul 30 12:12:58.516272 2026] [security2:error] [pid 703393:tid 703571] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/2.php"] [unique_id "amuGGs637Arlr6Yb1Ef-PwAAALU"]
[Thu Jul 30 12:12:58.516446 2026] [security2:error] [pid 703393:tid 703571] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/2.php"] [unique_id "amuGGs637Arlr6Yb1Ef-PwAAALU"]
[Thu Jul 30 12:12:58.794681 2026] [security2:error] [pid 703393:tid 703582] [client 191.232.199.39:46469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/file4.php"] [unique_id "amuGGs637Arlr6Yb1Ef-RgAAAMA"]
[Thu Jul 30 12:12:59.065048 2026] [security2:error] [pid 703393:tid 703538] [client 191.232.199.39:6874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/ini.php"] [unique_id "amuGG8637Arlr6Yb1Ef-SgAAAJQ"]
[Thu Jul 30 12:12:59.065394 2026] [security2:error] [pid 703393:tid 703596] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/op.php"] [unique_id "amuGG8637Arlr6Yb1Ef-SwAAAM4"]
[Thu Jul 30 12:12:59.065464 2026] [security2:error] [pid 703393:tid 703596] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/op.php"] [unique_id "amuGG8637Arlr6Yb1Ef-SwAAAM4"]
[Thu Jul 30 12:12:59.106698 2026] [security2:error] [pid 703393:tid 703427] [remote 152.53.37.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.37.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oceanscout.com"] [uri "/wp-login.php"] [unique_id "amuGG8637Arlr6Yb1Ef-TgAAwSE"]
[Thu Jul 30 12:12:59.330313 2026] [security2:error] [pid 703393:tid 703645] [client 66.249.74.4:49030] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "abudhabifurnituremoverspackers.com"] [uri "/robots.txt"] [unique_id "amuGG8637Arlr6Yb1Ef-UgAAAP8"]
[Thu Jul 30 12:12:59.331120 2026] [security2:error] [pid 703393:tid 703647] [client 20.203.156.12:26114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/43.php"] [unique_id "amuGG8637Arlr6Yb1Ef-UwAAAQE"]
[Thu Jul 30 12:12:59.331202 2026] [security2:error] [pid 703393:tid 703647] [client 20.203.156.12:26114] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/43.php"] [unique_id "amuGG8637Arlr6Yb1Ef-UwAAAQE"]
[Thu Jul 30 12:12:59.576515 2026] [security2:error] [pid 703393:tid 703600] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/a5.php"] [unique_id "amuGG8637Arlr6Yb1Ef-VQAAANI"]
[Thu Jul 30 12:12:59.576668 2026] [security2:error] [pid 703393:tid 703600] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/a5.php"] [unique_id "amuGG8637Arlr6Yb1Ef-VQAAANI"]
[Thu Jul 30 12:12:59.747304 2026] [security2:error] [pid 703393:tid 703555] [client 20.63.98.115:21253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-links.php"] [unique_id "amuGG8637Arlr6Yb1Ef-YQAAAKU"]
[Thu Jul 30 12:12:59.760630 2026] [security2:error] [pid 703393:tid 703528] [client 20.203.156.12:26045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/42.php"] [unique_id "amuGG8637Arlr6Yb1Ef-YgAAAIo"]
[Thu Jul 30 12:12:59.760717 2026] [security2:error] [pid 703393:tid 703528] [client 20.203.156.12:26045] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/42.php"] [unique_id "amuGG8637Arlr6Yb1Ef-YgAAAIo"]
[Thu Jul 30 12:13:00.079588 2026] [security2:error] [pid 703393:tid 703534] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/ws80.php"] [unique_id "amuGHM637Arlr6Yb1Ef-ZwAAAJA"]
[Thu Jul 30 12:13:00.079695 2026] [security2:error] [pid 703393:tid 703534] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/ws80.php"] [unique_id "amuGHM637Arlr6Yb1Ef-ZwAAAJA"]
[Thu Jul 30 12:13:00.102828 2026] [security2:error] [pid 703393:tid 703614] [client 20.203.156.12:54503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/41.php"] [unique_id "amuGHM637Arlr6Yb1Ef-aAAAAOA"]
[Thu Jul 30 12:13:00.102917 2026] [security2:error] [pid 703393:tid 703614] [client 20.203.156.12:54503] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/41.php"] [unique_id "amuGHM637Arlr6Yb1Ef-aAAAAOA"]
[Thu Jul 30 12:13:00.183859 2026] [security2:error] [pid 703393:tid 703563] [client 191.232.199.39:46488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/flower.php"] [unique_id "amuGHM637Arlr6Yb1Ef-bAAAAK0"]
[Thu Jul 30 12:13:00.332795 2026] [autoindex:error] [pid 703393:tid 703604] [client 64.69.216.78:59142] AH01276: Cannot serve directory /home1/khwnyxte/arabiantourz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:13:00.496237 2026] [core:notice] [pid 703393:tid 703635] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:00.503611 2026] [security2:error] [pid 703393:tid 703635] [client 103.215.74.26:50216] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGHM637Arlr6Yb1Ef-dAAAAPU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:00.530149 2026] [security2:error] [pid 703393:tid 703549] [client 66.249.73.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shop-kent.com"] [uri "/index.php"] [unique_id "amuGG8637Arlr6Yb1Ef-XQAAAJ8"]
[Thu Jul 30 12:13:00.608810 2026] [security2:error] [pid 703393:tid 703545] [client 20.203.156.12:47527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/40.php"] [unique_id "amuGHM637Arlr6Yb1Ef-dgAAAJs"]
[Thu Jul 30 12:13:00.608924 2026] [security2:error] [pid 703393:tid 703545] [client 20.203.156.12:47527] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/40.php"] [unique_id "amuGHM637Arlr6Yb1Ef-dgAAAJs"]
[Thu Jul 30 12:13:00.616964 2026] [security2:error] [pid 703393:tid 703582] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/xa.php"] [unique_id "amuGHM637Arlr6Yb1Ef-dwAAAMA"]
[Thu Jul 30 12:13:00.617080 2026] [security2:error] [pid 703393:tid 703582] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/xa.php"] [unique_id "amuGHM637Arlr6Yb1Ef-dwAAAMA"]
[Thu Jul 30 12:13:00.632150 2026] [security2:error] [pid 703393:tid 703540] [client 20.63.98.115:21288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/fi2.php"] [unique_id "amuGHM637Arlr6Yb1Ef-eAAAAJY"]
[Thu Jul 30 12:13:00.937349 2026] [security2:error] [pid 703393:tid 703629] [client 191.232.199.39:60739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/admin-ajax.php"] [unique_id "amuGHM637Arlr6Yb1Ef-ggAAAO8"]
[Thu Jul 30 12:13:01.128998 2026] [security2:error] [pid 703393:tid 703590] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/asd67.php"] [unique_id "amuGHc637Arlr6Yb1Ef-gwAAAMg"]
[Thu Jul 30 12:13:01.129109 2026] [security2:error] [pid 703393:tid 703590] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/asd67.php"] [unique_id "amuGHc637Arlr6Yb1Ef-gwAAAMg"]
[Thu Jul 30 12:13:01.167535 2026] [security2:error] [pid 703393:tid 703568] [client 74.7.241.163:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.mskabir.com"] [uri "/index.php"] [unique_id "amuGG8637Arlr6Yb1Ef-YwAAsjQ"]
[Thu Jul 30 12:13:01.167563 2026] [security2:error] [pid 703393:tid 703568] [client 74.7.241.163:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mskabir.com"] [uri "/index.php"] [unique_id "amuGG8637Arlr6Yb1Ef-YwAAsjQ"]
[Thu Jul 30 12:13:01.227664 2026] [security2:error] [pid 703393:tid 703558] [client 20.203.156.12:33855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/39.php"] [unique_id "amuGHc637Arlr6Yb1Ef-iQAAAKg"]
[Thu Jul 30 12:13:01.227750 2026] [security2:error] [pid 703393:tid 703558] [client 20.203.156.12:33855] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/39.php"] [unique_id "amuGHc637Arlr6Yb1Ef-iQAAAKg"]
[Thu Jul 30 12:13:01.273127 2026] [core:notice] [pid 703393:tid 703623] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:01.279545 2026] [security2:error] [pid 703393:tid 703623] [client 103.215.74.26:50230] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGHc637Arlr6Yb1Ef-iwAAAOk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:01.516540 2026] [security2:error] [pid 703393:tid 703555] [client 191.232.199.39:46477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/form.php"] [unique_id "amuGHc637Arlr6Yb1Ef-kAAAAKU"]
[Thu Jul 30 12:13:01.616791 2026] [security2:error] [pid 703393:tid 703611] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/bk.php"] [unique_id "amuGHc637Arlr6Yb1Ef-kgAAAN0"]
[Thu Jul 30 12:13:01.616893 2026] [security2:error] [pid 703393:tid 703611] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/bk.php"] [unique_id "amuGHc637Arlr6Yb1Ef-kgAAAN0"]
[Thu Jul 30 12:13:01.782874 2026] [security2:error] [pid 703393:tid 703584] [client 20.203.156.12:47522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/38.php"] [unique_id "amuGHc637Arlr6Yb1Ef-mgAAAMI"]
[Thu Jul 30 12:13:01.782987 2026] [security2:error] [pid 703393:tid 703584] [client 20.203.156.12:47522] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/38.php"] [unique_id "amuGHc637Arlr6Yb1Ef-mgAAAMI"]
[Thu Jul 30 12:13:01.996226 2026] [core:notice] [pid 703393:tid 703567] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:02.005312 2026] [security2:error] [pid 703393:tid 703567] [client 103.215.74.26:50238] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGHc637Arlr6Yb1Ef-mwAAALE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:02.099543 2026] [security2:error] [pid 703393:tid 703646] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-links.php"] [unique_id "amuGHs637Arlr6Yb1Ef-nQAAAQA"]
[Thu Jul 30 12:13:02.099688 2026] [security2:error] [pid 703393:tid 703646] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-links.php"] [unique_id "amuGHs637Arlr6Yb1Ef-nQAAAQA"]
[Thu Jul 30 12:13:02.271334 2026] [security2:error] [pid 703393:tid 703546] [client 74.7.241.163:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mskabir.com"] [uri "/index.php"] [unique_id "amuGHs637Arlr6Yb1Ef-ngAAnEk"], referer: https://www.mskabir.com/robots.txt
[Thu Jul 30 12:13:02.283025 2026] [security2:error] [pid 703393:tid 703618] [client 20.203.156.12:47430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/37.php"] [unique_id "amuGHs637Arlr6Yb1Ef-pQAAAOQ"]
[Thu Jul 30 12:13:02.283147 2026] [security2:error] [pid 703393:tid 703618] [client 20.203.156.12:47430] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/37.php"] [unique_id "amuGHs637Arlr6Yb1Ef-pQAAAOQ"]
[Thu Jul 30 12:13:02.363593 2026] [security2:error] [pid 703393:tid 703579] [client 191.232.199.39:6880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/akc.php"] [unique_id "amuGHs637Arlr6Yb1Ef-pwAAAL0"]
[Thu Jul 30 12:13:02.582884 2026] [security2:error] [pid 703393:tid 703528] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/mosty.php"] [unique_id "amuGHs637Arlr6Yb1Ef-qAAAAIo"]
[Thu Jul 30 12:13:02.583005 2026] [security2:error] [pid 703393:tid 703528] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/mosty.php"] [unique_id "amuGHs637Arlr6Yb1Ef-qAAAAIo"]
[Thu Jul 30 12:13:02.716125 2026] [core:notice] [pid 703393:tid 703559] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:02.724213 2026] [security2:error] [pid 703393:tid 703559] [client 103.215.74.26:50242] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGHs637Arlr6Yb1Ef-rAAAAKk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:02.896700 2026] [security2:error] [pid 703393:tid 703636] [client 20.203.156.12:56139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/36.php"] [unique_id "amuGHs637Arlr6Yb1Ef-sQAAAPY"]
[Thu Jul 30 12:13:02.896822 2026] [security2:error] [pid 703393:tid 703636] [client 20.203.156.12:56139] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/36.php"] [unique_id "amuGHs637Arlr6Yb1Ef-sQAAAPY"]
[Thu Jul 30 12:13:03.070359 2026] [security2:error] [pid 703393:tid 703531] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/sump3.php"] [unique_id "amuGH8637Arlr6Yb1Ef-sgAAAI0"]
[Thu Jul 30 12:13:03.070462 2026] [security2:error] [pid 703393:tid 703531] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/sump3.php"] [unique_id "amuGH8637Arlr6Yb1Ef-sgAAAI0"]
[Thu Jul 30 12:13:03.231280 2026] [security2:error] [pid 703393:tid 703560] [client 20.203.156.12:56178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/35.php"] [unique_id "amuGH8637Arlr6Yb1Ef-tQAAAKo"]
[Thu Jul 30 12:13:03.231383 2026] [security2:error] [pid 703393:tid 703560] [client 20.203.156.12:56178] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/35.php"] [unique_id "amuGH8637Arlr6Yb1Ef-tQAAAKo"]
[Thu Jul 30 12:13:03.387095 2026] [security2:error] [pid 703393:tid 703606] [client 191.232.199.39:46479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/gecko.php"] [unique_id "amuGH8637Arlr6Yb1Ef-uwAAANg"]
[Thu Jul 30 12:13:03.423004 2026] [security2:error] [pid 703393:tid 703635] [client 20.63.98.115:21313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/0x.php"] [unique_id "amuGH8637Arlr6Yb1Ef-vgAAAPU"]
[Thu Jul 30 12:13:03.457692 2026] [core:notice] [pid 703393:tid 703525] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:03.464082 2026] [security2:error] [pid 703393:tid 703525] [client 103.215.74.26:20782] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGH8637Arlr6Yb1Ef-vwAAAIc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:03.556178 2026] [security2:error] [pid 703393:tid 703581] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/first.php"] [unique_id "amuGH8637Arlr6Yb1Ef-wAAAAL8"]
[Thu Jul 30 12:13:03.556293 2026] [security2:error] [pid 703393:tid 703581] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/first.php"] [unique_id "amuGH8637Arlr6Yb1Ef-wAAAAL8"]
[Thu Jul 30 12:13:03.565247 2026] [security2:error] [pid 703393:tid 703600] [client 20.203.156.12:56165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/34.php"] [unique_id "amuGH8637Arlr6Yb1Ef-wQAAANI"]
[Thu Jul 30 12:13:03.565330 2026] [security2:error] [pid 703393:tid 703600] [client 20.203.156.12:56165] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/34.php"] [unique_id "amuGH8637Arlr6Yb1Ef-wQAAANI"]
[Thu Jul 30 12:13:03.873015 2026] [security2:error] [pid 703393:tid 703595] [client 191.232.199.39:6856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/akcc.php"] [unique_id "amuGH8637Arlr6Yb1Ef-yQAAAM0"]
[Thu Jul 30 12:13:03.964965 2026] [security2:error] [pid 703393:tid 703614] [client 20.203.156.12:44337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/33.php"] [unique_id "amuGH8637Arlr6Yb1Ef-ygAAAOA"]
[Thu Jul 30 12:13:03.965098 2026] [security2:error] [pid 703393:tid 703614] [client 20.203.156.12:44337] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/33.php"] [unique_id "amuGH8637Arlr6Yb1Ef-ygAAAOA"]
[Thu Jul 30 12:13:04.057432 2026] [security2:error] [pid 703393:tid 703602] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/acp.php"] [unique_id "amuGIM637Arlr6Yb1Ef-ywAAANQ"]
[Thu Jul 30 12:13:04.057560 2026] [security2:error] [pid 703393:tid 703602] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/acp.php"] [unique_id "amuGIM637Arlr6Yb1Ef-ywAAANQ"]
[Thu Jul 30 12:13:04.079303 2026] [security2:error] [pid 703393:tid 703639] [client 109.172.91.206:56422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.91.172.109.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.remoteworksit.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuGIM637Arlr6Yb1Ef-zAAAAPk"], referer: https://www.remoteworksit.com/contact-us/
[Thu Jul 30 12:13:04.191704 2026] [core:notice] [pid 703393:tid 703634] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:04.197831 2026] [security2:error] [pid 703393:tid 703634] [client 103.215.74.26:20796] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGIM637Arlr6Yb1Ef-zgAAAPQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:04.238238 2026] [security2:error] [pid 703393:tid 703621] [client 20.203.156.12:41547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/25.php"] [unique_id "amuGIM637Arlr6Yb1Ef-zwAAAOc"]
[Thu Jul 30 12:13:04.238356 2026] [security2:error] [pid 703393:tid 703621] [client 20.203.156.12:41547] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/25.php"] [unique_id "amuGIM637Arlr6Yb1Ef-zwAAAOc"]
[Thu Jul 30 12:13:04.394263 2026] [security2:error] [pid 703393:tid 703523] [client 20.63.98.115:36889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/k.php"] [unique_id "amuGIM637Arlr6Yb1Ef-1gAAAIU"]
[Thu Jul 30 12:13:04.523363 2026] [security2:error] [pid 703393:tid 703584] [client 20.203.156.12:60449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/24.php"] [unique_id "amuGIM637Arlr6Yb1Ef-1wAAAMI"]
[Thu Jul 30 12:13:04.523469 2026] [security2:error] [pid 703393:tid 703584] [client 20.203.156.12:60449] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/24.php"] [unique_id "amuGIM637Arlr6Yb1Ef-1wAAAMI"]
[Thu Jul 30 12:13:04.536121 2026] [security2:error] [pid 703393:tid 703574] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-good.php"] [unique_id "amuGIM637Arlr6Yb1Ef-2AAAALg"]
[Thu Jul 30 12:13:04.536199 2026] [security2:error] [pid 703393:tid 703574] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-good.php"] [unique_id "amuGIM637Arlr6Yb1Ef-2AAAALg"]
[Thu Jul 30 12:13:04.845820 2026] [security2:error] [pid 703393:tid 703607] [client 20.203.156.12:47940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/15.php"] [unique_id "amuGIM637Arlr6Yb1Ef-3wAAANk"]
[Thu Jul 30 12:13:04.845921 2026] [security2:error] [pid 703393:tid 703607] [client 20.203.156.12:47940] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/15.php"] [unique_id "amuGIM637Arlr6Yb1Ef-3wAAANk"]
[Thu Jul 30 12:13:04.912569 2026] [core:notice] [pid 703393:tid 703582] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:04.918837 2026] [security2:error] [pid 703393:tid 703582] [client 103.215.74.26:20798] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGIM637Arlr6Yb1Ef-5gAAAMA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:05.029088 2026] [security2:error] [pid 703393:tid 703526] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/daerl3.php"] [unique_id "amuGIc637Arlr6Yb1Ef-6AAAAIg"]
[Thu Jul 30 12:13:05.029194 2026] [security2:error] [pid 703393:tid 703526] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/daerl3.php"] [unique_id "amuGIc637Arlr6Yb1Ef-6AAAAIg"]
[Thu Jul 30 12:13:05.224517 2026] [security2:error] [pid 703393:tid 703645] [client 20.63.98.115:49238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/gecko-new.php"] [unique_id "amuGIc637Arlr6Yb1Ef-6QAAAP8"]
[Thu Jul 30 12:13:05.298407 2026] [security2:error] [pid 703393:tid 703573] [client 20.203.156.12:44347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/123456.php"] [unique_id "amuGIc637Arlr6Yb1Ef-6gAAALc"]
[Thu Jul 30 12:13:05.298509 2026] [security2:error] [pid 703393:tid 703573] [client 20.203.156.12:44347] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/123456.php"] [unique_id "amuGIc637Arlr6Yb1Ef-6gAAALc"]
[Thu Jul 30 12:13:05.489781 2026] [core:notice] [pid 703393:tid 703557] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:05.506498 2026] [security2:error] [pid 703393:tid 703561] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/php5.php"] [unique_id "amuGIc637Arlr6Yb1Ef-8wAAAKs"]
[Thu Jul 30 12:13:05.506581 2026] [security2:error] [pid 703393:tid 703561] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/php5.php"] [unique_id "amuGIc637Arlr6Yb1Ef-8wAAAKs"]
[Thu Jul 30 12:13:05.643085 2026] [core:notice] [pid 703393:tid 703633] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:05.649429 2026] [security2:error] [pid 703393:tid 703633] [client 103.215.74.26:20804] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGIc637Arlr6Yb1Ef-9AAAAPM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:05.912021 2026] [security2:error] [pid 703393:tid 703632] [client 20.203.156.12:47441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/12345.php"] [unique_id "amuGIc637Arlr6Yb1Ef--QAAAPI"]
[Thu Jul 30 12:13:05.912139 2026] [security2:error] [pid 703393:tid 703632] [client 20.203.156.12:47441] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/12345.php"] [unique_id "amuGIc637Arlr6Yb1Ef--QAAAPI"]
[Thu Jul 30 12:13:06.007774 2026] [security2:error] [pid 703393:tid 703535] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/xoot.php"] [unique_id "amuGIs637Arlr6Yb1Ef-_QAAAJE"]
[Thu Jul 30 12:13:06.007875 2026] [security2:error] [pid 703393:tid 703535] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/xoot.php"] [unique_id "amuGIs637Arlr6Yb1Ef-_QAAAJE"]
[Thu Jul 30 12:13:06.310695 2026] [security2:error] [pid 703393:tid 703622] [client 20.203.156.12:56154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/1234.php"] [unique_id "amuGIs637Arlr6Yb1Ef-_wAAAOg"]
[Thu Jul 30 12:13:06.310877 2026] [security2:error] [pid 703393:tid 703622] [client 20.203.156.12:56154] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/1234.php"] [unique_id "amuGIs637Arlr6Yb1Ef-_wAAAOg"]
[Thu Jul 30 12:13:06.394704 2026] [core:notice] [pid 703393:tid 703523] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:06.401130 2026] [security2:error] [pid 703393:tid 703523] [client 103.215.74.26:20816] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGIs637Arlr6Yb1Ef_AwAAAIU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:06.533890 2026] [security2:error] [pid 703393:tid 703646] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/clxcc.php"] [unique_id "amuGIs637Arlr6Yb1Ef_CAAAAQA"]
[Thu Jul 30 12:13:06.534025 2026] [security2:error] [pid 703393:tid 703646] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/clxcc.php"] [unique_id "amuGIs637Arlr6Yb1Ef_CAAAAQA"]
[Thu Jul 30 12:13:06.549083 2026] [security2:error] [pid 703393:tid 703584] [client 43.173.179.190:56350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dlr.djb.temporary.site"] [uri "/index.php"] [unique_id "amuGIs637Arlr6Yb1Ef-_gAAAMI"]
[Thu Jul 30 12:13:06.788224 2026] [security2:error] [pid 703393:tid 703607] [client 20.203.156.12:60473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/10.php"] [unique_id "amuGIs637Arlr6Yb1Ef_CQAAANk"]
[Thu Jul 30 12:13:06.788369 2026] [security2:error] [pid 703393:tid 703607] [client 20.203.156.12:60473] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/10.php"] [unique_id "amuGIs637Arlr6Yb1Ef_CQAAANk"]
[Thu Jul 30 12:13:07.024358 2026] [security2:error] [pid 703393:tid 703526] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/ai.php"] [unique_id "amuGI8637Arlr6Yb1Ef_EAAAAIg"]
[Thu Jul 30 12:13:07.024491 2026] [security2:error] [pid 703393:tid 703526] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/ai.php"] [unique_id "amuGI8637Arlr6Yb1Ef_EAAAAIg"]
[Thu Jul 30 12:13:07.131849 2026] [core:notice] [pid 703393:tid 703615] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:07.138294 2026] [security2:error] [pid 703393:tid 703615] [client 103.215.74.26:20832] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGI8637Arlr6Yb1Ef_EQAAAOE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:07.513227 2026] [security2:error] [pid 703393:tid 703563] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/nwflm.php"] [unique_id "amuGI8637Arlr6Yb1Ef_HQAAAK0"]
[Thu Jul 30 12:13:07.513351 2026] [security2:error] [pid 703393:tid 703563] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/nwflm.php"] [unique_id "amuGI8637Arlr6Yb1Ef_HQAAAK0"]
[Thu Jul 30 12:13:07.609794 2026] [security2:error] [pid 703393:tid 703537] [client 191.232.199.39:46466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/kyami.php"] [unique_id "amuGI8637Arlr6Yb1Ef_HwAAAJM"]
[Thu Jul 30 12:13:07.883551 2026] [core:notice] [pid 703393:tid 703619] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:07.889842 2026] [security2:error] [pid 703393:tid 703619] [client 103.215.74.26:20836] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGI8637Arlr6Yb1Ef_JwAAAOU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:08.002767 2026] [security2:error] [pid 703393:tid 703545] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/hypo.php"] [unique_id "amuGJM637Arlr6Yb1Ef_KwAAAJs"]
[Thu Jul 30 12:13:08.002867 2026] [security2:error] [pid 703393:tid 703545] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/hypo.php"] [unique_id "amuGJM637Arlr6Yb1Ef_KwAAAJs"]
[Thu Jul 30 12:13:08.064601 2026] [security2:error] [pid 703393:tid 703624] [client 20.63.98.115:57171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/alfanew.php"] [unique_id "amuGJM637Arlr6Yb1Ef_LwAAAOo"]
[Thu Jul 30 12:13:08.095957 2026] [security2:error] [pid 703393:tid 703561] [client 185.191.171.17:59064] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/10/26/tre-pb-cassa-chapa-de-vereadores-de-cubati-por-fraude-a-cota-de-genero/"] [unique_id "amuGJM637Arlr6Yb1Ef_MAAAAKs"]
[Thu Jul 30 12:13:08.096077 2026] [security2:error] [pid 703393:tid 703561] [client 185.191.171.17:59064] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/10/26/tre-pb-cassa-chapa-de-vereadores-de-cubati-por-fraude-a-cota-de-genero/"] [unique_id "amuGJM637Arlr6Yb1Ef_MAAAAKs"]
[Thu Jul 30 12:13:08.270504 2026] [core:notice] [pid 703393:tid 703403] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:08.311447 2026] [security2:error] [pid 703393:tid 703565] [client 20.91.140.156:29859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/opts.php"] [unique_id "amuGJM637Arlr6Yb1Ef_MwAAAK8"]
[Thu Jul 30 12:13:08.311549 2026] [security2:error] [pid 703393:tid 703565] [client 20.91.140.156:29859] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/opts.php"] [unique_id "amuGJM637Arlr6Yb1Ef_MwAAAK8"]
[Thu Jul 30 12:13:08.333764 2026] [core:error] [pid 703393:tid 703584] [client 66.249.74.108:43735] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:13:08.333789 2026] [core:error] [pid 703393:tid 703584] [client 66.249.74.108:43735] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:13:08.487401 2026] [security2:error] [pid 703393:tid 703618] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/w3llscc.php"] [unique_id "amuGJM637Arlr6Yb1Ef_OAAAAOQ"]
[Thu Jul 30 12:13:08.487508 2026] [security2:error] [pid 703393:tid 703618] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/w3llscc.php"] [unique_id "amuGJM637Arlr6Yb1Ef_OAAAAOQ"]
[Thu Jul 30 12:13:08.620089 2026] [core:notice] [pid 703393:tid 703583] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:08.626385 2026] [security2:error] [pid 703393:tid 703583] [client 103.215.74.26:20846] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGJM637Arlr6Yb1Ef_PAAAAME"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:08.690026 2026] [security2:error] [pid 703393:tid 703551] [client 20.91.140.156:29852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/filer.php"] [unique_id "amuGJM637Arlr6Yb1Ef_PQAAAKE"]
[Thu Jul 30 12:13:08.690126 2026] [security2:error] [pid 703393:tid 703551] [client 20.91.140.156:29852] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/filer.php"] [unique_id "amuGJM637Arlr6Yb1Ef_PQAAAKE"]
[Thu Jul 30 12:13:09.028709 2026] [security2:error] [pid 703393:tid 703621] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/11PJcpMFsD8B.php"] [unique_id "amuGJc637Arlr6Yb1Ef_QgAAAOc"]
[Thu Jul 30 12:13:09.028799 2026] [security2:error] [pid 703393:tid 703621] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/11PJcpMFsD8B.php"] [unique_id "amuGJc637Arlr6Yb1Ef_QgAAAOc"]
[Thu Jul 30 12:13:09.041885 2026] [security2:error] [pid 703393:tid 703611] [client 191.232.199.39:46517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/manager.php"] [unique_id "amuGJc637Arlr6Yb1Ef_RAAAAN0"]
[Thu Jul 30 12:13:09.070926 2026] [security2:error] [pid 703393:tid 703554] [client 20.91.140.156:32219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/lites.php"] [unique_id "amuGJc637Arlr6Yb1Ef_RwAAAKQ"]
[Thu Jul 30 12:13:09.071090 2026] [security2:error] [pid 703393:tid 703554] [client 20.91.140.156:32219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/lites.php"] [unique_id "amuGJc637Arlr6Yb1Ef_RwAAAKQ"]
[Thu Jul 30 12:13:09.192420 2026] [security2:error] [pid 703393:tid 703563] [client 20.63.98.115:64894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/text.php"] [unique_id "amuGJc637Arlr6Yb1Ef_SAAAAK0"]
[Thu Jul 30 12:13:09.362126 2026] [core:notice] [pid 703393:tid 703627] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:09.368877 2026] [security2:error] [pid 703393:tid 703627] [client 103.215.74.26:20860] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGJc637Arlr6Yb1Ef_SgAAAO0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:09.387460 2026] [core:notice] [pid 703393:tid 703501] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:09.562667 2026] [security2:error] [pid 703393:tid 703637] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/8.php"] [unique_id "amuGJc637Arlr6Yb1Ef_UAAAAPc"]
[Thu Jul 30 12:13:09.562756 2026] [security2:error] [pid 703393:tid 703637] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/8.php"] [unique_id "amuGJc637Arlr6Yb1Ef_UAAAAPc"]
[Thu Jul 30 12:13:09.577226 2026] [security2:error] [pid 703393:tid 703417] [remote 74.7.241.59:48960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuGJc637Arlr6Yb1Ef_UwAAoBc"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/premium-addons-for-elementor/modules/woocommerce/templates
[Thu Jul 30 12:13:09.613160 2026] [security2:error] [pid 703393:tid 703561] [client 20.91.140.156:32808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/0x.php"] [unique_id "amuGJc637Arlr6Yb1Ef_VQAAAKs"]
[Thu Jul 30 12:13:09.613277 2026] [security2:error] [pid 703393:tid 703561] [client 20.91.140.156:32808] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/0x.php"] [unique_id "amuGJc637Arlr6Yb1Ef_VQAAAKs"]
[Thu Jul 30 12:13:09.780632 2026] [security2:error] [pid 703393:tid 703537] [client 94.103.90.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuGJc637Arlr6Yb1Ef_QQAAk2I"], referer: https://allmontecristi.com/5-important-characteristics-to-identify-an-export-panama-hat/?srsltid=afmbooobpjslvy1dcritpm3oyoloutbopk2q0t238sboel09-jvs0f2z
[Thu Jul 30 12:13:09.993267 2026] [security2:error] [pid 703393:tid 703582] [client 20.91.140.156:32192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/bless3.php"] [unique_id "amuGJc637Arlr6Yb1Ef_WgAAAMA"]
[Thu Jul 30 12:13:09.993374 2026] [security2:error] [pid 703393:tid 703582] [client 20.91.140.156:32192] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/bless3.php"] [unique_id "amuGJc637Arlr6Yb1Ef_WgAAAMA"]
[Thu Jul 30 12:13:10.084272 2026] [security2:error] [pid 703393:tid 703536] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/fnstall.php"] [unique_id "amuGJs637Arlr6Yb1Ef_XgAAAJI"]
[Thu Jul 30 12:13:10.084367 2026] [security2:error] [pid 703393:tid 703536] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/fnstall.php"] [unique_id "amuGJs637Arlr6Yb1Ef_XgAAAJI"]
[Thu Jul 30 12:13:10.102893 2026] [core:notice] [pid 703393:tid 703565] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:10.109081 2026] [security2:error] [pid 703393:tid 703565] [client 103.215.74.26:20868] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGJs637Arlr6Yb1Ef_XwAAAK8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:10.140433 2026] [security2:error] [pid 703393:tid 703597] [client 20.63.98.115:62421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/f.php"] [unique_id "amuGJs637Arlr6Yb1Ef_YwAAAM8"]
[Thu Jul 30 12:13:10.295266 2026] [security2:error] [pid 703393:tid 703453] [remote 47.128.118.133:28824] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "womenclothingbox.com"] [uri "/blog/"] [unique_id "amuGJs637Arlr6Yb1Ef_ZAAAujs"]
[Thu Jul 30 12:13:10.397145 2026] [security2:error] [pid 703393:tid 703556] [client 191.232.199.39:46483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/mari.php"] [unique_id "amuGJs637Arlr6Yb1Ef_ZQAAAKY"]
[Thu Jul 30 12:13:10.449438 2026] [security2:error] [pid 703393:tid 703591] [client 20.91.140.156:38837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/wsd.php"] [unique_id "amuGJs637Arlr6Yb1Ef_ZgAAAMk"]
[Thu Jul 30 12:13:10.449534 2026] [security2:error] [pid 703393:tid 703591] [client 20.91.140.156:38837] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/wsd.php"] [unique_id "amuGJs637Arlr6Yb1Ef_ZgAAAMk"]
[Thu Jul 30 12:13:10.578073 2026] [security2:error] [pid 703393:tid 703559] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/edorxrr.php"] [unique_id "amuGJs637Arlr6Yb1Ef_aAAAAKk"]
[Thu Jul 30 12:13:10.578168 2026] [security2:error] [pid 703393:tid 703559] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/edorxrr.php"] [unique_id "amuGJs637Arlr6Yb1Ef_aAAAAKk"]
[Thu Jul 30 12:13:10.784995 2026] [security2:error] [pid 703393:tid 703611] [client 20.91.140.156:32794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/f6.php"] [unique_id "amuGJs637Arlr6Yb1Ef_bwAAAN0"]
[Thu Jul 30 12:13:10.785099 2026] [security2:error] [pid 703393:tid 703611] [client 20.91.140.156:32794] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/f6.php"] [unique_id "amuGJs637Arlr6Yb1Ef_bwAAAN0"]
[Thu Jul 30 12:13:10.831536 2026] [core:notice] [pid 703393:tid 703630] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:10.837782 2026] [security2:error] [pid 703393:tid 703630] [client 103.215.74.26:20882] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGJs637Arlr6Yb1Ef_cQAAAPA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:11.061535 2026] [security2:error] [pid 703393:tid 703585] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/setup.php"] [unique_id "amuGJ8637Arlr6Yb1Ef_dQAAAMM"]
[Thu Jul 30 12:13:11.061648 2026] [security2:error] [pid 703393:tid 703585] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/setup.php"] [unique_id "amuGJ8637Arlr6Yb1Ef_dQAAAMM"]
[Thu Jul 30 12:13:11.148562 2026] [security2:error] [pid 703393:tid 703560] [client 20.91.140.156:38819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/he.php"] [unique_id "amuGJ8637Arlr6Yb1Ef_eQAAAKo"]
[Thu Jul 30 12:13:11.148655 2026] [security2:error] [pid 703393:tid 703560] [client 20.91.140.156:38819] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/he.php"] [unique_id "amuGJ8637Arlr6Yb1Ef_eQAAAKo"]
[Thu Jul 30 12:13:11.354069 2026] [security2:error] [pid 703393:tid 703424] [remote 74.7.241.60:34174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/article.php"] [unique_id "amuGJ8637Arlr6Yb1Ef_fgAAhR4"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/main_image_6a3229a631e84.jpg
[Thu Jul 30 12:13:11.530164 2026] [security2:error] [pid 703393:tid 703606] [client 20.91.140.156:38825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/aves.php"] [unique_id "amuGJ8637Arlr6Yb1Ef_fwAAANg"]
[Thu Jul 30 12:13:11.530277 2026] [security2:error] [pid 703393:tid 703606] [client 20.91.140.156:38825] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/aves.php"] [unique_id "amuGJ8637Arlr6Yb1Ef_fwAAANg"]
[Thu Jul 30 12:13:11.552796 2026] [core:notice] [pid 703393:tid 703566] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:11.559429 2026] [security2:error] [pid 703393:tid 703566] [client 103.215.74.26:20884] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGJ8637Arlr6Yb1Ef_gAAAALA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:11.581129 2026] [security2:error] [pid 703393:tid 703552] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/6.php"] [unique_id "amuGJ8637Arlr6Yb1Ef_gQAAAKI"]
[Thu Jul 30 12:13:11.581232 2026] [security2:error] [pid 703393:tid 703552] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/6.php"] [unique_id "amuGJ8637Arlr6Yb1Ef_gQAAAKI"]
[Thu Jul 30 12:13:11.628737 2026] [security2:error] [pid 703393:tid 703650] [client 20.215.216.94:35295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuGJ8637Arlr6Yb1Ef_gwAAAQQ"]
[Thu Jul 30 12:13:11.628847 2026] [security2:error] [pid 703393:tid 703650] [client 20.215.216.94:35295] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuGJ8637Arlr6Yb1Ef_gwAAAQQ"]
[Thu Jul 30 12:13:11.633792 2026] [security2:error] [pid 703393:tid 703539] [client 20.63.98.115:57161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amuGJ8637Arlr6Yb1Ef_hQAAAJU"]
[Thu Jul 30 12:13:11.876028 2026] [security2:error] [pid 703393:tid 703605] [client 20.91.140.156:32201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "amuGJ8637Arlr6Yb1Ef_jAAAANc"]
[Thu Jul 30 12:13:11.876125 2026] [security2:error] [pid 703393:tid 703605] [client 20.91.140.156:32201] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "amuGJ8637Arlr6Yb1Ef_jAAAANc"]
[Thu Jul 30 12:13:11.938742 2026] [security2:error] [pid 703393:tid 703641] [client 191.232.199.39:6862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/asasx.php"] [unique_id "amuGJ8637Arlr6Yb1Ef_jwAAAPs"]
[Thu Jul 30 12:13:12.088865 2026] [security2:error] [pid 703393:tid 703528] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/w3lls.php"] [unique_id "amuGKM637Arlr6Yb1Ef_kAAAAIo"]
[Thu Jul 30 12:13:12.088972 2026] [security2:error] [pid 703393:tid 703528] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/w3lls.php"] [unique_id "amuGKM637Arlr6Yb1Ef_kAAAAIo"]
[Thu Jul 30 12:13:12.212036 2026] [security2:error] [pid 703393:tid 703634] [client 20.91.140.156:39458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/gorila.php"] [unique_id "amuGKM637Arlr6Yb1Ef_lwAAAPQ"]
[Thu Jul 30 12:13:12.212123 2026] [security2:error] [pid 703393:tid 703634] [client 20.91.140.156:39458] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/gorila.php"] [unique_id "amuGKM637Arlr6Yb1Ef_lwAAAPQ"]
[Thu Jul 30 12:13:12.283885 2026] [core:notice] [pid 703393:tid 703614] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:12.290079 2026] [security2:error] [pid 703393:tid 703614] [client 103.215.74.26:20896] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGKM637Arlr6Yb1Ef_mAAAAOA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:12.323275 2026] [core:notice] [pid 703393:tid 703437] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:12.435702 2026] [security2:error] [pid 703393:tid 703525] [client 94.103.90.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuGJ8637Arlr6Yb1Ef_jgAAhxU"], referer: https://allmontecristi.com/contact/
[Thu Jul 30 12:13:12.595832 2026] [security2:error] [pid 703393:tid 703577] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/99.php"] [unique_id "amuGKM637Arlr6Yb1Ef_mgAAALs"]
[Thu Jul 30 12:13:12.595946 2026] [security2:error] [pid 703393:tid 703577] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/99.php"] [unique_id "amuGKM637Arlr6Yb1Ef_mgAAALs"]
[Thu Jul 30 12:13:12.666062 2026] [security2:error] [pid 703393:tid 703588] [client 20.91.140.156:38845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/vanta.php"] [unique_id "amuGKM637Arlr6Yb1Ef_nAAAAMY"]
[Thu Jul 30 12:13:12.666177 2026] [security2:error] [pid 703393:tid 703588] [client 20.91.140.156:38845] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/vanta.php"] [unique_id "amuGKM637Arlr6Yb1Ef_nAAAAMY"]
[Thu Jul 30 12:13:13.049551 2026] [security2:error] [pid 703393:tid 703643] [client 191.232.199.39:46465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/nc4.php"] [unique_id "amuGKc637Arlr6Yb1Ef_owAAAP0"]
[Thu Jul 30 12:13:13.059830 2026] [core:notice] [pid 703393:tid 703633] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:13.066224 2026] [security2:error] [pid 703393:tid 703633] [client 103.215.74.26:10852] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGKc637Arlr6Yb1Ef_pAAAAPM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:13.114106 2026] [security2:error] [pid 703393:tid 703573] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-content/admin.php"] [unique_id "amuGKc637Arlr6Yb1Ef_pQAAALc"]
[Thu Jul 30 12:13:13.114204 2026] [security2:error] [pid 703393:tid 703573] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-content/admin.php"] [unique_id "amuGKc637Arlr6Yb1Ef_pQAAALc"]
[Thu Jul 30 12:13:13.133184 2026] [security2:error] [pid 703393:tid 703599] [client 20.91.140.156:29862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/sh3ll.php"] [unique_id "amuGKc637Arlr6Yb1Ef_pgAAANE"]
[Thu Jul 30 12:13:13.133262 2026] [security2:error] [pid 703393:tid 703599] [client 20.91.140.156:29862] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/sh3ll.php"] [unique_id "amuGKc637Arlr6Yb1Ef_pgAAANE"]
[Thu Jul 30 12:13:13.518298 2026] [security2:error] [pid 703393:tid 703580] [client 20.91.140.156:29637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/cabs.php"] [unique_id "amuGKc637Arlr6Yb1Ef_rgAAAL4"]
[Thu Jul 30 12:13:13.518422 2026] [security2:error] [pid 703393:tid 703580] [client 20.91.140.156:29637] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/cabs.php"] [unique_id "amuGKc637Arlr6Yb1Ef_rgAAAL4"]
[Thu Jul 30 12:13:13.631153 2026] [security2:error] [pid 703393:tid 703541] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/media.php"] [unique_id "amuGKc637Arlr6Yb1Ef_rwAAAJc"]
[Thu Jul 30 12:13:13.631275 2026] [security2:error] [pid 703393:tid 703541] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/media.php"] [unique_id "amuGKc637Arlr6Yb1Ef_rwAAAJc"]
[Thu Jul 30 12:13:13.787910 2026] [core:notice] [pid 703393:tid 703626] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:13.793954 2026] [security2:error] [pid 703393:tid 703626] [client 103.215.74.26:10860] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGKc637Arlr6Yb1Ef_tAAAAOw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:13.863366 2026] [security2:error] [pid 703393:tid 703631] [client 20.91.140.156:39437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/filesss.php"] [unique_id "amuGKc637Arlr6Yb1Ef_tQAAAPE"]
[Thu Jul 30 12:13:13.863469 2026] [security2:error] [pid 703393:tid 703631] [client 20.91.140.156:39437] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/filesss.php"] [unique_id "amuGKc637Arlr6Yb1Ef_tQAAAPE"]
[Thu Jul 30 12:13:14.142828 2026] [security2:error] [pid 703393:tid 703628] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-includes/blocks/audio/index.php"] [unique_id "amuGKs637Arlr6Yb1Ef_uQAAAO4"]
[Thu Jul 30 12:13:14.142940 2026] [security2:error] [pid 703393:tid 703628] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-includes/blocks/audio/index.php"] [unique_id "amuGKs637Arlr6Yb1Ef_uQAAAO4"]
[Thu Jul 30 12:13:14.266456 2026] [security2:error] [pid 703393:tid 703649] [client 213.152.187.215:42330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.187.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuGKs637Arlr6Yb1Ef_vQAAAQM"]
[Thu Jul 30 12:13:14.266573 2026] [security2:error] [pid 703393:tid 703649] [client 213.152.187.215:42330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuGKs637Arlr6Yb1Ef_vQAAAQM"]
[Thu Jul 30 12:13:14.300310 2026] [proxy:error] [pid 703393:tid 703542] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:13:14.300387 2026] [proxy_http:error] [pid 703393:tid 703542] [client 191.232.199.39:46497] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:13:14.301040 2026] [proxy:error] [pid 703393:tid 703542] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:13:14.301087 2026] [proxy_http:error] [pid 703393:tid 703542] [client 191.232.199.39:46497] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:13:14.307778 2026] [security2:error] [pid 703393:tid 703543] [client 20.91.140.156:38809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/wp-aaa.php"] [unique_id "amuGKs637Arlr6Yb1Ef_wQAAAJk"]
[Thu Jul 30 12:13:14.307952 2026] [security2:error] [pid 703393:tid 703543] [client 20.91.140.156:38809] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/wp-aaa.php"] [unique_id "amuGKs637Arlr6Yb1Ef_wQAAAJk"]
[Thu Jul 30 12:13:14.573518 2026] [core:notice] [pid 703393:tid 703525] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:14.580572 2026] [security2:error] [pid 703393:tid 703525] [client 103.215.74.26:10868] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGKs637Arlr6Yb1Ef_wgAAAIc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:14.625849 2026] [security2:error] [pid 703393:tid 703619] [client 20.63.98.115:57202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/hehe.php"] [unique_id "amuGKs637Arlr6Yb1Ef_wwAAAOU"]
[Thu Jul 30 12:13:14.655229 2026] [security2:error] [pid 703393:tid 703578] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/222.php"] [unique_id "amuGKs637Arlr6Yb1Ef_xAAAALw"]
[Thu Jul 30 12:13:14.655329 2026] [security2:error] [pid 703393:tid 703578] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/222.php"] [unique_id "amuGKs637Arlr6Yb1Ef_xAAAALw"]
[Thu Jul 30 12:13:14.715484 2026] [security2:error] [pid 703393:tid 703566] [client 20.91.140.156:38795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/css.php"] [unique_id "amuGKs637Arlr6Yb1Ef_yQAAALA"]
[Thu Jul 30 12:13:14.715607 2026] [security2:error] [pid 703393:tid 703566] [client 20.91.140.156:38795] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/css.php"] [unique_id "amuGKs637Arlr6Yb1Ef_yQAAALA"]
[Thu Jul 30 12:13:15.097798 2026] [security2:error] [pid 703393:tid 703565] [client 20.91.140.156:29844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/ioxi-o.php"] [unique_id "amuGK8637Arlr6Yb1Ef_0AAAAK8"]
[Thu Jul 30 12:13:15.097906 2026] [security2:error] [pid 703393:tid 703565] [client 20.91.140.156:29844] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/ioxi-o.php"] [unique_id "amuGK8637Arlr6Yb1Ef_0AAAAK8"]
[Thu Jul 30 12:13:15.144288 2026] [security2:error] [pid 703393:tid 703612] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-load.php"] [unique_id "amuGK8637Arlr6Yb1Ef_0QAAAN4"]
[Thu Jul 30 12:13:15.144437 2026] [security2:error] [pid 703393:tid 703612] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-load.php"] [unique_id "amuGK8637Arlr6Yb1Ef_0QAAAN4"]
[Thu Jul 30 12:13:15.322273 2026] [core:notice] [pid 703393:tid 703593] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:15.328804 2026] [security2:error] [pid 703393:tid 703593] [client 103.215.74.26:10870] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGK8637Arlr6Yb1Ef_2QAAAMs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:15.425812 2026] [security2:error] [pid 703393:tid 703591] [client 20.91.140.156:32236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/classwithtostring.php"] [unique_id "amuGK8637Arlr6Yb1Ef_2gAAAMk"]
[Thu Jul 30 12:13:15.425928 2026] [security2:error] [pid 703393:tid 703591] [client 20.91.140.156:32236] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/classwithtostring.php"] [unique_id "amuGK8637Arlr6Yb1Ef_2gAAAMk"]
[Thu Jul 30 12:13:15.469549 2026] [security2:error] [pid 703393:tid 703551] [client 20.63.98.115:64858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/options.php"] [unique_id "amuGK8637Arlr6Yb1Ef_2wAAAKE"]
[Thu Jul 30 12:13:15.639555 2026] [security2:error] [pid 703393:tid 703644] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuGK8637Arlr6Yb1Ef_3AAAAP4"]
[Thu Jul 30 12:13:15.639675 2026] [security2:error] [pid 703393:tid 703644] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuGK8637Arlr6Yb1Ef_3AAAAP4"]
[Thu Jul 30 12:13:15.798841 2026] [security2:error] [pid 703393:tid 703594] [client 20.91.140.156:38785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "amuGK8637Arlr6Yb1Ef_4AAAAMw"]
[Thu Jul 30 12:13:15.798936 2026] [security2:error] [pid 703393:tid 703594] [client 20.91.140.156:38785] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "amuGK8637Arlr6Yb1Ef_4AAAAMw"]
[Thu Jul 30 12:13:15.948185 2026] [security2:error] [pid 703393:tid 703623] [client 191.232.199.39:6897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/axx.php"] [unique_id "amuGK8637Arlr6Yb1Ef_5AAAAOk"]
[Thu Jul 30 12:13:16.052312 2026] [core:notice] [pid 703393:tid 703639] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:16.058008 2026] [security2:error] [pid 703393:tid 703639] [client 103.215.74.26:10874] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGLM637Arlr6Yb1Ef_5gAAAPk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:16.144532 2026] [security2:error] [pid 703393:tid 703554] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuGLM637Arlr6Yb1Ef_5wAAAKQ"]
[Thu Jul 30 12:13:16.144700 2026] [security2:error] [pid 703393:tid 703554] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuGLM637Arlr6Yb1Ef_5wAAAKQ"]
[Thu Jul 30 12:13:16.214823 2026] [security2:error] [pid 703393:tid 703631] [client 20.91.140.156:32807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/fm.php"] [unique_id "amuGLM637Arlr6Yb1Ef_6AAAAPE"]
[Thu Jul 30 12:13:16.214932 2026] [security2:error] [pid 703393:tid 703631] [client 20.91.140.156:32807] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/fm.php"] [unique_id "amuGLM637Arlr6Yb1Ef_6AAAAPE"]
[Thu Jul 30 12:13:16.595494 2026] [security2:error] [pid 703393:tid 703637] [client 20.91.140.156:32827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/403.php"] [unique_id "amuGLM637Arlr6Yb1Ef_7wAAAPc"]
[Thu Jul 30 12:13:16.595608 2026] [security2:error] [pid 703393:tid 703637] [client 20.91.140.156:32827] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/403.php"] [unique_id "amuGLM637Arlr6Yb1Ef_7wAAAPc"]
[Thu Jul 30 12:13:16.668899 2026] [security2:error] [pid 703393:tid 703585] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/memberfuns.php"] [unique_id "amuGLM637Arlr6Yb1Ef_8AAAAMM"]
[Thu Jul 30 12:13:16.669020 2026] [security2:error] [pid 703393:tid 703585] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/memberfuns.php"] [unique_id "amuGLM637Arlr6Yb1Ef_8AAAAMM"]
[Thu Jul 30 12:13:16.946517 2026] [security2:error] [pid 703393:tid 703618] [client 20.91.140.156:39433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/admin.php"] [unique_id "amuGLM637Arlr6Yb1Ef_9wAAAOQ"]
[Thu Jul 30 12:13:16.946620 2026] [security2:error] [pid 703393:tid 703618] [client 20.91.140.156:39433] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/admin.php"] [unique_id "amuGLM637Arlr6Yb1Ef_9wAAAOQ"]
[Thu Jul 30 12:13:17.177128 2026] [security2:error] [pid 703393:tid 703524] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/orange3.php"] [unique_id "amuGLc637Arlr6Yb1Ef_-QAAAIY"]
[Thu Jul 30 12:13:17.177247 2026] [security2:error] [pid 703393:tid 703524] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/orange3.php"] [unique_id "amuGLc637Arlr6Yb1Ef_-QAAAIY"]
[Thu Jul 30 12:13:17.342811 2026] [security2:error] [pid 703393:tid 703581] [client 20.91.140.156:29641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/lv.php"] [unique_id "amuGLc637Arlr6Yb1Ef_-wAAAL8"]
[Thu Jul 30 12:13:17.342956 2026] [security2:error] [pid 703393:tid 703581] [client 20.91.140.156:29641] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/lv.php"] [unique_id "amuGLc637Arlr6Yb1Ef_-wAAAL8"]
[Thu Jul 30 12:13:17.582919 2026] [security2:error] [pid 703393:tid 703608] [client 191.232.199.39:6891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/berax.php"] [unique_id "amuGLc637Arlr6Yb1EcAAwAAANo"]
[Thu Jul 30 12:13:17.668658 2026] [security2:error] [pid 703393:tid 703571] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amuGLc637Arlr6Yb1EcABAAAALU"]
[Thu Jul 30 12:13:17.668778 2026] [security2:error] [pid 703393:tid 703571] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amuGLc637Arlr6Yb1EcABAAAALU"]
[Thu Jul 30 12:13:17.854572 2026] [security2:error] [pid 703393:tid 703583] [client 20.215.216.94:35291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuGLc637Arlr6Yb1EcABwAAAME"]
[Thu Jul 30 12:13:17.854672 2026] [security2:error] [pid 703393:tid 703583] [client 20.215.216.94:35291] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuGLc637Arlr6Yb1EcABwAAAME"]
[Thu Jul 30 12:13:17.867287 2026] [core:notice] [pid 703393:tid 703449] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:18.169115 2026] [security2:error] [pid 703393:tid 703570] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-the.php"] [unique_id "amuGLs637Arlr6Yb1EcAEAAAALQ"]
[Thu Jul 30 12:13:18.169227 2026] [security2:error] [pid 703393:tid 703570] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-the.php"] [unique_id "amuGLs637Arlr6Yb1EcAEAAAALQ"]
[Thu Jul 30 12:13:18.199702 2026] [security2:error] [pid 703393:tid 703598] [client 20.63.98.115:62455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amuGLs637Arlr6Yb1EcAEQAAANA"]
[Thu Jul 30 12:13:18.468530 2026] [core:notice] [pid 703393:tid 703491] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:18.684807 2026] [security2:error] [pid 703393:tid 703609] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/crgio.php"] [unique_id "amuGLs637Arlr6Yb1EcAHwAAANs"]
[Thu Jul 30 12:13:18.684946 2026] [security2:error] [pid 703393:tid 703609] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/crgio.php"] [unique_id "amuGLs637Arlr6Yb1EcAHwAAANs"]
[Thu Jul 30 12:13:19.239678 2026] [security2:error] [pid 703393:tid 703623] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/ws13.php"] [unique_id "amuGL8637Arlr6Yb1EcAKAAAAOk"]
[Thu Jul 30 12:13:19.239806 2026] [security2:error] [pid 703393:tid 703623] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/ws13.php"] [unique_id "amuGL8637Arlr6Yb1EcAKAAAAOk"]
[Thu Jul 30 12:13:19.261110 2026] [core:error] [pid 703393:tid 703626] [client 74.7.175.159:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:13:19.261133 2026] [core:error] [pid 703393:tid 703626] [client 74.7.175.159:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:13:19.261256 2026] [security2:error] [pid 703393:tid 703626] [client 74.7.175.159:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.ste.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "amuGL8637Arlr6Yb1EcAKwAAAOw"]
[Thu Jul 30 12:13:19.261828 2026] [security2:error] [pid 703393:tid 703594] [client 74.7.175.159:56720] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.ste.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "amuGL8637Arlr6Yb1EcAKQAAzBA"]
[Thu Jul 30 12:13:19.747342 2026] [security2:error] [pid 703393:tid 703525] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/srontol.php"] [unique_id "amuGL8637Arlr6Yb1EcAMgAAAIc"]
[Thu Jul 30 12:13:19.747460 2026] [security2:error] [pid 703393:tid 703525] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/srontol.php"] [unique_id "amuGL8637Arlr6Yb1EcAMgAAAIc"]
[Thu Jul 30 12:13:20.231379 2026] [security2:error] [pid 703393:tid 703584] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/miru3.php"] [unique_id "amuGMM637Arlr6Yb1EcAPwAAAMI"]
[Thu Jul 30 12:13:20.231507 2026] [security2:error] [pid 703393:tid 703584] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/miru3.php"] [unique_id "amuGMM637Arlr6Yb1EcAPwAAAMI"]
[Thu Jul 30 12:13:20.396233 2026] [security2:error] [pid 703393:tid 703568] [client 57.141.0.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuGMM637Arlr6Yb1EcAPgAAALI"]
[Thu Jul 30 12:13:20.682795 2026] [autoindex:error] [pid 703393:tid 703472] [remote 45.33.110.19:60260] AH01276: Cannot serve directory /home1/uixgzjte/public_html/chicago-mfg.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:13:20.728334 2026] [security2:error] [pid 703393:tid 703543] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/ingfo.php"] [unique_id "amuGMM637Arlr6Yb1EcASgAAAJk"]
[Thu Jul 30 12:13:20.728447 2026] [security2:error] [pid 703393:tid 703543] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/ingfo.php"] [unique_id "amuGMM637Arlr6Yb1EcASgAAAJk"]
[Thu Jul 30 12:13:21.164469 2026] [security2:error] [pid 703393:tid 703612] [client 20.215.216.94:35708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuGMc637Arlr6Yb1EcAZQAAAN4"]
[Thu Jul 30 12:13:21.164660 2026] [security2:error] [pid 703393:tid 703612] [client 20.215.216.94:35708] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuGMc637Arlr6Yb1EcAZQAAAN4"]
[Thu Jul 30 12:13:21.219582 2026] [security2:error] [pid 703393:tid 703581] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/ey5.php"] [unique_id "amuGMc637Arlr6Yb1EcAZgAAAL8"]
[Thu Jul 30 12:13:21.219801 2026] [security2:error] [pid 703393:tid 703581] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/ey5.php"] [unique_id "amuGMc637Arlr6Yb1EcAZgAAAL8"]
[Thu Jul 30 12:13:21.394365 2026] [security2:error] [pid 703393:tid 703404] [remote 250.49.135.140:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuGMM637Arlr6Yb1EcASAAA-Ao"]
[Thu Jul 30 12:13:21.394792 2026] [security2:error] [pid 703393:tid 703638] [client 250.49.135.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuGMM637Arlr6Yb1EcASAAA-Ao"]
[Thu Jul 30 12:13:21.710159 2026] [security2:error] [pid 703393:tid 703630] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/fine.php"] [unique_id "amuGMc637Arlr6Yb1EcAcAAAAPA"]
[Thu Jul 30 12:13:21.710252 2026] [security2:error] [pid 703393:tid 703630] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/fine.php"] [unique_id "amuGMc637Arlr6Yb1EcAcAAAAPA"]
[Thu Jul 30 12:13:21.756391 2026] [security2:error] [pid 703393:tid 703647] [client 191.232.199.39:6898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/build.php"] [unique_id "amuGMc637Arlr6Yb1EcAcQAAAQE"]
[Thu Jul 30 12:13:21.790324 2026] [core:notice] [pid 703393:tid 703601] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:21.796636 2026] [security2:error] [pid 703393:tid 703601] [client 103.215.74.26:10884] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGMc637Arlr6Yb1EcAcgAAANM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:21.834072 2026] [security2:error] [pid 703393:tid 703544] [client 20.63.98.115:38949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/images/index.php"] [unique_id "amuGMc637Arlr6Yb1EcAdgAAAJo"]
[Thu Jul 30 12:13:22.361142 2026] [security2:error] [pid 703393:tid 703646] [client 172.237.109.114:7060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMM637Arlr6Yb1EcASwAAAQA"]
[Thu Jul 30 12:13:22.409767 2026] [security2:error] [pid 703393:tid 703594] [client 57.141.0.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuGMc637Arlr6Yb1EcAbwAAAMw"]
[Thu Jul 30 12:13:22.446740 2026] [security2:error] [pid 703393:tid 703586] [client 172.237.109.114:50036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMM637Arlr6Yb1EcATQAAAMQ"]
[Thu Jul 30 12:13:22.468072 2026] [security2:error] [pid 703393:tid 703607] [client 172.237.109.114:16217] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMM637Arlr6Yb1EcATwAAANk"]
[Thu Jul 30 12:13:22.468071 2026] [security2:error] [pid 703393:tid 703525] [client 172.237.109.114:24173] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMM637Arlr6Yb1EcAUgAAAIc"]
[Thu Jul 30 12:13:22.471716 2026] [security2:error] [pid 703393:tid 703648] [client 172.237.109.114:11892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMM637Arlr6Yb1EcAUwAAAQI"]
[Thu Jul 30 12:13:22.489464 2026] [security2:error] [pid 703393:tid 703531] [client 172.237.109.114:1707] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMM637Arlr6Yb1EcAUAAAAI0"]
[Thu Jul 30 12:13:22.494023 2026] [security2:error] [pid 703393:tid 703621] [client 172.237.109.114:9703] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMM637Arlr6Yb1EcAVwAAAOc"]
[Thu Jul 30 12:13:22.498212 2026] [security2:error] [pid 703393:tid 703577] [client 172.237.109.114:30994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMM637Arlr6Yb1EcATgAAALs"]
[Thu Jul 30 12:13:22.509416 2026] [security2:error] [pid 703393:tid 703618] [client 172.237.109.114:28924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMM637Arlr6Yb1EcAVgAAAOQ"]
[Thu Jul 30 12:13:22.521331 2026] [security2:error] [pid 703393:tid 703603] [client 172.237.109.114:59920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMM637Arlr6Yb1EcAVAAAANU"]
[Thu Jul 30 12:13:22.521731 2026] [security2:error] [pid 703393:tid 703552] [client 172.237.109.114:43404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMc637Arlr6Yb1EcAXgAAAKI"]
[Thu Jul 30 12:13:22.540115 2026] [security2:error] [pid 703393:tid 703562] [client 172.237.109.114:43281] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMc637Arlr6Yb1EcAWwAAAKw"]
[Thu Jul 30 12:13:22.541000 2026] [security2:error] [pid 703393:tid 703523] [client 172.237.109.114:65343] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMM637Arlr6Yb1EcAUQAAAIU"]
[Thu Jul 30 12:13:22.543330 2026] [security2:error] [pid 703393:tid 703566] [client 172.237.109.114:20729] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMc637Arlr6Yb1EcAWQAAALA"]
[Thu Jul 30 12:13:22.550577 2026] [security2:error] [pid 703393:tid 703570] [client 57.141.0.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuGMc637Arlr6Yb1EcAeQAAALQ"]
[Thu Jul 30 12:13:22.551834 2026] [security2:error] [pid 703393:tid 703537] [client 172.237.109.114:14974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMM637Arlr6Yb1EcATAAAAJM"]
[Thu Jul 30 12:13:22.560166 2026] [security2:error] [pid 703393:tid 703649] [client 172.237.109.114:60680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMM637Arlr6Yb1EcAWAAAAQM"]
[Thu Jul 30 12:13:22.561243 2026] [security2:error] [pid 703393:tid 703596] [client 172.237.109.114:21369] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMc637Arlr6Yb1EcAWgAAAM4"]
[Thu Jul 30 12:13:22.577188 2026] [security2:error] [pid 703393:tid 703559] [client 172.237.109.114:47889] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMM637Arlr6Yb1EcAVQAAAKk"]
[Thu Jul 30 12:13:22.584716 2026] [security2:error] [pid 703393:tid 703549] [client 172.237.109.114:41397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMc637Arlr6Yb1EcAXAAAAJ8"]
[Thu Jul 30 12:13:22.631679 2026] [security2:error] [pid 703393:tid 703546] [client 172.237.109.114:41736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMc637Arlr6Yb1EcAXQAAAJw"]
[Thu Jul 30 12:13:23.040204 2026] [security2:error] [pid 703393:tid 703622] [client 191.232.199.39:6906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/buy.php"] [unique_id "amuGM8637Arlr6Yb1EcAiQAAAOg"]
[Thu Jul 30 12:13:23.922811 2026] [security2:error] [pid 703393:tid 703533] [client 57.141.0.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuGM8637Arlr6Yb1EcAkwAAAI8"]
[Thu Jul 30 12:13:24.004438 2026] [security2:error] [pid 703393:tid 703605] [client 20.63.98.115:62440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/uploads/index.php"] [unique_id "amuGNM637Arlr6Yb1EcAmgAAANc"]
[Thu Jul 30 12:13:24.290868 2026] [security2:error] [pid 703393:tid 703540] [client 20.215.216.94:35279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/err.php"] [unique_id "amuGNM637Arlr6Yb1EcAowAAAJY"]
[Thu Jul 30 12:13:24.291001 2026] [security2:error] [pid 703393:tid 703540] [client 20.215.216.94:35279] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/err.php"] [unique_id "amuGNM637Arlr6Yb1EcAowAAAJY"]
[Thu Jul 30 12:13:25.163414 2026] [security2:error] [pid 703393:tid 703608] [client 185.189.112.11:56158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.112.189.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuGNc637Arlr6Yb1EcAqwAAANo"]
[Thu Jul 30 12:13:25.163520 2026] [security2:error] [pid 703393:tid 703608] [client 185.189.112.11:56158] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuGNc637Arlr6Yb1EcAqwAAANo"]
[Thu Jul 30 12:13:25.195231 2026] [security2:error] [pid 703393:tid 703587] [client 20.63.98.115:63124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/13.php"] [unique_id "amuGNc637Arlr6Yb1EcArQAAAMU"]
[Thu Jul 30 12:13:25.868131 2026] [security2:error] [pid 703393:tid 703550] [client 20.215.216.94:35650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/img.php"] [unique_id "amuGNc637Arlr6Yb1EcAuQAAAKA"]
[Thu Jul 30 12:13:25.868224 2026] [security2:error] [pid 703393:tid 703550] [client 20.215.216.94:35650] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/img.php"] [unique_id "amuGNc637Arlr6Yb1EcAuQAAAKA"]
[Thu Jul 30 12:13:26.052718 2026] [security2:error] [pid 703393:tid 703553] [client 85.208.96.200:53718] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/08/25/veneziano-reforca-compromisso-com-agricultura-familiar-e-parcerias-para-construcao-e-reestruturacao-de-mercados-publicos/"] [unique_id "amuGNs637Arlr6Yb1EcAugAAAKM"]
[Thu Jul 30 12:13:26.052880 2026] [security2:error] [pid 703393:tid 703553] [client 85.208.96.200:53718] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/08/25/veneziano-reforca-compromisso-com-agricultura-familiar-e-parcerias-para-construcao-e-reestruturacao-de-mercados-publicos/"] [unique_id "amuGNs637Arlr6Yb1EcAugAAAKM"]
[Thu Jul 30 12:13:26.687641 2026] [security2:error] [pid 703393:tid 703548] [client 20.215.216.94:35698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/aa.php"] [unique_id "amuGNs637Arlr6Yb1EcAvwAAAJ4"]
[Thu Jul 30 12:13:26.687742 2026] [security2:error] [pid 703393:tid 703548] [client 20.215.216.94:35698] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/aa.php"] [unique_id "amuGNs637Arlr6Yb1EcAvwAAAJ4"]
[Thu Jul 30 12:13:27.428722 2026] [security2:error] [pid 703393:tid 703559] [client 20.63.98.115:57200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/inputs.php"] [unique_id "amuGN8637Arlr6Yb1EcAzAAAAKk"]
[Thu Jul 30 12:13:27.538735 2026] [core:notice] [pid 703393:tid 703537] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:27.545023 2026] [security2:error] [pid 703393:tid 703537] [client 103.215.74.26:19328] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGN8637Arlr6Yb1EcAzgAAAJM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:28.015688 2026] [security2:error] [pid 703393:tid 703645] [client 20.215.216.94:35695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/av.php"] [unique_id "amuGOM637Arlr6Yb1EcA1wAAAP8"]
[Thu Jul 30 12:13:28.015783 2026] [security2:error] [pid 703393:tid 703645] [client 20.215.216.94:35695] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/av.php"] [unique_id "amuGOM637Arlr6Yb1EcA1wAAAP8"]
[Thu Jul 30 12:13:28.261732 2026] [core:notice] [pid 703393:tid 703633] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:28.269236 2026] [security2:error] [pid 703393:tid 703633] [client 103.215.74.26:19342] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGOM637Arlr6Yb1EcA3wAAAPM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:29.032588 2026] [core:notice] [pid 703393:tid 703533] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:29.038405 2026] [security2:error] [pid 703393:tid 703533] [client 103.215.74.26:19356] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGOc637Arlr6Yb1EcA9gAAAI8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:29.442637 2026] [security2:error] [pid 703393:tid 703627] [client 20.215.216.94:35666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/xa.php"] [unique_id "amuGOc637Arlr6Yb1EcBDgAAAO0"]
[Thu Jul 30 12:13:29.442740 2026] [security2:error] [pid 703393:tid 703627] [client 20.215.216.94:35666] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/xa.php"] [unique_id "amuGOc637Arlr6Yb1EcBDgAAAO0"]
[Thu Jul 30 12:13:29.777292 2026] [core:notice] [pid 703393:tid 703581] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:29.783473 2026] [security2:error] [pid 703393:tid 703581] [client 103.215.74.26:19370] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGOc637Arlr6Yb1EcBFgAAAL8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:30.536482 2026] [core:notice] [pid 703393:tid 703628] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:30.542408 2026] [security2:error] [pid 703393:tid 703628] [client 103.215.74.26:19376] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGOs637Arlr6Yb1EcBIwAAAO4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:30.599226 2026] [security2:error] [pid 703393:tid 703527] [client 20.215.216.94:35707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/media.php"] [unique_id "amuGOs637Arlr6Yb1EcBJAAAAIk"]
[Thu Jul 30 12:13:30.599371 2026] [security2:error] [pid 703393:tid 703527] [client 20.215.216.94:35707] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/media.php"] [unique_id "amuGOs637Arlr6Yb1EcBJAAAAIk"]
[Thu Jul 30 12:13:31.122938 2026] [security2:error] [pid 703393:tid 703537] [client 57.141.0.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuGOs637Arlr6Yb1EcBIgAAAJM"]
[Thu Jul 30 12:13:31.273671 2026] [core:notice] [pid 703393:tid 703572] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:31.280440 2026] [security2:error] [pid 703393:tid 703572] [client 103.215.74.26:19386] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGO8637Arlr6Yb1EcBMQAAALY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:31.673023 2026] [security2:error] [pid 703393:tid 703622] [client 191.232.199.39:60741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/checkbox.php"] [unique_id "amuGO8637Arlr6Yb1EcBRQAAAOg"]
[Thu Jul 30 12:13:31.952897 2026] [security2:error] [pid 703393:tid 703563] [client 20.215.216.94:35677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/images.php"] [unique_id "amuGO8637Arlr6Yb1EcBYgAAAK0"]
[Thu Jul 30 12:13:31.953047 2026] [security2:error] [pid 703393:tid 703563] [client 20.215.216.94:35677] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/images.php"] [unique_id "amuGO8637Arlr6Yb1EcBYgAAAK0"]
[Thu Jul 30 12:13:31.981685 2026] [security2:error] [pid 703393:tid 703560] [client 2a03:2880:f800:23:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuGO8637Arlr6Yb1EcBNwAAqhw"]
[Thu Jul 30 12:13:32.030267 2026] [core:notice] [pid 703393:tid 703596] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:32.036845 2026] [security2:error] [pid 703393:tid 703596] [client 103.215.74.26:19390] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGPM637Arlr6Yb1EcBYwAAAM4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:32.148186 2026] [security2:error] [pid 703393:tid 703535] [client 20.63.98.115:63469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/jquery.php"] [unique_id "amuGPM637Arlr6Yb1EcBZAAAAJE"]
[Thu Jul 30 12:13:32.762768 2026] [core:notice] [pid 703393:tid 703565] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:32.773255 2026] [security2:error] [pid 703393:tid 703565] [client 103.215.74.26:19400] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGPM637Arlr6Yb1EcBcAAAAK8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:32.944696 2026] [security2:error] [pid 703393:tid 703526] [client 191.232.199.39:6890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/cong.php"] [unique_id "amuGPM637Arlr6Yb1EcBdAAAAIg"]
[Thu Jul 30 12:13:33.349190 2026] [security2:error] [pid 703393:tid 703592] [client 20.215.216.94:35304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/gecko.php"] [unique_id "amuGPc637Arlr6Yb1EcBeAAAAMo"]
[Thu Jul 30 12:13:33.349278 2026] [security2:error] [pid 703393:tid 703592] [client 20.215.216.94:35304] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/gecko.php"] [unique_id "amuGPc637Arlr6Yb1EcBeAAAAMo"]
[Thu Jul 30 12:13:33.502682 2026] [core:notice] [pid 703393:tid 703552] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:33.509132 2026] [security2:error] [pid 703393:tid 703552] [client 103.215.74.26:33072] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGPc637Arlr6Yb1EcBfAAAAKI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:34.244761 2026] [core:notice] [pid 703393:tid 703621] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:34.251153 2026] [security2:error] [pid 703393:tid 703621] [client 103.215.74.26:33084] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGPs637Arlr6Yb1EcBhQAAAOc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:34.526185 2026] [security2:error] [pid 703393:tid 703564] [client 191.232.199.39:60771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/file4.php"] [unique_id "amuGPs637Arlr6Yb1EcBjAAAAK4"]
[Thu Jul 30 12:13:34.969074 2026] [core:notice] [pid 703393:tid 703644] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:34.976100 2026] [security2:error] [pid 703393:tid 703644] [client 103.215.74.26:33092] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGPs637Arlr6Yb1EcBlgAAAP4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:35.038481 2026] [security2:error] [pid 703393:tid 703551] [client 20.215.216.94:35702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/82.php"] [unique_id "amuGP8637Arlr6Yb1EcBmgAAAKE"]
[Thu Jul 30 12:13:35.038569 2026] [security2:error] [pid 703393:tid 703551] [client 20.215.216.94:35702] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/82.php"] [unique_id "amuGP8637Arlr6Yb1EcBmgAAAKE"]
[Thu Jul 30 12:13:35.724276 2026] [core:notice] [pid 703393:tid 703578] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:35.730504 2026] [security2:error] [pid 703393:tid 703578] [client 103.215.74.26:33098] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGP8637Arlr6Yb1EcBowAAALw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:35.920790 2026] [security2:error] [pid 703393:tid 703467] [remote 51.195.183.133:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "saiqon.net"] [uri "/contact/"] [unique_id "amuGP8637Arlr6Yb1EcBpwAAhkk"]
[Thu Jul 30 12:13:35.920930 2026] [security2:error] [pid 703393:tid 703524] [client 51.195.183.133:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "saiqon.net"] [uri "/contact/"] [unique_id "amuGP8637Arlr6Yb1EcBpwAAhkk"]
[Thu Jul 30 12:13:36.207830 2026] [security2:error] [pid 703393:tid 703569] [client 191.232.199.39:60749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/flower.php"] [unique_id "amuGQM637Arlr6Yb1EcBrgAAALM"]
[Thu Jul 30 12:13:36.448609 2026] [core:notice] [pid 703393:tid 703611] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:36.454926 2026] [security2:error] [pid 703393:tid 703611] [client 103.215.74.26:33108] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGQM637Arlr6Yb1EcBtQAAAN0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:36.894453 2026] [security2:error] [pid 703393:tid 703642] [client 57.141.0.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuGQM637Arlr6Yb1EcBsQAAAPw"]
[Thu Jul 30 12:13:37.083756 2026] [security2:error] [pid 703393:tid 703570] [client 2a03:2880:f800:f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuGQM637Arlr6Yb1EcBtgAAtGU"]
[Thu Jul 30 12:13:37.197529 2026] [core:notice] [pid 703393:tid 703538] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:37.208157 2026] [security2:error] [pid 703393:tid 703538] [client 103.215.74.26:33110] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGQc637Arlr6Yb1EcBxAAAAJQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:37.509478 2026] [security2:error] [pid 703393:tid 703594] [client 20.215.216.94:35688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/xstelth.php"] [unique_id "amuGQc637Arlr6Yb1EcByAAAAMw"]
[Thu Jul 30 12:13:37.509591 2026] [security2:error] [pid 703393:tid 703594] [client 20.215.216.94:35688] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/xstelth.php"] [unique_id "amuGQc637Arlr6Yb1EcByAAAAMw"]
[Thu Jul 30 12:13:37.621120 2026] [security2:error] [pid 703393:tid 703591] [client 191.232.199.39:6886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/form.php"] [unique_id "amuGQc637Arlr6Yb1EcBzwAAAMk"]
[Thu Jul 30 12:13:37.962369 2026] [core:notice] [pid 703393:tid 703528] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:37.973080 2026] [security2:error] [pid 703393:tid 703528] [client 103.215.74.26:33120] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGQc637Arlr6Yb1EcB1QAAAIo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:38.066837 2026] [security2:error] [pid 703393:tid 703616] [client 20.63.98.115:63460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/doc.php"] [unique_id "amuGQs637Arlr6Yb1EcB3AAAAOI"]
[Thu Jul 30 12:13:38.461446 2026] [security2:error] [pid 703393:tid 703527] [client 57.141.0.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuGQc637Arlr6Yb1EcB1AAAAIk"]
[Thu Jul 30 12:13:38.695326 2026] [core:notice] [pid 703393:tid 703626] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:38.701630 2026] [security2:error] [pid 703393:tid 703626] [client 103.215.74.26:33130] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGQs637Arlr6Yb1EcB5wAAAOw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:39.324195 2026] [security2:error] [pid 703393:tid 703598] [client 191.232.199.39:6902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/gecko.php"] [unique_id "amuGQ8637Arlr6Yb1EcB8QAAANA"]
[Thu Jul 30 12:13:39.464740 2026] [core:notice] [pid 703393:tid 703607] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:39.471307 2026] [security2:error] [pid 703393:tid 703607] [client 103.215.74.26:33132] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGQ8637Arlr6Yb1EcB8gAAANk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:40.198864 2026] [core:notice] [pid 703393:tid 703553] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:40.205219 2026] [security2:error] [pid 703393:tid 703553] [client 103.215.74.26:33144] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGRM637Arlr6Yb1EcCAgAAAKM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:40.518596 2026] [security2:error] [pid 703393:tid 703578] [client 20.63.98.115:65282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/02.php"] [unique_id "amuGRM637Arlr6Yb1EcCBgAAALw"]
[Thu Jul 30 12:13:40.937589 2026] [core:notice] [pid 703393:tid 703524] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:40.944033 2026] [security2:error] [pid 703393:tid 703524] [client 103.215.74.26:33146] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGRM637Arlr6Yb1EcCDgAAAIY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:41.219047 2026] [security2:error] [pid 703393:tid 703619] [client 191.232.199.39:6900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/kyami.php"] [unique_id "amuGRc637Arlr6Yb1EcCFQAAAOU"]
[Thu Jul 30 12:13:41.520261 2026] [security2:error] [pid 703393:tid 703536] [client 20.63.98.115:49128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/well-known/admin.php"] [unique_id "amuGRc637Arlr6Yb1EcCHgAAAJI"]
[Thu Jul 30 12:13:41.676989 2026] [core:notice] [pid 703393:tid 703637] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:41.683328 2026] [security2:error] [pid 703393:tid 703637] [client 103.215.74.26:33156] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGRc637Arlr6Yb1EcCHwAAAPc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:41.738832 2026] [security2:error] [pid 703393:tid 703521] [remote 40.77.167.67:5174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/pbb/article/download/7395/index_php/index/index_php/JGST"] [unique_id "amuGRc637Arlr6Yb1EcCIwAA7n8"]
[Thu Jul 30 12:13:42.426766 2026] [core:notice] [pid 703393:tid 703525] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:42.433173 2026] [security2:error] [pid 703393:tid 703525] [client 103.215.74.26:33162] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGRs637Arlr6Yb1EcCLgAAAIc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:42.860231 2026] [autoindex:error] [pid 703393:tid 703543] [client 20.63.98.115:47173] AH01276: Cannot serve directory /home1/wdrgplte/public_html/jesus.claims/wp-includes/js/tinymce/plugins/compat3x/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:13:43.045642 2026] [autoindex:error] [pid 703393:tid 703593] [client 66.132.172.202:0] AH01276: Cannot serve directory /home1/mthgzjte/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:13:43.063768 2026] [security2:error] [pid 703393:tid 703625] [client 20.63.98.115:47173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/v.php"] [unique_id "amuGR8637Arlr6Yb1EcCPAAAAOs"]
[Thu Jul 30 12:13:43.161395 2026] [core:notice] [pid 703393:tid 703557] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:43.168480 2026] [security2:error] [pid 703393:tid 703557] [client 103.215.74.26:59326] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGR8637Arlr6Yb1EcCPQAAAKc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:43.857681 2026] [security2:error] [pid 703393:tid 703578] [client 20.215.216.94:35685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/xp.php"] [unique_id "amuGR8637Arlr6Yb1EcCSgAAALw"]
[Thu Jul 30 12:13:43.857776 2026] [security2:error] [pid 703393:tid 703578] [client 20.215.216.94:35685] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/xp.php"] [unique_id "amuGR8637Arlr6Yb1EcCSgAAALw"]
[Thu Jul 30 12:13:43.886571 2026] [core:notice] [pid 703393:tid 703561] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:43.892952 2026] [security2:error] [pid 703393:tid 703561] [client 103.215.74.26:59330] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGR8637Arlr6Yb1EcCTgAAAKs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:44.507734 2026] [security2:error] [pid 703393:tid 703612] [client 20.63.98.115:47199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/main.php"] [unique_id "amuGSM637Arlr6Yb1EcCWAAAAN4"]
[Thu Jul 30 12:13:44.557376 2026] [security2:error] [pid 703393:tid 703594] [client 57.141.0.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuGR8637Arlr6Yb1EcCUQAAAMw"]
[Thu Jul 30 12:13:44.623291 2026] [security2:error] [pid 703393:tid 703558] [client 191.232.199.39:60750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/manager.php"] [unique_id "amuGSM637Arlr6Yb1EcCWQAAAKg"]
[Thu Jul 30 12:13:44.671441 2026] [core:notice] [pid 703393:tid 703593] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:44.677652 2026] [security2:error] [pid 703393:tid 703593] [client 103.215.74.26:59344] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGSM637Arlr6Yb1EcCWwAAAMs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:45.317988 2026] [core:notice] [pid 703393:tid 703627] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:45.388173 2026] [core:notice] [pid 703393:tid 703530] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:45.394205 2026] [security2:error] [pid 703393:tid 703530] [client 103.215.74.26:59378] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGSc637Arlr6Yb1EcCagAAAIw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:46.127819 2026] [core:notice] [pid 703393:tid 703594] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:46.134305 2026] [security2:error] [pid 703393:tid 703594] [client 103.215.74.26:59394] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGSs637Arlr6Yb1EcCdwAAAMw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:46.353417 2026] [security2:error] [pid 703393:tid 703587] [client 20.63.98.115:63450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/.well-known/file.php"] [unique_id "amuGSs637Arlr6Yb1EcCewAAAMU"]
[Thu Jul 30 12:13:46.451351 2026] [core:notice] [pid 703393:tid 703439] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:46.800221 2026] [security2:error] [pid 703393:tid 703601] [client 185.191.171.9:38924] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2020/10/26/petrobras-reduz-preco-do-diesel-em-4-e-o-da-gasolina-em-5/"] [unique_id "amuGSs637Arlr6Yb1EcChAAAANM"]
[Thu Jul 30 12:13:46.800367 2026] [security2:error] [pid 703393:tid 703601] [client 185.191.171.9:38924] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2020/10/26/petrobras-reduz-preco-do-diesel-em-4-e-o-da-gasolina-em-5/"] [unique_id "amuGSs637Arlr6Yb1EcChAAAANM"]
[Thu Jul 30 12:13:46.854080 2026] [core:notice] [pid 703393:tid 703643] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:46.860473 2026] [security2:error] [pid 703393:tid 703643] [client 103.215.74.26:59428] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGSs637Arlr6Yb1EcChQAAAP0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:46.956955 2026] [core:notice] [pid 703393:tid 703441] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:47.047350 2026] [security2:error] [pid 703393:tid 703644] [client 20.215.216.94:35668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/admin.php"] [unique_id "amuGS8637Arlr6Yb1EcCjQAAAP4"]
[Thu Jul 30 12:13:47.047446 2026] [security2:error] [pid 703393:tid 703644] [client 20.215.216.94:35668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/admin.php"] [unique_id "amuGS8637Arlr6Yb1EcCjQAAAP4"]
[Thu Jul 30 12:13:47.607075 2026] [core:notice] [pid 703393:tid 703558] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:47.613890 2026] [security2:error] [pid 703393:tid 703558] [client 103.215.74.26:59436] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGS8637Arlr6Yb1EcCmAAAAKg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:47.942476 2026] [security2:error] [pid 703393:tid 703648] [client 2a03:2880:f800:6:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuGS8637Arlr6Yb1EcCkQABAjU"]
[Thu Jul 30 12:13:48.093645 2026] [security2:error] [pid 703393:tid 703523] [client 20.63.98.115:47188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/.well-known/pki-validation/index.php"] [unique_id "amuGTM637Arlr6Yb1EcCpAAAAIU"]
[Thu Jul 30 12:13:48.350183 2026] [core:notice] [pid 703393:tid 703537] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:48.361008 2026] [security2:error] [pid 703393:tid 703537] [client 103.215.74.26:59460] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGTM637Arlr6Yb1EcCpQAAAJM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:48.445546 2026] [core:notice] [pid 703393:tid 703457] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:48.613633 2026] [security2:error] [pid 703393:tid 703564] [client 146.103.115.7:53376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.103.146.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "online-hope.com"] [uri "/my-account/"] [unique_id "amuGTM637Arlr6Yb1EcCrgAAAK4"], referer: https://online-hope.com/
[Thu Jul 30 12:13:48.714128 2026] [security2:error] [pid 703393:tid 703600] [client 2a03:2880:f800:2d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuGTM637Arlr6Yb1EcCowAA0g0"]
[Thu Jul 30 12:13:48.862141 2026] [core:notice] [pid 703393:tid 703490] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:49.094718 2026] [core:notice] [pid 703393:tid 703584] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:49.101155 2026] [security2:error] [pid 703393:tid 703584] [client 103.215.74.26:59472] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGTc637Arlr6Yb1EcCtwAAAMI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:49.450789 2026] [security2:error] [pid 703393:tid 703586] [client 57.141.0.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "stunningtouchcleaning.com"] [uri "/index.php"] [unique_id "amuGS8637Arlr6Yb1EcCkAAAAMQ"]
[Thu Jul 30 12:13:49.720493 2026] [security2:error] [pid 703393:tid 703555] [client 20.63.98.115:20866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "amuGTc637Arlr6Yb1EcCwgAAAKU"]
[Thu Jul 30 12:13:49.742174 2026] [security2:error] [pid 703393:tid 703588] [client 81.255.2.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "espairsa.com"] [uri "/index.php"] [unique_id "amuGS8637Arlr6Yb1EcCmwAAxhI"]
[Thu Jul 30 12:13:49.812453 2026] [core:notice] [pid 703393:tid 703561] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:49.819058 2026] [security2:error] [pid 703393:tid 703561] [client 103.215.74.26:59520] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGTc637Arlr6Yb1EcCwwAAAKs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:50.256531 2026] [security2:error] [pid 703393:tid 703552] [client 81.255.2.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "espairsa.com"] [uri "/index.php"] [unique_id "amuGS8637Arlr6Yb1EcCmQAAojg"]
[Thu Jul 30 12:13:50.302207 2026] [security2:error] [pid 703393:tid 703542] [client 81.255.2.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "espairsa.com"] [uri "/index.php"] [unique_id "amuGS8637Arlr6Yb1EcCnQAAmCg"]
[Thu Jul 30 12:13:50.539460 2026] [core:notice] [pid 703393:tid 703584] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:50.545945 2026] [security2:error] [pid 703393:tid 703584] [client 103.215.74.26:59526] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGTs637Arlr6Yb1EcC1gAAAMI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:51.266800 2026] [security2:error] [pid 703393:tid 703524] [client 20.63.98.115:20869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/file.php"] [unique_id "amuGT8637Arlr6Yb1EcC6AAAAIY"]
[Thu Jul 30 12:13:51.272671 2026] [core:notice] [pid 703393:tid 703556] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:51.279253 2026] [security2:error] [pid 703393:tid 703556] [client 103.215.74.26:59564] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGT8637Arlr6Yb1EcC6QAAAKY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:51.445906 2026] [security2:error] [pid 703393:tid 703554] [client 57.141.0.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuGTs637Arlr6Yb1EcC3wAAAKQ"]
[Thu Jul 30 12:13:52.029792 2026] [core:notice] [pid 703393:tid 703550] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:52.036436 2026] [security2:error] [pid 703393:tid 703550] [client 103.215.74.26:59568] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGUM637Arlr6Yb1EcC9gAAAKA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:52.491809 2026] [security2:error] [pid 703393:tid 703547] [client 68.67.112.200:64927] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "kicksity.com"] [uri "/robots.txt"] [unique_id "amuGUM637Arlr6Yb1EcDAAAAAJ0"]
[Thu Jul 30 12:13:52.762572 2026] [core:notice] [pid 703393:tid 703644] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:52.773339 2026] [security2:error] [pid 703393:tid 703644] [client 103.215.74.26:59614] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGUM637Arlr6Yb1EcDBwAAAP4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:53.088377 2026] [security2:error] [pid 703393:tid 703587] [client 146.103.110.13:61998] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "146.103.110.13" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "online-hope.com"] [uri "/wp-comments-post.php"] [unique_id "amuGUc637Arlr6Yb1EcDCQAAAMU"], referer: https://online-hope.com/hello-world/
[Thu Jul 30 12:13:53.088498 2026] [security2:error] [pid 703393:tid 703587] [client 146.103.110.13:61998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "online-hope.com"] [uri "/wp-comments-post.php"] [unique_id "amuGUc637Arlr6Yb1EcDCQAAAMU"], referer: https://online-hope.com/hello-world/
[Thu Jul 30 12:13:53.549524 2026] [core:notice] [pid 703393:tid 703588] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:53.555542 2026] [security2:error] [pid 703393:tid 703588] [client 103.215.74.26:9556] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGUc637Arlr6Yb1EcDEwAAAMY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:53.768213 2026] [core:error] [pid 703393:tid 703600] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:13:53.768234 2026] [core:error] [pid 703393:tid 703600] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:13:54.164240 2026] [security2:error] [pid 703393:tid 703581] [client 191.232.199.39:6864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/mari.php"] [unique_id "amuGUs637Arlr6Yb1EcDHAAAAL8"]
[Thu Jul 30 12:13:54.281852 2026] [core:notice] [pid 703393:tid 703640] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:54.288899 2026] [security2:error] [pid 703393:tid 703640] [client 103.215.74.26:9564] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGUs637Arlr6Yb1EcDIgAAAPo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:55.044860 2026] [core:notice] [pid 703393:tid 703598] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:55.051427 2026] [security2:error] [pid 703393:tid 703598] [client 103.215.74.26:9574] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGU8637Arlr6Yb1EcDMAAAANA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:55.084793 2026] [core:notice] [pid 703393:tid 703541] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:55.303937 2026] [security2:error] [pid 703393:tid 703597] [client 20.63.98.115:62824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-signup.php"] [unique_id "amuGU8637Arlr6Yb1EcDNgAAAM8"]
[Thu Jul 30 12:13:55.762774 2026] [security2:error] [pid 703393:tid 703624] [client 191.232.199.39:60755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/nc4.php"] [unique_id "amuGU8637Arlr6Yb1EcDOwAAAOo"]
[Thu Jul 30 12:13:55.793370 2026] [core:notice] [pid 703393:tid 703573] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:55.799896 2026] [security2:error] [pid 703393:tid 703573] [client 103.215.74.26:9576] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGU8637Arlr6Yb1EcDQAAAALc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:56.450327 2026] [security2:error] [pid 703393:tid 703620] [client 20.63.98.115:57218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/css/index.php"] [unique_id "amuGVM637Arlr6Yb1EcDXQAAAOY"]
[Thu Jul 30 12:13:56.529636 2026] [core:notice] [pid 703393:tid 703531] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:56.535505 2026] [security2:error] [pid 703393:tid 703531] [client 103.215.74.26:9580] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGVM637Arlr6Yb1EcDgwAAAI0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:57.059954 2026] [proxy:error] [pid 703393:tid 703569] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:13:57.060052 2026] [proxy_http:error] [pid 703393:tid 703569] [client 191.232.199.39:60743] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:13:57.060767 2026] [proxy:error] [pid 703393:tid 703569] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:13:57.060816 2026] [proxy_http:error] [pid 703393:tid 703569] [client 191.232.199.39:60743] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:13:57.270940 2026] [core:notice] [pid 703393:tid 703559] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:57.277615 2026] [security2:error] [pid 703393:tid 703559] [client 103.215.74.26:9588] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGVc637Arlr6Yb1EcDnQAAAKk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:58.054661 2026] [core:notice] [pid 703393:tid 703604] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:58.060722 2026] [security2:error] [pid 703393:tid 703604] [client 103.215.74.26:9590] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGVs637Arlr6Yb1EcDtQAAANY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:58.358394 2026] [security2:error] [pid 703393:tid 703407] [remote 57.141.0.54:33120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuGVs637Arlr6Yb1EcDtwAAxQ0"]
[Thu Jul 30 12:13:58.547663 2026] [security2:error] [pid 703393:tid 703555] [client 20.63.98.115:20885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/ge.php"] [unique_id "amuGVs637Arlr6Yb1EcDuwAAAKU"]
[Thu Jul 30 12:13:58.618308 2026] [core:notice] [pid 703393:tid 703639] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:58.643219 2026] [security2:error] [pid 703393:tid 703541] [client 146.103.115.7:54563] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuGVM637Arlr6Yb1EcDjQAAAJc"], referer: https://online-hope.com/xmlrpc.php
[Thu Jul 30 12:13:58.774483 2026] [security2:error] [pid 703393:tid 703643] [client 89.238.167.166:51762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuGVs637Arlr6Yb1EcDwwAAAP0"]
[Thu Jul 30 12:13:58.774588 2026] [security2:error] [pid 703393:tid 703643] [client 89.238.167.166:51762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuGVs637Arlr6Yb1EcDwwAAAP0"]
[Thu Jul 30 12:13:58.802442 2026] [core:notice] [pid 703393:tid 703621] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:58.809920 2026] [security2:error] [pid 703393:tid 703621] [client 103.215.74.26:9602] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGVs637Arlr6Yb1EcDxAAAAOc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:59.554778 2026] [core:notice] [pid 703393:tid 703563] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:59.561366 2026] [security2:error] [pid 703393:tid 703563] [client 103.215.74.26:9606] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGV8637Arlr6Yb1EcD0AAAAK0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:59.618512 2026] [security2:error] [pid 703393:tid 703594] [client 20.63.98.115:20886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/goods.php"] [unique_id "amuGV8637Arlr6Yb1EcD0gAAAMw"]
[Thu Jul 30 12:13:59.730266 2026] [security2:error] [pid 703393:tid 703586] [client 20.215.216.94:35704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/adminner.php"] [unique_id "amuGV8637Arlr6Yb1EcD1gAAAMQ"]
[Thu Jul 30 12:13:59.730359 2026] [security2:error] [pid 703393:tid 703586] [client 20.215.216.94:35704] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/adminner.php"] [unique_id "amuGV8637Arlr6Yb1EcD1gAAAMQ"]
[Thu Jul 30 12:13:59.817621 2026] [security2:error] [pid 703393:tid 703597] [client 87.201.220.126:60239] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "skcarrental.ae"] [uri "/index.php"] [unique_id "amuGV8637Arlr6Yb1EcD0QAAzyk"], referer: https://skcarrental.ae/car-type/monthly-car/?gad_source=1&gad_campaignid=23407362884&gbraid=0AAAABCcUrdmCj2hdePFXzuK89ExS49TME&gclid=CjwKCAjw7KvTBhA6EiwAWnutYT7TM1e7sTtzf3_4glgZsj6VbtVzH6Yz9lo4i36-pSHqaqej9B_nqRoCh3AQAvD_BwE
[Thu Jul 30 12:13:59.928717 2026] [core:notice] [pid 703393:tid 703626] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:00.201663 2026] [security2:error] [pid 703393:tid 703450] [remote 250.49.135.140:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuGWM637Arlr6Yb1EcD4gAAkzg"]
[Thu Jul 30 12:14:00.201835 2026] [security2:error] [pid 703393:tid 703537] [client 250.49.135.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuGWM637Arlr6Yb1EcD4gAAkzg"]
[Thu Jul 30 12:14:00.290310 2026] [core:notice] [pid 703393:tid 703538] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:00.296945 2026] [security2:error] [pid 703393:tid 703538] [client 103.215.74.26:9618] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGWM637Arlr6Yb1EcD5QAAAJQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:00.799227 2026] [security2:error] [pid 703393:tid 703612] [client 146.103.115.7:54864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuGV8637Arlr6Yb1EcDyAAAAN4"], referer: https://online-hope.com/xmlrpc.php
[Thu Jul 30 12:14:01.053959 2026] [core:notice] [pid 703393:tid 703604] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:01.060277 2026] [security2:error] [pid 703393:tid 703604] [client 103.215.74.26:9624] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGWc637Arlr6Yb1EcD8QAAANY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:01.133910 2026] [security2:error] [pid 703393:tid 703649] [client 20.63.98.115:47210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/403.php"] [unique_id "amuGWc637Arlr6Yb1EcD9QAAAQM"]
[Thu Jul 30 12:14:01.320048 2026] [security2:error] [pid 703393:tid 703410] [remote 157.55.39.58:6620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.39.55.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/-/media/Files/OGB/Soumu/article.php"] [unique_id "amuGWc637Arlr6Yb1EcD_gAAtxA"]
[Thu Jul 30 12:14:01.784108 2026] [core:notice] [pid 703393:tid 703614] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:01.790103 2026] [security2:error] [pid 703393:tid 703614] [client 103.215.74.26:9632] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGWc637Arlr6Yb1EcEAwAAAOA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:02.520849 2026] [core:notice] [pid 703393:tid 703527] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:02.527147 2026] [security2:error] [pid 703393:tid 703527] [client 103.215.74.26:9634] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGWs637Arlr6Yb1EcEDgAAAIk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:03.276454 2026] [core:notice] [pid 703393:tid 703537] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:03.282857 2026] [security2:error] [pid 703393:tid 703537] [client 103.215.74.26:10724] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGW8637Arlr6Yb1EcEGwAAAJM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:03.935560 2026] [security2:error] [pid 703393:tid 703584] [client 20.215.216.94:35659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/a.php"] [unique_id "amuGW8637Arlr6Yb1EcEJwAAAMI"]
[Thu Jul 30 12:14:03.935653 2026] [security2:error] [pid 703393:tid 703584] [client 20.215.216.94:35659] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/a.php"] [unique_id "amuGW8637Arlr6Yb1EcEJwAAAMI"]
[Thu Jul 30 12:14:04.034694 2026] [core:notice] [pid 703393:tid 703629] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:04.041421 2026] [security2:error] [pid 703393:tid 703629] [client 103.215.74.26:10730] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGXM637Arlr6Yb1EcEKQAAAO8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:04.778220 2026] [core:notice] [pid 703393:tid 703650] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:04.784279 2026] [security2:error] [pid 703393:tid 703650] [client 103.215.74.26:10732] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGXM637Arlr6Yb1EcEMgAAAQQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:05.507346 2026] [core:notice] [pid 703393:tid 703595] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:05.513409 2026] [security2:error] [pid 703393:tid 703595] [client 103.215.74.26:10738] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGXc637Arlr6Yb1EcETAAAAM0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:05.532882 2026] [security2:error] [pid 703393:tid 703552] [client 146.103.115.7:55443] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "online-hope.com"] [uri "/wp-admin/post-new.php"] [unique_id "amuGW8637Arlr6Yb1EcEHwAAAKI"], referer: https://online-hope.com/my-account/?action=register&xoo_el_reg_email=gb_caitlyntarenorerer%40falderewonek.site&xoo_el_reg_fname=Judy&xoo_el_reg_lname=Handcock&xoo_el_reg_pass=uFSL5SYn290x*5&xoo_el_reg_pass_again=uFSL5SYn290x*5&xoo_el_reg_terms=yes&_xoo_el_form=register&xoo_el_redirect=%2Fmy-account%2F%3Faction%3Dregister
[Thu Jul 30 12:14:06.238248 2026] [core:notice] [pid 703393:tid 703641] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:06.244657 2026] [security2:error] [pid 703393:tid 703641] [client 103.215.74.26:10750] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGXs637Arlr6Yb1EcEVwAAAPs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:06.355005 2026] [security2:error] [pid 703393:tid 703529] [client 20.215.216.94:35327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/k.php"] [unique_id "amuGXs637Arlr6Yb1EcEWAAAAIs"]
[Thu Jul 30 12:14:06.355116 2026] [security2:error] [pid 703393:tid 703529] [client 20.215.216.94:35327] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/k.php"] [unique_id "amuGXs637Arlr6Yb1EcEWAAAAIs"]
[Thu Jul 30 12:14:06.530296 2026] [core:notice] [pid 703393:tid 703615] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:06.551974 2026] [security2:error] [pid 703393:tid 703474] [remote 57.141.0.6:44720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/53909108632/feed/rss2/"] [unique_id "amuGXs637Arlr6Yb1EcEYAAAzFA"]
[Thu Jul 30 12:14:06.963261 2026] [core:notice] [pid 703393:tid 703642] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:06.969662 2026] [security2:error] [pid 703393:tid 703642] [client 103.215.74.26:10754] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGXs637Arlr6Yb1EcEZgAAAPw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:07.241557 2026] [security2:error] [pid 703393:tid 703485] [remote 160.191.139.115:46986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.139.191.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nfh.udi.temporary.site"] [uri "/wp-login.php"] [unique_id "amuGX8637Arlr6Yb1EcEawAAu1s"]
[Thu Jul 30 12:14:07.270438 2026] [security2:error] [pid 703393:tid 703611] [client 213.152.187.215:48840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.187.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuGX8637Arlr6Yb1EcEbQAAAN0"]
[Thu Jul 30 12:14:07.270521 2026] [security2:error] [pid 703393:tid 703611] [client 213.152.187.215:48840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuGX8637Arlr6Yb1EcEbQAAAN0"]
[Thu Jul 30 12:14:07.274815 2026] [security2:error] [pid 703393:tid 703554] [client 185.200.117.131:60416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.117.200.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuGX8637Arlr6Yb1EcEbAAAAKQ"]
[Thu Jul 30 12:14:07.274899 2026] [security2:error] [pid 703393:tid 703554] [client 185.200.117.131:60416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuGX8637Arlr6Yb1EcEbAAAAKQ"]
[Thu Jul 30 12:14:07.353216 2026] [security2:error] [pid 703393:tid 703621] [client 72.13.46.9:40584] ModSecurity: Warning. Matched phrase "ips-agent" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.kbsgg.click"] [uri "/robots.txt"] [unique_id "amuGX8637Arlr6Yb1EcEbgAAAOc"]
[Thu Jul 30 12:14:07.697049 2026] [core:notice] [pid 703393:tid 703598] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:07.703422 2026] [security2:error] [pid 703393:tid 703598] [client 103.215.74.26:10766] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGX8637Arlr6Yb1EcEdgAAANA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:08.807685 2026] [security2:error] [pid 703393:tid 703480] [remote 97.74.93.24:42712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/wp-login.php"] [unique_id "amuGYM637Arlr6Yb1EcEgwAA7FY"]
[Thu Jul 30 12:14:09.021908 2026] [security2:error] [pid 703393:tid 703526] [client 20.215.216.94:35296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/222.php"] [unique_id "amuGYc637Arlr6Yb1EcEhwAAAIg"]
[Thu Jul 30 12:14:09.022030 2026] [security2:error] [pid 703393:tid 703526] [client 20.215.216.94:35296] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/222.php"] [unique_id "amuGYc637Arlr6Yb1EcEhwAAAIg"]
[Thu Jul 30 12:14:10.909715 2026] [security2:error] [pid 703393:tid 703596] [client 20.63.98.115:20927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/public/makeasmtp.php"] [unique_id "amuGYs637Arlr6Yb1EcErQAAAM4"]
[Thu Jul 30 12:14:10.964043 2026] [security2:error] [pid 703393:tid 703554] [client 57.141.0.20:28756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuGYs637Arlr6Yb1EcEogAApE0"], referer: https://igetvape-australia.com/product/alibarbar-rich-8000-puffs-8/?add-to-cart=1055
[Thu Jul 30 12:14:11.136418 2026] [security2:error] [pid 703393:tid 703515] [remote 74.7.241.59:53852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuGY8637Arlr6Yb1EcEsQAAink"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/premium-addons-for-elementor/modules/woocommerce/templates
[Thu Jul 30 12:14:11.647854 2026] [security2:error] [pid 703393:tid 703545] [client 57.141.0.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuGY8637Arlr6Yb1EcEsAAAAJs"]
[Thu Jul 30 12:14:12.348738 2026] [security2:error] [pid 703393:tid 703605] [client 20.63.98.115:57270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/mar.php"] [unique_id "amuGZM637Arlr6Yb1EcExAAAANc"]
[Thu Jul 30 12:14:12.566961 2026] [security2:error] [pid 703393:tid 703562] [client 57.141.0.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuGY8637Arlr6Yb1EcEwAAAAKw"]
[Thu Jul 30 12:14:13.054278 2026] [security2:error] [pid 703393:tid 703531] [client 20.215.216.94:35286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/mac.php"] [unique_id "amuGZc637Arlr6Yb1EcEzgAAAI0"]
[Thu Jul 30 12:14:13.054405 2026] [security2:error] [pid 703393:tid 703531] [client 20.215.216.94:35286] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/mac.php"] [unique_id "amuGZc637Arlr6Yb1EcEzgAAAI0"]
[Thu Jul 30 12:14:13.427173 2026] [core:notice] [pid 703393:tid 703585] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:13.433411 2026] [security2:error] [pid 703393:tid 703585] [client 103.215.74.26:6336] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGZc637Arlr6Yb1EcE1QAAAMM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:13.859125 2026] [security2:error] [pid 703393:tid 703520] [remote 57.141.0.68:37434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuGZc637Arlr6Yb1EcE2gAAzX4"]
[Thu Jul 30 12:14:13.901515 2026] [security2:error] [pid 703393:tid 703559] [client 20.63.98.115:43288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/system.php"] [unique_id "amuGZc637Arlr6Yb1EcE3QAAAKk"]
[Thu Jul 30 12:14:14.033577 2026] [security2:error] [pid 703393:tid 703511] [remote 74.7.241.60:48972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/article.php"] [unique_id "amuGZs637Arlr6Yb1EcE3wAAxnU"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/main_image_6a3229a631e84.jpg
[Thu Jul 30 12:14:14.151151 2026] [core:notice] [pid 703393:tid 703601] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:14.157493 2026] [security2:error] [pid 703393:tid 703601] [client 103.215.74.26:6342] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGZs637Arlr6Yb1EcE4QAAANM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:14.567013 2026] [security2:error] [pid 703393:tid 703546] [client 2a03:2880:f800:2d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuGZc637Arlr6Yb1EcE3gAAnHQ"]
[Thu Jul 30 12:14:14.889928 2026] [core:notice] [pid 703393:tid 703563] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:14.896231 2026] [security2:error] [pid 703393:tid 703563] [client 103.215.74.26:6346] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGZs637Arlr6Yb1EcE7AAAAK0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:15.368813 2026] [security2:error] [pid 703393:tid 703597] [client 20.63.98.115:62792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/lock360.php"] [unique_id "amuGZ8637Arlr6Yb1EcE9gAAAM8"]
[Thu Jul 30 12:14:15.634002 2026] [core:notice] [pid 703393:tid 703634] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:15.640192 2026] [security2:error] [pid 703393:tid 703634] [client 103.215.74.26:6354] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGZ8637Arlr6Yb1EcE-gAAAPQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:16.391273 2026] [core:notice] [pid 703393:tid 703581] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:16.397394 2026] [security2:error] [pid 703393:tid 703581] [client 103.215.74.26:6370] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGaM637Arlr6Yb1EcFBAAAAL8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:17.120273 2026] [core:notice] [pid 703393:tid 703532] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:17.126213 2026] [security2:error] [pid 703393:tid 703532] [client 103.215.74.26:6372] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGac637Arlr6Yb1EcFDgAAAI4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:17.325518 2026] [core:notice] [pid 703393:tid 703443] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:17.865833 2026] [core:notice] [pid 703393:tid 703627] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:17.872188 2026] [security2:error] [pid 703393:tid 703627] [client 103.215.74.26:6380] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGac637Arlr6Yb1EcFHwAAAO0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:17.938907 2026] [core:error] [pid 703393:tid 703590] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:14:17.938927 2026] [core:error] [pid 703393:tid 703590] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:14:18.075584 2026] [security2:error] [pid 703393:tid 703539] [client 20.63.98.115:31862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "amuGas637Arlr6Yb1EcFKQAAAJU"]
[Thu Jul 30 12:14:18.365444 2026] [security2:error] [pid 703393:tid 703577] [client 2a03:2880:f800:1d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuGac637Arlr6Yb1EcFHgAAuw8"]
[Thu Jul 30 12:14:18.604514 2026] [core:notice] [pid 703393:tid 703607] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:18.611043 2026] [security2:error] [pid 703393:tid 703607] [client 103.215.74.26:6388] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGas637Arlr6Yb1EcFNQAAANk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:18.726792 2026] [security2:error] [pid 703393:tid 703423] [remote 67.207.94.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.94.207.67.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "totalwebsite.biz"] [uri "/wp-login.php"] [unique_id "amuGas637Arlr6Yb1EcFNAAA_h0"]
[Thu Jul 30 12:14:19.230398 2026] [security2:error] [pid 703393:tid 703567] [client 85.107.110.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuGa8637Arlr6Yb1EcFSQAAALE"], referer: https://cnpinyin.com
[Thu Jul 30 12:14:19.288755 2026] [security2:error] [pid 703393:tid 703557] [client 20.63.98.115:31865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/mah.php"] [unique_id "amuGa8637Arlr6Yb1EcFUQAAAKc"]
[Thu Jul 30 12:14:19.328354 2026] [lsapi:error] [pid 703393:tid 703397] [remote 102.209.111.62:0] [host flixon.net] Error receiving response: ReceiveResponse: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1009; user ID 1009), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://flixon.net/video/love-hurts-vj-junior/
[Thu Jul 30 12:14:19.915622 2026] [security2:error] [pid 703393:tid 703634] [client 216.244.66.196:44122] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amuGa8637Arlr6Yb1EcFXQAAAPQ"]
[Thu Jul 30 12:14:19.915716 2026] [security2:error] [pid 703393:tid 703634] [client 216.244.66.196:44122] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amuGa8637Arlr6Yb1EcFXQAAAPQ"]
[Thu Jul 30 12:14:20.317429 2026] [autoindex:error] [pid 703393:tid 703554] [client 20.63.98.115:20899] AH01276: Cannot serve directory /home1/wdrgplte/public_html/jesus.claims/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:14:20.605641 2026] [security2:error] [pid 703393:tid 703582] [client 20.63.98.115:20899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-class.php"] [unique_id "amuGbM637Arlr6Yb1EcFbQAAAMA"]
[Thu Jul 30 12:14:21.165571 2026] [security2:error] [pid 703393:tid 703558] [client 185.200.117.131:44872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.117.200.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuGbc637Arlr6Yb1EcFeAAAAKg"]
[Thu Jul 30 12:14:21.165670 2026] [security2:error] [pid 703393:tid 703558] [client 185.200.117.131:44872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuGbc637Arlr6Yb1EcFeAAAAKg"]
[Thu Jul 30 12:14:22.240550 2026] [security2:error] [pid 703393:tid 703577] [client 20.63.98.115:31861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/backup.php"] [unique_id "amuGbs637Arlr6Yb1EcFiQAAALs"]
[Thu Jul 30 12:14:22.732514 2026] [security2:error] [pid 703393:tid 703504] [remote 57.141.0.46:37826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuGbs637Arlr6Yb1EcFmwAAxm4"]
[Thu Jul 30 12:14:23.074191 2026] [security2:error] [pid 703393:tid 703622] [client 20.63.98.115:31849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/default.php"] [unique_id "amuGb8637Arlr6Yb1EcFogAAAOg"]
[Thu Jul 30 12:14:24.164832 2026] [security2:error] [pid 703393:tid 703525] [client 20.63.98.115:62804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/maint/about.php"] [unique_id "amuGcM637Arlr6Yb1EcFvQAAAIc"]
[Thu Jul 30 12:14:24.371701 2026] [core:notice] [pid 703393:tid 703584] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:24.378210 2026] [security2:error] [pid 703393:tid 703584] [client 103.215.74.26:2660] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGcM637Arlr6Yb1EcFwQAAAMI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:24.928653 2026] [security2:error] [pid 703393:tid 703632] [client 20.63.98.115:57298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/uploads/2022/10/upload.php"] [unique_id "amuGcM637Arlr6Yb1EcFyQAAAPI"]
[Thu Jul 30 12:14:25.104465 2026] [core:notice] [pid 703393:tid 703635] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:25.111045 2026] [security2:error] [pid 703393:tid 703635] [client 103.215.74.26:2664] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGcc637Arlr6Yb1EcFzgAAAPU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:25.835991 2026] [core:notice] [pid 703393:tid 703529] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:25.846567 2026] [security2:error] [pid 703393:tid 703529] [client 103.215.74.26:2666] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGcc637Arlr6Yb1EcF4AAAAIs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:26.079114 2026] [security2:error] [pid 703393:tid 703640] [client 20.63.98.115:62790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/ty.php"] [unique_id "amuGcs637Arlr6Yb1EcF6AAAAPo"]
[Thu Jul 30 12:14:26.585264 2026] [core:notice] [pid 703393:tid 703597] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:26.591724 2026] [security2:error] [pid 703393:tid 703597] [client 103.215.74.26:2674] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGcs637Arlr6Yb1EcF7wAAAM8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:26.786943 2026] [security2:error] [pid 703393:tid 703480] [remote 250.49.135.140:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuGcs637Arlr6Yb1EcF8QAAxFY"]
[Thu Jul 30 12:14:26.787154 2026] [security2:error] [pid 703393:tid 703586] [client 250.49.135.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuGcs637Arlr6Yb1EcF8QAAxFY"]
[Thu Jul 30 12:14:27.340468 2026] [core:notice] [pid 703393:tid 703621] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:27.346734 2026] [security2:error] [pid 703393:tid 703621] [client 103.215.74.26:2684] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGc8637Arlr6Yb1EcF_AAAAOc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:27.383509 2026] [security2:error] [pid 703393:tid 703582] [client 20.63.98.115:38003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/readme.php"] [unique_id "amuGc8637Arlr6Yb1EcF_wAAAMA"]
[Thu Jul 30 12:14:28.085297 2026] [core:notice] [pid 703393:tid 703607] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:28.091297 2026] [security2:error] [pid 703393:tid 703607] [client 103.215.74.26:2692] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGdM637Arlr6Yb1EcGCQAAANk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:28.801328 2026] [security2:error] [pid 703393:tid 703646] [client 20.63.98.115:62803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/options.php"] [unique_id "amuGdM637Arlr6Yb1EcGGAAAAQA"]
[Thu Jul 30 12:14:28.821990 2026] [core:notice] [pid 703393:tid 703564] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:28.828668 2026] [security2:error] [pid 703393:tid 703564] [client 103.215.74.26:2700] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGdM637Arlr6Yb1EcGGQAAAK4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:28.897800 2026] [security2:error] [pid 703393:tid 703643] [client 127.0.0.1:12210] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuGdM637Arlr6Yb1EcGHgAAAP0"]
[Thu Jul 30 12:14:28.897889 2026] [security2:error] [pid 703393:tid 703578] [client 74.7.228.35:56120] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.dov.dtn.temporary.site"] [uri "/robots.txt"] [unique_id "amuGdM637Arlr6Yb1EcGHQAAvH8"]
[Thu Jul 30 12:14:28.997672 2026] [security2:error] [pid 703393:tid 703648] [client 57.141.0.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuGdM637Arlr6Yb1EcGEwAAAQI"]
[Thu Jul 30 12:14:29.550569 2026] [security2:error] [pid 703393:tid 703561] [client 220.181.108.113:61903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.108.181.220.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/cicee/article/view/9466"] [unique_id "amuGdc637Arlr6Yb1EcGLAAAAKs"]
[Thu Jul 30 12:14:29.557272 2026] [core:notice] [pid 703393:tid 703547] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:29.563811 2026] [security2:error] [pid 703393:tid 703547] [client 103.215.74.26:2724] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGdc637Arlr6Yb1EcGLQAAAJ0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:30.025778 2026] [security2:error] [pid 703393:tid 703540] [client 20.63.98.115:62815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/admin.php7"] [unique_id "amuGds637Arlr6Yb1EcGOgAAAJY"]
[Thu Jul 30 12:14:30.297211 2026] [core:notice] [pid 703393:tid 703581] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:30.303636 2026] [security2:error] [pid 703393:tid 703581] [client 103.215.74.26:2744] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGds637Arlr6Yb1EcGQwAAAL8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:30.308625 2026] [security2:error] [pid 703393:tid 703616] [client 17.246.23.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuGds637Arlr6Yb1EcGQQAAAOI"]
[Thu Jul 30 12:14:30.534024 2026] [core:notice] [pid 703393:tid 703541] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:30.573223 2026] [core:notice] [pid 703393:tid 703529] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:31.021222 2026] [core:notice] [pid 703393:tid 703648] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:31.026787 2026] [security2:error] [pid 703393:tid 703648] [client 103.215.74.26:2760] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGd8637Arlr6Yb1EcGgAAAAQI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:31.716777 2026] [security2:error] [pid 703393:tid 703625] [client 20.63.98.115:57325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/.well-known/wp-login.php"] [unique_id "amuGd8637Arlr6Yb1EcGoAAAAOs"]
[Thu Jul 30 12:14:31.764404 2026] [core:notice] [pid 703393:tid 703620] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:31.770916 2026] [security2:error] [pid 703393:tid 703620] [client 103.215.74.26:2768] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGd8637Arlr6Yb1EcGoQAAAOY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:32.171617 2026] [security2:error] [pid 703393:tid 703576] [client 136.114.127.127:35034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "www.shop-peace.com"] [uri "/index.cgi"] [unique_id "amuGeM637Arlr6Yb1EcGsgAAALo"]
[Thu Jul 30 12:14:32.507354 2026] [security2:error] [pid 703393:tid 703528] [client 20.63.98.115:57293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amuGeM637Arlr6Yb1EcGtQAAAIo"]
[Thu Jul 30 12:14:32.513508 2026] [core:notice] [pid 703393:tid 703572] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:32.519753 2026] [security2:error] [pid 703393:tid 703572] [client 103.215.74.26:2782] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGeM637Arlr6Yb1EcGtgAAALY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:33.252518 2026] [core:notice] [pid 703393:tid 703636] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:33.258783 2026] [security2:error] [pid 703393:tid 703636] [client 103.215.74.26:2260] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGec637Arlr6Yb1EcGwwAAAPY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:34.024621 2026] [core:notice] [pid 703393:tid 703560] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:34.031201 2026] [security2:error] [pid 703393:tid 703560] [client 103.215.74.26:2268] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGes637Arlr6Yb1EcGzgAAAKo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:34.321257 2026] [security2:error] [pid 703393:tid 703556] [client 20.63.98.115:37996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/file.php"] [unique_id "amuGes637Arlr6Yb1EcG1QAAAKY"]
[Thu Jul 30 12:14:34.474413 2026] [core:notice] [pid 703393:tid 703474] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:34.770874 2026] [core:notice] [pid 703393:tid 703540] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:34.777294 2026] [security2:error] [pid 703393:tid 703540] [client 103.215.74.26:2278] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGes637Arlr6Yb1EcG4QAAAJY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:35.165013 2026] [security2:error] [pid 703393:tid 703562] [client 20.63.98.115:37980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/bak.php"] [unique_id "amuGe8637Arlr6Yb1EcG6AAAAKw"]
[Thu Jul 30 12:14:35.988357 2026] [core:notice] [pid 703393:tid 703487] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:36.377200 2026] [core:notice] [pid 703393:tid 703633] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:36.838303 2026] [security2:error] [pid 703393:tid 703538] [client 57.141.0.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuGfM637Arlr6Yb1EcG-gAAAJQ"]
[Thu Jul 30 12:14:37.167309 2026] [security2:error] [pid 703393:tid 703614] [client 20.63.98.115:62667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/config.php"] [unique_id "amuGfc637Arlr6Yb1EcHBgAAAOA"]
[Thu Jul 30 12:14:37.936173 2026] [security2:error] [pid 703393:tid 703616] [client 20.63.98.115:31809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/uploads/2025/03/themes.php"] [unique_id "amuGfc637Arlr6Yb1EcHFwAAAOI"]
[Thu Jul 30 12:14:38.677653 2026] [core:error] [pid 703393:tid 703512] (36)File name too long: [remote 173.214.181.134:51584] AH00036: access to />","sale_flash_html":""},{"attributes":{"attribute_size":"44"},"availability_html":"","backorders_allowed":false,"dimensions":{"length":"","width":"","height":""},"dimensions_html":"N/A","display_price":209.9,"display_regular_price":209.9,"image":{"title":"8765f1ca-scaled-1.jpg","caption":"","url":"https:/kicksity.com/wp-content/uploads/2024/08/8765f1ca-scaled-1.jpg","alt":"8765f1ca-scaled-1.jpg","src":"https:/kicksity.com/wp-content/uploads/2024/08/8765f1ca-scaled-1-600x400.jpg","srcset":"https:/kicksity.com/wp-content/uploads/2024/08/8765f1ca-scaled-1-600x400.jpg failed (filesystem path '/home1/vdbnyxte/public_html/website_3f9373c9/>","sale_flash_html":""},{"attributes":{"attribute_size":"44"},"availability_html":"","backorders_allowed":false,"dimensions":{"length":"","width":"","height":""},"dimensions_html":"N'), referer: https://kicksity.com/product/nike-air-jordan-4-mushroom/
[Thu Jul 30 12:14:39.235371 2026] [security2:error] [pid 703393:tid 703636] [client 3.79.134.69:12992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuGf8637Arlr6Yb1EcHKgAAAPY"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:14:39.470760 2026] [security2:error] [pid 703393:tid 703515] [remote 250.49.135.140:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuGfs637Arlr6Yb1EcHIwAA8Xk"]
[Thu Jul 30 12:14:39.470997 2026] [security2:error] [pid 703393:tid 703631] [client 250.49.135.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuGfs637Arlr6Yb1EcHIwAA8Xk"]
[Thu Jul 30 12:14:39.775410 2026] [security2:error] [pid 703393:tid 703638] [client 20.63.98.115:62698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-activate.php"] [unique_id "amuGf8637Arlr6Yb1EcHMgAAAPg"]
[Thu Jul 30 12:14:39.829721 2026] [core:notice] [pid 703393:tid 703605] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:39.833994 2026] [security2:error] [pid 703393:tid 703605] [client 3.79.134.69:12994] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGf8637Arlr6Yb1EcHMwAAANc"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:14:40.500105 2026] [core:notice] [pid 703393:tid 703632] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:40.506449 2026] [security2:error] [pid 703393:tid 703632] [client 103.215.74.26:2292] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGgM637Arlr6Yb1EcHQAAAAPI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:40.616226 2026] [security2:error] [pid 703393:tid 703589] [client 3.79.134.69:12998] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuGgM637Arlr6Yb1EcHSQAAAMc"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:14:40.687821 2026] [security2:error] [pid 703393:tid 703536] [client 103.133.205.238:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuGgM637Arlr6Yb1EcHSAAAAJI"], referer: http://cnpinyin.com
[Thu Jul 30 12:14:41.204266 2026] [security2:error] [pid 703393:tid 703550] [client 121.229.156.119:45888] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product-category/sneaker/louis-vuitton/"] [unique_id "amuGgc637Arlr6Yb1EcHUQAAAKA"]
[Thu Jul 30 12:14:41.204396 2026] [security2:error] [pid 703393:tid 703550] [client 121.229.156.119:45888] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/product-category/sneaker/louis-vuitton/"] [unique_id "amuGgc637Arlr6Yb1EcHUQAAAKA"]
[Thu Jul 30 12:14:41.257008 2026] [core:notice] [pid 703393:tid 703572] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:41.263270 2026] [security2:error] [pid 703393:tid 703572] [client 103.215.74.26:2302] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGgc637Arlr6Yb1EcHUgAAALY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:41.365035 2026] [security2:error] [pid 703393:tid 703608] [client 20.63.98.115:57339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-file.php"] [unique_id "amuGgc637Arlr6Yb1EcHUwAAANo"]
[Thu Jul 30 12:14:41.795479 2026] [core:notice] [pid 703393:tid 703624] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:41.999216 2026] [core:notice] [pid 703393:tid 703590] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:42.005099 2026] [security2:error] [pid 703393:tid 703590] [client 103.215.74.26:2316] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGgc637Arlr6Yb1EcHXQAAAMg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:42.129439 2026] [security2:error] [pid 703393:tid 703542] [client 20.63.98.115:57324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/12.php"] [unique_id "amuGgs637Arlr6Yb1EcHYgAAAJg"]
[Thu Jul 30 12:14:42.433347 2026] [security2:error] [pid 703393:tid 703629] [client 40.77.167.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuGgM637Arlr6Yb1EcHPgAAAO8"]
[Thu Jul 30 12:14:42.707585 2026] [core:notice] [pid 703393:tid 703636] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:42.741076 2026] [core:notice] [pid 703393:tid 703526] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:42.747335 2026] [security2:error] [pid 703393:tid 703526] [client 103.215.74.26:2318] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGgs637Arlr6Yb1EcHbwAAAIg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:43.348306 2026] [security2:error] [pid 703393:tid 703649] [client 20.63.98.115:61358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/epinyins.php"] [unique_id "amuGg8637Arlr6Yb1EcHeQAAAQM"]
[Thu Jul 30 12:14:43.370662 2026] [security2:error] [pid 703393:tid 703615] [client 40.77.167.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuGg8637Arlr6Yb1EcHcwAAAOE"]
[Thu Jul 30 12:14:43.483589 2026] [core:notice] [pid 703393:tid 703623] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:43.489887 2026] [security2:error] [pid 703393:tid 703623] [client 103.215.74.26:31954] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGg8637Arlr6Yb1EcHegAAAOk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:43.746454 2026] [security2:error] [pid 703393:tid 703570] [client 185.200.117.131:57732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.117.200.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuGg8637Arlr6Yb1EcHgQAAALQ"]
[Thu Jul 30 12:14:43.746567 2026] [security2:error] [pid 703393:tid 703570] [client 185.200.117.131:57732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuGg8637Arlr6Yb1EcHgQAAALQ"]
[Thu Jul 30 12:14:44.233482 2026] [core:notice] [pid 703393:tid 703562] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:44.239599 2026] [security2:error] [pid 703393:tid 703562] [client 103.215.74.26:31966] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGhM637Arlr6Yb1EcHhgAAAKw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:44.973274 2026] [core:notice] [pid 703393:tid 703529] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:44.979513 2026] [security2:error] [pid 703393:tid 703529] [client 103.215.74.26:31980] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGhM637Arlr6Yb1EcHjwAAAIs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:45.252628 2026] [security2:error] [pid 703393:tid 703587] [client 185.200.117.131:57746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.117.200.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuGhc637Arlr6Yb1EcHnAAAAMU"]
[Thu Jul 30 12:14:45.252733 2026] [security2:error] [pid 703393:tid 703587] [client 185.200.117.131:57746] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuGhc637Arlr6Yb1EcHnAAAAMU"]
[Thu Jul 30 12:14:45.352768 2026] [security2:error] [pid 703393:tid 703547] [client 185.189.112.11:50856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.112.189.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuGhc637Arlr6Yb1EcHngAAAJ0"]
[Thu Jul 30 12:14:45.352874 2026] [security2:error] [pid 703393:tid 703547] [client 185.189.112.11:50856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuGhc637Arlr6Yb1EcHngAAAJ0"]
[Thu Jul 30 12:14:45.421273 2026] [security2:error] [pid 703393:tid 703635] [client 40.77.167.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuGhc637Arlr6Yb1EcHlQAAAPU"]
[Thu Jul 30 12:14:45.702340 2026] [core:notice] [pid 703393:tid 703535] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:45.712772 2026] [security2:error] [pid 703393:tid 703535] [client 103.215.74.26:31992] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGhc637Arlr6Yb1EcHpQAAAJE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:45.952084 2026] [security2:error] [pid 703393:tid 703538] [client 20.63.98.115:39120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "amuGhc637Arlr6Yb1EcHqQAAAJQ"]
[Thu Jul 30 12:14:46.431421 2026] [security2:error] [pid 703393:tid 703534] [client 172.236.9.101:43223] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/api/.env"] [unique_id "amuGhs637Arlr6Yb1EcHsgAAAJA"]
[Thu Jul 30 12:14:46.727669 2026] [security2:error] [pid 703393:tid 703640] [client 20.63.98.115:38896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/system_log.php"] [unique_id "amuGhs637Arlr6Yb1EcHtQAAAPo"]
[Thu Jul 30 12:14:47.370591 2026] [core:notice] [pid 703393:tid 703420] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:47.746290 2026] [security2:error] [pid 703393:tid 703625] [client 172.236.9.101:50165] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGhs637Arlr6Yb1EcHsQAAAOs"]
[Thu Jul 30 12:14:48.211827 2026] [security2:error] [pid 703393:tid 703642] [client 20.63.98.115:44003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuGiM637Arlr6Yb1EcHygAAAPw"]
[Thu Jul 30 12:14:49.079639 2026] [security2:error] [pid 703393:tid 703569] [client 77.75.78.165:14381] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.alseermarine.com"] [uri "/robots.txt"] [unique_id "amuGic637Arlr6Yb1EcH2wAAALM"]
[Thu Jul 30 12:14:49.079761 2026] [security2:error] [pid 703393:tid 703569] [client 77.75.78.165:14381] ModSecurity: Warning. Matched phrase "Seznam" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.alseermarine.com"] [uri "/robots.txt"] [unique_id "amuGic637Arlr6Yb1EcH2wAAALM"]
[Thu Jul 30 12:14:49.124842 2026] [security2:error] [pid 703393:tid 703596] [client 77.75.78.165:23829] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.alseermarine.com"] [uri "/contact/"] [unique_id "amuGic637Arlr6Yb1EcH3AAAAM4"]
[Thu Jul 30 12:14:49.124946 2026] [security2:error] [pid 703393:tid 703596] [client 77.75.78.165:23829] ModSecurity: Warning. Matched phrase "Seznam" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.alseermarine.com"] [uri "/contact/"] [unique_id "amuGic637Arlr6Yb1EcH3AAAAM4"]
[Thu Jul 30 12:14:49.131897 2026] [security2:error] [pid 703393:tid 703454] [remote 15.235.27.14:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "spececigarette.com"] [uri "/brand/mond/"] [unique_id "amuGic637Arlr6Yb1EcH3QAA8Tw"]
[Thu Jul 30 12:14:49.132030 2026] [security2:error] [pid 703393:tid 703631] [client 15.235.27.14:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "spececigarette.com"] [uri "/brand/mond/"] [unique_id "amuGic637Arlr6Yb1EcH3QAA8Tw"]
[Thu Jul 30 12:14:49.171898 2026] [security2:error] [pid 703393:tid 703641] [client 77.75.78.165:31262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.alseermarine.com"] [uri "/robots.txt"] [unique_id "amuGic637Arlr6Yb1EcH3gAAAPs"]
[Thu Jul 30 12:14:49.172008 2026] [security2:error] [pid 703393:tid 703641] [client 77.75.78.165:31262] ModSecurity: Warning. Matched phrase "Seznam" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.alseermarine.com"] [uri "/robots.txt"] [unique_id "amuGic637Arlr6Yb1EcH3gAAAPs"]
[Thu Jul 30 12:14:51.161408 2026] [security2:error] [pid 703393:tid 703609] [client 57.141.0.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuGis637Arlr6Yb1EcIAQAAANs"]
[Thu Jul 30 12:14:51.372247 2026] [core:error] [pid 703393:tid 703601] [client 40.77.167.219:33486] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:14:51.372272 2026] [core:error] [pid 703393:tid 703601] [client 40.77.167.219:33486] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:14:51.523539 2026] [core:notice] [pid 703393:tid 703619] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:51.529443 2026] [security2:error] [pid 703393:tid 703619] [client 103.215.74.26:32006] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGi8637Arlr6Yb1EcIDwAAAOU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:51.827113 2026] [security2:error] [pid 703393:tid 703425] [remote 250.49.135.140:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuGi8637Arlr6Yb1EcIEQAAkx8"]
[Thu Jul 30 12:14:51.827268 2026] [security2:error] [pid 703393:tid 703537] [client 250.49.135.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuGi8637Arlr6Yb1EcIEQAAkx8"]
[Thu Jul 30 12:14:51.862211 2026] [core:notice] [pid 703393:tid 703396] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:52.124240 2026] [security2:error] [pid 703393:tid 703649] [client 74.7.230.42:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.xyu.gpl.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuGjM637Arlr6Yb1EcIHQAAAQM"]
[Thu Jul 30 12:14:52.124905 2026] [security2:error] [pid 703393:tid 703631] [client 74.7.230.42:44934] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.xyu.gpl.temporary.site"] [uri "/robots.txt"] [unique_id "amuGjM637Arlr6Yb1EcIGwAA8VI"]
[Thu Jul 30 12:14:52.279313 2026] [core:notice] [pid 703393:tid 703647] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:52.285403 2026] [security2:error] [pid 703393:tid 703647] [client 103.215.74.26:32012] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGjM637Arlr6Yb1EcIIQAAAQE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:54.524676 2026] [security2:error] [pid 703393:tid 703480] [remote 57.141.0.16:48008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amuGjs637Arlr6Yb1EcIVgABAVY"]
[Thu Jul 30 12:14:54.838190 2026] [security2:error] [pid 703393:tid 703639] [client 85.208.96.200:38878] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/06/17/na-radio-rural-todo-sabado-das-13h-as-15h-o-paraiba-em-debate-entra-no-ar-com-o-bom-jornalismo/"] [unique_id "amuGjs637Arlr6Yb1EcIXQAAAPk"]
[Thu Jul 30 12:14:54.838302 2026] [security2:error] [pid 703393:tid 703639] [client 85.208.96.200:38878] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/06/17/na-radio-rural-todo-sabado-das-13h-as-15h-o-paraiba-em-debate-entra-no-ar-com-o-bom-jornalismo/"] [unique_id "amuGjs637Arlr6Yb1EcIXQAAAPk"]
[Thu Jul 30 12:14:55.711652 2026] [security2:error] [pid 703393:tid 703650] [client 20.63.98.115:49932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/ini.php"] [unique_id "amuGj8637Arlr6Yb1EcIcgAAAQQ"]
[Thu Jul 30 12:14:56.484660 2026] [security2:error] [pid 703393:tid 703508] [remote 57.141.0.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuGkM637Arlr6Yb1EcIfgAAy3I"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_brand=desigual&filter_materials=aluminum,carbon,denim,nylon,polyester,silicon,steel,linen&filter_size=small&rating=5&status=instock&unfilter=1
[Thu Jul 30 12:14:56.545613 2026] [security2:error] [pid 703393:tid 703518] [remote 57.141.0.1:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuGkM637Arlr6Yb1EcIfwAAvnw"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_brand=desigual&filter_materials=aluminum,carbon,denim,nylon,polyester,silicon,steel,linen&filter_size=small&rating=5&status=instock&unfilter=1
[Thu Jul 30 12:14:57.148407 2026] [security2:error] [pid 703393:tid 703536] [client 47.128.121.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuGkc637Arlr6Yb1EcIigAAAJI"]
[Thu Jul 30 12:14:57.462153 2026] [security2:error] [pid 703393:tid 703540] [client 20.63.98.115:27224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/ok.php"] [unique_id "amuGkc637Arlr6Yb1EcIkQAAAJY"]
[Thu Jul 30 12:14:57.865505 2026] [security2:error] [pid 703393:tid 703552] [client 188.129.154.230:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuGkc637Arlr6Yb1EcIlwAAAKI"], referer: http://cnpinyin.com
[Thu Jul 30 12:14:58.009331 2026] [core:notice] [pid 703393:tid 703625] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:58.015791 2026] [security2:error] [pid 703393:tid 703625] [client 103.215.74.26:11450] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGks637Arlr6Yb1EcImwAAAOs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:58.142149 2026] [security2:error] [pid 703393:tid 703599] [client 213.152.187.215:45678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.187.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuGks637Arlr6Yb1EcInwAAANE"]
[Thu Jul 30 12:14:58.142287 2026] [security2:error] [pid 703393:tid 703599] [client 213.152.187.215:45678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuGks637Arlr6Yb1EcInwAAANE"]
[Thu Jul 30 12:14:58.315731 2026] [core:notice] [pid 703393:tid 703546] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:58.761411 2026] [core:notice] [pid 703393:tid 703537] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:58.770776 2026] [security2:error] [pid 703393:tid 703537] [client 103.215.74.26:11458] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGks637Arlr6Yb1EcIrAAAAJM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:59.279238 2026] [security2:error] [pid 703393:tid 703571] [client 20.63.98.115:32445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/includes/about.php"] [unique_id "amuGk8637Arlr6Yb1EcItQAAALU"]
[Thu Jul 30 12:14:59.496951 2026] [core:notice] [pid 703393:tid 703577] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:59.503261 2026] [security2:error] [pid 703393:tid 703577] [client 103.215.74.26:11460] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGk8637Arlr6Yb1EcIuQAAALs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:15:00.269054 2026] [core:notice] [pid 703393:tid 703544] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:00.275696 2026] [security2:error] [pid 703393:tid 703544] [client 103.215.74.26:11472] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGlM637Arlr6Yb1EcIwgAAAJo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:15:00.473309 2026] [security2:error] [pid 703393:tid 703611] [client 185.191.171.8:53030] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/04/12/setor-de-servicos-recua-02-em-fevereiro-e-tem-2a-queda-seguida/"] [unique_id "amuGlM637Arlr6Yb1EcIxgAAAN0"]
[Thu Jul 30 12:15:00.473484 2026] [security2:error] [pid 703393:tid 703611] [client 185.191.171.8:53030] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/04/12/setor-de-servicos-recua-02-em-fevereiro-e-tem-2a-queda-seguida/"] [unique_id "amuGlM637Arlr6Yb1EcIxgAAAN0"]
[Thu Jul 30 12:15:00.860944 2026] [security2:error] [pid 703393:tid 703414] [remote 57.141.0.14:32802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuGlM637Arlr6Yb1EcIzAAAnBQ"]
[Thu Jul 30 12:15:01.015255 2026] [core:notice] [pid 703393:tid 703574] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:01.020942 2026] [security2:error] [pid 703393:tid 703574] [client 103.215.74.26:11484] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGlc637Arlr6Yb1EcI0gAAALg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:15:01.773560 2026] [core:notice] [pid 703393:tid 703647] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:01.779912 2026] [security2:error] [pid 703393:tid 703647] [client 103.215.74.26:11488] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGlc637Arlr6Yb1EcI5AAAAQE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:15:02.506259 2026] [core:notice] [pid 703393:tid 703579] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:02.512592 2026] [security2:error] [pid 703393:tid 703579] [client 103.215.74.26:11498] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGls637Arlr6Yb1EcI8AAAAL0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:15:02.818411 2026] [security2:error] [pid 703393:tid 703642] [client 216.244.66.236:54594] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amuGls637Arlr6Yb1EcI-AAAAPw"]
[Thu Jul 30 12:15:02.818523 2026] [security2:error] [pid 703393:tid 703642] [client 216.244.66.236:54594] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amuGls637Arlr6Yb1EcI-AAAAPw"]
[Thu Jul 30 12:15:02.828786 2026] [security2:error] [pid 703393:tid 703615] [client 216.244.66.236:54608] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amuGls637Arlr6Yb1EcI-QAAAOE"]
[Thu Jul 30 12:15:02.828877 2026] [security2:error] [pid 703393:tid 703615] [client 216.244.66.236:54608] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amuGls637Arlr6Yb1EcI-QAAAOE"]
[Thu Jul 30 12:15:03.266171 2026] [core:notice] [pid 703393:tid 703620] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:03.276522 2026] [security2:error] [pid 703393:tid 703620] [client 103.215.74.26:48050] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGl8637Arlr6Yb1EcJAwAAAOY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:15:03.372447 2026] [core:notice] [pid 703393:tid 703452] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:03.769380 2026] [core:notice] [pid 703393:tid 703423] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:04.002048 2026] [core:notice] [pid 703393:tid 703558] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:04.008266 2026] [security2:error] [pid 703393:tid 703558] [client 103.215.74.26:48052] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGmM637Arlr6Yb1EcJGAAAAKg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:15:04.294513 2026] [autoindex:error] [pid 703393:tid 703582] [client 20.63.98.115:32386] AH01276: Cannot serve directory /home1/wdrgplte/public_html/jesus.claims/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:15:04.497830 2026] [security2:error] [pid 703393:tid 703647] [client 20.63.98.115:32386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-configs.php"] [unique_id "amuGmM637Arlr6Yb1EcJHwAAAQE"]
[Thu Jul 30 12:15:04.739558 2026] [core:notice] [pid 703393:tid 703585] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:04.745269 2026] [security2:error] [pid 703393:tid 703585] [client 103.215.74.26:48056] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGmM637Arlr6Yb1EcJJwAAAMM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:15:05.450946 2026] [core:notice] [pid 703393:tid 703564] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:07.147927 2026] [security2:error] [pid 703393:tid 703559] [client 74.7.244.10:43740] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "webmail.cwf.djb.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuGm8637Arlr6Yb1EcJVAAAAKk"]
[Thu Jul 30 12:15:07.224104 2026] [security2:error] [pid 703393:tid 703596] [client 57.141.0.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuGms637Arlr6Yb1EcJTQAAAM4"]
[Thu Jul 30 12:15:09.354234 2026] [security2:error] [pid 703393:tid 703557] [client 20.63.98.115:53840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/01.php"] [unique_id "amuGnc637Arlr6Yb1EcJeQAAAKc"]
[Thu Jul 30 12:15:09.390158 2026] [security2:error] [pid 703393:tid 703478] [remote 47.128.27.80:32722] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/search/Nike/page/107/"] [unique_id "amuGnc637Arlr6Yb1EcJfQAArFQ"]
[Thu Jul 30 12:15:09.710969 2026] [security2:error] [pid 703393:tid 703480] [remote 57.141.0.7:50730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/718396362/feed/rss2/"] [unique_id "amuGnc637Arlr6Yb1EcJkQAA8lY"]
[Thu Jul 30 12:15:10.439752 2026] [security2:error] [pid 703393:tid 703582] [client 20.63.98.115:55322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "amuGns637Arlr6Yb1EcJpwAAAMA"]
[Thu Jul 30 12:15:12.385038 2026] [security2:error] [pid 703393:tid 703650] [client 20.63.98.115:38203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/css/colors/midnight/colors.php"] [unique_id "amuGoM637Arlr6Yb1EcJzgAAAQQ"]
[Thu Jul 30 12:15:12.856173 2026] [security2:error] [pid 703393:tid 703511] [remote 57.141.0.15:33424] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "thdinfinity.com"] [uri "/search/3981330618/feed/rss2/"] [unique_id "amuGoM637Arlr6Yb1EcJ2AAA4nU"]
[Thu Jul 30 12:15:13.213507 2026] [security2:error] [pid 703393:tid 703614] [client 20.63.98.115:62057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/upgrade/index.php"] [unique_id "amuGoc637Arlr6Yb1EcJ3AAAAOA"]
[Thu Jul 30 12:15:15.263139 2026] [security2:error] [pid 703393:tid 703398] [remote 74.7.241.59:57000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuGo8637Arlr6Yb1EcJ9wAArAQ"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/premium-addons-for-elementor/modules/woocommerce/templates
[Thu Jul 30 12:15:15.331772 2026] [security2:error] [pid 703393:tid 703439] [remote 74.7.241.60:56254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/content/article.php"] [unique_id "amuGo8637Arlr6Yb1EcJ-wAAhi0"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/content/1784123347_ed%20inclusive.jpg
[Thu Jul 30 12:15:15.941490 2026] [security2:error] [pid 703393:tid 703647] [client 20.63.98.115:47263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/db.php"] [unique_id "amuGo8637Arlr6Yb1EcKBgAAAQE"]
[Thu Jul 30 12:15:16.912820 2026] [security2:error] [pid 703393:tid 703574] [client 209.35.163.56:55499] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "hris.rgserve.ph"] [uri "/login.php"] [unique_id "amuGpM637Arlr6Yb1EcKCwAAuCI"]
[Thu Jul 30 12:15:17.003525 2026] [security2:error] [pid 703393:tid 703589] [client 57.141.0.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuGpM637Arlr6Yb1EcKEgAAAMc"]
[Thu Jul 30 12:15:17.373753 2026] [security2:error] [pid 703393:tid 703549] [client 20.63.98.115:57096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/pages.php"] [unique_id "amuGpc637Arlr6Yb1EcKIQAAAJ8"]
[Thu Jul 30 12:15:18.294712 2026] [security2:error] [pid 703393:tid 703526] [client 20.63.98.115:47289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/admin.php"] [unique_id "amuGps637Arlr6Yb1EcKLgAAAIg"]
[Thu Jul 30 12:15:19.347147 2026] [core:error] [pid 703393:tid 703416] [remote 216.73.216.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:15:19.347172 2026] [core:error] [pid 703393:tid 703416] [remote 216.73.216.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:15:19.865412 2026] [security2:error] [pid 703393:tid 703583] [client 20.63.98.115:61941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-load.php"] [unique_id "amuGp8637Arlr6Yb1EcKTQAAAME"]
[Thu Jul 30 12:15:19.972762 2026] [core:error] [pid 703393:tid 703421] [remote 216.73.216.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:15:19.972785 2026] [core:error] [pid 703393:tid 703421] [remote 216.73.216.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:15:20.267192 2026] [security2:error] [pid 703393:tid 703496] [remote 216.73.216.152:56072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuGqM637Arlr6Yb1EcKWAAA5WY"]
[Thu Jul 30 12:15:20.315566 2026] [security2:error] [pid 703393:tid 703590] [client 57.141.0.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuGp8637Arlr6Yb1EcKTAAAAMg"]
[Thu Jul 30 12:15:20.745094 2026] [security2:error] [pid 703393:tid 703544] [client 20.63.98.115:51799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/as/function.php"] [unique_id "amuGqM637Arlr6Yb1EcKZAAAAJo"]
[Thu Jul 30 12:15:22.212805 2026] [security2:error] [pid 703393:tid 703538] [client 20.104.16.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thesounddepot.com"] [uri "/index.php"] [unique_id "amuGp8637Arlr6Yb1EcKQgAAlDA"]
[Thu Jul 30 12:15:22.903056 2026] [security2:error] [pid 703393:tid 703540] [client 20.63.98.115:62041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/filter.php"] [unique_id "amuGqs637Arlr6Yb1EcKmAAAAJY"]
[Thu Jul 30 12:15:24.496679 2026] [core:notice] [pid 703393:tid 703527] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:25.079818 2026] [security2:error] [pid 703393:tid 703532] [client 172.237.109.114:21980] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/alseermarine.com:443.sql"] [unique_id "amuGrc637Arlr6Yb1EcKywAAAI4"]
[Thu Jul 30 12:15:25.088422 2026] [security2:error] [pid 703393:tid 703579] [client 172.237.109.114:18579] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/database.sql"] [unique_id "amuGrc637Arlr6Yb1EcKzAAAAL0"]
[Thu Jul 30 12:15:25.103756 2026] [security2:error] [pid 703393:tid 703626] [client 172.237.109.114:26058] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/backup.sql"] [unique_id "amuGrc637Arlr6Yb1EcKzQAAAOw"]
[Thu Jul 30 12:15:25.121854 2026] [security2:error] [pid 703393:tid 703574] [client 172.237.109.114:6118] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/database.sql"] [unique_id "amuGrc637Arlr6Yb1EcKzgAAALg"]
[Thu Jul 30 12:15:25.122290 2026] [security2:error] [pid 703393:tid 703637] [client 172.237.109.114:63687] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/db.sql"] [unique_id "amuGrc637Arlr6Yb1EcKzwAAAPc"]
[Thu Jul 30 12:15:25.123300 2026] [security2:error] [pid 703393:tid 703644] [client 172.237.109.114:44734] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/alseermarine.com:443.sql"] [unique_id "amuGrc637Arlr6Yb1EcK0AAAAP4"]
[Thu Jul 30 12:15:25.123800 2026] [security2:error] [pid 703393:tid 703624] [client 172.237.109.114:62415] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/backups/database.sql"] [unique_id "amuGrc637Arlr6Yb1EcK0QAAAOo"]
[Thu Jul 30 12:15:25.149290 2026] [security2:error] [pid 703393:tid 703612] [client 172.237.109.114:54317] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/backup.sql"] [unique_id "amuGrc637Arlr6Yb1EcK0gAAAN4"]
[Thu Jul 30 12:15:25.149683 2026] [security2:error] [pid 703393:tid 703531] [client 172.237.109.114:54819] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/wp-content/database.sql"] [unique_id "amuGrc637Arlr6Yb1EcK0wAAAI0"]
[Thu Jul 30 12:15:25.150678 2026] [security2:error] [pid 703393:tid 703605] [client 172.237.109.114:51180] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/mysql.sql"] [unique_id "amuGrc637Arlr6Yb1EcK1AAAANc"]
[Thu Jul 30 12:15:25.150842 2026] [security2:error] [pid 703393:tid 703524] [client 172.237.109.114:56885] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/dump.sql"] [unique_id "amuGrc637Arlr6Yb1EcK1QAAAIY"]
[Thu Jul 30 12:15:25.151098 2026] [security2:error] [pid 703393:tid 703553] [client 172.237.109.114:28741] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/dump.sql"] [unique_id "amuGrc637Arlr6Yb1EcK1gAAAKM"]
[Thu Jul 30 12:15:25.160747 2026] [core:notice] [pid 703393:tid 703546] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:25.826262 2026] [core:notice] [pid 703393:tid 703523] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:26.593659 2026] [security2:error] [pid 703393:tid 703555] [client 20.63.98.115:57107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/he.php"] [unique_id "amuGrs637Arlr6Yb1EcK8QAAAKU"]
[Thu Jul 30 12:15:27.656422 2026] [security2:error] [pid 703393:tid 703532] [client 2a03:2880:f800:2b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuGr8637Arlr6Yb1EcK-QAAjnM"]
[Thu Jul 30 12:15:28.532484 2026] [security2:error] [pid 703393:tid 703604] [client 20.63.98.115:60815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/setup-config.php"] [unique_id "amuGsM637Arlr6Yb1EcLEAAAANY"]
[Thu Jul 30 12:15:29.604566 2026] [security2:error] [pid 703393:tid 703595] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuGsc637Arlr6Yb1EcLHQAAAM0"]
[Thu Jul 30 12:15:29.604679 2026] [security2:error] [pid 703393:tid 703595] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuGsc637Arlr6Yb1EcLHQAAAM0"]
[Thu Jul 30 12:15:30.110764 2026] [security2:error] [pid 703393:tid 703541] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuGss637Arlr6Yb1EcLKAAAAJc"]
[Thu Jul 30 12:15:30.110848 2026] [security2:error] [pid 703393:tid 703541] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuGss637Arlr6Yb1EcLKAAAAJc"]
[Thu Jul 30 12:15:30.204474 2026] [security2:error] [pid 703393:tid 703589] [client 20.63.98.115:60824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/languages/wp-login.php"] [unique_id "amuGss637Arlr6Yb1EcLKwAAAMc"]
[Thu Jul 30 12:15:30.518249 2026] [core:notice] [pid 703393:tid 703530] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:30.630717 2026] [security2:error] [pid 703393:tid 703553] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/bootstrap.php"] [unique_id "amuGss637Arlr6Yb1EcLMwAAAKM"]
[Thu Jul 30 12:15:30.630825 2026] [security2:error] [pid 703393:tid 703553] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/bootstrap.php"] [unique_id "amuGss637Arlr6Yb1EcLMwAAAKM"]
[Thu Jul 30 12:15:31.131740 2026] [security2:error] [pid 703393:tid 703590] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-blog-header.php"] [unique_id "amuGs8637Arlr6Yb1EcLPAAAAMg"]
[Thu Jul 30 12:15:31.131846 2026] [security2:error] [pid 703393:tid 703590] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-blog-header.php"] [unique_id "amuGs8637Arlr6Yb1EcLPAAAAMg"]
[Thu Jul 30 12:15:31.155350 2026] [security2:error] [pid 703393:tid 703542] [client 20.63.98.115:57092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/autoload_classmap.php"] [unique_id "amuGs8637Arlr6Yb1EcLPwAAAJg"]
[Thu Jul 30 12:15:31.685050 2026] [security2:error] [pid 703393:tid 703582] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-load.php"] [unique_id "amuGs8637Arlr6Yb1EcLRwAAAMA"]
[Thu Jul 30 12:15:31.685137 2026] [security2:error] [pid 703393:tid 703582] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-load.php"] [unique_id "amuGs8637Arlr6Yb1EcLRwAAAMA"]
[Thu Jul 30 12:15:32.238584 2026] [security2:error] [pid 703393:tid 703527] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/edit.php"] [unique_id "amuGtM637Arlr6Yb1EcLUgAAAIk"]
[Thu Jul 30 12:15:32.238693 2026] [security2:error] [pid 703393:tid 703527] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/edit.php"] [unique_id "amuGtM637Arlr6Yb1EcLUgAAAIk"]
[Thu Jul 30 12:15:32.753534 2026] [security2:error] [pid 703393:tid 703539] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/___proxy_subdomain_webdisk/cgi-bin"] [unique_id "amuGtM637Arlr6Yb1EcLWwAAAJU"]
[Thu Jul 30 12:15:33.150436 2026] [security2:error] [pid 703393:tid 703550] [client 20.63.98.115:47250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/plugins/WordPressCore/include.php"] [unique_id "amuGtc637Arlr6Yb1EcLXwAAAKA"]
[Thu Jul 30 12:15:33.417864 2026] [security2:error] [pid 703393:tid 703592] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/mah.php"] [unique_id "amuGtc637Arlr6Yb1EcLZwAAAMo"]
[Thu Jul 30 12:15:33.417966 2026] [security2:error] [pid 703393:tid 703592] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/mah.php"] [unique_id "amuGtc637Arlr6Yb1EcLZwAAAMo"]
[Thu Jul 30 12:15:33.673283 2026] [core:notice] [pid 703393:tid 703415] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:33.681829 2026] [security2:error] [pid 703393:tid 703632] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/archive.php"] [unique_id "amuGtc637Arlr6Yb1EcLaQAAAPI"]
[Thu Jul 30 12:15:33.681913 2026] [security2:error] [pid 703393:tid 703632] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/archive.php"] [unique_id "amuGtc637Arlr6Yb1EcLaQAAAPI"]
[Thu Jul 30 12:15:33.985311 2026] [security2:error] [pid 703393:tid 703565] [client 20.63.98.115:54539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/atomlib.php"] [unique_id "amuGtc637Arlr6Yb1EcLcAAAAK8"]
[Thu Jul 30 12:15:34.167151 2026] [security2:error] [pid 703393:tid 703542] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/hosty.php"] [unique_id "amuGts637Arlr6Yb1EcLcQAAAJg"]
[Thu Jul 30 12:15:34.167263 2026] [security2:error] [pid 703393:tid 703542] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/hosty.php"] [unique_id "amuGts637Arlr6Yb1EcLcQAAAJg"]
[Thu Jul 30 12:15:34.735484 2026] [security2:error] [pid 703393:tid 703540] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/___proxy_subdomain_webdisk/wp-includes/Text/Diff/"] [unique_id "amuGts637Arlr6Yb1EcLeQAAAJY"]
[Thu Jul 30 12:15:35.289367 2026] [security2:error] [pid 703393:tid 703628] [client 20.63.98.115:20653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "amuGt8637Arlr6Yb1EcLhgAAAO4"]
[Thu Jul 30 12:15:35.749160 2026] [security2:error] [pid 703393:tid 703618] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/admin.php"] [unique_id "amuGt8637Arlr6Yb1EcLjgAAAOQ"]
[Thu Jul 30 12:15:35.749299 2026] [security2:error] [pid 703393:tid 703618] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/admin.php"] [unique_id "amuGt8637Arlr6Yb1EcLjgAAAOQ"]
[Thu Jul 30 12:15:36.301604 2026] [security2:error] [pid 703393:tid 703612] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/av.php"] [unique_id "amuGuM637Arlr6Yb1EcLmQAAAN4"]
[Thu Jul 30 12:15:36.301707 2026] [security2:error] [pid 703393:tid 703612] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/av.php"] [unique_id "amuGuM637Arlr6Yb1EcLmQAAAN4"]
[Thu Jul 30 12:15:36.788664 2026] [security2:error] [pid 703393:tid 703649] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/shell.php"] [unique_id "amuGuM637Arlr6Yb1EcLngAAAQM"]
[Thu Jul 30 12:15:36.788783 2026] [security2:error] [pid 703393:tid 703649] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/shell.php"] [unique_id "amuGuM637Arlr6Yb1EcLngAAAQM"]
[Thu Jul 30 12:15:36.973000 2026] [security2:error] [pid 703393:tid 703594] [client 172.237.109.114:58046] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "alseermarine.com"] [uri "/WEB_VMS/LEVEL15/"] [unique_id "amuGuM637Arlr6Yb1EcLowAAAMw"]
[Thu Jul 30 12:15:37.251531 2026] [core:notice] [pid 703393:tid 703420] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:37.330466 2026] [security2:error] [pid 703393:tid 703591] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/storage/index.php"] [unique_id "amuGuc637Arlr6Yb1EcLqwAAAMk"]
[Thu Jul 30 12:15:37.330595 2026] [security2:error] [pid 703393:tid 703591] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/storage/index.php"] [unique_id "amuGuc637Arlr6Yb1EcLqwAAAMk"]
[Thu Jul 30 12:15:37.870378 2026] [security2:error] [pid 703393:tid 703585] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/w.php"] [unique_id "amuGuc637Arlr6Yb1EcLsgAAAMM"]
[Thu Jul 30 12:15:37.870469 2026] [security2:error] [pid 703393:tid 703585] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/w.php"] [unique_id "amuGuc637Arlr6Yb1EcLsgAAAMM"]
[Thu Jul 30 12:15:37.921739 2026] [core:notice] [pid 703393:tid 703571] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:37.996436 2026] [core:notice] [pid 703393:tid 703576] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:38.369209 2026] [security2:error] [pid 703393:tid 703600] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/jp.php"] [unique_id "amuGus637Arlr6Yb1EcLvAAAANI"]
[Thu Jul 30 12:15:38.369294 2026] [security2:error] [pid 703393:tid 703600] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/jp.php"] [unique_id "amuGus637Arlr6Yb1EcLvAAAANI"]
[Thu Jul 30 12:15:38.675672 2026] [security2:error] [pid 703393:tid 703575] [client 20.63.98.115:63377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/gebase.php"] [unique_id "amuGus637Arlr6Yb1EcLwAAAALk"]
[Thu Jul 30 12:15:38.874971 2026] [security2:error] [pid 703393:tid 703642] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/___proxy_subdomain_webdisk/php.ini"] [unique_id "amuGus637Arlr6Yb1EcLxQAAAPw"]
[Thu Jul 30 12:15:39.139596 2026] [security2:error] [pid 703393:tid 703605] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/ws77.php"] [unique_id "amuGu8637Arlr6Yb1EcLyQAAANc"]
[Thu Jul 30 12:15:39.139717 2026] [security2:error] [pid 703393:tid 703605] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/ws77.php"] [unique_id "amuGu8637Arlr6Yb1EcLyQAAANc"]
[Thu Jul 30 12:15:39.680073 2026] [security2:error] [pid 703393:tid 703621] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/blass.php"] [unique_id "amuGu8637Arlr6Yb1EcL0wAAAOc"]
[Thu Jul 30 12:15:39.680181 2026] [security2:error] [pid 703393:tid 703621] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/blass.php"] [unique_id "amuGu8637Arlr6Yb1EcL0wAAAOc"]
[Thu Jul 30 12:15:39.719764 2026] [security2:error] [pid 703393:tid 703546] [client 20.63.98.115:20616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/xl.php"] [unique_id "amuGu8637Arlr6Yb1EcL1AAAAJw"]
[Thu Jul 30 12:15:40.519631 2026] [security2:error] [pid 703393:tid 703557] [client 20.63.98.115:63400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/2.php"] [unique_id "amuGvM637Arlr6Yb1EcL4QAAAKc"]
[Thu Jul 30 12:15:40.567793 2026] [security2:error] [pid 703393:tid 703609] [client 89.238.167.166:51896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuGvM637Arlr6Yb1EcL4gAAANs"]
[Thu Jul 30 12:15:40.567891 2026] [security2:error] [pid 703393:tid 703609] [client 89.238.167.166:51896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuGvM637Arlr6Yb1EcL4gAAANs"]
[Thu Jul 30 12:15:40.973397 2026] [security2:error] [pid 703393:tid 703440] [remote 216.73.216.152:8129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuGvM637Arlr6Yb1EcL6AAAvC4"]
[Thu Jul 30 12:15:41.576868 2026] [security2:error] [pid 703393:tid 703572] [client 20.63.98.115:60820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/baxa1.php"] [unique_id "amuGvc637Arlr6Yb1EcL9AAAALY"]
[Thu Jul 30 12:15:41.669101 2026] [core:notice] [pid 703393:tid 703635] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:42.503458 2026] [security2:error] [pid 703393:tid 703535] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-info.php"] [unique_id "amuGvs637Arlr6Yb1EcMAAAAAJE"]
[Thu Jul 30 12:15:42.503589 2026] [security2:error] [pid 703393:tid 703535] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-info.php"] [unique_id "amuGvs637Arlr6Yb1EcMAAAAAJE"]
[Thu Jul 30 12:15:42.915142 2026] [security2:error] [pid 703393:tid 703594] [client 117.5.152.212:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuGvs637Arlr6Yb1EcMEgAAAMw"]
[Thu Jul 30 12:15:43.076610 2026] [security2:error] [pid 703393:tid 703567] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/CDX1.php"] [unique_id "amuGv8637Arlr6Yb1EcMFQAAALE"]
[Thu Jul 30 12:15:43.076744 2026] [security2:error] [pid 703393:tid 703567] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/CDX1.php"] [unique_id "amuGv8637Arlr6Yb1EcMFQAAALE"]
[Thu Jul 30 12:15:43.617769 2026] [security2:error] [pid 703393:tid 703558] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wpc.php"] [unique_id "amuGv8637Arlr6Yb1EcMHAAAAKg"]
[Thu Jul 30 12:15:43.617862 2026] [security2:error] [pid 703393:tid 703558] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wpc.php"] [unique_id "amuGv8637Arlr6Yb1EcMHAAAAKg"]
[Thu Jul 30 12:15:44.096565 2026] [security2:error] [pid 703393:tid 703576] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/jga.php"] [unique_id "amuGwM637Arlr6Yb1EcMIAAAALo"]
[Thu Jul 30 12:15:44.096677 2026] [security2:error] [pid 703393:tid 703576] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/jga.php"] [unique_id "amuGwM637Arlr6Yb1EcMIAAAALo"]
[Thu Jul 30 12:15:44.594213 2026] [security2:error] [pid 703393:tid 703579] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/666.php"] [unique_id "amuGwM637Arlr6Yb1EcMKwAAAL0"]
[Thu Jul 30 12:15:44.594326 2026] [security2:error] [pid 703393:tid 703579] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/666.php"] [unique_id "amuGwM637Arlr6Yb1EcMKwAAAL0"]
[Thu Jul 30 12:15:44.769642 2026] [core:notice] [pid 703393:tid 703476] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:44.805033 2026] [security2:error] [pid 703393:tid 703583] [client 20.63.98.115:63409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/settings.php"] [unique_id "amuGwM637Arlr6Yb1EcMMAAAAME"]
[Thu Jul 30 12:15:45.136422 2026] [security2:error] [pid 703393:tid 703605] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/htaccess.php"] [unique_id "amuGwc637Arlr6Yb1EcMNwAAANc"]
[Thu Jul 30 12:15:45.136554 2026] [security2:error] [pid 703393:tid 703605] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/htaccess.php"] [unique_id "amuGwc637Arlr6Yb1EcMNwAAANc"]
[Thu Jul 30 12:15:45.523884 2026] [core:notice] [pid 703393:tid 703620] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:45.661723 2026] [security2:error] [pid 703393:tid 703634] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/m.php"] [unique_id "amuGwc637Arlr6Yb1EcMSgAAAPQ"]
[Thu Jul 30 12:15:45.661821 2026] [security2:error] [pid 703393:tid 703634] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/m.php"] [unique_id "amuGwc637Arlr6Yb1EcMSgAAAPQ"]
[Thu Jul 30 12:15:46.157409 2026] [security2:error] [pid 703393:tid 703531] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/file.php"] [unique_id "amuGws637Arlr6Yb1EcMUgAAAI0"]
[Thu Jul 30 12:15:46.157530 2026] [security2:error] [pid 703393:tid 703531] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/file.php"] [unique_id "amuGws637Arlr6Yb1EcMUgAAAI0"]
[Thu Jul 30 12:15:46.407776 2026] [security2:error] [pid 703393:tid 703631] [client 85.208.96.193:26084] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/02/25/bancos-fecham-no-carnaval-e-reabrem-na-quarta-feira-de-cinzas/"] [unique_id "amuGws637Arlr6Yb1EcMVwAAAPE"]
[Thu Jul 30 12:15:46.407936 2026] [security2:error] [pid 703393:tid 703631] [client 85.208.96.193:26084] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/02/25/bancos-fecham-no-carnaval-e-reabrem-na-quarta-feira-de-cinzas/"] [unique_id "amuGws637Arlr6Yb1EcMVwAAAPE"]
[Thu Jul 30 12:15:46.669620 2026] [security2:error] [pid 703393:tid 703625] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/.dj/index.php"] [unique_id "amuGws637Arlr6Yb1EcMXQAAAOs"]
[Thu Jul 30 12:15:46.669748 2026] [security2:error] [pid 703393:tid 703625] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/.dj/index.php"] [unique_id "amuGws637Arlr6Yb1EcMXQAAAOs"]
[Thu Jul 30 12:15:47.172137 2026] [security2:error] [pid 703393:tid 703595] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-admin/maint/index.php"] [unique_id "amuGw8637Arlr6Yb1EcMZgAAAM0"]
[Thu Jul 30 12:15:47.172290 2026] [security2:error] [pid 703393:tid 703595] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-admin/maint/index.php"] [unique_id "amuGw8637Arlr6Yb1EcMZgAAAM0"]
[Thu Jul 30 12:15:47.671069 2026] [security2:error] [pid 703393:tid 703605] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/pages.php"] [unique_id "amuGw8637Arlr6Yb1EcMcAAAANc"]
[Thu Jul 30 12:15:47.671218 2026] [security2:error] [pid 703393:tid 703605] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/pages.php"] [unique_id "amuGw8637Arlr6Yb1EcMcAAAANc"]
[Thu Jul 30 12:15:47.759991 2026] [security2:error] [pid 703393:tid 703589] [client 46.6.123.252:61208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuGw8637Arlr6Yb1EcMbgAAAMc"], referer: http://pkf.jo
[Thu Jul 30 12:15:47.926782 2026] [security2:error] [pid 703393:tid 703638] [client 154.160.2.71:5939] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuGw8637Arlr6Yb1EcMbwAAAPg"], referer: http://pkf.jo
[Thu Jul 30 12:15:48.150929 2026] [security2:error] [pid 703393:tid 703586] [client 223.109.252.236:41570] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/x-travis-scott-x-nike-air-jordan-1-low-black/"] [unique_id "amuGxM637Arlr6Yb1EcMeAAAAMQ"]
[Thu Jul 30 12:15:48.151060 2026] [security2:error] [pid 703393:tid 703586] [client 223.109.252.236:41570] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/product/x-travis-scott-x-nike-air-jordan-1-low-black/"] [unique_id "amuGxM637Arlr6Yb1EcMeAAAAMQ"]
[Thu Jul 30 12:15:48.199026 2026] [security2:error] [pid 703393:tid 703630] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/adminfuns.php"] [unique_id "amuGxM637Arlr6Yb1EcMeQAAAPA"]
[Thu Jul 30 12:15:48.199137 2026] [security2:error] [pid 703393:tid 703630] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/adminfuns.php"] [unique_id "amuGxM637Arlr6Yb1EcMeQAAAPA"]
[Thu Jul 30 12:15:48.427265 2026] [security2:error] [pid 703393:tid 703565] [client 41.105.24.105:42582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuGxM637Arlr6Yb1EcMdwAAAK8"], referer: http://pkf.jo
[Thu Jul 30 12:15:48.718331 2026] [security2:error] [pid 703393:tid 703534] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/aa.php"] [unique_id "amuGxM637Arlr6Yb1EcMgQAAAJA"]
[Thu Jul 30 12:15:48.718450 2026] [security2:error] [pid 703393:tid 703534] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/aa.php"] [unique_id "amuGxM637Arlr6Yb1EcMgQAAAJA"]
[Thu Jul 30 12:15:48.724670 2026] [security2:error] [pid 703393:tid 703641] [client 196.191.240.134:37590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuGxM637Arlr6Yb1EcMfAAAAPs"], referer: http://pkf.jo
[Thu Jul 30 12:15:49.266307 2026] [security2:error] [pid 703393:tid 703618] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/___proxy_subdomain_webdisk/wp-includes/Text/Diff/Engine/"] [unique_id "amuGxc637Arlr6Yb1EcMiQAAAOQ"]
[Thu Jul 30 12:15:49.331347 2026] [core:notice] [pid 703393:tid 703426] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:49.432294 2026] [security2:error] [pid 703393:tid 703648] [client 20.63.98.115:63382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/dropdown.php"] [unique_id "amuGxc637Arlr6Yb1EcMiwAAAQI"]
[Thu Jul 30 12:15:49.520244 2026] [security2:error] [pid 703393:tid 703529] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/classwithtostring.php"] [unique_id "amuGxc637Arlr6Yb1EcMjwAAAIs"]
[Thu Jul 30 12:15:49.520356 2026] [security2:error] [pid 703393:tid 703529] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/classwithtostring.php"] [unique_id "amuGxc637Arlr6Yb1EcMjwAAAIs"]
[Thu Jul 30 12:15:50.029382 2026] [security2:error] [pid 703393:tid 703589] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/about.php"] [unique_id "amuGxs637Arlr6Yb1EcMlgAAAMc"]
[Thu Jul 30 12:15:50.029487 2026] [security2:error] [pid 703393:tid 703589] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/about.php"] [unique_id "amuGxs637Arlr6Yb1EcMlgAAAMc"]
[Thu Jul 30 12:15:50.521064 2026] [security2:error] [pid 703393:tid 703586] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/goods.php"] [unique_id "amuGxs637Arlr6Yb1EcMoAAAAMQ"]
[Thu Jul 30 12:15:50.521175 2026] [security2:error] [pid 703393:tid 703586] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/goods.php"] [unique_id "amuGxs637Arlr6Yb1EcMoAAAAMQ"]
[Thu Jul 30 12:15:51.047301 2026] [security2:error] [pid 703393:tid 703646] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/php8.php"] [unique_id "amuGx8637Arlr6Yb1EcMqAAAAQA"]
[Thu Jul 30 12:15:51.047403 2026] [security2:error] [pid 703393:tid 703646] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/php8.php"] [unique_id "amuGx8637Arlr6Yb1EcMqAAAAQA"]
[Thu Jul 30 12:15:51.069789 2026] [autoindex:error] [pid 703393:tid 703547] [client 20.63.98.115:21112] AH01276: Cannot serve directory /home1/wdrgplte/public_html/jesus.claims/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:15:51.273267 2026] [security2:error] [pid 703393:tid 703557] [client 20.63.98.115:21112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin.php"] [unique_id "amuGx8637Arlr6Yb1EcMrQAAAKc"]
[Thu Jul 30 12:15:51.592370 2026] [security2:error] [pid 703393:tid 703571] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/info.php"] [unique_id "amuGx8637Arlr6Yb1EcMsQAAALU"]
[Thu Jul 30 12:15:51.592469 2026] [security2:error] [pid 703393:tid 703571] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/info.php"] [unique_id "amuGx8637Arlr6Yb1EcMsQAAALU"]
[Thu Jul 30 12:15:52.075568 2026] [security2:error] [pid 703393:tid 703622] [client 20.63.98.115:60266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/buy.php"] [unique_id "amuGyM637Arlr6Yb1EcMuAAAAOg"]
[Thu Jul 30 12:15:52.142759 2026] [security2:error] [pid 703393:tid 703648] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/class-t.api.php"] [unique_id "amuGyM637Arlr6Yb1EcMuQAAAQI"]
[Thu Jul 30 12:15:52.142871 2026] [security2:error] [pid 703393:tid 703648] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/class-t.api.php"] [unique_id "amuGyM637Arlr6Yb1EcMuQAAAQI"]
[Thu Jul 30 12:15:52.636663 2026] [security2:error] [pid 703393:tid 703538] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/simple.php"] [unique_id "amuGyM637Arlr6Yb1EcMwAAAAJQ"]
[Thu Jul 30 12:15:52.636760 2026] [security2:error] [pid 703393:tid 703538] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/simple.php"] [unique_id "amuGyM637Arlr6Yb1EcMwAAAAJQ"]
[Thu Jul 30 12:15:52.917460 2026] [security2:error] [pid 703393:tid 703608] [client 20.63.98.115:54548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/mini.php"] [unique_id "amuGyM637Arlr6Yb1EcMxAAAANo"]
[Thu Jul 30 12:15:53.163240 2026] [security2:error] [pid 703393:tid 703636] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/ioxi-o.php"] [unique_id "amuGyc637Arlr6Yb1EcMyAAAAPY"]
[Thu Jul 30 12:15:53.163351 2026] [security2:error] [pid 703393:tid 703636] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/ioxi-o.php"] [unique_id "amuGyc637Arlr6Yb1EcMyAAAAPY"]
[Thu Jul 30 12:15:53.725220 2026] [security2:error] [pid 703393:tid 703524] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/___proxy_subdomain_webdisk/wp-admin"] [unique_id "amuGyc637Arlr6Yb1EcM0AAAAIY"]
[Thu Jul 30 12:15:53.987408 2026] [security2:error] [pid 703393:tid 703546] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp.php"] [unique_id "amuGyc637Arlr6Yb1EcM1AAAAJw"]
[Thu Jul 30 12:15:53.987516 2026] [security2:error] [pid 703393:tid 703546] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp.php"] [unique_id "amuGyc637Arlr6Yb1EcM1AAAAJw"]
[Thu Jul 30 12:15:54.736909 2026] [security2:error] [pid 703393:tid 703614] [client 2a03:2880:f800:8:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuGys637Arlr6Yb1EcM6QAA4H4"]
[Thu Jul 30 12:15:55.083194 2026] [security2:error] [pid 703393:tid 703615] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/file2.php"] [unique_id "amuGy8637Arlr6Yb1EcM9wAAAOE"]
[Thu Jul 30 12:15:55.083321 2026] [security2:error] [pid 703393:tid 703615] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/file2.php"] [unique_id "amuGy8637Arlr6Yb1EcM9wAAAOE"]
[Thu Jul 30 12:15:55.285874 2026] [security2:error] [pid 703393:tid 703562] [client 2a03:2880:f800:33:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuGys637Arlr6Yb1EcM8AAArC0"]
[Thu Jul 30 12:15:55.615436 2026] [security2:error] [pid 703393:tid 703541] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/images/class-config.php"] [unique_id "amuGy8637Arlr6Yb1EcNCQAAAJc"]
[Thu Jul 30 12:15:55.615558 2026] [security2:error] [pid 703393:tid 703541] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/images/class-config.php"] [unique_id "amuGy8637Arlr6Yb1EcNCQAAAJc"]
[Thu Jul 30 12:15:55.892265 2026] [security2:error] [pid 703393:tid 703635] [client 57.141.0.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuGy8637Arlr6Yb1EcM_gAAAPU"]
[Thu Jul 30 12:15:56.166791 2026] [security2:error] [pid 703393:tid 703634] [client 20.9.4.9:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/1.php"] [unique_id "amuGzM637Arlr6Yb1EcNGQAAAPQ"]
[Thu Jul 30 12:15:56.166908 2026] [security2:error] [pid 703393:tid 703634] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/1.php"] [unique_id "amuGzM637Arlr6Yb1EcNGQAAAPQ"]
[Thu Jul 30 12:15:56.167014 2026] [security2:error] [pid 703393:tid 703634] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/1.php"] [unique_id "amuGzM637Arlr6Yb1EcNGQAAAPQ"]
[Thu Jul 30 12:15:56.311451 2026] [security2:error] [pid 703393:tid 703603] [client 2a03:2880:f800:39:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuGy8637Arlr6Yb1EcM-AAA1RU"]
[Thu Jul 30 12:15:56.653985 2026] [core:error] [pid 703393:tid 703645] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:15:56.654008 2026] [core:error] [pid 703393:tid 703645] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:15:56.666733 2026] [security2:error] [pid 703393:tid 703632] [client 20.63.98.115:60235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/cd.php"] [unique_id "amuGzM637Arlr6Yb1EcNJQAAAPI"]
[Thu Jul 30 12:15:56.695696 2026] [security2:error] [pid 703393:tid 703621] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/222.php"] [unique_id "amuGzM637Arlr6Yb1EcNJgAAAOc"]
[Thu Jul 30 12:15:56.695801 2026] [security2:error] [pid 703393:tid 703621] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/222.php"] [unique_id "amuGzM637Arlr6Yb1EcNJgAAAOc"]
[Thu Jul 30 12:15:57.199890 2026] [security2:error] [pid 703393:tid 703596] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/themes.php"] [unique_id "amuGzc637Arlr6Yb1EcNNQAAAM4"]
[Thu Jul 30 12:15:57.200032 2026] [security2:error] [pid 703393:tid 703596] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/themes.php"] [unique_id "amuGzc637Arlr6Yb1EcNNQAAAM4"]
[Thu Jul 30 12:15:57.724703 2026] [security2:error] [pid 703393:tid 703564] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-content/admin.php"] [unique_id "amuGzc637Arlr6Yb1EcNQQAAAK4"]
[Thu Jul 30 12:15:57.724822 2026] [security2:error] [pid 703393:tid 703564] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-content/admin.php"] [unique_id "amuGzc637Arlr6Yb1EcNQQAAAK4"]
[Thu Jul 30 12:15:58.222785 2026] [security2:error] [pid 703393:tid 703599] [client 20.63.98.115:60270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/images/admin.php"] [unique_id "amuGzs637Arlr6Yb1EcNSQAAANE"]
[Thu Jul 30 12:15:58.288038 2026] [security2:error] [pid 703393:tid 703569] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/dropdown.php"] [unique_id "amuGzs637Arlr6Yb1EcNSgAAALM"]
[Thu Jul 30 12:15:58.288201 2026] [security2:error] [pid 703393:tid 703569] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/dropdown.php"] [unique_id "amuGzs637Arlr6Yb1EcNSgAAALM"]
[Thu Jul 30 12:15:58.849932 2026] [security2:error] [pid 703393:tid 703526] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/inputs.php"] [unique_id "amuGzs637Arlr6Yb1EcNVAAAAIg"]
[Thu Jul 30 12:15:58.850074 2026] [security2:error] [pid 703393:tid 703526] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/inputs.php"] [unique_id "amuGzs637Arlr6Yb1EcNVAAAAIg"]
[Thu Jul 30 12:15:59.399850 2026] [security2:error] [pid 703393:tid 703534] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/100.php"] [unique_id "amuGz8637Arlr6Yb1EcNXgAAAJA"]
[Thu Jul 30 12:15:59.400049 2026] [security2:error] [pid 703393:tid 703534] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/100.php"] [unique_id "amuGz8637Arlr6Yb1EcNXgAAAJA"]
[Thu Jul 30 12:15:59.427742 2026] [security2:error] [pid 703393:tid 703570] [client 98.6.138.186:35237] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuGz8637Arlr6Yb1EcNWwAAALQ"], referer: http://pkf.jo
[Thu Jul 30 12:15:59.452177 2026] [security2:error] [pid 703393:tid 703607] [client 20.63.98.115:21089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/batm.php"] [unique_id "amuGz8637Arlr6Yb1EcNXwAAANk"]
[Thu Jul 30 12:15:59.890046 2026] [security2:error] [pid 703393:tid 703588] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/autoload_classmap/function.php"] [unique_id "amuGz8637Arlr6Yb1EcNaQAAAMY"]
[Thu Jul 30 12:15:59.890145 2026] [security2:error] [pid 703393:tid 703588] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/autoload_classmap/function.php"] [unique_id "amuGz8637Arlr6Yb1EcNaQAAAMY"]
[Thu Jul 30 12:16:00.216626 2026] [security2:error] [pid 703393:tid 703573] [client 20.63.98.115:21091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/hehehehe.php"] [unique_id "amuG0M637Arlr6Yb1EcNcAAAALc"]
[Thu Jul 30 12:16:00.763591 2026] [security2:error] [pid 703393:tid 703532] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/php.php"] [unique_id "amuG0M637Arlr6Yb1EcNewAAAI4"]
[Thu Jul 30 12:16:00.763690 2026] [security2:error] [pid 703393:tid 703532] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/php.php"] [unique_id "amuG0M637Arlr6Yb1EcNewAAAI4"]
[Thu Jul 30 12:16:01.203123 2026] [security2:error] [pid 703393:tid 703475] [remote 103.255.134.61:57572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "exploringchanges.com"] [uri "/wp-login.php"] [unique_id "amuG0c637Arlr6Yb1EcNfwABBFE"]
[Thu Jul 30 12:16:01.243427 2026] [security2:error] [pid 703393:tid 703535] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/t.php"] [unique_id "amuG0c637Arlr6Yb1EcNgwAAAJE"]
[Thu Jul 30 12:16:01.243521 2026] [security2:error] [pid 703393:tid 703535] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/t.php"] [unique_id "amuG0c637Arlr6Yb1EcNgwAAAJE"]
[Thu Jul 30 12:16:01.413873 2026] [security2:error] [pid 703393:tid 703601] [client 20.63.98.115:21084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/sim.php/wp-includes/certificates/plugins.php"] [unique_id "amuG0c637Arlr6Yb1EcNhAAAANM"]
[Thu Jul 30 12:16:01.764776 2026] [security2:error] [pid 703393:tid 703570] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-blink.php"] [unique_id "amuG0c637Arlr6Yb1EcNkAAAALQ"]
[Thu Jul 30 12:16:01.764914 2026] [security2:error] [pid 703393:tid 703570] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-blink.php"] [unique_id "amuG0c637Arlr6Yb1EcNkAAAALQ"]
[Thu Jul 30 12:16:01.765739 2026] [core:notice] [pid 703393:tid 703621] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:16:02.473482 2026] [security2:error] [pid 703393:tid 703564] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/xfun.php"] [unique_id "amuG0s637Arlr6Yb1EcNrgAAAK4"]
[Thu Jul 30 12:16:02.473674 2026] [security2:error] [pid 703393:tid 703564] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/xfun.php"] [unique_id "amuG0s637Arlr6Yb1EcNrgAAAK4"]
[Thu Jul 30 12:16:02.535024 2026] [core:notice] [pid 703393:tid 703616] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:16:02.744244 2026] [core:error] [pid 703393:tid 703552] [client 74.7.175.158:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:16:02.744269 2026] [core:error] [pid 703393:tid 703552] [client 74.7.175.158:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:16:02.744404 2026] [security2:error] [pid 703393:tid 703552] [client 74.7.175.158:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.xyt.gzj.temporary.site"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amuG0s637Arlr6Yb1EcNtgAAAKI"]
[Thu Jul 30 12:16:02.745027 2026] [security2:error] [pid 703393:tid 703644] [client 74.7.175.158:36270] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.xyt.gzj.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuG0s637Arlr6Yb1EcNtAAA_gI"]
[Thu Jul 30 12:16:02.853946 2026] [security2:error] [pid 703393:tid 703544] [client 20.63.98.115:60234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-seo.php"] [unique_id "amuG0s637Arlr6Yb1EcNugAAAJo"]
[Thu Jul 30 12:16:02.906865 2026] [security2:error] [pid 703393:tid 703442] [remote 40.77.167.67:5155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/camic/article/view/9080"] [unique_id "amuG0s637Arlr6Yb1EcNuwAAszA"]
[Thu Jul 30 12:16:02.967054 2026] [security2:error] [pid 703393:tid 703599] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/p.php"] [unique_id "amuG0s637Arlr6Yb1EcNvAAAANE"]
[Thu Jul 30 12:16:02.967170 2026] [security2:error] [pid 703393:tid 703599] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/p.php"] [unique_id "amuG0s637Arlr6Yb1EcNvAAAANE"]
[Thu Jul 30 12:16:03.042403 2026] [core:notice] [pid 703393:tid 703551] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:16:03.499369 2026] [security2:error] [pid 703393:tid 703558] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-content/themes/admin.php"] [unique_id "amuG08637Arlr6Yb1EcNxwAAAKg"]
[Thu Jul 30 12:16:03.499539 2026] [security2:error] [pid 703393:tid 703558] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-content/themes/admin.php"] [unique_id "amuG08637Arlr6Yb1EcNxwAAAKg"]
[Thu Jul 30 12:16:03.510950 2026] [security2:error] [pid 703393:tid 703611] [client 172.237.109.114:12869] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0c637Arlr6Yb1EcNlAAAAN0"]
[Thu Jul 30 12:16:03.517096 2026] [security2:error] [pid 703393:tid 703600] [client 172.237.109.114:17910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0c637Arlr6Yb1EcNnwAAANI"]
[Thu Jul 30 12:16:03.519329 2026] [security2:error] [pid 703393:tid 703614] [client 172.237.109.114:1927] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0c637Arlr6Yb1EcNlQAAAOA"]
[Thu Jul 30 12:16:03.530585 2026] [security2:error] [pid 703393:tid 703548] [client 172.237.109.114:28182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0c637Arlr6Yb1EcNkwAAAJ4"]
[Thu Jul 30 12:16:03.531174 2026] [security2:error] [pid 703393:tid 703582] [client 172.237.109.114:56117] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0c637Arlr6Yb1EcNoAAAAMA"]
[Thu Jul 30 12:16:03.531249 2026] [security2:error] [pid 703393:tid 703595] [client 172.237.109.114:40416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0c637Arlr6Yb1EcNoQAAAM0"]
[Thu Jul 30 12:16:03.534029 2026] [security2:error] [pid 703393:tid 703617] [client 172.237.109.114:13885] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0c637Arlr6Yb1EcNmwAAAOM"]
[Thu Jul 30 12:16:03.535450 2026] [security2:error] [pid 703393:tid 703622] [client 172.237.109.114:44221] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0c637Arlr6Yb1EcNlgAAAOg"]
[Thu Jul 30 12:16:03.544137 2026] [security2:error] [pid 703393:tid 703536] [client 172.237.109.114:1784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0c637Arlr6Yb1EcNmQAAAJI"]
[Thu Jul 30 12:16:03.544516 2026] [security2:error] [pid 703393:tid 703596] [client 172.237.109.114:27669] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0c637Arlr6Yb1EcNlwAAAM4"]
[Thu Jul 30 12:16:03.550304 2026] [security2:error] [pid 703393:tid 703593] [client 172.237.109.114:9468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0c637Arlr6Yb1EcNnAAAAMs"]
[Thu Jul 30 12:16:03.555527 2026] [security2:error] [pid 703393:tid 703613] [client 172.237.109.114:47285] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0c637Arlr6Yb1EcNnQAAAN8"]
[Thu Jul 30 12:16:03.559838 2026] [security2:error] [pid 703393:tid 703597] [client 172.237.109.114:7431] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0s637Arlr6Yb1EcNpQAAAM8"]
[Thu Jul 30 12:16:03.559955 2026] [security2:error] [pid 703393:tid 703615] [client 172.237.109.114:43483] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0c637Arlr6Yb1EcNmgAAAOE"]
[Thu Jul 30 12:16:03.563971 2026] [security2:error] [pid 703393:tid 703527] [client 172.237.109.114:14723] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0c637Arlr6Yb1EcNmAAAAIk"]
[Thu Jul 30 12:16:03.594547 2026] [security2:error] [pid 703393:tid 703618] [client 172.237.109.114:8234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0c637Arlr6Yb1EcNngAAAOQ"]
[Thu Jul 30 12:16:03.618501 2026] [security2:error] [pid 703393:tid 703628] [client 172.237.109.114:46366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0s637Arlr6Yb1EcNpAAAAO4"]
[Thu Jul 30 12:16:03.647120 2026] [security2:error] [pid 703393:tid 703588] [client 172.237.109.114:56155] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0c637Arlr6Yb1EcNogAAAMY"]
[Thu Jul 30 12:16:03.658368 2026] [security2:error] [pid 703393:tid 703647] [client 172.237.109.114:25599] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0s637Arlr6Yb1EcNpwAAAQE"]
[Thu Jul 30 12:16:03.659871 2026] [security2:error] [pid 703393:tid 703623] [client 172.237.109.114:50747] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0s637Arlr6Yb1EcNpgAAAOk"]
[Thu Jul 30 12:16:03.665089 2026] [security2:error] [pid 703393:tid 703565] [client 223.109.255.141:44372] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "marlboro-shop.com"] [uri "/"] [unique_id "amuG08637Arlr6Yb1EcNzAAAAK8"]
[Thu Jul 30 12:16:03.665197 2026] [security2:error] [pid 703393:tid 703565] [client 223.109.255.141:44372] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "marlboro-shop.com"] [uri "/"] [unique_id "amuG08637Arlr6Yb1EcNzAAAAK8"]
[Thu Jul 30 12:16:03.778351 2026] [security2:error] [pid 703393:tid 703554] [client 74.7.175.131:49662] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "helper.adtop.net"] [uri "/robots.txt"] [unique_id "amuG08637Arlr6Yb1EcN0gAApEk"]
[Thu Jul 30 12:16:04.023439 2026] [security2:error] [pid 703393:tid 703579] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/aaa.php"] [unique_id "amuG1M637Arlr6Yb1EcN1gAAAL0"]
[Thu Jul 30 12:16:04.023556 2026] [security2:error] [pid 703393:tid 703579] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/aaa.php"] [unique_id "amuG1M637Arlr6Yb1EcN1gAAAL0"]
[Thu Jul 30 12:16:04.035668 2026] [security2:error] [pid 703393:tid 703526] [client 57.141.0.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuG08637Arlr6Yb1EcNxgAAAIg"]
[Thu Jul 30 12:16:04.389489 2026] [security2:error] [pid 703393:tid 703643] [client 57.141.0.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuG08637Arlr6Yb1EcN1AAAAP0"]
[Thu Jul 30 12:16:04.575190 2026] [security2:error] [pid 703393:tid 703644] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/7.php"] [unique_id "amuG1M637Arlr6Yb1EcN3QAAAP4"]
[Thu Jul 30 12:16:04.575312 2026] [security2:error] [pid 703393:tid 703644] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/7.php"] [unique_id "amuG1M637Arlr6Yb1EcN3QAAAP4"]
[Thu Jul 30 12:16:05.114944 2026] [security2:error] [pid 703393:tid 703646] [client 20.63.98.115:42950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/zwso.php"] [unique_id "amuG1c637Arlr6Yb1EcN5QAAAQA"]
[Thu Jul 30 12:16:05.158379 2026] [security2:error] [pid 703393:tid 703546] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/file5.php"] [unique_id "amuG1c637Arlr6Yb1EcN6AAAAJw"]
[Thu Jul 30 12:16:05.158494 2026] [security2:error] [pid 703393:tid 703546] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/file5.php"] [unique_id "amuG1c637Arlr6Yb1EcN6AAAAJw"]
[Thu Jul 30 12:16:05.176644 2026] [core:notice] [pid 703393:tid 703456] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:16:05.764389 2026] [security2:error] [pid 703393:tid 703593] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/makeasmtp.php"] [unique_id "amuG1c637Arlr6Yb1EcN9AAAAMs"]
[Thu Jul 30 12:16:05.764505 2026] [security2:error] [pid 703393:tid 703593] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/makeasmtp.php"] [unique_id "amuG1c637Arlr6Yb1EcN9AAAAMs"]
[Thu Jul 30 12:16:06.297298 2026] [security2:error] [pid 703393:tid 703604] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-content/index.php"] [unique_id "amuG1s637Arlr6Yb1EcN_gAAANY"]
[Thu Jul 30 12:16:06.297402 2026] [security2:error] [pid 703393:tid 703604] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-content/index.php"] [unique_id "amuG1s637Arlr6Yb1EcN_gAAANY"]
[Thu Jul 30 12:16:06.791450 2026] [security2:error] [pid 703393:tid 703573] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/atomlib.php"] [unique_id "amuG1s637Arlr6Yb1EcOBQAAALc"]
[Thu Jul 30 12:16:06.791565 2026] [security2:error] [pid 703393:tid 703573] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/atomlib.php"] [unique_id "amuG1s637Arlr6Yb1EcOBQAAALc"]
[Thu Jul 30 12:16:07.002021 2026] [security2:error] [pid 703393:tid 703571] [client 20.63.98.115:44096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/user.php"] [unique_id "amuG18637Arlr6Yb1EcOCgAAALU"]
[Thu Jul 30 12:16:07.330466 2026] [security2:error] [pid 703393:tid 703624] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/min.php"] [unique_id "amuG18637Arlr6Yb1EcODgAAAOo"]
[Thu Jul 30 12:16:07.330590 2026] [security2:error] [pid 703393:tid 703624] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/min.php"] [unique_id "amuG18637Arlr6Yb1EcODgAAAOo"]
[Thu Jul 30 12:16:08.039343 2026] [security2:error] [pid 703393:tid 703544] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/moon.php"] [unique_id "amuG2M637Arlr6Yb1EcOGAAAAJo"]
[Thu Jul 30 12:16:08.039463 2026] [security2:error] [pid 703393:tid 703544] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/moon.php"] [unique_id "amuG2M637Arlr6Yb1EcOGAAAAJo"]
[Thu Jul 30 12:16:08.047629 2026] [security2:error] [pid 703393:tid 703635] [client 20.63.98.115:42996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/assets/index.php"] [unique_id "amuG2M637Arlr6Yb1EcOGgAAAPU"]
[Thu Jul 30 12:16:08.561249 2026] [security2:error] [pid 703393:tid 703537] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/ws83.php"] [unique_id "amuG2M637Arlr6Yb1EcOIwAAAJM"]
[Thu Jul 30 12:16:08.561352 2026] [security2:error] [pid 703393:tid 703537] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/ws83.php"] [unique_id "amuG2M637Arlr6Yb1EcOIwAAAJM"]
[Thu Jul 30 12:16:08.865785 2026] [security2:error] [pid 703393:tid 703498] [remote 74.7.242.7:49830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.242.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/"] [unique_id "amuG2M637Arlr6Yb1EcOJwAAwGg"], referer: https://www.thdinfinity.com/
[Thu Jul 30 12:16:09.073998 2026] [security2:error] [pid 703393:tid 703613] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/403.php"] [unique_id "amuG2c637Arlr6Yb1EcOKAAAAN8"]
[Thu Jul 30 12:16:09.074112 2026] [security2:error] [pid 703393:tid 703613] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/403.php"] [unique_id "amuG2c637Arlr6Yb1EcOKAAAAN8"]
[Thu Jul 30 12:16:09.116630 2026] [security2:error] [pid 703393:tid 703600] [client 20.63.98.115:39085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/byp.php"] [unique_id "amuG2c637Arlr6Yb1EcOLAAAANI"]
[Thu Jul 30 12:16:09.263015 2026] [core:notice] [pid 703393:tid 703485] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:16:09.582597 2026] [security2:error] [pid 703393:tid 703531] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/api.php"] [unique_id "amuG2c637Arlr6Yb1EcOMwAAAI0"]
[Thu Jul 30 12:16:09.582725 2026] [security2:error] [pid 703393:tid 703531] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/api.php"] [unique_id "amuG2c637Arlr6Yb1EcOMwAAAI0"]
[Thu Jul 30 12:16:09.985123 2026] [autoindex:error] [pid 703393:tid 703579] [client 34.195.23.187:0] AH01276: Cannot serve directory /home2/mbmudite/koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:16:10.067727 2026] [security2:error] [pid 703393:tid 703539] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/3.php"] [unique_id "amuG2s637Arlr6Yb1EcOPAAAAJU"]
[Thu Jul 30 12:16:10.067844 2026] [security2:error] [pid 703393:tid 703539] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/3.php"] [unique_id "amuG2s637Arlr6Yb1EcOPAAAAJU"]
[Thu Jul 30 12:16:11.532198 2026] [core:notice] [pid 703393:tid 703508] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:16:11.591256 2026] [autoindex:error] [pid 703393:tid 703614] [client 32.193.141.171:0] AH01276: Cannot serve directory /home2/mbmudite/otbola.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:16:11.976971 2026] [security2:error] [pid 703393:tid 703600] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/___proxy_subdomain_webdisk/wp-includes/PHPMailer/"] [unique_id "amuG28637Arlr6Yb1EcOYQAAANI"]
[Thu Jul 30 12:16:13.767953 2026] [security2:error] [pid 703393:tid 703583] [client 114.119.156.131:53941] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.azureskyfilms.com"] [uri "/dsc4-2.html"] [unique_id "amuG3c637Arlr6Yb1EcOfAAAAME"], referer: https://www.azureskyfilms.com/dsc4-2.html
[Thu Jul 30 12:16:15.070303 2026] [security2:error] [pid 703393:tid 703586] [client 2a03:2880:f800:3d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuG3s637Arlr6Yb1EcOjgAAxCM"]
[Thu Jul 30 12:16:15.220856 2026] [security2:error] [pid 703393:tid 703600] [client 223.109.255.161:36288] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/nike-air-jordan-1-mid-black-gold/"] [unique_id "amuG38637Arlr6Yb1EcOngAAANI"]
[Thu Jul 30 12:16:15.220970 2026] [security2:error] [pid 703393:tid 703600] [client 223.109.255.161:36288] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/product/nike-air-jordan-1-mid-black-gold/"] [unique_id "amuG38637Arlr6Yb1EcOngAAANI"]
[Thu Jul 30 12:16:15.317654 2026] [security2:error] [pid 703393:tid 703554] [client 20.63.98.115:58178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/bs1.php"] [unique_id "amuG38637Arlr6Yb1EcOowAAAKQ"]
[Thu Jul 30 12:16:16.427076 2026] [security2:error] [pid 703393:tid 703585] [client 20.63.98.115:39042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/IXR/allez.php"] [unique_id "amuG4M637Arlr6Yb1EcOtgAAAMM"]
[Thu Jul 30 12:16:16.796496 2026] [security2:error] [pid 703393:tid 703634] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/ws77.php"] [unique_id "amuG4M637Arlr6Yb1EcOxQAAAPQ"]
[Thu Jul 30 12:16:16.796591 2026] [security2:error] [pid 703393:tid 703634] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/ws77.php"] [unique_id "amuG4M637Arlr6Yb1EcOxQAAAPQ"]
[Thu Jul 30 12:16:17.028863 2026] [security2:error] [pid 703393:tid 703496] [remote 74.7.241.59:46250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuG4c637Arlr6Yb1EcO0gAAxWY"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/premium-addons-for-elementor/modules/woocommerce/templates
[Thu Jul 30 12:16:17.343597 2026] [security2:error] [pid 703393:tid 703534] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/nc4.php"] [unique_id "amuG4c637Arlr6Yb1EcO2QAAAJA"]
[Thu Jul 30 12:16:17.343685 2026] [security2:error] [pid 703393:tid 703534] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/nc4.php"] [unique_id "amuG4c637Arlr6Yb1EcO2QAAAJA"]
[Thu Jul 30 12:16:17.478547 2026] [security2:error] [pid 703393:tid 703443] [remote 198.244.168.162:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "filmtvyap.com"] [uri "/barbie-film/"] [unique_id "amuG4c637Arlr6Yb1EcO3QAAujE"]
[Thu Jul 30 12:16:17.478794 2026] [security2:error] [pid 703393:tid 703576] [client 198.244.168.162:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "filmtvyap.com"] [uri "/barbie-film/"] [unique_id "amuG4c637Arlr6Yb1EcO3QAAujE"]
[Thu Jul 30 12:16:17.510195 2026] [security2:error] [pid 703393:tid 703645] [client 20.63.98.115:42961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/load.php"] [unique_id "amuG4c637Arlr6Yb1EcO3gAAAP8"]
[Thu Jul 30 12:16:17.528071 2026] [security2:error] [pid 703393:tid 703615] [client 57.141.0.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuG4M637Arlr6Yb1EcOzQAAAOE"]
[Thu Jul 30 12:16:17.756430 2026] [security2:error] [pid 703393:tid 703567] [client 51.120.69.65:16264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/alpas.php"] [unique_id "amuG4c637Arlr6Yb1EcO5AAAALE"]
[Thu Jul 30 12:16:17.756544 2026] [security2:error] [pid 703393:tid 703567] [client 51.120.69.65:16264] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/alpas.php"] [unique_id "amuG4c637Arlr6Yb1EcO5AAAALE"]
[Thu Jul 30 12:16:17.824808 2026] [security2:error] [pid 703393:tid 703539] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/as.php"] [unique_id "amuG4c637Arlr6Yb1EcO5gAAAJU"]
[Thu Jul 30 12:16:17.824915 2026] [security2:error] [pid 703393:tid 703539] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/as.php"] [unique_id "amuG4c637Arlr6Yb1EcO5gAAAJU"]
[Thu Jul 30 12:16:18.341688 2026] [security2:error] [pid 703393:tid 703524] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/k.php"] [unique_id "amuG4s637Arlr6Yb1EcO8AAAAIY"]
[Thu Jul 30 12:16:18.341781 2026] [security2:error] [pid 703393:tid 703524] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/k.php"] [unique_id "amuG4s637Arlr6Yb1EcO8AAAAIY"]
[Thu Jul 30 12:16:18.365660 2026] [security2:error] [pid 703393:tid 703580] [client 51.120.69.65:16275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/alfa.php"] [unique_id "amuG4s637Arlr6Yb1EcO8QAAAL4"]
[Thu Jul 30 12:16:18.365742 2026] [security2:error] [pid 703393:tid 703580] [client 51.120.69.65:16275] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/alfa.php"] [unique_id "amuG4s637Arlr6Yb1EcO8QAAAL4"]
[Thu Jul 30 12:16:18.559066 2026] [security2:error] [pid 703393:tid 703404] [remote 74.7.241.60:60628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/content/article.php"] [unique_id "amuG4s637Arlr6Yb1EcO9QAA8Qo"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/content/1784123347_ed%20inclusive.jpg
[Thu Jul 30 12:16:18.809652 2026] [security2:error] [pid 703393:tid 703629] [client 51.120.69.65:16350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/0byte.php"] [unique_id "amuG4s637Arlr6Yb1EcO9gAAAO8"]
[Thu Jul 30 12:16:18.809763 2026] [security2:error] [pid 703393:tid 703629] [client 51.120.69.65:16350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/0byte.php"] [unique_id "amuG4s637Arlr6Yb1EcO9gAAAO8"]
[Thu Jul 30 12:16:18.842530 2026] [security2:error] [pid 703393:tid 703602] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/system_log.php"] [unique_id "amuG4s637Arlr6Yb1EcO-gAAANQ"]
[Thu Jul 30 12:16:18.842694 2026] [security2:error] [pid 703393:tid 703602] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/system_log.php"] [unique_id "amuG4s637Arlr6Yb1EcO-gAAANQ"]
[Thu Jul 30 12:16:19.269969 2026] [security2:error] [pid 703393:tid 703614] [client 51.120.69.65:16289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/index3.php"] [unique_id "amuG48637Arlr6Yb1EcPAgAAAOA"]
[Thu Jul 30 12:16:19.270096 2026] [security2:error] [pid 703393:tid 703614] [client 51.120.69.65:16289] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/index3.php"] [unique_id "amuG48637Arlr6Yb1EcPAgAAAOA"]
[Thu Jul 30 12:16:19.380972 2026] [security2:error] [pid 703393:tid 703598] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/x.php"] [unique_id "amuG48637Arlr6Yb1EcPCQAAANA"]
[Thu Jul 30 12:16:19.381154 2026] [security2:error] [pid 703393:tid 703598] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/x.php"] [unique_id "amuG48637Arlr6Yb1EcPCQAAANA"]
[Thu Jul 30 12:16:19.665831 2026] [security2:error] [pid 703393:tid 703543] [client 20.63.98.115:20707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/privacy.php"] [unique_id "amuG48637Arlr6Yb1EcPEAAAAJk"]
[Thu Jul 30 12:16:19.739469 2026] [security2:error] [pid 703393:tid 703615] [client 51.120.69.65:16281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/index2.php"] [unique_id "amuG48637Arlr6Yb1EcPEQAAAOE"]
[Thu Jul 30 12:16:19.739593 2026] [security2:error] [pid 703393:tid 703615] [client 51.120.69.65:16281] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/index2.php"] [unique_id "amuG48637Arlr6Yb1EcPEQAAAOE"]
[Thu Jul 30 12:16:19.808306 2026] [security2:error] [pid 703393:tid 703542] [client 46.16.148.94:47950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuG48637Arlr6Yb1EcPCwAAAJg"], referer: http://pkf.jo
[Thu Jul 30 12:16:19.815741 2026] [security2:error] [pid 703393:tid 703647] [client 109.198.225.117:6124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuG48637Arlr6Yb1EcPCgAAAQE"], referer: http://pkf.jo
[Thu Jul 30 12:16:19.979993 2026] [security2:error] [pid 703393:tid 703601] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/autoload_classmap.php"] [unique_id "amuG48637Arlr6Yb1EcPHAAAANM"]
[Thu Jul 30 12:16:19.980094 2026] [security2:error] [pid 703393:tid 703601] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/autoload_classmap.php"] [unique_id "amuG48637Arlr6Yb1EcPHAAAANM"]
[Thu Jul 30 12:16:20.191613 2026] [security2:error] [pid 703393:tid 703630] [client 51.120.69.65:16286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/index1.php"] [unique_id "amuG5M637Arlr6Yb1EcPIAAAAPA"]
[Thu Jul 30 12:16:20.191728 2026] [security2:error] [pid 703393:tid 703630] [client 51.120.69.65:16286] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/index1.php"] [unique_id "amuG5M637Arlr6Yb1EcPIAAAAPA"]
[Thu Jul 30 12:16:20.374517 2026] [security2:error] [pid 703393:tid 703584] [client 157.51.194.171:46013] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuG5M637Arlr6Yb1EcPHwAAAMI"], referer: http://pkf.jo
[Thu Jul 30 12:16:20.548291 2026] [security2:error] [pid 703393:tid 703585] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/test1.php"] [unique_id "amuG5M637Arlr6Yb1EcPKgAAAMM"]
[Thu Jul 30 12:16:20.548428 2026] [security2:error] [pid 703393:tid 703585] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/test1.php"] [unique_id "amuG5M637Arlr6Yb1EcPKgAAAMM"]
[Thu Jul 30 12:16:20.665360 2026] [security2:error] [pid 703393:tid 703530] [client 51.120.69.65:16364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/303.php"] [unique_id "amuG5M637Arlr6Yb1EcPLwAAAIw"]
[Thu Jul 30 12:16:20.665467 2026] [security2:error] [pid 703393:tid 703530] [client 51.120.69.65:16364] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/303.php"] [unique_id "amuG5M637Arlr6Yb1EcPLwAAAIw"]
[Thu Jul 30 12:16:20.818995 2026] [security2:error] [pid 703393:tid 703646] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "baytalhuboob.com"] [uri "/.well-known/about.php"] [unique_id "amuG5M637Arlr6Yb1EcPMAAAAQA"]
[Thu Jul 30 12:16:20.819104 2026] [security2:error] [pid 703393:tid 703646] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "baytalhuboob.com"] [uri "/.well-known/about.php"] [unique_id "amuG5M637Arlr6Yb1EcPMAAAAQA"]
[Thu Jul 30 12:16:20.943093 2026] [security2:error] [pid 703393:tid 703566] [client 38.41.27.135:42528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuG5M637Arlr6Yb1EcPLgAAALA"], referer: http://pkf.jo
[Thu Jul 30 12:16:21.057197 2026] [security2:error] [pid 703393:tid 703558] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/___proxy_subdomain_webdisk/mini"] [unique_id "amuG5c637Arlr6Yb1EcPNAAAAKg"]
[Thu Jul 30 12:16:21.086964 2026] [security2:error] [pid 703393:tid 703644] [client 51.120.69.65:16360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/505.php"] [unique_id "amuG5c637Arlr6Yb1EcPNQAAAP4"]
[Thu Jul 30 12:16:21.087076 2026] [security2:error] [pid 703393:tid 703644] [client 51.120.69.65:16360] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/505.php"] [unique_id "amuG5c637Arlr6Yb1EcPNQAAAP4"]
[Thu Jul 30 12:16:21.297149 2026] [security2:error] [pid 703393:tid 703546] [client 20.63.98.115:60238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-cli.php"] [unique_id "amuG5c637Arlr6Yb1EcPOgAAAJw"]
[Thu Jul 30 12:16:21.308159 2026] [security2:error] [pid 703393:tid 703598] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-signin.php"] [unique_id "amuG5c637Arlr6Yb1EcPOwAAANA"]
[Thu Jul 30 12:16:21.308306 2026] [security2:error] [pid 703393:tid 703598] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-signin.php"] [unique_id "amuG5c637Arlr6Yb1EcPOwAAANA"]
[Thu Jul 30 12:16:21.580469 2026] [security2:error] [pid 703393:tid 703625] [client 51.120.69.65:16325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/500.php"] [unique_id "amuG5c637Arlr6Yb1EcPRgAAAOs"]
[Thu Jul 30 12:16:21.580577 2026] [security2:error] [pid 703393:tid 703625] [client 51.120.69.65:16325] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/500.php"] [unique_id "amuG5c637Arlr6Yb1EcPRgAAAOs"]
[Thu Jul 30 12:16:21.805851 2026] [security2:error] [pid 703393:tid 703623] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/gg.php"] [unique_id "amuG5c637Arlr6Yb1EcPSAAAAOk"]
[Thu Jul 30 12:16:21.805961 2026] [security2:error] [pid 703393:tid 703623] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/gg.php"] [unique_id "amuG5c637Arlr6Yb1EcPSAAAAOk"]
[Thu Jul 30 12:16:22.083789 2026] [security2:error] [pid 703393:tid 703549] [client 51.120.69.65:16258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/77.php"] [unique_id "amuG5s637Arlr6Yb1EcPTAAAAJ8"]
[Thu Jul 30 12:16:22.083896 2026] [security2:error] [pid 703393:tid 703549] [client 51.120.69.65:16258] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/77.php"] [unique_id "amuG5s637Arlr6Yb1EcPTAAAAJ8"]
[Thu Jul 30 12:16:22.295857 2026] [security2:error] [pid 703393:tid 703608] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/class.php"] [unique_id "amuG5s637Arlr6Yb1EcPUAAAANo"]
[Thu Jul 30 12:16:22.295968 2026] [security2:error] [pid 703393:tid 703608] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/class.php"] [unique_id "amuG5s637Arlr6Yb1EcPUAAAANo"]
[Thu Jul 30 12:16:22.607608 2026] [security2:error] [pid 703393:tid 703553] [client 51.120.69.65:16356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/76.php"] [unique_id "amuG5s637Arlr6Yb1EcPVAAAAKM"]
[Thu Jul 30 12:16:22.607691 2026] [security2:error] [pid 703393:tid 703553] [client 51.120.69.65:16356] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/76.php"] [unique_id "amuG5s637Arlr6Yb1EcPVAAAAKM"]
[Thu Jul 30 12:16:22.805567 2026] [security2:error] [pid 703393:tid 703533] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/404.php"] [unique_id "amuG5s637Arlr6Yb1EcPWgAAAI8"]
[Thu Jul 30 12:16:22.805683 2026] [security2:error] [pid 703393:tid 703533] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/404.php"] [unique_id "amuG5s637Arlr6Yb1EcPWgAAAI8"]
[Thu Jul 30 12:16:22.903248 2026] [security2:error] [pid 703393:tid 703624] [client 20.63.98.115:65468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/cc.php"] [unique_id "amuG5s637Arlr6Yb1EcPWwAAAOo"]
[Thu Jul 30 12:16:23.048851 2026] [security2:error] [pid 703393:tid 703603] [client 51.120.69.65:16380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/74.php"] [unique_id "amuG58637Arlr6Yb1EcPYAAAANU"]
[Thu Jul 30 12:16:23.048995 2026] [security2:error] [pid 703393:tid 703603] [client 51.120.69.65:16380] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/74.php"] [unique_id "amuG58637Arlr6Yb1EcPYAAAANU"]
[Thu Jul 30 12:16:23.362595 2026] [security2:error] [pid 703393:tid 703597] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/lite.php"] [unique_id "amuG58637Arlr6Yb1EcPZAAAAM8"]
[Thu Jul 30 12:16:23.362709 2026] [security2:error] [pid 703393:tid 703597] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/lite.php"] [unique_id "amuG58637Arlr6Yb1EcPZAAAAM8"]
[Thu Jul 30 12:16:23.463225 2026] [security2:error] [pid 703393:tid 703546] [client 51.120.69.65:16357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/wp-config.php"] [unique_id "amuG58637Arlr6Yb1EcPZgAAAJw"]
[Thu Jul 30 12:16:23.463340 2026] [security2:error] [pid 703393:tid 703546] [client 51.120.69.65:16357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/wp-config.php"] [unique_id "amuG58637Arlr6Yb1EcPZgAAAJw"]
[Thu Jul 30 12:16:23.928563 2026] [security2:error] [pid 703393:tid 703586] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/lock360.php"] [unique_id "amuG58637Arlr6Yb1EcPbgAAAMQ"]
[Thu Jul 30 12:16:23.928701 2026] [security2:error] [pid 703393:tid 703586] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/lock360.php"] [unique_id "amuG58637Arlr6Yb1EcPbgAAAMQ"]
[Thu Jul 30 12:16:23.955502 2026] [security2:error] [pid 703393:tid 703618] [client 51.120.69.65:16260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/75.php"] [unique_id "amuG58637Arlr6Yb1EcPbwAAAOQ"]
[Thu Jul 30 12:16:23.955649 2026] [security2:error] [pid 703393:tid 703618] [client 51.120.69.65:16260] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/75.php"] [unique_id "amuG58637Arlr6Yb1EcPbwAAAOQ"]
[Thu Jul 30 12:16:24.484382 2026] [security2:error] [pid 703393:tid 703570] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-content/wp-conflg.php"] [unique_id "amuG6M637Arlr6Yb1EcPeAAAALQ"]
[Thu Jul 30 12:16:24.484527 2026] [security2:error] [pid 703393:tid 703570] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-content/wp-conflg.php"] [unique_id "amuG6M637Arlr6Yb1EcPeAAAALQ"]
[Thu Jul 30 12:16:24.516353 2026] [security2:error] [pid 703393:tid 703529] [client 51.120.69.65:16371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/71.php"] [unique_id "amuG6M637Arlr6Yb1EcPeQAAAIs"]
[Thu Jul 30 12:16:24.516462 2026] [security2:error] [pid 703393:tid 703529] [client 51.120.69.65:16371] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/71.php"] [unique_id "amuG6M637Arlr6Yb1EcPeQAAAIs"]
[Thu Jul 30 12:16:24.744869 2026] [autoindex:error] [pid 703393:tid 703541] [client 43.140.247.223:33368] AH01276: Cannot serve directory /home1/uixgzjte/public_html/guethleentertainment.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:16:24.803242 2026] [security2:error] [pid 703393:tid 703640] [client 20.63.98.115:44140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/media-new.php"] [unique_id "amuG6M637Arlr6Yb1EcPgQAAAPo"]
[Thu Jul 30 12:16:24.893394 2026] [security2:error] [pid 703393:tid 703552] [client 51.120.69.65:16272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/72.php"] [unique_id "amuG6M637Arlr6Yb1EcPggAAAKI"]
[Thu Jul 30 12:16:24.893492 2026] [security2:error] [pid 703393:tid 703552] [client 51.120.69.65:16272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/72.php"] [unique_id "amuG6M637Arlr6Yb1EcPggAAAKI"]
[Thu Jul 30 12:16:24.973334 2026] [security2:error] [pid 703393:tid 703584] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-links-opml.php"] [unique_id "amuG6M637Arlr6Yb1EcPgwAAAMI"]
[Thu Jul 30 12:16:24.973435 2026] [security2:error] [pid 703393:tid 703584] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-links-opml.php"] [unique_id "amuG6M637Arlr6Yb1EcPgwAAAMI"]
[Thu Jul 30 12:16:25.400694 2026] [security2:error] [pid 703393:tid 703631] [client 51.120.69.65:15617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/70.php"] [unique_id "amuG6c637Arlr6Yb1EcPjgAAAPE"]
[Thu Jul 30 12:16:25.400790 2026] [security2:error] [pid 703393:tid 703631] [client 51.120.69.65:15617] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/70.php"] [unique_id "amuG6c637Arlr6Yb1EcPjgAAAPE"]
[Thu Jul 30 12:16:25.467824 2026] [security2:error] [pid 703393:tid 703551] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-content/uploads/min.php"] [unique_id "amuG6c637Arlr6Yb1EcPjwAAAKE"]
[Thu Jul 30 12:16:25.467927 2026] [security2:error] [pid 703393:tid 703551] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-content/uploads/min.php"] [unique_id "amuG6c637Arlr6Yb1EcPjwAAAKE"]
[Thu Jul 30 12:16:25.774326 2026] [security2:error] [pid 703393:tid 703526] [client 20.63.98.115:44150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-blog.php"] [unique_id "amuG6c637Arlr6Yb1EcPkwAAAIg"]
[Thu Jul 30 12:16:26.186622 2026] [security2:error] [pid 703393:tid 703563] [client 51.120.69.65:16279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/69.php"] [unique_id "amuG6s637Arlr6Yb1EcPnQAAAK0"]
[Thu Jul 30 12:16:26.186732 2026] [security2:error] [pid 703393:tid 703563] [client 51.120.69.65:16279] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/69.php"] [unique_id "amuG6s637Arlr6Yb1EcPnQAAAK0"]
[Thu Jul 30 12:16:26.591857 2026] [core:notice] [pid 703393:tid 703613] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:16:27.006212 2026] [security2:error] [pid 703393:tid 703642] [client 51.120.69.65:16278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/68.php"] [unique_id "amuG68637Arlr6Yb1EcPrAAAAPw"]
[Thu Jul 30 12:16:27.006368 2026] [security2:error] [pid 703393:tid 703642] [client 51.120.69.65:16278] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/68.php"] [unique_id "amuG68637Arlr6Yb1EcPrAAAAPw"]
[Thu Jul 30 12:16:27.493790 2026] [security2:error] [pid 703393:tid 703628] [client 51.120.69.65:16341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/66.php"] [unique_id "amuG68637Arlr6Yb1EcPugAAAO4"]
[Thu Jul 30 12:16:27.493894 2026] [security2:error] [pid 703393:tid 703628] [client 51.120.69.65:16341] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/66.php"] [unique_id "amuG68637Arlr6Yb1EcPugAAAO4"]
[Thu Jul 30 12:16:28.042428 2026] [security2:error] [pid 703393:tid 703550] [client 51.120.69.65:16297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/67.php"] [unique_id "amuG7M637Arlr6Yb1EcPwQAAAKA"]
[Thu Jul 30 12:16:28.042525 2026] [security2:error] [pid 703393:tid 703550] [client 51.120.69.65:16297] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/67.php"] [unique_id "amuG7M637Arlr6Yb1EcPwQAAAKA"]
[Thu Jul 30 12:16:28.068511 2026] [security2:error] [pid 703393:tid 703632] [client 20.63.98.115:42981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-2019.php"] [unique_id "amuG7M637Arlr6Yb1EcPwgAAAPI"]
[Thu Jul 30 12:16:28.329785 2026] [security2:error] [pid 703393:tid 703519] [remote 72.167.132.114:60442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/wp-login.php"] [unique_id "amuG7M637Arlr6Yb1EcPywAAtH0"]
[Thu Jul 30 12:16:28.516691 2026] [security2:error] [pid 703393:tid 703634] [client 51.120.69.65:16296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/65.php"] [unique_id "amuG7M637Arlr6Yb1EcPzwAAAPQ"]
[Thu Jul 30 12:16:28.516869 2026] [security2:error] [pid 703393:tid 703634] [client 51.120.69.65:16296] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/65.php"] [unique_id "amuG7M637Arlr6Yb1EcPzwAAAPQ"]
[Thu Jul 30 12:16:28.824566 2026] [security2:error] [pid 703393:tid 703646] [client 184.75.223.195:53234] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuG7M637Arlr6Yb1EcP1AAAAQA"]
[Thu Jul 30 12:16:28.824665 2026] [security2:error] [pid 703393:tid 703646] [client 184.75.223.195:53234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuG7M637Arlr6Yb1EcP1AAAAQA"]
[Thu Jul 30 12:16:28.988999 2026] [security2:error] [pid 703393:tid 703624] [client 51.120.69.65:16287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/64.php"] [unique_id "amuG7M637Arlr6Yb1EcP2QAAAOo"]
[Thu Jul 30 12:16:28.989143 2026] [security2:error] [pid 703393:tid 703624] [client 51.120.69.65:16287] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/64.php"] [unique_id "amuG7M637Arlr6Yb1EcP2QAAAOo"]
[Thu Jul 30 12:16:29.376065 2026] [security2:error] [pid 703393:tid 703560] [client 51.120.69.65:15618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/63.php"] [unique_id "amuG7c637Arlr6Yb1EcP3QAAAKo"]
[Thu Jul 30 12:16:29.376173 2026] [security2:error] [pid 703393:tid 703560] [client 51.120.69.65:15618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/63.php"] [unique_id "amuG7c637Arlr6Yb1EcP3QAAAKo"]
[Thu Jul 30 12:16:29.481204 2026] [security2:error] [pid 703393:tid 703578] [client 20.104.18.253:7095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/n9z13o5s.php"] [unique_id "amuG7c637Arlr6Yb1EcP4QAAALw"]
[Thu Jul 30 12:16:29.757105 2026] [security2:error] [pid 703393:tid 703545] [client 51.120.69.65:16266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/62.php"] [unique_id "amuG7c637Arlr6Yb1EcP5QAAAJs"]
[Thu Jul 30 12:16:29.757207 2026] [security2:error] [pid 703393:tid 703545] [client 51.120.69.65:16266] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/62.php"] [unique_id "amuG7c637Arlr6Yb1EcP5QAAAJs"]
[Thu Jul 30 12:16:29.767552 2026] [core:notice] [pid 703393:tid 703613] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:16:30.174262 2026] [security2:error] [pid 703393:tid 703534] [client 51.120.69.65:16370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/61.php"] [unique_id "amuG7s637Arlr6Yb1EcP6gAAAJA"]
[Thu Jul 30 12:16:30.174390 2026] [security2:error] [pid 703393:tid 703534] [client 51.120.69.65:16370] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/61.php"] [unique_id "amuG7s637Arlr6Yb1EcP6gAAAJA"]
[Thu Jul 30 12:16:30.329923 2026] [security2:error] [pid 703393:tid 703554] [client 20.104.18.253:7071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/uploads/2014/03/smile.php"] [unique_id "amuG7s637Arlr6Yb1EcP8AAAAKQ"]
[Thu Jul 30 12:16:30.460071 2026] [security2:error] [pid 703393:tid 703526] [client 20.63.98.115:60224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/menu.php"] [unique_id "amuG7s637Arlr6Yb1EcP8wAAAIg"]
[Thu Jul 30 12:16:30.655111 2026] [security2:error] [pid 703393:tid 703573] [client 51.120.69.65:15622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/60.php"] [unique_id "amuG7s637Arlr6Yb1EcP-AAAALc"]
[Thu Jul 30 12:16:30.655210 2026] [security2:error] [pid 703393:tid 703573] [client 51.120.69.65:15622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/60.php"] [unique_id "amuG7s637Arlr6Yb1EcP-AAAALc"]
[Thu Jul 30 12:16:31.047535 2026] [security2:error] [pid 703393:tid 703557] [client 20.104.18.253:7064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/ini.php"] [unique_id "amuG78637Arlr6Yb1EcQAAAAAKc"]
[Thu Jul 30 12:16:31.069780 2026] [security2:error] [pid 703393:tid 703600] [client 51.120.69.65:16352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/58.php"] [unique_id "amuG78637Arlr6Yb1EcQAQAAANI"]
[Thu Jul 30 12:16:31.069863 2026] [security2:error] [pid 703393:tid 703600] [client 51.120.69.65:16352] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/58.php"] [unique_id "amuG78637Arlr6Yb1EcQAQAAANI"]
[Thu Jul 30 12:16:31.459922 2026] [security2:error] [pid 703393:tid 703638] [client 51.120.69.65:16274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/59.php"] [unique_id "amuG78637Arlr6Yb1EcQCAAAAPg"]
[Thu Jul 30 12:16:31.460089 2026] [security2:error] [pid 703393:tid 703638] [client 51.120.69.65:16274] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/59.php"] [unique_id "amuG78637Arlr6Yb1EcQCAAAAPg"]
[Thu Jul 30 12:16:31.501527 2026] [security2:error] [pid 703393:tid 703587] [client 43.134.69.235:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuG78637Arlr6Yb1EcQBAAAAMU"]
[Thu Jul 30 12:16:31.510194 2026] [security2:error] [pid 703393:tid 703636] [client 20.63.98.115:20819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-crons.php"] [unique_id "amuG78637Arlr6Yb1EcQDQAAAPY"]
[Thu Jul 30 12:16:31.680571 2026] [security2:error] [pid 703393:tid 703599] [client 87.101.92.171:43482] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuG78637Arlr6Yb1EcQDgAAANE"]
[Thu Jul 30 12:16:31.680677 2026] [security2:error] [pid 703393:tid 703599] [client 87.101.92.171:43482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuG78637Arlr6Yb1EcQDgAAANE"]
[Thu Jul 30 12:16:31.882787 2026] [security2:error] [pid 703393:tid 703566] [client 51.120.69.65:16375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/57.php/56.php"] [unique_id "amuG78637Arlr6Yb1EcQGQAAALA"]
[Thu Jul 30 12:16:31.882934 2026] [security2:error] [pid 703393:tid 703566] [client 51.120.69.65:16375] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/57.php/56.php"] [unique_id "amuG78637Arlr6Yb1EcQGQAAALA"]
[Thu Jul 30 12:16:32.300795 2026] [security2:error] [pid 703393:tid 703610] [client 51.120.69.65:16293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/55.php"] [unique_id "amuG8M637Arlr6Yb1EcQJQAAANw"]
[Thu Jul 30 12:16:32.300914 2026] [security2:error] [pid 703393:tid 703610] [client 51.120.69.65:16293] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/55.php"] [unique_id "amuG8M637Arlr6Yb1EcQJQAAANw"]
[Thu Jul 30 12:16:32.743737 2026] [security2:error] [pid 703393:tid 703534] [client 20.63.98.115:65449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/class.php"] [unique_id "amuG8M637Arlr6Yb1EcQOAAAAJA"]
[Thu Jul 30 12:16:33.115372 2026] [security2:error] [pid 703393:tid 703525] [client 14.191.108.32:20538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuG8M637Arlr6Yb1EcQOQAAAIc"], referer: http://pkf.jo
[Thu Jul 30 12:16:33.153288 2026] [security2:error] [pid 703393:tid 703530] [client 20.104.18.253:6830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/img/xleet.php"] [unique_id "amuG8c637Arlr6Yb1EcQQgAAAIw"]
[Thu Jul 30 12:16:33.227714 2026] [security2:error] [pid 703393:tid 703565] [client 51.120.69.65:16257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/54.php"] [unique_id "amuG8c637Arlr6Yb1EcQRAAAAK8"]
[Thu Jul 30 12:16:33.227809 2026] [security2:error] [pid 703393:tid 703565] [client 51.120.69.65:16257] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/54.php"] [unique_id "amuG8c637Arlr6Yb1EcQRAAAAK8"]
[Thu Jul 30 12:16:33.657456 2026] [security2:error] [pid 703393:tid 703600] [client 51.120.69.65:16321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/53.php"] [unique_id "amuG8c637Arlr6Yb1EcQTQAAANI"]
[Thu Jul 30 12:16:33.657561 2026] [security2:error] [pid 703393:tid 703600] [client 51.120.69.65:16321] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/53.php"] [unique_id "amuG8c637Arlr6Yb1EcQTQAAANI"]
[Thu Jul 30 12:16:33.770367 2026] [security2:error] [pid 703393:tid 703529] [client 20.63.98.115:65450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/login.php"] [unique_id "amuG8c637Arlr6Yb1EcQTgAAAIs"]
[Thu Jul 30 12:16:33.897124 2026] [proxy:error] [pid 703393:tid 703557] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:16:33.897176 2026] [proxy_http:error] [pid 703393:tid 703557] [client 20.104.18.253:6841] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:16:33.897736 2026] [proxy:error] [pid 703393:tid 703557] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:16:33.897777 2026] [proxy_http:error] [pid 703393:tid 703557] [client 20.104.18.253:6841] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:16:34.040832 2026] [security2:error] [pid 703393:tid 703587] [client 51.120.69.65:16362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/52.php"] [unique_id "amuG8s637Arlr6Yb1EcQVwAAAMU"]
[Thu Jul 30 12:16:34.040931 2026] [security2:error] [pid 703393:tid 703587] [client 51.120.69.65:16362] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/52.php"] [unique_id "amuG8s637Arlr6Yb1EcQVwAAAMU"]
[Thu Jul 30 12:16:34.417306 2026] [security2:error] [pid 703393:tid 703619] [client 51.120.69.65:16267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/51.php"] [unique_id "amuG8s637Arlr6Yb1EcQWAAAAOU"]
[Thu Jul 30 12:16:34.417431 2026] [security2:error] [pid 703393:tid 703619] [client 51.120.69.65:16267] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/51.php"] [unique_id "amuG8s637Arlr6Yb1EcQWAAAAOU"]
[Thu Jul 30 12:16:34.565843 2026] [security2:error] [pid 703393:tid 703532] [client 85.208.96.194:33916] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.urwru.club"] [uri "/copy-of-32-weeks-coaching"] [unique_id "amuG8s637Arlr6Yb1EcQXAAAAI4"]
[Thu Jul 30 12:16:34.566011 2026] [security2:error] [pid 703393:tid 703532] [client 85.208.96.194:33916] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.urwru.club"] [uri "/copy-of-32-weeks-coaching"] [unique_id "amuG8s637Arlr6Yb1EcQXAAAAI4"]
[Thu Jul 30 12:16:34.663516 2026] [security2:error] [pid 703393:tid 703551] [client 20.104.18.253:6802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/server.php"] [unique_id "amuG8s637Arlr6Yb1EcQYAAAAKE"]
[Thu Jul 30 12:16:34.783279 2026] [security2:error] [pid 703393:tid 703650] [client 51.120.69.65:16285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/50.php"] [unique_id "amuG8s637Arlr6Yb1EcQYQAAAQQ"]
[Thu Jul 30 12:16:34.783397 2026] [security2:error] [pid 703393:tid 703650] [client 51.120.69.65:16285] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/50.php"] [unique_id "amuG8s637Arlr6Yb1EcQYQAAAQQ"]
[Thu Jul 30 12:16:35.187912 2026] [security2:error] [pid 703393:tid 703610] [client 51.120.69.65:16298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/49.php"] [unique_id "amuG88637Arlr6Yb1EcQaQAAANw"]
[Thu Jul 30 12:16:35.188047 2026] [security2:error] [pid 703393:tid 703610] [client 51.120.69.65:16298] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/49.php"] [unique_id "amuG88637Arlr6Yb1EcQaQAAANw"]
[Thu Jul 30 12:16:35.462049 2026] [security2:error] [pid 703393:tid 703617] [client 20.104.18.253:7078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/.well-known/pki-validation/wp-config.php"] [unique_id "amuG88637Arlr6Yb1EcQbgAAAOM"]
[Thu Jul 30 12:16:35.585567 2026] [security2:error] [pid 703393:tid 703631] [client 51.120.69.65:16282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/48.php"] [unique_id "amuG88637Arlr6Yb1EcQcgAAAPE"]
[Thu Jul 30 12:16:35.585668 2026] [security2:error] [pid 703393:tid 703631] [client 51.120.69.65:16282] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/48.php"] [unique_id "amuG88637Arlr6Yb1EcQcgAAAPE"]
[Thu Jul 30 12:16:35.648039 2026] [security2:error] [pid 703393:tid 703625] [client 20.63.98.115:43006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/aged.php"] [unique_id "amuG88637Arlr6Yb1EcQdQAAAOs"]
[Thu Jul 30 12:16:35.975897 2026] [security2:error] [pid 703393:tid 703554] [client 51.120.69.65:15712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/47.php"] [unique_id "amuG88637Arlr6Yb1EcQeQAAAKQ"]
[Thu Jul 30 12:16:35.976038 2026] [security2:error] [pid 703393:tid 703554] [client 51.120.69.65:15712] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/47.php"] [unique_id "amuG88637Arlr6Yb1EcQeQAAAKQ"]
[Thu Jul 30 12:16:36.367307 2026] [security2:error] [pid 703393:tid 703525] [client 20.104.18.253:7045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/themes/twentytwentyfive/flower.php"] [unique_id "amuG9M637Arlr6Yb1EcQggAAAIc"]
[Thu Jul 30 12:16:36.613616 2026] [security2:error] [pid 703393:tid 703550] [client 51.120.69.65:16268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/46.php"] [unique_id "amuG9M637Arlr6Yb1EcQhwAAAKA"]
[Thu Jul 30 12:16:36.613721 2026] [security2:error] [pid 703393:tid 703550] [client 51.120.69.65:16268] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/46.php"] [unique_id "amuG9M637Arlr6Yb1EcQhwAAAKA"]
[Thu Jul 30 12:16:37.061305 2026] [security2:error] [pid 703393:tid 703556] [client 51.120.69.65:15646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/44.php"] [unique_id "amuG9c637Arlr6Yb1EcQjAAAAKY"]
[Thu Jul 30 12:16:37.061433 2026] [security2:error] [pid 703393:tid 703556] [client 51.120.69.65:15646] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/44.php"] [unique_id "amuG9c637Arlr6Yb1EcQjAAAAKY"]
[Thu Jul 30 12:16:37.442373 2026] [security2:error] [pid 703393:tid 703601] [client 20.63.98.115:20734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/vv.php"] [unique_id "amuG9c637Arlr6Yb1EcQkwAAANM"]
[Thu Jul 30 12:16:37.527209 2026] [security2:error] [pid 703393:tid 703585] [client 51.120.69.65:15625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/43.php"] [unique_id "amuG9c637Arlr6Yb1EcQlAAAAMM"]
[Thu Jul 30 12:16:37.527329 2026] [security2:error] [pid 703393:tid 703585] [client 51.120.69.65:15625] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/43.php"] [unique_id "amuG9c637Arlr6Yb1EcQlAAAAMM"]
[Thu Jul 30 12:16:37.938609 2026] [security2:error] [pid 703393:tid 703646] [client 20.104.18.253:6674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/xleet.php"] [unique_id "amuG9c637Arlr6Yb1EcQnwAAAQA"]
[Thu Jul 30 12:16:38.001357 2026] [security2:error] [pid 703393:tid 703577] [client 51.120.69.65:16351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/42.php"] [unique_id "amuG9s637Arlr6Yb1EcQoAAAALs"]
[Thu Jul 30 12:16:38.001458 2026] [security2:error] [pid 703393:tid 703577] [client 51.120.69.65:16351] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/42.php"] [unique_id "amuG9s637Arlr6Yb1EcQoAAAALs"]
[Thu Jul 30 12:16:38.522089 2026] [security2:error] [pid 703393:tid 703547] [client 20.63.98.115:20590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/user-edit.php"] [unique_id "amuG9s637Arlr6Yb1EcQpwAAAJ0"]
[Thu Jul 30 12:16:38.566601 2026] [security2:error] [pid 703393:tid 703561] [client 51.120.69.65:16328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/41.php"] [unique_id "amuG9s637Arlr6Yb1EcQqAAAAKs"]
[Thu Jul 30 12:16:38.566711 2026] [security2:error] [pid 703393:tid 703561] [client 51.120.69.65:16328] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/41.php"] [unique_id "amuG9s637Arlr6Yb1EcQqAAAAKs"]
[Thu Jul 30 12:16:38.860916 2026] [security2:error] [pid 703393:tid 703598] [client 20.104.18.253:6666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/shell1.php"] [unique_id "amuG9s637Arlr6Yb1EcQsgAAANA"]
[Thu Jul 30 12:16:38.880104 2026] [core:notice] [pid 703393:tid 703463] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:16:38.881492 2026] [security2:error] [pid 703393:tid 703590] [client 74.7.241.133:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "teknomalay.com"] [uri "/category/tutorial/"] [unique_id "amuG9s637Arlr6Yb1EcQswAAyEU"], referer: https://aleorestaurant.com/robots.txt
[Thu Jul 30 12:16:38.908759 2026] [security2:error] [pid 703393:tid 703527] [client 51.120.69.65:16322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/40.php"] [unique_id "amuG9s637Arlr6Yb1EcQtAAAAIk"]
[Thu Jul 30 12:16:38.908856 2026] [security2:error] [pid 703393:tid 703527] [client 51.120.69.65:16322] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/40.php"] [unique_id "amuG9s637Arlr6Yb1EcQtAAAAIk"]
[Thu Jul 30 12:16:39.259127 2026] [security2:error] [pid 703393:tid 703531] [client 51.120.69.65:16318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/39.php"] [unique_id "amuG98637Arlr6Yb1EcQuAAAAI0"]
[Thu Jul 30 12:16:39.259279 2026] [security2:error] [pid 703393:tid 703531] [client 51.120.69.65:16318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/39.php"] [unique_id "amuG98637Arlr6Yb1EcQuAAAAI0"]
[Thu Jul 30 12:16:39.616721 2026] [core:notice] [pid 703393:tid 703468] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:16:39.698657 2026] [security2:error] [pid 703393:tid 703623] [client 51.120.69.65:16377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/38.php"] [unique_id "amuG98637Arlr6Yb1EcQwAAAAOk"]
[Thu Jul 30 12:16:39.698759 2026] [security2:error] [pid 703393:tid 703623] [client 51.120.69.65:16377] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/38.php"] [unique_id "amuG98637Arlr6Yb1EcQwAAAAOk"]
[Thu Jul 30 12:16:39.719333 2026] [security2:error] [pid 703393:tid 703575] [client 20.104.18.253:6683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-set.php"] [unique_id "amuG98637Arlr6Yb1EcQwQAAALk"]
[Thu Jul 30 12:16:40.085777 2026] [security2:error] [pid 703393:tid 703628] [client 74.7.241.133:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "teknomalay.com"] [uri "/index.html"] [unique_id "amuG98637Arlr6Yb1EcQvwAA7ko"], referer: https://teknomalay.com/category/tutorial/
[Thu Jul 30 12:16:40.110664 2026] [security2:error] [pid 703393:tid 703639] [client 51.120.69.65:16324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/37.php"] [unique_id "amuG-M637Arlr6Yb1EcQzAAAAPk"]
[Thu Jul 30 12:16:40.110764 2026] [security2:error] [pid 703393:tid 703639] [client 51.120.69.65:16324] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/37.php"] [unique_id "amuG-M637Arlr6Yb1EcQzAAAAPk"]
[Thu Jul 30 12:16:40.451144 2026] [security2:error] [pid 703393:tid 703548] [client 51.120.69.65:15623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/36.php"] [unique_id "amuG-M637Arlr6Yb1EcQ2QAAAJ4"]
[Thu Jul 30 12:16:40.451255 2026] [security2:error] [pid 703393:tid 703548] [client 51.120.69.65:15623] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/36.php"] [unique_id "amuG-M637Arlr6Yb1EcQ2QAAAJ4"]
[Thu Jul 30 12:16:40.800872 2026] [security2:error] [pid 703393:tid 703646] [client 113.189.29.160:33770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuG-M637Arlr6Yb1EcQ2gAAAQA"], referer: http://pkf.jo
[Thu Jul 30 12:16:41.223785 2026] [security2:error] [pid 703393:tid 703617] [client 51.120.69.65:16304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/35.php"] [unique_id "amuG-c637Arlr6Yb1EcQ5wAAAOM"]
[Thu Jul 30 12:16:41.223943 2026] [security2:error] [pid 703393:tid 703617] [client 51.120.69.65:16304] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/35.php"] [unique_id "amuG-c637Arlr6Yb1EcQ5wAAAOM"]
[Thu Jul 30 12:16:41.326558 2026] [security2:error] [pid 703393:tid 703613] [client 20.63.98.115:65417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "amuG-c637Arlr6Yb1EcQ6AAAAN8"]
[Thu Jul 30 12:16:41.787489 2026] [security2:error] [pid 703393:tid 703573] [client 51.120.69.65:16311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/34.php"] [unique_id "amuG-c637Arlr6Yb1EcQ8AAAALc"]
[Thu Jul 30 12:16:41.787609 2026] [security2:error] [pid 703393:tid 703573] [client 51.120.69.65:16311] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/34.php"] [unique_id "amuG-c637Arlr6Yb1EcQ8AAAALc"]
[Thu Jul 30 12:16:42.266386 2026] [security2:error] [pid 703393:tid 703529] [client 51.120.69.65:15673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/33.php"] [unique_id "amuG-s637Arlr6Yb1EcQ-wAAAIs"]
[Thu Jul 30 12:16:42.266536 2026] [security2:error] [pid 703393:tid 703529] [client 51.120.69.65:15673] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/33.php"] [unique_id "amuG-s637Arlr6Yb1EcQ-wAAAIs"]
[Thu Jul 30 12:16:42.709332 2026] [security2:error] [pid 703393:tid 703624] [client 51.120.69.65:16383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/25.php"] [unique_id "amuG-s637Arlr6Yb1EcRBAAAAOo"]
[Thu Jul 30 12:16:42.709482 2026] [security2:error] [pid 703393:tid 703624] [client 51.120.69.65:16383] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/25.php"] [unique_id "amuG-s637Arlr6Yb1EcRBAAAAOo"]
[Thu Jul 30 12:16:42.893156 2026] [lsapi:error] [pid 703393:tid 703413] [remote 102.209.111.62:0] [host flixon.net] Error receiving response: ReceiveResponse: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1009; user ID 1009), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://flixon.net/video/captain-america-brave-new-world-vj-junior/
[Thu Jul 30 12:16:43.041838 2026] [security2:error] [pid 703393:tid 703533] [client 20.63.98.115:61389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/engine.php"] [unique_id "amuG-8637Arlr6Yb1EcRDgAAAI8"]
[Thu Jul 30 12:16:43.140177 2026] [security2:error] [pid 703393:tid 703620] [client 20.104.18.253:6676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/.well-known/makeasmtp.php"] [unique_id "amuG-8637Arlr6Yb1EcREQAAAOY"]
[Thu Jul 30 12:16:43.270566 2026] [security2:error] [pid 703393:tid 703587] [client 51.120.69.65:15657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/24.php"] [unique_id "amuG-8637Arlr6Yb1EcRGAAAAMU"]
[Thu Jul 30 12:16:43.270672 2026] [security2:error] [pid 703393:tid 703587] [client 51.120.69.65:15657] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/24.php"] [unique_id "amuG-8637Arlr6Yb1EcRGAAAAMU"]
[Thu Jul 30 12:16:43.729024 2026] [security2:error] [pid 703393:tid 703543] [client 51.120.69.65:16292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/15.php"] [unique_id "amuG-8637Arlr6Yb1EcRKQAAAJk"]
[Thu Jul 30 12:16:43.729140 2026] [security2:error] [pid 703393:tid 703543] [client 51.120.69.65:16292] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/15.php"] [unique_id "amuG-8637Arlr6Yb1EcRKQAAAJk"]
[Thu Jul 30 12:16:43.858579 2026] [security2:error] [pid 703393:tid 703581] [client 20.104.18.253:6469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/oauth.php"] [unique_id "amuG-8637Arlr6Yb1EcRKgAAAL8"]
[Thu Jul 30 12:16:43.902493 2026] [security2:error] [pid 703393:tid 703570] [client 57.141.0.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuG-8637Arlr6Yb1EcRGwAAALQ"]
[Thu Jul 30 12:16:44.150393 2026] [security2:error] [pid 703393:tid 703594] [client 20.63.98.115:20553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/edit-comments.php"] [unique_id "amuG_M637Arlr6Yb1EcRMwAAAMw"]
[Thu Jul 30 12:16:44.210032 2026] [security2:error] [pid 703393:tid 703559] [client 51.120.69.65:16326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/123456.php"] [unique_id "amuG_M637Arlr6Yb1EcRNAAAAKk"]
[Thu Jul 30 12:16:44.210150 2026] [security2:error] [pid 703393:tid 703559] [client 51.120.69.65:16326] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/123456.php"] [unique_id "amuG_M637Arlr6Yb1EcRNAAAAKk"]
[Thu Jul 30 12:16:44.663759 2026] [proxy:error] [pid 703393:tid 703640] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:16:44.663845 2026] [proxy_http:error] [pid 703393:tid 703640] [client 20.104.18.253:6525] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:16:44.664415 2026] [proxy:error] [pid 703393:tid 703640] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:16:44.664461 2026] [proxy_http:error] [pid 703393:tid 703640] [client 20.104.18.253:6525] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:16:44.695216 2026] [security2:error] [pid 703393:tid 703550] [client 51.120.69.65:16382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/12345.php"] [unique_id "amuG_M637Arlr6Yb1EcRQgAAAKA"]
[Thu Jul 30 12:16:44.695342 2026] [security2:error] [pid 703393:tid 703550] [client 51.120.69.65:16382] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/12345.php"] [unique_id "amuG_M637Arlr6Yb1EcRQgAAAKA"]
[Thu Jul 30 12:16:45.157239 2026] [security2:error] [pid 703393:tid 703532] [client 51.120.69.65:16302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/1234.php"] [unique_id "amuG_c637Arlr6Yb1EcRSwAAAI4"]
[Thu Jul 30 12:16:45.157339 2026] [security2:error] [pid 703393:tid 703532] [client 51.120.69.65:16302] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/1234.php"] [unique_id "amuG_c637Arlr6Yb1EcRSwAAAI4"]
[Thu Jul 30 12:16:45.387932 2026] [security2:error] [pid 703393:tid 703553] [client 20.104.18.253:6470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/cgi-bin/upfile.php"] [unique_id "amuG_c637Arlr6Yb1EcRUAAAAKM"]
[Thu Jul 30 12:16:45.525615 2026] [security2:error] [pid 703393:tid 703540] [client 20.63.98.115:36817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-blog-header.php"] [unique_id "amuG_c637Arlr6Yb1EcRVAAAAJY"]
[Thu Jul 30 12:16:45.753395 2026] [security2:error] [pid 703393:tid 703578] [client 51.120.69.65:16270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/10.php"] [unique_id "amuG_c637Arlr6Yb1EcRWAAAALw"]
[Thu Jul 30 12:16:45.753515 2026] [security2:error] [pid 703393:tid 703578] [client 51.120.69.65:16270] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/10.php"] [unique_id "amuG_c637Arlr6Yb1EcRWAAAALw"]
[Thu Jul 30 12:16:46.222110 2026] [security2:error] [pid 703393:tid 703561] [client 20.104.18.253:6526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/upload_file1.php"] [unique_id "amuG_s637Arlr6Yb1EcRYgAAAKs"]
[Thu Jul 30 12:16:46.244305 2026] [security2:error] [pid 703393:tid 703581] [client 51.120.69.65:16343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/9.php"] [unique_id "amuG_s637Arlr6Yb1EcRYwAAAL8"]
[Thu Jul 30 12:16:46.244402 2026] [security2:error] [pid 703393:tid 703581] [client 51.120.69.65:16343] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/9.php"] [unique_id "amuG_s637Arlr6Yb1EcRYwAAAL8"]
[Thu Jul 30 12:16:46.560655 2026] [security2:error] [pid 703393:tid 703611] [client 20.63.98.115:20831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/alfa-rex.php7"] [unique_id "amuG_s637Arlr6Yb1EcRZAAAAN0"]
[Thu Jul 30 12:16:46.798851 2026] [security2:error] [pid 703393:tid 703625] [client 51.120.69.65:15621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/8.php"] [unique_id "amuG_s637Arlr6Yb1EcRawAAAOs"]
[Thu Jul 30 12:16:46.798999 2026] [security2:error] [pid 703393:tid 703625] [client 51.120.69.65:15621] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/8.php"] [unique_id "amuG_s637Arlr6Yb1EcRawAAAOs"]
[Thu Jul 30 12:16:47.277000 2026] [security2:error] [pid 703393:tid 703546] [client 20.104.18.253:6521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/rafa.php"] [unique_id "amuG_8637Arlr6Yb1EcRcwAAAJw"]
[Thu Jul 30 12:16:47.304017 2026] [security2:error] [pid 703393:tid 703579] [client 51.120.69.65:16335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/7.php"] [unique_id "amuG_8637Arlr6Yb1EcRdAAAAL0"]
[Thu Jul 30 12:16:47.304104 2026] [security2:error] [pid 703393:tid 703579] [client 51.120.69.65:16335] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/7.php"] [unique_id "amuG_8637Arlr6Yb1EcRdAAAAL0"]
[Thu Jul 30 12:16:48.094251 2026] [security2:error] [pid 703393:tid 703557] [client 20.104.18.253:6472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/maint/src_api.php"] [unique_id "amuHAM637Arlr6Yb1EcRfQAAAKc"]
[Thu Jul 30 12:16:48.191709 2026] [security2:error] [pid 703393:tid 703564] [client 20.63.98.115:36825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/pomo/fgertreyersd.php"] [unique_id "amuHAM637Arlr6Yb1EcRgQAAAK4"]
[Thu Jul 30 12:16:48.469525 2026] [security2:error] [pid 703393:tid 703635] [client 51.120.69.65:16284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/6.php"] [unique_id "amuHAM637Arlr6Yb1EcRiQAAAPU"]
[Thu Jul 30 12:16:48.469637 2026] [security2:error] [pid 703393:tid 703635] [client 51.120.69.65:16284] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/6.php"] [unique_id "amuHAM637Arlr6Yb1EcRiQAAAPU"]
[Thu Jul 30 12:16:48.609174 2026] [core:notice] [pid 703393:tid 703624] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:16:49.175387 2026] [security2:error] [pid 703393:tid 703638] [client 51.120.69.65:16283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/5.php"] [unique_id "amuHAc637Arlr6Yb1EcRkgAAAPg"]
[Thu Jul 30 12:16:49.175531 2026] [security2:error] [pid 703393:tid 703638] [client 51.120.69.65:16283] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/5.php"] [unique_id "amuHAc637Arlr6Yb1EcRkgAAAPg"]
[Thu Jul 30 12:16:49.315581 2026] [security2:error] [pid 703393:tid 703605] [client 20.104.18.253:6519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/atomlib.php"] [unique_id "amuHAc637Arlr6Yb1EcRmQAAANc"]
[Thu Jul 30 12:16:49.399535 2026] [security2:error] [pid 703393:tid 703533] [client 20.63.98.115:21382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/css/xmrlpc.php"] [unique_id "amuHAc637Arlr6Yb1EcRmgAAAI8"]
[Thu Jul 30 12:16:49.407554 2026] [security2:error] [pid 703393:tid 703604] [client 213.152.161.118:49342] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuHAc637Arlr6Yb1EcRmwAAANY"]
[Thu Jul 30 12:16:49.407640 2026] [security2:error] [pid 703393:tid 703604] [client 213.152.161.118:49342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuHAc637Arlr6Yb1EcRmwAAANY"]
[Thu Jul 30 12:16:49.608018 2026] [core:notice] [pid 703393:tid 703644] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:16:49.736721 2026] [security2:error] [pid 703393:tid 703642] [client 51.120.69.65:16319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/4.php"] [unique_id "amuHAc637Arlr6Yb1EcRoAAAAPw"]
[Thu Jul 30 12:16:49.736812 2026] [security2:error] [pid 703393:tid 703642] [client 51.120.69.65:16319] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/4.php"] [unique_id "amuHAc637Arlr6Yb1EcRoAAAAPw"]
[Thu Jul 30 12:16:50.240115 2026] [security2:error] [pid 703393:tid 703591] [client 51.120.69.65:16331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/3.php"] [unique_id "amuHAs637Arlr6Yb1EcRqAAAAMk"]
[Thu Jul 30 12:16:50.240225 2026] [security2:error] [pid 703393:tid 703591] [client 51.120.69.65:16331] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/3.php"] [unique_id "amuHAs637Arlr6Yb1EcRqAAAAMk"]
[Thu Jul 30 12:16:50.365457 2026] [security2:error] [pid 703393:tid 703558] [client 20.63.98.115:61421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/classsmtps.php"] [unique_id "amuHAs637Arlr6Yb1EcRsgAAAKg"]
[Thu Jul 30 12:16:50.727779 2026] [security2:error] [pid 703393:tid 703576] [client 20.104.18.253:6667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-trackback.php"] [unique_id "amuHAs637Arlr6Yb1EcRtQAAALo"]
[Thu Jul 30 12:16:50.742994 2026] [security2:error] [pid 703393:tid 703630] [client 51.120.69.65:16263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/2.php"] [unique_id "amuHAs637Arlr6Yb1EcRtgAAAPA"]
[Thu Jul 30 12:16:50.743109 2026] [security2:error] [pid 703393:tid 703630] [client 51.120.69.65:16263] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/2.php"] [unique_id "amuHAs637Arlr6Yb1EcRtgAAAPA"]
[Thu Jul 30 12:16:50.881377 2026] [security2:error] [pid 703393:tid 703525] [client 168.144.252.192:61999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.252.144.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.emj.gpl.temporary.site"] [uri "/wp-login.php"] [unique_id "amuHAs637Arlr6Yb1EcRvgAAAIc"], referer: https://www.bing.com/
[Thu Jul 30 12:16:51.046990 2026] [security2:error] [pid 703393:tid 703549] [client 103.76.148.17:4759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuHAs637Arlr6Yb1EcRtwAAAJ8"], referer: http://pkf.jo
[Thu Jul 30 12:16:51.234071 2026] [security2:error] [pid 703393:tid 703619] [client 51.120.69.65:16330] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.guardian-heir.com"] [uri "/1.php"] [unique_id "amuHA8637Arlr6Yb1EcRwAAAAOU"]
[Thu Jul 30 12:16:51.234196 2026] [security2:error] [pid 703393:tid 703619] [client 51.120.69.65:16330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/1.php"] [unique_id "amuHA8637Arlr6Yb1EcRwAAAAOU"]
[Thu Jul 30 12:16:51.234291 2026] [security2:error] [pid 703393:tid 703619] [client 51.120.69.65:16330] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/1.php"] [unique_id "amuHA8637Arlr6Yb1EcRwAAAAOU"]
[Thu Jul 30 12:16:51.329056 2026] [security2:error] [pid 703393:tid 703636] [client 139.47.26.50:59256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuHA8637Arlr6Yb1EcRvwAAAPY"], referer: http://pkf.jo
[Thu Jul 30 12:16:51.432216 2026] [security2:error] [pid 703393:tid 703643] [client 185.191.171.7:38628] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/04/14/semana-santa-gestores-gastam-quase-r-4-milhoes-em-peixes-e-outros-produtos-para-doacoes/"] [unique_id "amuHA8637Arlr6Yb1EcRxwAAAP0"]
[Thu Jul 30 12:16:51.432362 2026] [security2:error] [pid 703393:tid 703643] [client 185.191.171.7:38628] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/04/14/semana-santa-gestores-gastam-quase-r-4-milhoes-em-peixes-e-outros-produtos-para-doacoes/"] [unique_id "amuHA8637Arlr6Yb1EcRxwAAAP0"]
[Thu Jul 30 12:16:51.748714 2026] [security2:error] [pid 703393:tid 703528] [client 51.120.69.65:15619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/0.php"] [unique_id "amuHA8637Arlr6Yb1EcRyAAAAIo"]
[Thu Jul 30 12:16:51.748832 2026] [security2:error] [pid 703393:tid 703528] [client 51.120.69.65:15619] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/0.php"] [unique_id "amuHA8637Arlr6Yb1EcRyAAAAIo"]
[Thu Jul 30 12:16:51.753444 2026] [security2:error] [pid 703393:tid 703599] [client 20.104.18.253:6659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "amuHA8637Arlr6Yb1EcRyQAAANE"]
[Thu Jul 30 12:16:52.232572 2026] [security2:error] [pid 703393:tid 703524] [client 20.63.98.115:20801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/themes/zMousse/otuz1.php"] [unique_id "amuHBM637Arlr6Yb1EcR0AAAAIY"]
[Thu Jul 30 12:16:52.243103 2026] [security2:error] [pid 703393:tid 703605] [client 51.120.69.65:16291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/z.php"] [unique_id "amuHBM637Arlr6Yb1EcR0QAAANc"]
[Thu Jul 30 12:16:52.243272 2026] [security2:error] [pid 703393:tid 703605] [client 51.120.69.65:16291] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/z.php"] [unique_id "amuHBM637Arlr6Yb1EcR0QAAANc"]
[Thu Jul 30 12:16:52.725051 2026] [security2:error] [pid 703393:tid 703554] [client 51.120.69.65:16315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/y.php"] [unique_id "amuHBM637Arlr6Yb1EcR3gAAAKQ"]
[Thu Jul 30 12:16:52.725166 2026] [security2:error] [pid 703393:tid 703554] [client 51.120.69.65:16315] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/y.php"] [unique_id "amuHBM637Arlr6Yb1EcR3gAAAKQ"]
[Thu Jul 30 12:16:52.733006 2026] [core:notice] [pid 703393:tid 703439] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:16:52.753329 2026] [security2:error] [pid 703393:tid 703570] [client 20.104.18.253:6490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/doc.php/"] [unique_id "amuHBM637Arlr6Yb1EcR4AAAALQ"]
[Thu Jul 30 12:16:52.952636 2026] [core:notice] [pid 703393:tid 703501] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:16:52.966405 2026] [security2:error] [pid 703393:tid 703609] [client 160.191.208.12:21981] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuHBM637Arlr6Yb1EcR3QAAANs"], referer: http://pkf.jo
[Thu Jul 30 12:16:53.006441 2026] [security2:error] [pid 703393:tid 703615] [client 168.144.252.192:62441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.252.144.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.emj.gpl.temporary.site"] [uri "/wp-login.php"] [unique_id "amuHBc637Arlr6Yb1EcR6gAAAOE"]
[Thu Jul 30 12:16:53.184635 2026] [security2:error] [pid 703393:tid 703580] [client 51.120.69.65:15659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/x.php"] [unique_id "amuHBc637Arlr6Yb1EcR7gAAAL4"]
[Thu Jul 30 12:16:53.184742 2026] [security2:error] [pid 703393:tid 703580] [client 51.120.69.65:15659] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/x.php"] [unique_id "amuHBc637Arlr6Yb1EcR7gAAAL4"]
[Thu Jul 30 12:16:53.236633 2026] [security2:error] [pid 703393:tid 703418] [remote 190.92.174.21:48232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-login.php"] [unique_id "amuHBM637Arlr6Yb1EcR6AAAlRg"]
[Thu Jul 30 12:16:53.684928 2026] [security2:error] [pid 703393:tid 703535] [client 51.120.69.65:16372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/w.php"] [unique_id "amuHBc637Arlr6Yb1EcR-wAAAJE"]
[Thu Jul 30 12:16:53.685056 2026] [security2:error] [pid 703393:tid 703535] [client 51.120.69.65:16372] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/w.php"] [unique_id "amuHBc637Arlr6Yb1EcR-wAAAJE"]
[Thu Jul 30 12:16:54.172801 2026] [security2:error] [pid 703393:tid 703602] [client 51.120.69.65:16337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/v.php"] [unique_id "amuHBs637Arlr6Yb1EcSBgAAANQ"]
[Thu Jul 30 12:16:54.172919 2026] [security2:error] [pid 703393:tid 703602] [client 51.120.69.65:16337] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/v.php"] [unique_id "amuHBs637Arlr6Yb1EcSBgAAANQ"]
[Thu Jul 30 12:16:54.666489 2026] [security2:error] [pid 703393:tid 703536] [client 51.120.69.65:16379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/u.php"] [unique_id "amuHBs637Arlr6Yb1EcSFgAAAJI"]
[Thu Jul 30 12:16:54.666599 2026] [security2:error] [pid 703393:tid 703536] [client 51.120.69.65:16379] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/u.php"] [unique_id "amuHBs637Arlr6Yb1EcSFgAAAJI"]
[Thu Jul 30 12:16:55.254390 2026] [security2:error] [pid 703393:tid 703558] [client 51.120.69.65:15629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/s.php"] [unique_id "amuHB8637Arlr6Yb1EcSKgAAAKg"]
[Thu Jul 30 12:16:55.254532 2026] [security2:error] [pid 703393:tid 703558] [client 51.120.69.65:15629] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/s.php"] [unique_id "amuHB8637Arlr6Yb1EcSKgAAAKg"]
[Thu Jul 30 12:16:55.401734 2026] [core:notice] [pid 703393:tid 703454] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:16:55.881830 2026] [security2:error] [pid 703393:tid 703557] [client 20.104.18.253:6486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/error_exception.php"] [unique_id "amuHB8637Arlr6Yb1EcSNQAAAKc"]
[Thu Jul 30 12:16:56.016942 2026] [core:error] [pid 703393:tid 703564] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:16:56.016967 2026] [core:error] [pid 703393:tid 703564] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:16:56.099765 2026] [core:notice] [pid 703393:tid 703529] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:16:56.119285 2026] [security2:error] [pid 703393:tid 703636] [client 51.120.69.65:16354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/t.php"] [unique_id "amuHCM637Arlr6Yb1EcSPgAAAPY"]
[Thu Jul 30 12:16:56.119372 2026] [security2:error] [pid 703393:tid 703636] [client 51.120.69.65:16354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/t.php"] [unique_id "amuHCM637Arlr6Yb1EcSPgAAAPY"]
[Thu Jul 30 12:16:56.618152 2026] [security2:error] [pid 703393:tid 703649] [client 51.120.69.65:16259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/r.php"] [unique_id "amuHCM637Arlr6Yb1EcSRQAAAQM"]
[Thu Jul 30 12:16:56.618257 2026] [security2:error] [pid 703393:tid 703649] [client 51.120.69.65:16259] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/r.php"] [unique_id "amuHCM637Arlr6Yb1EcSRQAAAQM"]
[Thu Jul 30 12:16:56.669283 2026] [security2:error] [pid 703393:tid 703643] [client 20.104.18.253:6481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/infos.php"] [unique_id "amuHCM637Arlr6Yb1EcSRwAAAP0"]
[Thu Jul 30 12:16:57.233024 2026] [security2:error] [pid 703393:tid 703548] [client 20.63.98.115:20584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/123.php"] [unique_id "amuHCc637Arlr6Yb1EcSUgAAAJ4"]
[Thu Jul 30 12:16:57.280237 2026] [security2:error] [pid 703393:tid 703531] [client 51.120.69.65:16256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/q.php"] [unique_id "amuHCc637Arlr6Yb1EcSWAAAAI0"]
[Thu Jul 30 12:16:57.280370 2026] [security2:error] [pid 703393:tid 703531] [client 51.120.69.65:16256] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/q.php"] [unique_id "amuHCc637Arlr6Yb1EcSWAAAAI0"]
[Thu Jul 30 12:16:57.791260 2026] [core:notice] [pid 703393:tid 703468] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:16:57.830582 2026] [security2:error] [pid 703393:tid 703550] [client 51.120.69.65:16381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/p.php"] [unique_id "amuHCc637Arlr6Yb1EcSaAAAAKA"]
[Thu Jul 30 12:16:57.830721 2026] [security2:error] [pid 703393:tid 703550] [client 51.120.69.65:16381] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/p.php"] [unique_id "amuHCc637Arlr6Yb1EcSaAAAAKA"]
[Thu Jul 30 12:16:58.473515 2026] [security2:error] [pid 703393:tid 703582] [client 51.120.69.65:16290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/n.php"] [unique_id "amuHCs637Arlr6Yb1EcSeAAAAMA"]
[Thu Jul 30 12:16:58.473636 2026] [security2:error] [pid 703393:tid 703582] [client 51.120.69.65:16290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/n.php"] [unique_id "amuHCs637Arlr6Yb1EcSeAAAAMA"]
[Thu Jul 30 12:16:58.489802 2026] [security2:error] [pid 703393:tid 703627] [client 20.63.98.115:21427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "amuHCs637Arlr6Yb1EcSeQAAAO0"]
[Thu Jul 30 12:16:58.719850 2026] [security2:error] [pid 703393:tid 703543] [client 20.104.18.253:6465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/contact.php"] [unique_id "amuHCs637Arlr6Yb1EcSfQAAAJk"]
[Thu Jul 30 12:16:58.983641 2026] [security2:error] [pid 703393:tid 703567] [client 51.120.69.65:16347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/o.php"] [unique_id "amuHCs637Arlr6Yb1EcSjgAAALE"]
[Thu Jul 30 12:16:58.983763 2026] [security2:error] [pid 703393:tid 703567] [client 51.120.69.65:16347] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/o.php"] [unique_id "amuHCs637Arlr6Yb1EcSjgAAALE"]
[Thu Jul 30 12:16:59.445623 2026] [security2:error] [pid 703393:tid 703554] [client 51.120.69.65:15713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/m.php"] [unique_id "amuHC8637Arlr6Yb1EcSlgAAAKQ"]
[Thu Jul 30 12:16:59.445709 2026] [security2:error] [pid 703393:tid 703554] [client 51.120.69.65:15713] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/m.php"] [unique_id "amuHC8637Arlr6Yb1EcSlgAAAKQ"]
[Thu Jul 30 12:16:59.506303 2026] [proxy:error] [pid 703393:tid 703614] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:16:59.506382 2026] [proxy_http:error] [pid 703393:tid 703614] [client 20.104.18.253:6493] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:16:59.506945 2026] [proxy:error] [pid 703393:tid 703614] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:16:59.507010 2026] [proxy_http:error] [pid 703393:tid 703614] [client 20.104.18.253:6493] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:16:59.566135 2026] [security2:error] [pid 703393:tid 703551] [client 2a03:2880:f800:1a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuHCs637Arlr6Yb1EcSigAAoQ4"]
[Thu Jul 30 12:16:59.992084 2026] [security2:error] [pid 703393:tid 703621] [client 51.120.69.65:16294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/l.php"] [unique_id "amuHC8637Arlr6Yb1EcSqQAAAOc"]
[Thu Jul 30 12:16:59.992195 2026] [security2:error] [pid 703393:tid 703621] [client 51.120.69.65:16294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/l.php"] [unique_id "amuHC8637Arlr6Yb1EcSqQAAAOc"]
[Thu Jul 30 12:17:00.124636 2026] [security2:error] [pid 703393:tid 703582] [client 168.144.252.192:64237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.252.144.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.remoteworksit.com"] [uri "/wp-login.php"] [unique_id "amuHDM637Arlr6Yb1EcSrAAAAMA"], referer: https://wordpress.org/
[Thu Jul 30 12:17:00.270607 2026] [security2:error] [pid 703393:tid 703611] [client 20.63.98.115:20575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/filebrowser.php"] [unique_id "amuHDM637Arlr6Yb1EcStgAAAN0"]
[Thu Jul 30 12:17:00.341848 2026] [security2:error] [pid 703393:tid 703643] [client 20.104.18.253:6474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/user.php"] [unique_id "amuHDM637Arlr6Yb1EcSuQAAAP0"]
[Thu Jul 30 12:17:00.488773 2026] [security2:error] [pid 703393:tid 703495] [remote 57.141.0.11:24360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/4627290655/feed/rss2/"] [unique_id "amuHDM637Arlr6Yb1EcSwgAAvGU"]
[Thu Jul 30 12:17:00.709565 2026] [security2:error] [pid 703393:tid 703537] [client 51.120.69.65:15680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/k.php"] [unique_id "amuHDM637Arlr6Yb1EcS0AAAAJM"]
[Thu Jul 30 12:17:00.709704 2026] [security2:error] [pid 703393:tid 703537] [client 51.120.69.65:15680] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/k.php"] [unique_id "amuHDM637Arlr6Yb1EcS0AAAAJM"]
[Thu Jul 30 12:17:01.138588 2026] [security2:error] [pid 703393:tid 703540] [client 51.120.69.65:16374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/j.php"] [unique_id "amuHDc637Arlr6Yb1EcS4wAAAJY"]
[Thu Jul 30 12:17:01.138728 2026] [security2:error] [pid 703393:tid 703540] [client 51.120.69.65:16374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/j.php"] [unique_id "amuHDc637Arlr6Yb1EcS4wAAAJY"]
[Thu Jul 30 12:17:01.300474 2026] [security2:error] [pid 703393:tid 703588] [client 20.104.18.253:6705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/env.php"] [unique_id "amuHDc637Arlr6Yb1EcS5wAAAMY"]
[Thu Jul 30 12:17:01.716860 2026] [security2:error] [pid 703393:tid 703578] [client 51.120.69.65:15658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/i.php"] [unique_id "amuHDc637Arlr6Yb1EcTMwAAALw"]
[Thu Jul 30 12:17:01.717074 2026] [security2:error] [pid 703393:tid 703578] [client 51.120.69.65:15658] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/i.php"] [unique_id "amuHDc637Arlr6Yb1EcTMwAAALw"]
[Thu Jul 30 12:17:02.037471 2026] [security2:error] [pid 703393:tid 703633] [client 57.141.0.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuHDc637Arlr6Yb1EcS_gAAAPM"]
[Thu Jul 30 12:17:02.123482 2026] [security2:error] [pid 703393:tid 703605] [client 20.63.98.115:21503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/makeasmtp.php"] [unique_id "amuHDs637Arlr6Yb1EcTUgAAANc"]
[Thu Jul 30 12:17:02.135171 2026] [security2:error] [pid 703393:tid 703626] [client 20.104.18.253:6503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/uploads/de_fb_uploads/b.php"] [unique_id "amuHDs637Arlr6Yb1EcTUwAAAOw"]
[Thu Jul 30 12:17:02.250176 2026] [security2:error] [pid 703393:tid 703560] [client 51.120.69.65:15645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/h.php"] [unique_id "amuHDs637Arlr6Yb1EcTVQAAAKo"]
[Thu Jul 30 12:17:02.250376 2026] [security2:error] [pid 703393:tid 703560] [client 51.120.69.65:15645] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/h.php"] [unique_id "amuHDs637Arlr6Yb1EcTVQAAAKo"]
[Thu Jul 30 12:17:02.983826 2026] [security2:error] [pid 703393:tid 703591] [client 57.141.0.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuHDs637Arlr6Yb1EcTWgAAAMk"]
[Thu Jul 30 12:17:03.021140 2026] [security2:error] [pid 703393:tid 703611] [client 20.104.18.253:6495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/.well-known//index.php"] [unique_id "amuHD8637Arlr6Yb1EcTcAAAAN0"]
[Thu Jul 30 12:17:03.430579 2026] [security2:error] [pid 703393:tid 703555] [client 20.63.98.115:20816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/bypass.php"] [unique_id "amuHD8637Arlr6Yb1EcTegAAAKU"]
[Thu Jul 30 12:17:03.499800 2026] [security2:error] [pid 703393:tid 703613] [client 51.120.69.65:16273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/g.php"] [unique_id "amuHD8637Arlr6Yb1EcTfQAAAN8"]
[Thu Jul 30 12:17:03.499914 2026] [security2:error] [pid 703393:tid 703613] [client 51.120.69.65:16273] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/g.php"] [unique_id "amuHD8637Arlr6Yb1EcTfQAAAN8"]
[Thu Jul 30 12:17:03.844885 2026] [security2:error] [pid 703393:tid 703543] [client 58.69.103.164:43632] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.remoteworksit.com"] [uri "/wp-comments-post.php"] [unique_id "amuHD8637Arlr6Yb1EcTeQAAAJk"]
[Thu Jul 30 12:17:03.979183 2026] [security2:error] [pid 703393:tid 703552] [client 20.104.18.253:6511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/blog/wp-content/plugins/ubh/up.php"] [unique_id "amuHD8637Arlr6Yb1EcThgAAAKI"]
[Thu Jul 30 12:17:04.001091 2026] [security2:error] [pid 703393:tid 703543] [client 58.69.103.164:43632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "www.remoteworksit.com"] [uri "/wp-comments-post.php"] [unique_id "amuHD8637Arlr6Yb1EcTeQAAAJk"]
[Thu Jul 30 12:17:04.039946 2026] [security2:error] [pid 703393:tid 703612] [client 51.120.69.65:16314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/f.php"] [unique_id "amuHEM637Arlr6Yb1EcThwAAAN4"]
[Thu Jul 30 12:17:04.040071 2026] [security2:error] [pid 703393:tid 703612] [client 51.120.69.65:16314] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/f.php"] [unique_id "amuHEM637Arlr6Yb1EcThwAAAN4"]
[Thu Jul 30 12:17:04.521455 2026] [security2:error] [pid 703393:tid 703582] [client 51.120.69.65:16332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/e.php"] [unique_id "amuHEM637Arlr6Yb1EcTjwAAAMA"]
[Thu Jul 30 12:17:04.521569 2026] [security2:error] [pid 703393:tid 703582] [client 51.120.69.65:16332] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/e.php"] [unique_id "amuHEM637Arlr6Yb1EcTjwAAAMA"]
[Thu Jul 30 12:17:04.906377 2026] [security2:error] [pid 703393:tid 703638] [client 51.120.69.65:15721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/d.php"] [unique_id "amuHEM637Arlr6Yb1EcTmgAAAPg"]
[Thu Jul 30 12:17:04.906517 2026] [security2:error] [pid 703393:tid 703638] [client 51.120.69.65:15721] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/d.php"] [unique_id "amuHEM637Arlr6Yb1EcTmgAAAPg"]
[Thu Jul 30 12:17:05.148532 2026] [security2:error] [pid 703393:tid 703583] [client 20.104.18.253:6665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/edit.php"] [unique_id "amuHEc637Arlr6Yb1EcTmwAAAME"]
[Thu Jul 30 12:17:05.251420 2026] [core:notice] [pid 703393:tid 703526] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:17:05.473434 2026] [security2:error] [pid 703393:tid 703644] [client 51.120.69.65:16309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/c.php"] [unique_id "amuHEc637Arlr6Yb1EcTpgAAAP4"]
[Thu Jul 30 12:17:05.473536 2026] [security2:error] [pid 703393:tid 703644] [client 51.120.69.65:16309] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/c.php"] [unique_id "amuHEc637Arlr6Yb1EcTpgAAAP4"]
[Thu Jul 30 12:17:05.945172 2026] [proxy:error] [pid 703393:tid 703539] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:05.945254 2026] [proxy_http:error] [pid 703393:tid 703539] [client 20.104.18.253:6477] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:05.945806 2026] [proxy:error] [pid 703393:tid 703539] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:05.945848 2026] [proxy_http:error] [pid 703393:tid 703539] [client 20.104.18.253:6477] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:06.289310 2026] [security2:error] [pid 703393:tid 703626] [client 51.120.69.65:16271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/b.php"] [unique_id "amuHEs637Arlr6Yb1EcTtQAAAOw"]
[Thu Jul 30 12:17:06.289413 2026] [security2:error] [pid 703393:tid 703626] [client 51.120.69.65:16271] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/b.php"] [unique_id "amuHEs637Arlr6Yb1EcTtQAAAOw"]
[Thu Jul 30 12:17:06.710468 2026] [security2:error] [pid 703393:tid 703587] [client 20.104.18.253:6510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/locks.php"] [unique_id "amuHEs637Arlr6Yb1EcTvgAAAMU"]
[Thu Jul 30 12:17:06.711437 2026] [security2:error] [pid 703393:tid 703565] [client 20.63.98.115:21499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/pi.php"] [unique_id "amuHEs637Arlr6Yb1EcTvwAAAK8"]
[Thu Jul 30 12:17:06.751253 2026] [security2:error] [pid 703393:tid 703478] [remote 144.79.133.30:52248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.133.79.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ahm.djb.temporary.site"] [uri "/wp-login.php"] [unique_id "amuHEs637Arlr6Yb1EcTwAAA5lQ"]
[Thu Jul 30 12:17:06.783811 2026] [security2:error] [pid 703393:tid 703582] [client 51.120.69.65:15665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/indexc.php"] [unique_id "amuHEs637Arlr6Yb1EcTxAAAAMA"]
[Thu Jul 30 12:17:06.783913 2026] [security2:error] [pid 703393:tid 703582] [client 51.120.69.65:15665] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/indexc.php"] [unique_id "amuHEs637Arlr6Yb1EcTxAAAAMA"]
[Thu Jul 30 12:17:07.328096 2026] [security2:error] [pid 703393:tid 703634] [client 51.120.69.65:16301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/147w3sdtB9D.php"] [unique_id "amuHE8637Arlr6Yb1EcTzwAAAPQ"]
[Thu Jul 30 12:17:07.328197 2026] [security2:error] [pid 703393:tid 703634] [client 51.120.69.65:16301] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/147w3sdtB9D.php"] [unique_id "amuHE8637Arlr6Yb1EcTzwAAAPQ"]
[Thu Jul 30 12:17:07.583109 2026] [security2:error] [pid 703393:tid 703638] [client 20.104.18.253:6478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/alfa-rex1.php"] [unique_id "amuHE8637Arlr6Yb1EcT1wAAAPg"]
[Thu Jul 30 12:17:07.726034 2026] [security2:error] [pid 703393:tid 703580] [client 51.120.69.65:16355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/12htKbyVOUv.php"] [unique_id "amuHE8637Arlr6Yb1EcT2AAAAL4"]
[Thu Jul 30 12:17:07.726173 2026] [security2:error] [pid 703393:tid 703580] [client 51.120.69.65:16355] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/12htKbyVOUv.php"] [unique_id "amuHE8637Arlr6Yb1EcT2AAAAL4"]
[Thu Jul 30 12:17:08.257401 2026] [security2:error] [pid 703393:tid 703576] [client 51.120.69.65:16329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/0PeeTQW2sZ.php"] [unique_id "amuHFM637Arlr6Yb1EcT3QAAALo"]
[Thu Jul 30 12:17:08.257518 2026] [security2:error] [pid 703393:tid 703576] [client 51.120.69.65:16329] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/0PeeTQW2sZ.php"] [unique_id "amuHFM637Arlr6Yb1EcT3QAAALo"]
[Thu Jul 30 12:17:08.348523 2026] [security2:error] [pid 703393:tid 703550] [client 20.104.18.253:6514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/uploads/gfwisone.php"] [unique_id "amuHFM637Arlr6Yb1EcT4AAAAKA"]
[Thu Jul 30 12:17:08.936699 2026] [security2:error] [pid 703393:tid 703551] [client 51.120.69.65:16316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/.561988674612251.php"] [unique_id "amuHFM637Arlr6Yb1EcT6AAAAKE"]
[Thu Jul 30 12:17:08.936830 2026] [security2:error] [pid 703393:tid 703551] [client 51.120.69.65:16316] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/.561988674612251.php"] [unique_id "amuHFM637Arlr6Yb1EcT6AAAAKE"]
[Thu Jul 30 12:17:09.152545 2026] [security2:error] [pid 703393:tid 703626] [client 20.104.18.253:6803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/rex/l/flower.php"] [unique_id "amuHFc637Arlr6Yb1EcT7QAAAOw"]
[Thu Jul 30 12:17:09.771756 2026] [security2:error] [pid 703393:tid 703618] [client 51.120.69.65:15701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/indexw.php"] [unique_id "amuHFc637Arlr6Yb1EcT_QAAAOQ"]
[Thu Jul 30 12:17:09.771903 2026] [security2:error] [pid 703393:tid 703618] [client 51.120.69.65:15701] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/indexw.php"] [unique_id "amuHFc637Arlr6Yb1EcT_QAAAOQ"]
[Thu Jul 30 12:17:10.141477 2026] [proxy:error] [pid 703393:tid 703535] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:10.141565 2026] [proxy_http:error] [pid 703393:tid 703535] [client 20.104.18.253:6669] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:10.142128 2026] [proxy:error] [pid 703393:tid 703535] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:10.142172 2026] [proxy_http:error] [pid 703393:tid 703535] [client 20.104.18.253:6669] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:10.440942 2026] [security2:error] [pid 703393:tid 703622] [client 51.120.69.65:16368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/.284214373991941.php"] [unique_id "amuHFs637Arlr6Yb1EcUBgAAAOg"]
[Thu Jul 30 12:17:10.441072 2026] [security2:error] [pid 703393:tid 703622] [client 51.120.69.65:16368] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/.284214373991941.php"] [unique_id "amuHFs637Arlr6Yb1EcUBgAAAOg"]
[Thu Jul 30 12:17:10.608604 2026] [security2:error] [pid 703393:tid 703530] [client 20.63.98.115:21497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-seo.php"] [unique_id "amuHFs637Arlr6Yb1EcUDQAAAIw"]
[Thu Jul 30 12:17:11.227136 2026] [proxy:error] [pid 703393:tid 703632] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:11.227224 2026] [proxy_http:error] [pid 703393:tid 703632] [client 20.104.18.253:6691] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:11.227787 2026] [proxy:error] [pid 703393:tid 703632] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:11.227830 2026] [proxy_http:error] [pid 703393:tid 703632] [client 20.104.18.253:6691] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:11.365837 2026] [security2:error] [pid 703393:tid 703539] [client 51.120.69.65:15651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/.109753674214724.php"] [unique_id "amuHF8637Arlr6Yb1EcUFQAAAJU"]
[Thu Jul 30 12:17:11.366011 2026] [security2:error] [pid 703393:tid 703539] [client 51.120.69.65:15651] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/.109753674214724.php"] [unique_id "amuHF8637Arlr6Yb1EcUFQAAAJU"]
[Thu Jul 30 12:17:11.546485 2026] [security2:error] [pid 703393:tid 703538] [client 20.63.98.115:21471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/gebase.php69"] [unique_id "amuHF8637Arlr6Yb1EcUGgAAAJQ"]
[Thu Jul 30 12:17:11.931199 2026] [security2:error] [pid 703393:tid 703552] [client 51.120.69.65:14020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/kjihe.php"] [unique_id "amuHF8637Arlr6Yb1EcUHgAAAKI"]
[Thu Jul 30 12:17:11.931307 2026] [security2:error] [pid 703393:tid 703552] [client 51.120.69.65:14020] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/kjihe.php"] [unique_id "amuHF8637Arlr6Yb1EcUHgAAAKI"]
[Thu Jul 30 12:17:12.048758 2026] [security2:error] [pid 703393:tid 703599] [client 20.104.18.253:6500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/user/post.php"] [unique_id "amuHGM637Arlr6Yb1EcUIgAAANE"]
[Thu Jul 30 12:17:12.563923 2026] [security2:error] [pid 703393:tid 703616] [client 51.120.69.65:15630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/Uploading.php"] [unique_id "amuHGM637Arlr6Yb1EcUKgAAAOI"]
[Thu Jul 30 12:17:12.564051 2026] [security2:error] [pid 703393:tid 703616] [client 51.120.69.65:15630] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/Uploading.php"] [unique_id "amuHGM637Arlr6Yb1EcUKgAAAOI"]
[Thu Jul 30 12:17:13.557747 2026] [security2:error] [pid 703393:tid 703618] [client 50.6.43.217:47026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuHGM637Arlr6Yb1EcUNwAAAOQ"]
[Thu Jul 30 12:17:13.604826 2026] [security2:error] [pid 703393:tid 703584] [client 20.63.98.115:58080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/config.php"] [unique_id "amuHGc637Arlr6Yb1EcURAAAAMI"]
[Thu Jul 30 12:17:13.638686 2026] [proxy:error] [pid 703393:tid 703559] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:13.638753 2026] [proxy_http:error] [pid 703393:tid 703559] [client 20.104.18.253:6494] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:13.639496 2026] [proxy:error] [pid 703393:tid 703559] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:13.639547 2026] [proxy_http:error] [pid 703393:tid 703559] [client 20.104.18.253:6494] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:13.802339 2026] [security2:error] [pid 703393:tid 703576] [client 184.75.223.195:33100] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuHGc637Arlr6Yb1EcUTgAAALo"]
[Thu Jul 30 12:17:13.802448 2026] [security2:error] [pid 703393:tid 703576] [client 184.75.223.195:33100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuHGc637Arlr6Yb1EcUTgAAALo"]
[Thu Jul 30 12:17:14.308422 2026] [security2:error] [pid 703393:tid 703594] [client 50.6.43.217:47068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuHGc637Arlr6Yb1EcUQAAAAMw"]
[Thu Jul 30 12:17:14.475832 2026] [security2:error] [pid 703393:tid 703597] [client 74.7.244.25:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "owz.nyx.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuHGs637Arlr6Yb1EcUZQAAAM8"]
[Thu Jul 30 12:17:14.476581 2026] [security2:error] [pid 703393:tid 703602] [client 74.7.244.25:59308] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "owz.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuHGs637Arlr6Yb1EcUYwAA1E4"]
[Thu Jul 30 12:17:14.670424 2026] [security2:error] [pid 703393:tid 703571] [client 209.35.163.56:55557] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "hris.rgserve.ph"] [uri "/login.php"] [unique_id "amuHGs637Arlr6Yb1EcUbwAAtQs"]
[Thu Jul 30 12:17:14.711616 2026] [security2:error] [pid 703393:tid 703563] [client 20.63.98.115:20551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/ws.php"] [unique_id "amuHGs637Arlr6Yb1EcUcwAAAK0"]
[Thu Jul 30 12:17:14.927085 2026] [security2:error] [pid 703393:tid 703645] [client 20.104.18.253:6523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/file5.php"] [unique_id "amuHGs637Arlr6Yb1EcUfgAAAP8"]
[Thu Jul 30 12:17:15.098283 2026] [security2:error] [pid 703393:tid 703490] [remote 40.77.167.55:63183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/agro_sintesa/article/view/2911/1555"] [unique_id "amuHG8637Arlr6Yb1EcUgQAAwmA"]
[Thu Jul 30 12:17:15.166455 2026] [proxy:error] [pid 703393:tid 703511] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:15.166519 2026] [proxy_http:error] [pid 703393:tid 703511] [remote 74.7.244.12:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:15.167103 2026] [proxy:error] [pid 703393:tid 703511] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:15.167152 2026] [proxy_http:error] [pid 703393:tid 703511] [remote 74.7.244.12:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:15.398413 2026] [security2:error] [pid 703393:tid 703635] [client 74.7.244.42:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.vietnambitcoin.app"] [uri "/index.php"] [unique_id "amuHGs637Arlr6Yb1EcUawAAAPU"]
[Thu Jul 30 12:17:15.399190 2026] [security2:error] [pid 703393:tid 703649] [client 74.7.244.42:44034] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.vietnambitcoin.app"] [uri "/robots.txt"] [unique_id "amuHGs637Arlr6Yb1EcUaQABAzI"]
[Thu Jul 30 12:17:15.639892 2026] [security2:error] [pid 703393:tid 703548] [client 74.7.241.155:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.kool-shop.com"] [uri "/index.php"] [unique_id "amuHGs637Arlr6Yb1EcUeQAAAJ4"]
[Thu Jul 30 12:17:15.640625 2026] [security2:error] [pid 703393:tid 703615] [client 74.7.241.155:36894] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.kool-shop.com"] [uri "/robots.txt"] [unique_id "amuHGs637Arlr6Yb1EcUdwAA4RQ"]
[Thu Jul 30 12:17:16.245915 2026] [security2:error] [pid 703393:tid 703533] [client 20.63.98.115:20604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/admin/function.php"] [unique_id "amuHHM637Arlr6Yb1EcUogAAAI8"]
[Thu Jul 30 12:17:16.824206 2026] [proxy:error] [pid 703393:tid 703626] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:16.824293 2026] [proxy_http:error] [pid 703393:tid 703626] [client 20.104.18.253:6479] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:16.824851 2026] [proxy:error] [pid 703393:tid 703626] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:16.824894 2026] [proxy_http:error] [pid 703393:tid 703626] [client 20.104.18.253:6479] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:17.825735 2026] [proxy:error] [pid 703393:tid 703638] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:17.825821 2026] [proxy_http:error] [pid 703393:tid 703638] [client 20.104.18.253:6476] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:17.826419 2026] [proxy:error] [pid 703393:tid 703638] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:17.826467 2026] [proxy_http:error] [pid 703393:tid 703638] [client 20.104.18.253:6476] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:17.961324 2026] [security2:error] [pid 703393:tid 703579] [client 195.113.175.167:5449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.175.113.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/index.php"] [unique_id "amuHHc637Arlr6Yb1EcUtAAAAL0"]
[Thu Jul 30 12:17:18.135959 2026] [security2:error] [pid 703393:tid 703531] [client 57.141.0.29:26336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuHHc637Arlr6Yb1EcUtgAAjTM"], referer: https://igetvape-australia.com/store/?product-page=1&add-to-cart=108
[Thu Jul 30 12:17:18.651253 2026] [proxy:error] [pid 703393:tid 703633] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:18.651351 2026] [proxy_http:error] [pid 703393:tid 703633] [client 20.104.18.253:6706] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:18.651895 2026] [proxy:error] [pid 703393:tid 703633] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:18.651938 2026] [proxy_http:error] [pid 703393:tid 703633] [client 20.104.18.253:6706] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:19.207630 2026] [core:notice] [pid 703393:tid 703590] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:17:19.481434 2026] [security2:error] [pid 703393:tid 703634] [client 20.104.18.253:6695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/query-standard-post.php"] [unique_id "amuHH8637Arlr6Yb1EcU5AAAAPQ"]
[Thu Jul 30 12:17:19.613244 2026] [security2:error] [pid 703393:tid 703547] [client 68.235.38.2:59194] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuHH8637Arlr6Yb1EcU5QAAAJ0"]
[Thu Jul 30 12:17:19.613371 2026] [security2:error] [pid 703393:tid 703547] [client 68.235.38.2:59194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuHH8637Arlr6Yb1EcU5QAAAJ0"]
[Thu Jul 30 12:17:20.114004 2026] [core:notice] [pid 703393:tid 703491] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:17:20.294957 2026] [security2:error] [pid 703393:tid 703565] [client 5.161.117.52:1442] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuHHs637Arlr6Yb1EcU1wAAAK8"], referer: https://globalmarks.pk/
[Thu Jul 30 12:17:20.414245 2026] [security2:error] [pid 703393:tid 703600] [client 20.104.18.253:6719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/images/include.php"] [unique_id "amuHIM637Arlr6Yb1EcVAAAAANI"]
[Thu Jul 30 12:17:20.775922 2026] [security2:error] [pid 703393:tid 703539] [client 77.83.36.161:1869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/index.php"] [unique_id "amuHIM637Arlr6Yb1EcVAQAAAJU"]
[Thu Jul 30 12:17:20.808594 2026] [core:notice] [pid 703393:tid 703435] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:17:21.331610 2026] [security2:error] [pid 703393:tid 703617] [client 77.83.36.161:2379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/index.php"] [unique_id "amuHIc637Arlr6Yb1EcVCgAAAOM"]
[Thu Jul 30 12:17:21.673902 2026] [security2:error] [pid 703393:tid 703618] [client 20.63.98.115:58088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/Requests/chosen.php"] [unique_id "amuHIc637Arlr6Yb1EcVEQAAAOQ"]
[Thu Jul 30 12:17:21.880625 2026] [security2:error] [pid 703393:tid 703554] [client 20.104.18.253:6527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/--wp-lgj.php"] [unique_id "amuHIc637Arlr6Yb1EcVFQAAAKQ"]
[Thu Jul 30 12:17:21.894559 2026] [security2:error] [pid 703393:tid 703584] [client 77.83.36.161:2710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/index.php"] [unique_id "amuHIc637Arlr6Yb1EcVFgAAAMI"]
[Thu Jul 30 12:17:21.931599 2026] [security2:error] [pid 703393:tid 703467] [remote 74.7.241.59:50424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuHIc637Arlr6Yb1EcVFwAAx0k"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/premium-addons-for-elementor/modules/woocommerce/templates
[Thu Jul 30 12:17:22.541513 2026] [security2:error] [pid 703393:tid 703614] [client 20.63.98.115:43925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/themes/about.php"] [unique_id "amuHIs637Arlr6Yb1EcVIQAAAOA"]
[Thu Jul 30 12:17:22.676516 2026] [security2:error] [pid 703393:tid 703538] [client 20.104.18.253:6671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-p.php"] [unique_id "amuHIs637Arlr6Yb1EcVJQAAAJQ"]
[Thu Jul 30 12:17:23.482281 2026] [proxy:error] [pid 703393:tid 703528] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:23.482379 2026] [proxy_http:error] [pid 703393:tid 703528] [client 20.104.18.253:6466] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:23.482933 2026] [proxy:error] [pid 703393:tid 703528] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:23.482990 2026] [proxy_http:error] [pid 703393:tid 703528] [client 20.104.18.253:6466] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:23.495743 2026] [security2:error] [pid 703393:tid 703587] [client 20.63.98.115:58066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/pomo/about.php"] [unique_id "amuHI8637Arlr6Yb1EcVMgAAAMU"]
[Thu Jul 30 12:17:23.777288 2026] [security2:error] [pid 703393:tid 703488] [remote 74.7.241.60:36938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/content/article.php"] [unique_id "amuHI8637Arlr6Yb1EcVNgAAoV4"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/content/1784123347_ed%20inclusive.jpg
[Thu Jul 30 12:17:23.864734 2026] [autoindex:error] [pid 703393:tid 703573] [client 43.166.226.57:33622] AH01276: Cannot serve directory /home2/evmudite/public_html/wp/wp-content/plugins/wp-google-map-plugin/assets/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:17:24.348931 2026] [security2:error] [pid 703393:tid 703639] [client 20.104.18.253:6517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/css/colors/ectoplasm/flower.php"] [unique_id "amuHJM637Arlr6Yb1EcVQgAAAPk"]
[Thu Jul 30 12:17:24.934321 2026] [security2:error] [pid 703393:tid 703627] [client 177.230.27.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shop-kent.com"] [uri "/index.php"] [unique_id "amuHJM637Arlr6Yb1EcVPgAAAO0"]
[Thu Jul 30 12:17:25.085644 2026] [security2:error] [pid 703393:tid 703640] [client 20.63.98.115:21220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/uploads/2024/index.php"] [unique_id "amuHJc637Arlr6Yb1EcVVwAAAPo"]
[Thu Jul 30 12:17:25.229263 2026] [security2:error] [pid 703393:tid 703537] [client 2a03:2880:f800:36:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuHJM637Arlr6Yb1EcVSgAAkxM"]
[Thu Jul 30 12:17:25.251905 2026] [security2:error] [pid 703393:tid 703585] [client 57.141.0.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuHJM637Arlr6Yb1EcVSQAAAMM"]
[Thu Jul 30 12:17:25.385649 2026] [security2:error] [pid 703393:tid 703568] [client 20.104.18.253:6660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amuHJc637Arlr6Yb1EcVXwAAALI"]
[Thu Jul 30 12:17:25.546601 2026] [security2:error] [pid 703393:tid 703603] [client 57.141.0.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuHJM637Arlr6Yb1EcVUgAAANU"]
[Thu Jul 30 12:17:25.698761 2026] [security2:error] [pid 703393:tid 703606] [client 131.226.103.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "palmtreepools.ca"] [uri "/index.php"] [unique_id "amuHJM637Arlr6Yb1EcVRgAAANg"]
[Thu Jul 30 12:17:26.304195 2026] [security2:error] [pid 703393:tid 703591] [client 20.104.18.253:6485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/autoload_classmap.php"] [unique_id "amuHJs637Arlr6Yb1EcVbgAAAMk"]
[Thu Jul 30 12:17:27.012904 2026] [security2:error] [pid 703393:tid 703546] [client 185.191.171.19:19482] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "inmobiliariadia.com"] [uri "/robots.txt"] [unique_id "amuHJ8637Arlr6Yb1EcVewAAAJw"]
[Thu Jul 30 12:17:27.013062 2026] [security2:error] [pid 703393:tid 703546] [client 185.191.171.19:19482] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "inmobiliariadia.com"] [uri "/robots.txt"] [unique_id "amuHJ8637Arlr6Yb1EcVewAAAJw"]
[Thu Jul 30 12:17:27.028721 2026] [proxy:error] [pid 703393:tid 703576] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:27.028815 2026] [proxy_http:error] [pid 703393:tid 703576] [client 20.104.18.253:6468] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:27.029571 2026] [proxy:error] [pid 703393:tid 703576] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:27.029620 2026] [proxy_http:error] [pid 703393:tid 703576] [client 20.104.18.253:6468] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:27.896883 2026] [security2:error] [pid 703393:tid 703568] [client 85.208.96.205:41042] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "inmobiliariadia.com"] [uri "/"] [unique_id "amuHJ8637Arlr6Yb1EcViQAAALI"]
[Thu Jul 30 12:17:27.897003 2026] [security2:error] [pid 703393:tid 703568] [client 85.208.96.205:41042] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "inmobiliariadia.com"] [uri "/"] [unique_id "amuHJ8637Arlr6Yb1EcViQAAALI"]
[Thu Jul 30 12:17:27.947645 2026] [security2:error] [pid 703393:tid 703593] [client 20.63.98.115:21189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/.well-known/cong.php"] [unique_id "amuHJ8637Arlr6Yb1EcVigAAAMs"]
[Thu Jul 30 12:17:28.251454 2026] [security2:error] [pid 703393:tid 703637] [client 20.104.18.253:6506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/plugins/rxxdfx/xleet.php"] [unique_id "amuHKM637Arlr6Yb1EcVlAAAAPc"]
[Thu Jul 30 12:17:28.875684 2026] [core:notice] [pid 703393:tid 703512] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:17:28.914955 2026] [security2:error] [pid 703393:tid 703617] [client 114.119.144.15:45283] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "globalmarks.pk"] [uri "/wp-content/uploads/2021/08/Mission-icon-1.png"] [unique_id "amuHKM637Arlr6Yb1EcVowAAAOM"], referer: https://globalmarks.pk/wp-content/uploads/2021/08/Mission-icon-1.png
[Thu Jul 30 12:17:29.095149 2026] [security2:error] [pid 703393:tid 703641] [client 20.104.18.253:6522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/module.tag.idv1.php"] [unique_id "amuHKc637Arlr6Yb1EcVpQAAAPs"]
[Thu Jul 30 12:17:29.179957 2026] [security2:error] [pid 703393:tid 703587] [client 57.141.0.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuHKM637Arlr6Yb1EcVmwAAAMU"]
[Thu Jul 30 12:17:29.342197 2026] [security2:error] [pid 703393:tid 703569] [client 20.63.98.115:49226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/languages/about.php"] [unique_id "amuHKc637Arlr6Yb1EcVrQAAALM"]
[Thu Jul 30 12:17:29.418731 2026] [core:notice] [pid 703393:tid 703646] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:17:29.849937 2026] [core:notice] [pid 703393:tid 703579] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:17:29.999033 2026] [security2:error] [pid 703393:tid 703550] [client 20.104.18.253:6670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/packed.php"] [unique_id "amuHKc637Arlr6Yb1EcVvgAAAKA"]
[Thu Jul 30 12:17:30.846513 2026] [lsapi:error] [pid 703393:tid 703461] [remote 102.209.111.62:0] [host flixon.net] Error receiving response: ReceiveResponse: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1009; user ID 1009), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://flixon.net/video/wolf-man-vj-junior/
[Thu Jul 30 12:17:30.950251 2026] [security2:error] [pid 703393:tid 703608] [client 20.104.18.253:6707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/css/F0x.php"] [unique_id "amuHKs637Arlr6Yb1EcV1gAAANo"]
[Thu Jul 30 12:17:31.826409 2026] [security2:error] [pid 703393:tid 703575] [client 20.104.18.253:6825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/view.php"] [unique_id "amuHK8637Arlr6Yb1EcV5wAAALk"]
[Thu Jul 30 12:17:31.893507 2026] [core:notice] [pid 703393:tid 703597] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:17:32.380917 2026] [security2:error] [pid 703393:tid 703405] [remote 5.56.58.49:40450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.56.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upns.ca"] [uri "/wp-login.php"] [unique_id "amuHLM637Arlr6Yb1EcV9AAA9Qs"]
[Thu Jul 30 12:17:32.561871 2026] [security2:error] [pid 703393:tid 703603] [client 50.6.43.217:32490] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuHLM637Arlr6Yb1EcWAAAAANU"]
[Thu Jul 30 12:17:32.594057 2026] [security2:error] [pid 703393:tid 703625] [client 50.6.43.217:32498] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuHLM637Arlr6Yb1EcWBAAAAOs"]
[Thu Jul 30 12:17:32.789009 2026] [security2:error] [pid 703393:tid 703647] [client 20.63.98.115:49240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/edit.php"] [unique_id "amuHLM637Arlr6Yb1EcWCwAAAQE"]
[Thu Jul 30 12:17:33.333353 2026] [security2:error] [pid 703393:tid 703552] [client 20.104.18.253:6812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/blocks/site-title/index.php"] [unique_id "amuHLc637Arlr6Yb1EcWFQAAAKI"]
[Thu Jul 30 12:17:33.408822 2026] [security2:error] [pid 703393:tid 703571] [client 74.7.244.42:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-32717c4b.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuHLM637Arlr6Yb1EcWAwAAALU"]
[Thu Jul 30 12:17:33.409641 2026] [security2:error] [pid 703393:tid 703593] [client 74.7.244.42:42142] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-32717c4b.glb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuHLM637Arlr6Yb1EcWAQAAyxE"]
[Thu Jul 30 12:17:34.142947 2026] [security2:error] [pid 703393:tid 703589] [client 20.104.18.253:6491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/GOD.php"] [unique_id "amuHLs637Arlr6Yb1EcWIQAAAMc"]
[Thu Jul 30 12:17:34.783100 2026] [security2:error] [pid 703393:tid 703546] [client 213.152.161.118:56932] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuHLs637Arlr6Yb1EcWKgAAAJw"]
[Thu Jul 30 12:17:34.783207 2026] [security2:error] [pid 703393:tid 703546] [client 213.152.161.118:56932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuHLs637Arlr6Yb1EcWKgAAAJw"]
[Thu Jul 30 12:17:35.199841 2026] [security2:error] [pid 703393:tid 703629] [client 20.104.18.253:6488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "amuHL8637Arlr6Yb1EcWMQAAAO8"]
[Thu Jul 30 12:17:35.788705 2026] [security2:error] [pid 703393:tid 703540] [client 20.63.98.115:21292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/about/function.php"] [unique_id "amuHL8637Arlr6Yb1EcWPQAAAJY"]
[Thu Jul 30 12:17:35.959454 2026] [security2:error] [pid 703393:tid 703591] [client 20.104.18.253:6657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-configs.php"] [unique_id "amuHL8637Arlr6Yb1EcWQgAAAMk"]
[Thu Jul 30 12:17:36.941100 2026] [security2:error] [pid 703393:tid 703610] [client 20.104.18.253:6484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/contrjibus.php"] [unique_id "amuHMM637Arlr6Yb1EcWTwAAANw"]
[Thu Jul 30 12:17:37.054725 2026] [security2:error] [pid 703393:tid 703587] [client 20.63.98.115:43941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/simple/function.php"] [unique_id "amuHMc637Arlr6Yb1EcWUwAAAMU"]
[Thu Jul 30 12:17:37.964394 2026] [security2:error] [pid 703393:tid 703622] [client 20.63.98.115:21248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/mah/function.php"] [unique_id "amuHMc637Arlr6Yb1EcWXgAAAOg"]
[Thu Jul 30 12:17:38.045972 2026] [security2:error] [pid 703393:tid 703579] [client 20.104.18.253:6662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/contentloader1.php"] [unique_id "amuHMs637Arlr6Yb1EcWXwAAAL0"]
[Thu Jul 30 12:17:38.943597 2026] [security2:error] [pid 703393:tid 703551] [client 20.63.98.115:36866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/go.php"] [unique_id "amuHMs637Arlr6Yb1EcWbQAAAKE"]
[Thu Jul 30 12:17:38.968219 2026] [security2:error] [pid 703393:tid 703532] [client 20.104.18.253:6658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/F0x.php"] [unique_id "amuHMs637Arlr6Yb1EcWbgAAAI4"]
[Thu Jul 30 12:17:39.678550 2026] [security2:error] [pid 703393:tid 703570] [client 20.104.18.253:6675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/item.php"] [unique_id "amuHM8637Arlr6Yb1EcWewAAALQ"]
[Thu Jul 30 12:17:39.846230 2026] [security2:error] [pid 703393:tid 703524] [client 20.63.98.115:32954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/buy.php"] [unique_id "amuHM8637Arlr6Yb1EcWgAAAAIY"]
[Thu Jul 30 12:17:41.717075 2026] [security2:error] [pid 703393:tid 703607] [client 20.63.98.115:39173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/themes/astra/inc/ki1k.php"] [unique_id "amuHNc637Arlr6Yb1EcWogAAANk"]
[Thu Jul 30 12:17:42.639145 2026] [core:notice] [pid 703393:tid 703524] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:17:44.161770 2026] [core:notice] [pid 703393:tid 703565] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:17:44.406863 2026] [core:notice] [pid 703393:tid 703620] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:17:45.599877 2026] [core:notice] [pid 703393:tid 703636] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:17:45.845827 2026] [core:notice] [pid 703393:tid 703581] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:17:47.718479 2026] [security2:error] [pid 703393:tid 703650] [client 20.63.98.115:47332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wq.php7"] [unique_id "amuHO8637Arlr6Yb1EcXAQAAAQQ"]
[Thu Jul 30 12:17:50.612919 2026] [security2:error] [pid 703393:tid 703536] [client 20.91.199.21:46517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.tmb/LA.php"] [unique_id "amuHPs637Arlr6Yb1EcXKQAAAJI"]
[Thu Jul 30 12:17:51.060070 2026] [security2:error] [pid 703393:tid 703563] [client 20.63.98.115:62459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/forum.php"] [unique_id "amuHP8637Arlr6Yb1EcXMAAAAK0"]
[Thu Jul 30 12:17:51.801488 2026] [security2:error] [pid 703393:tid 703540] [client 20.91.199.21:40328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.tmb/admin.php"] [unique_id "amuHP8637Arlr6Yb1EcXQQAAAJY"]
[Thu Jul 30 12:17:51.903231 2026] [security2:error] [pid 703393:tid 703633] [client 20.63.98.115:38918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/5index.php"] [unique_id "amuHP8637Arlr6Yb1EcXQgAAAPM"]
[Thu Jul 30 12:17:52.505987 2026] [core:error] [pid 703393:tid 703523] [client 4.240.96.129:61453] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: binance.com
[Thu Jul 30 12:17:52.506011 2026] [core:error] [pid 703393:tid 703523] [client 4.240.96.129:61453] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: binance.com
[Thu Jul 30 12:17:53.471296 2026] [security2:error] [pid 703393:tid 703598] [client 20.91.199.21:32962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.tmb/class_api.php"] [unique_id "amuHQc637Arlr6Yb1EcXYgAAANA"]
[Thu Jul 30 12:17:54.240694 2026] [security2:error] [pid 703393:tid 703546] [client 20.91.199.21:34154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.tmb/cpabpkyk.php"] [unique_id "amuHQs637Arlr6Yb1EcXawAAAJw"]
[Thu Jul 30 12:17:55.110241 2026] [security2:error] [pid 703393:tid 703550] [client 20.63.98.115:47354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/cookie.php"] [unique_id "amuHQ8637Arlr6Yb1EcXegAAAKA"]
[Thu Jul 30 12:17:55.597088 2026] [security2:error] [pid 703393:tid 703417] [remote 72.167.132.114:40044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.zjp.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuHQ8637Arlr6Yb1EcXhAAA8Rc"]
[Thu Jul 30 12:17:55.804471 2026] [security2:error] [pid 703393:tid 703558] [client 20.91.199.21:32984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.tmb/wp-login.php"] [unique_id "amuHQ8637Arlr6Yb1EcXhwAAAKg"]
[Thu Jul 30 12:17:56.032152 2026] [security2:error] [pid 703393:tid 703607] [client 49.51.253.26:54416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.253.51.49.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/theme/darm_theme_basic01/page_html/company_organization.php"] [unique_id "amuHQ8637Arlr6Yb1EcXhgAAANk"]
[Thu Jul 30 12:17:56.431610 2026] [security2:error] [pid 703393:tid 703593] [client 20.91.199.21:46478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known//.well-known/owlmailer.php"] [unique_id "amuHRM637Arlr6Yb1EcXkAAAAMs"]
[Thu Jul 30 12:17:56.526716 2026] [security2:error] [pid 703393:tid 703535] [client 20.63.98.115:62408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/edit-form.php"] [unique_id "amuHRM637Arlr6Yb1EcXlgAAAJE"]
[Thu Jul 30 12:17:57.172763 2026] [security2:error] [pid 703393:tid 703527] [client 20.91.199.21:34159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/991176.php"] [unique_id "amuHRc637Arlr6Yb1EcXngAAAIk"]
[Thu Jul 30 12:17:57.571265 2026] [security2:error] [pid 703393:tid 703614] [client 185.191.171.10:51514] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/04/18/tudo-muito-magico-diz-ivete-sangalo-sobre-final-do-masked-singer/"] [unique_id "amuHRc637Arlr6Yb1EcXpQAAAOA"]
[Thu Jul 30 12:17:57.571390 2026] [security2:error] [pid 703393:tid 703614] [client 185.191.171.10:51514] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/04/18/tudo-muito-magico-diz-ivete-sangalo-sobre-final-do-masked-singer/"] [unique_id "amuHRc637Arlr6Yb1EcXpQAAAOA"]
[Thu Jul 30 12:17:58.462653 2026] [security2:error] [pid 703393:tid 703605] [client 20.63.98.115:38942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/aleXus.php"] [unique_id "amuHRs637Arlr6Yb1EcXtQAAANc"]
[Thu Jul 30 12:17:58.518340 2026] [security2:error] [pid 703393:tid 703557] [client 20.91.199.21:40381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/adminfuns.php"] [unique_id "amuHRs637Arlr6Yb1EcXtgAAAKc"]
[Thu Jul 30 12:17:58.541695 2026] [core:error] [pid 703393:tid 703611] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:17:58.541727 2026] [core:error] [pid 703393:tid 703611] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:17:58.649416 2026] [core:error] [pid 703393:tid 703637] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:17:58.649436 2026] [core:error] [pid 703393:tid 703637] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:17:58.674016 2026] [core:error] [pid 703393:tid 703533] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:17:58.674036 2026] [core:error] [pid 703393:tid 703533] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:17:58.707773 2026] [core:error] [pid 703393:tid 703619] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:17:58.707794 2026] [core:error] [pid 703393:tid 703619] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:17:58.730971 2026] [core:error] [pid 703393:tid 703569] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:17:58.731012 2026] [core:error] [pid 703393:tid 703569] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:17:59.341684 2026] [security2:error] [pid 703393:tid 703538] [client 20.63.98.115:57156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/user.php"] [unique_id "amuHR8637Arlr6Yb1EcX6AAAAJQ"]
[Thu Jul 30 12:17:59.866597 2026] [security2:error] [pid 703393:tid 703531] [client 20.91.199.21:46483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "amuHR8637Arlr6Yb1EcYBwAAAI0"]
[Thu Jul 30 12:18:00.202480 2026] [core:error] [pid 703393:tid 703583] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:18:00.202525 2026] [core:error] [pid 703393:tid 703583] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:18:00.309274 2026] [security2:error] [pid 703393:tid 703568] [client 2a03:2880:f800:16:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuHR8637Arlr6Yb1EcYAgAAsgI"]
[Thu Jul 30 12:18:00.851418 2026] [lsapi:error] [pid 703393:tid 703460] [remote 102.209.111.62:0] [host flixon.net] Error receiving response: ReceiveResponse: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1009; user ID 1009), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://flixon.net/video/about-time-vj-junior/
[Thu Jul 30 12:18:00.938416 2026] [security2:error] [pid 703393:tid 703575] [client 20.91.199.21:34123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/classsmtps.php"] [unique_id "amuHSM637Arlr6Yb1EcYNQAAALk"]
[Thu Jul 30 12:18:01.729173 2026] [security2:error] [pid 703393:tid 703613] [client 20.91.199.21:35170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "amuHSc637Arlr6Yb1EcYQAAAAN8"]
[Thu Jul 30 12:18:01.928730 2026] [security2:error] [pid 703393:tid 703622] [client 216.244.66.243:38406] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabiandubaisafari.com"] [uri "/louis-vuitton/oc2-outrigger-canoe-for-sale"] [unique_id "amuHSc637Arlr6Yb1EcYSAAAAOg"]
[Thu Jul 30 12:18:01.928890 2026] [security2:error] [pid 703393:tid 703622] [client 216.244.66.243:38406] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "arabiandubaisafari.com"] [uri "/louis-vuitton/oc2-outrigger-canoe-for-sale"] [unique_id "amuHSc637Arlr6Yb1EcYSAAAAOg"]
[Thu Jul 30 12:18:02.942231 2026] [security2:error] [pid 703393:tid 703563] [client 57.141.0.43:40058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuHSs637Arlr6Yb1EcYTwAArWg"], referer: https://igetvape-australia.com/product/alibarbar-pandora-7000-puffs-12/?add-to-cart=1016
[Thu Jul 30 12:18:03.337878 2026] [core:notice] [pid 703393:tid 703631] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:18:03.340852 2026] [core:notice] [pid 703393:tid 703542] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:18:03.345563 2026] [core:notice] [pid 703393:tid 703580] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:18:03.350148 2026] [core:notice] [pid 703393:tid 703633] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:18:03.350148 2026] [core:notice] [pid 703393:tid 703586] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:18:03.357931 2026] [core:notice] [pid 703393:tid 703578] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:18:03.378239 2026] [core:notice] [pid 703393:tid 703540] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:18:03.380627 2026] [security2:error] [pid 703393:tid 703533] [client 20.63.98.115:62448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/ab1ux1ft.php"] [unique_id "amuHS8637Arlr6Yb1EcYZwAAAI8"]
[Thu Jul 30 12:18:03.386252 2026] [core:notice] [pid 703393:tid 703587] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:18:03.449390 2026] [security2:error] [pid 703393:tid 703524] [client 20.91.199.21:34116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/doc.php"] [unique_id "amuHS8637Arlr6Yb1EcYagAAAIY"]
[Thu Jul 30 12:18:03.721727 2026] [security2:error] [pid 703393:tid 703572] [client 74.7.244.35:57974] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.pvl.djb.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuHS8637Arlr6Yb1EcYbgAAtj0"]
[Thu Jul 30 12:18:04.512030 2026] [core:notice] [pid 703393:tid 703538] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:18:06.570719 2026] [security2:error] [pid 703393:tid 703541] [client 40.77.167.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuHTM637Arlr6Yb1EcYhQAAAJc"]
[Thu Jul 30 12:18:06.829473 2026] [security2:error] [pid 703393:tid 703532] [client 20.91.199.21:32626] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuHTc637Arlr6Yb1EcYkwAAAI4"]
[Thu Jul 30 12:18:06.984594 2026] [security2:error] [pid 703393:tid 703645] [client 20.91.199.21:32626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/fond.php"] [unique_id "amuHTs637Arlr6Yb1EcYrAAAAP8"]
[Thu Jul 30 12:18:07.559033 2026] [security2:error] [pid 703393:tid 703620] [client 172.237.109.114:56849] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuHTs637Arlr6Yb1EcYrQAAAOY"]
[Thu Jul 30 12:18:07.560804 2026] [security2:error] [pid 703393:tid 703548] [client 172.237.109.114:55493] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuHTs637Arlr6Yb1EcYrgAAAJ4"]
[Thu Jul 30 12:18:07.563291 2026] [security2:error] [pid 703393:tid 703592] [client 172.237.109.114:5473] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuHTs637Arlr6Yb1EcYrwAAAMo"]
[Thu Jul 30 12:18:07.570163 2026] [security2:error] [pid 703393:tid 703546] [client 172.237.109.114:54750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuHTs637Arlr6Yb1EcYqgAAAJw"]
[Thu Jul 30 12:18:07.571575 2026] [security2:error] [pid 703393:tid 703629] [client 20.91.199.21:46473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "amuHT8637Arlr6Yb1EcYvAAAAO8"]
[Thu Jul 30 12:18:07.576108 2026] [security2:error] [pid 703393:tid 703526] [client 172.237.109.114:19855] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuHTs637Arlr6Yb1EcYqwAAAIg"]
[Thu Jul 30 12:18:07.897421 2026] [security2:error] [pid 703393:tid 703557] [client 20.63.98.115:49124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/home/function.php"] [unique_id "amuHT8637Arlr6Yb1EcYwAAAAKc"]
[Thu Jul 30 12:18:07.931053 2026] [security2:error] [pid 703393:tid 703619] [client 20.215.186.36:12550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.186.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ai-kr.com"] [uri "/coba.php"] [unique_id "amuHT8637Arlr6Yb1EcYwQAAAOU"]
[Thu Jul 30 12:18:07.931172 2026] [security2:error] [pid 703393:tid 703619] [client 20.215.186.36:12550] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.ai-kr.com"] [uri "/coba.php"] [unique_id "amuHT8637Arlr6Yb1EcYwQAAAOU"]
[Thu Jul 30 12:18:08.161547 2026] [security2:error] [pid 703393:tid 703617] [client 20.151.221.234:35105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wk/index.php"] [unique_id "amuHUM637Arlr6Yb1EcYyAAAAOM"]
[Thu Jul 30 12:18:08.242674 2026] [security2:error] [pid 703393:tid 703576] [client 20.215.186.36:12568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.186.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ai-kr.com"] [uri "/replace.php"] [unique_id "amuHUM637Arlr6Yb1EcYyQAAALo"]
[Thu Jul 30 12:18:08.242781 2026] [security2:error] [pid 703393:tid 703576] [client 20.215.186.36:12568] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.ai-kr.com"] [uri "/replace.php"] [unique_id "amuHUM637Arlr6Yb1EcYyQAAALo"]
[Thu Jul 30 12:18:08.464167 2026] [security2:error] [pid 703393:tid 703439] [remote 52.167.144.217:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/issue/view/16"] [unique_id "amuHUM637Arlr6Yb1EcY0gAA8C0"]
[Thu Jul 30 12:18:08.577940 2026] [security2:error] [pid 703393:tid 703638] [client 20.215.186.36:12436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.186.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ai-kr.com"] [uri "/echo.php"] [unique_id "amuHUM637Arlr6Yb1EcY1gAAAPg"]
[Thu Jul 30 12:18:08.578076 2026] [security2:error] [pid 703393:tid 703638] [client 20.215.186.36:12436] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.ai-kr.com"] [uri "/echo.php"] [unique_id "amuHUM637Arlr6Yb1EcY1gAAAPg"]
[Thu Jul 30 12:18:08.669040 2026] [security2:error] [pid 703393:tid 703605] [client 20.91.199.21:34471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/license.php"] [unique_id "amuHUM637Arlr6Yb1EcY2wAAANc"]
[Thu Jul 30 12:18:08.853791 2026] [security2:error] [pid 703393:tid 703580] [client 20.63.98.115:60224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-login.php"] [unique_id "amuHUM637Arlr6Yb1EcY1wAAAL4"]
[Thu Jul 30 12:18:08.917266 2026] [security2:error] [pid 703393:tid 703614] [client 20.215.186.36:12580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.186.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ai-kr.com"] [uri "/haxor.php"] [unique_id "amuHUM637Arlr6Yb1EcY3QAAAOA"]
[Thu Jul 30 12:18:08.917383 2026] [security2:error] [pid 703393:tid 703614] [client 20.215.186.36:12580] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.ai-kr.com"] [uri "/haxor.php"] [unique_id "amuHUM637Arlr6Yb1EcY3QAAAOA"]
[Thu Jul 30 12:18:09.230686 2026] [security2:error] [pid 703393:tid 703613] [client 20.215.186.36:12421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.186.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ai-kr.com"] [uri "/sym.php"] [unique_id "amuHUc637Arlr6Yb1EcY5QAAAN8"]
[Thu Jul 30 12:18:09.230845 2026] [security2:error] [pid 703393:tid 703613] [client 20.215.186.36:12421] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.ai-kr.com"] [uri "/sym.php"] [unique_id "amuHUc637Arlr6Yb1EcY5QAAAN8"]
[Thu Jul 30 12:18:09.260682 2026] [security2:error] [pid 703393:tid 703541] [client 20.91.199.21:35178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/mariju.php"] [unique_id "amuHUc637Arlr6Yb1EcY5gAAAJc"]
[Thu Jul 30 12:18:09.336292 2026] [security2:error] [pid 703393:tid 703591] [client 2a03:2880:f800:18:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuHUM637Arlr6Yb1EcY3AAAySw"]
[Thu Jul 30 12:18:09.541795 2026] [security2:error] [pid 703393:tid 703564] [client 20.215.186.36:12602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.186.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ai-kr.com"] [uri "/symlink.php"] [unique_id "amuHUc637Arlr6Yb1EcY7AAAAK4"]
[Thu Jul 30 12:18:09.541901 2026] [security2:error] [pid 703393:tid 703564] [client 20.215.186.36:12602] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.ai-kr.com"] [uri "/symlink.php"] [unique_id "amuHUc637Arlr6Yb1EcY7AAAAK4"]
[Thu Jul 30 12:18:09.634506 2026] [security2:error] [pid 703393:tid 703645] [client 52.167.144.172:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuHUc637Arlr6Yb1EcY6QAAAP8"]
[Thu Jul 30 12:18:09.715490 2026] [security2:error] [pid 703393:tid 703594] [client 20.151.221.234:35094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/av.php"] [unique_id "amuHUc637Arlr6Yb1EcY8wAAAMw"]
[Thu Jul 30 12:18:09.905805 2026] [security2:error] [pid 703393:tid 703568] [client 20.215.186.36:12420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.186.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ai-kr.com"] [uri "/sym403.php"] [unique_id "amuHUc637Arlr6Yb1EcY9QAAALI"]
[Thu Jul 30 12:18:09.905931 2026] [security2:error] [pid 703393:tid 703568] [client 20.215.186.36:12420] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.ai-kr.com"] [uri "/sym403.php"] [unique_id "amuHUc637Arlr6Yb1EcY9QAAALI"]
[Thu Jul 30 12:18:09.979014 2026] [security2:error] [pid 703393:tid 703527] [client 2a03:2880:f800:8:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuHUc637Arlr6Yb1EcY6gAAiXQ"]
[Thu Jul 30 12:18:10.039511 2026] [security2:error] [pid 703393:tid 703595] [client 20.63.98.115:38923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/upgrade/about.php"] [unique_id "amuHUs637Arlr6Yb1EcY9gAAAM0"]
[Thu Jul 30 12:18:10.066242 2026] [security2:error] [pid 703393:tid 703523] [client 20.91.199.21:33959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/moon.php"] [unique_id "amuHUs637Arlr6Yb1EcY9wAAAIU"]
[Thu Jul 30 12:18:10.219215 2026] [security2:error] [pid 703393:tid 703604] [client 20.215.186.36:12459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.186.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ai-kr.com"] [uri "/fw.php"] [unique_id "amuHUs637Arlr6Yb1EcY-wAAANY"]
[Thu Jul 30 12:18:10.219310 2026] [security2:error] [pid 703393:tid 703604] [client 20.215.186.36:12459] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.ai-kr.com"] [uri "/fw.php"] [unique_id "amuHUs637Arlr6Yb1EcY-wAAANY"]
[Thu Jul 30 12:18:10.538300 2026] [security2:error] [pid 703393:tid 703586] [client 20.215.186.36:12430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.186.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ai-kr.com"] [uri "/xyz.php"] [unique_id "amuHUs637Arlr6Yb1EcZAgAAAMQ"]
[Thu Jul 30 12:18:10.538426 2026] [security2:error] [pid 703393:tid 703586] [client 20.215.186.36:12430] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.ai-kr.com"] [uri "/xyz.php"] [unique_id "amuHUs637Arlr6Yb1EcZAgAAAMQ"]
[Thu Jul 30 12:18:10.930996 2026] [security2:error] [pid 703393:tid 703553] [client 20.215.186.36:12437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.186.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ai-kr.com"] [uri "/tolol.php"] [unique_id "amuHUs637Arlr6Yb1EcZCQAAAKM"]
[Thu Jul 30 12:18:10.931114 2026] [security2:error] [pid 703393:tid 703553] [client 20.215.186.36:12437] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.ai-kr.com"] [uri "/tolol.php"] [unique_id "amuHUs637Arlr6Yb1EcZCQAAAKM"]
[Thu Jul 30 12:18:11.303951 2026] [security2:error] [pid 703393:tid 703578] [client 20.91.199.21:10801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amuHU8637Arlr6Yb1EcZEAAAALw"]
[Thu Jul 30 12:18:11.356117 2026] [core:error] [pid 703393:tid 703445] [remote 216.73.217.129:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:18:11.356138 2026] [core:error] [pid 703393:tid 703445] [remote 216.73.217.129:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:18:12.016479 2026] [security2:error] [pid 703393:tid 703542] [client 20.151.221.234:35451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/mini.php"] [unique_id "amuHVM637Arlr6Yb1EcZHAAAAJg"]
[Thu Jul 30 12:18:12.134715 2026] [security2:error] [pid 703393:tid 703613] [client 77.83.36.161:30044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/administrator/index.php"] [unique_id "amuHVM637Arlr6Yb1EcZHQAAAN8"]
[Thu Jul 30 12:18:12.494514 2026] [security2:error] [pid 703393:tid 703544] [client 2a03:2880:f800:1e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuHU8637Arlr6Yb1EcZGgAAmjg"]
[Thu Jul 30 12:18:12.556587 2026] [security2:error] [pid 703393:tid 703629] [client 202.21.121.117:63931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.121.21.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vertexroofsolutions.com"] [uri "/xmlrpc.php"] [unique_id "amuHVM637Arlr6Yb1EcZJwAAAO8"]
[Thu Jul 30 12:18:12.556702 2026] [security2:error] [pid 703393:tid 703629] [client 202.21.121.117:63931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vertexroofsolutions.com"] [uri "/xmlrpc.php"] [unique_id "amuHVM637Arlr6Yb1EcZJwAAAO8"]
[Thu Jul 30 12:18:12.792291 2026] [security2:error] [pid 703393:tid 703538] [client 77.83.36.161:30355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/administrator/index.php"] [unique_id "amuHVM637Arlr6Yb1EcZLAAAAJQ"]
[Thu Jul 30 12:18:12.973660 2026] [security2:error] [pid 703393:tid 703568] [client 20.63.98.115:62435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp.php"] [unique_id "amuHVM637Arlr6Yb1EcZMQAAALI"]
[Thu Jul 30 12:18:13.371534 2026] [security2:error] [pid 703393:tid 703551] [client 77.83.36.161:30694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/administrator/index.php"] [unique_id "amuHVc637Arlr6Yb1EcZNQAAAKE"]
[Thu Jul 30 12:18:13.392678 2026] [security2:error] [pid 703393:tid 703639] [client 20.151.221.234:35519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/aa.php"] [unique_id "amuHVc637Arlr6Yb1EcZNgAAAPk"]
[Thu Jul 30 12:18:14.148150 2026] [security2:error] [pid 703393:tid 703553] [client 52.167.144.172:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuHVc637Arlr6Yb1EcZPAAAAKM"]
[Thu Jul 30 12:18:14.296407 2026] [security2:error] [pid 703393:tid 703642] [client 20.63.98.115:62442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/Requests/library/about.php"] [unique_id "amuHVs637Arlr6Yb1EcZQAAAAPw"]
[Thu Jul 30 12:18:14.638383 2026] [security2:error] [pid 703393:tid 703616] [client 52.167.144.172:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuHVs637Arlr6Yb1EcZQwAAAOI"]
[Thu Jul 30 12:18:14.765732 2026] [security2:error] [pid 703393:tid 703640] [client 20.151.221.234:35487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/w.php"] [unique_id "amuHVs637Arlr6Yb1EcZSgAAAPo"]
[Thu Jul 30 12:18:14.884466 2026] [security2:error] [pid 703393:tid 703615] [client 103.245.38.203:53564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "ajakholding.net"] [uri "/"] [unique_id "amuHVs637Arlr6Yb1EcZSwAAAOE"]
[Thu Jul 30 12:18:14.925822 2026] [security2:error] [pid 703393:tid 703603] [client 195.113.175.167:1400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.175.113.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/indexf.php"] [unique_id "amuHVs637Arlr6Yb1EcZTwAAANU"]
[Thu Jul 30 12:18:15.499270 2026] [security2:error] [pid 703393:tid 703636] [client 20.91.199.21:11029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "amuHV8637Arlr6Yb1EcZWwAAAPY"]
[Thu Jul 30 12:18:15.895135 2026] [security2:error] [pid 703393:tid 703591] [client 2a03:2880:f800:3f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuHV8637Arlr6Yb1EcZUwAAySk"]
[Thu Jul 30 12:18:16.215870 2026] [security2:error] [pid 703393:tid 703608] [client 20.91.199.21:11154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "amuHWM637Arlr6Yb1EcZaQAAANo"]
[Thu Jul 30 12:18:16.222520 2026] [security2:error] [pid 703393:tid 703619] [client 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.lapakjitu78.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuHWM637Arlr6Yb1EcZagAAAOU"]
[Thu Jul 30 12:18:16.484868 2026] [security2:error] [pid 703393:tid 703589] [client 82.102.18.188:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.lapakjitu78.com"] [uri "/xmlrpc.php"] [unique_id "amuHWM637Arlr6Yb1EcZbgAAAMc"]
[Thu Jul 30 12:18:17.079761 2026] [security2:error] [pid 703393:tid 703614] [client 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.lapakjitu78.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuHWc637Arlr6Yb1EcZdgAAAOA"]
[Thu Jul 30 12:18:17.134172 2026] [security2:error] [pid 703393:tid 703570] [client 114.119.158.113:32081] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "deltaedu.net"] [uri "/category/expense-in-china/"] [unique_id "amuHWc637Arlr6Yb1EcZegAAALQ"], referer: http://deltaedu.net/category/expense-in-china/
[Thu Jul 30 12:18:17.187780 2026] [security2:error] [pid 703393:tid 703524] [client 20.91.199.21:10776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/amaxx.php"] [unique_id "amuHWc637Arlr6Yb1EcZewAAAIY"]
[Thu Jul 30 12:18:17.238067 2026] [security2:error] [pid 703393:tid 703577] [client 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.lapakjitu78.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuHWc637Arlr6Yb1EcZfAAAALs"]
[Thu Jul 30 12:18:17.491083 2026] [security2:error] [pid 703393:tid 703562] [client 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.lapakjitu78.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuHWc637Arlr6Yb1EcZfQAAAKw"]
[Thu Jul 30 12:18:17.614495 2026] [security2:error] [pid 703393:tid 703622] [client 20.63.98.115:63163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/.well-known/index.php"] [unique_id "amuHWc637Arlr6Yb1EcZhAAAAOg"]
[Thu Jul 30 12:18:17.760633 2026] [security2:error] [pid 703393:tid 703525] [client 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.lapakjitu78.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuHWc637Arlr6Yb1EcZhgAAAIc"]
[Thu Jul 30 12:18:18.007518 2026] [security2:error] [pid 703393:tid 703627] [client 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.lapakjitu78.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuHWs637Arlr6Yb1EcZhwAAAO0"]
[Thu Jul 30 12:18:18.048208 2026] [security2:error] [pid 703393:tid 703569] [client 102.51.21.89:47669] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dlr.djb.temporary.site"] [uri "/index.php"] [unique_id "amuHWc637Arlr6Yb1EcZhQAAALM"]
[Thu Jul 30 12:18:18.257035 2026] [security2:error] [pid 703393:tid 703595] [client 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.lapakjitu78.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuHWs637Arlr6Yb1EcZjwAAAM0"]
[Thu Jul 30 12:18:18.506288 2026] [security2:error] [pid 703393:tid 703538] [client 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.lapakjitu78.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuHWs637Arlr6Yb1EcZkAAAAJQ"]
[Thu Jul 30 12:18:18.759227 2026] [security2:error] [pid 703393:tid 703559] [client 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.lapakjitu78.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuHWs637Arlr6Yb1EcZlwAAAKk"]
[Thu Jul 30 12:18:19.006930 2026] [security2:error] [pid 703393:tid 703533] [client 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.lapakjitu78.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuHW8637Arlr6Yb1EcZmQAAAI8"]
[Thu Jul 30 12:18:19.246081 2026] [security2:error] [pid 703393:tid 703611] [client 20.63.98.115:49137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/asasx.php"] [unique_id "amuHW8637Arlr6Yb1EcZoQAAAN0"]
[Thu Jul 30 12:18:19.259790 2026] [security2:error] [pid 703393:tid 703626] [client 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.lapakjitu78.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuHW8637Arlr6Yb1EcZogAAAOw"]
[Thu Jul 30 12:18:19.334053 2026] [security2:error] [pid 703393:tid 703628] [client 20.91.199.21:11171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/bek.php"] [unique_id "amuHW8637Arlr6Yb1EcZowAAAO4"]
[Thu Jul 30 12:18:19.480905 2026] [core:notice] [pid 703393:tid 703580] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:18:19.520417 2026] [security2:error] [pid 703393:tid 703644] [client 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.lapakjitu78.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuHW8637Arlr6Yb1EcZpgAAAP4"]
[Thu Jul 30 12:18:19.793118 2026] [security2:error] [pid 703393:tid 703602] [client 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.lapakjitu78.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuHW8637Arlr6Yb1EcZsQAAANQ"]
[Thu Jul 30 12:18:20.055020 2026] [security2:error] [pid 703393:tid 703542] [client 20.91.199.21:10786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/caches.php.suspected"] [unique_id "amuHXM637Arlr6Yb1EcZugAAAJg"]
[Thu Jul 30 12:18:20.061716 2026] [security2:error] [pid 703393:tid 703594] [client 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.lapakjitu78.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuHXM637Arlr6Yb1EcZuwAAAMw"]
[Thu Jul 30 12:18:20.388351 2026] [security2:error] [pid 703393:tid 703625] [client 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.lapakjitu78.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuHXM637Arlr6Yb1EcZxAAAAOs"]
[Thu Jul 30 12:18:20.640007 2026] [security2:error] [pid 703393:tid 703581] [client 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.lapakjitu78.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuHXM637Arlr6Yb1EcZyAAAAL8"]
[Thu Jul 30 12:18:20.682216 2026] [security2:error] [pid 703393:tid 703523] [client 20.91.199.21:33978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/class.api.php"] [unique_id "amuHXM637Arlr6Yb1EcZywAAAIU"]
[Thu Jul 30 12:18:20.902998 2026] [security2:error] [pid 703393:tid 703634] [client 20.63.98.115:65290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/user/wp-login.php"] [unique_id "amuHXM637Arlr6Yb1EcZ0gAAAPQ"]
[Thu Jul 30 12:18:20.913838 2026] [security2:error] [pid 703393:tid 703624] [client 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.lapakjitu78.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuHXM637Arlr6Yb1EcZ0wAAAOo"]
[Thu Jul 30 12:18:21.207794 2026] [security2:error] [pid 703393:tid 703631] [client 52.167.144.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuHXM637Arlr6Yb1EcZ0QAAAPE"]
[Thu Jul 30 12:18:22.633542 2026] [security2:error] [pid 703393:tid 703618] [client 52.167.144.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuHXs637Arlr6Yb1EcZ5QAAAOQ"]
[Thu Jul 30 12:18:24.144654 2026] [security2:error] [pid 703393:tid 703552] [client 20.91.199.21:10763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/cong.php"] [unique_id "amuHYM637Arlr6Yb1EcaAgAAAKI"]
[Thu Jul 30 12:18:24.251802 2026] [security2:error] [pid 703393:tid 703628] [client 20.63.98.115:63110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "amuHYM637Arlr6Yb1EcaAwAAAO4"]
[Thu Jul 30 12:18:24.341502 2026] [security2:error] [pid 703393:tid 703498] [remote 74.7.241.60:41576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/article.php"] [unique_id "amuHYM637Arlr6Yb1EcaBwABAWg"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/main_image_6a3229a631e84.jpg
[Thu Jul 30 12:18:24.758726 2026] [core:notice] [pid 703393:tid 703634] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:18:25.084966 2026] [security2:error] [pid 703393:tid 703588] [client 20.63.98.115:64863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/radio.php"] [unique_id "amuHYc637Arlr6Yb1EcaFQAAAMY"]
[Thu Jul 30 12:18:25.349614 2026] [security2:error] [pid 703393:tid 703572] [client 158.173.25.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "appliancerepairservice.one"] [uri "/index.php"] [unique_id "amuHYM637Arlr6Yb1EcaEQAAthk"]
[Thu Jul 30 12:18:25.535822 2026] [security2:error] [pid 703393:tid 703566] [client 20.91.199.21:10706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/content.php"] [unique_id "amuHYc637Arlr6Yb1EcaHQAAALA"]
[Thu Jul 30 12:18:25.941868 2026] [security2:error] [pid 703393:tid 703641] [client 40.77.167.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuHYc637Arlr6Yb1EcaIwAAAPs"]
[Thu Jul 30 12:18:26.501679 2026] [security2:error] [pid 703393:tid 703546] [client 20.63.98.115:62410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/plugins/about.php"] [unique_id "amuHYs637Arlr6Yb1EcaMQAAAJw"]
[Thu Jul 30 12:18:26.520103 2026] [security2:error] [pid 703393:tid 703593] [client 150.223.194.180:52635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.194.223.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp-login.php"] [unique_id "amuHYs637Arlr6Yb1EcaLAAAAMs"]
[Thu Jul 30 12:18:26.935588 2026] [security2:error] [pid 703393:tid 703401] [remote 74.7.241.59:37632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuHYs637Arlr6Yb1EcaNgAA8wc"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/premium-addons-for-elementor/modules/woocommerce/templates
[Thu Jul 30 12:18:27.202677 2026] [security2:error] [pid 703393:tid 703622] [client 20.91.199.21:10777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/cwianpri.php"] [unique_id "amuHY8637Arlr6Yb1EcaQAAAAOg"]
[Thu Jul 30 12:18:27.508184 2026] [proxy:error] [pid 703393:tid 703537] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:18:27.508256 2026] [proxy_http:error] [pid 703393:tid 703537] [client 74.7.241.144:57376] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:18:27.508836 2026] [proxy:error] [pid 703393:tid 703537] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:18:27.508881 2026] [proxy_http:error] [pid 703393:tid 703537] [client 74.7.241.144:57376] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:18:27.509012 2026] [security2:error] [pid 703393:tid 703537] [client 74.7.241.144:57376] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "cpcontacts.nmk.djb.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuHY8637Arlr6Yb1EcaRgAAAJM"]
[Thu Jul 30 12:18:28.014824 2026] [security2:error] [pid 703393:tid 703524] [client 20.91.199.21:10692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/elp.php"] [unique_id "amuHZM637Arlr6Yb1EcaTgAAAIY"]
[Thu Jul 30 12:18:28.588149 2026] [security2:error] [pid 703393:tid 703620] [client 74.7.228.41:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amuHZM637Arlr6Yb1EcaVAAAAOY"]
[Thu Jul 30 12:18:28.589151 2026] [security2:error] [pid 703393:tid 703550] [client 74.7.228.41:33592] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tereashops.com"] [uri "/robots.txt"] [unique_id "amuHZM637Arlr6Yb1EcaUQAAoCQ"]
[Thu Jul 30 12:18:28.830262 2026] [security2:error] [pid 703393:tid 703525] [client 20.151.221.234:12847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/admin.php"] [unique_id "amuHZM637Arlr6Yb1EcaZwAAAIc"]
[Thu Jul 30 12:18:28.838844 2026] [security2:error] [pid 703393:tid 703606] [client 20.91.199.21:32600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/kwggvpup.php"] [unique_id "amuHZM637Arlr6Yb1EcaaAAAANg"]
[Thu Jul 30 12:18:29.163413 2026] [security2:error] [pid 703393:tid 703559] [client 20.63.98.115:65331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/st.php"] [unique_id "amuHZc637Arlr6Yb1EcacQAAAKk"]
[Thu Jul 30 12:18:29.370534 2026] [core:error] [pid 703393:tid 703553] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:18:29.370553 2026] [core:error] [pid 703393:tid 703553] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:18:30.292756 2026] [security2:error] [pid 703393:tid 703579] [client 20.91.199.21:10749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/101d2ae2-f2f3-4977-b35d-b3a0ad74a469.php"] [unique_id "amuHZs637Arlr6Yb1EcagwAAAL0"]
[Thu Jul 30 12:18:30.668078 2026] [security2:error] [pid 703393:tid 703569] [client 20.151.221.234:4377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuHZs637Arlr6Yb1EcakgAAALM"]
[Thu Jul 30 12:18:30.773866 2026] [security2:error] [pid 703393:tid 703596] [client 20.63.98.115:64860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/about.php"] [unique_id "amuHZs637Arlr6Yb1EcalAAAAM4"]
[Thu Jul 30 12:18:31.180569 2026] [security2:error] [pid 703393:tid 703628] [client 20.91.199.21:11140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/LA.php"] [unique_id "amuHZ8637Arlr6Yb1EcaoAAAAO4"]
[Thu Jul 30 12:18:31.293279 2026] [security2:error] [pid 703393:tid 703445] [remote 5.161.62.209:33244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.psz.dtn.temporary.site"] [uri "/.env"] [unique_id "amuHZ8637Arlr6Yb1EcapQAAkDM"]
[Thu Jul 30 12:18:31.697206 2026] [security2:error] [pid 703393:tid 703575] [client 20.63.98.115:64865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/admin.php"] [unique_id "amuHZ8637Arlr6Yb1EcasAAAALk"]
[Thu Jul 30 12:18:31.890355 2026] [security2:error] [pid 703393:tid 703623] [client 20.91.199.21:11027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/Newsupway.php"] [unique_id "amuHZ8637Arlr6Yb1EcatgAAAOk"]
[Thu Jul 30 12:18:32.072090 2026] [core:error] [pid 703393:tid 703614] [client 158.173.25.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://appliancerepairservice.one/
[Thu Jul 30 12:18:32.072120 2026] [core:error] [pid 703393:tid 703614] [client 158.173.25.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://appliancerepairservice.one/
[Thu Jul 30 12:18:32.404099 2026] [core:notice] [pid 703393:tid 703421] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:18:32.946341 2026] [security2:error] [pid 703393:tid 703563] [client 20.91.199.21:11017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/a.php"] [unique_id "amuHaM637Arlr6Yb1EcazgAAAK0"]
[Thu Jul 30 12:18:33.123131 2026] [security2:error] [pid 703393:tid 703553] [client 186.52.238.32:45260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dlr.djb.temporary.site"] [uri "/index.php"] [unique_id "amuHaM637Arlr6Yb1EcazQAAAKM"]
[Thu Jul 30 12:18:33.770065 2026] [core:notice] [pid 703393:tid 703435] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:18:33.793913 2026] [security2:error] [pid 703393:tid 703593] [client 20.91.199.21:10774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "amuHac637Arlr6Yb1Eca4wAAAMs"]
[Thu Jul 30 12:18:34.126448 2026] [security2:error] [pid 703393:tid 703646] [client 213.152.161.118:35272] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuHas637Arlr6Yb1Eca5wAAAQA"]
[Thu Jul 30 12:18:34.126545 2026] [security2:error] [pid 703393:tid 703646] [client 213.152.161.118:35272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuHas637Arlr6Yb1Eca5wAAAQA"]
[Thu Jul 30 12:18:34.200134 2026] [security2:error] [pid 703393:tid 703623] [client 20.151.221.234:4399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/m.php"] [unique_id "amuHas637Arlr6Yb1Eca6gAAAOk"]
[Thu Jul 30 12:18:34.272442 2026] [security2:error] [pid 703393:tid 703555] [client 20.63.98.115:63126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/css/admin.php"] [unique_id "amuHas637Arlr6Yb1Eca7AAAAKU"]
[Thu Jul 30 12:18:34.673026 2026] [security2:error] [pid 703393:tid 703617] [client 52.238.199.152:1447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/gmo.php"] [unique_id "amuHas637Arlr6Yb1Eca9AAAAOM"]
[Thu Jul 30 12:18:34.758571 2026] [security2:error] [pid 703393:tid 703592] [client 20.91.199.21:10331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/amaxx.php"] [unique_id "amuHas637Arlr6Yb1Eca9QAAAMo"]
[Thu Jul 30 12:18:35.309065 2026] [security2:error] [pid 703393:tid 703539] [client 20.91.199.21:10345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/bb.php"] [unique_id "amuHa8637Arlr6Yb1EcbAQAAAJU"]
[Thu Jul 30 12:18:35.803545 2026] [security2:error] [pid 703393:tid 703533] [client 20.63.98.115:20997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/plugins/simple/simple.php"] [unique_id "amuHa8637Arlr6Yb1EcbDQAAAI8"]
[Thu Jul 30 12:18:36.435833 2026] [security2:error] [pid 703393:tid 703638] [client 20.151.221.234:12812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuHbM637Arlr6Yb1EcbEgAAAPg"]
[Thu Jul 30 12:18:37.213618 2026] [security2:error] [pid 703393:tid 703649] [client 20.63.98.115:63426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp2.php"] [unique_id "amuHbc637Arlr6Yb1EcbKgAAAQM"]
[Thu Jul 30 12:18:37.270619 2026] [security2:error] [pid 703393:tid 703576] [client 52.238.199.152:1669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/nakrip.php"] [unique_id "amuHbc637Arlr6Yb1EcbMAAAALo"]
[Thu Jul 30 12:18:37.286732 2026] [security2:error] [pid 703393:tid 703595] [client 127.0.0.1:33764] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuHbc637Arlr6Yb1EcbLgAAAM0"]
[Thu Jul 30 12:18:37.286762 2026] [security2:error] [pid 703393:tid 703539] [client 127.0.0.1:33762] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.fyi.nyx.temporary.site"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuHbc637Arlr6Yb1EcbLQAAAJU"]
[Thu Jul 30 12:18:37.286873 2026] [security2:error] [pid 703393:tid 703551] [client 74.7.228.4:56284] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.fyi.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuHbc637Arlr6Yb1EcbLAAAoUw"]
[Thu Jul 30 12:18:37.320664 2026] [core:notice] [pid 703393:tid 703482] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:18:37.467806 2026] [security2:error] [pid 703393:tid 703583] [client 20.151.221.234:35462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/classwithtostring.php"] [unique_id "amuHbc637Arlr6Yb1EcbNQAAAME"]
[Thu Jul 30 12:18:38.199722 2026] [security2:error] [pid 703393:tid 703585] [client 20.100.203.84:48678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuHbs637Arlr6Yb1EcbQgAAAMM"]
[Thu Jul 30 12:18:38.199829 2026] [security2:error] [pid 703393:tid 703585] [client 20.100.203.84:48678] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuHbs637Arlr6Yb1EcbQgAAAMM"]
[Thu Jul 30 12:18:38.265451 2026] [security2:error] [pid 703393:tid 703560] [client 20.91.199.21:33622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/cifcxgxm.php"] [unique_id "amuHbs637Arlr6Yb1EcbRgAAAKo"]
[Thu Jul 30 12:18:38.508864 2026] [security2:error] [pid 703393:tid 703636] [client 20.100.203.84:48652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuHbs637Arlr6Yb1EcbSgAAAPY"]
[Thu Jul 30 12:18:38.509040 2026] [security2:error] [pid 703393:tid 703636] [client 20.100.203.84:48652] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuHbs637Arlr6Yb1EcbSgAAAPY"]
[Thu Jul 30 12:18:38.794817 2026] [security2:error] [pid 703393:tid 703566] [client 20.151.221.234:4413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/gmo.php"] [unique_id "amuHbs637Arlr6Yb1EcbTwAAALA"]
[Thu Jul 30 12:18:38.863851 2026] [security2:error] [pid 703393:tid 703627] [client 20.100.203.84:48670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/x.php"] [unique_id "amuHbs637Arlr6Yb1EcbUAAAAO0"]
[Thu Jul 30 12:18:38.863957 2026] [security2:error] [pid 703393:tid 703627] [client 20.100.203.84:48670] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/x.php"] [unique_id "amuHbs637Arlr6Yb1EcbUAAAAO0"]
[Thu Jul 30 12:18:39.008194 2026] [security2:error] [pid 703393:tid 703552] [client 20.63.98.115:49116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/s.php"] [unique_id "amuHb8637Arlr6Yb1EcbUQAAAKI"]
[Thu Jul 30 12:18:39.200615 2026] [security2:error] [pid 703393:tid 703559] [client 20.100.203.84:43778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/mgrr.php"] [unique_id "amuHb8637Arlr6Yb1EcbVQAAAKk"]
[Thu Jul 30 12:18:39.200730 2026] [security2:error] [pid 703393:tid 703559] [client 20.100.203.84:43778] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/mgrr.php"] [unique_id "amuHb8637Arlr6Yb1EcbVQAAAKk"]
[Thu Jul 30 12:18:39.404345 2026] [security2:error] [pid 703393:tid 703574] [client 20.91.199.21:10343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/ckyocyyp.php"] [unique_id "amuHb8637Arlr6Yb1EcbWQAAALg"]
[Thu Jul 30 12:18:39.505828 2026] [security2:error] [pid 703393:tid 703530] [client 20.100.203.84:43813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/domvf.php"] [unique_id "amuHb8637Arlr6Yb1EcbXAAAAIw"]
[Thu Jul 30 12:18:39.505938 2026] [security2:error] [pid 703393:tid 703530] [client 20.100.203.84:43813] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/domvf.php"] [unique_id "amuHb8637Arlr6Yb1EcbXAAAAIw"]
[Thu Jul 30 12:18:39.619826 2026] [security2:error] [pid 703393:tid 703589] [client 20.151.221.234:4403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-content/languages/index.php"] [unique_id "amuHb8637Arlr6Yb1EcbYAAAAMc"]
[Thu Jul 30 12:18:39.670069 2026] [security2:error] [pid 703393:tid 703498] [remote 57.141.0.40:45330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/snpm/user/register"] [unique_id "amuHb8637Arlr6Yb1EcbWgAA82g"]
[Thu Jul 30 12:18:39.737094 2026] [security2:error] [pid 703393:tid 703599] [client 52.238.199.152:1471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/radio.php"] [unique_id "amuHb8637Arlr6Yb1EcbYgAAANE"]
[Thu Jul 30 12:18:39.810636 2026] [security2:error] [pid 703393:tid 703619] [client 20.100.203.84:57682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/yup.php"] [unique_id "amuHb8637Arlr6Yb1EcbZgAAAOU"]
[Thu Jul 30 12:18:39.810745 2026] [security2:error] [pid 703393:tid 703619] [client 20.100.203.84:57682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/yup.php"] [unique_id "amuHb8637Arlr6Yb1EcbZgAAAOU"]
[Thu Jul 30 12:18:40.140635 2026] [security2:error] [pid 703393:tid 703531] [client 20.100.203.84:43777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/X.php"] [unique_id "amuHcM637Arlr6Yb1EcbagAAAI0"]
[Thu Jul 30 12:18:40.140743 2026] [security2:error] [pid 703393:tid 703531] [client 20.100.203.84:43777] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/X.php"] [unique_id "amuHcM637Arlr6Yb1EcbagAAAI0"]
[Thu Jul 30 12:18:40.472153 2026] [security2:error] [pid 703393:tid 703528] [client 20.100.203.84:57709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amuHcM637Arlr6Yb1EcbcgAAAIo"]
[Thu Jul 30 12:18:40.472269 2026] [security2:error] [pid 703393:tid 703528] [client 20.100.203.84:57709] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amuHcM637Arlr6Yb1EcbcgAAAIo"]
[Thu Jul 30 12:18:40.554069 2026] [security2:error] [pid 703393:tid 703613] [client 20.63.98.115:21047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/help.php"] [unique_id "amuHcM637Arlr6Yb1EcbcwAAAN8"]
[Thu Jul 30 12:18:40.746534 2026] [security2:error] [pid 703393:tid 703585] [client 52.238.199.152:1479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/wp-singin.php"] [unique_id "amuHcM637Arlr6Yb1EcbeAAAAMM"]
[Thu Jul 30 12:18:40.881122 2026] [security2:error] [pid 703393:tid 703550] [client 20.100.203.84:48697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/gec.php"] [unique_id "amuHcM637Arlr6Yb1EcbegAAAKA"]
[Thu Jul 30 12:18:40.881226 2026] [security2:error] [pid 703393:tid 703550] [client 20.100.203.84:48697] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/gec.php"] [unique_id "amuHcM637Arlr6Yb1EcbegAAAKA"]
[Thu Jul 30 12:18:41.076603 2026] [security2:error] [pid 703393:tid 703603] [client 20.91.199.21:10748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/classwithtostring.php"] [unique_id "amuHcc637Arlr6Yb1EcbfgAAANU"]
[Thu Jul 30 12:18:41.093670 2026] [security2:error] [pid 703393:tid 703646] [client 20.151.221.234:12863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-the.php"] [unique_id "amuHcc637Arlr6Yb1EcbfwAAAQA"]
[Thu Jul 30 12:18:41.182357 2026] [security2:error] [pid 703393:tid 703610] [client 20.100.203.84:43823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/sky.php"] [unique_id "amuHcc637Arlr6Yb1EcbgwAAANw"]
[Thu Jul 30 12:18:41.182457 2026] [security2:error] [pid 703393:tid 703610] [client 20.100.203.84:43823] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/sky.php"] [unique_id "amuHcc637Arlr6Yb1EcbgwAAANw"]
[Thu Jul 30 12:18:41.206785 2026] [security2:error] [pid 703393:tid 703581] [client 74.7.228.27:47644] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.aetiiph.net.smo.zzt.temporary.site"] [uri "/index.php"] [unique_id "amuHcM637Arlr6Yb1EcbdwAAvxo"]
[Thu Jul 30 12:18:41.500922 2026] [security2:error] [pid 703393:tid 703539] [client 20.100.203.84:48682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/fffm.php"] [unique_id "amuHcc637Arlr6Yb1EcbhwAAAJU"]
[Thu Jul 30 12:18:41.501036 2026] [security2:error] [pid 703393:tid 703539] [client 20.100.203.84:48682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/fffm.php"] [unique_id "amuHcc637Arlr6Yb1EcbhwAAAJU"]
[Thu Jul 30 12:18:41.820597 2026] [security2:error] [pid 703393:tid 703589] [client 20.100.203.84:43839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/sixxis.php"] [unique_id "amuHcc637Arlr6Yb1EcbjQAAAMc"]
[Thu Jul 30 12:18:41.820707 2026] [security2:error] [pid 703393:tid 703589] [client 20.100.203.84:43839] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/sixxis.php"] [unique_id "amuHcc637Arlr6Yb1EcbjQAAAMc"]
[Thu Jul 30 12:18:41.887955 2026] [security2:error] [pid 703393:tid 703596] [client 52.238.199.152:1671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/as.php"] [unique_id "amuHcc637Arlr6Yb1EcbjwAAAM4"]
[Thu Jul 30 12:18:41.890721 2026] [security2:error] [pid 703393:tid 703558] [client 87.101.92.171:51364] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuHcc637Arlr6Yb1EcbjgAAAKg"]
[Thu Jul 30 12:18:41.890816 2026] [security2:error] [pid 703393:tid 703558] [client 87.101.92.171:51364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuHcc637Arlr6Yb1EcbjgAAAKg"]
[Thu Jul 30 12:18:41.957910 2026] [security2:error] [pid 703393:tid 703551] [client 20.91.199.21:10734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/content.php"] [unique_id "amuHcc637Arlr6Yb1EcbkwAAAKE"]
[Thu Jul 30 12:18:41.994352 2026] [security2:error] [pid 703393:tid 703530] [client 20.151.221.234:4414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/404.php"] [unique_id "amuHcc637Arlr6Yb1EcblQAAAIw"]
[Thu Jul 30 12:18:42.121038 2026] [security2:error] [pid 703393:tid 703523] [client 20.100.203.84:48690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/yj09.php"] [unique_id "amuHcs637Arlr6Yb1EcblgAAAIU"]
[Thu Jul 30 12:18:42.121153 2026] [security2:error] [pid 703393:tid 703523] [client 20.100.203.84:48690] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/yj09.php"] [unique_id "amuHcs637Arlr6Yb1EcblgAAAIU"]
[Thu Jul 30 12:18:42.221740 2026] [security2:error] [pid 703393:tid 703628] [client 20.63.98.115:63441] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "jesus.claims"] [uri "/wp-content/plugins/pwnd/1.php"] [unique_id "amuHcs637Arlr6Yb1EcbmgAAAO4"]
[Thu Jul 30 12:18:42.221866 2026] [security2:error] [pid 703393:tid 703628] [client 20.63.98.115:63441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/plugins/pwnd/1.php"] [unique_id "amuHcs637Arlr6Yb1EcbmgAAAO4"]
[Thu Jul 30 12:18:42.464460 2026] [security2:error] [pid 703393:tid 703638] [client 20.100.203.84:57670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/k.php"] [unique_id "amuHcs637Arlr6Yb1EcbngAAAPg"]
[Thu Jul 30 12:18:42.464571 2026] [security2:error] [pid 703393:tid 703638] [client 20.100.203.84:57670] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/k.php"] [unique_id "amuHcs637Arlr6Yb1EcbngAAAPg"]
[Thu Jul 30 12:18:42.757228 2026] [security2:error] [pid 703393:tid 703536] [client 20.91.199.21:46432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/content.php.suspected"] [unique_id "amuHcs637Arlr6Yb1EcbowAAAJI"]
[Thu Jul 30 12:18:42.831382 2026] [security2:error] [pid 703393:tid 703607] [client 20.151.221.234:4405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/init.php"] [unique_id "amuHcs637Arlr6Yb1EcbpAAAANk"]
[Thu Jul 30 12:18:42.964475 2026] [security2:error] [pid 703393:tid 703566] [client 20.100.203.84:48641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/k2.php"] [unique_id "amuHcs637Arlr6Yb1EcbpwAAALA"]
[Thu Jul 30 12:18:42.964564 2026] [security2:error] [pid 703393:tid 703566] [client 20.100.203.84:48641] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/k2.php"] [unique_id "amuHcs637Arlr6Yb1EcbpwAAALA"]
[Thu Jul 30 12:18:43.027506 2026] [security2:error] [pid 703393:tid 703621] [client 52.238.199.152:1415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/x.php"] [unique_id "amuHc8637Arlr6Yb1EcbrgAAAOc"]
[Thu Jul 30 12:18:43.700759 2026] [security2:error] [pid 703393:tid 703576] [client 20.151.221.234:12840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/file5.php"] [unique_id "amuHc8637Arlr6Yb1EcbvAAAALo"]
[Thu Jul 30 12:18:43.844998 2026] [security2:error] [pid 703393:tid 703620] [client 20.63.98.115:47228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/admin/upload/css.php"] [unique_id "amuHc8637Arlr6Yb1EcbvQAAAOY"]
[Thu Jul 30 12:18:43.861504 2026] [security2:error] [pid 703393:tid 703551] [client 20.100.203.84:43796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/w.php"] [unique_id "amuHc8637Arlr6Yb1EcbvgAAAKE"]
[Thu Jul 30 12:18:43.861580 2026] [security2:error] [pid 703393:tid 703551] [client 20.100.203.84:43796] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/w.php"] [unique_id "amuHc8637Arlr6Yb1EcbvgAAAKE"]
[Thu Jul 30 12:18:44.678266 2026] [security2:error] [pid 703393:tid 703535] [client 20.151.221.234:12851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amuHdM637Arlr6Yb1EcbygAAAJE"]
[Thu Jul 30 12:18:44.697156 2026] [security2:error] [pid 703393:tid 703611] [client 20.100.203.84:48689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/fpwch.php"] [unique_id "amuHdM637Arlr6Yb1EcbzgAAAN0"]
[Thu Jul 30 12:18:44.697267 2026] [security2:error] [pid 703393:tid 703611] [client 20.100.203.84:48689] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/fpwch.php"] [unique_id "amuHdM637Arlr6Yb1EcbzgAAAN0"]
[Thu Jul 30 12:18:44.773232 2026] [security2:error] [pid 703393:tid 703531] [client 20.63.98.115:65301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/images/about.php"] [unique_id "amuHdM637Arlr6Yb1Ecb0AAAAI0"]
[Thu Jul 30 12:18:44.899970 2026] [security2:error] [pid 703393:tid 703405] [remote 74.7.242.7:46884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.242.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/"] [unique_id "amuHdM637Arlr6Yb1Ecb1AAAsQs"], referer: https://www.thdinfinity.com/
[Thu Jul 30 12:18:45.295842 2026] [security2:error] [pid 703393:tid 703564] [client 20.91.199.21:10336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/doc.php"] [unique_id "amuHdc637Arlr6Yb1Ecb3gAAAK4"]
[Thu Jul 30 12:18:45.305246 2026] [security2:error] [pid 703393:tid 703557] [client 20.100.203.84:57695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/w2025.php"] [unique_id "amuHdc637Arlr6Yb1Ecb3wAAAKc"]
[Thu Jul 30 12:18:45.305360 2026] [security2:error] [pid 703393:tid 703557] [client 20.100.203.84:57695] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/w2025.php"] [unique_id "amuHdc637Arlr6Yb1Ecb3wAAAKc"]
[Thu Jul 30 12:18:45.638672 2026] [security2:error] [pid 703393:tid 703621] [client 52.167.144.209:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuHdc637Arlr6Yb1Ecb3AAAAOc"]
[Thu Jul 30 12:18:45.733705 2026] [security2:error] [pid 703393:tid 703556] [client 20.100.203.84:48692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/FWAZ.php"] [unique_id "amuHdc637Arlr6Yb1Ecb6AAAAKY"]
[Thu Jul 30 12:18:45.733822 2026] [security2:error] [pid 703393:tid 703556] [client 20.100.203.84:48692] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/FWAZ.php"] [unique_id "amuHdc637Arlr6Yb1Ecb6AAAAKY"]
[Thu Jul 30 12:18:45.742287 2026] [security2:error] [pid 703393:tid 703566] [client 20.151.221.234:12841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/shell.php"] [unique_id "amuHdc637Arlr6Yb1Ecb6QAAALA"]
[Thu Jul 30 12:18:45.847895 2026] [security2:error] [pid 703393:tid 703629] [client 20.63.98.115:62820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/autoloadclassmap.php"] [unique_id "amuHdc637Arlr6Yb1Ecb7QAAAO8"]
[Thu Jul 30 12:18:45.954261 2026] [security2:error] [pid 703393:tid 703624] [client 20.91.199.21:10350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/fond.php"] [unique_id "amuHdc637Arlr6Yb1Ecb7gAAAOo"]
[Thu Jul 30 12:18:46.129210 2026] [security2:error] [pid 703393:tid 703605] [client 20.100.203.84:43791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/qterm.php"] [unique_id "amuHds637Arlr6Yb1Ecb8AAAANc"]
[Thu Jul 30 12:18:46.129329 2026] [security2:error] [pid 703393:tid 703605] [client 20.100.203.84:43791] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/qterm.php"] [unique_id "amuHds637Arlr6Yb1Ecb8AAAANc"]
[Thu Jul 30 12:18:46.657042 2026] [security2:error] [pid 703393:tid 703630] [client 20.63.98.115:21036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/x.php"] [unique_id "amuHds637Arlr6Yb1Ecb-QAAAPA"]
[Thu Jul 30 12:18:46.701279 2026] [security2:error] [pid 703393:tid 703562] [client 20.91.199.21:35260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/gkiliuew.php"] [unique_id "amuHds637Arlr6Yb1Ecb_AAAAKw"]
[Thu Jul 30 12:18:46.887344 2026] [security2:error] [pid 703393:tid 703645] [client 20.100.203.84:48676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/blurbs.php"] [unique_id "amuHds637Arlr6Yb1EccAQAAAP8"]
[Thu Jul 30 12:18:46.887460 2026] [security2:error] [pid 703393:tid 703645] [client 20.100.203.84:48676] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/blurbs.php"] [unique_id "amuHds637Arlr6Yb1EccAQAAAP8"]
[Thu Jul 30 12:18:47.023913 2026] [security2:error] [pid 703393:tid 703594] [client 20.151.221.234:4354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/f35.php"] [unique_id "amuHd8637Arlr6Yb1EccAgAAAMw"]
[Thu Jul 30 12:18:47.269778 2026] [security2:error] [pid 703393:tid 703534] [client 20.100.203.84:43805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-ws68.php"] [unique_id "amuHd8637Arlr6Yb1EccBwAAAJA"]
[Thu Jul 30 12:18:47.269859 2026] [security2:error] [pid 703393:tid 703534] [client 20.100.203.84:43805] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-ws68.php"] [unique_id "amuHd8637Arlr6Yb1EccBwAAAJA"]
[Thu Jul 30 12:18:47.441933 2026] [security2:error] [pid 703393:tid 703560] [client 20.63.98.115:21007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-class.php"] [unique_id "amuHd8637Arlr6Yb1EccCwAAAKo"]
[Thu Jul 30 12:18:47.534721 2026] [security2:error] [pid 703393:tid 703526] [client 20.91.199.21:10307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/iR7SzrsOUEP.php"] [unique_id "amuHd8637Arlr6Yb1EccDAAAAIg"]
[Thu Jul 30 12:18:47.624193 2026] [security2:error] [pid 703393:tid 703607] [client 20.100.203.84:57683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/xyn.php"] [unique_id "amuHd8637Arlr6Yb1EccDQAAANk"]
[Thu Jul 30 12:18:47.624309 2026] [security2:error] [pid 703393:tid 703607] [client 20.100.203.84:57683] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/xyn.php"] [unique_id "amuHd8637Arlr6Yb1EccDQAAANk"]
[Thu Jul 30 12:18:47.634255 2026] [security2:error] [pid 703393:tid 703555] [client 144.123.76.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuHd8637Arlr6Yb1EccBgAApXE"]
[Thu Jul 30 12:18:47.710580 2026] [security2:error] [pid 703393:tid 703506] [remote 57.141.0.25:43248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/674008491/feed/rss2/"] [unique_id "amuHd8637Arlr6Yb1EccDwAAlHA"]
[Thu Jul 30 12:18:47.967032 2026] [security2:error] [pid 703393:tid 703525] [client 20.100.203.84:48649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/ccc.php"] [unique_id "amuHd8637Arlr6Yb1EccFwAAAIc"]
[Thu Jul 30 12:18:47.967136 2026] [security2:error] [pid 703393:tid 703525] [client 20.100.203.84:48649] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/ccc.php"] [unique_id "amuHd8637Arlr6Yb1EccFwAAAIc"]
[Thu Jul 30 12:18:48.339201 2026] [security2:error] [pid 703393:tid 703529] [client 20.100.203.84:34630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/get.php"] [unique_id "amuHeM637Arlr6Yb1EccGwAAAIs"]
[Thu Jul 30 12:18:48.339309 2026] [security2:error] [pid 703393:tid 703529] [client 20.100.203.84:34630] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/get.php"] [unique_id "amuHeM637Arlr6Yb1EccGwAAAIs"]
[Thu Jul 30 12:18:48.399783 2026] [core:error] [pid 703393:tid 703574] [client 88.151.33.203:56330] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh)
[Thu Jul 30 12:18:48.544887 2026] [security2:error] [pid 703393:tid 703577] [client 20.151.221.234:35510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/new.php"] [unique_id "amuHeM637Arlr6Yb1EccIAAAALs"]
[Thu Jul 30 12:18:48.653567 2026] [security2:error] [pid 703393:tid 703624] [client 20.100.203.84:48657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/images.php"] [unique_id "amuHeM637Arlr6Yb1EccIgAAAOo"]
[Thu Jul 30 12:18:48.653669 2026] [security2:error] [pid 703393:tid 703624] [client 20.100.203.84:48657] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/images.php"] [unique_id "amuHeM637Arlr6Yb1EccIgAAAOo"]
[Thu Jul 30 12:18:48.996135 2026] [security2:error] [pid 703393:tid 703551] [client 20.100.203.84:57718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/alls.php"] [unique_id "amuHeM637Arlr6Yb1EccJwAAAKE"]
[Thu Jul 30 12:18:48.996260 2026] [security2:error] [pid 703393:tid 703551] [client 20.100.203.84:57718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/alls.php"] [unique_id "amuHeM637Arlr6Yb1EccJwAAAKE"]
[Thu Jul 30 12:18:49.057772 2026] [security2:error] [pid 703393:tid 703573] [client 20.91.199.21:33641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/ibkejxnu.php"] [unique_id "amuHec637Arlr6Yb1EccKwAAALc"]
[Thu Jul 30 12:18:49.321568 2026] [security2:error] [pid 703393:tid 703545] [client 20.63.98.115:21009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/content.php"] [unique_id "amuHec637Arlr6Yb1EccLQAAAJs"]
[Thu Jul 30 12:18:49.388323 2026] [security2:error] [pid 703393:tid 703535] [client 20.100.203.84:57711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/coffexium.php"] [unique_id "amuHec637Arlr6Yb1EccMQAAAJE"]
[Thu Jul 30 12:18:49.388440 2026] [security2:error] [pid 703393:tid 703535] [client 20.100.203.84:57711] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/coffexium.php"] [unique_id "amuHec637Arlr6Yb1EccMQAAAJE"]
[Thu Jul 30 12:18:49.506158 2026] [security2:error] [pid 703393:tid 703634] [client 2a03:2880:f800:35:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuHeM637Arlr6Yb1EccJgAA9Cg"]
[Thu Jul 30 12:18:49.634102 2026] [security2:error] [pid 703393:tid 703593] [client 20.151.221.234:35459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/adminfuns.php"] [unique_id "amuHec637Arlr6Yb1EccOAAAAMs"]
[Thu Jul 30 12:18:49.756557 2026] [security2:error] [pid 703393:tid 703578] [client 20.100.203.84:43811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/red.php"] [unique_id "amuHec637Arlr6Yb1EccOgAAALw"]
[Thu Jul 30 12:18:49.756713 2026] [security2:error] [pid 703393:tid 703578] [client 20.100.203.84:43811] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/red.php"] [unique_id "amuHec637Arlr6Yb1EccOgAAALw"]
[Thu Jul 30 12:18:49.941045 2026] [security2:error] [pid 703393:tid 703614] [client 20.91.199.21:46420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/install.php"] [unique_id "amuHec637Arlr6Yb1EccPgAAAOA"]
[Thu Jul 30 12:18:50.081507 2026] [security2:error] [pid 703393:tid 703563] [client 172.213.232.128:6682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/geju.php"] [unique_id "amuHes637Arlr6Yb1EccQgAAAK0"]
[Thu Jul 30 12:18:50.200614 2026] [security2:error] [pid 703393:tid 703582] [client 20.100.203.84:48683] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.heatstickhk.com"] [uri "/___proxy_subdomain_cpanel/wp-includes/sodium_compat/"] [unique_id "amuHes637Arlr6Yb1EccQwAAAMA"]
[Thu Jul 30 12:18:50.493718 2026] [security2:error] [pid 703393:tid 703570] [client 51.120.79.193:10773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuHes637Arlr6Yb1EccSgAAALQ"]
[Thu Jul 30 12:18:50.493815 2026] [security2:error] [pid 703393:tid 703570] [client 51.120.79.193:10773] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "progroup.jo"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuHes637Arlr6Yb1EccSgAAALQ"]
[Thu Jul 30 12:18:50.495899 2026] [security2:error] [pid 703393:tid 703595] [client 20.100.203.84:48683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amuHes637Arlr6Yb1EccSwAAAM0"]
[Thu Jul 30 12:18:50.495993 2026] [security2:error] [pid 703393:tid 703595] [client 20.100.203.84:48683] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amuHes637Arlr6Yb1EccSwAAAM0"]
[Thu Jul 30 12:18:50.740040 2026] [security2:error] [pid 703393:tid 703646] [client 20.63.98.115:47208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/acp.php"] [unique_id "amuHes637Arlr6Yb1EccUgAAAQA"]
[Thu Jul 30 12:18:50.850134 2026] [security2:error] [pid 703393:tid 703558] [client 20.91.199.21:35259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/lang-load-role.php"] [unique_id "amuHes637Arlr6Yb1EccVAAAAKg"]
[Thu Jul 30 12:18:50.850792 2026] [security2:error] [pid 703393:tid 703566] [client 20.100.203.84:48666] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.heatstickhk.com"] [uri "/___proxy_subdomain_cpanel/wp-includes/Text/"] [unique_id "amuHes637Arlr6Yb1EccUwAAALA"]
[Thu Jul 30 12:18:51.108016 2026] [security2:error] [pid 703393:tid 703530] [client 20.151.221.234:12809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/fm.php"] [unique_id "amuHe8637Arlr6Yb1EccXAAAAIw"]
[Thu Jul 30 12:18:51.199663 2026] [security2:error] [pid 703393:tid 703551] [client 20.100.203.84:48666] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.heatstickhk.com"] [uri "/___proxy_subdomain_cpanel/wp-content/uploads/"] [unique_id "amuHe8637Arlr6Yb1EccYAAAAKE"]
[Thu Jul 30 12:18:51.349789 2026] [security2:error] [pid 703393:tid 703616] [client 20.100.203.84:48666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-content/index.php"] [unique_id "amuHe8637Arlr6Yb1EccYQAAAOI"]
[Thu Jul 30 12:18:51.349897 2026] [security2:error] [pid 703393:tid 703616] [client 20.100.203.84:48666] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-content/index.php"] [unique_id "amuHe8637Arlr6Yb1EccYQAAAOI"]
[Thu Jul 30 12:18:51.486134 2026] [security2:error] [pid 703393:tid 703590] [client 172.213.232.128:23126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/plugins/about.php"] [unique_id "amuHe8637Arlr6Yb1EccYwAAAMg"]
[Thu Jul 30 12:18:51.631112 2026] [security2:error] [pid 703393:tid 703573] [client 20.91.199.21:46419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/link.php"] [unique_id "amuHe8637Arlr6Yb1EccZwAAALc"]
[Thu Jul 30 12:18:51.731409 2026] [security2:error] [pid 703393:tid 703623] [client 20.100.203.84:57678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/admin.php"] [unique_id "amuHe8637Arlr6Yb1EccawAAAOk"]
[Thu Jul 30 12:18:51.731509 2026] [security2:error] [pid 703393:tid 703623] [client 20.100.203.84:57678] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/admin.php"] [unique_id "amuHe8637Arlr6Yb1EccawAAAOk"]
[Thu Jul 30 12:18:51.856173 2026] [security2:error] [pid 703393:tid 703602] [client 51.120.79.193:11211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuHe8637Arlr6Yb1EccbAAAANQ"]
[Thu Jul 30 12:18:51.856331 2026] [security2:error] [pid 703393:tid 703602] [client 51.120.79.193:11211] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "progroup.jo"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuHe8637Arlr6Yb1EccbAAAANQ"]
[Thu Jul 30 12:18:52.054849 2026] [security2:error] [pid 703393:tid 703614] [client 20.100.203.84:43833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/177.php"] [unique_id "amuHfM637Arlr6Yb1EcccAAAAOA"]
[Thu Jul 30 12:18:52.054935 2026] [security2:error] [pid 703393:tid 703614] [client 20.100.203.84:43833] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/177.php"] [unique_id "amuHfM637Arlr6Yb1EcccAAAAOA"]
[Thu Jul 30 12:18:52.101179 2026] [security2:error] [pid 703393:tid 703594] [client 20.63.98.115:37993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/g.php"] [unique_id "amuHfM637Arlr6Yb1EcccQAAAMw"]
[Thu Jul 30 12:18:52.211696 2026] [security2:error] [pid 703393:tid 703560] [client 20.91.199.21:10745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/mar.php"] [unique_id "amuHfM637Arlr6Yb1EccegAAAKo"]
[Thu Jul 30 12:18:52.352396 2026] [security2:error] [pid 703393:tid 703557] [client 20.151.221.234:12848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/file.php"] [unique_id "amuHfM637Arlr6Yb1EccewAAAKc"]
[Thu Jul 30 12:18:52.376581 2026] [security2:error] [pid 703393:tid 703592] [client 20.100.203.84:48643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/199.php"] [unique_id "amuHfM637Arlr6Yb1EccfAAAAMo"]
[Thu Jul 30 12:18:52.376684 2026] [security2:error] [pid 703393:tid 703592] [client 20.100.203.84:48643] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/199.php"] [unique_id "amuHfM637Arlr6Yb1EccfAAAAMo"]
[Thu Jul 30 12:18:52.559790 2026] [core:notice] [pid 703393:tid 703597] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:18:52.764212 2026] [security2:error] [pid 703393:tid 703585] [client 20.100.203.84:43783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/file52.php"] [unique_id "amuHfM637Arlr6Yb1EcchAAAAMM"]
[Thu Jul 30 12:18:52.764379 2026] [security2:error] [pid 703393:tid 703585] [client 20.100.203.84:43783] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/file52.php"] [unique_id "amuHfM637Arlr6Yb1EcchAAAAMM"]
[Thu Jul 30 12:18:52.821413 2026] [security2:error] [pid 703393:tid 703626] [client 52.238.199.152:30084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/item.php"] [unique_id "amuHfM637Arlr6Yb1EcchQAAAOw"]
[Thu Jul 30 12:18:52.983046 2026] [security2:error] [pid 703393:tid 703565] [client 184.75.223.195:43378] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuHfM637Arlr6Yb1EcchgAAAK8"]
[Thu Jul 30 12:18:52.983139 2026] [security2:error] [pid 703393:tid 703565] [client 184.75.223.195:43378] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuHfM637Arlr6Yb1EcchgAAAK8"]
[Thu Jul 30 12:18:53.072127 2026] [security2:error] [pid 703393:tid 703646] [client 20.100.203.84:31806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/geck.php"] [unique_id "amuHfc637Arlr6Yb1EcchwAAAQA"]
[Thu Jul 30 12:18:53.072233 2026] [security2:error] [pid 703393:tid 703646] [client 20.100.203.84:31806] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/geck.php"] [unique_id "amuHfc637Arlr6Yb1EcchwAAAQA"]
[Thu Jul 30 12:18:53.131884 2026] [security2:error] [pid 703393:tid 703539] [client 20.91.199.21:46436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "amuHfc637Arlr6Yb1EccjAAAAJU"]
[Thu Jul 30 12:18:53.228574 2026] [security2:error] [pid 703393:tid 703556] [client 20.63.98.115:57317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/.well-known/caches.php"] [unique_id "amuHfc637Arlr6Yb1EccjwAAAKY"]
[Thu Jul 30 12:18:53.380758 2026] [security2:error] [pid 703393:tid 703569] [client 172.213.232.128:8263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp.php"] [unique_id "amuHfc637Arlr6Yb1EcckAAAALM"]
[Thu Jul 30 12:18:53.428798 2026] [security2:error] [pid 703393:tid 703609] [client 51.120.79.193:16077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuHfc637Arlr6Yb1EcckQAAANs"]
[Thu Jul 30 12:18:53.428943 2026] [security2:error] [pid 703393:tid 703609] [client 51.120.79.193:16077] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "progroup.jo"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuHfc637Arlr6Yb1EcckQAAANs"]
[Thu Jul 30 12:18:53.550633 2026] [security2:error] [pid 703393:tid 703586] [client 20.100.203.84:43826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/biufile.php"] [unique_id "amuHfc637Arlr6Yb1EcckgAAAMQ"]
[Thu Jul 30 12:18:53.550749 2026] [security2:error] [pid 703393:tid 703586] [client 20.100.203.84:43826] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/biufile.php"] [unique_id "amuHfc637Arlr6Yb1EcckgAAAMQ"]
[Thu Jul 30 12:18:53.872884 2026] [core:notice] [pid 703393:tid 703479] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:18:53.885109 2026] [security2:error] [pid 703393:tid 703602] [client 20.100.203.84:43780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/dejavu.php"] [unique_id "amuHfc637Arlr6Yb1EccmwAAANQ"]
[Thu Jul 30 12:18:53.885234 2026] [security2:error] [pid 703393:tid 703602] [client 20.100.203.84:43780] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/dejavu.php"] [unique_id "amuHfc637Arlr6Yb1EccmwAAANQ"]
[Thu Jul 30 12:18:54.212403 2026] [security2:error] [pid 703393:tid 703617] [client 20.100.203.84:57684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/aaf.php"] [unique_id "amuHfs637Arlr6Yb1EccpgAAAOM"]
[Thu Jul 30 12:18:54.212494 2026] [security2:error] [pid 703393:tid 703617] [client 20.100.203.84:57684] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/aaf.php"] [unique_id "amuHfs637Arlr6Yb1EccpgAAAOM"]
[Thu Jul 30 12:18:54.559334 2026] [security2:error] [pid 703393:tid 703627] [client 20.100.203.84:48645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/ha.php"] [unique_id "amuHfs637Arlr6Yb1EccpwAAAO0"]
[Thu Jul 30 12:18:54.559460 2026] [security2:error] [pid 703393:tid 703627] [client 20.100.203.84:48645] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/ha.php"] [unique_id "amuHfs637Arlr6Yb1EccpwAAAO0"]
[Thu Jul 30 12:18:54.703680 2026] [security2:error] [pid 703393:tid 703603] [client 20.63.98.115:20889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/classwithtostring.php"] [unique_id "amuHfs637Arlr6Yb1EccqwAAANU"]
[Thu Jul 30 12:18:54.875590 2026] [security2:error] [pid 703393:tid 703649] [client 20.100.203.84:57664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/hur.php"] [unique_id "amuHfs637Arlr6Yb1EccrwAAAQM"]
[Thu Jul 30 12:18:54.875703 2026] [security2:error] [pid 703393:tid 703649] [client 20.100.203.84:57664] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/hur.php"] [unique_id "amuHfs637Arlr6Yb1EccrwAAAQM"]
[Thu Jul 30 12:18:54.971400 2026] [security2:error] [pid 703393:tid 703541] [client 20.91.199.21:33624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "amuHfs637Arlr6Yb1EccsAAAAJc"]
[Thu Jul 30 12:18:55.207016 2026] [security2:error] [pid 703393:tid 703578] [client 20.100.203.84:57701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/h02ugyh.php"] [unique_id "amuHf8637Arlr6Yb1EcctgAAALw"]
[Thu Jul 30 12:18:55.207132 2026] [security2:error] [pid 703393:tid 703578] [client 20.100.203.84:57701] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/h02ugyh.php"] [unique_id "amuHf8637Arlr6Yb1EcctgAAALw"]
[Thu Jul 30 12:18:55.506489 2026] [security2:error] [pid 703393:tid 703624] [client 20.100.203.84:57684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/155.php"] [unique_id "amuHf8637Arlr6Yb1EccvQAAAOo"]
[Thu Jul 30 12:18:55.506592 2026] [security2:error] [pid 703393:tid 703624] [client 20.100.203.84:57684] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/155.php"] [unique_id "amuHf8637Arlr6Yb1EccvQAAAOo"]
[Thu Jul 30 12:18:55.615542 2026] [security2:error] [pid 703393:tid 703530] [client 51.120.79.193:11222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/media.php"] [unique_id "amuHf8637Arlr6Yb1EccvgAAAIw"]
[Thu Jul 30 12:18:55.615671 2026] [security2:error] [pid 703393:tid 703530] [client 51.120.79.193:11222] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "progroup.jo"] [uri "/media.php"] [unique_id "amuHf8637Arlr6Yb1EccvgAAAIw"]
[Thu Jul 30 12:18:55.892870 2026] [security2:error] [pid 703393:tid 703523] [client 20.100.203.84:43782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/ops.php"] [unique_id "amuHf8637Arlr6Yb1EccxwAAAIU"]
[Thu Jul 30 12:18:55.892971 2026] [security2:error] [pid 703393:tid 703523] [client 20.100.203.84:43782] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/ops.php"] [unique_id "amuHf8637Arlr6Yb1EccxwAAAIU"]
[Thu Jul 30 12:18:56.233653 2026] [security2:error] [pid 703393:tid 703602] [client 20.100.203.84:57725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/ingfo.php"] [unique_id "amuHgM637Arlr6Yb1EcczgAAANQ"]
[Thu Jul 30 12:18:56.233784 2026] [security2:error] [pid 703393:tid 703602] [client 20.100.203.84:57725] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/ingfo.php"] [unique_id "amuHgM637Arlr6Yb1EcczgAAANQ"]
[Thu Jul 30 12:18:56.437432 2026] [security2:error] [pid 703393:tid 703631] [client 20.63.98.115:57340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/css/about.php"] [unique_id "amuHgM637Arlr6Yb1Ecc3AAAAPE"]
[Thu Jul 30 12:18:56.510584 2026] [security2:error] [pid 703393:tid 703627] [client 20.151.221.234:4395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/bolt.php"] [unique_id "amuHgM637Arlr6Yb1Ecc3QAAAO0"]
[Thu Jul 30 12:18:56.563798 2026] [security2:error] [pid 703393:tid 703536] [client 172.213.232.128:1123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/aaa.php"] [unique_id "amuHgM637Arlr6Yb1Ecc4QAAAJI"]
[Thu Jul 30 12:18:56.594700 2026] [security2:error] [pid 703393:tid 703610] [client 20.100.203.84:48688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/error_log.php"] [unique_id "amuHgM637Arlr6Yb1Ecc4gAAANw"]
[Thu Jul 30 12:18:56.594877 2026] [security2:error] [pid 703393:tid 703610] [client 20.100.203.84:48688] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/error_log.php"] [unique_id "amuHgM637Arlr6Yb1Ecc4gAAANw"]
[Thu Jul 30 12:18:56.644248 2026] [security2:error] [pid 703393:tid 703505] [remote 52.167.144.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "emmanueljrodriguez.com"] [uri "/index.php"] [unique_id "amuHf8637Arlr6Yb1EccwwAAum8"]
[Thu Jul 30 12:18:56.868901 2026] [security2:error] [pid 703393:tid 703546] [client 20.91.199.21:35246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/plugins.php"] [unique_id "amuHgM637Arlr6Yb1Ecc7AAAAJw"]
[Thu Jul 30 12:18:56.911402 2026] [security2:error] [pid 703393:tid 703561] [client 51.120.79.193:10686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/images.php"] [unique_id "amuHgM637Arlr6Yb1Ecc7gAAAKs"]
[Thu Jul 30 12:18:56.911488 2026] [security2:error] [pid 703393:tid 703561] [client 51.120.79.193:10686] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "progroup.jo"] [uri "/images.php"] [unique_id "amuHgM637Arlr6Yb1Ecc7gAAAKs"]
[Thu Jul 30 12:18:56.945327 2026] [security2:error] [pid 703393:tid 703629] [client 20.100.203.84:57708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/koala.php"] [unique_id "amuHgM637Arlr6Yb1Ecc7wAAAO8"]
[Thu Jul 30 12:18:56.945428 2026] [security2:error] [pid 703393:tid 703629] [client 20.100.203.84:57708] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/koala.php"] [unique_id "amuHgM637Arlr6Yb1Ecc7wAAAO8"]
[Thu Jul 30 12:18:57.201347 2026] [security2:error] [pid 703393:tid 703577] [client 172.213.232.128:8314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/hoot.php"] [unique_id "amuHgc637Arlr6Yb1Ecc8AAAALs"]
[Thu Jul 30 12:18:57.249080 2026] [security2:error] [pid 703393:tid 703619] [client 20.100.203.84:48679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/mac.php"] [unique_id "amuHgc637Arlr6Yb1Ecc8QAAAOU"]
[Thu Jul 30 12:18:57.249195 2026] [security2:error] [pid 703393:tid 703619] [client 20.100.203.84:48679] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/mac.php"] [unique_id "amuHgc637Arlr6Yb1Ecc8QAAAOU"]
[Thu Jul 30 12:18:57.475945 2026] [security2:error] [pid 703393:tid 703560] [client 2a03:2880:f800:25:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuHgM637Arlr6Yb1Ecc6AAAqkw"]
[Thu Jul 30 12:18:57.523754 2026] [security2:error] [pid 703393:tid 703533] [client 20.151.221.234:44151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/3.php"] [unique_id "amuHgc637Arlr6Yb1Ecc-gAAAI8"]
[Thu Jul 30 12:18:57.551241 2026] [security2:error] [pid 703393:tid 703615] [client 20.100.203.84:57675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/wefile.php"] [unique_id "amuHgc637Arlr6Yb1Ecc-wAAAOE"]
[Thu Jul 30 12:18:57.551336 2026] [security2:error] [pid 703393:tid 703615] [client 20.100.203.84:57675] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/wefile.php"] [unique_id "amuHgc637Arlr6Yb1Ecc-wAAAOE"]
[Thu Jul 30 12:18:57.680924 2026] [security2:error] [pid 703393:tid 703620] [client 43.173.181.200:56552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.181.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/07/14/soldes-ete-2012-30-paires-de-chaussures-a-moins-de-100e/feed/"] [unique_id "amuHgc637Arlr6Yb1Ecc-AAAAOY"]
[Thu Jul 30 12:18:57.710536 2026] [security2:error] [pid 703393:tid 703543] [client 43.173.173.140:48750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.173.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2017/03/12/sostrene-grene-printemps-2017/"] [unique_id "amuHgc637Arlr6Yb1Ecc-QAAAJk"]
[Thu Jul 30 12:18:57.894399 2026] [security2:error] [pid 703393:tid 703613] [client 20.100.203.84:57720] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.heatstickhk.com"] [uri "/___proxy_subdomain_cpanel/wp-includes/blocks/post-comments-form/"] [unique_id "amuHgc637Arlr6Yb1EcdCAAAAN8"]
[Thu Jul 30 12:18:57.946916 2026] [security2:error] [pid 703393:tid 703638] [client 47.128.121.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuHgc637Arlr6Yb1EcdAQAAAPg"]
[Thu Jul 30 12:18:58.184598 2026] [core:notice] [pid 703393:tid 703591] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:18:58.189196 2026] [security2:error] [pid 703393:tid 703591] [client 43.172.198.9:34386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/07/14/soldes-ete-2012-30-paires-de-chaussures-a-moins-de-100e/feed/"] [unique_id "amuHgs637Arlr6Yb1EcdCgAAAMk"], referer: https://carnetdeshopping.com/index.php/2012/07/14/soldes-ete-2012-30-paires-de-chaussures-a-moins-de-100e/feed/
[Thu Jul 30 12:18:58.227442 2026] [security2:error] [pid 703393:tid 703542] [client 20.100.203.84:57720] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.heatstickhk.com"] [uri "/___proxy_subdomain_cpanel/wp-admin/js/"] [unique_id "amuHgs637Arlr6Yb1EcdCwAAAJg"]
[Thu Jul 30 12:18:58.380340 2026] [security2:error] [pid 703393:tid 703597] [client 20.100.203.84:57720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/makeasmtp.php"] [unique_id "amuHgs637Arlr6Yb1EcdDwAAAM8"]
[Thu Jul 30 12:18:58.380422 2026] [security2:error] [pid 703393:tid 703597] [client 20.100.203.84:57720] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/makeasmtp.php"] [unique_id "amuHgs637Arlr6Yb1EcdDwAAAM8"]
[Thu Jul 30 12:18:58.397245 2026] [core:notice] [pid 703393:tid 703643] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:18:58.401844 2026] [security2:error] [pid 703393:tid 703643] [client 43.173.177.180:51950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2017/03/12/sostrene-grene-printemps-2017/"] [unique_id "amuHgs637Arlr6Yb1EcdEAAAAP0"], referer: https://carnetdeshopping.com/index.php/2017/03/12/sostrene-grene-printemps-2017/
[Thu Jul 30 12:18:58.423374 2026] [security2:error] [pid 703393:tid 703570] [client 4.225.166.222:29222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuHgs637Arlr6Yb1EcdEQAAALQ"]
[Thu Jul 30 12:18:58.423479 2026] [security2:error] [pid 703393:tid 703570] [client 4.225.166.222:29222] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuHgs637Arlr6Yb1EcdEQAAALQ"]
[Thu Jul 30 12:18:58.579811 2026] [security2:error] [pid 703393:tid 703592] [client 20.151.221.234:44778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/222.php"] [unique_id "amuHgs637Arlr6Yb1EcdFQAAAMo"]
[Thu Jul 30 12:18:58.732264 2026] [security2:error] [pid 703393:tid 703574] [client 20.100.203.84:57713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/2P.php"] [unique_id "amuHgs637Arlr6Yb1EcdFgAAALg"]
[Thu Jul 30 12:18:58.732394 2026] [security2:error] [pid 703393:tid 703574] [client 20.100.203.84:57713] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/2P.php"] [unique_id "amuHgs637Arlr6Yb1EcdFgAAALg"]
[Thu Jul 30 12:18:58.764144 2026] [security2:error] [pid 703393:tid 703626] [client 51.120.79.193:11251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/adminner.php"] [unique_id "amuHgs637Arlr6Yb1EcdFwAAAOw"]
[Thu Jul 30 12:18:58.764235 2026] [security2:error] [pid 703393:tid 703626] [client 51.120.79.193:11251] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "progroup.jo"] [uri "/adminner.php"] [unique_id "amuHgs637Arlr6Yb1EcdFwAAAOw"]
[Thu Jul 30 12:18:58.845637 2026] [security2:error] [pid 703393:tid 703554] [client 20.63.98.115:62698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/files/index.php"] [unique_id "amuHgs637Arlr6Yb1EcdHAAAAKQ"]
[Thu Jul 30 12:18:58.886244 2026] [security2:error] [pid 703393:tid 703561] [client 4.225.166.222:46286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuHgs637Arlr6Yb1EcdHQAAAKs"]
[Thu Jul 30 12:18:58.886345 2026] [security2:error] [pid 703393:tid 703561] [client 4.225.166.222:46286] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuHgs637Arlr6Yb1EcdHQAAAKs"]
[Thu Jul 30 12:18:59.038520 2026] [security2:error] [pid 703393:tid 703624] [client 20.100.203.84:34659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/.well-known/about.php"] [unique_id "amuHg8637Arlr6Yb1EcdIQAAAOo"]
[Thu Jul 30 12:18:59.038629 2026] [security2:error] [pid 703393:tid 703624] [client 20.100.203.84:34659] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/.well-known/about.php"] [unique_id "amuHg8637Arlr6Yb1EcdIQAAAOo"]
[Thu Jul 30 12:18:59.170470 2026] [security2:error] [pid 703393:tid 703589] [client 20.91.199.21:46443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/post.php"] [unique_id "amuHg8637Arlr6Yb1EcdJwAAAMc"]
[Thu Jul 30 12:18:59.204998 2026] [security2:error] [pid 703393:tid 703644] [client 4.225.166.222:59013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/x.php"] [unique_id "amuHg8637Arlr6Yb1EcdKAAAAP4"]
[Thu Jul 30 12:18:59.205132 2026] [security2:error] [pid 703393:tid 703644] [client 4.225.166.222:59013] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/x.php"] [unique_id "amuHg8637Arlr6Yb1EcdKAAAAP4"]
[Thu Jul 30 12:18:59.217669 2026] [security2:error] [pid 703393:tid 703599] [client 57.141.0.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuHg8637Arlr6Yb1EcdJAAAANE"]
[Thu Jul 30 12:18:59.349453 2026] [security2:error] [pid 703393:tid 703618] [client 20.100.203.84:34668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuHg8637Arlr6Yb1EcdKwAAAOQ"]
[Thu Jul 30 12:18:59.349552 2026] [security2:error] [pid 703393:tid 703618] [client 20.100.203.84:34668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuHg8637Arlr6Yb1EcdKwAAAOQ"]
[Thu Jul 30 12:18:59.589747 2026] [security2:error] [pid 703393:tid 703635] [client 4.225.166.222:29189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/mgrr.php"] [unique_id "amuHg8637Arlr6Yb1EcdMQAAAPU"]
[Thu Jul 30 12:18:59.589847 2026] [security2:error] [pid 703393:tid 703635] [client 4.225.166.222:29189] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/mgrr.php"] [unique_id "amuHg8637Arlr6Yb1EcdMQAAAPU"]
[Thu Jul 30 12:18:59.699352 2026] [security2:error] [pid 703393:tid 703617] [client 20.100.203.84:57689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/system_log.php"] [unique_id "amuHg8637Arlr6Yb1EcdNAAAAOM"]
[Thu Jul 30 12:18:59.699450 2026] [security2:error] [pid 703393:tid 703617] [client 20.100.203.84:57689] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/system_log.php"] [unique_id "amuHg8637Arlr6Yb1EcdNAAAAOM"]
[Thu Jul 30 12:19:00.054716 2026] [security2:error] [pid 703393:tid 703567] [client 20.100.203.84:48700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.heatstickhk.com"] [uri "/___proxy_subdomain_cpanel/wp-admin/css/"] [unique_id "amuHhM637Arlr6Yb1EcdOgAAALE"]
[Thu Jul 30 12:19:00.118658 2026] [security2:error] [pid 703393:tid 703627] [client 4.225.166.222:29216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/domvf.php"] [unique_id "amuHhM637Arlr6Yb1EcdPQAAAO0"]
[Thu Jul 30 12:19:00.118758 2026] [security2:error] [pid 703393:tid 703627] [client 4.225.166.222:29216] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/domvf.php"] [unique_id "amuHhM637Arlr6Yb1EcdPQAAAO0"]
[Thu Jul 30 12:19:00.332879 2026] [security2:error] [pid 703393:tid 703603] [client 51.120.79.193:11242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/admin.php"] [unique_id "amuHhM637Arlr6Yb1EcdPwAAANU"]
[Thu Jul 30 12:19:00.333012 2026] [security2:error] [pid 703393:tid 703603] [client 51.120.79.193:11242] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "progroup.jo"] [uri "/admin.php"] [unique_id "amuHhM637Arlr6Yb1EcdPwAAANU"]
[Thu Jul 30 12:19:00.396396 2026] [security2:error] [pid 703393:tid 703568] [client 20.100.203.84:48700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.heatstickhk.com"] [uri "/___proxy_subdomain_cpanel/wp-admin/css/colors/modern/"] [unique_id "amuHhM637Arlr6Yb1EcdQAAAALI"]
[Thu Jul 30 12:19:00.535718 2026] [security2:error] [pid 703393:tid 703592] [client 4.225.166.222:59068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/yup.php"] [unique_id "amuHhM637Arlr6Yb1EcdSAAAAMo"]
[Thu Jul 30 12:19:00.535826 2026] [security2:error] [pid 703393:tid 703592] [client 4.225.166.222:59068] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/yup.php"] [unique_id "amuHhM637Arlr6Yb1EcdSAAAAMo"]
[Thu Jul 30 12:19:00.547017 2026] [security2:error] [pid 703393:tid 703622] [client 20.100.203.84:48700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/crgio.php"] [unique_id "amuHhM637Arlr6Yb1EcdSQAAAOg"]
[Thu Jul 30 12:19:00.547175 2026] [security2:error] [pid 703393:tid 703622] [client 20.100.203.84:48700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/crgio.php"] [unique_id "amuHhM637Arlr6Yb1EcdSQAAAOg"]
[Thu Jul 30 12:19:00.564647 2026] [security2:error] [pid 703393:tid 703640] [client 20.151.221.234:44750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amuHhM637Arlr6Yb1EcdTAAAAPo"]
[Thu Jul 30 12:19:00.815971 2026] [security2:error] [pid 703393:tid 703639] [client 52.238.199.152:30131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/app.php"] [unique_id "amuHhM637Arlr6Yb1EcdTwAAAPk"]
[Thu Jul 30 12:19:00.851232 2026] [security2:error] [pid 703393:tid 703621] [client 20.100.203.84:48668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/pucci.php"] [unique_id "amuHhM637Arlr6Yb1EcdUAAAAOc"]
[Thu Jul 30 12:19:00.851324 2026] [security2:error] [pid 703393:tid 703621] [client 20.100.203.84:48668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/pucci.php"] [unique_id "amuHhM637Arlr6Yb1EcdUAAAAOc"]
[Thu Jul 30 12:19:01.075826 2026] [security2:error] [pid 703393:tid 703539] [client 51.120.79.193:10796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/ops.php"] [unique_id "amuHhc637Arlr6Yb1EcdVQAAAJU"]
[Thu Jul 30 12:19:01.075924 2026] [security2:error] [pid 703393:tid 703539] [client 51.120.79.193:10796] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "progroup.jo"] [uri "/ops.php"] [unique_id "amuHhc637Arlr6Yb1EcdVQAAAJU"]
[Thu Jul 30 12:19:01.195303 2026] [security2:error] [pid 703393:tid 703606] [client 20.100.203.84:34628] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.heatstickhk.com"] [uri "/___proxy_subdomain_cpanel/wp-includes/blocks/details/"] [unique_id "amuHhc637Arlr6Yb1EcdWgAAANg"]
[Thu Jul 30 12:19:01.208058 2026] [security2:error] [pid 703393:tid 703588] [client 4.225.166.222:59018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/X.php"] [unique_id "amuHhc637Arlr6Yb1EcdXAAAAMY"]
[Thu Jul 30 12:19:01.208165 2026] [security2:error] [pid 703393:tid 703588] [client 4.225.166.222:59018] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/X.php"] [unique_id "amuHhc637Arlr6Yb1EcdXAAAAMY"]
[Thu Jul 30 12:19:01.432231 2026] [security2:error] [pid 703393:tid 703604] [client 20.91.199.21:33605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/shell.php"] [unique_id "amuHhc637Arlr6Yb1EcdYQAAANY"]
[Thu Jul 30 12:19:01.525998 2026] [security2:error] [pid 703393:tid 703623] [client 4.225.166.222:59071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amuHhc637Arlr6Yb1EcdZwAAAOk"]
[Thu Jul 30 12:19:01.526103 2026] [security2:error] [pid 703393:tid 703623] [client 4.225.166.222:59071] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amuHhc637Arlr6Yb1EcdZwAAAOk"]
[Thu Jul 30 12:19:01.531605 2026] [security2:error] [pid 703393:tid 703635] [client 20.100.203.84:34628] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.heatstickhk.com"] [uri "/___proxy_subdomain_cpanel/wp-includes/blocks/audio/"] [unique_id "amuHhc637Arlr6Yb1EcdZQAAAPU"]
[Thu Jul 30 12:19:01.588130 2026] [security2:error] [pid 703393:tid 703533] [client 20.151.221.234:44100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amuHhc637Arlr6Yb1EcdaQAAAI8"]
[Thu Jul 30 12:19:01.682815 2026] [security2:error] [pid 703393:tid 703631] [client 20.100.203.84:34628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-temp.php"] [unique_id "amuHhc637Arlr6Yb1EcdbAAAAPE"]
[Thu Jul 30 12:19:01.682955 2026] [security2:error] [pid 703393:tid 703631] [client 20.100.203.84:34628] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-temp.php"] [unique_id "amuHhc637Arlr6Yb1EcdbAAAAPE"]
[Thu Jul 30 12:19:01.777349 2026] [security2:error] [pid 703393:tid 703587] [client 38.190.144.4:58079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuHhc637Arlr6Yb1EcdZgAAAMU"]
[Thu Jul 30 12:19:01.777565 2026] [security2:error] [pid 703393:tid 703587] [client 38.190.144.4:58079] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuHhc637Arlr6Yb1EcdZgAAAMU"]
[Thu Jul 30 12:19:01.829479 2026] [security2:error] [pid 703393:tid 703611] [client 52.167.144.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuHhc637Arlr6Yb1EcdZAAAAN0"]
[Thu Jul 30 12:19:01.850456 2026] [security2:error] [pid 703393:tid 703534] [client 195.113.175.167:35785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.175.113.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/aboutf.php"] [unique_id "amuHhc637Arlr6Yb1EcdbQAAAJA"]
[Thu Jul 30 12:19:01.941212 2026] [security2:error] [pid 703393:tid 703536] [client 4.225.166.222:46294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/gec.php"] [unique_id "amuHhc637Arlr6Yb1EcddAAAAJI"]
[Thu Jul 30 12:19:01.941330 2026] [security2:error] [pid 703393:tid 703536] [client 4.225.166.222:46294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/gec.php"] [unique_id "amuHhc637Arlr6Yb1EcddAAAAJI"]
[Thu Jul 30 12:19:02.021182 2026] [security2:error] [pid 703393:tid 703568] [client 20.100.203.84:43790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuHhs637Arlr6Yb1EcddQAAALI"]
[Thu Jul 30 12:19:02.021302 2026] [security2:error] [pid 703393:tid 703568] [client 20.100.203.84:43790] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuHhs637Arlr6Yb1EcddQAAALI"]
[Thu Jul 30 12:19:02.060269 2026] [security2:error] [pid 703393:tid 703627] [client 57.141.0.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuHhc637Arlr6Yb1EcdcwAAAO0"]
[Thu Jul 30 12:19:02.252290 2026] [security2:error] [pid 703393:tid 703615] [client 20.63.98.115:62677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "amuHhs637Arlr6Yb1EcdfAAAAOE"]
[Thu Jul 30 12:19:02.282819 2026] [security2:error] [pid 703393:tid 703578] [client 4.225.166.222:59028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/sky.php"] [unique_id "amuHhs637Arlr6Yb1EcdfQAAALw"]
[Thu Jul 30 12:19:02.282931 2026] [security2:error] [pid 703393:tid 703578] [client 4.225.166.222:59028] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/sky.php"] [unique_id "amuHhs637Arlr6Yb1EcdfQAAALw"]
[Thu Jul 30 12:19:02.407177 2026] [security2:error] [pid 703393:tid 703579] [client 20.100.203.84:48665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/puc.php"] [unique_id "amuHhs637Arlr6Yb1EcdfgAAAL0"]
[Thu Jul 30 12:19:02.407304 2026] [security2:error] [pid 703393:tid 703579] [client 20.100.203.84:48665] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/puc.php"] [unique_id "amuHhs637Arlr6Yb1EcdfgAAAL0"]
[Thu Jul 30 12:19:02.634512 2026] [security2:error] [pid 703393:tid 703556] [client 51.120.79.193:10810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/mac.php"] [unique_id "amuHhs637Arlr6Yb1EcdhAAAAKY"]
[Thu Jul 30 12:19:02.634605 2026] [security2:error] [pid 703393:tid 703556] [client 51.120.79.193:10810] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "progroup.jo"] [uri "/mac.php"] [unique_id "amuHhs637Arlr6Yb1EcdhAAAAKY"]
[Thu Jul 30 12:19:02.649121 2026] [security2:error] [pid 703393:tid 703551] [client 4.225.166.222:59051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/fffm.php"] [unique_id "amuHhs637Arlr6Yb1EcdhQAAAKE"]
[Thu Jul 30 12:19:02.649200 2026] [security2:error] [pid 703393:tid 703551] [client 4.225.166.222:59051] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/fffm.php"] [unique_id "amuHhs637Arlr6Yb1EcdhQAAAKE"]
[Thu Jul 30 12:19:02.734215 2026] [security2:error] [pid 703393:tid 703644] [client 20.100.203.84:43824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/dx.php"] [unique_id "amuHhs637Arlr6Yb1EcdiQAAAP4"]
[Thu Jul 30 12:19:02.734363 2026] [security2:error] [pid 703393:tid 703644] [client 20.100.203.84:43824] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/dx.php"] [unique_id "amuHhs637Arlr6Yb1EcdiQAAAP4"]
[Thu Jul 30 12:19:02.743034 2026] [security2:error] [pid 703393:tid 703619] [client 20.151.221.234:44752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-content/admin.php"] [unique_id "amuHhs637Arlr6Yb1EcdigAAAOU"]
[Thu Jul 30 12:19:02.950555 2026] [security2:error] [pid 703393:tid 703586] [client 20.91.199.21:10323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/ssl.php"] [unique_id "amuHhs637Arlr6Yb1EcdiwAAAMQ"]
[Thu Jul 30 12:19:03.139698 2026] [security2:error] [pid 703393:tid 703623] [client 20.100.203.84:43803] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.heatstickhk.com"] [uri "/___proxy_subdomain_cpanel/wp-includes/Requests/"] [unique_id "amuHh8637Arlr6Yb1EcdkgAAAOk"]
[Thu Jul 30 12:19:03.178971 2026] [security2:error] [pid 703393:tid 703533] [client 4.225.166.222:46276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/sixxis.php"] [unique_id "amuHh8637Arlr6Yb1EcdkwAAAI8"]
[Thu Jul 30 12:19:03.179076 2026] [security2:error] [pid 703393:tid 703533] [client 4.225.166.222:46276] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/sixxis.php"] [unique_id "amuHh8637Arlr6Yb1EcdkwAAAI8"]
[Thu Jul 30 12:19:03.444664 2026] [security2:error] [pid 703393:tid 703611] [client 20.100.203.84:43803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/7.php"] [unique_id "amuHh8637Arlr6Yb1EcdmAAAAN0"]
[Thu Jul 30 12:19:03.444778 2026] [security2:error] [pid 703393:tid 703611] [client 20.100.203.84:43803] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/7.php"] [unique_id "amuHh8637Arlr6Yb1EcdmAAAAN0"]
[Thu Jul 30 12:19:03.512041 2026] [security2:error] [pid 703393:tid 703572] [client 66.249.68.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.dapperdangolf.com"] [uri "/index.php"] [unique_id "amuHhc637Arlr6Yb1EcdVAAAALY"]
[Thu Jul 30 12:19:03.575918 2026] [security2:error] [pid 703393:tid 703608] [client 20.151.221.234:44119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-configs.php"] [unique_id "amuHh8637Arlr6Yb1EcdnQAAANo"]
[Thu Jul 30 12:19:03.576517 2026] [security2:error] [pid 703393:tid 703625] [client 4.225.166.222:59035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/yj09.php"] [unique_id "amuHh8637Arlr6Yb1EcdngAAAOs"]
[Thu Jul 30 12:19:03.576632 2026] [security2:error] [pid 703393:tid 703625] [client 4.225.166.222:59035] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/yj09.php"] [unique_id "amuHh8637Arlr6Yb1EcdngAAAOs"]
[Thu Jul 30 12:19:03.686056 2026] [security2:error] [pid 703393:tid 703557] [client 87.101.92.171:36314] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuHh8637Arlr6Yb1EcdnwAAAKc"]
[Thu Jul 30 12:19:03.686158 2026] [security2:error] [pid 703393:tid 703557] [client 87.101.92.171:36314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuHh8637Arlr6Yb1EcdnwAAAKc"]
[Thu Jul 30 12:19:03.719301 2026] [security2:error] [pid 703393:tid 703540] [client 20.63.98.115:61366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/network/admin.php"] [unique_id "amuHh8637Arlr6Yb1EcdoAAAAJY"]
[Thu Jul 30 12:19:03.737330 2026] [security2:error] [pid 703393:tid 703600] [client 43.173.181.235:35478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.181.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/01/19/sarah-jessica-parker-devoile-sa-premiere-collection-de-chaussures/"] [unique_id "amuHh8637Arlr6Yb1EcdnAAAANI"]
[Thu Jul 30 12:19:03.791770 2026] [security2:error] [pid 703393:tid 703568] [client 20.100.203.84:43806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/8.php"] [unique_id "amuHh8637Arlr6Yb1EcdpAAAALI"]
[Thu Jul 30 12:19:03.791898 2026] [security2:error] [pid 703393:tid 703568] [client 20.100.203.84:43806] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/8.php"] [unique_id "amuHh8637Arlr6Yb1EcdpAAAALI"]
[Thu Jul 30 12:19:03.890269 2026] [security2:error] [pid 703393:tid 703527] [client 4.225.166.222:46299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/k.php"] [unique_id "amuHh8637Arlr6Yb1EcdpQAAAIk"]
[Thu Jul 30 12:19:03.890377 2026] [security2:error] [pid 703393:tid 703527] [client 4.225.166.222:46299] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/k.php"] [unique_id "amuHh8637Arlr6Yb1EcdpQAAAIk"]
[Thu Jul 30 12:19:04.018393 2026] [security2:error] [pid 703393:tid 703607] [client 20.91.199.21:34997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/sx.php"] [unique_id "amuHiM637Arlr6Yb1EcdqQAAANk"]
[Thu Jul 30 12:19:04.179037 2026] [security2:error] [pid 703393:tid 703581] [client 52.238.199.152:30113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/k.php"] [unique_id "amuHiM637Arlr6Yb1EcdrQAAAL8"]
[Thu Jul 30 12:19:04.191893 2026] [security2:error] [pid 703393:tid 703633] [client 20.100.203.84:43799] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.heatstickhk.com"] [uri "/1.php"] [unique_id "amuHiM637Arlr6Yb1EcdsAAAAPM"]
[Thu Jul 30 12:19:04.192003 2026] [security2:error] [pid 703393:tid 703633] [client 20.100.203.84:43799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/1.php"] [unique_id "amuHiM637Arlr6Yb1EcdsAAAAPM"]
[Thu Jul 30 12:19:04.192080 2026] [security2:error] [pid 703393:tid 703633] [client 20.100.203.84:43799] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/1.php"] [unique_id "amuHiM637Arlr6Yb1EcdsAAAAPM"]
[Thu Jul 30 12:19:04.192745 2026] [security2:error] [pid 703393:tid 703583] [client 51.120.79.193:10664] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "progroup.jo"] [uri "/cgi-sys/404.html"] [unique_id "amuHiM637Arlr6Yb1EcdrwAAAME"]
[Thu Jul 30 12:19:04.508851 2026] [http2:info] [pid 727775:tid 727775] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 12:19:04.524253 2026] [security2:error] [pid 727775:tid 727905] [client 20.100.203.84:57676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/about.php"] [unique_id "amuHiMDCZkc4BvDXnoC2pAAAAAA"]
[Thu Jul 30 12:19:04.524462 2026] [security2:error] [pid 727775:tid 727905] [client 20.100.203.84:57676] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/about.php"] [unique_id "amuHiMDCZkc4BvDXnoC2pAAAAAA"]
[Thu Jul 30 12:19:04.583039 2026] [core:notice] [pid 727775:tid 727909] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:19:04.590668 2026] [security2:error] [pid 727775:tid 727909] [client 43.173.174.253:37836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/01/19/sarah-jessica-parker-devoile-sa-premiere-collection-de-chaussures/"] [unique_id "amuHiMDCZkc4BvDXnoC2pwAAAAQ"], referer: https://carnetdeshopping.com/index.php/2014/01/19/sarah-jessica-parker-devoile-sa-premiere-collection-de-chaussures/?replytocom=1041
[Thu Jul 30 12:19:04.622100 2026] [security2:error] [pid 727775:tid 727913] [client 4.225.166.222:29204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/k2.php"] [unique_id "amuHiMDCZkc4BvDXnoC2qAAAAAg"]
[Thu Jul 30 12:19:04.622435 2026] [security2:error] [pid 727775:tid 727913] [client 4.225.166.222:29204] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/k2.php"] [unique_id "amuHiMDCZkc4BvDXnoC2qAAAAAg"]
[Thu Jul 30 12:19:04.847696 2026] [security2:error] [pid 727775:tid 727926] [client 20.100.203.84:43786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/admin.php"] [unique_id "amuHiMDCZkc4BvDXnoC2sAAAABU"]
[Thu Jul 30 12:19:04.848122 2026] [security2:error] [pid 727775:tid 727926] [client 20.100.203.84:43786] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/admin.php"] [unique_id "amuHiMDCZkc4BvDXnoC2sAAAABU"]
[Thu Jul 30 12:19:04.966999 2026] [security2:error] [pid 727775:tid 727911] [client 20.91.199.21:46444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/themes.php"] [unique_id "amuHiMDCZkc4BvDXnoC2sQAAAAY"]
[Thu Jul 30 12:19:05.012265 2026] [security2:error] [pid 727775:tid 727906] [client 20.151.221.234:44761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/php.php"] [unique_id "amuHiMDCZkc4BvDXnoC2tAAAAAE"]
[Thu Jul 30 12:19:05.190434 2026] [security2:error] [pid 727775:tid 727912] [client 57.141.0.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuHiMDCZkc4BvDXnoC2pgAAAAc"]
[Thu Jul 30 12:19:05.229780 2026] [security2:error] [pid 727775:tid 727950] [client 20.100.203.84:57705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/edit.php"] [unique_id "amuHicDCZkc4BvDXnoC2uwAAAC0"]
[Thu Jul 30 12:19:05.229920 2026] [security2:error] [pid 727775:tid 727950] [client 20.100.203.84:57705] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/edit.php"] [unique_id "amuHicDCZkc4BvDXnoC2uwAAAC0"]
[Thu Jul 30 12:19:05.279189 2026] [security2:error] [pid 727775:tid 727951] [client 4.225.166.222:29200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/w.php"] [unique_id "amuHicDCZkc4BvDXnoC2vAAAAC4"]
[Thu Jul 30 12:19:05.279323 2026] [security2:error] [pid 727775:tid 727951] [client 4.225.166.222:29200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/w.php"] [unique_id "amuHicDCZkc4BvDXnoC2vAAAAC4"]
[Thu Jul 30 12:19:05.439437 2026] [security2:error] [pid 727775:tid 727907] [client 20.63.98.115:20512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/Requests/about.php"] [unique_id "amuHicDCZkc4BvDXnoC2xAAAAAI"]
[Thu Jul 30 12:19:05.533262 2026] [security2:error] [pid 727775:tid 727967] [client 20.100.203.84:48693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-content/admin.php"] [unique_id "amuHicDCZkc4BvDXnoC2xQAAAD4"]
[Thu Jul 30 12:19:05.533529 2026] [security2:error] [pid 727775:tid 727967] [client 20.100.203.84:48693] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-content/admin.php"] [unique_id "amuHicDCZkc4BvDXnoC2xQAAAD4"]
[Thu Jul 30 12:19:05.607648 2026] [security2:error] [pid 727775:tid 727972] [client 4.225.166.222:59058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/fpwch.php"] [unique_id "amuHicDCZkc4BvDXnoC2yQAAAEM"]
[Thu Jul 30 12:19:05.607828 2026] [security2:error] [pid 727775:tid 727972] [client 4.225.166.222:59058] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/fpwch.php"] [unique_id "amuHicDCZkc4BvDXnoC2yQAAAEM"]
[Thu Jul 30 12:19:05.652968 2026] [security2:error] [pid 727775:tid 727935] [client 57.141.0.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuHicDCZkc4BvDXnoC2uAAAAB4"]
[Thu Jul 30 12:19:05.770258 2026] [security2:error] [pid 727775:tid 727971] [client 20.151.221.234:12860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-includes/index.php"] [unique_id "amuHicDCZkc4BvDXnoC2zgAAAEI"]
[Thu Jul 30 12:19:05.775556 2026] [security2:error] [pid 727775:tid 727986] [client 51.120.79.193:10683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/pucci.php"] [unique_id "amuHicDCZkc4BvDXnoC2zwAAAFE"]
[Thu Jul 30 12:19:05.775664 2026] [security2:error] [pid 727775:tid 727986] [client 51.120.79.193:10683] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "progroup.jo"] [uri "/pucci.php"] [unique_id "amuHicDCZkc4BvDXnoC2zwAAAFE"]
[Thu Jul 30 12:19:05.891480 2026] [security2:error] [pid 727775:tid 727996] [client 20.100.203.84:57672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/inputs.php"] [unique_id "amuHicDCZkc4BvDXnoC21wAAAFs"]
[Thu Jul 30 12:19:05.891639 2026] [security2:error] [pid 727775:tid 727996] [client 20.100.203.84:57672] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/inputs.php"] [unique_id "amuHicDCZkc4BvDXnoC21wAAAFs"]
[Thu Jul 30 12:19:05.937784 2026] [security2:error] [pid 727775:tid 727927] [client 172.213.232.128:23134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/about.php"] [unique_id "amuHicDCZkc4BvDXnoC22wAAABY"]
[Thu Jul 30 12:19:05.970992 2026] [security2:error] [pid 727775:tid 728007] [client 4.225.166.222:46292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/w2025.php"] [unique_id "amuHicDCZkc4BvDXnoC23QAAAGY"]
[Thu Jul 30 12:19:05.971090 2026] [security2:error] [pid 727775:tid 728007] [client 4.225.166.222:46292] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/w2025.php"] [unique_id "amuHicDCZkc4BvDXnoC23QAAAGY"]
[Thu Jul 30 12:19:06.023214 2026] [core:notice] [pid 727775:tid 727789] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:19:06.028748 2026] [security2:error] [pid 727775:tid 728011] [client 127.0.0.1:18848] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuHisDCZkc4BvDXnoC23wAAAGo"]
[Thu Jul 30 12:19:06.028831 2026] [security2:error] [pid 727775:tid 727987] [client 74.7.241.192:57958] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.nuk.gzj.temporary.site"] [uri "/robots.txt"] [unique_id "amuHicDCZkc4BvDXnoC23gAAUgw"]
[Thu Jul 30 12:19:06.047302 2026] [security2:error] [pid 727775:tid 727968] [client 20.91.199.21:46413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/worksec.php"] [unique_id "amuHisDCZkc4BvDXnoC25AAAAD8"]
[Thu Jul 30 12:19:06.230704 2026] [security2:error] [pid 727775:tid 728024] [client 20.100.203.84:43794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/av.php"] [unique_id "amuHisDCZkc4BvDXnoC25gAAAHc"]
[Thu Jul 30 12:19:06.230839 2026] [security2:error] [pid 727775:tid 728024] [client 20.100.203.84:43794] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/av.php"] [unique_id "amuHisDCZkc4BvDXnoC25gAAAHc"]
[Thu Jul 30 12:19:06.250688 2026] [security2:error] [pid 727775:tid 727982] [client 57.141.0.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuHicDCZkc4BvDXnoC2zQAAAE0"]
[Thu Jul 30 12:19:06.395877 2026] [security2:error] [pid 727775:tid 728016] [client 40.77.167.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuHisDCZkc4BvDXnoC24wAAAG8"]
[Thu Jul 30 12:19:06.456778 2026] [security2:error] [pid 727775:tid 727926] [client 4.225.166.222:46317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/FWAZ.php"] [unique_id "amuHisDCZkc4BvDXnoC26gAAABU"]
[Thu Jul 30 12:19:06.456888 2026] [security2:error] [pid 727775:tid 727926] [client 4.225.166.222:46317] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/FWAZ.php"] [unique_id "amuHisDCZkc4BvDXnoC26gAAABU"]
[Thu Jul 30 12:19:06.512907 2026] [security2:error] [pid 727775:tid 728028] [client 20.151.221.234:44780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-admin/a.php"] [unique_id "amuHisDCZkc4BvDXnoC27gAAAHs"]
[Thu Jul 30 12:19:06.529541 2026] [security2:error] [pid 727775:tid 727970] [client 57.141.0.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "smoke-tfhk.com"] [uri "/index.php"] [unique_id "amuHicDCZkc4BvDXnoC2yAAAAEE"]
[Thu Jul 30 12:19:06.631806 2026] [security2:error] [pid 727775:tid 727936] [client 20.100.203.84:57679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/classwithtostring.php"] [unique_id "amuHisDCZkc4BvDXnoC28wAAAB8"]
[Thu Jul 30 12:19:06.631956 2026] [security2:error] [pid 727775:tid 727936] [client 20.100.203.84:57679] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/classwithtostring.php"] [unique_id "amuHisDCZkc4BvDXnoC28wAAAB8"]
[Thu Jul 30 12:19:06.773604 2026] [security2:error] [pid 727775:tid 727912] [client 4.225.166.222:56118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/qterm.php"] [unique_id "amuHisDCZkc4BvDXnoC29AAAAAc"]
[Thu Jul 30 12:19:06.773717 2026] [security2:error] [pid 727775:tid 727912] [client 4.225.166.222:56118] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/qterm.php"] [unique_id "amuHisDCZkc4BvDXnoC29AAAAAc"]
[Thu Jul 30 12:19:07.088948 2026] [security2:error] [pid 727775:tid 727960] [client 20.100.203.84:43800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuHi8DCZkc4BvDXnoC2_gAAADc"]
[Thu Jul 30 12:19:07.089113 2026] [security2:error] [pid 727775:tid 727960] [client 20.100.203.84:43800] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuHi8DCZkc4BvDXnoC2_gAAADc"]
[Thu Jul 30 12:19:07.122010 2026] [security2:error] [pid 727775:tid 727967] [client 4.225.166.222:29223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/blurbs.php"] [unique_id "amuHi8DCZkc4BvDXnoC2_wAAAD4"]
[Thu Jul 30 12:19:07.122132 2026] [security2:error] [pid 727775:tid 727967] [client 4.225.166.222:29223] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/blurbs.php"] [unique_id "amuHi8DCZkc4BvDXnoC2_wAAAD4"]
[Thu Jul 30 12:19:07.414527 2026] [security2:error] [pid 727775:tid 727984] [client 20.100.203.84:34669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-blog.php"] [unique_id "amuHi8DCZkc4BvDXnoC3BwAAAE8"]
[Thu Jul 30 12:19:07.414649 2026] [security2:error] [pid 727775:tid 727984] [client 20.100.203.84:34669] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-blog.php"] [unique_id "amuHi8DCZkc4BvDXnoC3BwAAAE8"]
[Thu Jul 30 12:19:07.525531 2026] [security2:error] [pid 727775:tid 727986] [client 4.225.166.222:59062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/wp-ws68.php"] [unique_id "amuHi8DCZkc4BvDXnoC3CQAAAFE"]
[Thu Jul 30 12:19:07.525647 2026] [security2:error] [pid 727775:tid 727986] [client 4.225.166.222:59062] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/wp-ws68.php"] [unique_id "amuHi8DCZkc4BvDXnoC3CQAAAFE"]
[Thu Jul 30 12:19:07.542571 2026] [security2:error] [pid 727775:tid 727996] [client 51.120.79.193:16127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-admin/js/index.php"] [unique_id "amuHi8DCZkc4BvDXnoC3CgAAAFs"]
[Thu Jul 30 12:19:07.542724 2026] [security2:error] [pid 727775:tid 727996] [client 51.120.79.193:16127] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "progroup.jo"] [uri "/wp-admin/js/index.php"] [unique_id "amuHi8DCZkc4BvDXnoC3CgAAAFs"]
[Thu Jul 30 12:19:07.857814 2026] [security2:error] [pid 727775:tid 727973] [client 20.100.203.84:48644] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.heatstickhk.com"] [uri "/___proxy_subdomain_cpanel/wp-includes/js/jquery/"] [unique_id "amuHi8DCZkc4BvDXnoC3DQAAAEQ"]
[Thu Jul 30 12:19:07.862488 2026] [security2:error] [pid 727775:tid 728000] [client 4.225.166.222:46311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/xyn.php"] [unique_id "amuHi8DCZkc4BvDXnoC3DwAAAF8"]
[Thu Jul 30 12:19:07.862644 2026] [security2:error] [pid 727775:tid 728000] [client 4.225.166.222:46311] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/xyn.php"] [unique_id "amuHi8DCZkc4BvDXnoC3DwAAAF8"]
[Thu Jul 30 12:19:08.039648 2026] [security2:error] [pid 727775:tid 728007] [client 20.151.221.234:44102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuHjMDCZkc4BvDXnoC3FwAAAGY"]
[Thu Jul 30 12:19:08.039688 2026] [security2:error] [pid 727775:tid 727985] [client 2a03:2880:f800:19:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuHi8DCZkc4BvDXnoC3CAAAUBc"]
[Thu Jul 30 12:19:08.100971 2026] [security2:error] [pid 727775:tid 727918] [client 172.213.232.128:8800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/admin.php"] [unique_id "amuHjMDCZkc4BvDXnoC3GAAAAA0"]
[Thu Jul 30 12:19:08.158894 2026] [security2:error] [pid 727775:tid 728012] [client 20.100.203.84:48644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-content/admin.php"] [unique_id "amuHjMDCZkc4BvDXnoC3GQAAAGs"]
[Thu Jul 30 12:19:08.159036 2026] [security2:error] [pid 727775:tid 728012] [client 20.100.203.84:48644] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-content/admin.php"] [unique_id "amuHjMDCZkc4BvDXnoC3GQAAAGs"]
[Thu Jul 30 12:19:08.199736 2026] [security2:error] [pid 727775:tid 727987] [client 4.225.166.222:29224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/ccc.php"] [unique_id "amuHjMDCZkc4BvDXnoC3GgAAAFI"]
[Thu Jul 30 12:19:08.199845 2026] [security2:error] [pid 727775:tid 727987] [client 4.225.166.222:29224] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/ccc.php"] [unique_id "amuHjMDCZkc4BvDXnoC3GgAAAFI"]
[Thu Jul 30 12:19:08.217664 2026] [security2:error] [pid 727775:tid 727999] [client 20.91.199.21:35209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/wp-admin/install.php"] [unique_id "amuHjMDCZkc4BvDXnoC3GwAAAF4"]
[Thu Jul 30 12:19:08.250754 2026] [security2:error] [pid 727775:tid 727989] [client 51.120.79.193:10807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/8.php"] [unique_id "amuHjMDCZkc4BvDXnoC3HAAAAFQ"]
[Thu Jul 30 12:19:08.250877 2026] [security2:error] [pid 727775:tid 727989] [client 51.120.79.193:10807] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "progroup.jo"] [uri "/8.php"] [unique_id "amuHjMDCZkc4BvDXnoC3HAAAAFQ"]
[Thu Jul 30 12:19:08.490660 2026] [security2:error] [pid 727775:tid 727983] [client 2a03:2880:f800:26:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuHi8DCZkc4BvDXnoC3DAAAThg"]
[Thu Jul 30 12:19:08.502804 2026] [security2:error] [pid 727775:tid 728026] [client 4.225.166.222:29214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/get.php"] [unique_id "amuHjMDCZkc4BvDXnoC3JAAAAHk"]
[Thu Jul 30 12:19:08.502918 2026] [security2:error] [pid 727775:tid 728026] [client 4.225.166.222:29214] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/get.php"] [unique_id "amuHjMDCZkc4BvDXnoC3JAAAAHk"]
[Thu Jul 30 12:19:08.504749 2026] [security2:error] [pid 727775:tid 727981] [client 20.100.203.84:43785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/adminfuns.php"] [unique_id "amuHjMDCZkc4BvDXnoC3JQAAAEw"]
[Thu Jul 30 12:19:08.504851 2026] [security2:error] [pid 727775:tid 727981] [client 20.100.203.84:43785] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/adminfuns.php"] [unique_id "amuHjMDCZkc4BvDXnoC3JQAAAEw"]
[Thu Jul 30 12:19:08.751350 2026] [security2:error] [pid 727775:tid 727983] [client 2a03:2880:f800:2f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuHjMDCZkc4BvDXnoC3FgAAThs"]
[Thu Jul 30 12:19:08.794665 2026] [security2:error] [pid 727775:tid 727807] [remote 57.141.0.33:28174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/94764231632/feed/rss2/"] [unique_id "amuHjMDCZkc4BvDXnoC3JgAAeh8"]
[Thu Jul 30 12:19:08.823208 2026] [security2:error] [pid 727775:tid 727905] [client 20.100.203.84:48651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/goods.php"] [unique_id "amuHjMDCZkc4BvDXnoC3JwAAAAA"]
[Thu Jul 30 12:19:08.823375 2026] [security2:error] [pid 727775:tid 727905] [client 20.100.203.84:48651] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/goods.php"] [unique_id "amuHjMDCZkc4BvDXnoC3JwAAAAA"]
[Thu Jul 30 12:19:08.840040 2026] [security2:error] [pid 727775:tid 727913] [client 4.225.166.222:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/images.php"] [unique_id "amuHjMDCZkc4BvDXnoC3KAAAAAg"]
[Thu Jul 30 12:19:08.840158 2026] [security2:error] [pid 727775:tid 727913] [client 4.225.166.222:59060] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/images.php"] [unique_id "amuHjMDCZkc4BvDXnoC3KAAAAAg"]
[Thu Jul 30 12:19:09.149765 2026] [security2:error] [pid 727775:tid 727906] [client 4.225.166.222:29235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/alls.php"] [unique_id "amuHjcDCZkc4BvDXnoC3MAAAAAE"]
[Thu Jul 30 12:19:09.149872 2026] [security2:error] [pid 727775:tid 727906] [client 4.225.166.222:29235] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/alls.php"] [unique_id "amuHjcDCZkc4BvDXnoC3MAAAAAE"]
[Thu Jul 30 12:19:09.162707 2026] [security2:error] [pid 727775:tid 727969] [client 20.100.203.84:34679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/ms-edit.php"] [unique_id "amuHjcDCZkc4BvDXnoC3MQAAAEA"]
[Thu Jul 30 12:19:09.162841 2026] [security2:error] [pid 727775:tid 727969] [client 20.100.203.84:34679] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/ms-edit.php"] [unique_id "amuHjcDCZkc4BvDXnoC3MQAAAEA"]
[Thu Jul 30 12:19:09.379320 2026] [security2:error] [pid 727775:tid 728014] [client 20.151.221.234:44784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-admin.php"] [unique_id "amuHjcDCZkc4BvDXnoC3MgAAAG0"]
[Thu Jul 30 12:19:09.381696 2026] [security2:error] [pid 727775:tid 727924] [client 20.91.199.21:46411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "amuHjcDCZkc4BvDXnoC3LwAAABM"]
[Thu Jul 30 12:19:09.394916 2026] [security2:error] [pid 727775:tid 727970] [client 172.213.232.128:9115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "amuHjcDCZkc4BvDXnoC3NAAAAEE"]
[Thu Jul 30 12:19:09.462677 2026] [security2:error] [pid 727775:tid 727941] [client 20.100.203.84:57692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/222.php"] [unique_id "amuHjcDCZkc4BvDXnoC3OAAAACQ"]
[Thu Jul 30 12:19:09.462771 2026] [security2:error] [pid 727775:tid 727941] [client 20.100.203.84:57692] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/222.php"] [unique_id "amuHjcDCZkc4BvDXnoC3OAAAACQ"]
[Thu Jul 30 12:19:09.571714 2026] [security2:error] [pid 727775:tid 727949] [client 4.225.166.222:29244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/coffexium.php"] [unique_id "amuHjcDCZkc4BvDXnoC3PAAAACw"]
[Thu Jul 30 12:19:09.571821 2026] [security2:error] [pid 727775:tid 727949] [client 4.225.166.222:29244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/coffexium.php"] [unique_id "amuHjcDCZkc4BvDXnoC3PAAAACw"]
[Thu Jul 30 12:19:09.813409 2026] [security2:error] [pid 727775:tid 727813] [remote 47.128.28.101:46408] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/nike-air-jordan-1-retro-high-og-chenille/"] [unique_id "amuHjcDCZkc4BvDXnoC3PgAAOiU"]
[Thu Jul 30 12:19:10.111116 2026] [security2:error] [pid 727775:tid 727964] [client 172.213.232.128:1541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/db-cache.php"] [unique_id "amuHjsDCZkc4BvDXnoC3RgAAADs"]
[Thu Jul 30 12:19:10.388448 2026] [autoindex:error] [pid 727775:tid 727923] [client 87.236.176.79:0] AH01276: Cannot serve directory /home2/mbmudite/ok.koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://ok.koidomino.click:8880
[Thu Jul 30 12:19:10.411185 2026] [security2:error] [pid 727775:tid 727956] [client 20.151.221.234:4358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/size.php"] [unique_id "amuHjsDCZkc4BvDXnoC3SgAAADM"]
[Thu Jul 30 12:19:10.664637 2026] [security2:error] [pid 727775:tid 727986] [client 172.213.232.128:16232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/themes/twentyeleven/functions.php"] [unique_id "amuHjsDCZkc4BvDXnoC3UwAAAFE"]
[Thu Jul 30 12:19:10.784801 2026] [security2:error] [pid 727775:tid 727958] [client 2a03:2880:f800:46:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuHjsDCZkc4BvDXnoC3RwAANSk"]
[Thu Jul 30 12:19:11.445205 2026] [security2:error] [pid 727775:tid 728029] [client 20.63.98.115:54188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/widgets/about.php"] [unique_id "amuHj8DCZkc4BvDXnoC3XwAAAHw"]
[Thu Jul 30 12:19:11.527886 2026] [security2:error] [pid 727775:tid 728005] [client 57.141.0.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuHjsDCZkc4BvDXnoC3VgAAAGQ"]
[Thu Jul 30 12:19:12.296242 2026] [security2:error] [pid 727775:tid 728023] [client 20.151.221.234:44747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-includes/wp-class.php"] [unique_id "amuHkMDCZkc4BvDXnoC3bQAAAHY"]
[Thu Jul 30 12:19:12.474454 2026] [core:error] [pid 727775:tid 727952] [client 74.7.230.63:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:19:12.474481 2026] [core:error] [pid 727775:tid 727952] [client 74.7.230.63:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:19:12.474640 2026] [security2:error] [pid 727775:tid 727952] [client 74.7.230.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.elitegaragedoorrepairservices.us"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "amuHkMDCZkc4BvDXnoC3cAAAAC8"]
[Thu Jul 30 12:19:12.475161 2026] [security2:error] [pid 727775:tid 727930] [client 74.7.230.63:34086] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.elitegaragedoorrepairservices.us"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuHkMDCZkc4BvDXnoC3bgAAGTY"]
[Thu Jul 30 12:19:12.750924 2026] [security2:error] [pid 727775:tid 727924] [client 20.63.98.115:44013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/fonts/wp-login.php"] [unique_id "amuHkMDCZkc4BvDXnoC3dwAAABM"]
[Thu Jul 30 12:19:13.085436 2026] [security2:error] [pid 727775:tid 727835] [remote 104.238.222.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.222.238.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-login.php"] [unique_id "amuHkcDCZkc4BvDXnoC3fAAALjs"], referer: https://t.co/
[Thu Jul 30 12:19:13.241061 2026] [security2:error] [pid 727775:tid 727950] [client 20.151.221.234:4378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/403.php"] [unique_id "amuHkcDCZkc4BvDXnoC3gwAAAC0"]
[Thu Jul 30 12:19:13.360073 2026] [security2:error] [pid 727775:tid 728020] [client 172.213.232.128:18101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/themes/oceanwp/functions.php"] [unique_id "amuHkcDCZkc4BvDXnoC3hAAAAHM"]
[Thu Jul 30 12:19:13.431909 2026] [security2:error] [pid 727775:tid 727944] [client 57.141.0.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuHkMDCZkc4BvDXnoC3egAAACc"]
[Thu Jul 30 12:19:13.570296 2026] [security2:error] [pid 727775:tid 727966] [client 20.63.98.115:54149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/themes.php"] [unique_id "amuHkcDCZkc4BvDXnoC3hQAAAD0"]
[Thu Jul 30 12:19:13.810511 2026] [security2:error] [pid 727775:tid 727840] [remote 104.238.222.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.222.238.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-login.php"] [unique_id "amuHkcDCZkc4BvDXnoC3jAAAXUA"], referer: https://www.google.com/
[Thu Jul 30 12:19:14.113420 2026] [security2:error] [pid 727775:tid 727992] [client 20.151.221.234:35495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amuHksDCZkc4BvDXnoC3jwAAAFc"]
[Thu Jul 30 12:19:14.119061 2026] [security2:error] [pid 727775:tid 727996] [client 172.213.232.128:13828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/themes/twentythirteen/functions.php"] [unique_id "amuHksDCZkc4BvDXnoC3kAAAAFs"]
[Thu Jul 30 12:19:14.417007 2026] [security2:error] [pid 727775:tid 727995] [client 20.63.98.115:43308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/if.php"] [unique_id "amuHksDCZkc4BvDXnoC3mAAAAFo"]
[Thu Jul 30 12:19:14.954239 2026] [security2:error] [pid 727775:tid 728019] [client 20.151.221.234:44144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/as.php"] [unique_id "amuHksDCZkc4BvDXnoC3owAAAHI"]
[Thu Jul 30 12:19:14.955890 2026] [security2:error] [pid 727775:tid 727850] [remote 104.238.222.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.222.238.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-login.php"] [unique_id "amuHksDCZkc4BvDXnoC3pAAATEo"]
[Thu Jul 30 12:19:15.112555 2026] [security2:error] [pid 727775:tid 728011] [client 57.141.0.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuHksDCZkc4BvDXnoC3mwAAAGo"]
[Thu Jul 30 12:19:16.315693 2026] [security2:error] [pid 727775:tid 728024] [client 20.63.98.115:57235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/editor.php"] [unique_id "amuHlMDCZkc4BvDXnoC3vQAAAHc"]
[Thu Jul 30 12:19:16.817877 2026] [security2:error] [pid 727775:tid 727950] [client 20.151.221.234:44157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-admin/includes/index.php"] [unique_id "amuHlMDCZkc4BvDXnoC3xAAAAC0"]
[Thu Jul 30 12:19:16.975515 2026] [security2:error] [pid 727775:tid 727944] [client 172.213.232.128:1552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/themes/kadence/functions.php"] [unique_id "amuHlMDCZkc4BvDXnoC3yAAAACc"]
[Thu Jul 30 12:19:17.203772 2026] [security2:error] [pid 727775:tid 727964] [client 74.7.241.139:35798] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "google-search.org"] [uri "/robots.txt"] [unique_id "amuHlcDCZkc4BvDXnoC3yQAAO1Y"]
[Thu Jul 30 12:19:17.574047 2026] [security2:error] [pid 727775:tid 727934] [client 20.63.98.115:43272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/click.php"] [unique_id "amuHlcDCZkc4BvDXnoC30gAAAB0"]
[Thu Jul 30 12:19:17.620360 2026] [security2:error] [pid 727775:tid 727991] [client 20.151.221.234:4357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amuHlcDCZkc4BvDXnoC30wAAAFY"]
[Thu Jul 30 12:19:17.804911 2026] [security2:error] [pid 727775:tid 727958] [client 172.213.232.128:7754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/themes/twentytwenty/functions.php"] [unique_id "amuHlcDCZkc4BvDXnoC31AAAADU"]
[Thu Jul 30 12:19:18.507401 2026] [security2:error] [pid 727775:tid 727968] [client 20.151.221.234:44744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/plugins.php"] [unique_id "amuHlsDCZkc4BvDXnoC35QAAAD8"]
[Thu Jul 30 12:19:18.604736 2026] [core:error] [pid 727775:tid 727916] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:19:18.604762 2026] [core:error] [pid 727775:tid 727916] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:19:18.699205 2026] [core:error] [pid 727775:tid 728023] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:19:18.699221 2026] [core:error] [pid 727775:tid 727906] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:19:18.699228 2026] [core:error] [pid 727775:tid 728023] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:19:18.699237 2026] [core:error] [pid 727775:tid 727906] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:19:18.709162 2026] [security2:error] [pid 727775:tid 727981] [client 172.213.232.128:23136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/content.php"] [unique_id "amuHlsDCZkc4BvDXnoC39gAAAEw"]
[Thu Jul 30 12:19:18.715427 2026] [core:error] [pid 727775:tid 727937] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:19:18.715448 2026] [core:error] [pid 727775:tid 727937] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:19:18.757611 2026] [core:error] [pid 727775:tid 727945] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:19:18.757631 2026] [core:error] [pid 727775:tid 727945] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:19:18.784329 2026] [security2:error] [pid 727775:tid 728022] [client 57.141.0.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuHlsDCZkc4BvDXnoC33gAAAHU"]
[Thu Jul 30 12:19:19.476999 2026] [security2:error] [pid 727775:tid 727976] [client 20.151.221.234:44757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-includes/js/index.php"] [unique_id "amuHl8DCZkc4BvDXnoC4DAAAAEc"]
[Thu Jul 30 12:19:20.267820 2026] [security2:error] [pid 727775:tid 727988] [client 20.63.98.115:57248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/test.php7"] [unique_id "amuHmMDCZkc4BvDXnoC4GQAAAFM"]
[Thu Jul 30 12:19:20.304478 2026] [security2:error] [pid 727775:tid 728018] [client 87.101.92.171:43646] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuHmMDCZkc4BvDXnoC4GgAAAHE"]
[Thu Jul 30 12:19:20.304582 2026] [security2:error] [pid 727775:tid 728018] [client 87.101.92.171:43646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuHmMDCZkc4BvDXnoC4GgAAAHE"]
[Thu Jul 30 12:19:20.473079 2026] [security2:error] [pid 727775:tid 728001] [client 20.151.221.234:44741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/go.php"] [unique_id "amuHmMDCZkc4BvDXnoC4JQAAAGA"]
[Thu Jul 30 12:19:20.840251 2026] [security2:error] [pid 727775:tid 727989] [client 57.141.0.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuHmMDCZkc4BvDXnoC4GAAAAFQ"]
[Thu Jul 30 12:19:21.598274 2026] [security2:error] [pid 727775:tid 728020] [client 172.213.232.128:39193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/plugins/not/includes/about.php"] [unique_id "amuHmcDCZkc4BvDXnoC4PQAAAHM"]
[Thu Jul 30 12:19:22.371834 2026] [security2:error] [pid 727775:tid 727936] [client 20.151.221.234:44114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/test1.php"] [unique_id "amuHmsDCZkc4BvDXnoC4RQAAAB8"]
[Thu Jul 30 12:19:22.385686 2026] [security2:error] [pid 727775:tid 728024] [client 172.213.232.128:1131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/plugins/simple/simple.php"] [unique_id "amuHmsDCZkc4BvDXnoC4RgAAAHc"]
[Thu Jul 30 12:19:23.322061 2026] [security2:error] [pid 727775:tid 728002] [client 172.213.232.128:1090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/plugins/wp-theme-editor/include.php"] [unique_id "amuHm8DCZkc4BvDXnoC4WgAAAGE"]
[Thu Jul 30 12:19:23.933524 2026] [core:notice] [pid 727775:tid 727794] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:19:24.340781 2026] [security2:error] [pid 727775:tid 727937] [client 213.152.161.118:40076] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuHnMDCZkc4BvDXnoC4bgAAACA"]
[Thu Jul 30 12:19:24.340876 2026] [security2:error] [pid 727775:tid 727937] [client 213.152.161.118:40076] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuHnMDCZkc4BvDXnoC4bgAAACA"]
[Thu Jul 30 12:19:24.502152 2026] [security2:error] [pid 727775:tid 728014] [client 20.151.221.234:44766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/images/index.php"] [unique_id "amuHnMDCZkc4BvDXnoC4bwAAAG0"]
[Thu Jul 30 12:19:24.703924 2026] [security2:error] [pid 727775:tid 727994] [client 20.63.98.115:57228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "amuHnMDCZkc4BvDXnoC4dQAAAFk"]
[Thu Jul 30 12:19:24.752953 2026] [security2:error] [pid 727775:tid 727906] [client 172.213.232.128:23117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/themes/aahana/json.php"] [unique_id "amuHnMDCZkc4BvDXnoC4eAAAAAE"]
[Thu Jul 30 12:19:25.006935 2026] [security2:error] [pid 727775:tid 728029] [client 174.138.89.209:47568] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.248"] [uri "/"] [unique_id "amuHncDCZkc4BvDXnoC4eQAAAHw"]
[Thu Jul 30 12:19:25.197032 2026] [security2:error] [pid 727775:tid 727957] [client 114.119.155.153:35323] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.mediaspawn.com"] [uri "/robots.txt"] [unique_id "amuHncDCZkc4BvDXnoC4gQAAADQ"], referer: http://www.mediaspawn.com/robots.txt
[Thu Jul 30 12:19:25.234003 2026] [security2:error] [pid 727775:tid 727949] [client 174.138.89.209:37054] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.248"] [uri "/"] [unique_id "amuHncDCZkc4BvDXnoC4hQAAACw"]
[Thu Jul 30 12:19:25.537854 2026] [security2:error] [pid 727775:tid 727963] [client 20.63.98.115:57220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/content.php"] [unique_id "amuHncDCZkc4BvDXnoC4iQAAADo"]
[Thu Jul 30 12:19:25.560521 2026] [security2:error] [pid 727775:tid 727936] [client 172.213.232.128:18623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/plugins/awesome-coming-soon/come.php"] [unique_id "amuHncDCZkc4BvDXnoC4iwAAAB8"]
[Thu Jul 30 12:19:25.949713 2026] [security2:error] [pid 727775:tid 727964] [client 47.128.56.189:22946] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.northyorksheridanmall.com"] [uri "/robots.txt"] [unique_id "amuHncDCZkc4BvDXnoC4mAAAADs"]
[Thu Jul 30 12:19:26.329015 2026] [security2:error] [pid 727775:tid 727988] [client 172.213.232.128:1585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/plugins/wp-conflg.php"] [unique_id "amuHnsDCZkc4BvDXnoC4owAAAFM"]
[Thu Jul 30 12:19:26.789948 2026] [security2:error] [pid 727775:tid 727958] [client 20.63.98.115:57278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/.well-known.php"] [unique_id "amuHnsDCZkc4BvDXnoC4rQAAADU"]
[Thu Jul 30 12:19:27.028328 2026] [security2:error] [pid 727775:tid 727913] [client 20.151.221.234:4352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/asd.php"] [unique_id "amuHn8DCZkc4BvDXnoC4rwAAAAg"]
[Thu Jul 30 12:19:27.337804 2026] [security2:error] [pid 727775:tid 727816] [remote 74.7.241.60:50634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/article.php"] [unique_id "amuHn8DCZkc4BvDXnoC4tgAAIig"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/main_image_6a3229a631e84.jpg
[Thu Jul 30 12:19:27.654110 2026] [security2:error] [pid 727775:tid 727922] [client 20.63.98.115:55356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/cgi-bin/wp-login.php"] [unique_id "amuHn8DCZkc4BvDXnoC4uwAAABE"]
[Thu Jul 30 12:19:27.927096 2026] [security2:error] [pid 727775:tid 727957] [client 20.151.221.234:12839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-includes/customize/index.php"] [unique_id "amuHn8DCZkc4BvDXnoC4xAAAADQ"]
[Thu Jul 30 12:19:28.720514 2026] [security2:error] [pid 727775:tid 727956] [client 20.63.98.115:54777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/themes/twenty/twenty.php"] [unique_id "amuHoMDCZkc4BvDXnoC40gAAADM"]
[Thu Jul 30 12:19:28.743074 2026] [security2:error] [pid 727775:tid 727998] [client 20.151.221.234:44111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amuHoMDCZkc4BvDXnoC40wAAAF0"]
[Thu Jul 30 12:19:29.424677 2026] [core:notice] [pid 727775:tid 727982] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:19:29.585237 2026] [security2:error] [pid 727775:tid 727821] [remote 66.249.88.164:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuHoMDCZkc4BvDXnoC40AAAHi0"]
[Thu Jul 30 12:19:29.591824 2026] [security2:error] [pid 727775:tid 728009] [client 20.63.98.115:27243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/images/cloud.php"] [unique_id "amuHocDCZkc4BvDXnoC43wAAAGg"]
[Thu Jul 30 12:19:29.760897 2026] [security2:error] [pid 727775:tid 727927] [client 158.158.105.63:52240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuHocDCZkc4BvDXnoC44wAAABY"]
[Thu Jul 30 12:19:29.761017 2026] [security2:error] [pid 727775:tid 727927] [client 158.158.105.63:52240] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuHocDCZkc4BvDXnoC44wAAABY"]
[Thu Jul 30 12:19:30.061799 2026] [security2:error] [pid 727775:tid 727914] [client 158.158.105.63:19623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuHosDCZkc4BvDXnoC46AAAAAk"]
[Thu Jul 30 12:19:30.061883 2026] [security2:error] [pid 727775:tid 727914] [client 158.158.105.63:19623] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuHosDCZkc4BvDXnoC46AAAAAk"]
[Thu Jul 30 12:19:30.189648 2026] [security2:error] [pid 727775:tid 727911] [client 172.213.232.128:7772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "amuHosDCZkc4BvDXnoC47AAAAAY"]
[Thu Jul 30 12:19:30.330430 2026] [security2:error] [pid 727775:tid 728016] [client 158.158.105.63:19620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/x.php"] [unique_id "amuHosDCZkc4BvDXnoC47gAAAG8"]
[Thu Jul 30 12:19:30.330563 2026] [security2:error] [pid 727775:tid 728016] [client 158.158.105.63:19620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/x.php"] [unique_id "amuHosDCZkc4BvDXnoC47gAAAG8"]
[Thu Jul 30 12:19:30.536705 2026] [core:notice] [pid 727775:tid 727937] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:19:30.627829 2026] [security2:error] [pid 727775:tid 728006] [client 20.63.98.115:32429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/css/about.php"] [unique_id "amuHosDCZkc4BvDXnoC49gAAAGU"]
[Thu Jul 30 12:19:30.641182 2026] [security2:error] [pid 727775:tid 728005] [client 158.158.105.63:52226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/mgrr.php"] [unique_id "amuHosDCZkc4BvDXnoC49wAAAGQ"]
[Thu Jul 30 12:19:30.641266 2026] [security2:error] [pid 727775:tid 728005] [client 158.158.105.63:52226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/mgrr.php"] [unique_id "amuHosDCZkc4BvDXnoC49wAAAGQ"]
[Thu Jul 30 12:19:30.716364 2026] [security2:error] [pid 727775:tid 727837] [remote 74.7.241.59:53642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuHosDCZkc4BvDXnoC4-AAACD0"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/premium-addons-for-elementor/modules/woocommerce/templates
[Thu Jul 30 12:19:30.911592 2026] [security2:error] [pid 727775:tid 727990] [client 158.158.105.63:19621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/domvf.php"] [unique_id "amuHosDCZkc4BvDXnoC4_QAAAFU"]
[Thu Jul 30 12:19:30.911757 2026] [security2:error] [pid 727775:tid 727990] [client 158.158.105.63:19621] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/domvf.php"] [unique_id "amuHosDCZkc4BvDXnoC4_QAAAFU"]
[Thu Jul 30 12:19:31.138513 2026] [security2:error] [pid 727775:tid 727939] [client 172.213.232.128:1536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/style-engine/about.php"] [unique_id "amuHo8DCZkc4BvDXnoC5AwAAACI"]
[Thu Jul 30 12:19:31.177564 2026] [security2:error] [pid 727775:tid 727920] [client 158.158.105.63:19611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/yup.php"] [unique_id "amuHo8DCZkc4BvDXnoC5BAAAAA8"]
[Thu Jul 30 12:19:31.177673 2026] [security2:error] [pid 727775:tid 727920] [client 158.158.105.63:19611] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/yup.php"] [unique_id "amuHo8DCZkc4BvDXnoC5BAAAAA8"]
[Thu Jul 30 12:19:31.442916 2026] [security2:error] [pid 727775:tid 728008] [client 158.158.105.63:19633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/X.php"] [unique_id "amuHo8DCZkc4BvDXnoC5CgAAAGc"]
[Thu Jul 30 12:19:31.443074 2026] [security2:error] [pid 727775:tid 728008] [client 158.158.105.63:19633] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/X.php"] [unique_id "amuHo8DCZkc4BvDXnoC5CgAAAGc"]
[Thu Jul 30 12:19:31.690332 2026] [security2:error] [pid 727775:tid 727987] [client 216.73.217.139:31341] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "tmrfsl.com"] [uri "/index.php"] [unique_id "amuHo8DCZkc4BvDXnoC5DgAAUkU"]
[Thu Jul 30 12:19:31.747545 2026] [security2:error] [pid 727775:tid 727998] [client 158.158.105.63:19613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amuHo8DCZkc4BvDXnoC5DwAAAF0"]
[Thu Jul 30 12:19:31.747656 2026] [security2:error] [pid 727775:tid 727998] [client 158.158.105.63:19613] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amuHo8DCZkc4BvDXnoC5DwAAAF0"]
[Thu Jul 30 12:19:31.780289 2026] [security2:error] [pid 727775:tid 728001] [client 20.151.221.234:44129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/atomlib.php"] [unique_id "amuHo8DCZkc4BvDXnoC5EQAAAGA"]
[Thu Jul 30 12:19:31.886853 2026] [security2:error] [pid 727775:tid 727997] [client 172.213.232.128:16209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "amuHo8DCZkc4BvDXnoC5EgAAAFw"]
[Thu Jul 30 12:19:31.980623 2026] [security2:error] [pid 727775:tid 727957] [client 20.63.98.115:53851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/customize/about.php"] [unique_id "amuHo8DCZkc4BvDXnoC5FQAAADQ"]
[Thu Jul 30 12:19:31.981086 2026] [security2:error] [pid 727775:tid 727931] [client 216.73.217.139:31341] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tmrfsl.com"] [uri "/index.php"] [unique_id "amuHo8DCZkc4BvDXnoC5EwAAGkE"], referer: https://tmrfsl.com/sitemap.xml
[Thu Jul 30 12:19:32.019486 2026] [security2:error] [pid 727775:tid 728004] [client 158.158.105.63:52261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/gec.php"] [unique_id "amuHpMDCZkc4BvDXnoC5GAAAAGM"]
[Thu Jul 30 12:19:32.019619 2026] [security2:error] [pid 727775:tid 728004] [client 158.158.105.63:52261] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/gec.php"] [unique_id "amuHpMDCZkc4BvDXnoC5GAAAAGM"]
[Thu Jul 30 12:19:32.318224 2026] [security2:error] [pid 727775:tid 727985] [client 158.158.105.63:52245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/sky.php"] [unique_id "amuHpMDCZkc4BvDXnoC5HAAAAFA"]
[Thu Jul 30 12:19:32.318344 2026] [security2:error] [pid 727775:tid 727985] [client 158.158.105.63:52245] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/sky.php"] [unique_id "amuHpMDCZkc4BvDXnoC5HAAAAFA"]
[Thu Jul 30 12:19:32.586763 2026] [security2:error] [pid 727775:tid 727925] [client 158.158.105.63:52258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/fffm.php"] [unique_id "amuHpMDCZkc4BvDXnoC5IAAAABQ"]
[Thu Jul 30 12:19:32.586894 2026] [security2:error] [pid 727775:tid 727925] [client 158.158.105.63:52258] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/fffm.php"] [unique_id "amuHpMDCZkc4BvDXnoC5IAAAABQ"]
[Thu Jul 30 12:19:32.884919 2026] [security2:error] [pid 727775:tid 727952] [client 158.158.105.63:19603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/sixxis.php"] [unique_id "amuHpMDCZkc4BvDXnoC5JwAAAC8"]
[Thu Jul 30 12:19:32.885052 2026] [security2:error] [pid 727775:tid 727952] [client 158.158.105.63:19603] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/sixxis.php"] [unique_id "amuHpMDCZkc4BvDXnoC5JwAAAC8"]
[Thu Jul 30 12:19:32.924107 2026] [core:error] [pid 727775:tid 727905] [client 74.7.175.188:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:19:32.924137 2026] [core:error] [pid 727775:tid 727905] [client 74.7.175.188:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:19:32.924301 2026] [security2:error] [pid 727775:tid 727905] [client 74.7.175.188:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.kax.udi.temporary.site"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amuHpMDCZkc4BvDXnoC5KgAAAAA"]
[Thu Jul 30 12:19:32.924859 2026] [security2:error] [pid 727775:tid 728015] [client 74.7.175.188:41304] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.kax.udi.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuHpMDCZkc4BvDXnoC5KAAAbks"]
[Thu Jul 30 12:19:33.151084 2026] [security2:error] [pid 727775:tid 727940] [client 158.158.105.63:19628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/yj09.php"] [unique_id "amuHpcDCZkc4BvDXnoC5KwAAACM"]
[Thu Jul 30 12:19:33.151231 2026] [security2:error] [pid 727775:tid 727940] [client 158.158.105.63:19628] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/yj09.php"] [unique_id "amuHpcDCZkc4BvDXnoC5KwAAACM"]
[Thu Jul 30 12:19:33.425503 2026] [security2:error] [pid 727775:tid 727913] [client 158.158.105.63:18442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/k.php"] [unique_id "amuHpcDCZkc4BvDXnoC5NAAAAAg"]
[Thu Jul 30 12:19:33.425611 2026] [security2:error] [pid 727775:tid 727913] [client 158.158.105.63:18442] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/k.php"] [unique_id "amuHpcDCZkc4BvDXnoC5NAAAAAg"]
[Thu Jul 30 12:19:33.452661 2026] [security2:error] [pid 727775:tid 727946] [client 172.213.232.128:12437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuHpcDCZkc4BvDXnoC5NQAAACk"]
[Thu Jul 30 12:19:33.777025 2026] [security2:error] [pid 727775:tid 727906] [client 158.158.105.63:52243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/k2.php"] [unique_id "amuHpcDCZkc4BvDXnoC5PwAAAAE"]
[Thu Jul 30 12:19:33.777142 2026] [security2:error] [pid 727775:tid 727906] [client 158.158.105.63:52243] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/k2.php"] [unique_id "amuHpcDCZkc4BvDXnoC5PwAAAAE"]
[Thu Jul 30 12:19:33.842289 2026] [security2:error] [pid 727775:tid 727944] [client 20.151.221.234:44122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amuHpcDCZkc4BvDXnoC5QAAAACc"]
[Thu Jul 30 12:19:34.005485 2026] [security2:error] [pid 727775:tid 727927] [client 20.63.98.115:32384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "amuHpsDCZkc4BvDXnoC5VAAAABY"]
[Thu Jul 30 12:19:34.043997 2026] [security2:error] [pid 727775:tid 727971] [client 158.158.105.63:52257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/w.php"] [unique_id "amuHpsDCZkc4BvDXnoC5VQAAAEI"]
[Thu Jul 30 12:19:34.044098 2026] [security2:error] [pid 727775:tid 727971] [client 158.158.105.63:52257] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/w.php"] [unique_id "amuHpsDCZkc4BvDXnoC5VQAAAEI"]
[Thu Jul 30 12:19:34.304867 2026] [security2:error] [pid 727775:tid 727966] [client 158.158.105.63:52234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/fpwch.php"] [unique_id "amuHpsDCZkc4BvDXnoC5XQAAAD0"]
[Thu Jul 30 12:19:34.304959 2026] [security2:error] [pid 727775:tid 727966] [client 158.158.105.63:52234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/fpwch.php"] [unique_id "amuHpsDCZkc4BvDXnoC5XQAAAD0"]
[Thu Jul 30 12:19:34.665833 2026] [security2:error] [pid 727775:tid 728026] [client 158.158.105.63:19589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/w2025.php"] [unique_id "amuHpsDCZkc4BvDXnoC5fQAAAHk"]
[Thu Jul 30 12:19:34.665944 2026] [security2:error] [pid 727775:tid 728026] [client 158.158.105.63:19589] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/w2025.php"] [unique_id "amuHpsDCZkc4BvDXnoC5fQAAAHk"]
[Thu Jul 30 12:19:34.680895 2026] [core:notice] [pid 727775:tid 727920] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:19:34.776414 2026] [security2:error] [pid 727775:tid 727779] [remote 103.164.173.46:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.173.164.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/wp-login.php"] [unique_id "amuHpsDCZkc4BvDXnoC5fwAAcQM"]
[Thu Jul 30 12:19:34.985817 2026] [security2:error] [pid 727775:tid 728021] [client 158.158.105.63:52263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/FWAZ.php"] [unique_id "amuHpsDCZkc4BvDXnoC5hAAAAHQ"]
[Thu Jul 30 12:19:34.985932 2026] [security2:error] [pid 727775:tid 728021] [client 158.158.105.63:52263] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/FWAZ.php"] [unique_id "amuHpsDCZkc4BvDXnoC5hAAAAHQ"]
[Thu Jul 30 12:19:35.034233 2026] [security2:error] [pid 727775:tid 727964] [client 20.63.98.115:62332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/files.php"] [unique_id "amuHp8DCZkc4BvDXnoC5iAAAADs"]
[Thu Jul 30 12:19:35.247538 2026] [security2:error] [pid 727775:tid 727919] [client 158.158.105.63:19596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/qterm.php"] [unique_id "amuHp8DCZkc4BvDXnoC5jwAAAA4"]
[Thu Jul 30 12:19:35.247642 2026] [security2:error] [pid 727775:tid 727919] [client 158.158.105.63:19596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/qterm.php"] [unique_id "amuHp8DCZkc4BvDXnoC5jwAAAA4"]
[Thu Jul 30 12:19:35.308028 2026] [security2:error] [pid 727775:tid 727986] [client 20.151.221.234:41660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/inputs.php"] [unique_id "amuHp8DCZkc4BvDXnoC5kAAAAFE"]
[Thu Jul 30 12:19:35.574057 2026] [security2:error] [pid 727775:tid 727983] [client 158.158.105.63:52274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/blurbs.php"] [unique_id "amuHp8DCZkc4BvDXnoC5mAAAAE4"]
[Thu Jul 30 12:19:35.574148 2026] [security2:error] [pid 727775:tid 727983] [client 158.158.105.63:52274] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/blurbs.php"] [unique_id "amuHp8DCZkc4BvDXnoC5mAAAAE4"]
[Thu Jul 30 12:19:35.878507 2026] [security2:error] [pid 727775:tid 727938] [client 158.158.105.63:19614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-ws68.php"] [unique_id "amuHp8DCZkc4BvDXnoC5nAAAACE"]
[Thu Jul 30 12:19:35.878595 2026] [security2:error] [pid 727775:tid 727938] [client 158.158.105.63:19614] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-ws68.php"] [unique_id "amuHp8DCZkc4BvDXnoC5nAAAACE"]
[Thu Jul 30 12:19:36.144809 2026] [security2:error] [pid 727775:tid 727951] [client 158.158.105.63:19637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/xyn.php"] [unique_id "amuHqMDCZkc4BvDXnoC5oAAAAC4"]
[Thu Jul 30 12:19:36.144909 2026] [security2:error] [pid 727775:tid 727951] [client 158.158.105.63:19637] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/xyn.php"] [unique_id "amuHqMDCZkc4BvDXnoC5oAAAAC4"]
[Thu Jul 30 12:19:36.323531 2026] [security2:error] [pid 727775:tid 727992] [client 20.151.221.234:44748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-content/index.php"] [unique_id "amuHqMDCZkc4BvDXnoC5pAAAAFc"]
[Thu Jul 30 12:19:36.419388 2026] [security2:error] [pid 727775:tid 727932] [client 158.158.105.63:52248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/ccc.php"] [unique_id "amuHqMDCZkc4BvDXnoC5qQAAABs"]
[Thu Jul 30 12:19:36.419497 2026] [security2:error] [pid 727775:tid 727932] [client 158.158.105.63:52248] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/ccc.php"] [unique_id "amuHqMDCZkc4BvDXnoC5qQAAABs"]
[Thu Jul 30 12:19:36.616781 2026] [security2:error] [pid 727775:tid 727939] [client 172.213.232.128:8815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/banners/about.php"] [unique_id "amuHqMDCZkc4BvDXnoC5rQAAACI"]
[Thu Jul 30 12:19:36.757092 2026] [security2:error] [pid 727775:tid 727979] [client 158.158.105.63:19597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/get.php"] [unique_id "amuHqMDCZkc4BvDXnoC5rgAAAEo"]
[Thu Jul 30 12:19:36.757243 2026] [security2:error] [pid 727775:tid 727979] [client 158.158.105.63:19597] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/get.php"] [unique_id "amuHqMDCZkc4BvDXnoC5rgAAAEo"]
[Thu Jul 30 12:19:36.909970 2026] [security2:error] [pid 727775:tid 727994] [client 20.63.98.115:54752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/Text/index.php"] [unique_id "amuHqMDCZkc4BvDXnoC5sgAAAFk"]
[Thu Jul 30 12:19:37.019333 2026] [security2:error] [pid 727775:tid 727956] [client 158.158.105.63:19626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/images.php"] [unique_id "amuHqcDCZkc4BvDXnoC5uAAAADM"]
[Thu Jul 30 12:19:37.019422 2026] [security2:error] [pid 727775:tid 727956] [client 158.158.105.63:19626] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/images.php"] [unique_id "amuHqcDCZkc4BvDXnoC5uAAAADM"]
[Thu Jul 30 12:19:37.255645 2026] [security2:error] [pid 727775:tid 728000] [client 20.151.221.234:41753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-admin/network/index.php"] [unique_id "amuHqcDCZkc4BvDXnoC5vQAAAF8"]
[Thu Jul 30 12:19:37.284228 2026] [security2:error] [pid 727775:tid 727957] [client 158.158.105.63:19584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/alls.php"] [unique_id "amuHqcDCZkc4BvDXnoC5vgAAADQ"]
[Thu Jul 30 12:19:37.284363 2026] [security2:error] [pid 727775:tid 727957] [client 158.158.105.63:19584] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/alls.php"] [unique_id "amuHqcDCZkc4BvDXnoC5vgAAADQ"]
[Thu Jul 30 12:19:37.422497 2026] [security2:error] [pid 727775:tid 727997] [client 172.213.232.128:23109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/about.php"] [unique_id "amuHqcDCZkc4BvDXnoC5wgAAAFw"]
[Thu Jul 30 12:19:37.543811 2026] [security2:error] [pid 727775:tid 727985] [client 158.158.105.63:52230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/coffexium.php"] [unique_id "amuHqcDCZkc4BvDXnoC5wwAAAFA"]
[Thu Jul 30 12:19:37.543917 2026] [security2:error] [pid 727775:tid 727985] [client 158.158.105.63:52230] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/coffexium.php"] [unique_id "amuHqcDCZkc4BvDXnoC5wwAAAFA"]
[Thu Jul 30 12:19:37.802549 2026] [security2:error] [pid 727775:tid 727971] [client 2a03:2880:f800:42:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuHqcDCZkc4BvDXnoC5vAAAQhk"]
[Thu Jul 30 12:19:37.864132 2026] [security2:error] [pid 727775:tid 727962] [client 158.158.105.63:18434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/red.php"] [unique_id "amuHqcDCZkc4BvDXnoC5ygAAADk"]
[Thu Jul 30 12:19:37.864235 2026] [security2:error] [pid 727775:tid 727962] [client 158.158.105.63:18434] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/red.php"] [unique_id "amuHqcDCZkc4BvDXnoC5ygAAADk"]
[Thu Jul 30 12:19:38.021543 2026] [security2:error] [pid 727775:tid 728015] [client 20.63.98.115:54741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "amuHqsDCZkc4BvDXnoC51gAAAG4"]
[Thu Jul 30 12:19:38.062723 2026] [security2:error] [pid 727775:tid 728028] [client 172.213.232.128:18590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/.well-known/about.php"] [unique_id "amuHqsDCZkc4BvDXnoC51wAAAHs"]
[Thu Jul 30 12:19:38.139713 2026] [security2:error] [pid 727775:tid 727905] [client 158.158.105.63:52238] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/___proxy_subdomain_webdisk/wp-includes/sodium_compat/"] [unique_id "amuHqsDCZkc4BvDXnoC52AAAAAA"]
[Thu Jul 30 12:19:38.222354 2026] [core:error] [pid 727775:tid 728016] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:19:38.222397 2026] [core:error] [pid 727775:tid 728016] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:19:38.269628 2026] [security2:error] [pid 727775:tid 727937] [client 158.158.105.63:52238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amuHqsDCZkc4BvDXnoC53QAAACA"]
[Thu Jul 30 12:19:38.269719 2026] [security2:error] [pid 727775:tid 727937] [client 158.158.105.63:52238] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amuHqsDCZkc4BvDXnoC53QAAACA"]
[Thu Jul 30 12:19:38.544251 2026] [security2:error] [pid 727775:tid 728006] [client 158.158.105.63:19625] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/___proxy_subdomain_webdisk/wp-includes/Text/"] [unique_id "amuHqsDCZkc4BvDXnoC54gAAAGU"]
[Thu Jul 30 12:19:38.684113 2026] [security2:error] [pid 727775:tid 727990] [client 158.158.105.63:19625] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/___proxy_subdomain_webdisk/wp-content/uploads/"] [unique_id "amuHqsDCZkc4BvDXnoC55QAAAFU"]
[Thu Jul 30 12:19:38.705941 2026] [security2:error] [pid 727775:tid 727945] [client 20.151.221.234:41638] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "arabiandubaisafari.com"] [uri "/wp-content/1.php"] [unique_id "amuHqsDCZkc4BvDXnoC55gAAACg"]
[Thu Jul 30 12:19:38.706070 2026] [security2:error] [pid 727775:tid 727945] [client 20.151.221.234:41638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-content/1.php"] [unique_id "amuHqsDCZkc4BvDXnoC55gAAACg"]
[Thu Jul 30 12:19:38.812834 2026] [security2:error] [pid 727775:tid 727970] [client 158.158.105.63:19625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-content/index.php"] [unique_id "amuHqsDCZkc4BvDXnoC57QAAAEE"]
[Thu Jul 30 12:19:38.812921 2026] [security2:error] [pid 727775:tid 727970] [client 158.158.105.63:19625] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-content/index.php"] [unique_id "amuHqsDCZkc4BvDXnoC57QAAAEE"]
[Thu Jul 30 12:19:39.080122 2026] [security2:error] [pid 727775:tid 727933] [client 158.158.105.63:52275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/admin.php"] [unique_id "amuHq8DCZkc4BvDXnoC59AAAABw"]
[Thu Jul 30 12:19:39.080246 2026] [security2:error] [pid 727775:tid 727933] [client 158.158.105.63:52275] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/admin.php"] [unique_id "amuHq8DCZkc4BvDXnoC59AAAABw"]
[Thu Jul 30 12:19:39.341030 2026] [security2:error] [pid 727775:tid 727907] [client 158.158.105.63:52239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/177.php"] [unique_id "amuHq8DCZkc4BvDXnoC5-gAAAAI"]
[Thu Jul 30 12:19:39.341138 2026] [security2:error] [pid 727775:tid 727907] [client 158.158.105.63:52239] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/177.php"] [unique_id "amuHq8DCZkc4BvDXnoC5-gAAAAI"]
[Thu Jul 30 12:19:39.566831 2026] [security2:error] [pid 727775:tid 727820] [remote 74.7.242.7:33248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.242.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/"] [unique_id "amuHq8DCZkc4BvDXnoC5_wAAAyw"], referer: https://www.thdinfinity.com/
[Thu Jul 30 12:19:39.600086 2026] [security2:error] [pid 727775:tid 727957] [client 158.158.105.63:52281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/199.php"] [unique_id "amuHq8DCZkc4BvDXnoC6AAAAADQ"]
[Thu Jul 30 12:19:39.600193 2026] [security2:error] [pid 727775:tid 727957] [client 158.158.105.63:52281] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/199.php"] [unique_id "amuHq8DCZkc4BvDXnoC6AAAAADQ"]
[Thu Jul 30 12:19:39.862521 2026] [core:error] [pid 727775:tid 727929] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:19:39.862542 2026] [core:error] [pid 727775:tid 727929] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:19:39.930151 2026] [security2:error] [pid 727775:tid 727988] [client 158.158.105.63:52228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/file52.php"] [unique_id "amuHq8DCZkc4BvDXnoC6CwAAAFM"]
[Thu Jul 30 12:19:39.930278 2026] [security2:error] [pid 727775:tid 727988] [client 158.158.105.63:52228] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/file52.php"] [unique_id "amuHq8DCZkc4BvDXnoC6CwAAAFM"]
[Thu Jul 30 12:19:40.281609 2026] [security2:error] [pid 727775:tid 728007] [client 158.158.105.63:18476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/geck.php"] [unique_id "amuHrMDCZkc4BvDXnoC6EQAAAGY"]
[Thu Jul 30 12:19:40.281717 2026] [security2:error] [pid 727775:tid 728007] [client 158.158.105.63:18476] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/geck.php"] [unique_id "amuHrMDCZkc4BvDXnoC6EQAAAGY"]
[Thu Jul 30 12:19:40.540575 2026] [security2:error] [pid 727775:tid 727940] [client 158.158.105.63:19629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/biufile.php"] [unique_id "amuHrMDCZkc4BvDXnoC6FQAAACM"]
[Thu Jul 30 12:19:40.540694 2026] [security2:error] [pid 727775:tid 727940] [client 158.158.105.63:19629] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/biufile.php"] [unique_id "amuHrMDCZkc4BvDXnoC6FQAAACM"]
[Thu Jul 30 12:19:40.783090 2026] [security2:error] [pid 727775:tid 728009] [client 172.213.232.128:8788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuHrMDCZkc4BvDXnoC6HgAAAGg"]
[Thu Jul 30 12:19:40.835025 2026] [security2:error] [pid 727775:tid 727951] [client 158.158.105.63:19627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/dejavu.php"] [unique_id "amuHrMDCZkc4BvDXnoC6HwAAAC4"]
[Thu Jul 30 12:19:40.835125 2026] [security2:error] [pid 727775:tid 727951] [client 158.158.105.63:19627] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/dejavu.php"] [unique_id "amuHrMDCZkc4BvDXnoC6HwAAAC4"]
[Thu Jul 30 12:19:41.179918 2026] [security2:error] [pid 727775:tid 728003] [client 158.158.105.63:18457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/aaf.php"] [unique_id "amuHrcDCZkc4BvDXnoC6KAAAAGI"]
[Thu Jul 30 12:19:41.180042 2026] [security2:error] [pid 727775:tid 728003] [client 158.158.105.63:18457] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/aaf.php"] [unique_id "amuHrcDCZkc4BvDXnoC6KAAAAGI"]
[Thu Jul 30 12:19:41.288863 2026] [security2:error] [pid 727775:tid 727942] [client 20.63.98.115:38151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/rest-api/about.php"] [unique_id "amuHrcDCZkc4BvDXnoC6KQAAACU"]
[Thu Jul 30 12:19:41.382218 2026] [security2:error] [pid 727775:tid 728014] [client 20.151.221.234:41632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/plugin.php"] [unique_id "amuHrcDCZkc4BvDXnoC6KwAAAG0"]
[Thu Jul 30 12:19:41.503034 2026] [security2:error] [pid 727775:tid 727923] [client 158.158.105.63:52287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/ha.php"] [unique_id "amuHrcDCZkc4BvDXnoC6LwAAABI"]
[Thu Jul 30 12:19:41.503134 2026] [security2:error] [pid 727775:tid 727923] [client 158.158.105.63:52287] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/ha.php"] [unique_id "amuHrcDCZkc4BvDXnoC6LwAAABI"]
[Thu Jul 30 12:19:41.783507 2026] [security2:error] [pid 727775:tid 727953] [client 158.158.105.63:18473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/hur.php"] [unique_id "amuHrcDCZkc4BvDXnoC6OwAAADA"]
[Thu Jul 30 12:19:41.783612 2026] [security2:error] [pid 727775:tid 727953] [client 158.158.105.63:18473] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/hur.php"] [unique_id "amuHrcDCZkc4BvDXnoC6OwAAADA"]
[Thu Jul 30 12:19:42.176194 2026] [security2:error] [pid 727775:tid 727964] [client 158.158.105.63:52260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/h02ugyh.php"] [unique_id "amuHrsDCZkc4BvDXnoC6RwAAADs"]
[Thu Jul 30 12:19:42.176293 2026] [security2:error] [pid 727775:tid 727964] [client 158.158.105.63:52260] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/h02ugyh.php"] [unique_id "amuHrsDCZkc4BvDXnoC6RwAAADs"]
[Thu Jul 30 12:19:42.203522 2026] [security2:error] [pid 727775:tid 727908] [client 20.151.221.234:44751] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "arabiandubaisafari.com"] [uri "/1.php"] [unique_id "amuHrsDCZkc4BvDXnoC6SQAAAAM"]
[Thu Jul 30 12:19:42.203654 2026] [security2:error] [pid 727775:tid 727908] [client 20.151.221.234:44751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/1.php"] [unique_id "amuHrsDCZkc4BvDXnoC6SQAAAAM"]
[Thu Jul 30 12:19:42.436672 2026] [security2:error] [pid 727775:tid 727930] [client 158.158.105.63:52269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/155.php"] [unique_id "amuHrsDCZkc4BvDXnoC6TQAAABk"]
[Thu Jul 30 12:19:42.436773 2026] [security2:error] [pid 727775:tid 727930] [client 158.158.105.63:52269] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/155.php"] [unique_id "amuHrsDCZkc4BvDXnoC6TQAAABk"]
[Thu Jul 30 12:19:42.696403 2026] [security2:error] [pid 727775:tid 728015] [client 158.158.105.63:19639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/ops.php"] [unique_id "amuHrsDCZkc4BvDXnoC6UgAAAG4"]
[Thu Jul 30 12:19:42.696515 2026] [security2:error] [pid 727775:tid 728015] [client 158.158.105.63:19639] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/ops.php"] [unique_id "amuHrsDCZkc4BvDXnoC6UgAAAG4"]
[Thu Jul 30 12:19:42.781165 2026] [security2:error] [pid 727775:tid 727912] [client 172.213.232.128:1596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuHrsDCZkc4BvDXnoC6VAAAAAc"]
[Thu Jul 30 12:19:43.071915 2026] [security2:error] [pid 727775:tid 727989] [client 158.158.105.63:19634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/ingfo.php"] [unique_id "amuHr8DCZkc4BvDXnoC6WAAAAFQ"]
[Thu Jul 30 12:19:43.072039 2026] [security2:error] [pid 727775:tid 727989] [client 158.158.105.63:19634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/ingfo.php"] [unique_id "amuHr8DCZkc4BvDXnoC6WAAAAFQ"]
[Thu Jul 30 12:19:43.372943 2026] [security2:error] [pid 727775:tid 727913] [client 158.158.105.63:52256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/error_log.php"] [unique_id "amuHr8DCZkc4BvDXnoC6YwAAAAg"]
[Thu Jul 30 12:19:43.373066 2026] [security2:error] [pid 727775:tid 727913] [client 158.158.105.63:52256] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/error_log.php"] [unique_id "amuHr8DCZkc4BvDXnoC6YwAAAAg"]
[Thu Jul 30 12:19:43.582270 2026] [ssl:error] [pid 727775:tid 728010] [client 66.132.195.52:45374] AH02032: Hostname sh00085.hostgator.com (default host as no SNI was provided) and hostname mail.megasuppliesdistrict.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Thu Jul 30 12:19:43.645094 2026] [security2:error] [pid 727775:tid 727977] [client 158.158.105.63:19622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/koala.php"] [unique_id "amuHr8DCZkc4BvDXnoC6aAAAAEg"]
[Thu Jul 30 12:19:43.645198 2026] [security2:error] [pid 727775:tid 727977] [client 158.158.105.63:19622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/koala.php"] [unique_id "amuHr8DCZkc4BvDXnoC6aAAAAEg"]
[Thu Jul 30 12:19:43.702376 2026] [security2:error] [pid 727775:tid 727951] [client 20.63.98.115:20885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/ws.php"] [unique_id "amuHr8DCZkc4BvDXnoC6aQAAAC4"]
[Thu Jul 30 12:19:43.792102 2026] [security2:error] [pid 727775:tid 727986] [client 172.213.232.128:12430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/img/about.php"] [unique_id "amuHr8DCZkc4BvDXnoC6cQAAAFE"]
[Thu Jul 30 12:19:44.051534 2026] [security2:error] [pid 727775:tid 728004] [client 158.158.105.63:52232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/mac.php"] [unique_id "amuHsMDCZkc4BvDXnoC6dwAAAGM"]
[Thu Jul 30 12:19:44.051651 2026] [security2:error] [pid 727775:tid 728004] [client 158.158.105.63:52232] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/mac.php"] [unique_id "amuHsMDCZkc4BvDXnoC6dwAAAGM"]
[Thu Jul 30 12:19:44.310797 2026] [security2:error] [pid 727775:tid 727918] [client 158.158.105.63:19607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wefile.php"] [unique_id "amuHsMDCZkc4BvDXnoC6fgAAAA0"]
[Thu Jul 30 12:19:44.310961 2026] [security2:error] [pid 727775:tid 727918] [client 158.158.105.63:19607] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wefile.php"] [unique_id "amuHsMDCZkc4BvDXnoC6fgAAAA0"]
[Thu Jul 30 12:19:44.590889 2026] [security2:error] [pid 727775:tid 728006] [client 74.7.230.33:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "pkv.tqa.temporary.site"] [uri "/index.php"] [unique_id "amuHr8DCZkc4BvDXnoC6WwAAAGU"]
[Thu Jul 30 12:19:44.592034 2026] [security2:error] [pid 727775:tid 728022] [client 74.7.230.33:36206] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "pkv.tqa.temporary.site"] [uri "/robots.txt"] [unique_id "amuHr8DCZkc4BvDXnoC6WQAAdUY"]
[Thu Jul 30 12:19:44.596734 2026] [security2:error] [pid 727775:tid 728008] [client 158.158.105.63:18458] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/___proxy_subdomain_webdisk/wp-includes/blocks/post-comments-form/"] [unique_id "amuHsMDCZkc4BvDXnoC6hAAAAGc"]
[Thu Jul 30 12:19:44.719478 2026] [security2:error] [pid 727775:tid 727998] [client 20.63.98.115:38179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-config-sample.php"] [unique_id "amuHsMDCZkc4BvDXnoC6hQAAAF0"]
[Thu Jul 30 12:19:44.739349 2026] [security2:error] [pid 727775:tid 727988] [client 158.158.105.63:18458] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/___proxy_subdomain_webdisk/wp-admin/js/"] [unique_id "amuHsMDCZkc4BvDXnoC6hgAAAFM"]
[Thu Jul 30 12:19:44.868663 2026] [security2:error] [pid 727775:tid 727962] [client 158.158.105.63:18458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/makeasmtp.php"] [unique_id "amuHsMDCZkc4BvDXnoC6igAAADk"]
[Thu Jul 30 12:19:44.868778 2026] [security2:error] [pid 727775:tid 727962] [client 158.158.105.63:18458] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/makeasmtp.php"] [unique_id "amuHsMDCZkc4BvDXnoC6igAAADk"]
[Thu Jul 30 12:19:45.142602 2026] [security2:error] [pid 727775:tid 728007] [client 158.158.105.63:18446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/2P.php"] [unique_id "amuHscDCZkc4BvDXnoC6kQAAAGY"]
[Thu Jul 30 12:19:45.142697 2026] [security2:error] [pid 727775:tid 728007] [client 158.158.105.63:18446] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/2P.php"] [unique_id "amuHscDCZkc4BvDXnoC6kQAAAGY"]
[Thu Jul 30 12:19:45.357231 2026] [security2:error] [pid 727775:tid 727937] [client 195.113.175.167:12606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.175.113.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/misionf.php"] [unique_id "amuHscDCZkc4BvDXnoC6lAAAACA"]
[Thu Jul 30 12:19:45.409948 2026] [security2:error] [pid 727775:tid 727921] [client 158.158.105.63:19606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/.well-known/about.php"] [unique_id "amuHscDCZkc4BvDXnoC6lwAAABA"]
[Thu Jul 30 12:19:45.410059 2026] [security2:error] [pid 727775:tid 727921] [client 158.158.105.63:19606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/.well-known/about.php"] [unique_id "amuHscDCZkc4BvDXnoC6lwAAABA"]
[Thu Jul 30 12:19:45.435719 2026] [security2:error] [pid 727775:tid 727972] [client 20.151.221.234:41731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/gg.php"] [unique_id "amuHscDCZkc4BvDXnoC6mwAAAEM"]
[Thu Jul 30 12:19:45.734340 2026] [security2:error] [pid 727775:tid 728019] [client 74.7.241.191:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "evermed-med-sa.com"] [uri "/cgi-sys/404.html"] [unique_id "amuHscDCZkc4BvDXnoC6owAAclY"]
[Thu Jul 30 12:19:45.798025 2026] [security2:error] [pid 727775:tid 727942] [client 158.158.105.63:18453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuHscDCZkc4BvDXnoC6pAAAACU"]
[Thu Jul 30 12:19:45.798129 2026] [security2:error] [pid 727775:tid 727942] [client 158.158.105.63:18453] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuHscDCZkc4BvDXnoC6pAAAACU"]
[Thu Jul 30 12:19:46.085523 2026] [security2:error] [pid 727775:tid 727986] [client 158.158.105.63:18485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/system_log.php"] [unique_id "amuHssDCZkc4BvDXnoC6rQAAAFE"]
[Thu Jul 30 12:19:46.085683 2026] [security2:error] [pid 727775:tid 727986] [client 158.158.105.63:18485] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/system_log.php"] [unique_id "amuHssDCZkc4BvDXnoC6rQAAAFE"]
[Thu Jul 30 12:19:46.342426 2026] [security2:error] [pid 727775:tid 727944] [client 74.7.228.16:54050] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.bss.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuHr8DCZkc4BvDXnoC6bwAAJ04"]
[Thu Jul 30 12:19:46.342463 2026] [security2:error] [pid 727775:tid 727944] [client 74.7.228.16:54050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bss.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuHr8DCZkc4BvDXnoC6bwAAJ04"]
[Thu Jul 30 12:19:46.355023 2026] [security2:error] [pid 727775:tid 728026] [client 74.7.230.30:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-3a7cf4bc.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuHsMDCZkc4BvDXnoC6fQAAAHk"]
[Thu Jul 30 12:19:46.356090 2026] [security2:error] [pid 727775:tid 728001] [client 74.7.230.30:46260] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-3a7cf4bc.glb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuHsMDCZkc4BvDXnoC6ewAAYFU"]
[Thu Jul 30 12:19:46.454604 2026] [security2:error] [pid 727775:tid 728006] [client 20.151.221.234:41735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp.php"] [unique_id "amuHssDCZkc4BvDXnoC6ugAAAGU"]
[Thu Jul 30 12:19:46.529887 2026] [security2:error] [pid 727775:tid 727936] [client 40.77.167.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuHssDCZkc4BvDXnoC6swAAAB8"]
[Thu Jul 30 12:19:46.550051 2026] [security2:error] [pid 727775:tid 727926] [client 157.90.155.240:3748] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuHssDCZkc4BvDXnoC6vQAAABU"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:19:46.613353 2026] [security2:error] [pid 727775:tid 727995] [client 158.158.105.63:52279] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/"] [unique_id "amuHssDCZkc4BvDXnoC6vgAAAFo"]
[Thu Jul 30 12:19:46.830304 2026] [security2:error] [pid 727775:tid 727916] [client 158.158.105.63:52279] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/colors/modern/"] [unique_id "amuHssDCZkc4BvDXnoC6xgAAAAs"]
[Thu Jul 30 12:19:46.960107 2026] [security2:error] [pid 727775:tid 727968] [client 158.158.105.63:52279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/crgio.php"] [unique_id "amuHssDCZkc4BvDXnoC6ygAAAD8"]
[Thu Jul 30 12:19:46.960222 2026] [security2:error] [pid 727775:tid 727968] [client 158.158.105.63:52279] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/crgio.php"] [unique_id "amuHssDCZkc4BvDXnoC6ygAAAD8"]
[Thu Jul 30 12:19:47.029681 2026] [security2:error] [pid 727775:tid 728008] [client 20.63.98.115:47274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wso.php"] [unique_id "amuHs8DCZkc4BvDXnoC60QAAAGc"]
[Thu Jul 30 12:19:47.094501 2026] [security2:error] [pid 727775:tid 727910] [client 74.7.228.16:34452] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bss.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuHssDCZkc4BvDXnoC6zAAABXg"], referer: https://www.bss.nyx.temporary.site/robots.txt
[Thu Jul 30 12:19:47.113747 2026] [core:notice] [pid 727775:tid 727993] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:19:47.121796 2026] [security2:error] [pid 727775:tid 727993] [client 157.90.155.240:3758] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuHs8DCZkc4BvDXnoC60gAAAFg"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:19:47.320308 2026] [security2:error] [pid 727775:tid 727960] [client 158.158.105.63:19638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/pucci.php"] [unique_id "amuHs8DCZkc4BvDXnoC64AAAADc"]
[Thu Jul 30 12:19:47.320432 2026] [security2:error] [pid 727775:tid 727960] [client 158.158.105.63:19638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/pucci.php"] [unique_id "amuHs8DCZkc4BvDXnoC64AAAADc"]
[Thu Jul 30 12:19:47.443865 2026] [security2:error] [pid 727775:tid 727907] [client 20.151.221.234:44739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuHs8DCZkc4BvDXnoC65AAAAAI"]
[Thu Jul 30 12:19:47.604579 2026] [security2:error] [pid 727775:tid 727978] [client 158.158.105.63:56069] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/___proxy_subdomain_webdisk/wp-includes/blocks/details/"] [unique_id "amuHs8DCZkc4BvDXnoC66wAAAEk"]
[Thu Jul 30 12:19:47.610322 2026] [security2:error] [pid 727775:tid 728028] [client 2a03:2880:f800:43:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuHssDCZkc4BvDXnoC6zQAAe3w"]
[Thu Jul 30 12:19:47.684012 2026] [security2:error] [pid 727775:tid 728010] [client 157.90.155.240:24706] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuHs8DCZkc4BvDXnoC67wAAAGk"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:19:47.746179 2026] [security2:error] [pid 727775:tid 727943] [client 158.158.105.63:56069] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/___proxy_subdomain_webdisk/wp-includes/blocks/audio/"] [unique_id "amuHs8DCZkc4BvDXnoC68AAAACY"]
[Thu Jul 30 12:19:47.874828 2026] [security2:error] [pid 727775:tid 727957] [client 158.158.105.63:56069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-temp.php"] [unique_id "amuHs8DCZkc4BvDXnoC69QAAADQ"]
[Thu Jul 30 12:19:47.874956 2026] [security2:error] [pid 727775:tid 727957] [client 158.158.105.63:56069] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-temp.php"] [unique_id "amuHs8DCZkc4BvDXnoC69QAAADQ"]
[Thu Jul 30 12:19:48.089059 2026] [security2:error] [pid 727775:tid 727999] [client 172.213.232.128:18596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/languages/about.php"] [unique_id "amuHtMDCZkc4BvDXnoC6_gAAAF4"]
[Thu Jul 30 12:19:48.146938 2026] [security2:error] [pid 727775:tid 727911] [client 158.158.105.63:18465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-admin/js/index.php"] [unique_id "amuHtMDCZkc4BvDXnoC7AAAAAAY"]
[Thu Jul 30 12:19:48.147063 2026] [security2:error] [pid 727775:tid 727911] [client 158.158.105.63:18465] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-admin/js/index.php"] [unique_id "amuHtMDCZkc4BvDXnoC7AAAAAAY"]
[Thu Jul 30 12:19:48.172089 2026] [core:notice] [pid 727775:tid 727935] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:19:48.468275 2026] [security2:error] [pid 727775:tid 727959] [client 20.151.221.234:44127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-admin/file.php"] [unique_id "amuHtMDCZkc4BvDXnoC7DQAAADY"]
[Thu Jul 30 12:19:48.604708 2026] [core:notice] [pid 727775:tid 728027] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:19:48.699341 2026] [security2:error] [pid 727775:tid 727983] [client 158.158.105.63:52278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/puc.php"] [unique_id "amuHtMDCZkc4BvDXnoC7GwAAAE4"]
[Thu Jul 30 12:19:48.699468 2026] [security2:error] [pid 727775:tid 727983] [client 158.158.105.63:52278] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/puc.php"] [unique_id "amuHtMDCZkc4BvDXnoC7GwAAAE4"]
[Thu Jul 30 12:19:48.707529 2026] [security2:error] [pid 727775:tid 727931] [client 20.63.98.115:61421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/sh.php"] [unique_id "amuHtMDCZkc4BvDXnoC7HAAAABo"]
[Thu Jul 30 12:19:48.993871 2026] [security2:error] [pid 727775:tid 727938] [client 172.213.232.128:23105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/customize/about.php"] [unique_id "amuHtMDCZkc4BvDXnoC7JAAAACE"]
[Thu Jul 30 12:19:49.056866 2026] [security2:error] [pid 727775:tid 727978] [client 158.158.105.63:56083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/dx.php"] [unique_id "amuHtcDCZkc4BvDXnoC7KgAAAEk"]
[Thu Jul 30 12:19:49.056965 2026] [security2:error] [pid 727775:tid 727978] [client 158.158.105.63:56083] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/dx.php"] [unique_id "amuHtcDCZkc4BvDXnoC7KgAAAEk"]
[Thu Jul 30 12:19:49.400214 2026] [security2:error] [pid 727775:tid 727932] [client 158.158.105.63:18464] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/___proxy_subdomain_webdisk/wp-includes/Requests/"] [unique_id "amuHtcDCZkc4BvDXnoC7MQAAABs"]
[Thu Jul 30 12:19:49.540747 2026] [security2:error] [pid 727775:tid 727987] [client 158.158.105.63:18464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/7.php"] [unique_id "amuHtcDCZkc4BvDXnoC7NgAAAFI"]
[Thu Jul 30 12:19:49.540846 2026] [security2:error] [pid 727775:tid 727987] [client 158.158.105.63:18464] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/7.php"] [unique_id "amuHtcDCZkc4BvDXnoC7NgAAAFI"]
[Thu Jul 30 12:19:49.720173 2026] [security2:error] [pid 727775:tid 727944] [client 172.213.232.128:16222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes.bak/html-api/about.php"] [unique_id "amuHtcDCZkc4BvDXnoC7OAAAACc"]
[Thu Jul 30 12:19:49.759073 2026] [core:notice] [pid 727775:tid 727946] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:19:49.853974 2026] [security2:error] [pid 727775:tid 727985] [client 158.158.105.63:52285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/8.php"] [unique_id "amuHtcDCZkc4BvDXnoC7OwAAAFA"]
[Thu Jul 30 12:19:49.854096 2026] [security2:error] [pid 727775:tid 727985] [client 158.158.105.63:52285] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/8.php"] [unique_id "amuHtcDCZkc4BvDXnoC7OwAAAFA"]
[Thu Jul 30 12:19:50.063360 2026] [security2:error] [pid 727775:tid 727950] [client 20.63.98.115:51807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/send.php"] [unique_id "amuHtsDCZkc4BvDXnoC7QgAAAC0"]
[Thu Jul 30 12:19:50.083383 2026] [security2:error] [pid 727775:tid 727934] [client 20.151.221.234:41661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-admin/user/index.php"] [unique_id "amuHtsDCZkc4BvDXnoC7QwAAAB0"]
[Thu Jul 30 12:19:50.158392 2026] [security2:error] [pid 727775:tid 727964] [client 158.158.105.63:52237] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/1.php"] [unique_id "amuHtsDCZkc4BvDXnoC7RAAAADs"]
[Thu Jul 30 12:19:50.158512 2026] [security2:error] [pid 727775:tid 727964] [client 158.158.105.63:52237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/1.php"] [unique_id "amuHtsDCZkc4BvDXnoC7RAAAADs"]
[Thu Jul 30 12:19:50.158605 2026] [security2:error] [pid 727775:tid 727964] [client 158.158.105.63:52237] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/1.php"] [unique_id "amuHtsDCZkc4BvDXnoC7RAAAADs"]
[Thu Jul 30 12:19:50.490414 2026] [security2:error] [pid 727775:tid 727912] [client 158.158.105.63:19605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/about.php"] [unique_id "amuHtsDCZkc4BvDXnoC7UwAAAAc"]
[Thu Jul 30 12:19:50.490505 2026] [security2:error] [pid 727775:tid 727912] [client 158.158.105.63:19605] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/about.php"] [unique_id "amuHtsDCZkc4BvDXnoC7UwAAAAc"]
[Thu Jul 30 12:19:50.874175 2026] [security2:error] [pid 727775:tid 727945] [client 158.158.105.63:19586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/admin.php"] [unique_id "amuHtsDCZkc4BvDXnoC7WgAAACg"]
[Thu Jul 30 12:19:50.874285 2026] [security2:error] [pid 727775:tid 727945] [client 158.158.105.63:19586] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/admin.php"] [unique_id "amuHtsDCZkc4BvDXnoC7WgAAACg"]
[Thu Jul 30 12:19:51.338968 2026] [security2:error] [pid 727775:tid 727978] [client 158.158.105.63:56096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/edit.php"] [unique_id "amuHt8DCZkc4BvDXnoC7YgAAAEk"]
[Thu Jul 30 12:19:51.339128 2026] [security2:error] [pid 727775:tid 727978] [client 158.158.105.63:56096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/edit.php"] [unique_id "amuHt8DCZkc4BvDXnoC7YgAAAEk"]
[Thu Jul 30 12:19:51.616212 2026] [security2:error] [pid 727775:tid 727916] [client 158.158.105.63:19619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-content/admin.php"] [unique_id "amuHt8DCZkc4BvDXnoC7bQAAAAs"]
[Thu Jul 30 12:19:51.616329 2026] [security2:error] [pid 727775:tid 727916] [client 158.158.105.63:19619] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-content/admin.php"] [unique_id "amuHt8DCZkc4BvDXnoC7bQAAAAs"]
[Thu Jul 30 12:19:51.697846 2026] [security2:error] [pid 727775:tid 727991] [client 172.213.232.128:6708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/widgets/about.php"] [unique_id "amuHt8DCZkc4BvDXnoC7bgAAAFY"]
[Thu Jul 30 12:19:51.878347 2026] [security2:error] [pid 727775:tid 727961] [client 158.158.105.63:19598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/inputs.php"] [unique_id "amuHt8DCZkc4BvDXnoC7bwAAADg"]
[Thu Jul 30 12:19:51.878449 2026] [security2:error] [pid 727775:tid 727961] [client 158.158.105.63:19598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/inputs.php"] [unique_id "amuHt8DCZkc4BvDXnoC7bwAAADg"]
[Thu Jul 30 12:19:52.165688 2026] [security2:error] [pid 727775:tid 727934] [client 158.158.105.63:19599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/av.php"] [unique_id "amuHuMDCZkc4BvDXnoC7egAAAB0"]
[Thu Jul 30 12:19:52.165789 2026] [security2:error] [pid 727775:tid 727934] [client 158.158.105.63:19599] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/av.php"] [unique_id "amuHuMDCZkc4BvDXnoC7egAAAB0"]
[Thu Jul 30 12:19:52.175155 2026] [security2:error] [pid 727775:tid 728000] [client 2a03:2880:f800:3e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuHt8DCZkc4BvDXnoC7aAAAXyc"]
[Thu Jul 30 12:19:52.457612 2026] [security2:error] [pid 727775:tid 727997] [client 158.158.105.63:52252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/classwithtostring.php"] [unique_id "amuHuMDCZkc4BvDXnoC7fQAAAFw"]
[Thu Jul 30 12:19:52.457738 2026] [security2:error] [pid 727775:tid 727997] [client 158.158.105.63:52252] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/classwithtostring.php"] [unique_id "amuHuMDCZkc4BvDXnoC7fQAAAFw"]
[Thu Jul 30 12:19:52.680266 2026] [security2:error] [pid 727775:tid 727955] [client 20.151.221.234:41785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amuHuMDCZkc4BvDXnoC7hwAAADI"]
[Thu Jul 30 12:19:52.778374 2026] [security2:error] [pid 727775:tid 727914] [client 158.158.105.63:52284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-content/themes/index.php"] [unique_id "amuHuMDCZkc4BvDXnoC7iAAAAAk"]
[Thu Jul 30 12:19:52.778507 2026] [security2:error] [pid 727775:tid 727914] [client 158.158.105.63:52284] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-content/themes/index.php"] [unique_id "amuHuMDCZkc4BvDXnoC7iAAAAAk"]
[Thu Jul 30 12:19:52.956290 2026] [security2:error] [pid 727775:tid 727956] [client 172.213.232.128:1772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/IXR/about.php"] [unique_id "amuHuMDCZkc4BvDXnoC7iQAAADM"]
[Thu Jul 30 12:19:53.188752 2026] [security2:error] [pid 727775:tid 727942] [client 158.158.105.63:52272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-blog.php"] [unique_id "amuHucDCZkc4BvDXnoC7kAAAACU"]
[Thu Jul 30 12:19:53.188838 2026] [security2:error] [pid 727775:tid 727942] [client 158.158.105.63:52272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-blog.php"] [unique_id "amuHucDCZkc4BvDXnoC7kAAAACU"]
[Thu Jul 30 12:19:53.785606 2026] [security2:error] [pid 727775:tid 728028] [client 158.158.105.63:19617] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/___proxy_subdomain_webdisk/wp-includes/js/jquery/"] [unique_id "amuHucDCZkc4BvDXnoC7mAAAAHs"]
[Thu Jul 30 12:19:53.891159 2026] [security2:error] [pid 727775:tid 728019] [client 20.151.221.234:44743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/index/function.php"] [unique_id "amuHucDCZkc4BvDXnoC7mQAAAHI"]
[Thu Jul 30 12:19:53.915056 2026] [security2:error] [pid 727775:tid 727927] [client 158.158.105.63:19617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-content/admin.php"] [unique_id "amuHucDCZkc4BvDXnoC7mgAAABY"]
[Thu Jul 30 12:19:53.915224 2026] [security2:error] [pid 727775:tid 727927] [client 158.158.105.63:19617] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-content/admin.php"] [unique_id "amuHucDCZkc4BvDXnoC7mgAAABY"]
[Thu Jul 30 12:19:54.193768 2026] [security2:error] [pid 727775:tid 727932] [client 158.158.105.63:19594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/adminfuns.php"] [unique_id "amuHusDCZkc4BvDXnoC7owAAABs"]
[Thu Jul 30 12:19:54.193899 2026] [security2:error] [pid 727775:tid 727932] [client 158.158.105.63:19594] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/adminfuns.php"] [unique_id "amuHusDCZkc4BvDXnoC7owAAABs"]
[Thu Jul 30 12:19:54.237141 2026] [security2:error] [pid 727775:tid 728024] [client 172.213.232.128:12447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/js/about.php"] [unique_id "amuHusDCZkc4BvDXnoC7pQAAAHc"]
[Thu Jul 30 12:19:54.499302 2026] [security2:error] [pid 727775:tid 727954] [client 158.158.105.63:19587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/goods.php"] [unique_id "amuHusDCZkc4BvDXnoC7pwAAADE"]
[Thu Jul 30 12:19:54.499417 2026] [security2:error] [pid 727775:tid 727954] [client 158.158.105.63:19587] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/goods.php"] [unique_id "amuHusDCZkc4BvDXnoC7pwAAADE"]
[Thu Jul 30 12:19:54.797288 2026] [security2:error] [pid 727775:tid 728023] [client 57.141.0.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuHusDCZkc4BvDXnoC7oQAAAHY"]
[Thu Jul 30 12:19:54.894785 2026] [security2:error] [pid 727775:tid 727999] [client 158.158.105.63:19602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/ms-edit.php"] [unique_id "amuHusDCZkc4BvDXnoC7rgAAAF4"]
[Thu Jul 30 12:19:54.894902 2026] [security2:error] [pid 727775:tid 727999] [client 158.158.105.63:19602] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/ms-edit.php"] [unique_id "amuHusDCZkc4BvDXnoC7rgAAAF4"]
[Thu Jul 30 12:19:55.168685 2026] [security2:error] [pid 727775:tid 728000] [client 158.158.105.63:19624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/222.php"] [unique_id "amuHu8DCZkc4BvDXnoC7sgAAAF8"]
[Thu Jul 30 12:19:55.168788 2026] [security2:error] [pid 727775:tid 728000] [client 158.158.105.63:19624] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/222.php"] [unique_id "amuHu8DCZkc4BvDXnoC7sgAAAF8"]
[Thu Jul 30 12:19:55.290117 2026] [security2:error] [pid 727775:tid 727959] [client 20.63.98.115:62035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/ds.php"] [unique_id "amuHu8DCZkc4BvDXnoC7tgAAADY"]
[Thu Jul 30 12:19:55.437668 2026] [security2:error] [pid 727775:tid 727995] [client 172.213.232.128:8803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amuHu8DCZkc4BvDXnoC7twAAAFo"]
[Thu Jul 30 12:19:55.462684 2026] [security2:error] [pid 727775:tid 728011] [client 158.158.105.63:19635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/cgi-bin/index.php"] [unique_id "amuHu8DCZkc4BvDXnoC7uAAAAGo"]
[Thu Jul 30 12:19:55.462829 2026] [security2:error] [pid 727775:tid 728011] [client 158.158.105.63:19635] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/cgi-bin/index.php"] [unique_id "amuHu8DCZkc4BvDXnoC7uAAAAGo"]
[Thu Jul 30 12:19:55.788287 2026] [security2:error] [pid 727775:tid 727909] [client 158.158.105.63:18445] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/___proxy_subdomain_webdisk/wp-includes/css/dist/"] [unique_id "amuHu8DCZkc4BvDXnoC7wQAAAAQ"]
[Thu Jul 30 12:19:55.917260 2026] [security2:error] [pid 727775:tid 727905] [client 158.158.105.63:18445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/BDKR28WP.php"] [unique_id "amuHu8DCZkc4BvDXnoC7wgAAAAA"]
[Thu Jul 30 12:19:55.917395 2026] [security2:error] [pid 727775:tid 727905] [client 158.158.105.63:18445] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/BDKR28WP.php"] [unique_id "amuHu8DCZkc4BvDXnoC7wgAAAAA"]
[Thu Jul 30 12:19:56.236784 2026] [security2:error] [pid 727775:tid 728007] [client 158.158.105.63:19612] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/___proxy_subdomain_webdisk/wp-includes/l10n/"] [unique_id "amuHvMDCZkc4BvDXnoC7xwAAAGY"]
[Thu Jul 30 12:19:56.379974 2026] [security2:error] [pid 727775:tid 727915] [client 158.158.105.63:19612] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/___proxy_subdomain_webdisk/wp-content/uploads/"] [unique_id "amuHvMDCZkc4BvDXnoC7ywAAAAo"]
[Thu Jul 30 12:19:56.509621 2026] [security2:error] [pid 727775:tid 727990] [client 158.158.105.63:19612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp.php"] [unique_id "amuHvMDCZkc4BvDXnoC7zAAAAFU"]
[Thu Jul 30 12:19:56.509776 2026] [security2:error] [pid 727775:tid 727990] [client 158.158.105.63:19612] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp.php"] [unique_id "amuHvMDCZkc4BvDXnoC7zAAAAFU"]
[Thu Jul 30 12:19:56.742093 2026] [security2:error] [pid 727775:tid 727944] [client 2a03:2880:f800:f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuHvMDCZkc4BvDXnoC7wwAAJz8"]
[Thu Jul 30 12:19:56.885282 2026] [core:notice] [pid 727775:tid 727955] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:19:57.060425 2026] [security2:error] [pid 727775:tid 728032] [client 158.158.105.63:18438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/abcd.php"] [unique_id "amuHvcDCZkc4BvDXnoC71QAAAH8"]
[Thu Jul 30 12:19:57.060545 2026] [security2:error] [pid 727775:tid 728032] [client 158.158.105.63:18438] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/abcd.php"] [unique_id "amuHvcDCZkc4BvDXnoC71QAAAH8"]
[Thu Jul 30 12:19:57.379482 2026] [security2:error] [pid 727775:tid 728024] [client 158.158.105.63:19641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/a1.php"] [unique_id "amuHvcDCZkc4BvDXnoC74AAAAHc"]
[Thu Jul 30 12:19:57.379589 2026] [security2:error] [pid 727775:tid 728024] [client 158.158.105.63:19641] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/a1.php"] [unique_id "amuHvcDCZkc4BvDXnoC74AAAAHc"]
[Thu Jul 30 12:19:57.389574 2026] [security2:error] [pid 727775:tid 727914] [client 20.63.98.115:47472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wso112233.php"] [unique_id "amuHvcDCZkc4BvDXnoC74QAAAAk"]
[Thu Jul 30 12:19:57.428822 2026] [security2:error] [pid 727775:tid 727916] [client 20.151.221.234:44762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/aaa.php"] [unique_id "amuHvcDCZkc4BvDXnoC74gAAAAs"]
[Thu Jul 30 12:19:57.796288 2026] [security2:error] [pid 727775:tid 728022] [client 158.158.105.63:18452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amuHvcDCZkc4BvDXnoC75gAAAHU"]
[Thu Jul 30 12:19:57.796398 2026] [security2:error] [pid 727775:tid 728022] [client 158.158.105.63:18452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amuHvcDCZkc4BvDXnoC75gAAAHU"]
[Thu Jul 30 12:19:58.488871 2026] [security2:error] [pid 727775:tid 727995] [client 158.158.105.63:33996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/cgi-bin/admin.php"] [unique_id "amuHvsDCZkc4BvDXnoC79AAAAFo"]
[Thu Jul 30 12:19:58.488994 2026] [security2:error] [pid 727775:tid 727995] [client 158.158.105.63:33996] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/cgi-bin/admin.php"] [unique_id "amuHvsDCZkc4BvDXnoC79AAAAFo"]
[Thu Jul 30 12:19:59.020366 2026] [security2:error] [pid 727775:tid 727924] [client 57.141.0.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuHvsDCZkc4BvDXnoC7_QAAABM"]
[Thu Jul 30 12:19:59.048781 2026] [security2:error] [pid 727775:tid 727920] [client 158.158.105.63:18449] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/___proxy_subdomain_webdisk/wp-content/"] [unique_id "amuHv8DCZkc4BvDXnoC8AQAAAA8"]
[Thu Jul 30 12:19:59.177792 2026] [security2:error] [pid 727775:tid 728017] [client 158.158.105.63:18449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/simple.php"] [unique_id "amuHv8DCZkc4BvDXnoC8AgAAAHA"]
[Thu Jul 30 12:19:59.177925 2026] [security2:error] [pid 727775:tid 728017] [client 158.158.105.63:18449] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/simple.php"] [unique_id "amuHv8DCZkc4BvDXnoC8AgAAAHA"]
[Thu Jul 30 12:19:59.560456 2026] [security2:error] [pid 727775:tid 728021] [client 20.151.221.234:41605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/getid3-core.php"] [unique_id "amuHv8DCZkc4BvDXnoC8CwAAAHQ"]
[Thu Jul 30 12:19:59.562142 2026] [security2:error] [pid 727775:tid 727939] [client 158.158.105.63:52286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/xxx.php"] [unique_id "amuHv8DCZkc4BvDXnoC8DAAAACI"]
[Thu Jul 30 12:19:59.562221 2026] [security2:error] [pid 727775:tid 727939] [client 158.158.105.63:52286] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/xxx.php"] [unique_id "amuHv8DCZkc4BvDXnoC8DAAAACI"]
[Thu Jul 30 12:19:59.834610 2026] [security2:error] [pid 727775:tid 727982] [client 20.63.98.115:47477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/images/wp-login.php"] [unique_id "amuHv8DCZkc4BvDXnoC8DQAAAE0"]
[Thu Jul 30 12:19:59.867187 2026] [security2:error] [pid 727775:tid 728031] [client 172.213.232.128:9685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/pomo/about.php"] [unique_id "amuHv8DCZkc4BvDXnoC8DgAAAH4"]
[Thu Jul 30 12:19:59.934074 2026] [security2:error] [pid 727775:tid 727917] [client 158.158.105.63:56065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/hypo.php"] [unique_id "amuHv8DCZkc4BvDXnoC8EgAAAAw"]
[Thu Jul 30 12:19:59.934167 2026] [security2:error] [pid 727775:tid 727917] [client 158.158.105.63:56065] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/hypo.php"] [unique_id "amuHv8DCZkc4BvDXnoC8EgAAAAw"]
[Thu Jul 30 12:20:00.529209 2026] [security2:error] [pid 727775:tid 727932] [client 158.158.105.63:18468] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/colors/blue/"] [unique_id "amuHwMDCZkc4BvDXnoC8HQAAABs"]
[Thu Jul 30 12:20:00.657741 2026] [security2:error] [pid 727775:tid 727916] [client 158.158.105.63:18468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/chosen.php"] [unique_id "amuHwMDCZkc4BvDXnoC8IAAAAAs"]
[Thu Jul 30 12:20:00.657869 2026] [security2:error] [pid 727775:tid 727916] [client 158.158.105.63:18468] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/chosen.php"] [unique_id "amuHwMDCZkc4BvDXnoC8IAAAAAs"]
[Thu Jul 30 12:20:00.716727 2026] [security2:error] [pid 727775:tid 727871] [remote 57.141.0.49:36352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/458796423/feed/rss2/"] [unique_id "amuHwMDCZkc4BvDXnoC8IgAAaV8"]
[Thu Jul 30 12:20:00.967913 2026] [security2:error] [pid 727775:tid 727994] [client 172.213.232.128:13827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/block-patterns/about.php"] [unique_id "amuHwMDCZkc4BvDXnoC8JwAAAFk"]
[Thu Jul 30 12:20:01.041598 2026] [security2:error] [pid 727775:tid 727976] [client 158.158.105.63:18436] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/___proxy_subdomain_webdisk/wp-includes/block-bindings/"] [unique_id "amuHwcDCZkc4BvDXnoC8KwAAAEc"]
[Thu Jul 30 12:20:01.171220 2026] [security2:error] [pid 727775:tid 727964] [client 158.158.105.63:18436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/als.php"] [unique_id "amuHwcDCZkc4BvDXnoC8LQAAADs"]
[Thu Jul 30 12:20:01.171341 2026] [security2:error] [pid 727775:tid 727964] [client 158.158.105.63:18436] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/als.php"] [unique_id "amuHwcDCZkc4BvDXnoC8LQAAADs"]
[Thu Jul 30 12:20:01.184790 2026] [security2:error] [pid 727775:tid 728028] [client 20.151.221.234:41649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/adminer.php"] [unique_id "amuHwcDCZkc4BvDXnoC8LgAAAHs"]
[Thu Jul 30 12:20:01.285344 2026] [security2:error] [pid 727775:tid 727985] [client 20.63.98.115:60802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "amuHwcDCZkc4BvDXnoC8LwAAAFA"]
[Thu Jul 30 12:20:01.498739 2026] [security2:error] [pid 727775:tid 727962] [client 158.158.105.63:19590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/pol.php"] [unique_id "amuHwcDCZkc4BvDXnoC8MwAAADk"]
[Thu Jul 30 12:20:01.498852 2026] [security2:error] [pid 727775:tid 727962] [client 158.158.105.63:19590] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/pol.php"] [unique_id "amuHwcDCZkc4BvDXnoC8MwAAADk"]
[Thu Jul 30 12:20:01.694774 2026] [security2:error] [pid 727775:tid 727867] [remote 52.167.144.147:63153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.aded-rdc.org"] [uri "/buy_guide/misionf.php"] [unique_id "amuHwcDCZkc4BvDXnoC8OAAAels"]
[Thu Jul 30 12:20:01.734726 2026] [security2:error] [pid 727775:tid 728009] [client 2a03:2880:f800:23:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuHwcDCZkc4BvDXnoC8LAAAaF0"]
[Thu Jul 30 12:20:01.790228 2026] [security2:error] [pid 727775:tid 727969] [client 158.158.105.63:52233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/file5.php"] [unique_id "amuHwcDCZkc4BvDXnoC8OgAAAEA"]
[Thu Jul 30 12:20:01.790414 2026] [security2:error] [pid 727775:tid 727969] [client 158.158.105.63:52233] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/file5.php"] [unique_id "amuHwcDCZkc4BvDXnoC8OgAAAEA"]
[Thu Jul 30 12:20:02.270089 2026] [security2:error] [pid 727775:tid 727956] [client 158.158.105.63:18441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/file.php"] [unique_id "amuHwsDCZkc4BvDXnoC8QQAAADM"]
[Thu Jul 30 12:20:02.270199 2026] [security2:error] [pid 727775:tid 727956] [client 158.158.105.63:18441] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/file.php"] [unique_id "amuHwsDCZkc4BvDXnoC8QQAAADM"]
[Thu Jul 30 12:20:02.385280 2026] [security2:error] [pid 727775:tid 727911] [client 172.213.232.128:1752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/updraft/about.php"] [unique_id "amuHwsDCZkc4BvDXnoC8QgAAAAY"]
[Thu Jul 30 12:20:02.454102 2026] [security2:error] [pid 727775:tid 727989] [client 20.63.98.115:61932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/mail.php"] [unique_id "amuHwsDCZkc4BvDXnoC8RAAAAFQ"]
[Thu Jul 30 12:20:02.561102 2026] [security2:error] [pid 727775:tid 728005] [client 158.158.105.63:18475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/admin.php"] [unique_id "amuHwsDCZkc4BvDXnoC8SAAAAGQ"]
[Thu Jul 30 12:20:02.561182 2026] [security2:error] [pid 727775:tid 728005] [client 158.158.105.63:18475] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/admin.php"] [unique_id "amuHwsDCZkc4BvDXnoC8SAAAAGQ"]
[Thu Jul 30 12:20:02.597001 2026] [security2:error] [pid 727775:tid 727990] [client 20.151.221.234:44738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/alfa.php"] [unique_id "amuHwsDCZkc4BvDXnoC8TAAAAFU"]
[Thu Jul 30 12:20:02.916058 2026] [security2:error] [pid 727775:tid 727982] [client 158.158.105.63:19636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/aa2.php"] [unique_id "amuHwsDCZkc4BvDXnoC8TQAAAE0"]
[Thu Jul 30 12:20:02.916174 2026] [security2:error] [pid 727775:tid 727982] [client 158.158.105.63:19636] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/aa2.php"] [unique_id "amuHwsDCZkc4BvDXnoC8TQAAAE0"]
[Thu Jul 30 12:20:03.301641 2026] [security2:error] [pid 727775:tid 728012] [client 158.158.105.63:19644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/ccou.php"] [unique_id "amuHw8DCZkc4BvDXnoC8VQAAAGs"]
[Thu Jul 30 12:20:03.301746 2026] [security2:error] [pid 727775:tid 728012] [client 158.158.105.63:19644] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/ccou.php"] [unique_id "amuHw8DCZkc4BvDXnoC8VQAAAGs"]
[Thu Jul 30 12:20:03.365373 2026] [security2:error] [pid 727775:tid 727965] [client 172.213.232.128:13881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "amuHw8DCZkc4BvDXnoC8VwAAADw"]
[Thu Jul 30 12:20:03.499896 2026] [security2:error] [pid 727775:tid 727881] [remote 57.141.0.49:36366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuHw8DCZkc4BvDXnoC8WAAAbWk"]
[Thu Jul 30 12:20:03.580362 2026] [security2:error] [pid 727775:tid 727943] [client 20.63.98.115:47428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-mail.php"] [unique_id "amuHw8DCZkc4BvDXnoC8YQAAACY"]
[Thu Jul 30 12:20:03.595506 2026] [security2:error] [pid 727775:tid 728004] [client 158.158.105.63:19593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/dr.php"] [unique_id "amuHw8DCZkc4BvDXnoC8YwAAAGM"]
[Thu Jul 30 12:20:03.595609 2026] [security2:error] [pid 727775:tid 728004] [client 158.158.105.63:19593] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/dr.php"] [unique_id "amuHw8DCZkc4BvDXnoC8YwAAAGM"]
[Thu Jul 30 12:20:03.605944 2026] [security2:error] [pid 727775:tid 727947] [client 68.235.38.2:39218] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuHw8DCZkc4BvDXnoC8VgAAACo"]
[Thu Jul 30 12:20:03.606061 2026] [security2:error] [pid 727775:tid 727947] [client 68.235.38.2:39218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuHw8DCZkc4BvDXnoC8VgAAACo"]
[Thu Jul 30 12:20:05.042054 2026] [security2:error] [pid 727775:tid 727958] [client 172.213.232.128:8812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/themes/about.php"] [unique_id "amuHxcDCZkc4BvDXnoC8dQAAADU"]
[Thu Jul 30 12:20:05.269189 2026] [security2:error] [pid 727775:tid 727906] [client 20.151.221.234:44785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amuHxcDCZkc4BvDXnoC8fwAAAAE"]
[Thu Jul 30 12:20:05.342012 2026] [security2:error] [pid 727775:tid 727908] [client 20.63.98.115:61940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-trackback.php"] [unique_id "amuHxcDCZkc4BvDXnoC8ggAAAAM"]
[Thu Jul 30 12:20:05.756221 2026] [security2:error] [pid 727775:tid 727911] [client 40.77.167.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuHxcDCZkc4BvDXnoC8hQAAAAY"]
[Thu Jul 30 12:20:06.058094 2026] [security2:error] [pid 727775:tid 727978] [client 20.151.221.234:41769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuHxsDCZkc4BvDXnoC8lQAAAEk"]
[Thu Jul 30 12:20:06.884823 2026] [core:notice] [pid 727775:tid 727929] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:20:06.888576 2026] [security2:error] [pid 727775:tid 727987] [client 172.213.232.128:8828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/includes/about.php"] [unique_id "amuHxsDCZkc4BvDXnoC8pQAAAFI"]
[Thu Jul 30 12:20:07.365713 2026] [security2:error] [pid 727775:tid 727963] [client 20.63.98.115:57108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/uploads/cong.php"] [unique_id "amuHx8DCZkc4BvDXnoC8sAAAADo"]
[Thu Jul 30 12:20:07.441294 2026] [security2:error] [pid 727775:tid 727946] [client 20.151.221.234:44746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amuHx8DCZkc4BvDXnoC8sQAAACk"]
[Thu Jul 30 12:20:08.246965 2026] [security2:error] [pid 727775:tid 727998] [client 172.213.232.128:8799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/images/about.php"] [unique_id "amuHyMDCZkc4BvDXnoC8wgAAAF0"]
[Thu Jul 30 12:20:08.340505 2026] [security2:error] [pid 727775:tid 728011] [client 20.63.98.115:61909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/plugins/admin.php"] [unique_id "amuHyMDCZkc4BvDXnoC8xgAAAGo"]
[Thu Jul 30 12:20:08.389265 2026] [security2:error] [pid 727775:tid 728007] [client 20.151.221.234:44774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/edit.php"] [unique_id "amuHyMDCZkc4BvDXnoC8ygAAAGY"]
[Thu Jul 30 12:20:09.539779 2026] [security2:error] [pid 727775:tid 727984] [client 68.235.38.2:56952] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuHycDCZkc4BvDXnoC84wAAAE8"]
[Thu Jul 30 12:20:09.539890 2026] [security2:error] [pid 727775:tid 727984] [client 68.235.38.2:56952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuHycDCZkc4BvDXnoC84wAAAE8"]
[Thu Jul 30 12:20:09.624428 2026] [security2:error] [pid 727775:tid 727970] [client 172.213.232.128:1766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/blogs.dir/about.php"] [unique_id "amuHycDCZkc4BvDXnoC85AAAAEE"]
[Thu Jul 30 12:20:09.645582 2026] [core:notice] [pid 727775:tid 727997] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:20:09.860035 2026] [security2:error] [pid 727775:tid 727943] [client 38.190.144.4:61288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuHycDCZkc4BvDXnoC86QAAACY"]
[Thu Jul 30 12:20:09.862332 2026] [security2:error] [pid 727775:tid 727943] [client 38.190.144.4:61288] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuHycDCZkc4BvDXnoC86QAAACY"]
[Thu Jul 30 12:20:09.897340 2026] [security2:error] [pid 727775:tid 727979] [client 20.63.98.115:62058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/webadmin.php"] [unique_id "amuHycDCZkc4BvDXnoC87QAAAEo"]
[Thu Jul 30 12:20:10.032658 2026] [security2:error] [pid 727775:tid 727962] [client 127.0.0.1:47862] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuHysDCZkc4BvDXnoC88wAAADk"]
[Thu Jul 30 12:20:10.032673 2026] [security2:error] [pid 727775:tid 727950] [client 127.0.0.1:47858] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.embassyofitalyislamabad.vip"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuHysDCZkc4BvDXnoC88gAAAC0"]
[Thu Jul 30 12:20:10.032786 2026] [security2:error] [pid 727775:tid 727930] [client 74.7.175.140:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.embassyofitalyislamabad.vip"] [uri "/robots.txt"] [unique_id "amuHysDCZkc4BvDXnoC88QAAGR4"]
[Thu Jul 30 12:20:10.485419 2026] [security2:error] [pid 727775:tid 727805] [remote 162.0.217.83:54042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.217.0.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/wp-login.php"] [unique_id "amuHysDCZkc4BvDXnoC8-QAASx0"]
[Thu Jul 30 12:20:10.610264 2026] [core:error] [pid 727775:tid 727909] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:20:10.610301 2026] [core:error] [pid 727775:tid 727909] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:20:10.639765 2026] [security2:error] [pid 727775:tid 727919] [client 172.213.232.128:8287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/images/about.php"] [unique_id "amuHysDCZkc4BvDXnoC8_QAAAA4"]
[Thu Jul 30 12:20:10.970940 2026] [security2:error] [pid 727775:tid 728029] [client 20.151.221.234:4353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/sf.php"] [unique_id "amuHysDCZkc4BvDXnoC9BgAAAHw"]
[Thu Jul 30 12:20:11.030859 2026] [security2:error] [pid 727775:tid 727907] [client 20.63.98.115:57136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/link.php"] [unique_id "amuHy8DCZkc4BvDXnoC9CgAAAAI"]
[Thu Jul 30 12:20:11.369909 2026] [core:notice] [pid 727775:tid 728018] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:20:12.160511 2026] [security2:error] [pid 727775:tid 727984] [client 20.151.221.234:41754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wso.php"] [unique_id "amuHzMDCZkc4BvDXnoC9HQAAAE8"]
[Thu Jul 30 12:20:12.224421 2026] [security2:error] [pid 727775:tid 728019] [client 172.213.232.128:1791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/about.php"] [unique_id "amuHzMDCZkc4BvDXnoC9HgAAAHI"]
[Thu Jul 30 12:20:12.678901 2026] [security2:error] [pid 727775:tid 728022] [client 20.63.98.115:60844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/ova.php"] [unique_id "amuHzMDCZkc4BvDXnoC9JwAAAHU"]
[Thu Jul 30 12:20:13.314652 2026] [security2:error] [pid 727775:tid 728008] [client 172.213.232.128:15689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/cgi-bin/about.php"] [unique_id "amuHzcDCZkc4BvDXnoC9MQAAAGc"]
[Thu Jul 30 12:20:13.738079 2026] [security2:error] [pid 727775:tid 727980] [client 20.63.98.115:20643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/css/colors/coffee/about.php"] [unique_id "amuHzcDCZkc4BvDXnoC9OQAAAEs"]
[Thu Jul 30 12:20:13.833187 2026] [security2:error] [pid 727775:tid 727985] [client 20.151.221.234:41636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/ioxi-o.php"] [unique_id "amuHzcDCZkc4BvDXnoC9OgAAAFA"]
[Thu Jul 30 12:20:14.425784 2026] [security2:error] [pid 727775:tid 727924] [client 172.213.232.128:9701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/gallery/about.php"] [unique_id "amuHzsDCZkc4BvDXnoC9RQAAABM"]
[Thu Jul 30 12:20:15.162750 2026] [security2:error] [pid 727775:tid 727913] [client 20.151.221.234:44754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/file56.php"] [unique_id "amuHz8DCZkc4BvDXnoC9WAAAAAg"]
[Thu Jul 30 12:20:15.170414 2026] [security2:error] [pid 727775:tid 728030] [client 57.141.0.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuHzsDCZkc4BvDXnoC9SAAAAH0"]
[Thu Jul 30 12:20:15.358239 2026] [security2:error] [pid 727775:tid 727999] [client 139.28.219.70:46454] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "exploringchanges.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuHz8DCZkc4BvDXnoC9XQAAAF4"]
[Thu Jul 30 12:20:15.388859 2026] [security2:error] [pid 727775:tid 728010] [client 172.213.232.128:1774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuHz8DCZkc4BvDXnoC9XgAAAGk"]
[Thu Jul 30 12:20:15.654350 2026] [security2:error] [pid 727775:tid 727842] [remote 216.73.216.152:54907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuHz8DCZkc4BvDXnoC9YgAAd0I"]
[Thu Jul 30 12:20:16.002436 2026] [security2:error] [pid 727775:tid 728022] [client 139.28.219.70:46470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "exploringchanges.com"] [uri "/xmlrpc.php"] [unique_id "amuHz8DCZkc4BvDXnoC9agAAAHU"]
[Thu Jul 30 12:20:16.252621 2026] [security2:error] [pid 727775:tid 727979] [client 20.63.98.115:57138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amuH0MDCZkc4BvDXnoC9cgAAAEo"]
[Thu Jul 30 12:20:16.346752 2026] [security2:error] [pid 727775:tid 727983] [client 172.213.232.128:13828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/css/about.php"] [unique_id "amuH0MDCZkc4BvDXnoC9dAAAAE4"]
[Thu Jul 30 12:20:16.481298 2026] [security2:error] [pid 727775:tid 727940] [client 20.151.221.234:41611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amuH0MDCZkc4BvDXnoC9dQAAACM"]
[Thu Jul 30 12:20:17.811551 2026] [security2:error] [pid 727775:tid 727915] [client 20.151.221.234:41758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-admin/css/index.php"] [unique_id "amuH0cDCZkc4BvDXnoC9kgAAAAo"]
[Thu Jul 30 12:20:18.460378 2026] [security2:error] [pid 727775:tid 727965] [client 74.7.241.129:58654] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.website-d29d2608.vdb.nyx.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuH0sDCZkc4BvDXnoC9ogAAPEw"]
[Thu Jul 30 12:20:18.716061 2026] [security2:error] [pid 727775:tid 727941] [client 172.213.232.128:39282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/images/about.php"] [unique_id "amuH0sDCZkc4BvDXnoC9owAAACQ"]
[Thu Jul 30 12:20:18.866323 2026] [security2:error] [pid 727775:tid 727946] [client 139.28.219.70:46478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "exploringchanges.com"] [uri "/xmlrpc.php"] [unique_id "amuH0sDCZkc4BvDXnoC9qgAAACk"]
[Thu Jul 30 12:20:18.866425 2026] [security2:error] [pid 727775:tid 727946] [client 139.28.219.70:46478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "exploringchanges.com"] [uri "/xmlrpc.php"] [unique_id "amuH0sDCZkc4BvDXnoC9qgAAACk"]
[Thu Jul 30 12:20:19.035300 2026] [security2:error] [pid 727775:tid 727987] [client 20.63.98.115:57127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/users.php"] [unique_id "amuH08DCZkc4BvDXnoC9rAAAAFI"]
[Thu Jul 30 12:20:19.647749 2026] [core:notice] [pid 727775:tid 727873] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:20:19.730240 2026] [security2:error] [pid 727775:tid 727936] [client 2a03:2880:f800:1e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuH08DCZkc4BvDXnoC9sAAAH0Y"]
[Thu Jul 30 12:20:19.895960 2026] [security2:error] [pid 727775:tid 727980] [client 20.63.98.115:61903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/defaults.php"] [unique_id "amuH08DCZkc4BvDXnoC9xgAAAEs"]
[Thu Jul 30 12:20:19.934614 2026] [security2:error] [pid 727775:tid 727998] [client 172.213.232.128:25056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/.well-known/pki-validation/cloud.php"] [unique_id "amuH08DCZkc4BvDXnoC9xwAAAF0"]
[Thu Jul 30 12:20:21.057914 2026] [security2:error] [pid 727775:tid 727913] [client 172.213.232.128:10446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/.well-known/acme-challenge/cloud.php"] [unique_id "amuH1cDCZkc4BvDXnoC91wAAAAg"]
[Thu Jul 30 12:20:21.314106 2026] [security2:error] [pid 727775:tid 727949] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.dl.happymod-apk.com.mx"] [uri "/"] [unique_id "amuH1cDCZkc4BvDXnoC92AAAACw"]
[Thu Jul 30 12:20:22.340409 2026] [security2:error] [pid 727775:tid 727999] [client 172.213.232.128:6658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/network/cloud.php"] [unique_id "amuH1sDCZkc4BvDXnoC97wAAAF4"]
[Thu Jul 30 12:20:23.432171 2026] [security2:error] [pid 727775:tid 728007] [client 172.213.232.128:18685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/cloud.php"] [unique_id "amuH18DCZkc4BvDXnoC9_QAAAGY"]
[Thu Jul 30 12:20:23.554877 2026] [core:notice] [pid 727775:tid 728015] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:20:24.036595 2026] [core:notice] [pid 727775:tid 727911] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:20:24.086990 2026] [security2:error] [pid 727775:tid 728013] [client 172.213.232.128:7762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/cgi-bin/cloud.php"] [unique_id "amuH2MDCZkc4BvDXnoC-DwAAAGw"]
[Thu Jul 30 12:20:24.233958 2026] [security2:error] [pid 727775:tid 728000] [client 20.151.221.234:49632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-content/edit.php"] [unique_id "amuH2MDCZkc4BvDXnoC-EAAAAF8"]
[Thu Jul 30 12:20:24.528686 2026] [core:notice] [pid 727775:tid 727899] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:20:24.704969 2026] [security2:error] [pid 727775:tid 727970] [client 172.213.232.128:10482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/updates.php"] [unique_id "amuH2MDCZkc4BvDXnoC-GwAAAEE"]
[Thu Jul 30 12:20:24.980308 2026] [security2:error] [pid 727775:tid 727947] [client 27.17.144.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuH2MDCZkc4BvDXnoC-EwAAKmI"]
[Thu Jul 30 12:20:25.105935 2026] [security2:error] [pid 727775:tid 727914] [client 20.151.221.234:50126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/2.php"] [unique_id "amuH2cDCZkc4BvDXnoC-HwAAAAk"]
[Thu Jul 30 12:20:25.278893 2026] [security2:error] [pid 727775:tid 728010] [client 172.213.232.128:1528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/css/cloud.php"] [unique_id "amuH2cDCZkc4BvDXnoC-IwAAAGk"]
[Thu Jul 30 12:20:25.576329 2026] [security2:error] [pid 727775:tid 728006] [client 184.75.223.195:60748] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuH2cDCZkc4BvDXnoC-JAAAAGU"]
[Thu Jul 30 12:20:25.576493 2026] [security2:error] [pid 727775:tid 728006] [client 184.75.223.195:60748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuH2cDCZkc4BvDXnoC-JAAAAGU"]
[Thu Jul 30 12:20:26.147260 2026] [security2:error] [pid 727775:tid 727988] [client 20.63.98.115:60859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/Text/about.php"] [unique_id "amuH2sDCZkc4BvDXnoC-NAAAAFM"]
[Thu Jul 30 12:20:26.766862 2026] [security2:error] [pid 727775:tid 727966] [client 27.17.144.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuH2sDCZkc4BvDXnoC-OQAAPQE"]
[Thu Jul 30 12:20:27.150989 2026] [security2:error] [pid 727775:tid 727788] [remote 156.59.198.136:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "nafmedical.com"] [uri "/wp-content/uploads/2025/06/image-placeholder-5-uai-1706x1280.jpg"] [unique_id "amuH28DCZkc4BvDXnoC-TQAAegw"], referer: https://nafmedical.com/features/row-animations/
[Thu Jul 30 12:20:27.519014 2026] [security2:error] [pid 727775:tid 727960] [client 57.129.81.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuH28DCZkc4BvDXnoC-UwAAADc"]
[Thu Jul 30 12:20:27.562637 2026] [security2:error] [pid 727775:tid 727979] [client 20.151.221.234:49602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "amuH28DCZkc4BvDXnoC-WAAAAEo"]
[Thu Jul 30 12:20:28.475479 2026] [security2:error] [pid 727775:tid 727954] [client 27.17.144.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuH3MDCZkc4BvDXnoC-YwAAMQQ"]
[Thu Jul 30 12:20:28.543679 2026] [security2:error] [pid 727775:tid 727999] [client 87.101.92.171:33188] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuH3MDCZkc4BvDXnoC-cwAAAF4"]
[Thu Jul 30 12:20:28.543780 2026] [security2:error] [pid 727775:tid 727999] [client 87.101.92.171:33188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuH3MDCZkc4BvDXnoC-cwAAAF4"]
[Thu Jul 30 12:20:28.621634 2026] [security2:error] [pid 727775:tid 727798] [remote 54.39.210.105:21866] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.urwru.club"] [uri "/sitemap.xml"] [unique_id "amuH3MDCZkc4BvDXnoC-dQAAGxY"]
[Thu Jul 30 12:20:28.621827 2026] [security2:error] [pid 727775:tid 727932] [client 54.39.210.105:21866] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.urwru.club"] [uri "/sitemap.xml"] [unique_id "amuH3MDCZkc4BvDXnoC-dQAAGxY"]
[Thu Jul 30 12:20:28.630042 2026] [security2:error] [pid 727775:tid 728022] [client 20.151.221.234:49623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/mah.php"] [unique_id "amuH3MDCZkc4BvDXnoC-dgAAAHU"]
[Thu Jul 30 12:20:29.005611 2026] [core:notice] [pid 727775:tid 727801] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:20:29.131941 2026] [security2:error] [pid 727775:tid 727966] [client 195.113.175.167:1655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.175.113.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/valuef.php"] [unique_id "amuH3cDCZkc4BvDXnoC-gwAAAD0"]
[Thu Jul 30 12:20:29.229392 2026] [security2:error] [pid 727775:tid 727908] [client 172.213.232.128:22651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/user/cloud.php"] [unique_id "amuH3cDCZkc4BvDXnoC-hQAAAAM"]
[Thu Jul 30 12:20:29.357345 2026] [security2:error] [pid 727775:tid 728003] [client 54.38.214.226:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuH3cDCZkc4BvDXnoC-iQAAAGI"]
[Thu Jul 30 12:20:29.632062 2026] [security2:error] [pid 727775:tid 728027] [client 27.17.144.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuH3cDCZkc4BvDXnoC-jAAAeiA"]
[Thu Jul 30 12:20:29.735139 2026] [security2:error] [pid 727775:tid 727805] [remote 57.141.0.12:42830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/619183613/feed/rss2/"] [unique_id "amuH3cDCZkc4BvDXnoC-kQAAXx0"]
[Thu Jul 30 12:20:29.914740 2026] [security2:error] [pid 727775:tid 727928] [client 20.151.221.234:50149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/send.php"] [unique_id "amuH3cDCZkc4BvDXnoC-mAAAABc"]
[Thu Jul 30 12:20:29.961260 2026] [security2:error] [pid 727775:tid 728026] [client 172.213.232.128:2010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/img/cloud.php"] [unique_id "amuH3cDCZkc4BvDXnoC-mwAAAHk"]
[Thu Jul 30 12:20:30.093441 2026] [security2:error] [pid 727775:tid 727937] [client 20.63.98.115:62069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "amuH3sDCZkc4BvDXnoC-nAAAACA"]
[Thu Jul 30 12:20:30.461656 2026] [security2:error] [pid 727775:tid 727811] [remote 77.95.113.183:42542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.113.95.77.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp-login.php"] [unique_id "amuH3sDCZkc4BvDXnoC-pAAAKiM"]
[Thu Jul 30 12:20:30.573416 2026] [security2:error] [pid 727775:tid 728030] [client 172.213.232.128:6669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "amuH3sDCZkc4BvDXnoC-pQAAAH0"]
[Thu Jul 30 12:20:30.760680 2026] [security2:error] [pid 727775:tid 728025] [client 213.32.68.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuH3sDCZkc4BvDXnoC-qAAAAHg"]
[Thu Jul 30 12:20:30.806649 2026] [security2:error] [pid 727775:tid 727965] [client 20.151.221.234:49634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amuH3sDCZkc4BvDXnoC-sAAAADw"]
[Thu Jul 30 12:20:31.130282 2026] [security2:error] [pid 727775:tid 727976] [client 172.213.232.128:21661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/images/cloud.php"] [unique_id "amuH38DCZkc4BvDXnoC-vQAAAEc"]
[Thu Jul 30 12:20:31.235185 2026] [security2:error] [pid 727775:tid 727995] [client 51.38.115.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuH38DCZkc4BvDXnoC-vAAAAFo"]
[Thu Jul 30 12:20:31.330884 2026] [security2:error] [pid 727775:tid 728014] [client 2a03:2880:f800:5:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuH3sDCZkc4BvDXnoC-rAAAbSo"]
[Thu Jul 30 12:20:31.829810 2026] [security2:error] [pid 727775:tid 727957] [client 20.63.98.115:63364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/plugins.php"] [unique_id "amuH38DCZkc4BvDXnoC-xAAAADQ"]
[Thu Jul 30 12:20:32.134580 2026] [security2:error] [pid 727775:tid 727981] [client 172.213.232.128:19642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/avaa.php"] [unique_id "amuH4MDCZkc4BvDXnoC-zAAAAEw"]
[Thu Jul 30 12:20:32.299224 2026] [security2:error] [pid 727775:tid 727939] [client 20.151.221.234:49645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/about.php"] [unique_id "amuH4MDCZkc4BvDXnoC-zQAAACI"]
[Thu Jul 30 12:20:32.831899 2026] [security2:error] [pid 727775:tid 727944] [client 20.63.98.115:27168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/upgrade/wp-login.php"] [unique_id "amuH4MDCZkc4BvDXnoC-1QAAACc"]
[Thu Jul 30 12:20:33.003304 2026] [security2:error] [pid 727775:tid 727959] [client 27.17.144.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuH4MDCZkc4BvDXnoC-1AAANis"]
[Thu Jul 30 12:20:33.221906 2026] [security2:error] [pid 727775:tid 728026] [client 20.151.221.234:49662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/options.php"] [unique_id "amuH4cDCZkc4BvDXnoC-3wAAAHk"]
[Thu Jul 30 12:20:33.497161 2026] [security2:error] [pid 727775:tid 728012] [client 172.213.232.128:9701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/images/cloud.php"] [unique_id "amuH4cDCZkc4BvDXnoC-4wAAAGs"]
[Thu Jul 30 12:20:34.020694 2026] [security2:error] [pid 727775:tid 727965] [client 20.63.98.115:54562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/certificates/wp-login.php"] [unique_id "amuH4sDCZkc4BvDXnoC-7gAAADw"]
[Thu Jul 30 12:20:34.072834 2026] [core:notice] [pid 727775:tid 727836] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:20:34.095086 2026] [security2:error] [pid 727775:tid 728001] [client 20.151.221.234:49639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuH4sDCZkc4BvDXnoC-8wAAAGA"]
[Thu Jul 30 12:20:34.145716 2026] [core:notice] [pid 727775:tid 727975] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:20:34.308584 2026] [core:notice] [pid 727775:tid 727829] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:20:34.352474 2026] [security2:error] [pid 727775:tid 727833] [remote 57.141.0.6:50810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amuH4sDCZkc4BvDXnoC-9QAAMDk"]
[Thu Jul 30 12:20:34.899170 2026] [security2:error] [pid 727775:tid 727946] [client 20.151.221.234:50135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-file.php"] [unique_id "amuH4sDCZkc4BvDXnoC-_gAAACk"]
[Thu Jul 30 12:20:35.004931 2026] [security2:error] [pid 727775:tid 727986] [client 27.17.144.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuH4sDCZkc4BvDXnoC-_QAAUUI"]
[Thu Jul 30 12:20:35.095378 2026] [security2:error] [pid 727775:tid 727834] [remote 74.7.241.59:46718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuH48DCZkc4BvDXnoC_AgAALTo"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/premium-addons-for-elementor/modules/woocommerce/templates
[Thu Jul 30 12:20:35.745961 2026] [security2:error] [pid 727775:tid 727990] [client 20.63.98.115:21060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/css/network.php"] [unique_id "amuH48DCZkc4BvDXnoC_EAAAAFU"]
[Thu Jul 30 12:20:35.876042 2026] [security2:error] [pid 727775:tid 727984] [client 20.151.221.234:49636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/sid3.php"] [unique_id "amuH48DCZkc4BvDXnoC_EgAAAE8"]
[Thu Jul 30 12:20:36.216276 2026] [security2:error] [pid 727775:tid 727844] [remote 216.73.216.152:56387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuH5MDCZkc4BvDXnoC_GQAAdEQ"]
[Thu Jul 30 12:20:36.629092 2026] [security2:error] [pid 727775:tid 727934] [client 172.213.232.128:1400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/js/widgets/cloud.php"] [unique_id "amuH5MDCZkc4BvDXnoC_IwAAAB0"]
[Thu Jul 30 12:20:36.823281 2026] [security2:error] [pid 727775:tid 728024] [client 27.17.144.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuH5MDCZkc4BvDXnoC_GwAAd0g"]
[Thu Jul 30 12:20:36.840601 2026] [core:notice] [pid 727775:tid 728020] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:20:37.250298 2026] [security2:error] [pid 727775:tid 727988] [client 172.213.232.128:1880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/Requests/Text/admin.php"] [unique_id "amuH5cDCZkc4BvDXnoC_MwAAAFM"]
[Thu Jul 30 12:20:37.356118 2026] [security2:error] [pid 727775:tid 727937] [client 43.166.237.57:55288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.237.166.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/index/user/register"] [unique_id "amuH5cDCZkc4BvDXnoC_NAAAACA"], referer: https://ejournalugj.com/index_php/index/user/register
[Thu Jul 30 12:20:38.625937 2026] [security2:error] [pid 727775:tid 727958] [client 20.63.98.115:58212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-cron.php"] [unique_id "amuH5sDCZkc4BvDXnoC_QwAAADU"]
[Thu Jul 30 12:20:39.162221 2026] [security2:error] [pid 727775:tid 727938] [client 27.17.144.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuH5sDCZkc4BvDXnoC_RwAAIVw"]
[Thu Jul 30 12:20:39.520831 2026] [security2:error] [pid 727775:tid 727944] [client 20.63.98.115:54555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/acp.php"] [unique_id "amuH58DCZkc4BvDXnoC_VQAAACc"]
[Thu Jul 30 12:20:39.801940 2026] [core:notice] [pid 727775:tid 727996] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:20:40.670570 2026] [security2:error] [pid 727775:tid 727978] [client 20.63.98.115:39052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/assets/bypass.php"] [unique_id "amuH6MDCZkc4BvDXnoC_ZwAAAEk"]
[Thu Jul 30 12:20:42.024453 2026] [security2:error] [pid 727775:tid 727906] [client 20.63.98.115:54561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/sx.php"] [unique_id "amuH6sDCZkc4BvDXnoC_gAAAAAE"]
[Thu Jul 30 12:20:42.326108 2026] [security2:error] [pid 727775:tid 727886] [remote 27.17.144.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuH6cDCZkc4BvDXnoC_fwAATW4"]
[Thu Jul 30 12:20:42.788338 2026] [security2:error] [pid 727775:tid 727948] [client 57.141.0.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuH6sDCZkc4BvDXnoC_gwAAACs"]
[Thu Jul 30 12:20:43.046231 2026] [security2:error] [pid 727775:tid 728000] [client 20.63.98.115:58181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/adminfuns.php"] [unique_id "amuH68DCZkc4BvDXnoC_kgAAAF8"]
[Thu Jul 30 12:20:43.812425 2026] [core:error] [pid 727775:tid 727924] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:20:43.812452 2026] [core:error] [pid 727775:tid 727924] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:20:43.885173 2026] [security2:error] [pid 727775:tid 727996] [client 20.63.98.115:63381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/about.php"] [unique_id "amuH68DCZkc4BvDXnoC_lwAAAFs"]
[Thu Jul 30 12:20:45.197622 2026] [security2:error] [pid 727775:tid 727999] [client 27.17.144.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuH7MDCZkc4BvDXnoC_qgAAXnA"]
[Thu Jul 30 12:20:45.530656 2026] [core:notice] [pid 727775:tid 728002] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:20:45.711744 2026] [security2:error] [pid 727775:tid 727782] [remote 216.73.216.152:56387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuH7cDCZkc4BvDXnoC_ugAAcQY"]
[Thu Jul 30 12:20:45.819987 2026] [security2:error] [pid 727775:tid 728023] [client 68.67.112.136:46180] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "kicksity.com"] [uri "/robots.txt"] [unique_id "amuH7cDCZkc4BvDXnoC_wQAAAHY"]
[Thu Jul 30 12:20:46.021680 2026] [core:notice] [pid 727775:tid 727927] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:20:46.346021 2026] [autoindex:error] [pid 727775:tid 727953] [client 20.63.98.115:57095] AH01276: Cannot serve directory /home1/wdrgplte/public_html/jesus.claims/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:20:46.584666 2026] [security2:error] [pid 727775:tid 727997] [client 20.63.98.115:57095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/images/chosen.php"] [unique_id "amuH7sDCZkc4BvDXnoC_zQAAAFw"]
[Thu Jul 30 12:20:46.796799 2026] [security2:error] [pid 727775:tid 727785] [remote 54.87.95.7:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/"] [unique_id "amuH7sDCZkc4BvDXnoC_1wAAVQk"]
[Thu Jul 30 12:20:47.658866 2026] [security2:error] [pid 727775:tid 727957] [client 223.109.255.159:45484] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2024/05/28/ricardo-coutinho-alfineta-cicero-lucena-e-diz-que-decisao-do-pt-mexeu-com-emocional-do-prefeito/"] [unique_id "amuH78DCZkc4BvDXnoDADQAAADQ"]
[Thu Jul 30 12:20:47.658945 2026] [security2:error] [pid 727775:tid 727957] [client 223.109.255.159:45484] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2024/05/28/ricardo-coutinho-alfineta-cicero-lucena-e-diz-que-decisao-do-pt-mexeu-com-emocional-do-prefeito/"] [unique_id "amuH78DCZkc4BvDXnoDADQAAADQ"]
[Thu Jul 30 12:20:48.077448 2026] [security2:error] [pid 727775:tid 728017] [client 27.17.144.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuH78DCZkc4BvDXnoDAEAAAcCE"]
[Thu Jul 30 12:20:48.629500 2026] [security2:error] [pid 727775:tid 727925] [client 87.101.92.171:41462] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuH8MDCZkc4BvDXnoDAHgAAABQ"]
[Thu Jul 30 12:20:48.629609 2026] [security2:error] [pid 727775:tid 727925] [client 87.101.92.171:41462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuH8MDCZkc4BvDXnoDAHgAAABQ"]
[Thu Jul 30 12:20:48.971018 2026] [security2:error] [pid 727775:tid 727944] [client 20.63.98.115:39066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/wp-class.php"] [unique_id "amuH8MDCZkc4BvDXnoDAJQAAACc"]
[Thu Jul 30 12:20:49.404944 2026] [core:error] [pid 727775:tid 728010] [client 34.139.111.28:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:20:49.404967 2026] [core:error] [pid 727775:tid 728010] [client 34.139.111.28:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:20:50.623613 2026] [security2:error] [pid 727775:tid 728022] [client 2a03:2880:f800:44:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuH8sDCZkc4BvDXnoDAOQAAdTA"]
[Thu Jul 30 12:20:51.099128 2026] [security2:error] [pid 727775:tid 727905] [client 20.63.98.115:27197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/install.php"] [unique_id "amuH88DCZkc4BvDXnoDAUAAAAAA"]
[Thu Jul 30 12:20:51.607327 2026] [security2:error] [pid 727775:tid 727960] [client 27.17.144.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuH88DCZkc4BvDXnoDAUQAANzk"]
[Thu Jul 30 12:20:52.122132 2026] [security2:error] [pid 727775:tid 727933] [client 172.213.232.128:20658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "amuH9MDCZkc4BvDXnoDAXwAAABw"]
[Thu Jul 30 12:20:52.806897 2026] [security2:error] [pid 727775:tid 727911] [client 2a03:2880:f800:40:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuH9MDCZkc4BvDXnoDAYAAABjo"]
[Thu Jul 30 12:20:53.302105 2026] [security2:error] [pid 727775:tid 727844] [remote 190.92.174.190:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "embassyofitalyislamabad.vip"] [uri "/wp-login.php"] [unique_id "amuH9cDCZkc4BvDXnoDAdQAAfEQ"]
[Thu Jul 30 12:20:53.848771 2026] [core:error] [pid 727775:tid 727913] [client 34.139.111.28:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:20:53.848793 2026] [core:error] [pid 727775:tid 727913] [client 34.139.111.28:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:20:54.154691 2026] [security2:error] [pid 727775:tid 727908] [client 172.213.232.128:9205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/includes/cloud.php"] [unique_id "amuH9sDCZkc4BvDXnoDAiQAAAAM"]
[Thu Jul 30 12:20:55.076690 2026] [security2:error] [pid 727775:tid 727990] [client 172.213.232.128:23064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/css/colors/blue/cloud.php"] [unique_id "amuH98DCZkc4BvDXnoDAlAAAAFU"]
[Thu Jul 30 12:20:55.690337 2026] [security2:error] [pid 727775:tid 727935] [client 172.213.232.128:9175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/cloud.php"] [unique_id "amuH98DCZkc4BvDXnoDAnAAAAB4"]
[Thu Jul 30 12:20:55.908227 2026] [security2:error] [pid 727775:tid 728030] [client 57.141.0.41:21246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuH98DCZkc4BvDXnoDAmAAAfV8"], referer: https://igetvape-australia.com/product/iget-moon-passion-fruit-lychee/?add-to-cart=138
[Thu Jul 30 12:20:56.357766 2026] [security2:error] [pid 727775:tid 727975] [client 172.213.232.128:22131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/updates.php"] [unique_id "amuH-MDCZkc4BvDXnoDApgAAAEY"]
[Thu Jul 30 12:20:56.821307 2026] [security2:error] [pid 727775:tid 728006] [client 172.213.232.128:23063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/libraries/legacy/updates.php"] [unique_id "amuH-MDCZkc4BvDXnoDAsgAAAGU"]
[Thu Jul 30 12:20:57.464563 2026] [security2:error] [pid 727775:tid 727986] [client 172.213.232.128:9212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/libraries/phpmailer/updates.php"] [unique_id "amuH-cDCZkc4BvDXnoDAwAAAAFE"]
[Thu Jul 30 12:20:58.152028 2026] [security2:error] [pid 727775:tid 727905] [client 172.213.232.128:46959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/libraries/vendor/updates.php"] [unique_id "amuH-sDCZkc4BvDXnoDAzAAAAAA"]
[Thu Jul 30 12:20:59.632504 2026] [security2:error] [pid 727775:tid 727956] [client 172.213.232.128:15635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/alfa-rex.php7"] [unique_id "amuH-8DCZkc4BvDXnoDBDgAAADM"]
[Thu Jul 30 12:21:00.160215 2026] [security2:error] [pid 727775:tid 727976] [client 172.213.232.128:9199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/alfanew.php"] [unique_id "amuH_MDCZkc4BvDXnoDBHQAAAEc"]
[Thu Jul 30 12:21:00.662906 2026] [security2:error] [pid 727775:tid 727778] [remote 57.141.0.35:53132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuH_MDCZkc4BvDXnoDBKAAAVQI"]
[Thu Jul 30 12:21:00.758362 2026] [security2:error] [pid 727775:tid 727998] [client 57.141.0.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuH_MDCZkc4BvDXnoDBIAAAAF0"]
[Thu Jul 30 12:21:00.775578 2026] [security2:error] [pid 727775:tid 727925] [client 38.190.144.4:49369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuH_MDCZkc4BvDXnoDBKgAAABQ"]
[Thu Jul 30 12:21:00.775684 2026] [security2:error] [pid 727775:tid 727925] [client 38.190.144.4:49369] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuH_MDCZkc4BvDXnoDBKgAAABQ"]
[Thu Jul 30 12:21:00.779481 2026] [security2:error] [pid 727775:tid 727984] [client 74.7.244.13:52528] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "lark-shop.com"] [uri "/robots.txt"] [unique_id "amuH_MDCZkc4BvDXnoDBKQAATwA"]
[Thu Jul 30 12:21:00.993654 2026] [security2:error] [pid 727775:tid 727933] [client 172.213.232.128:25317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/plugins/Cache/Cache.php"] [unique_id "amuH_MDCZkc4BvDXnoDBNAAAABw"]
[Thu Jul 30 12:21:01.176223 2026] [security2:error] [pid 727775:tid 727949] [client 151.242.181.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amuH_MDCZkc4BvDXnoDBLgAAACw"], referer: https://tereashops.com/product-category/ploom-x/page/2/
[Thu Jul 30 12:21:02.479214 2026] [security2:error] [pid 727775:tid 727981] [client 20.63.98.115:21063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/cgi-bin/about.php"] [unique_id "amuH_sDCZkc4BvDXnoDBVAAAAEw"]
[Thu Jul 30 12:21:02.887029 2026] [core:error] [pid 727775:tid 727920] [client 66.249.65.101:63421] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:21:02.887054 2026] [core:error] [pid 727775:tid 727920] [client 66.249.65.101:63421] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:21:03.595517 2026] [security2:error] [pid 727775:tid 728016] [client 20.63.98.115:61444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/css/colors/about.php"] [unique_id "amuH_8DCZkc4BvDXnoDBbQAAAG8"]
[Thu Jul 30 12:21:04.819569 2026] [security2:error] [pid 727775:tid 728008] [client 20.63.98.115:61451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/.well-known/classwithtostring.php"] [unique_id "amuIAMDCZkc4BvDXnoDBhwAAAGc"]
[Thu Jul 30 12:21:05.350201 2026] [security2:error] [pid 727775:tid 728010] [client 68.235.38.2:53340] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuIAcDCZkc4BvDXnoDBjgAAAGk"]
[Thu Jul 30 12:21:05.350305 2026] [security2:error] [pid 727775:tid 728010] [client 68.235.38.2:53340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuIAcDCZkc4BvDXnoDBjgAAAGk"]
[Thu Jul 30 12:21:06.434241 2026] [core:notice] [pid 727775:tid 727951] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:21:08.451390 2026] [security2:error] [pid 727775:tid 728004] [client 20.203.148.31:36968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/011i.php"] [unique_id "amuIBMDCZkc4BvDXnoDBvAAAAGM"]
[Thu Jul 30 12:21:08.542548 2026] [core:notice] [pid 727775:tid 728006] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:21:08.591042 2026] [security2:error] [pid 727775:tid 727949] [client 123.245.84.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIBMDCZkc4BvDXnoDBuwAAACw"]
[Thu Jul 30 12:21:09.503934 2026] [security2:error] [pid 727775:tid 728010] [client 172.213.232.128:15637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/js/widgets/about.php7"] [unique_id "amuIBcDCZkc4BvDXnoDB2gAAAGk"]
[Thu Jul 30 12:21:09.590602 2026] [core:error] [pid 727775:tid 727838] [remote 74.7.230.55:57978] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:21:09.590622 2026] [core:error] [pid 727775:tid 727838] [remote 74.7.230.55:57978] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:21:09.590852 2026] [security2:error] [pid 727775:tid 727970] [client 74.7.230.55:57978] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "website-9bd961c9.ear.djb.temporary.site"] [uri "/index.php"] [unique_id "amuIBcDCZkc4BvDXnoDB2wAAQT4"]
[Thu Jul 30 12:21:10.065565 2026] [security2:error] [pid 727775:tid 727951] [client 20.203.148.31:49074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/03a005685d.php"] [unique_id "amuIBsDCZkc4BvDXnoDB6AAAAC4"]
[Thu Jul 30 12:21:10.775914 2026] [security2:error] [pid 727775:tid 727954] [client 172.213.232.128:23383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-p.php7"] [unique_id "amuIBsDCZkc4BvDXnoDCAAAAADE"]
[Thu Jul 30 12:21:11.191724 2026] [security2:error] [pid 727775:tid 728002] [client 57.141.0.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuIBsDCZkc4BvDXnoDB9gAAAGE"]
[Thu Jul 30 12:21:11.197737 2026] [security2:error] [pid 727775:tid 727926] [client 195.113.175.167:15593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.175.113.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/aprochef.php"] [unique_id "amuIB8DCZkc4BvDXnoDCNQAAABU"]
[Thu Jul 30 12:21:11.257656 2026] [core:notice] [pid 727775:tid 727973] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:21:11.334620 2026] [security2:error] [pid 727775:tid 727983] [client 172.213.232.128:52883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/repeater.php"] [unique_id "amuIB8DCZkc4BvDXnoDCOgAAAE4"]
[Thu Jul 30 12:21:11.539480 2026] [security2:error] [pid 727775:tid 727960] [client 20.63.98.115:39094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/js/about.php"] [unique_id "amuIB8DCZkc4BvDXnoDCQgAAADc"]
[Thu Jul 30 12:21:12.096295 2026] [security2:error] [pid 727775:tid 727918] [client 2a03:2880:f800:2f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuIB8DCZkc4BvDXnoDCQQAADVg"]
[Thu Jul 30 12:21:12.295655 2026] [security2:error] [pid 727775:tid 727948] [client 20.203.148.31:42587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/403.php"] [unique_id "amuICMDCZkc4BvDXnoDCUQAAACs"]
[Thu Jul 30 12:21:12.762136 2026] [security2:error] [pid 727775:tid 727881] [remote 144.79.133.30:39336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.133.79.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "supreme-hydraulics.com"] [uri "/wp-login.php"] [unique_id "amuICMDCZkc4BvDXnoDCWQAAKWk"]
[Thu Jul 30 12:21:13.239069 2026] [security2:error] [pid 727775:tid 727983] [client 20.203.148.31:42457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/404.php"] [unique_id "amuICcDCZkc4BvDXnoDCjQAAAE4"]
[Thu Jul 30 12:21:13.285230 2026] [security2:error] [pid 727775:tid 727973] [client 20.63.98.115:58211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/comfunctions.php"] [unique_id "amuICcDCZkc4BvDXnoDCjgAAAEQ"]
[Thu Jul 30 12:21:13.377065 2026] [security2:error] [pid 727775:tid 727967] [client 172.213.232.128:52890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/repeater.php"] [unique_id "amuICcDCZkc4BvDXnoDCkAAAAD4"]
[Thu Jul 30 12:21:14.034781 2026] [security2:error] [pid 727775:tid 727985] [client 172.213.232.128:25398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/repeater.php"] [unique_id "amuICsDCZkc4BvDXnoDCnQAAAFA"]
[Thu Jul 30 12:21:14.915547 2026] [security2:error] [pid 727775:tid 728007] [client 35.226.21.59:16384] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuICsDCZkc4BvDXnoDCrQAAAGY"]
[Thu Jul 30 12:21:14.969925 2026] [security2:error] [pid 727775:tid 727998] [client 43.135.142.7:50010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.142.135.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/mediaf.php"] [unique_id "amuICsDCZkc4BvDXnoDCswAAAF0"]
[Thu Jul 30 12:21:15.351950 2026] [security2:error] [pid 727775:tid 728030] [client 20.203.148.31:49085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/aa.php"] [unique_id "amuIC8DCZkc4BvDXnoDCwQAAAH0"]
[Thu Jul 30 12:21:16.616377 2026] [security2:error] [pid 727775:tid 727976] [client 35.226.21.59:16386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIDMDCZkc4BvDXnoDC1AAARww"]
[Thu Jul 30 12:21:16.647362 2026] [security2:error] [pid 727775:tid 727969] [client 20.203.148.31:37265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/aafewc0k.php"] [unique_id "amuIDMDCZkc4BvDXnoDC2wAAAEA"]
[Thu Jul 30 12:21:17.832973 2026] [security2:error] [pid 727775:tid 727978] [client 20.63.98.115:61486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/images/class-config.php"] [unique_id "amuIDcDCZkc4BvDXnoDC9AAAAEk"]
[Thu Jul 30 12:21:18.395626 2026] [security2:error] [pid 727775:tid 728010] [client 20.203.148.31:42491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/abcd.php"] [unique_id "amuIDsDCZkc4BvDXnoDDCQAAAGk"]
[Thu Jul 30 12:21:18.411216 2026] [security2:error] [pid 727775:tid 728011] [client 57.141.0.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuIDcDCZkc4BvDXnoDC8QAAAGo"]
[Thu Jul 30 12:21:18.905865 2026] [security2:error] [pid 727775:tid 727956] [client 20.63.98.115:61455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/widgets/include.php"] [unique_id "amuIDsDCZkc4BvDXnoDDEgAAADM"]
[Thu Jul 30 12:21:18.938965 2026] [security2:error] [pid 727775:tid 727815] [remote 103.211.202.51:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.202.211.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kbtfinancezambia.com"] [uri "/wp-login.php"] [unique_id "amuIDsDCZkc4BvDXnoDDGQAAAic"]
[Thu Jul 30 12:21:18.954411 2026] [security2:error] [pid 727775:tid 727953] [client 127.0.0.1:50534] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuIDsDCZkc4BvDXnoDDGAAAADA"]
[Thu Jul 30 12:21:18.954537 2026] [security2:error] [pid 727775:tid 727938] [client 74.7.241.142:57696] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.ecre.ae"] [uri "/robots.txt"] [unique_id "amuIDsDCZkc4BvDXnoDDFQAAISM"]
[Thu Jul 30 12:21:19.725623 2026] [security2:error] [pid 727775:tid 727986] [client 20.203.148.31:42452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/about.php"] [unique_id "amuID8DCZkc4BvDXnoDDLQAAAFE"]
[Thu Jul 30 12:21:22.110466 2026] [security2:error] [pid 727775:tid 727961] [client 20.203.148.31:37301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/admin.php"] [unique_id "amuIEsDCZkc4BvDXnoDDmQAAADg"]
[Thu Jul 30 12:21:22.122709 2026] [security2:error] [pid 727775:tid 727952] [client 20.63.98.115:58225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/install.php"] [unique_id "amuIEsDCZkc4BvDXnoDDmgAAAC8"]
[Thu Jul 30 12:21:22.482944 2026] [core:notice] [pid 727775:tid 727864] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:21:22.585042 2026] [security2:error] [pid 727775:tid 727854] [remote 216.73.216.152:36496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuIEsDCZkc4BvDXnoDDogAAeE4"]
[Thu Jul 30 12:21:23.044235 2026] [security2:error] [pid 727775:tid 727929] [client 20.63.98.115:42948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "amuIE8DCZkc4BvDXnoDDrAAAABg"]
[Thu Jul 30 12:21:23.885856 2026] [security2:error] [pid 727775:tid 727989] [client 20.203.148.31:37310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/adminfuns.php"] [unique_id "amuIE8DCZkc4BvDXnoDDvAAAAFQ"]
[Thu Jul 30 12:21:23.984149 2026] [security2:error] [pid 727775:tid 727915] [client 20.63.98.115:39079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/SimplePie/gzdecodes.php"] [unique_id "amuIE8DCZkc4BvDXnoDDwgAAAAo"]
[Thu Jul 30 12:21:25.023814 2026] [security2:error] [pid 727775:tid 728022] [client 20.63.98.115:20706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-back.php"] [unique_id "amuIFcDCZkc4BvDXnoDD2QAAAHU"]
[Thu Jul 30 12:21:25.056092 2026] [security2:error] [pid 727775:tid 727928] [client 2a03:2880:f800:11:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuIFMDCZkc4BvDXnoDDzAAAF30"]
[Thu Jul 30 12:21:25.377354 2026] [security2:error] [pid 727775:tid 727993] [client 68.235.38.2:54256] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuIFcDCZkc4BvDXnoDD4QAAAFg"]
[Thu Jul 30 12:21:25.377479 2026] [security2:error] [pid 727775:tid 727993] [client 68.235.38.2:54256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuIFcDCZkc4BvDXnoDD4QAAAFg"]
[Thu Jul 30 12:21:25.567451 2026] [proxy:error] [pid 727775:tid 727936] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:21:25.567504 2026] [proxy_http:error] [pid 727775:tid 727936] [client 143.244.57.82:60344] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:21:25.568208 2026] [proxy:error] [pid 727775:tid 727936] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:21:25.568254 2026] [proxy_http:error] [pid 727775:tid 727936] [client 143.244.57.82:60344] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:21:25.834598 2026] [security2:error] [pid 727775:tid 727917] [client 20.63.98.115:20721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "amuIFcDCZkc4BvDXnoDD7wAAAAw"]
[Thu Jul 30 12:21:25.855300 2026] [proxy:error] [pid 727775:tid 727950] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:21:25.855403 2026] [proxy_http:error] [pid 727775:tid 727950] [client 143.244.57.82:60346] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:21:25.856244 2026] [proxy:error] [pid 727775:tid 727950] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:21:25.856303 2026] [proxy_http:error] [pid 727775:tid 727950] [client 143.244.57.82:60346] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:21:26.145101 2026] [security2:error] [pid 727775:tid 727942] [client 143.244.57.82:60360] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mza.djb.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuIFsDCZkc4BvDXnoDD9wAAACU"]
[Thu Jul 30 12:21:26.327264 2026] [security2:error] [pid 727775:tid 727935] [client 68.235.38.2:48292] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuIFsDCZkc4BvDXnoDD-wAAAB4"]
[Thu Jul 30 12:21:26.327352 2026] [security2:error] [pid 727775:tid 727935] [client 68.235.38.2:48292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuIFsDCZkc4BvDXnoDD-wAAAB4"]
[Thu Jul 30 12:21:26.430767 2026] [security2:error] [pid 727775:tid 728013] [client 143.244.57.82:60376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.mza.djb.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuIFsDCZkc4BvDXnoDD_AAAAGw"]
[Thu Jul 30 12:21:26.466062 2026] [security2:error] [pid 727775:tid 728030] [client 20.203.148.31:48249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/albin.php"] [unique_id "amuIFsDCZkc4BvDXnoDD_QAAAH0"]
[Thu Jul 30 12:21:26.711158 2026] [proxy:error] [pid 727775:tid 727974] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:21:26.711237 2026] [proxy_http:error] [pid 727775:tid 727974] [client 143.244.57.82:60378] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:21:26.711802 2026] [proxy:error] [pid 727775:tid 727974] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:21:26.711845 2026] [proxy_http:error] [pid 727775:tid 727974] [client 143.244.57.82:60378] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:21:26.820337 2026] [security2:error] [pid 727775:tid 727943] [client 74.7.242.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "lark-shop.com"] [uri "/index.php"] [unique_id "amuIFcDCZkc4BvDXnoDD6wAAACY"], referer: https://lark-shop.com/product/mevius-13/
[Thu Jul 30 12:21:27.012819 2026] [security2:error] [pid 727775:tid 727964] [client 143.244.57.82:57994] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mza.djb.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuIF8DCZkc4BvDXnoDECwAAADs"]
[Thu Jul 30 12:21:27.287525 2026] [security2:error] [pid 727775:tid 727906] [client 143.244.57.82:57998] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mza.djb.temporary.site"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuIF8DCZkc4BvDXnoDEEwAAAAE"]
[Thu Jul 30 12:21:27.567639 2026] [security2:error] [pid 727775:tid 727920] [client 143.244.57.82:58008] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mza.djb.temporary.site"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuIF8DCZkc4BvDXnoDEHAAAAA8"]
[Thu Jul 30 12:21:27.608487 2026] [security2:error] [pid 727775:tid 728006] [client 2a03:2880:f800:3e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuIFsDCZkc4BvDXnoDECgAAZQo"]
[Thu Jul 30 12:21:27.855410 2026] [security2:error] [pid 727775:tid 727949] [client 143.244.57.82:58020] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mza.djb.temporary.site"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuIF8DCZkc4BvDXnoDEPAAAACw"]
[Thu Jul 30 12:21:28.145427 2026] [security2:error] [pid 727775:tid 728012] [client 143.244.57.82:58022] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mza.djb.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuIGMDCZkc4BvDXnoDEVgAAAGs"]
[Thu Jul 30 12:21:28.379488 2026] [security2:error] [pid 727775:tid 727911] [client 20.63.98.115:36861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/themes/index.php"] [unique_id "amuIGMDCZkc4BvDXnoDEXQAAAAY"]
[Thu Jul 30 12:21:28.418161 2026] [security2:error] [pid 727775:tid 727926] [client 143.244.57.82:58036] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mza.djb.temporary.site"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuIGMDCZkc4BvDXnoDEYgAAABU"]
[Thu Jul 30 12:21:28.701498 2026] [security2:error] [pid 727775:tid 727999] [client 143.244.57.82:58038] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mza.djb.temporary.site"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuIGMDCZkc4BvDXnoDEawAAAF4"]
[Thu Jul 30 12:21:28.965719 2026] [security2:error] [pid 727775:tid 727908] [client 20.203.148.31:52244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/amfsqvgv.php"] [unique_id "amuIGMDCZkc4BvDXnoDEbwAAAAM"]
[Thu Jul 30 12:21:28.998906 2026] [security2:error] [pid 727775:tid 727941] [client 143.244.57.82:58054] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mza.djb.temporary.site"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuIGMDCZkc4BvDXnoDEcgAAACQ"]
[Thu Jul 30 12:21:29.316921 2026] [security2:error] [pid 727775:tid 728028] [client 143.244.57.82:58056] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mza.djb.temporary.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuIGcDCZkc4BvDXnoDEewAAAHs"]
[Thu Jul 30 12:21:29.372938 2026] [security2:error] [pid 727775:tid 727821] [remote 74.7.241.60:34720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/article.php"] [unique_id "amuIGcDCZkc4BvDXnoDEdgAAZy0"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/1784117929_IMG_3676.jpg
[Thu Jul 30 12:21:29.460411 2026] [security2:error] [pid 727775:tid 727969] [client 112.86.225.93:60230] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/lanvin-classic-2/"] [unique_id "amuIGcDCZkc4BvDXnoDEgQAAAEA"]
[Thu Jul 30 12:21:29.460525 2026] [security2:error] [pid 727775:tid 727969] [client 112.86.225.93:60230] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/product/lanvin-classic-2/"] [unique_id "amuIGcDCZkc4BvDXnoDEgQAAAEA"]
[Thu Jul 30 12:21:29.561385 2026] [security2:error] [pid 727775:tid 727918] [client 20.203.148.31:48499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/ant.php"] [unique_id "amuIGcDCZkc4BvDXnoDEgwAAAA0"]
[Thu Jul 30 12:21:29.612918 2026] [security2:error] [pid 727775:tid 728029] [client 104.238.222.26:61475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.222.238.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-login.php"] [unique_id "amuIGcDCZkc4BvDXnoDEhQAAAHw"]
[Thu Jul 30 12:21:29.649733 2026] [security2:error] [pid 727775:tid 727956] [client 143.244.57.82:58070] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mza.djb.temporary.site"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuIGcDCZkc4BvDXnoDEiAAAADM"]
[Thu Jul 30 12:21:29.980370 2026] [security2:error] [pid 727775:tid 728024] [client 143.244.57.82:58074] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mza.djb.temporary.site"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuIGcDCZkc4BvDXnoDEkgAAAHc"]
[Thu Jul 30 12:21:30.052270 2026] [security2:error] [pid 727775:tid 727996] [client 104.238.222.26:61810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.222.238.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-login.php"] [unique_id "amuIGsDCZkc4BvDXnoDEkwAAAFs"]
[Thu Jul 30 12:21:30.149373 2026] [security2:error] [pid 727775:tid 727950] [client 2a03:2880:f800:31:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuIGcDCZkc4BvDXnoDEggAALTM"]
[Thu Jul 30 12:21:30.254065 2026] [security2:error] [pid 727775:tid 727960] [client 143.244.57.82:58080] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mza.djb.temporary.site"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuIGsDCZkc4BvDXnoDEmAAAADc"]
[Thu Jul 30 12:21:30.346034 2026] [security2:error] [pid 727775:tid 727905] [client 123.245.84.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIGcDCZkc4BvDXnoDEjQAAAAA"]
[Thu Jul 30 12:21:30.539336 2026] [core:notice] [pid 727775:tid 727978] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:21:31.637837 2026] [core:notice] [pid 727775:tid 728003] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:21:31.676420 2026] [security2:error] [pid 727775:tid 727923] [client 142.93.53.183:61161] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "toscanamall.com"] [uri "/"] [unique_id "amuIG8DCZkc4BvDXnoDEugAAABI"]
[Thu Jul 30 12:21:31.899655 2026] [security2:error] [pid 727775:tid 727945] [client 123.245.84.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIG8DCZkc4BvDXnoDEswAAACg"]
[Thu Jul 30 12:21:32.236361 2026] [core:notice] [pid 727775:tid 727924] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:21:32.372966 2026] [security2:error] [pid 727775:tid 727952] [client 143.244.57.86:55604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ai-kr.com.meg.gzj.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuIHMDCZkc4BvDXnoDEyAAAAC8"]
[Thu Jul 30 12:21:32.600908 2026] [security2:error] [pid 727775:tid 727844] [remote 216.73.216.152:63752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuIHMDCZkc4BvDXnoDE0AAAfUQ"]
[Thu Jul 30 12:21:32.721164 2026] [security2:error] [pid 727775:tid 727917] [client 20.63.98.115:65425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/user.php"] [unique_id "amuIHMDCZkc4BvDXnoDE1AAAAAw"]
[Thu Jul 30 12:21:32.821702 2026] [security2:error] [pid 727775:tid 727992] [client 20.203.148.31:48222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/appreciators.php"] [unique_id "amuIHMDCZkc4BvDXnoDE1QAAAFc"]
[Thu Jul 30 12:21:33.211380 2026] [security2:error] [pid 727775:tid 727948] [client 142.93.53.183:61412] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/Admin/warriors/Admin/pages/modules/datagrid/modules/jscalendar/skins/aqua/ERENUSE/Erencgiapi/perl.Eren"] [unique_id "amuIHcDCZkc4BvDXnoDE4gAAACs"]
[Thu Jul 30 12:21:33.247475 2026] [security2:error] [pid 727775:tid 727997] [client 143.244.57.86:55608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ai-kr.com.meg.gzj.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuIHMDCZkc4BvDXnoDE2wAAAFw"]
[Thu Jul 30 12:21:33.487428 2026] [security2:error] [pid 727775:tid 727911] [client 104.238.222.26:62027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.222.238.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-login.php"] [unique_id "amuIHcDCZkc4BvDXnoDE5wAAAAY"]
[Thu Jul 30 12:21:33.594085 2026] [security2:error] [pid 727775:tid 728021] [client 142.93.53.183:61474] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/lib/pkp/lib/vendor/voku/portable-ascii/src/voku/helper/data/ERENUSE/Erencgiapi/perl.Eren"] [unique_id "amuIHcDCZkc4BvDXnoDE6AAAAHQ"]
[Thu Jul 30 12:21:33.961143 2026] [security2:error] [pid 727775:tid 727963] [client 143.244.57.86:55612] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ai-kr.com.meg.gzj.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuIHcDCZkc4BvDXnoDE8AAAADo"]
[Thu Jul 30 12:21:33.968364 2026] [security2:error] [pid 727775:tid 727925] [client 142.93.53.183:61548] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/Admin/warriors/Admin/pages/modules/datagrid/modules/jscalendar/skins/aqua/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIHcDCZkc4BvDXnoDE8QAAABQ"]
[Thu Jul 30 12:21:34.196519 2026] [security2:error] [pid 727775:tid 727987] [client 20.203.148.31:36594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/archive.php"] [unique_id "amuIHsDCZkc4BvDXnoDE9wAAAFI"]
[Thu Jul 30 12:21:34.346157 2026] [security2:error] [pid 727775:tid 727922] [client 142.93.53.183:61602] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/Admin/warriors/Admin/pages/modules/datagrid/modules/jscalendar/skins/aqua/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuIHsDCZkc4BvDXnoDE-AAAABE"]
[Thu Jul 30 12:21:34.507713 2026] [security2:error] [pid 727775:tid 728032] [client 143.244.57.86:55622] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ai-kr.com.meg.gzj.temporary.site"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuIHsDCZkc4BvDXnoDE_AAAAH8"]
[Thu Jul 30 12:21:34.595516 2026] [security2:error] [pid 727775:tid 727975] [client 20.63.98.115:21423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "amuIHsDCZkc4BvDXnoDE_QAAAEY"]
[Thu Jul 30 12:21:34.723608 2026] [security2:error] [pid 727775:tid 728017] [client 142.93.53.183:61641] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/Admin/warriors/Admin/pages/modules/datagrid/modules/jscalendar/skins/aqua/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIHsDCZkc4BvDXnoDFAAAAAHA"]
[Thu Jul 30 12:21:35.073956 2026] [security2:error] [pid 727775:tid 728010] [client 20.203.148.31:36521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/as.php"] [unique_id "amuIH8DCZkc4BvDXnoDFBQAAAGk"]
[Thu Jul 30 12:21:35.101475 2026] [security2:error] [pid 727775:tid 727933] [client 142.93.53.183:61677] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIH8DCZkc4BvDXnoDFBgAAABw"]
[Thu Jul 30 12:21:35.104121 2026] [security2:error] [pid 727775:tid 727930] [client 143.244.57.86:55630] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ai-kr.com.meg.gzj.temporary.site"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuIH8DCZkc4BvDXnoDFBwAAABk"]
[Thu Jul 30 12:21:35.491764 2026] [security2:error] [pid 727775:tid 727917] [client 142.93.53.183:61737] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIH8DCZkc4BvDXnoDFDwAAAAw"]
[Thu Jul 30 12:21:35.696513 2026] [security2:error] [pid 727775:tid 728025] [client 143.244.57.86:55634] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ai-kr.com.meg.gzj.temporary.site"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuIH8DCZkc4BvDXnoDFEAAAAHg"]
[Thu Jul 30 12:21:35.804415 2026] [core:error] [pid 727775:tid 727965] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:21:35.804447 2026] [core:error] [pid 727775:tid 727965] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:21:35.871264 2026] [security2:error] [pid 727775:tid 727966] [client 142.93.53.183:61801] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/cache/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIH8DCZkc4BvDXnoDFFwAAAD0"]
[Thu Jul 30 12:21:35.901832 2026] [security2:error] [pid 727775:tid 728002] [client 20.203.148.31:36545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/atomlib.php"] [unique_id "amuIH8DCZkc4BvDXnoDFGAAAAGE"]
[Thu Jul 30 12:21:36.256696 2026] [security2:error] [pid 727775:tid 728018] [client 142.93.53.183:61860] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/wflogs/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIIMDCZkc4BvDXnoDFIAAAAHE"]
[Thu Jul 30 12:21:36.298599 2026] [security2:error] [pid 727775:tid 727997] [client 143.244.57.86:55644] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ai-kr.com.meg.gzj.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuIIMDCZkc4BvDXnoDFIwAAAFw"]
[Thu Jul 30 12:21:36.637763 2026] [security2:error] [pid 727775:tid 728022] [client 142.93.53.183:61915] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/wpo-cache/ALFA_DATA/alfacgiapi/perl.alfa/"] [unique_id "amuIIMDCZkc4BvDXnoDFJwAAAHU"]
[Thu Jul 30 12:21:36.903173 2026] [security2:error] [pid 727775:tid 727939] [client 143.244.57.86:55656] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ai-kr.com.meg.gzj.temporary.site"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuIIMDCZkc4BvDXnoDFLAAAACI"]
[Thu Jul 30 12:21:36.913833 2026] [security2:error] [pid 727775:tid 727944] [client 20.203.148.31:42861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/autoload_classmap.php"] [unique_id "amuIIMDCZkc4BvDXnoDFLQAAACc"]
[Thu Jul 30 12:21:37.020329 2026] [security2:error] [pid 727775:tid 727922] [client 142.93.53.183:61979] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/wpo-cache/config/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIIcDCZkc4BvDXnoDFLwAAABE"]
[Thu Jul 30 12:21:37.403331 2026] [security2:error] [pid 727775:tid 727924] [client 142.93.53.183:62039] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/updraft/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIIcDCZkc4BvDXnoDFNwAAABM"]
[Thu Jul 30 12:21:37.442963 2026] [security2:error] [pid 727775:tid 727932] [client 20.63.98.115:58055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/Requests/about.php"] [unique_id "amuIIcDCZkc4BvDXnoDFOAAAABs"]
[Thu Jul 30 12:21:37.498428 2026] [security2:error] [pid 727775:tid 727940] [client 143.244.57.86:54672] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ai-kr.com.meg.gzj.temporary.site"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuIIcDCZkc4BvDXnoDFOQAAACM"]
[Thu Jul 30 12:21:37.602788 2026] [security2:error] [pid 727775:tid 727881] [remote 216.73.216.152:63752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuIIcDCZkc4BvDXnoDFOgAAP2k"]
[Thu Jul 30 12:21:37.776401 2026] [security2:error] [pid 727775:tid 727927] [client 142.93.53.183:62100] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/mu-plugins/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIIcDCZkc4BvDXnoDFPgAAABY"]
[Thu Jul 30 12:21:38.104002 2026] [security2:error] [pid 727775:tid 727918] [client 143.244.57.86:54684] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ai-kr.com.meg.gzj.temporary.site"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuIIsDCZkc4BvDXnoDFQgAAAA0"]
[Thu Jul 30 12:21:38.150300 2026] [security2:error] [pid 727775:tid 727985] [client 142.93.53.183:62158] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/backups-dup-lite/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIIsDCZkc4BvDXnoDFRgAAAFA"]
[Thu Jul 30 12:21:38.538633 2026] [security2:error] [pid 727775:tid 727988] [client 142.93.53.183:62221] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/backups-dup-lite/tmp/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIIsDCZkc4BvDXnoDFTAAAAFM"]
[Thu Jul 30 12:21:38.695902 2026] [security2:error] [pid 727775:tid 727957] [client 143.244.57.86:54696] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ai-kr.com.meg.gzj.temporary.site"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuIIsDCZkc4BvDXnoDFUAAAADQ"]
[Thu Jul 30 12:21:38.787101 2026] [security2:error] [pid 727775:tid 727991] [client 20.203.148.31:35818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/bb.php"] [unique_id "amuIIsDCZkc4BvDXnoDFUQAAAFY"]
[Thu Jul 30 12:21:38.919946 2026] [security2:error] [pid 727775:tid 728020] [client 142.93.53.183:62278] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/alfacgiapi/perl.alfa"] [unique_id "amuIIsDCZkc4BvDXnoDFVQAAAHM"]
[Thu Jul 30 12:21:38.952950 2026] [security2:error] [pid 727775:tid 727921] [client 114.119.145.110:52397] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.bisbeewalk.com"] [uri "/images/bisbee-postoffice-10112003.jpg"] [unique_id "amuIIsDCZkc4BvDXnoDFVgAAABA"], referer: http://www.bisbeewalk.com/Bisbee_panoramas_from_off_the_wall.htm
[Thu Jul 30 12:21:39.240489 2026] [core:notice] [pid 727775:tid 727997] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:21:39.303047 2026] [security2:error] [pid 727775:tid 728019] [client 142.93.53.183:62323] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/libraries/smartslider3/GODEST/zestcgiapi/py.zest"] [unique_id "amuII8DCZkc4BvDXnoDFWwAAAHI"]
[Thu Jul 30 12:21:39.306908 2026] [security2:error] [pid 727775:tid 727960] [client 143.244.57.86:54710] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ai-kr.com.meg.gzj.temporary.site"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuII8DCZkc4BvDXnoDFXAAAADc"]
[Thu Jul 30 12:21:39.459903 2026] [security2:error] [pid 727775:tid 728012] [client 20.63.98.115:21221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/hehe.php"] [unique_id "amuII8DCZkc4BvDXnoDFYAAAAGs"]
[Thu Jul 30 12:21:39.694746 2026] [security2:error] [pid 727775:tid 727967] [client 142.93.53.183:62363] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/libraries/smartslider3/GODEST/zestcgiapi/perl.zest"] [unique_id "amuII8DCZkc4BvDXnoDFYwAAAD4"]
[Thu Jul 30 12:21:39.899623 2026] [security2:error] [pid 727775:tid 728011] [client 143.244.57.86:54714] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ai-kr.com.meg.gzj.temporary.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuII8DCZkc4BvDXnoDFZwAAAGo"]
[Thu Jul 30 12:21:40.073012 2026] [security2:error] [pid 727775:tid 727922] [client 142.93.53.183:62406] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/libraries/smartslider3/GODEST/zestcgiapi/bash.zest"] [unique_id "amuIJMDCZkc4BvDXnoDFawAAABE"]
[Thu Jul 30 12:21:40.319920 2026] [security2:error] [pid 727775:tid 727981] [client 20.203.148.31:36837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/bnm.php"] [unique_id "amuIJMDCZkc4BvDXnoDFbwAAAEw"]
[Thu Jul 30 12:21:40.455515 2026] [security2:error] [pid 727775:tid 727975] [client 142.93.53.183:62439] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/.tmb/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIJMDCZkc4BvDXnoDFcAAAAEY"]
[Thu Jul 30 12:21:40.474138 2026] [security2:error] [pid 727775:tid 727941] [client 20.63.98.115:21426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/webadmin.php"] [unique_id "amuIJMDCZkc4BvDXnoDFcgAAACQ"]
[Thu Jul 30 12:21:40.497197 2026] [security2:error] [pid 727775:tid 727949] [client 143.244.57.86:54716] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ai-kr.com.meg.gzj.temporary.site"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuIJMDCZkc4BvDXnoDFeAAAACw"]
[Thu Jul 30 12:21:40.715343 2026] [security2:error] [pid 727775:tid 727782] [remote 74.7.241.59:36858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuIJMDCZkc4BvDXnoDFeQAAIQY"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/premium-addons-for-elementor/modules/woocommerce/templates
[Thu Jul 30 12:21:40.850898 2026] [security2:error] [pid 727775:tid 727993] [client 142.93.53.183:62486] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/.well-known/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIJMDCZkc4BvDXnoDFfQAAAFg"]
[Thu Jul 30 12:21:41.102433 2026] [security2:error] [pid 727775:tid 727933] [client 143.244.57.86:54728] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ai-kr.com.meg.gzj.temporary.site"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuIJcDCZkc4BvDXnoDFgQAAABw"]
[Thu Jul 30 12:21:41.239298 2026] [security2:error] [pid 727775:tid 727969] [client 142.93.53.183:62536] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/.well-known/acme-challenge/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIJcDCZkc4BvDXnoDFggAAAEA"]
[Thu Jul 30 12:21:41.601664 2026] [security2:error] [pid 727775:tid 727985] [client 20.63.98.115:60278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/backup.php"] [unique_id "amuIJcDCZkc4BvDXnoDFiQAAAFA"]
[Thu Jul 30 12:21:41.614175 2026] [security2:error] [pid 727775:tid 728014] [client 142.93.53.183:62576] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/.well-known/pki-validation/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIJcDCZkc4BvDXnoDFigAAAG0"]
[Thu Jul 30 12:21:41.666357 2026] [security2:error] [pid 727775:tid 727989] [client 143.244.57.86:54744] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ai-kr.com.meg.gzj.temporary.site"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuIJcDCZkc4BvDXnoDFiwAAAFQ"]
[Thu Jul 30 12:21:41.703340 2026] [security2:error] [pid 727775:tid 727917] [client 20.203.148.31:37101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/bootstrap.php"] [unique_id "amuIJcDCZkc4BvDXnoDFjAAAAAw"]
[Thu Jul 30 12:21:41.991876 2026] [security2:error] [pid 727775:tid 727953] [client 142.93.53.183:62611] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/word/alfacgiapi/perl.alfa"] [unique_id "amuIJcDCZkc4BvDXnoDFkAAAADA"]
[Thu Jul 30 12:21:42.293871 2026] [security2:error] [pid 727775:tid 727996] [client 143.244.57.86:54756] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ai-kr.com.meg.gzj.temporary.site"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuIJsDCZkc4BvDXnoDFlwAAAFs"]
[Thu Jul 30 12:21:42.382190 2026] [security2:error] [pid 727775:tid 727986] [client 142.93.53.183:62654] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/word/alfacgiapi/py.alfa"] [unique_id "amuIJsDCZkc4BvDXnoDFnAAAAFE"]
[Thu Jul 30 12:21:42.756512 2026] [security2:error] [pid 727775:tid 727984] [client 142.93.53.183:62693] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/word/alfacgiapi/bash.alfa"] [unique_id "amuIJsDCZkc4BvDXnoDFpAAAAE8"]
[Thu Jul 30 12:21:43.137808 2026] [security2:error] [pid 727775:tid 728022] [client 142.93.53.183:62730] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/dist/editor/ckfinder/core/connector/RIMURU/rimurucgiapi/perl.rimuru"] [unique_id "amuIJ8DCZkc4BvDXnoDFqQAAAHU"]
[Thu Jul 30 12:21:43.296604 2026] [security2:error] [pid 727775:tid 727783] [remote 216.73.216.152:14669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuIJ8DCZkc4BvDXnoDFrQAAagc"]
[Thu Jul 30 12:21:43.343072 2026] [security2:error] [pid 727775:tid 728027] [client 57.141.0.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuIJsDCZkc4BvDXnoDFowAAAHo"]
[Thu Jul 30 12:21:43.381009 2026] [security2:error] [pid 727775:tid 728016] [client 127.0.0.1:20600] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuIJ8DCZkc4BvDXnoDFsAAAAG8"]
[Thu Jul 30 12:21:43.381064 2026] [security2:error] [pid 727775:tid 727922] [client 127.0.0.1:20592] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.tgv.gzj.temporary.site"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuIJ8DCZkc4BvDXnoDFrwAAABE"]
[Thu Jul 30 12:21:43.381177 2026] [security2:error] [pid 727775:tid 728001] [client 74.7.175.187:51048] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.tgv.gzj.temporary.site"] [uri "/robots.txt"] [unique_id "amuIJ8DCZkc4BvDXnoDFrgAAYAQ"]
[Thu Jul 30 12:21:43.524615 2026] [security2:error] [pid 727775:tid 727936] [client 142.93.53.183:62781] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/dist/editor/ckfinder/core/connector/RIMURU/rimurucgiapi/py.rimuru"] [unique_id "amuIJ8DCZkc4BvDXnoDFtAAAAB8"]
[Thu Jul 30 12:21:43.903809 2026] [security2:error] [pid 727775:tid 727935] [client 142.93.53.183:62837] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/dist/editor/ckfinder/core/connector/RIMURU/rimurucgiapi/bash.rimuru"] [unique_id "amuIJ8DCZkc4BvDXnoDFuAAAAB4"]
[Thu Jul 30 12:21:44.281018 2026] [security2:error] [pid 727775:tid 727929] [client 142.93.53.183:62886] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/admin/fonts/vazir/Without-Latin/HYBRID_THEORY/hybridcgiapi/perl.alfa"] [unique_id "amuIKMDCZkc4BvDXnoDFxQAAABg"]
[Thu Jul 30 12:21:44.660817 2026] [security2:error] [pid 727775:tid 727945] [client 142.93.53.183:62943] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/assets/admin/fonts/vazir/Without-Latin/HYBRID_THEORY/hybridcgiapi/perl.alfa"] [unique_id "amuIKMDCZkc4BvDXnoDFyQAAACg"]
[Thu Jul 30 12:21:44.809378 2026] [security2:error] [pid 727775:tid 727913] [client 20.203.148.31:44914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/buy.php"] [unique_id "amuIKMDCZkc4BvDXnoDFzQAAAAg"]
[Thu Jul 30 12:21:44.938216 2026] [security2:error] [pid 727775:tid 727802] [remote 57.141.0.53:33646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/73667776610/feed/rss2/"] [unique_id "amuIKMDCZkc4BvDXnoDFzwAAJho"]
[Thu Jul 30 12:21:45.037914 2026] [security2:error] [pid 727775:tid 727980] [client 142.93.53.183:62995] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/admin/fonts/vazir/Without-Latin/HYBRID_THEORY/hybridcgiapi/py.alfa"] [unique_id "amuIKcDCZkc4BvDXnoDF1AAAAEs"]
[Thu Jul 30 12:21:45.305812 2026] [security2:error] [pid 727775:tid 727914] [client 123.245.84.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIKMDCZkc4BvDXnoDF0AAAAAk"]
[Thu Jul 30 12:21:45.417471 2026] [security2:error] [pid 727775:tid 727973] [client 142.93.53.183:63049] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/assets/admin/fonts/vazir/Without-Latin/HYBRID_THEORY/hybridcgiapi/py.alfa"] [unique_id "amuIKcDCZkc4BvDXnoDF2QAAAEQ"]
[Thu Jul 30 12:21:45.515806 2026] [security2:error] [pid 727775:tid 727915] [client 20.203.148.31:36471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/chosen.php"] [unique_id "amuIKcDCZkc4BvDXnoDF3QAAAAo"]
[Thu Jul 30 12:21:45.801570 2026] [security2:error] [pid 727775:tid 727944] [client 142.93.53.183:63103] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/admin/fonts/vazir/Without-Latin/HYBRID_THEORY/hybridcgiapi/bash.alfa"] [unique_id "amuIKcDCZkc4BvDXnoDF4gAAACc"]
[Thu Jul 30 12:21:45.951380 2026] [security2:error] [pid 727775:tid 728007] [client 20.63.98.115:60276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/atomlib.php"] [unique_id "amuIKcDCZkc4BvDXnoDF5AAAAGY"]
[Thu Jul 30 12:21:46.022699 2026] [security2:error] [pid 727775:tid 727939] [client 20.203.148.31:43123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/class-wp-image.php"] [unique_id "amuIKsDCZkc4BvDXnoDF6AAAACI"]
[Thu Jul 30 12:21:46.180180 2026] [security2:error] [pid 727775:tid 727983] [client 142.93.53.183:63144] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/assets/admin/fonts/vazir/Without-Latin/HYBRID_THEORY/hybridcgiapi/bash.alfa"] [unique_id "amuIKsDCZkc4BvDXnoDF6QAAAE4"]
[Thu Jul 30 12:21:46.559385 2026] [security2:error] [pid 727775:tid 728017] [client 142.93.53.183:63193] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/assets/vendors/summernote/font/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIKsDCZkc4BvDXnoDF9AAAAHA"]
[Thu Jul 30 12:21:46.581224 2026] [security2:error] [pid 727775:tid 727981] [client 123.245.84.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIKsDCZkc4BvDXnoDF6gAAAEw"]
[Thu Jul 30 12:21:46.791649 2026] [security2:error] [pid 727775:tid 728028] [client 20.63.98.115:61393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/epinyins.php"] [unique_id "amuIKsDCZkc4BvDXnoDF9QAAAHs"]
[Thu Jul 30 12:21:46.939756 2026] [security2:error] [pid 727775:tid 727930] [client 142.93.53.183:63229] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/vendors/summernote/font/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIKsDCZkc4BvDXnoDF-QAAABk"]
[Thu Jul 30 12:21:47.299071 2026] [security2:error] [pid 727775:tid 727972] [client 20.203.148.31:44921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/classsmtps.php"] [unique_id "amuIK8DCZkc4BvDXnoDF_gAAAEM"]
[Thu Jul 30 12:21:47.314587 2026] [security2:error] [pid 727775:tid 728013] [client 142.93.53.183:63274] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/assets/vendors/summernote/font/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuIK8DCZkc4BvDXnoDF_wAAAGw"]
[Thu Jul 30 12:21:47.531265 2026] [security2:error] [pid 727775:tid 727916] [client 20.40.58.237:63611] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.kendarikomputer.com"] [uri "/wp-json/wp/v2/posts"] [unique_id "amuIK8DCZkc4BvDXnoDGBAAAAAs"]
[Thu Jul 30 12:21:47.695403 2026] [security2:error] [pid 727775:tid 727965] [client 142.93.53.183:63313] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/vendors/summernote/font/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuIK8DCZkc4BvDXnoDGCAAAADw"]
[Thu Jul 30 12:21:47.836729 2026] [security2:error] [pid 727775:tid 727979] [client 123.245.84.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIK8DCZkc4BvDXnoDGAwAAAEo"]
[Thu Jul 30 12:21:48.026856 2026] [security2:error] [pid 727775:tid 728002] [client 20.63.98.115:58057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amuILMDCZkc4BvDXnoDGDAAAAGE"]
[Thu Jul 30 12:21:48.084013 2026] [security2:error] [pid 727775:tid 727991] [client 142.93.53.183:63373] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/dist/css/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuILMDCZkc4BvDXnoDGDQAAAFY"]
[Thu Jul 30 12:21:48.463427 2026] [security2:error] [pid 727775:tid 727948] [client 142.93.53.183:63430] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/dist/css/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuILMDCZkc4BvDXnoDGFAAAACs"]
[Thu Jul 30 12:21:48.750036 2026] [security2:error] [pid 727775:tid 727926] [client 20.203.148.31:42542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/classwithtostring.php"] [unique_id "amuILMDCZkc4BvDXnoDGHAAAABU"]
[Thu Jul 30 12:21:48.846194 2026] [security2:error] [pid 727775:tid 727963] [client 142.93.53.183:63474] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/dist/css/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuILMDCZkc4BvDXnoDGHQAAADo"]
[Thu Jul 30 12:21:48.972173 2026] [security2:error] [pid 727775:tid 727986] [client 123.245.84.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuILMDCZkc4BvDXnoDGGAAAAFE"]
[Thu Jul 30 12:21:49.010154 2026] [security2:error] [pid 727775:tid 727918] [client 20.40.58.237:63687] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.kendarikomputer.com"] [uri "/wp-json/wp/v2/posts"] [unique_id "amuILcDCZkc4BvDXnoDGIQAAAA0"]
[Thu Jul 30 12:21:49.237124 2026] [security2:error] [pid 727775:tid 728011] [client 142.93.53.183:63512] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/assets/vendors/summernote/font/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuILcDCZkc4BvDXnoDGJgAAAGo"]
[Thu Jul 30 12:21:49.616944 2026] [security2:error] [pid 727775:tid 728001] [client 142.93.53.183:63554] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/vendors/summernote/font/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuILcDCZkc4BvDXnoDGLAAAAGA"]
[Thu Jul 30 12:21:49.936290 2026] [security2:error] [pid 727775:tid 727922] [client 43.248.108.240:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuILcDCZkc4BvDXnoDGKwAAETY"]
[Thu Jul 30 12:21:50.002505 2026] [security2:error] [pid 727775:tid 727931] [client 142.93.53.183:63596] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/help/en_US/bibliography/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuILsDCZkc4BvDXnoDGMQAAABo"]
[Thu Jul 30 12:21:50.395373 2026] [security2:error] [pid 727775:tid 728028] [client 142.93.53.183:63641] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/admin/default/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuILsDCZkc4BvDXnoDGOAAAAHs"]
[Thu Jul 30 12:21:50.406605 2026] [proxy:error] [pid 727775:tid 727821] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:21:50.406668 2026] [proxy_http:error] [pid 727775:tid 727821] [remote 74.7.175.185:54946] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:21:50.407306 2026] [proxy:error] [pid 727775:tid 727821] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:21:50.407358 2026] [proxy_http:error] [pid 727775:tid 727821] [remote 74.7.175.185:54946] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:21:50.782867 2026] [security2:error] [pid 727775:tid 728010] [client 142.93.53.183:63683] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/images/.../LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuILsDCZkc4BvDXnoDGQQAAAGk"]
[Thu Jul 30 12:21:50.930840 2026] [security2:error] [pid 727775:tid 727962] [client 184.75.223.195:58610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuILsDCZkc4BvDXnoDGQgAAADk"]
[Thu Jul 30 12:21:50.930942 2026] [security2:error] [pid 727775:tid 727962] [client 184.75.223.195:58610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuILsDCZkc4BvDXnoDGQgAAADk"]
[Thu Jul 30 12:21:51.159555 2026] [security2:error] [pid 727775:tid 727945] [client 142.93.53.183:63718] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/help/en_US/bibliography/SEOBARBAR_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIL8DCZkc4BvDXnoDGRgAAACg"]
[Thu Jul 30 12:21:51.471652 2026] [security2:error] [pid 727775:tid 727976] [client 130.49.115.193:55959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "raad.pk"] [uri "/xmlrpc.php"] [unique_id "amuIL8DCZkc4BvDXnoDGRwAARzU"]
[Thu Jul 30 12:21:51.540067 2026] [security2:error] [pid 727775:tid 728002] [client 142.93.53.183:63755] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/admin/default/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIL8DCZkc4BvDXnoDGTAAAAGE"]
[Thu Jul 30 12:21:51.919576 2026] [security2:error] [pid 727775:tid 727997] [client 142.93.53.183:63800] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/images/.../LEVIATHAN/haxorcgiapi/bash.haxor"] [unique_id "amuIL8DCZkc4BvDXnoDGVAAAAFw"]
[Thu Jul 30 12:21:52.108366 2026] [proxy:error] [pid 727775:tid 727910] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:21:52.108438 2026] [proxy_http:error] [pid 727775:tid 727910] [client 74.7.241.135:49764] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:21:52.109750 2026] [proxy:error] [pid 727775:tid 727910] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:21:52.109805 2026] [proxy_http:error] [pid 727775:tid 727910] [client 74.7.241.135:49764] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:21:52.109991 2026] [security2:error] [pid 727775:tid 727910] [client 74.7.241.135:49764] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "cpcontacts.asd.fyv.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuIMMDCZkc4BvDXnoDGWAAAAAU"]
[Thu Jul 30 12:21:52.315969 2026] [security2:error] [pid 727775:tid 727995] [client 142.93.53.183:63853] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/help/en_US/bibliography/SEOBARBAR_DATA/alfacgiapi/py.alfa"] [unique_id "amuIMMDCZkc4BvDXnoDGXQAAAFo"]
[Thu Jul 30 12:21:52.583196 2026] [security2:error] [pid 727775:tid 728022] [client 195.113.175.167:38641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.175.113.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/stafff.php"] [unique_id "amuIMMDCZkc4BvDXnoDGYQAAAHU"]
[Thu Jul 30 12:21:52.723678 2026] [security2:error] [pid 727775:tid 727958] [client 142.93.53.183:63905] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/admin/default/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuIMMDCZkc4BvDXnoDGZQAAADU"]
[Thu Jul 30 12:21:53.098623 2026] [security2:error] [pid 727775:tid 728001] [client 142.93.53.183:63954] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/images/.../LEVIATHAN/haxorcgiapi/py.haxor"] [unique_id "amuIMcDCZkc4BvDXnoDGawAAAGA"]
[Thu Jul 30 12:21:53.446379 2026] [security2:error] [pid 727775:tid 727998] [client 20.203.148.31:43076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/config.php"] [unique_id "amuIMcDCZkc4BvDXnoDGcwAAAF0"]
[Thu Jul 30 12:21:53.471880 2026] [security2:error] [pid 727775:tid 727946] [client 142.93.53.183:64003] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/cgi-bin/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIMcDCZkc4BvDXnoDGdAAAACk"]
[Thu Jul 30 12:21:53.768616 2026] [lsapi:error] [pid 703393:tid 703432] [remote 102.209.111.62:0] [host flixon.net] Error receiving response: ReceiveResponse: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1009; user ID 1009), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://flixon.net/video/captain-america-brave-new-world-vj-junior/
[Thu Jul 30 12:21:53.862237 2026] [security2:error] [pid 727775:tid 727969] [client 142.93.53.183:64053] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/image/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIMcDCZkc4BvDXnoDGgQAAAEA"]
[Thu Jul 30 12:21:53.996963 2026] [security2:error] [pid 727775:tid 727870] [remote 51.89.129.221:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "filmtvyap.com"] [uri "/newsletter/"] [unique_id "amuIMcDCZkc4BvDXnoDGhAAAbF4"]
[Thu Jul 30 12:21:53.997215 2026] [security2:error] [pid 727775:tid 728013] [client 51.89.129.221:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "filmtvyap.com"] [uri "/newsletter/"] [unique_id "amuIMcDCZkc4BvDXnoDGhAAAbF4"]
[Thu Jul 30 12:21:54.119277 2026] [security2:error] [pid 727775:tid 727981] [client 130.49.115.193:50535] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "raad.pk"] [uri "/xmlrpc.php"] [unique_id "amuIMcDCZkc4BvDXnoDGgwAATEw"]
[Thu Jul 30 12:21:54.250289 2026] [security2:error] [pid 727775:tid 727979] [client 142.93.53.183:64098] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/images/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIMsDCZkc4BvDXnoDGiAAAAEo"]
[Thu Jul 30 12:21:54.608357 2026] [security2:error] [pid 727775:tid 727929] [client 38.190.144.4:51822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuIMsDCZkc4BvDXnoDGjAAAABg"]
[Thu Jul 30 12:21:54.608571 2026] [security2:error] [pid 727775:tid 727929] [client 38.190.144.4:51822] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuIMsDCZkc4BvDXnoDGjAAAABg"]
[Thu Jul 30 12:21:54.632148 2026] [security2:error] [pid 727775:tid 728002] [client 142.93.53.183:64153] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIMsDCZkc4BvDXnoDGjQAAAGE"]
[Thu Jul 30 12:21:55.017196 2026] [security2:error] [pid 727775:tid 727973] [client 142.93.53.183:64204] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/asset/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIM8DCZkc4BvDXnoDGmAAAAEQ"]
[Thu Jul 30 12:21:55.409559 2026] [security2:error] [pid 727775:tid 728011] [client 142.93.53.183:64254] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/pub/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIM8DCZkc4BvDXnoDGnwAAAGo"]
[Thu Jul 30 12:21:55.786664 2026] [security2:error] [pid 727775:tid 728032] [client 142.93.53.183:64306] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIM8DCZkc4BvDXnoDGpwAAAH8"]
[Thu Jul 30 12:21:56.016735 2026] [security2:error] [pid 727775:tid 727953] [client 20.203.148.31:44906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/core.php"] [unique_id "amuINMDCZkc4BvDXnoDGqwAAADA"]
[Thu Jul 30 12:21:56.167117 2026] [security2:error] [pid 727775:tid 727970] [client 142.93.53.183:64348] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/js/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuINMDCZkc4BvDXnoDGrAAAAEE"]
[Thu Jul 30 12:21:56.544955 2026] [security2:error] [pid 727775:tid 727952] [client 142.93.53.183:64398] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/css/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuINMDCZkc4BvDXnoDGswAAAC8"]
[Thu Jul 30 12:21:56.922911 2026] [security2:error] [pid 727775:tid 727927] [client 142.93.53.183:64447] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuINMDCZkc4BvDXnoDGtwAAABY"]
[Thu Jul 30 12:21:57.297183 2026] [security2:error] [pid 727775:tid 727992] [client 142.93.53.183:64498] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wordpress/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuINcDCZkc4BvDXnoDGvQAAAFc"]
[Thu Jul 30 12:21:57.676465 2026] [security2:error] [pid 727775:tid 727979] [client 142.93.53.183:64547] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/blog/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuINcDCZkc4BvDXnoDGxQAAAEo"]
[Thu Jul 30 12:21:57.877383 2026] [security2:error] [pid 727775:tid 727935] [client 20.203.148.31:44907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/css.php"] [unique_id "amuINcDCZkc4BvDXnoDGyQAAAB4"]
[Thu Jul 30 12:21:58.060919 2026] [security2:error] [pid 727775:tid 727991] [client 142.93.53.183:64598] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/admin/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuINsDCZkc4BvDXnoDGzgAAAFY"]
[Thu Jul 30 12:21:58.451747 2026] [security2:error] [pid 727775:tid 728019] [client 142.93.53.183:64651] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/template/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuINsDCZkc4BvDXnoDG0wAAAHI"]
[Thu Jul 30 12:21:58.581586 2026] [security2:error] [pid 727775:tid 727874] [remote 57.141.0.42:27176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/458796423/feed/rss2/"] [unique_id "amuINsDCZkc4BvDXnoDG1QAAdmI"]
[Thu Jul 30 12:21:58.831138 2026] [security2:error] [pid 727775:tid 728006] [client 142.93.53.183:64703] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/template/beez3/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuINsDCZkc4BvDXnoDG3wAAAGU"]
[Thu Jul 30 12:21:59.139970 2026] [security2:error] [pid 727775:tid 727950] [client 2a03:2880:f800:3:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuINsDCZkc4BvDXnoDG1AAALVg"]
[Thu Jul 30 12:21:59.222161 2026] [security2:error] [pid 727775:tid 727923] [client 142.93.53.183:64755] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/administrator/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIN8DCZkc4BvDXnoDG5QAAABI"]
[Thu Jul 30 12:21:59.281257 2026] [security2:error] [pid 727775:tid 728000] [client 57.141.0.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuINsDCZkc4BvDXnoDG2AAAAF8"]
[Thu Jul 30 12:21:59.610961 2026] [security2:error] [pid 727775:tid 728001] [client 142.93.53.183:64818] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/.tmb/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIN8DCZkc4BvDXnoDG6QAAAGA"]
[Thu Jul 30 12:21:59.890027 2026] [security2:error] [pid 727775:tid 727938] [client 82.21.185.32:51068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuIN8DCZkc4BvDXnoDG7QAAACE"]
[Thu Jul 30 12:21:59.943946 2026] [security2:error] [pid 727775:tid 727937] [client 82.21.185.32:51061] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuIN8DCZkc4BvDXnoDG8gAAACA"]
[Thu Jul 30 12:21:59.974107 2026] [security2:error] [pid 727775:tid 728026] [client 82.21.185.32:51060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuIN8DCZkc4BvDXnoDG8wAAAHk"]
[Thu Jul 30 12:21:59.984965 2026] [security2:error] [pid 727775:tid 727952] [client 142.93.53.183:64887] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/.well-known/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIN8DCZkc4BvDXnoDG9AAAAC8"]
[Thu Jul 30 12:22:00.038147 2026] [security2:error] [pid 727775:tid 727970] [client 82.21.185.32:51064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuIN8DCZkc4BvDXnoDG9QAAAEE"]
[Thu Jul 30 12:22:00.043598 2026] [security2:error] [pid 727775:tid 727907] [client 82.21.185.32:51063] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuIN8DCZkc4BvDXnoDG9gAAAAI"]
[Thu Jul 30 12:22:00.059466 2026] [security2:error] [pid 727775:tid 727959] [client 82.21.185.32:51062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuIOMDCZkc4BvDXnoDG9wAAADY"]
[Thu Jul 30 12:22:00.110424 2026] [security2:error] [pid 727775:tid 727946] [client 82.21.185.32:51067] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuIOMDCZkc4BvDXnoDG-QAAACk"]
[Thu Jul 30 12:22:00.124402 2026] [security2:error] [pid 727775:tid 728017] [client 82.21.185.32:51066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuIOMDCZkc4BvDXnoDG-gAAAHA"]
[Thu Jul 30 12:22:00.154596 2026] [security2:error] [pid 727775:tid 727998] [client 82.21.185.32:51065] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuIOMDCZkc4BvDXnoDG-wAAAF0"]
[Thu Jul 30 12:22:00.210280 2026] [security2:error] [pid 727775:tid 727942] [client 82.21.185.32:51069] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuIOMDCZkc4BvDXnoDG_QAAACU"]
[Thu Jul 30 12:22:00.363947 2026] [security2:error] [pid 727775:tid 728030] [client 142.93.53.183:64958] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/dashboard/images/bitnami-xampp/7Syndicate/oxnixcgiapi/perl.oxnix"] [unique_id "amuIOMDCZkc4BvDXnoDHCgAAAH0"]
[Thu Jul 30 12:22:00.570972 2026] [security2:error] [pid 727775:tid 727971] [client 82.21.185.32:51070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuIOMDCZkc4BvDXnoDHDAAAAEI"]
[Thu Jul 30 12:22:00.743368 2026] [security2:error] [pid 727775:tid 727965] [client 142.93.53.183:65014] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/dashboard/images/bitnami-xampp/7Syndicate/oxnixcgiapi/py.oxnix"] [unique_id "amuIOMDCZkc4BvDXnoDHDQAAADw"]
[Thu Jul 30 12:22:01.051079 2026] [core:notice] [pid 727775:tid 727861] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:22:01.126193 2026] [security2:error] [pid 727775:tid 728018] [client 142.93.53.183:65069] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/dashboard/images/bitnami-xampp/7Syndicate/oxnixcgiapi/bash.oxnix"] [unique_id "amuIOcDCZkc4BvDXnoDHFgAAAHE"]
[Thu Jul 30 12:22:01.507474 2026] [security2:error] [pid 727775:tid 727925] [client 142.93.53.183:65134] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/GODEST/zestcgiapi/perl.zest"] [unique_id "amuIOcDCZkc4BvDXnoDHHwAAABQ"]
[Thu Jul 30 12:22:01.898174 2026] [security2:error] [pid 727775:tid 727950] [client 142.93.53.183:65195] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/GODEST/zestcgiapi/py.zest"] [unique_id "amuIOcDCZkc4BvDXnoDHIwAAAC0"]
[Thu Jul 30 12:22:02.286811 2026] [security2:error] [pid 727775:tid 728000] [client 142.93.53.183:65262] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/GODEST/zestcgiapi/bash.zest"] [unique_id "amuIOsDCZkc4BvDXnoDHKQAAAF8"]
[Thu Jul 30 12:22:02.332331 2026] [security2:error] [pid 727775:tid 727960] [client 20.203.148.31:43833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/database.php"] [unique_id "amuIOsDCZkc4BvDXnoDHKgAAADc"]
[Thu Jul 30 12:22:02.340016 2026] [security2:error] [pid 727775:tid 727920] [client 123.245.84.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIOcDCZkc4BvDXnoDHJAAAAA8"]
[Thu Jul 30 12:22:02.623595 2026] [autoindex:error] [pid 727775:tid 727934] [client 34.195.23.187:0] AH01276: Cannot serve directory /home2/mbmudite/koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:22:02.676716 2026] [security2:error] [pid 727775:tid 727922] [client 142.93.53.183:65316] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/.well-known/acme-challenge/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIOsDCZkc4BvDXnoDHNQAAABE"]
[Thu Jul 30 12:22:03.065297 2026] [security2:error] [pid 727775:tid 727952] [client 142.93.53.183:65373] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/.well-known/pki-validation/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIO8DCZkc4BvDXnoDHPAAAAC8"]
[Thu Jul 30 12:22:03.400950 2026] [autoindex:error] [pid 727775:tid 727933] [client 34.195.23.187:0] AH01276: Cannot serve directory /home2/mbmudite/otbola.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:22:03.438128 2026] [security2:error] [pid 727775:tid 727956] [client 142.93.53.183:65427] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/admin/js/tinymce/ONIC_ESPORT/haxorcgiapi/perl.haxor"] [unique_id "amuIO8DCZkc4BvDXnoDHRgAAADM"]
[Thu Jul 30 12:22:03.543012 2026] [security2:error] [pid 727775:tid 727942] [client 20.203.148.31:43597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/db.php"] [unique_id "amuIO8DCZkc4BvDXnoDHRwAAACU"]
[Thu Jul 30 12:22:03.652083 2026] [security2:error] [pid 727775:tid 728008] [client 123.245.84.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIO8DCZkc4BvDXnoDHQAAAAGc"]
[Thu Jul 30 12:22:03.814110 2026] [security2:error] [pid 727775:tid 728014] [client 142.93.53.183:65481] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/admin/js/tinymce/ONIC_ESPORT/haxorcgiapi/perl.haxor"] [unique_id "amuIO8DCZkc4BvDXnoDHTgAAAG0"]
[Thu Jul 30 12:22:03.916586 2026] [security2:error] [pid 727775:tid 727940] [client 2a03:2880:f800:38:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuIO8DCZkc4BvDXnoDHQQAAI3k"]
[Thu Jul 30 12:22:04.187427 2026] [security2:error] [pid 727775:tid 728009] [client 142.93.53.183:49155] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/cgi-bin/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIPMDCZkc4BvDXnoDHVQAAAGg"]
[Thu Jul 30 12:22:04.578395 2026] [security2:error] [pid 727775:tid 727943] [client 142.93.53.183:49215] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIPMDCZkc4BvDXnoDHWgAAACY"]
[Thu Jul 30 12:22:04.687778 2026] [core:notice] [pid 727775:tid 727965] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:22:04.868693 2026] [security2:error] [pid 727775:tid 728019] [client 123.245.84.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIPMDCZkc4BvDXnoDHWQAAAHI"]
[Thu Jul 30 12:22:04.971955 2026] [security2:error] [pid 727775:tid 727918] [client 142.93.53.183:49270] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/.tmb/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIPMDCZkc4BvDXnoDHYgAAAA0"]
[Thu Jul 30 12:22:05.344894 2026] [security2:error] [pid 727775:tid 728031] [client 142.93.53.183:49322] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/ijosi/files/contexts/1/library/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIPcDCZkc4BvDXnoDHbgAAAH4"]
[Thu Jul 30 12:22:05.722698 2026] [security2:error] [pid 727775:tid 727934] [client 142.93.53.183:49381] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/ijosi/files/contexts/1/library/LEVIATHAN/haxorcgiapi/py.haxor"] [unique_id "amuIPcDCZkc4BvDXnoDHtQAAAB0"]
[Thu Jul 30 12:22:05.888868 2026] [security2:error] [pid 727775:tid 728003] [client 20.203.148.31:43600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/default.php"] [unique_id "amuIPcDCZkc4BvDXnoDHtwAAAGI"]
[Thu Jul 30 12:22:06.112298 2026] [security2:error] [pid 727775:tid 727975] [client 142.93.53.183:49436] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/ijosi/files/contexts/1/library/LEVIATHAN/haxorcgiapi/bash.haxor"] [unique_id "amuIPsDCZkc4BvDXnoDHuwAAAEY"]
[Thu Jul 30 12:22:06.493800 2026] [security2:error] [pid 727775:tid 727930] [client 142.93.53.183:49494] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/.well-known/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIPsDCZkc4BvDXnoDHvwAAABk"]
[Thu Jul 30 12:22:06.871304 2026] [security2:error] [pid 727775:tid 727941] [client 123.245.84.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIPsDCZkc4BvDXnoDHwwAAACQ"]
[Thu Jul 30 12:22:06.874101 2026] [security2:error] [pid 727775:tid 727962] [client 142.93.53.183:49551] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/.well-known/acme-challenge/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIPsDCZkc4BvDXnoDHxwAAADk"]
[Thu Jul 30 12:22:07.250106 2026] [security2:error] [pid 727775:tid 727919] [client 142.93.53.183:49617] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/.well-known/pki-validation/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIP8DCZkc4BvDXnoDHzwAAAA4"]
[Thu Jul 30 12:22:07.645342 2026] [security2:error] [pid 727775:tid 727905] [client 142.93.53.183:49680] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/cgi-bin/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIP8DCZkc4BvDXnoDH1QAAAAA"]
[Thu Jul 30 12:22:08.034576 2026] [security2:error] [pid 727775:tid 727965] [client 142.93.53.183:49745] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/image/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIQMDCZkc4BvDXnoDH2QAAADw"]
[Thu Jul 30 12:22:08.191646 2026] [core:notice] [pid 727775:tid 727996] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:22:08.404601 2026] [security2:error] [pid 727775:tid 728018] [client 38.190.144.4:6929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuIQMDCZkc4BvDXnoDH4wAAAHE"]
[Thu Jul 30 12:22:08.404723 2026] [security2:error] [pid 727775:tid 728018] [client 38.190.144.4:6929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuIQMDCZkc4BvDXnoDH4wAAAHE"]
[Thu Jul 30 12:22:08.426395 2026] [security2:error] [pid 727775:tid 727960] [client 142.93.53.183:49838] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/images/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIQMDCZkc4BvDXnoDH5AAAADc"]
[Thu Jul 30 12:22:08.622483 2026] [security2:error] [pid 727775:tid 727968] [client 20.203.148.31:42555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/dropdown.php"] [unique_id "amuIQMDCZkc4BvDXnoDH5QAAAD8"]
[Thu Jul 30 12:22:08.707056 2026] [security2:error] [pid 727775:tid 727909] [client 123.245.84.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIQMDCZkc4BvDXnoDH4gAAAAQ"]
[Thu Jul 30 12:22:08.806292 2026] [security2:error] [pid 727775:tid 727920] [client 142.93.53.183:49933] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIQMDCZkc4BvDXnoDH7AAAAA8"]
[Thu Jul 30 12:22:09.179970 2026] [security2:error] [pid 727775:tid 727995] [client 142.93.53.183:50025] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/zoro/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIQcDCZkc4BvDXnoDH8AAAAFo"]
[Thu Jul 30 12:22:09.438482 2026] [security2:error] [pid 727775:tid 727983] [client 44.192.50.231:42330] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.northyorksheridanmall.com"] [uri "/"] [unique_id "amuIQcDCZkc4BvDXnoDH-QAAAE4"]
[Thu Jul 30 12:22:09.556308 2026] [security2:error] [pid 727775:tid 727936] [client 142.93.53.183:50111] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/916c19cf/ui/minified/i18n/-/HYBRID_THEORY/hybridcgiapi/perl.alfa"] [unique_id "amuIQcDCZkc4BvDXnoDH-gAAAB8"]
[Thu Jul 30 12:22:09.579938 2026] [security2:error] [pid 727775:tid 728000] [client 20.203.148.31:43790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/edit.php"] [unique_id "amuIQcDCZkc4BvDXnoDH-wAAAF8"]
[Thu Jul 30 12:22:09.940808 2026] [security2:error] [pid 727775:tid 727961] [client 142.93.53.183:50188] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/916c19cf/HYBRID_THEORY/hybridcgiapi/perl.alfa"] [unique_id "amuIQcDCZkc4BvDXnoDIAwAAADg"]
[Thu Jul 30 12:22:10.331489 2026] [security2:error] [pid 727775:tid 727978] [client 142.93.53.183:50281] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/security/class/data/User/admin/recycle_kod/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIQsDCZkc4BvDXnoDICQAAAEk"]
[Thu Jul 30 12:22:10.477424 2026] [security2:error] [pid 727775:tid 727942] [client 123.245.84.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIQsDCZkc4BvDXnoDIBQAAACU"]
[Thu Jul 30 12:22:10.717499 2026] [security2:error] [pid 727775:tid 727943] [client 142.93.53.183:50381] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/tes/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIQsDCZkc4BvDXnoDIDQAAACY"]
[Thu Jul 30 12:22:11.097825 2026] [security2:error] [pid 727775:tid 727986] [client 142.93.53.183:50497] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/berita/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIQ8DCZkc4BvDXnoDIFAAAAFE"]
[Thu Jul 30 12:22:11.202555 2026] [security2:error] [pid 727775:tid 727966] [client 20.203.148.31:44565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/f35.php"] [unique_id "amuIQ8DCZkc4BvDXnoDIFgAAAD0"]
[Thu Jul 30 12:22:11.485728 2026] [security2:error] [pid 727775:tid 728015] [client 142.93.53.183:50602] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/berita/LEVIATHAN/haxorcgiapi/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIQ8DCZkc4BvDXnoDIGgAAAG4"]
[Thu Jul 30 12:22:11.866394 2026] [security2:error] [pid 727775:tid 727999] [client 142.93.53.183:50714] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/asset/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIQ8DCZkc4BvDXnoDIJQAAAF4"]
[Thu Jul 30 12:22:11.985057 2026] [security2:error] [pid 727775:tid 727923] [client 127.0.0.1:34276] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuIQ8DCZkc4BvDXnoDIKAAAABI"]
[Thu Jul 30 12:22:11.985153 2026] [security2:error] [pid 727775:tid 728011] [client 74.7.228.3:44506] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.guethleentertainment.com"] [uri "/robots.txt"] [unique_id "amuIQ8DCZkc4BvDXnoDIJwAAamY"]
[Thu Jul 30 12:22:12.114584 2026] [security2:error] [pid 727775:tid 728032] [client 123.245.84.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIQ8DCZkc4BvDXnoDIHgAAAH8"]
[Thu Jul 30 12:22:12.169386 2026] [security2:error] [pid 727775:tid 728021] [client 51.116.238.8:5058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuIQ8DCZkc4BvDXnoDIJgAAAHQ"]
[Thu Jul 30 12:22:12.169542 2026] [security2:error] [pid 727775:tid 728021] [client 51.116.238.8:5058] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuIQ8DCZkc4BvDXnoDIJgAAAHQ"]
[Thu Jul 30 12:22:12.247130 2026] [security2:error] [pid 727775:tid 727952] [client 142.93.53.183:50797] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/pub/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIRMDCZkc4BvDXnoDILAAAAC8"]
[Thu Jul 30 12:22:12.615404 2026] [security2:error] [pid 727775:tid 727956] [client 51.116.238.8:5071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuIRMDCZkc4BvDXnoDIMwAAADM"]
[Thu Jul 30 12:22:12.615501 2026] [security2:error] [pid 727775:tid 727956] [client 51.116.238.8:5071] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuIRMDCZkc4BvDXnoDIMwAAADM"]
[Thu Jul 30 12:22:12.643385 2026] [security2:error] [pid 727775:tid 727961] [client 142.93.53.183:50876] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIRMDCZkc4BvDXnoDINQAAADg"]
[Thu Jul 30 12:22:12.788700 2026] [security2:error] [pid 727775:tid 728031] [client 20.203.148.31:43589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/f7.php"] [unique_id "amuIRMDCZkc4BvDXnoDINgAAAH4"]
[Thu Jul 30 12:22:13.022908 2026] [security2:error] [pid 727775:tid 727981] [client 142.93.53.183:50959] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/js/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIRcDCZkc4BvDXnoDIPAAAAEw"]
[Thu Jul 30 12:22:13.044516 2026] [security2:error] [pid 727775:tid 727978] [client 51.116.238.8:5102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuIRcDCZkc4BvDXnoDIPQAAAEk"]
[Thu Jul 30 12:22:13.044606 2026] [security2:error] [pid 727775:tid 727978] [client 51.116.238.8:5102] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuIRcDCZkc4BvDXnoDIPQAAAEk"]
[Thu Jul 30 12:22:13.409204 2026] [security2:error] [pid 727775:tid 727994] [client 142.93.53.183:51044] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/css/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIRcDCZkc4BvDXnoDIRAAAAFk"]
[Thu Jul 30 12:22:13.530882 2026] [security2:error] [pid 727775:tid 728002] [client 51.116.238.8:5091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/err.php"] [unique_id "amuIRcDCZkc4BvDXnoDIRgAAAGE"]
[Thu Jul 30 12:22:13.531004 2026] [security2:error] [pid 727775:tid 728002] [client 51.116.238.8:5091] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/err.php"] [unique_id "amuIRcDCZkc4BvDXnoDIRgAAAGE"]
[Thu Jul 30 12:22:13.797114 2026] [security2:error] [pid 727775:tid 728019] [client 142.93.53.183:51111] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIRcDCZkc4BvDXnoDIUAAAAHI"]
[Thu Jul 30 12:22:13.860219 2026] [security2:error] [pid 727775:tid 727988] [client 123.245.84.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIRcDCZkc4BvDXnoDIRQAAAFM"]
[Thu Jul 30 12:22:14.171962 2026] [security2:error] [pid 727775:tid 727968] [client 142.93.53.183:51180] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wordpress/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIRsDCZkc4BvDXnoDIXAAAAD8"]
[Thu Jul 30 12:22:14.269946 2026] [security2:error] [pid 727775:tid 727944] [client 51.116.238.8:5003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/img.php"] [unique_id "amuIRsDCZkc4BvDXnoDIXQAAACc"]
[Thu Jul 30 12:22:14.270070 2026] [security2:error] [pid 727775:tid 727944] [client 51.116.238.8:5003] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/img.php"] [unique_id "amuIRsDCZkc4BvDXnoDIXQAAACc"]
[Thu Jul 30 12:22:14.418072 2026] [core:error] [pid 727775:tid 727920] [client 74.7.244.16:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:22:14.418092 2026] [core:error] [pid 727775:tid 727920] [client 74.7.244.16:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:22:14.418243 2026] [security2:error] [pid 727775:tid 727920] [client 74.7.244.16:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.mhh.zzt.temporary.site"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amuIRsDCZkc4BvDXnoDIYwAAAA8"]
[Thu Jul 30 12:22:14.418917 2026] [security2:error] [pid 727775:tid 728015] [client 74.7.244.16:51124] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.mhh.zzt.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuIRsDCZkc4BvDXnoDIXwAAbnI"]
[Thu Jul 30 12:22:14.551458 2026] [security2:error] [pid 727775:tid 727964] [client 142.93.53.183:51241] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/blog/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIRsDCZkc4BvDXnoDIZAAAADs"]
[Thu Jul 30 12:22:14.939573 2026] [security2:error] [pid 727775:tid 727924] [client 142.93.53.183:51313] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/admin/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIRsDCZkc4BvDXnoDIaAAAABM"]
[Thu Jul 30 12:22:15.124766 2026] [security2:error] [pid 727775:tid 727983] [client 51.116.238.8:5080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/aa.php"] [unique_id "amuIR8DCZkc4BvDXnoDIbwAAAE4"]
[Thu Jul 30 12:22:15.124867 2026] [security2:error] [pid 727775:tid 727983] [client 51.116.238.8:5080] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/aa.php"] [unique_id "amuIR8DCZkc4BvDXnoDIbwAAAE4"]
[Thu Jul 30 12:22:15.330999 2026] [security2:error] [pid 727775:tid 728028] [client 142.93.53.183:51376] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/template/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIR8DCZkc4BvDXnoDIcwAAAHs"]
[Thu Jul 30 12:22:15.724228 2026] [security2:error] [pid 727775:tid 727969] [client 142.93.53.183:51447] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/template/beez3/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIR8DCZkc4BvDXnoDIewAAAEA"]
[Thu Jul 30 12:22:16.047124 2026] [security2:error] [pid 727775:tid 728008] [client 51.116.238.8:5014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/av.php"] [unique_id "amuISMDCZkc4BvDXnoDIfwAAAGc"]
[Thu Jul 30 12:22:16.047212 2026] [security2:error] [pid 727775:tid 728008] [client 51.116.238.8:5014] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/av.php"] [unique_id "amuISMDCZkc4BvDXnoDIfwAAAGc"]
[Thu Jul 30 12:22:16.106258 2026] [security2:error] [pid 727775:tid 728014] [client 142.93.53.183:51524] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/administrator/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuISMDCZkc4BvDXnoDIgAAAAG0"]
[Thu Jul 30 12:22:16.414544 2026] [security2:error] [pid 727775:tid 727979] [client 51.116.238.8:4992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/xa.php"] [unique_id "amuISMDCZkc4BvDXnoDIhAAAAEo"]
[Thu Jul 30 12:22:16.414707 2026] [security2:error] [pid 727775:tid 727979] [client 51.116.238.8:4992] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/xa.php"] [unique_id "amuISMDCZkc4BvDXnoDIhAAAAEo"]
[Thu Jul 30 12:22:16.488050 2026] [security2:error] [pid 727775:tid 727974] [client 142.93.53.183:51589] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/album/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuISMDCZkc4BvDXnoDIhQAAAEU"]
[Thu Jul 30 12:22:16.879814 2026] [security2:error] [pid 727775:tid 727911] [client 142.93.53.183:51674] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/SASKRA/alfacgiapi/perl.alfa"] [unique_id "amuISMDCZkc4BvDXnoDIjAAAAAY"]
[Thu Jul 30 12:22:17.160397 2026] [security2:error] [pid 727775:tid 727921] [client 38.190.144.4:52797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuIScDCZkc4BvDXnoDIkQAAABA"]
[Thu Jul 30 12:22:17.160527 2026] [security2:error] [pid 727775:tid 727921] [client 38.190.144.4:52797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuIScDCZkc4BvDXnoDIkQAAABA"]
[Thu Jul 30 12:22:17.253555 2026] [security2:error] [pid 727775:tid 727996] [client 142.93.53.183:51766] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/SASKRA/alfacgiapi/bash.alfa"] [unique_id "amuIScDCZkc4BvDXnoDIkgAAAFs"]
[Thu Jul 30 12:22:17.342068 2026] [security2:error] [pid 727775:tid 727966] [client 51.116.238.8:5081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/media.php"] [unique_id "amuIScDCZkc4BvDXnoDIlgAAAD0"]
[Thu Jul 30 12:22:17.342165 2026] [security2:error] [pid 727775:tid 727966] [client 51.116.238.8:5081] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/media.php"] [unique_id "amuIScDCZkc4BvDXnoDIlgAAAD0"]
[Thu Jul 30 12:22:17.639522 2026] [security2:error] [pid 727775:tid 728007] [client 142.93.53.183:51855] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/SASKRA/alfacgiapi/py.alfa"] [unique_id "amuIScDCZkc4BvDXnoDInQAAAGY"]
[Thu Jul 30 12:22:17.925470 2026] [security2:error] [pid 727775:tid 727939] [client 51.116.238.8:5008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/images.php"] [unique_id "amuIScDCZkc4BvDXnoDIoQAAACI"]
[Thu Jul 30 12:22:17.925625 2026] [security2:error] [pid 727775:tid 727939] [client 51.116.238.8:5008] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/images.php"] [unique_id "amuIScDCZkc4BvDXnoDIoQAAACI"]
[Thu Jul 30 12:22:18.034576 2026] [security2:error] [pid 727775:tid 727999] [client 142.93.53.183:51918] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/SASKRA/alfacgiapi/perl.alfa"] [unique_id "amuISsDCZkc4BvDXnoDIogAAAF4"]
[Thu Jul 30 12:22:18.262127 2026] [security2:error] [pid 727775:tid 728021] [client 51.116.238.8:5006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/gecko.php"] [unique_id "amuISsDCZkc4BvDXnoDIpwAAAHQ"]
[Thu Jul 30 12:22:18.262248 2026] [security2:error] [pid 727775:tid 728021] [client 51.116.238.8:5006] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/gecko.php"] [unique_id "amuISsDCZkc4BvDXnoDIpwAAAHQ"]
[Thu Jul 30 12:22:18.415823 2026] [security2:error] [pid 727775:tid 727983] [client 142.93.53.183:52013] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/SASKRA/alfacgiapi/py.alfa"] [unique_id "amuISsDCZkc4BvDXnoDIqwAAAE4"]
[Thu Jul 30 12:22:18.672601 2026] [security2:error] [pid 727775:tid 728017] [client 51.116.238.8:5000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/82.php"] [unique_id "amuISsDCZkc4BvDXnoDIsQAAAHA"]
[Thu Jul 30 12:22:18.672710 2026] [security2:error] [pid 727775:tid 728017] [client 51.116.238.8:5000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/82.php"] [unique_id "amuISsDCZkc4BvDXnoDIsQAAAHA"]
[Thu Jul 30 12:22:18.794738 2026] [security2:error] [pid 727775:tid 727990] [client 142.93.53.183:52098] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/SASKRA/alfacgiapi/bash.alfa"] [unique_id "amuISsDCZkc4BvDXnoDIuAAAAFU"]
[Thu Jul 30 12:22:19.128056 2026] [security2:error] [pid 727775:tid 728024] [client 51.116.238.8:5109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/xstelth.php"] [unique_id "amuIS8DCZkc4BvDXnoDIvgAAAHc"]
[Thu Jul 30 12:22:19.128171 2026] [security2:error] [pid 727775:tid 728024] [client 51.116.238.8:5109] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/xstelth.php"] [unique_id "amuIS8DCZkc4BvDXnoDIvgAAAHc"]
[Thu Jul 30 12:22:19.181531 2026] [security2:error] [pid 727775:tid 728008] [client 142.93.53.183:52231] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/1999_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIS8DCZkc4BvDXnoDIvwAAAGc"]
[Thu Jul 30 12:22:19.440059 2026] [security2:error] [pid 727775:tid 727957] [client 51.116.238.8:5067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/xp.php"] [unique_id "amuIS8DCZkc4BvDXnoDIyAAAADQ"]
[Thu Jul 30 12:22:19.440168 2026] [security2:error] [pid 727775:tid 727957] [client 51.116.238.8:5067] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/xp.php"] [unique_id "amuIS8DCZkc4BvDXnoDIyAAAADQ"]
[Thu Jul 30 12:22:19.556195 2026] [security2:error] [pid 727775:tid 727913] [client 142.93.53.183:52372] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/1999_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIS8DCZkc4BvDXnoDIygAAAAg"]
[Thu Jul 30 12:22:19.771467 2026] [security2:error] [pid 727775:tid 727943] [client 51.116.238.8:5113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/admin.php"] [unique_id "amuIS8DCZkc4BvDXnoDIzwAAACY"]
[Thu Jul 30 12:22:19.771610 2026] [security2:error] [pid 727775:tid 727943] [client 51.116.238.8:5113] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/admin.php"] [unique_id "amuIS8DCZkc4BvDXnoDIzwAAACY"]
[Thu Jul 30 12:22:19.936178 2026] [security2:error] [pid 727775:tid 728018] [client 142.93.53.183:52493] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/1999_DATA/alfacgiapi/py.alfa"] [unique_id "amuIS8DCZkc4BvDXnoDI1AAAAHE"]
[Thu Jul 30 12:22:20.222051 2026] [security2:error] [pid 727775:tid 727966] [client 51.116.238.8:5114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/adminner.php"] [unique_id "amuITMDCZkc4BvDXnoDI1wAAAD0"]
[Thu Jul 30 12:22:20.222174 2026] [security2:error] [pid 727775:tid 727966] [client 51.116.238.8:5114] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/adminner.php"] [unique_id "amuITMDCZkc4BvDXnoDI1wAAAD0"]
[Thu Jul 30 12:22:20.331760 2026] [security2:error] [pid 727775:tid 727918] [client 142.93.53.183:52602] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/easing/1999_DATA/alfacgiapi/perl.alfa"] [unique_id "amuITMDCZkc4BvDXnoDI3AAAAA0"]
[Thu Jul 30 12:22:20.555857 2026] [security2:error] [pid 727775:tid 727964] [client 51.116.238.8:5068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/a.php"] [unique_id "amuITMDCZkc4BvDXnoDI4wAAADs"]
[Thu Jul 30 12:22:20.555935 2026] [security2:error] [pid 727775:tid 727964] [client 51.116.238.8:5068] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/a.php"] [unique_id "amuITMDCZkc4BvDXnoDI4wAAADs"]
[Thu Jul 30 12:22:20.597319 2026] [core:error] [pid 727775:tid 727923] [client 74.7.175.129:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:22:20.597358 2026] [core:error] [pid 727775:tid 727923] [client 74.7.175.129:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:22:20.597506 2026] [security2:error] [pid 727775:tid 727923] [client 74.7.175.129:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.sharjahfurnituremoversandpackers.space"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amuITMDCZkc4BvDXnoDI5gAAABI"]
[Thu Jul 30 12:22:20.598212 2026] [security2:error] [pid 727775:tid 727948] [client 74.7.175.129:46910] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.sharjahfurnituremoversandpackers.space"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amuITMDCZkc4BvDXnoDI5AAAKx0"]
[Thu Jul 30 12:22:20.712251 2026] [security2:error] [pid 727775:tid 727924] [client 142.93.53.183:52705] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/easing/1999_DATA/alfacgiapi/bash.alfa"] [unique_id "amuITMDCZkc4BvDXnoDI6AAAABM"]
[Thu Jul 30 12:22:20.897895 2026] [security2:error] [pid 727775:tid 727932] [client 51.116.238.8:5007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/k.php"] [unique_id "amuITMDCZkc4BvDXnoDI7AAAABs"]
[Thu Jul 30 12:22:20.898030 2026] [security2:error] [pid 727775:tid 727932] [client 51.116.238.8:5007] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/k.php"] [unique_id "amuITMDCZkc4BvDXnoDI7AAAABs"]
[Thu Jul 30 12:22:21.013035 2026] [security2:error] [pid 727775:tid 727920] [client 57.141.0.11:31160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuITMDCZkc4BvDXnoDI5wAADyE"], referer: https://igetvape-australia.com/store/?product-page=2&add-to-cart=137
[Thu Jul 30 12:22:21.021095 2026] [security2:error] [pid 727775:tid 727818] [remote 146.88.232.46:40549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.232.88.146.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.lld.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuITcDCZkc4BvDXnoDI8AAAfyo"]
[Thu Jul 30 12:22:21.095518 2026] [security2:error] [pid 727775:tid 727937] [client 142.93.53.183:52824] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/easing/1999_DATA/alfacgiapi/py.alfa"] [unique_id "amuITcDCZkc4BvDXnoDI8QAAACA"]
[Thu Jul 30 12:22:21.221405 2026] [security2:error] [pid 727775:tid 727998] [client 51.116.238.8:5082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/222.php"] [unique_id "amuITcDCZkc4BvDXnoDI8gAAAF0"]
[Thu Jul 30 12:22:21.221524 2026] [security2:error] [pid 727775:tid 727998] [client 51.116.238.8:5082] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/222.php"] [unique_id "amuITcDCZkc4BvDXnoDI8gAAAF0"]
[Thu Jul 30 12:22:21.489132 2026] [security2:error] [pid 727775:tid 727941] [client 142.93.53.183:52925] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/RIMURU/rimurucgiapi/perl.rimuru"] [unique_id "amuITcDCZkc4BvDXnoDI9wAAACQ"]
[Thu Jul 30 12:22:21.687991 2026] [security2:error] [pid 727775:tid 727989] [client 51.116.238.8:5064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/mac.php"] [unique_id "amuITcDCZkc4BvDXnoDI_QAAAFQ"]
[Thu Jul 30 12:22:21.688099 2026] [security2:error] [pid 727775:tid 727989] [client 51.116.238.8:5064] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/mac.php"] [unique_id "amuITcDCZkc4BvDXnoDI_QAAAFQ"]
[Thu Jul 30 12:22:21.705246 2026] [core:notice] [pid 727775:tid 728027] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:22:21.866925 2026] [security2:error] [pid 727775:tid 727919] [client 142.93.53.183:53004] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/RIMURU/rimurucgiapi/py.rimuru"] [unique_id "amuITcDCZkc4BvDXnoDJAwAAAA4"]
[Thu Jul 30 12:22:22.107548 2026] [security2:error] [pid 727775:tid 727905] [client 51.116.238.8:5017] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "milfordauto.com"] [uri "/cgi-sys/404.html"] [unique_id "amuITsDCZkc4BvDXnoDJBwAAAAA"]
[Thu Jul 30 12:22:22.239873 2026] [security2:error] [pid 727775:tid 727957] [client 51.116.238.8:5017] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "milfordauto.com"] [uri "/cgi-sys/404.html"] [unique_id "amuITsDCZkc4BvDXnoDJCAAAADQ"]
[Thu Jul 30 12:22:22.246415 2026] [security2:error] [pid 727775:tid 727913] [client 142.93.53.183:53092] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/RIMURU/rimurucgiapi/bash.rimuru"] [unique_id "amuITsDCZkc4BvDXnoDJCQAAAAg"]
[Thu Jul 30 12:22:22.370235 2026] [security2:error] [pid 727775:tid 727980] [client 51.116.238.8:5017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/ops.php"] [unique_id "amuITsDCZkc4BvDXnoDJDwAAAEs"]
[Thu Jul 30 12:22:22.370337 2026] [security2:error] [pid 727775:tid 727980] [client 51.116.238.8:5017] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/ops.php"] [unique_id "amuITsDCZkc4BvDXnoDJDwAAAEs"]
[Thu Jul 30 12:22:22.627256 2026] [security2:error] [pid 727775:tid 728023] [client 142.93.53.183:53183] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/file/kkn/bimbingan/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuITsDCZkc4BvDXnoDJEwAAAHY"]
[Thu Jul 30 12:22:22.800603 2026] [security2:error] [pid 727775:tid 727914] [client 51.116.238.8:5092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/8.php"] [unique_id "amuITsDCZkc4BvDXnoDJFgAAAAk"]
[Thu Jul 30 12:22:22.800731 2026] [security2:error] [pid 727775:tid 727914] [client 51.116.238.8:5092] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/8.php"] [unique_id "amuITsDCZkc4BvDXnoDJFgAAAAk"]
[Thu Jul 30 12:22:23.005327 2026] [security2:error] [pid 727775:tid 727944] [client 142.93.53.183:53277] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/file/kkn/bimbingan/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIT8DCZkc4BvDXnoDJHgAAACc"]
[Thu Jul 30 12:22:23.393749 2026] [security2:error] [pid 727775:tid 727987] [client 142.93.53.183:53356] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/file/kkn/bimbingan/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuIT8DCZkc4BvDXnoDJJgAAAFI"]
[Thu Jul 30 12:22:23.492187 2026] [security2:error] [pid 727775:tid 727968] [client 51.116.238.8:5066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/FWAZ.php"] [unique_id "amuIT8DCZkc4BvDXnoDJJwAAAD8"]
[Thu Jul 30 12:22:23.492284 2026] [security2:error] [pid 727775:tid 727968] [client 51.116.238.8:5066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/FWAZ.php"] [unique_id "amuIT8DCZkc4BvDXnoDJJwAAAD8"]
[Thu Jul 30 12:22:23.594352 2026] [security2:error] [pid 727775:tid 728022] [client 57.141.0.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuITsDCZkc4BvDXnoDJHQAAAHU"]
[Thu Jul 30 12:22:23.768794 2026] [security2:error] [pid 727775:tid 727932] [client 142.93.53.183:53453] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/file/attachment_uet/ori/1337_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIT8DCZkc4BvDXnoDJMQAAABs"]
[Thu Jul 30 12:22:23.974420 2026] [security2:error] [pid 727775:tid 727949] [client 51.116.238.8:5002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/biufile.php"] [unique_id "amuIT8DCZkc4BvDXnoDJNgAAACw"]
[Thu Jul 30 12:22:23.974527 2026] [security2:error] [pid 727775:tid 727949] [client 51.116.238.8:5002] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/biufile.php"] [unique_id "amuIT8DCZkc4BvDXnoDJNgAAACw"]
[Thu Jul 30 12:22:24.159567 2026] [security2:error] [pid 727775:tid 728025] [client 142.93.53.183:53550] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/file/attachment_uet/ori/1337_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIUMDCZkc4BvDXnoDJPQAAAHg"]
[Thu Jul 30 12:22:24.213841 2026] [core:notice] [pid 727775:tid 727834] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:22:24.549777 2026] [security2:error] [pid 727775:tid 728013] [client 142.93.53.183:53661] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/file/attachment_uet/ori/1337_DATA/alfacgiapi/py.alfa"] [unique_id "amuIUMDCZkc4BvDXnoDJQwAAAGw"]
[Thu Jul 30 12:22:24.929758 2026] [security2:error] [pid 727775:tid 728014] [client 142.93.53.183:53775] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/application/controllers/bpm/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIUMDCZkc4BvDXnoDJSAAAAG0"]
[Thu Jul 30 12:22:25.047638 2026] [security2:error] [pid 727775:tid 728000] [client 51.116.238.8:4995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/coffexium.php"] [unique_id "amuIUcDCZkc4BvDXnoDJTAAAAF8"]
[Thu Jul 30 12:22:25.047743 2026] [security2:error] [pid 727775:tid 728000] [client 51.116.238.8:4995] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/coffexium.php"] [unique_id "amuIUcDCZkc4BvDXnoDJTAAAAF8"]
[Thu Jul 30 12:22:25.307763 2026] [security2:error] [pid 727775:tid 728002] [client 142.93.53.183:53890] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/application/controllers/bpm/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIUcDCZkc4BvDXnoDJWgAAAGE"]
[Thu Jul 30 12:22:25.688829 2026] [security2:error] [pid 727775:tid 727909] [client 142.93.53.183:54043] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/application/controllers/bpm/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuIUcDCZkc4BvDXnoDJYgAAAAQ"]
[Thu Jul 30 12:22:25.879426 2026] [security2:error] [pid 727775:tid 727963] [client 57.141.0.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuIUcDCZkc4BvDXnoDJWAAAADo"]
[Thu Jul 30 12:22:25.923443 2026] [security2:error] [pid 727775:tid 727996] [client 51.116.238.8:5103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/simple.php"] [unique_id "amuIUcDCZkc4BvDXnoDJYwAAAFs"]
[Thu Jul 30 12:22:25.923582 2026] [security2:error] [pid 727775:tid 727996] [client 51.116.238.8:5103] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/simple.php"] [unique_id "amuIUcDCZkc4BvDXnoDJYwAAAFs"]
[Thu Jul 30 12:22:26.014114 2026] [security2:error] [pid 727775:tid 727915] [client 2a03:2880:f800:45:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuIUcDCZkc4BvDXnoDJWwAAClM"]
[Thu Jul 30 12:22:26.071088 2026] [security2:error] [pid 727775:tid 728011] [client 142.93.53.183:54202] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/pages/manageIssues/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIUsDCZkc4BvDXnoDJawAAAGo"]
[Thu Jul 30 12:22:26.463400 2026] [security2:error] [pid 727775:tid 727977] [client 142.93.53.183:54349] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/pages/manageIssues/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIUsDCZkc4BvDXnoDJdwAAAEg"]
[Thu Jul 30 12:22:26.790356 2026] [security2:error] [pid 727775:tid 727961] [client 51.116.238.8:5106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/fpwch.php"] [unique_id "amuIUsDCZkc4BvDXnoDJgQAAADg"]
[Thu Jul 30 12:22:26.790494 2026] [security2:error] [pid 727775:tid 727961] [client 51.116.238.8:5106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/fpwch.php"] [unique_id "amuIUsDCZkc4BvDXnoDJgQAAADg"]
[Thu Jul 30 12:22:26.846724 2026] [security2:error] [pid 727775:tid 728031] [client 142.93.53.183:54490] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/pages/manageIssues/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuIUsDCZkc4BvDXnoDJgwAAAH4"]
[Thu Jul 30 12:22:27.217838 2026] [security2:error] [pid 727775:tid 727989] [client 51.116.238.8:5078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/dex.php"] [unique_id "amuIU8DCZkc4BvDXnoDJjAAAAFQ"]
[Thu Jul 30 12:22:27.217938 2026] [security2:error] [pid 727775:tid 727989] [client 51.116.238.8:5078] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/dex.php"] [unique_id "amuIU8DCZkc4BvDXnoDJjAAAAFQ"]
[Thu Jul 30 12:22:27.225718 2026] [security2:error] [pid 727775:tid 728008] [client 142.93.53.183:54648] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/image/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIU8DCZkc4BvDXnoDJjwAAAGc"]
[Thu Jul 30 12:22:27.347102 2026] [security2:error] [pid 727775:tid 727875] [remote 47.128.125.48:48040] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "black-devil-shop.com"] [uri "/robots.txt"] [unique_id "amuIU8DCZkc4BvDXnoDJkQAAbWM"]
[Thu Jul 30 12:22:27.606100 2026] [security2:error] [pid 727775:tid 727965] [client 142.93.53.183:54781] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/images/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIU8DCZkc4BvDXnoDJnAAAADw"]
[Thu Jul 30 12:22:27.615102 2026] [security2:error] [pid 727775:tid 728018] [client 54.87.112.51:24794] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuIUsDCZkc4BvDXnoDJcQAAAHE"], referer: https://globalmarks.pk/
[Thu Jul 30 12:22:27.687043 2026] [security2:error] [pid 727775:tid 727943] [client 57.141.0.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuIU8DCZkc4BvDXnoDJlwAAACY"]
[Thu Jul 30 12:22:27.909241 2026] [security2:error] [pid 727775:tid 727896] [remote 74.7.241.60:49484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/js/article.php"] [unique_id "amuIU8DCZkc4BvDXnoDJogAAc3g"], referer: https://aded-rdc.org/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/js/bootstrap.bundle.min.js
[Thu Jul 30 12:22:27.993040 2026] [security2:error] [pid 727775:tid 727963] [client 142.93.53.183:54917] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIU8DCZkc4BvDXnoDJowAAADo"]
[Thu Jul 30 12:22:27.993424 2026] [security2:error] [pid 727775:tid 728000] [client 57.141.0.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuIU8DCZkc4BvDXnoDJlAAAAF8"]
[Thu Jul 30 12:22:28.195559 2026] [security2:error] [pid 727775:tid 727984] [client 195.113.175.167:38420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.175.113.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/humanitariaf.php"] [unique_id "amuIVMDCZkc4BvDXnoDJqwAAAE8"]
[Thu Jul 30 12:22:28.268712 2026] [security2:error] [pid 727775:tid 727964] [client 51.116.238.8:5057] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "milfordauto.com"] [uri "/1.php"] [unique_id "amuIVMDCZkc4BvDXnoDJswAAADs"]
[Thu Jul 30 12:22:28.268852 2026] [security2:error] [pid 727775:tid 727964] [client 51.116.238.8:5057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/1.php"] [unique_id "amuIVMDCZkc4BvDXnoDJswAAADs"]
[Thu Jul 30 12:22:28.268999 2026] [security2:error] [pid 727775:tid 727964] [client 51.116.238.8:5057] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/1.php"] [unique_id "amuIVMDCZkc4BvDXnoDJswAAADs"]
[Thu Jul 30 12:22:28.440790 2026] [security2:error] [pid 727775:tid 727918] [client 142.93.53.183:55082] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/asset/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIVMDCZkc4BvDXnoDJtgAAAA0"]
[Thu Jul 30 12:22:28.529935 2026] [security2:error] [pid 727775:tid 727952] [client 52.167.144.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuIUsDCZkc4BvDXnoDJfQAAAC8"]
[Thu Jul 30 12:22:28.681420 2026] [security2:error] [pid 727775:tid 727932] [client 74.7.244.51:39390] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "lms-aetiiph-net.smo.zzt.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuIVMDCZkc4BvDXnoDJvgAAG24"]
[Thu Jul 30 12:22:28.817632 2026] [security2:error] [pid 727775:tid 727933] [client 142.93.53.183:55210] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/pub/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIVMDCZkc4BvDXnoDJwgAAABw"]
[Thu Jul 30 12:22:29.045436 2026] [security2:error] [pid 727775:tid 728010] [client 74.7.228.15:36610] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "dhowcruisedinner.com"] [uri "/robots.txt"] [unique_id "amuIVcDCZkc4BvDXnoDJwwAAaXQ"]
[Thu Jul 30 12:22:29.200013 2026] [security2:error] [pid 727775:tid 727994] [client 142.93.53.183:55338] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIVcDCZkc4BvDXnoDJzAAAAFk"]
[Thu Jul 30 12:22:29.303225 2026] [security2:error] [pid 727775:tid 727957] [client 51.116.238.8:5001] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "milfordauto.com"] [uri "/cgi-sys/404.html"] [unique_id "amuIVcDCZkc4BvDXnoDJ0gAAADQ"]
[Thu Jul 30 12:22:29.435066 2026] [security2:error] [pid 727775:tid 727965] [client 51.116.238.8:5001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/config.json.php"] [unique_id "amuIVcDCZkc4BvDXnoDJ1QAAADw"]
[Thu Jul 30 12:22:29.435181 2026] [security2:error] [pid 727775:tid 727965] [client 51.116.238.8:5001] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/config.json.php"] [unique_id "amuIVcDCZkc4BvDXnoDJ1QAAADw"]
[Thu Jul 30 12:22:29.447137 2026] [security2:error] [pid 727775:tid 728013] [client 52.167.144.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuIVcDCZkc4BvDXnoDJywAAAGw"]
[Thu Jul 30 12:22:29.501473 2026] [autoindex:error] [pid 727775:tid 727888] [remote 74.7.227.130:59116] AH01276: Cannot serve directory /home2/smozztte/public_html/new/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:22:29.617662 2026] [security2:error] [pid 727775:tid 728002] [client 142.93.53.183:55474] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/js/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIVcDCZkc4BvDXnoDJ1wAAAGE"]
[Thu Jul 30 12:22:29.801758 2026] [security2:error] [pid 727775:tid 727934] [client 57.141.0.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuIVcDCZkc4BvDXnoDJzwAAAB0"]
[Thu Jul 30 12:22:30.013376 2026] [security2:error] [pid 727775:tid 727954] [client 142.93.53.183:55587] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/css/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIVsDCZkc4BvDXnoDJ4AAAADE"]
[Thu Jul 30 12:22:30.452778 2026] [security2:error] [pid 727775:tid 727984] [client 142.93.53.183:55720] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIVsDCZkc4BvDXnoDJ5wAAAE8"]
[Thu Jul 30 12:22:30.597150 2026] [security2:error] [pid 727775:tid 727928] [client 2a03:2880:f800:1c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuIVcDCZkc4BvDXnoDJ3wAAFws"]
[Thu Jul 30 12:22:30.796175 2026] [security2:error] [pid 727775:tid 727986] [client 51.116.238.8:5059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/k2.php"] [unique_id "amuIVsDCZkc4BvDXnoDJ7AAAAFE"]
[Thu Jul 30 12:22:30.796295 2026] [security2:error] [pid 727775:tid 727986] [client 51.116.238.8:5059] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/k2.php"] [unique_id "amuIVsDCZkc4BvDXnoDJ7AAAAFE"]
[Thu Jul 30 12:22:30.862026 2026] [security2:error] [pid 727775:tid 727918] [client 142.93.53.183:55856] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wordpress/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIVsDCZkc4BvDXnoDJ8QAAAA0"]
[Thu Jul 30 12:22:31.247162 2026] [security2:error] [pid 727775:tid 727949] [client 142.93.53.183:55965] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/blog/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIV8DCZkc4BvDXnoDJ9wAAACw"]
[Thu Jul 30 12:22:31.695729 2026] [security2:error] [pid 727775:tid 727942] [client 142.93.53.183:56112] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/admin/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIV8DCZkc4BvDXnoDKAAAAACU"]
[Thu Jul 30 12:22:32.089467 2026] [security2:error] [pid 727775:tid 727972] [client 142.93.53.183:56260] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/template/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIWMDCZkc4BvDXnoDKCAAAAEM"]
[Thu Jul 30 12:22:32.397922 2026] [security2:error] [pid 727775:tid 728014] [client 51.116.238.8:5054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/raw.php"] [unique_id "amuIWMDCZkc4BvDXnoDKDQAAAG0"]
[Thu Jul 30 12:22:32.398077 2026] [security2:error] [pid 727775:tid 728014] [client 51.116.238.8:5054] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/raw.php"] [unique_id "amuIWMDCZkc4BvDXnoDKDQAAAG0"]
[Thu Jul 30 12:22:32.471842 2026] [security2:error] [pid 727775:tid 727943] [client 142.93.53.183:56408] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/template/beez3/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIWMDCZkc4BvDXnoDKEgAAACY"]
[Thu Jul 30 12:22:32.651926 2026] [security2:error] [pid 727775:tid 727974] [client 50.6.43.217:52052] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuIWMDCZkc4BvDXnoDKEwAAAEU"]
[Thu Jul 30 12:22:32.684916 2026] [security2:error] [pid 727775:tid 727945] [client 50.6.43.217:52062] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuIWMDCZkc4BvDXnoDKFAAAACg"]
[Thu Jul 30 12:22:32.854804 2026] [security2:error] [pid 727775:tid 727912] [client 142.93.53.183:56565] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/administrator/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIWMDCZkc4BvDXnoDKGQAAAAc"]
[Thu Jul 30 12:22:33.235278 2026] [security2:error] [pid 727775:tid 727939] [client 142.93.53.183:56712] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIWcDCZkc4BvDXnoDKHQAAACI"]
[Thu Jul 30 12:22:33.624477 2026] [security2:error] [pid 727775:tid 727999] [client 142.93.53.183:56850] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/alfacgiapi/perl.alfa"] [unique_id "amuIWcDCZkc4BvDXnoDKJQAAAF4"]
[Thu Jul 30 12:22:34.002082 2026] [security2:error] [pid 727775:tid 727998] [client 142.93.53.183:56983] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-admin/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIWsDCZkc4BvDXnoDKLAAAAF0"]
[Thu Jul 30 12:22:34.389483 2026] [security2:error] [pid 727775:tid 727916] [client 142.93.53.183:57118] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-admin/alfacgiapi/perl.alfa"] [unique_id "amuIWsDCZkc4BvDXnoDKMgAAAAs"]
[Thu Jul 30 12:22:34.631958 2026] [security2:error] [pid 727775:tid 727951] [client 172.213.232.128:28878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/geju.php"] [unique_id "amuIWsDCZkc4BvDXnoDKOQAAAC4"]
[Thu Jul 30 12:22:34.766426 2026] [security2:error] [pid 727775:tid 727991] [client 142.93.53.183:57242] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-admin/user/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIWsDCZkc4BvDXnoDKOgAAAFY"]
[Thu Jul 30 12:22:34.827444 2026] [core:notice] [pid 727775:tid 727959] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:22:34.855856 2026] [security2:error] [pid 727775:tid 727808] [remote 216.73.216.152:4013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuIWsDCZkc4BvDXnoDKPQAASSA"]
[Thu Jul 30 12:22:34.864694 2026] [security2:error] [pid 727775:tid 727919] [client 51.116.238.8:5104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp.php"] [unique_id "amuIWsDCZkc4BvDXnoDKQAAAAA4"]
[Thu Jul 30 12:22:34.864777 2026] [security2:error] [pid 727775:tid 727919] [client 51.116.238.8:5104] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/wp.php"] [unique_id "amuIWsDCZkc4BvDXnoDKQAAAAA4"]
[Thu Jul 30 12:22:35.303134 2026] [security2:error] [pid 727775:tid 727906] [client 142.93.53.183:57421] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-admin/user/alfacgiapi/perl.alfa"] [unique_id "amuIW8DCZkc4BvDXnoDKRQAAAAE"]
[Thu Jul 30 12:22:35.559310 2026] [autoindex:error] [pid 727775:tid 727985] [client 45.153.159.21:32204] AH01276: Cannot serve directory /home2/ubphmute/public_html/website_b63f1d3b/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:22:35.698597 2026] [security2:error] [pid 727775:tid 727926] [client 142.93.53.183:57567] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-admin/images/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIW8DCZkc4BvDXnoDKUwAAABU"]
[Thu Jul 30 12:22:35.942097 2026] [security2:error] [pid 727775:tid 727819] [remote 40.77.167.74:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/issue/view/2"] [unique_id "amuIW8DCZkc4BvDXnoDKWAAASis"]
[Thu Jul 30 12:22:36.035915 2026] [security2:error] [pid 727775:tid 728007] [client 184.75.223.195:48750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuIXMDCZkc4BvDXnoDKXAAAAGY"]
[Thu Jul 30 12:22:36.036075 2026] [security2:error] [pid 727775:tid 728007] [client 184.75.223.195:48750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuIXMDCZkc4BvDXnoDKXAAAAGY"]
[Thu Jul 30 12:22:36.078824 2026] [security2:error] [pid 727775:tid 727928] [client 142.93.53.183:57706] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-admin/images/alfacgiapi/perl.alfa"] [unique_id "amuIXMDCZkc4BvDXnoDKXQAAABc"]
[Thu Jul 30 12:22:36.459107 2026] [security2:error] [pid 727775:tid 727958] [client 142.93.53.183:57837] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-admin/includes/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIXMDCZkc4BvDXnoDKYgAAADU"]
[Thu Jul 30 12:22:36.837427 2026] [security2:error] [pid 727775:tid 728016] [client 142.93.53.183:57969] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-admin/includes/alfacgiapi/perl.alfa"] [unique_id "amuIXMDCZkc4BvDXnoDKZwAAAG8"]
[Thu Jul 30 12:22:36.843061 2026] [security2:error] [pid 727775:tid 727920] [client 51.116.238.8:5016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/fffm.php"] [unique_id "amuIXMDCZkc4BvDXnoDKaAAAAA8"]
[Thu Jul 30 12:22:36.843152 2026] [security2:error] [pid 727775:tid 727920] [client 51.116.238.8:5016] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/fffm.php"] [unique_id "amuIXMDCZkc4BvDXnoDKaAAAAA8"]
[Thu Jul 30 12:22:37.044172 2026] [core:notice] [pid 727775:tid 727829] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:22:37.239331 2026] [security2:error] [pid 727775:tid 727932] [client 142.93.53.183:58102] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-admin/js/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIXcDCZkc4BvDXnoDKcQAAABs"]
[Thu Jul 30 12:22:37.246757 2026] [core:notice] [pid 727775:tid 727816] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:22:37.319746 2026] [security2:error] [pid 727775:tid 728013] [client 172.213.232.128:17440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/plugins/about.php"] [unique_id "amuIXcDCZkc4BvDXnoDKdAAAAGw"]
[Thu Jul 30 12:22:37.643724 2026] [security2:error] [pid 727775:tid 727992] [client 142.93.53.183:58253] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-admin/js/alfacgiapi/perl.alfa"] [unique_id "amuIXcDCZkc4BvDXnoDKewAAAFc"]
[Thu Jul 30 12:22:37.897192 2026] [security2:error] [pid 727775:tid 727925] [client 38.190.144.4:53750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuIXcDCZkc4BvDXnoDKfAAAABQ"]
[Thu Jul 30 12:22:37.897328 2026] [security2:error] [pid 727775:tid 727925] [client 38.190.144.4:53750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuIXcDCZkc4BvDXnoDKfAAAABQ"]
[Thu Jul 30 12:22:38.032008 2026] [security2:error] [pid 727775:tid 728025] [client 142.93.53.183:58404] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-admin/maint/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIXsDCZkc4BvDXnoDKfQAAAHg"]
[Thu Jul 30 12:22:38.407819 2026] [security2:error] [pid 727775:tid 728008] [client 142.93.53.183:58568] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-admin/maint/alfacgiapi/perl.alfa"] [unique_id "amuIXsDCZkc4BvDXnoDKhgAAAGc"]
[Thu Jul 30 12:22:38.409653 2026] [security2:error] [pid 727775:tid 727965] [client 213.152.161.118:45324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuIXsDCZkc4BvDXnoDKhQAAADw"]
[Thu Jul 30 12:22:38.409732 2026] [security2:error] [pid 727775:tid 727965] [client 213.152.161.118:45324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuIXsDCZkc4BvDXnoDKhQAAADw"]
[Thu Jul 30 12:22:38.800015 2026] [security2:error] [pid 727775:tid 727989] [client 142.93.53.183:58722] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-admin/network/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIXsDCZkc4BvDXnoDKkgAAAFQ"]
[Thu Jul 30 12:22:38.812938 2026] [security2:error] [pid 727775:tid 727937] [client 51.116.238.8:5072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/111.php"] [unique_id "amuIXsDCZkc4BvDXnoDKkwAAACA"]
[Thu Jul 30 12:22:38.813041 2026] [security2:error] [pid 727775:tid 727937] [client 51.116.238.8:5072] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/111.php"] [unique_id "amuIXsDCZkc4BvDXnoDKkwAAACA"]
[Thu Jul 30 12:22:38.984406 2026] [security2:error] [pid 727775:tid 727960] [client 172.213.232.128:21622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp.php"] [unique_id "amuIXsDCZkc4BvDXnoDKlAAAADc"]
[Thu Jul 30 12:22:39.179287 2026] [security2:error] [pid 727775:tid 728002] [client 142.93.53.183:58882] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-admin/network/alfacgiapi/perl.alfa"] [unique_id "amuIX8DCZkc4BvDXnoDKmAAAAGE"]
[Thu Jul 30 12:22:39.412039 2026] [security2:error] [pid 727775:tid 727836] [remote 216.73.216.152:4013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuIX8DCZkc4BvDXnoDKnAAAWDw"]
[Thu Jul 30 12:22:39.547958 2026] [security2:error] [pid 727775:tid 727987] [client 172.213.232.128:17499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/aaa.php"] [unique_id "amuIX8DCZkc4BvDXnoDKngAAAFI"]
[Thu Jul 30 12:22:39.565212 2026] [security2:error] [pid 727775:tid 728007] [client 142.93.53.183:59034] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/fonts/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIX8DCZkc4BvDXnoDKnwAAAGY"]
[Thu Jul 30 12:22:39.742056 2026] [core:error] [pid 727775:tid 727999] [client 191.96.227.82:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://airevoduct.ltd/
[Thu Jul 30 12:22:39.742089 2026] [core:error] [pid 727775:tid 727999] [client 191.96.227.82:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://airevoduct.ltd/
[Thu Jul 30 12:22:39.945032 2026] [security2:error] [pid 727775:tid 727983] [client 142.93.53.183:59201] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/fonts/alfacgiapi/perl.alfa"] [unique_id "amuIX8DCZkc4BvDXnoDKqwAAAE4"]
[Thu Jul 30 12:22:40.026969 2026] [security2:error] [pid 727775:tid 727998] [client 51.116.238.8:5107] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "milfordauto.com"] [uri "/cgi-sys/404.html"] [unique_id "amuIYMDCZkc4BvDXnoDKrAAAAF0"]
[Thu Jul 30 12:22:40.156470 2026] [security2:error] [pid 727775:tid 727995] [client 51.116.238.8:5107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/ws.php"] [unique_id "amuIYMDCZkc4BvDXnoDKrQAAAFo"]
[Thu Jul 30 12:22:40.156580 2026] [security2:error] [pid 727775:tid 727995] [client 51.116.238.8:5107] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/ws.php"] [unique_id "amuIYMDCZkc4BvDXnoDKrQAAAFo"]
[Thu Jul 30 12:22:40.325321 2026] [security2:error] [pid 727775:tid 727968] [client 142.93.53.183:59361] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/languages/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIYMDCZkc4BvDXnoDKtQAAAD8"]
[Thu Jul 30 12:22:40.704720 2026] [security2:error] [pid 727775:tid 727956] [client 142.93.53.183:59528] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/languages/alfacgiapi/perl.alfa"] [unique_id "amuIYMDCZkc4BvDXnoDKugAAADM"]
[Thu Jul 30 12:22:41.087372 2026] [security2:error] [pid 727775:tid 727946] [client 142.93.53.183:59685] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/litespeed/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIYcDCZkc4BvDXnoDKwgAAACk"]
[Thu Jul 30 12:22:41.152515 2026] [lsapi:error] [pid 703393:tid 703473] [remote 102.209.111.62:0] [host flixon.net] Error receiving response: ReceiveResponse: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1009; user ID 1009), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://flixon.net/video/wolf-man-vj-junior/
[Thu Jul 30 12:22:41.204169 2026] [security2:error] [pid 727775:tid 728008] [client 51.116.238.8:5069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/coffee.php"] [unique_id "amuIYcDCZkc4BvDXnoDKxwAAAGc"]
[Thu Jul 30 12:22:41.204271 2026] [security2:error] [pid 727775:tid 728008] [client 51.116.238.8:5069] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/coffee.php"] [unique_id "amuIYcDCZkc4BvDXnoDKxwAAAGc"]
[Thu Jul 30 12:22:41.398577 2026] [proxy:error] [pid 727775:tid 728006] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:41.398650 2026] [proxy_http:error] [pid 727775:tid 728006] [client 2a09:bac0:1000:c48::2e9:aa:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:41.399614 2026] [proxy:error] [pid 727775:tid 728006] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:41.399670 2026] [proxy_http:error] [pid 727775:tid 728006] [client 2a09:bac0:1000:c48::2e9:aa:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:41.407471 2026] [proxy:error] [pid 727775:tid 727974] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:41.407541 2026] [proxy_http:error] [pid 727775:tid 727974] [client 2a09:bac0:1000:c48::2e9:aa:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:41.408249 2026] [proxy:error] [pid 727775:tid 727974] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:41.408302 2026] [proxy_http:error] [pid 727775:tid 727974] [client 2a09:bac0:1000:c48::2e9:aa:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:41.459151 2026] [proxy:error] [pid 727775:tid 727989] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:41.459230 2026] [proxy_http:error] [pid 727775:tid 727989] [client 2a09:bac0:1000:c48::1c:2a1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.nexiummedication.store.
[Thu Jul 30 12:22:41.459791 2026] [proxy:error] [pid 727775:tid 727989] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:41.459834 2026] [proxy_http:error] [pid 727775:tid 727989] [client 2a09:bac0:1000:c48::1c:2a1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.nexiummedication.store.
[Thu Jul 30 12:22:41.465544 2026] [security2:error] [pid 727775:tid 727944] [client 142.93.53.183:59850] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/litespeed/alfacgiapi/perl.alfa"] [unique_id "amuIYcDCZkc4BvDXnoDK2QAAACc"]
[Thu Jul 30 12:22:41.537665 2026] [proxy:error] [pid 727775:tid 727909] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:41.537734 2026] [proxy_http:error] [pid 727775:tid 727909] [client 2a09:bac0:1000:c48::1c:350:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.nexiummedication.store.
[Thu Jul 30 12:22:41.538331 2026] [proxy:error] [pid 727775:tid 727909] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:41.538375 2026] [proxy_http:error] [pid 727775:tid 727909] [client 2a09:bac0:1000:c48::1c:350:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.nexiummedication.store.
[Thu Jul 30 12:22:41.841777 2026] [security2:error] [pid 727775:tid 727918] [client 142.93.53.183:60007] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIYcDCZkc4BvDXnoDK8AAAAA0"]
[Thu Jul 30 12:22:42.172127 2026] [security2:error] [pid 727775:tid 727975] [client 172.213.232.128:21026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/hoot.php"] [unique_id "amuIYsDCZkc4BvDXnoDK9QAAAEY"]
[Thu Jul 30 12:22:42.219043 2026] [security2:error] [pid 727775:tid 728016] [client 51.116.238.8:5105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/goods.php"] [unique_id "amuIYsDCZkc4BvDXnoDK9gAAAG8"]
[Thu Jul 30 12:22:42.219137 2026] [security2:error] [pid 727775:tid 728016] [client 51.116.238.8:5105] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/goods.php"] [unique_id "amuIYsDCZkc4BvDXnoDK9gAAAG8"]
[Thu Jul 30 12:22:42.222948 2026] [security2:error] [pid 727775:tid 727955] [client 142.93.53.183:60155] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/alfacgiapi/perl.alfa"] [unique_id "amuIYsDCZkc4BvDXnoDK9wAAADI"]
[Thu Jul 30 12:22:42.368752 2026] [security2:error] [pid 727775:tid 728004] [client 52.167.144.172:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuIYsDCZkc4BvDXnoDK9AAAAGM"]
[Thu Jul 30 12:22:42.619741 2026] [security2:error] [pid 727775:tid 727956] [client 142.93.53.183:60326] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/akismet/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIYsDCZkc4BvDXnoDK_wAAADM"]
[Thu Jul 30 12:22:43.000540 2026] [security2:error] [pid 727775:tid 728003] [client 142.93.53.183:60493] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/akismet/alfacgiapi/perl.alfa"] [unique_id "amuIY8DCZkc4BvDXnoDLBgAAAGI"]
[Thu Jul 30 12:22:43.354116 2026] [proxy:error] [pid 727775:tid 727905] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:43.354192 2026] [proxy_http:error] [pid 727775:tid 727905] [client 2a09:bac0:1000:c48::1c:2a1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:43.354969 2026] [proxy:error] [pid 727775:tid 727905] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:43.355043 2026] [proxy_http:error] [pid 727775:tid 727905] [client 2a09:bac0:1000:c48::1c:2a1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:43.373123 2026] [security2:error] [pid 727775:tid 727863] [remote 74.7.241.59:47612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuIY8DCZkc4BvDXnoDLDgAADlc"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/premium-addons-for-elementor/modules/woocommerce/widgets
[Thu Jul 30 12:22:43.393423 2026] [security2:error] [pid 727775:tid 728014] [client 142.93.53.183:60653] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/all-in-one-wp-migration/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIY8DCZkc4BvDXnoDLEgAAAG0"]
[Thu Jul 30 12:22:43.457735 2026] [proxy:error] [pid 727775:tid 728019] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:43.457805 2026] [proxy_http:error] [pid 727775:tid 728019] [client 2a09:bac0:1000:c48::1c:350:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.koinjp189.com.
[Thu Jul 30 12:22:43.458401 2026] [proxy:error] [pid 727775:tid 728019] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:43.458446 2026] [proxy_http:error] [pid 727775:tid 728019] [client 2a09:bac0:1000:c48::1c:350:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.koinjp189.com.
[Thu Jul 30 12:22:43.544331 2026] [proxy:error] [pid 727775:tid 727910] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:43.544399 2026] [proxy_http:error] [pid 727775:tid 727910] [client 2a09:bac0:1000:c48::2e9:aa:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:43.544954 2026] [proxy:error] [pid 727775:tid 727910] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:43.545008 2026] [proxy_http:error] [pid 727775:tid 727910] [client 2a09:bac0:1000:c48::2e9:aa:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:43.613638 2026] [proxy:error] [pid 727775:tid 727937] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:43.613716 2026] [proxy_http:error] [pid 727775:tid 727937] [client 2a09:bac0:1000:c48::1c:2a1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.koinjp189.com.
[Thu Jul 30 12:22:43.614644 2026] [proxy:error] [pid 727775:tid 727937] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:43.614701 2026] [proxy_http:error] [pid 727775:tid 727937] [client 2a09:bac0:1000:c48::1c:2a1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.koinjp189.com.
[Thu Jul 30 12:22:43.744549 2026] [security2:error] [pid 727775:tid 727912] [client 51.116.238.8:5094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/about.php"] [unique_id "amuIY8DCZkc4BvDXnoDLKgAAAAc"]
[Thu Jul 30 12:22:43.744658 2026] [security2:error] [pid 727775:tid 727912] [client 51.116.238.8:5094] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/about.php"] [unique_id "amuIY8DCZkc4BvDXnoDLKgAAAAc"]
[Thu Jul 30 12:22:43.783212 2026] [security2:error] [pid 727775:tid 727929] [client 142.93.53.183:60814] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/all-in-one-wp-migration/alfacgiapi/perl.alfa"] [unique_id "amuIY8DCZkc4BvDXnoDLKwAAABg"]
[Thu Jul 30 12:22:44.174804 2026] [security2:error] [pid 727775:tid 727977] [client 142.93.53.183:60992] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/contact-form-7/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIZMDCZkc4BvDXnoDLNwAAAEg"]
[Thu Jul 30 12:22:44.518949 2026] [security2:error] [pid 727775:tid 727952] [client 20.91.199.21:47241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/json.php"] [unique_id "amuIZMDCZkc4BvDXnoDLQAAAAC8"]
[Thu Jul 30 12:22:44.550375 2026] [security2:error] [pid 727775:tid 727984] [client 172.237.109.114:28138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIY8DCZkc4BvDXnoDLMwAAAE8"]
[Thu Jul 30 12:22:44.556493 2026] [security2:error] [pid 727775:tid 727947] [client 142.93.53.183:61156] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/contact-form-7/alfacgiapi/perl.alfa"] [unique_id "amuIZMDCZkc4BvDXnoDLQgAAACo"]
[Thu Jul 30 12:22:44.561504 2026] [security2:error] [pid 727775:tid 727964] [client 172.237.109.114:25853] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIY8DCZkc4BvDXnoDLNAAAADs"]
[Thu Jul 30 12:22:44.616564 2026] [security2:error] [pid 727775:tid 727923] [client 51.116.238.8:5039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/about.php"] [unique_id "amuIZMDCZkc4BvDXnoDLQwAAABI"]
[Thu Jul 30 12:22:44.616681 2026] [security2:error] [pid 727775:tid 727923] [client 51.116.238.8:5039] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/about.php"] [unique_id "amuIZMDCZkc4BvDXnoDLQwAAABI"]
[Thu Jul 30 12:22:44.830422 2026] [proxy:error] [pid 727775:tid 728028] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:44.830489 2026] [proxy_http:error] [pid 727775:tid 728028] [client 2a09:bac0:1000:c48::21e:147:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:44.831044 2026] [proxy:error] [pid 727775:tid 728028] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:44.831088 2026] [proxy_http:error] [pid 727775:tid 728028] [client 2a09:bac0:1000:c48::21e:147:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:44.845958 2026] [autoindex:error] [pid 727775:tid 728025] [client 2a09:bac0:1000:c48::4d0:3e:0] AH01276: Cannot serve directory /home2/mbmudite/melatipkr.xyz/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:22:44.850092 2026] [autoindex:error] [pid 727775:tid 727942] [client 2a09:bac0:1000:c48::21e:147:0] AH01276: Cannot serve directory /home2/mbmudite/melatipkr.xyz/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:22:44.852030 2026] [proxy:error] [pid 727775:tid 727913] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:44.852117 2026] [proxy_http:error] [pid 727775:tid 727913] [client 2a09:bac0:1000:c48::4d0:3e:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:44.852547 2026] [autoindex:error] [pid 727775:tid 728010] [client 2a09:bac0:1000:c48::4d0:3e:0] AH01276: Cannot serve directory /home2/mbmudite/melatipkr.xyz/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:22:44.852878 2026] [proxy:error] [pid 727775:tid 727913] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:44.852937 2026] [proxy_http:error] [pid 727775:tid 727913] [client 2a09:bac0:1000:c48::4d0:3e:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:44.859050 2026] [autoindex:error] [pid 727775:tid 727925] [client 2a09:bac0:1000:c48::4:2ec:0] AH01276: Cannot serve directory /home2/mbmudite/ok.melatipkr.xyz/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:22:44.923324 2026] [autoindex:error] [pid 727775:tid 727978] [client 2a09:bac0:1000:c48::4d0:3e:0] AH01276: Cannot serve directory /home2/mbmudite/melatipkr.xyz/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://mail.melatipkr.xyz.
[Thu Jul 30 12:22:44.924119 2026] [autoindex:error] [pid 727775:tid 727927] [client 2a09:bac0:1000:c48::4d0:3e:0] AH01276: Cannot serve directory /home2/mbmudite/melatipkr.xyz/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://melatipkr.xyz.
[Thu Jul 30 12:22:44.931476 2026] [autoindex:error] [pid 727775:tid 728029] [client 2a09:bac0:1000:c48::4:2ec:0] AH01276: Cannot serve directory /home2/mbmudite/ok.melatipkr.xyz/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://ok.melatipkr.xyz.
[Thu Jul 30 12:22:44.933943 2026] [security2:error] [pid 727775:tid 727905] [client 142.93.53.183:61348] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/elementor/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIZMDCZkc4BvDXnoDLbgAAAAA"]
[Thu Jul 30 12:22:44.940767 2026] [proxy:error] [pid 727775:tid 727980] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:44.940840 2026] [proxy_http:error] [pid 727775:tid 727980] [client 2a09:bac0:1000:c48::4:2ec:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.melatipkr.xyz.
[Thu Jul 30 12:22:44.941416 2026] [proxy:error] [pid 727775:tid 727980] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:44.941464 2026] [proxy_http:error] [pid 727775:tid 727980] [client 2a09:bac0:1000:c48::4:2ec:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.melatipkr.xyz.
[Thu Jul 30 12:22:44.943882 2026] [proxy:error] [pid 727775:tid 727943] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:44.943938 2026] [proxy_http:error] [pid 727775:tid 727943] [client 2a09:bac0:1000:c48::4:2ec:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.melatipkr.xyz.
[Thu Jul 30 12:22:44.944529 2026] [proxy:error] [pid 727775:tid 727943] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:44.944584 2026] [proxy_http:error] [pid 727775:tid 727943] [client 2a09:bac0:1000:c48::4:2ec:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.melatipkr.xyz.
[Thu Jul 30 12:22:44.953303 2026] [autoindex:error] [pid 727775:tid 728014] [client 2a09:bac0:1000:c48::4:2ec:0] AH01276: Cannot serve directory /home2/mbmudite/melatipkr.xyz/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.melatipkr.xyz.
[Thu Jul 30 12:22:45.095277 2026] [security2:error] [pid 727775:tid 728018] [client 172.213.232.128:10320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/about.php"] [unique_id "amuIZcDCZkc4BvDXnoDLhgAAAHE"]
[Thu Jul 30 12:22:45.314723 2026] [security2:error] [pid 727775:tid 728015] [client 142.93.53.183:61529] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/elementor/alfacgiapi/perl.alfa"] [unique_id "amuIZcDCZkc4BvDXnoDLiAAAAG4"]
[Thu Jul 30 12:22:45.376252 2026] [proxy:error] [pid 727775:tid 727960] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:45.376373 2026] [proxy_http:error] [pid 727775:tid 727960] [client 74.7.230.52:49010] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:45.377955 2026] [proxy:error] [pid 727775:tid 727960] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:45.378048 2026] [proxy_http:error] [pid 727775:tid 727960] [client 74.7.230.52:49010] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:45.378256 2026] [security2:error] [pid 727775:tid 727960] [client 74.7.230.52:49010] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "cpcontacts.bgk.djb.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuIZcDCZkc4BvDXnoDLiQAAADc"]
[Thu Jul 30 12:22:45.414163 2026] [autoindex:error] [pid 727775:tid 727950] [client 2a09:bac0:1000:c48::2e9:aa:0] AH01276: Cannot serve directory /home2/mbmudite/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:22:45.460915 2026] [autoindex:error] [pid 727775:tid 728000] [client 2a09:bac0:1000:c48::1c:350:0] AH01276: Cannot serve directory /home2/mbmudite/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:22:45.463685 2026] [autoindex:error] [pid 727775:tid 727924] [client 2a09:bac0:1000:c48::1c:350:0] AH01276: Cannot serve directory /home2/mbmudite/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:22:45.470326 2026] [autoindex:error] [pid 727775:tid 727954] [client 2a09:bac0:1000:c48::2e9:aa:0] AH01276: Cannot serve directory /home2/mbmudite/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://mail.n1rmalabet88.com.
[Thu Jul 30 12:22:45.496901 2026] [autoindex:error] [pid 727775:tid 728012] [client 2a09:bac0:1000:c48::1c:2a1:0] AH01276: Cannot serve directory /home2/mbmudite/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.n1rmalabet88.com.
[Thu Jul 30 12:22:45.507732 2026] [autoindex:error] [pid 727775:tid 728004] [client 2a09:bac0:1000:c48::1c:2a1:0] AH01276: Cannot serve directory /home2/mbmudite/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://n1rmalabet88.com.
[Thu Jul 30 12:22:45.537764 2026] [security2:error] [pid 727775:tid 727916] [client 51.116.238.8:5083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/admin.php"] [unique_id "amuIZcDCZkc4BvDXnoDLsgAAAAs"]
[Thu Jul 30 12:22:45.537926 2026] [security2:error] [pid 727775:tid 727916] [client 51.116.238.8:5083] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/admin.php"] [unique_id "amuIZcDCZkc4BvDXnoDLsgAAAAs"]
[Thu Jul 30 12:22:45.580677 2026] [security2:error] [pid 727775:tid 728013] [client 87.101.92.171:56606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.92.101.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuIZcDCZkc4BvDXnoDLtQAAAGw"]
[Thu Jul 30 12:22:45.580866 2026] [security2:error] [pid 727775:tid 728013] [client 87.101.92.171:56606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuIZcDCZkc4BvDXnoDLtQAAAGw"]
[Thu Jul 30 12:22:45.614202 2026] [security2:error] [pid 727775:tid 727972] [client 172.237.109.114:60493] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIZMDCZkc4BvDXnoDLdAAAAEM"]
[Thu Jul 30 12:22:45.616243 2026] [security2:error] [pid 727775:tid 727926] [client 20.91.199.21:47248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/mini.php"] [unique_id "amuIZcDCZkc4BvDXnoDLtgAAABU"]
[Thu Jul 30 12:22:45.650812 2026] [security2:error] [pid 727775:tid 727934] [client 172.237.109.114:37563] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIZMDCZkc4BvDXnoDLeAAAAB0"]
[Thu Jul 30 12:22:45.701604 2026] [security2:error] [pid 727775:tid 728021] [client 142.93.53.183:61698] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/elementor-pro/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIZcDCZkc4BvDXnoDLtwAAAHQ"]
[Thu Jul 30 12:22:45.705201 2026] [security2:error] [pid 727775:tid 727937] [client 172.237.109.114:23359] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIZMDCZkc4BvDXnoDLgQAAACA"]
[Thu Jul 30 12:22:45.714417 2026] [security2:error] [pid 727775:tid 727945] [client 172.237.109.114:54742] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIZMDCZkc4BvDXnoDLfwAAACg"]
[Thu Jul 30 12:22:45.714586 2026] [security2:error] [pid 727775:tid 727973] [client 172.237.109.114:41773] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIZMDCZkc4BvDXnoDLewAAAEQ"]
[Thu Jul 30 12:22:45.714731 2026] [security2:error] [pid 727775:tid 727914] [client 172.237.109.114:9938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIZMDCZkc4BvDXnoDLfQAAAAk"]
[Thu Jul 30 12:22:45.715727 2026] [security2:error] [pid 727775:tid 728006] [client 172.237.109.114:13889] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIZMDCZkc4BvDXnoDLeQAAAGU"]
[Thu Jul 30 12:22:45.719168 2026] [security2:error] [pid 727775:tid 727974] [client 172.237.109.114:56414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIZMDCZkc4BvDXnoDLfgAAAEU"]
[Thu Jul 30 12:22:45.721414 2026] [security2:error] [pid 727775:tid 727935] [client 172.237.109.114:51632] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIZMDCZkc4BvDXnoDLegAAAB4"]
[Thu Jul 30 12:22:45.730780 2026] [security2:error] [pid 727775:tid 727966] [client 172.237.109.114:22527] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIZMDCZkc4BvDXnoDLggAAAD0"]
[Thu Jul 30 12:22:45.760026 2026] [security2:error] [pid 727775:tid 727989] [client 172.237.109.114:13511] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIZMDCZkc4BvDXnoDLgAAAAFQ"]
[Thu Jul 30 12:22:46.081630 2026] [security2:error] [pid 727775:tid 727962] [client 142.93.53.183:61870] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/elementor-pro/alfacgiapi/perl.alfa"] [unique_id "amuIZsDCZkc4BvDXnoDLwgAAADk"]
[Thu Jul 30 12:22:46.113861 2026] [security2:error] [pid 727775:tid 727781] [remote 216.73.216.152:50028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuIZsDCZkc4BvDXnoDLwwAAVwU"]
[Thu Jul 30 12:22:46.181142 2026] [security2:error] [pid 727775:tid 727946] [client 47.128.49.182:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.buyfluoxetine.store"] [uri "/robots.txt"] [unique_id "amuIZsDCZkc4BvDXnoDLxQAAACk"]
[Thu Jul 30 12:22:46.396071 2026] [security2:error] [pid 727775:tid 727931] [client 20.91.199.21:47257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/chosen.php"] [unique_id "amuIZsDCZkc4BvDXnoDLyAAAABo"]
[Thu Jul 30 12:22:46.464631 2026] [security2:error] [pid 727775:tid 727929] [client 142.93.53.183:62036] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/litespeed-cache/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIZsDCZkc4BvDXnoDLzAAAABg"]
[Thu Jul 30 12:22:46.557026 2026] [security2:error] [pid 727775:tid 728031] [client 172.213.232.128:4438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/admin.php"] [unique_id "amuIZsDCZkc4BvDXnoDL0AAAAH4"]
[Thu Jul 30 12:22:46.788956 2026] [security2:error] [pid 727775:tid 727953] [client 51.116.238.8:5112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/inputs.php"] [unique_id "amuIZsDCZkc4BvDXnoDL1gAAADA"]
[Thu Jul 30 12:22:46.789088 2026] [security2:error] [pid 727775:tid 727953] [client 51.116.238.8:5112] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/inputs.php"] [unique_id "amuIZsDCZkc4BvDXnoDL1gAAADA"]
[Thu Jul 30 12:22:46.789606 2026] [security2:error] [pid 727775:tid 727782] [remote 62.210.185.4:49084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.185.210.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ahm.djb.temporary.site"] [uri "/wp-login.php"] [unique_id "amuIZsDCZkc4BvDXnoDL1QAAegY"]
[Thu Jul 30 12:22:46.845798 2026] [security2:error] [pid 727775:tid 727932] [client 142.93.53.183:62185] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/importexport/medra/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIZsDCZkc4BvDXnoDL1wAAABs"]
[Thu Jul 30 12:22:46.890107 2026] [security2:error] [pid 727775:tid 727921] [client 52.167.144.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuIZsDCZkc4BvDXnoDLywAAABA"]
[Thu Jul 30 12:22:47.226773 2026] [security2:error] [pid 727775:tid 727925] [client 142.93.53.183:62343] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/importexport/medra/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuIZ8DCZkc4BvDXnoDL4wAAABQ"]
[Thu Jul 30 12:22:47.232292 2026] [security2:error] [pid 727775:tid 727941] [client 52.167.144.172:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuIZsDCZkc4BvDXnoDL2wAAACQ"]
[Thu Jul 30 12:22:47.437470 2026] [security2:error] [pid 727775:tid 728028] [client 172.213.232.128:21616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/plugins/admin.php"] [unique_id "amuIZ8DCZkc4BvDXnoDL6QAAAHs"]
[Thu Jul 30 12:22:47.520571 2026] [security2:error] [pid 727775:tid 728006] [client 20.91.199.21:47278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/kj.php"] [unique_id "amuIZ8DCZkc4BvDXnoDL6gAAAGU"]
[Thu Jul 30 12:22:47.553955 2026] [proxy:error] [pid 727775:tid 727991] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:47.554043 2026] [proxy_http:error] [pid 727775:tid 727991] [client 2a09:bac0:1000:c48::1c:350:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:47.554632 2026] [proxy:error] [pid 727775:tid 727991] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:47.554675 2026] [proxy_http:error] [pid 727775:tid 727991] [client 2a09:bac0:1000:c48::1c:350:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:47.579823 2026] [proxy:error] [pid 727775:tid 727931] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:47.579891 2026] [proxy_http:error] [pid 727775:tid 727931] [client 2a09:bac0:1000:c48::1c:350:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:47.580458 2026] [proxy:error] [pid 727775:tid 727931] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:47.580504 2026] [proxy_http:error] [pid 727775:tid 727931] [client 2a09:bac0:1000:c48::1c:350:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:47.604097 2026] [proxy:error] [pid 727775:tid 727957] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:47.604163 2026] [proxy_http:error] [pid 727775:tid 727957] [client 2a09:bac0:1000:c48::1c:2a1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.buyfluoxetine.store.
[Thu Jul 30 12:22:47.604782 2026] [proxy:error] [pid 727775:tid 727957] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:47.604837 2026] [proxy_http:error] [pid 727775:tid 727957] [client 2a09:bac0:1000:c48::1c:2a1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.buyfluoxetine.store.
[Thu Jul 30 12:22:47.631799 2026] [proxy:error] [pid 727775:tid 728022] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:47.631872 2026] [proxy_http:error] [pid 727775:tid 728022] [client 2a09:bac0:1000:c48::2e9:aa:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.buyfluoxetine.store.
[Thu Jul 30 12:22:47.632497 2026] [proxy:error] [pid 727775:tid 728022] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:47.632550 2026] [proxy_http:error] [pid 727775:tid 728022] [client 2a09:bac0:1000:c48::2e9:aa:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.buyfluoxetine.store.
[Thu Jul 30 12:22:47.633615 2026] [security2:error] [pid 727775:tid 727963] [client 142.93.53.183:62507] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/importexport/medra/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIZ8DCZkc4BvDXnoDMBAAAADo"]
[Thu Jul 30 12:22:48.032403 2026] [security2:error] [pid 727775:tid 727998] [client 142.93.53.183:62705] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/dokumen/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIaMDCZkc4BvDXnoDMFQAAAF0"]
[Thu Jul 30 12:22:48.163576 2026] [proxy:error] [pid 727775:tid 728016] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:48.163654 2026] [proxy_http:error] [pid 727775:tid 728016] [client 2a09:bac0:1000:c48::4d0:3e:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:48.164263 2026] [proxy:error] [pid 727775:tid 728016] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:48.164310 2026] [proxy_http:error] [pid 727775:tid 728016] [client 2a09:bac0:1000:c48::4d0:3e:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:48.197921 2026] [security2:error] [pid 727775:tid 727995] [client 172.213.232.128:4831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/db-cache.php"] [unique_id "amuIaMDCZkc4BvDXnoDMIQAAAFo"]
[Thu Jul 30 12:22:48.276946 2026] [proxy:error] [pid 727775:tid 727935] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:48.277023 2026] [proxy_http:error] [pid 727775:tid 727935] [client 2a09:bac0:1000:c48::4d0:3e:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.lapakjitu78.com.
[Thu Jul 30 12:22:48.277658 2026] [proxy:error] [pid 727775:tid 727935] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:48.277704 2026] [proxy_http:error] [pid 727775:tid 727935] [client 2a09:bac0:1000:c48::4d0:3e:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.lapakjitu78.com.
[Thu Jul 30 12:22:48.287026 2026] [proxy:error] [pid 727775:tid 727989] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:48.287087 2026] [proxy_http:error] [pid 727775:tid 727989] [client 2a09:bac0:1000:c48::21e:147:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:48.287652 2026] [proxy:error] [pid 727775:tid 727989] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:48.287694 2026] [proxy_http:error] [pid 727775:tid 727989] [client 2a09:bac0:1000:c48::21e:147:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:48.343890 2026] [security2:error] [pid 727775:tid 727993] [client 38.190.144.4:54225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuIaMDCZkc4BvDXnoDMMgAAAFg"]
[Thu Jul 30 12:22:48.344024 2026] [security2:error] [pid 727775:tid 727993] [client 38.190.144.4:54225] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuIaMDCZkc4BvDXnoDMMgAAAFg"]
[Thu Jul 30 12:22:48.354816 2026] [proxy:error] [pid 727775:tid 727926] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:48.354891 2026] [proxy_http:error] [pid 727775:tid 727926] [client 2a09:bac0:1000:c48::21e:147:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.lapakjitu78.com.
[Thu Jul 30 12:22:48.355786 2026] [proxy:error] [pid 727775:tid 727926] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:48.355850 2026] [proxy_http:error] [pid 727775:tid 727926] [client 2a09:bac0:1000:c48::21e:147:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.lapakjitu78.com.
[Thu Jul 30 12:22:48.425486 2026] [security2:error] [pid 727775:tid 727940] [client 142.93.53.183:62891] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/dokumen/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIaMDCZkc4BvDXnoDMPAAAACM"]
[Thu Jul 30 12:22:48.482609 2026] [security2:error] [pid 727775:tid 727947] [client 175.30.48.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIaMDCZkc4BvDXnoDMGgAAKiI"]
[Thu Jul 30 12:22:48.496802 2026] [security2:error] [pid 727775:tid 728025] [client 20.91.199.21:47255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/wp-files.php"] [unique_id "amuIaMDCZkc4BvDXnoDMPwAAAHg"]
[Thu Jul 30 12:22:48.610808 2026] [security2:error] [pid 727775:tid 727931] [client 51.116.238.8:5097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/inputs.php"] [unique_id "amuIaMDCZkc4BvDXnoDMRgAAABo"]
[Thu Jul 30 12:22:48.610894 2026] [security2:error] [pid 727775:tid 727931] [client 51.116.238.8:5097] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/inputs.php"] [unique_id "amuIaMDCZkc4BvDXnoDMRgAAABo"]
[Thu Jul 30 12:22:48.808433 2026] [security2:error] [pid 727775:tid 727938] [client 142.93.53.183:63058] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/dokumen/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuIaMDCZkc4BvDXnoDMTQAAACE"]
[Thu Jul 30 12:22:49.201736 2026] [security2:error] [pid 727775:tid 728024] [client 142.93.53.183:63227] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/perpustakaan/PHPExcel/Classes/PHPExcel/Shared/Escher/DggContainer/BstoreContainer/BSE/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIacDCZkc4BvDXnoDMVwAAAHc"]
[Thu Jul 30 12:22:49.601585 2026] [security2:error] [pid 727775:tid 727953] [client 142.93.53.183:63401] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/perpustakaan/PHPExcel/Classes/PHPExcel/Shared/Escher/DggContainer/BstoreContainer/BSE/SEOBARBAR_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIacDCZkc4BvDXnoDMWwAAADA"]
[Thu Jul 30 12:22:49.763518 2026] [security2:error] [pid 727775:tid 727923] [client 172.213.232.128:4456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/themes/twentyeleven/functions.php"] [unique_id "amuIacDCZkc4BvDXnoDMZQAAABI"]
[Thu Jul 30 12:22:49.991825 2026] [security2:error] [pid 727775:tid 727990] [client 142.93.53.183:63567] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/perpustakaan/PHPExcel/Classes/PHPExcel/Shared/Escher/DggContainer/BstoreContainer/BSE/SEOBARBAR_DATA/alfacgiapi/py.alfa"] [unique_id "amuIacDCZkc4BvDXnoDMZwAAAFU"]
[Thu Jul 30 12:22:50.230259 2026] [security2:error] [pid 727775:tid 727938] [client 51.116.238.8:5005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/adminfuns.php"] [unique_id "amuIasDCZkc4BvDXnoDMcgAAACE"]
[Thu Jul 30 12:22:50.230372 2026] [security2:error] [pid 727775:tid 727938] [client 51.116.238.8:5005] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/adminfuns.php"] [unique_id "amuIasDCZkc4BvDXnoDMcgAAACE"]
[Thu Jul 30 12:22:50.373115 2026] [security2:error] [pid 727775:tid 727910] [client 142.93.53.183:63729] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/PHPExcel/Classes/PHPExcel/Shared/Escher/DggContainer/BstoreContainer/BSE/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIasDCZkc4BvDXnoDMdAAAAAU"]
[Thu Jul 30 12:22:50.561725 2026] [security2:error] [pid 727775:tid 727970] [client 20.91.199.21:47250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/wp-setup.php"] [unique_id "amuIasDCZkc4BvDXnoDMdQAAAEE"]
[Thu Jul 30 12:22:50.626276 2026] [security2:error] [pid 727775:tid 728009] [client 172.213.232.128:4807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/themes/oceanwp/functions.php"] [unique_id "amuIasDCZkc4BvDXnoDMdgAAAGg"]
[Thu Jul 30 12:22:50.757938 2026] [security2:error] [pid 727775:tid 727942] [client 142.93.53.183:63893] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/PHPExcel/Classes/PHPExcel/Shared/Escher/DggContainer/BstoreContainer/BSE/SEOBARBAR_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIasDCZkc4BvDXnoDMfwAAACU"]
[Thu Jul 30 12:22:50.930251 2026] [security2:error] [pid 727775:tid 727992] [client 51.116.238.8:5022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/404.php"] [unique_id "amuIasDCZkc4BvDXnoDMgAAAAFc"]
[Thu Jul 30 12:22:50.930369 2026] [security2:error] [pid 727775:tid 727992] [client 51.116.238.8:5022] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/404.php"] [unique_id "amuIasDCZkc4BvDXnoDMgAAAAFc"]
[Thu Jul 30 12:22:51.145123 2026] [security2:error] [pid 727775:tid 727957] [client 142.93.53.183:64057] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/PHPExcel/Classes/PHPExcel/Shared/Escher/DggContainer/BstoreContainer/BSE/SEOBARBAR_DATA/alfacgiapi/py.alfa"] [unique_id "amuIa8DCZkc4BvDXnoDMgQAAADQ"]
[Thu Jul 30 12:22:51.350188 2026] [security2:error] [pid 727775:tid 727912] [client 172.213.232.128:21613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/themes/twentythirteen/functions.php"] [unique_id "amuIa8DCZkc4BvDXnoDMiAAAAAc"]
[Thu Jul 30 12:22:51.540697 2026] [security2:error] [pid 727775:tid 728011] [client 142.93.53.183:64233] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/html2pdf/_tcpdf_5.0.002/fonts/freefont-20090104/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIa8DCZkc4BvDXnoDMiQAAAGo"]
[Thu Jul 30 12:22:51.917286 2026] [security2:error] [pid 727775:tid 727949] [client 142.93.53.183:64386] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/html2pdf/_tcpdf_5.0.002/fonts/freefont-20090104/SEOBARBAR_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIa8DCZkc4BvDXnoDMlAAAACw"]
[Thu Jul 30 12:22:52.299454 2026] [security2:error] [pid 727775:tid 728024] [client 142.93.53.183:64550] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/html2pdf/_tcpdf_5.0.002/fonts/freefont-20090104/SEOBARBAR_DATA/alfacgiapi/py.alfa"] [unique_id "amuIbMDCZkc4BvDXnoDMmQAAAHc"]
[Thu Jul 30 12:22:52.542756 2026] [security2:error] [pid 727775:tid 727954] [client 218.60.174.243:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "marlboro-shop.com"] [uri "/index.php"] [unique_id "amuIa8DCZkc4BvDXnoDMjQAAADE"]
[Thu Jul 30 12:22:52.892490 2026] [security2:error] [pid 727775:tid 727985] [client 142.93.53.183:64802] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/foto_alumni/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIbMDCZkc4BvDXnoDMqQAAAFA"]
[Thu Jul 30 12:22:53.392058 2026] [security2:error] [pid 727775:tid 728001] [client 51.116.238.8:5038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/xxx.php"] [unique_id "amuIbcDCZkc4BvDXnoDMtAAAAGA"]
[Thu Jul 30 12:22:53.392192 2026] [security2:error] [pid 727775:tid 728001] [client 51.116.238.8:5038] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/xxx.php"] [unique_id "amuIbcDCZkc4BvDXnoDMtAAAAGA"]
[Thu Jul 30 12:22:53.484346 2026] [security2:error] [pid 727775:tid 727972] [client 142.93.53.183:65088] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/foto_alumni/SEOBARBAR_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIbcDCZkc4BvDXnoDMtQAAAEM"]
[Thu Jul 30 12:22:53.866460 2026] [security2:error] [pid 727775:tid 727962] [client 142.93.53.183:65299] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/test/journals/1/issues/ALFA_HAXOR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIbcDCZkc4BvDXnoDMvgAAADk"]
[Thu Jul 30 12:22:53.997472 2026] [security2:error] [pid 727775:tid 727982] [client 172.213.232.128:4254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/themes/kadence/functions.php"] [unique_id "amuIbcDCZkc4BvDXnoDMwAAAAE0"]
[Thu Jul 30 12:22:54.014399 2026] [security2:error] [pid 727775:tid 727997] [client 51.116.238.8:5089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/classwithtostring.php"] [unique_id "amuIbsDCZkc4BvDXnoDMwQAAAFw"]
[Thu Jul 30 12:22:54.014543 2026] [security2:error] [pid 727775:tid 727997] [client 51.116.238.8:5089] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/classwithtostring.php"] [unique_id "amuIbsDCZkc4BvDXnoDMwQAAAFw"]
[Thu Jul 30 12:22:54.273010 2026] [security2:error] [pid 727775:tid 728018] [client 142.93.53.183:65496] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/test/journals/1/issues/ALFA_HAXOR_DATA/alfacgiapi/py.alfa"] [unique_id "amuIbsDCZkc4BvDXnoDMwgAAAHE"]
[Thu Jul 30 12:22:54.296738 2026] [core:notice] [pid 727775:tid 727989] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:22:54.432796 2026] [security2:error] [pid 727775:tid 727847] [remote 216.73.216.152:50028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuIbsDCZkc4BvDXnoDM0wAAU0c"]
[Thu Jul 30 12:22:54.653568 2026] [security2:error] [pid 727775:tid 728030] [client 142.93.53.183:49321] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/test/journals/1/issues/ALFA_HAXOR_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIbsDCZkc4BvDXnoDM3QAAAH0"]
[Thu Jul 30 12:22:55.008582 2026] [security2:error] [pid 727775:tid 727975] [client 172.213.232.128:4454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/themes/twentytwenty/functions.php"] [unique_id "amuIb8DCZkc4BvDXnoDM5QAAAEY"]
[Thu Jul 30 12:22:55.222175 2026] [security2:error] [pid 727775:tid 728024] [client 142.93.53.183:49630] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/generic/citationStyleLanguage/lib/vendor/composer/MiawSecurity_DATA/MiawSecuritycgiapi/perl.MiawSecurity"] [unique_id "amuIb8DCZkc4BvDXnoDM6gAAAHc"]
[Thu Jul 30 12:22:55.347041 2026] [security2:error] [pid 727775:tid 727917] [client 51.116.238.8:5088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/234ff.php"] [unique_id "amuIb8DCZkc4BvDXnoDNAAAAAAw"]
[Thu Jul 30 12:22:55.347147 2026] [security2:error] [pid 727775:tid 727917] [client 51.116.238.8:5088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/234ff.php"] [unique_id "amuIb8DCZkc4BvDXnoDNAAAAAAw"]
[Thu Jul 30 12:22:55.569189 2026] [security2:error] [pid 727775:tid 727933] [client 172.213.232.128:4817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/content.php"] [unique_id "amuIb8DCZkc4BvDXnoDNCAAAABw"]
[Thu Jul 30 12:22:55.637144 2026] [security2:error] [pid 727775:tid 727939] [client 142.93.53.183:49821] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/generic/citationStyleLanguage/lib/vendor/composer/MiawSecurity_DATA/MiawSecuritycgiapi/py.MiawSecurity"] [unique_id "amuIb8DCZkc4BvDXnoDNDAAAACI"]
[Thu Jul 30 12:22:55.825549 2026] [security2:error] [pid 727775:tid 727921] [client 57.141.0.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuIb8DCZkc4BvDXnoDM6QAAABA"]
[Thu Jul 30 12:22:55.927009 2026] [security2:error] [pid 727775:tid 727888] [remote 216.73.216.152:14970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuIb8DCZkc4BvDXnoDNFgAAVnA"]
[Thu Jul 30 12:22:56.021277 2026] [security2:error] [pid 727775:tid 728008] [client 142.93.53.183:50027] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/generic/citationStyleLanguage/lib/vendor/composer/MiawSecurity_DATA/MiawSecuritycgiapi/bash.MiawSecurity"] [unique_id "amuIcMDCZkc4BvDXnoDNGgAAAGc"]
[Thu Jul 30 12:22:56.160365 2026] [security2:error] [pid 727775:tid 728006] [client 51.116.238.8:5087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/133.php"] [unique_id "amuIcMDCZkc4BvDXnoDNHQAAAGU"]
[Thu Jul 30 12:22:56.160472 2026] [security2:error] [pid 727775:tid 728006] [client 51.116.238.8:5087] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/133.php"] [unique_id "amuIcMDCZkc4BvDXnoDNHQAAAGU"]
[Thu Jul 30 12:22:56.328887 2026] [security2:error] [pid 727775:tid 727962] [client 172.213.232.128:21016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/plugins/not/includes/about.php"] [unique_id "amuIcMDCZkc4BvDXnoDNHgAAADk"]
[Thu Jul 30 12:22:56.450417 2026] [security2:error] [pid 727775:tid 727955] [client 142.93.53.183:50228] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/foto_alumni/SEOBARBAR_DATA/alfacgiapi/py.alfa"] [unique_id "amuIcMDCZkc4BvDXnoDNIgAAADI"]
[Thu Jul 30 12:22:56.831330 2026] [security2:error] [pid 727775:tid 727920] [client 142.93.53.183:50422] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/editor/themes/advanced/docs/en/images/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIcMDCZkc4BvDXnoDNLAAAAA8"]
[Thu Jul 30 12:22:56.929766 2026] [security2:error] [pid 727775:tid 727938] [client 51.116.238.8:4996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-ws68.php"] [unique_id "amuIcMDCZkc4BvDXnoDNLQAAACE"]
[Thu Jul 30 12:22:56.929915 2026] [security2:error] [pid 727775:tid 727938] [client 51.116.238.8:4996] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/wp-ws68.php"] [unique_id "amuIcMDCZkc4BvDXnoDNLQAAACE"]
[Thu Jul 30 12:22:57.181890 2026] [security2:error] [pid 727775:tid 728011] [client 172.213.232.128:17532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/plugins/simple/simple.php"] [unique_id "amuIccDCZkc4BvDXnoDNNQAAAGo"]
[Thu Jul 30 12:22:57.208168 2026] [security2:error] [pid 727775:tid 727928] [client 142.93.53.183:50643] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/editor/themes/advanced/docs/en/images/SEOBARBAR_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIccDCZkc4BvDXnoDNNgAAABc"]
[Thu Jul 30 12:22:57.447224 2026] [security2:error] [pid 727775:tid 728013] [client 51.116.238.8:5030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/mgrr.php"] [unique_id "amuIccDCZkc4BvDXnoDNNwAAAGw"]
[Thu Jul 30 12:22:57.447377 2026] [security2:error] [pid 727775:tid 728013] [client 51.116.238.8:5030] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/mgrr.php"] [unique_id "amuIccDCZkc4BvDXnoDNNwAAAGw"]
[Thu Jul 30 12:22:57.532213 2026] [security2:error] [pid 727775:tid 727978] [client 20.91.199.21:47244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/defaults.php"] [unique_id "amuIccDCZkc4BvDXnoDNPAAAAEk"]
[Thu Jul 30 12:22:57.596876 2026] [security2:error] [pid 727775:tid 727954] [client 142.93.53.183:50838] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/editor/themes/advanced/docs/en/images/SEOBARBAR_DATA/alfacgiapi/py.alfa"] [unique_id "amuIccDCZkc4BvDXnoDNQAAAADE"]
[Thu Jul 30 12:22:57.665012 2026] [security2:error] [pid 727775:tid 727937] [client 195.113.175.167:58021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.175.113.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/youthf.php"] [unique_id "amuIccDCZkc4BvDXnoDNQQAAACA"]
[Thu Jul 30 12:22:57.994768 2026] [security2:error] [pid 727775:tid 727913] [client 142.93.53.183:51043] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/PHPExcel/Documentation/markdown/CalculationEngine/FunctionReference/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIccDCZkc4BvDXnoDNRgAAAAg"]
[Thu Jul 30 12:22:58.057745 2026] [security2:error] [pid 727775:tid 727951] [client 47.128.121.93:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuIccDCZkc4BvDXnoDNRQAAAC4"]
[Thu Jul 30 12:22:58.271400 2026] [security2:error] [pid 727775:tid 727925] [client 51.116.238.8:5051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/55.php"] [unique_id "amuIcsDCZkc4BvDXnoDNTwAAABQ"]
[Thu Jul 30 12:22:58.271504 2026] [security2:error] [pid 727775:tid 727925] [client 51.116.238.8:5051] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/55.php"] [unique_id "amuIcsDCZkc4BvDXnoDNTwAAABQ"]
[Thu Jul 30 12:22:58.459388 2026] [security2:error] [pid 727775:tid 728025] [client 20.91.199.21:47283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/gtc.php"] [unique_id "amuIcsDCZkc4BvDXnoDNUAAAAHg"]
[Thu Jul 30 12:22:58.506904 2026] [security2:error] [pid 727775:tid 727998] [client 142.93.53.183:51317] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/PHPExcel/Documentation/markdown/CalculationEngine/FunctionReference/SEOBARBAR_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIcsDCZkc4BvDXnoDNUQAAAF0"]
[Thu Jul 30 12:22:58.535638 2026] [security2:error] [pid 727775:tid 727990] [client 68.67.112.68:17096] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "alseermarine.com"] [uri "/robots.txt"] [unique_id "amuIcsDCZkc4BvDXnoDNUgAAAFU"]
[Thu Jul 30 12:22:58.864252 2026] [core:notice] [pid 727775:tid 727802] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:22:59.000217 2026] [security2:error] [pid 727775:tid 728010] [client 172.213.232.128:21027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/plugins/wp-theme-editor/include.php"] [unique_id "amuIcsDCZkc4BvDXnoDNWgAAAGk"]
[Thu Jul 30 12:22:59.010242 2026] [security2:error] [pid 727775:tid 728014] [client 142.93.53.183:51577] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/PHPExcel/Documentation/markdown/CalculationEngine/FunctionReference/SEOBARBAR_DATA/alfacgiapi/py.alfa"] [unique_id "amuIc8DCZkc4BvDXnoDNWwAAAG0"]
[Thu Jul 30 12:22:59.417225 2026] [security2:error] [pid 727775:tid 727915] [client 142.93.53.183:51737] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/librari/PHPExcel/Documentation/markdown/CalculationEngine/FunctionReference/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIc8DCZkc4BvDXnoDNYgAAAAo"]
[Thu Jul 30 12:22:59.809419 2026] [security2:error] [pid 727775:tid 728015] [client 142.93.53.183:51948] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/librari/PHPExcel/Documentation/markdown/CalculationEngine/FunctionReference/SEOBARBAR_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIc8DCZkc4BvDXnoDNbAAAAG4"]
[Thu Jul 30 12:22:59.817410 2026] [security2:error] [pid 727775:tid 727929] [client 20.91.199.21:47264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/import.php"] [unique_id "amuIc8DCZkc4BvDXnoDNbQAAABg"]
[Thu Jul 30 12:23:00.210324 2026] [security2:error] [pid 727775:tid 728026] [client 142.93.53.183:52132] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/librari/PHPExcel/Documentation/markdown/CalculationEngine/FunctionReference/SEOBARBAR_DATA/alfacgiapi/py.alfa"] [unique_id "amuIdMDCZkc4BvDXnoDNcwAAAHk"]
[Thu Jul 30 12:23:00.258518 2026] [autoindex:error] [pid 727775:tid 727928] [client 2a09:bac0:1000:c48::2e9:73:0] AH01276: Cannot serve directory /home2/mbmudite/tiger388.shop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:23:00.258881 2026] [autoindex:error] [pid 727775:tid 728022] [client 2a09:bac0:1000:c48::2db:d9:0] AH01276: Cannot serve directory /home2/mbmudite/ok.tiger388.shop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:23:00.271678 2026] [autoindex:error] [pid 727775:tid 727978] [client 2a09:bac0:1000:c48::2e9:73:0] AH01276: Cannot serve directory /home2/mbmudite/tiger388.shop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:23:00.272106 2026] [autoindex:error] [pid 727775:tid 727972] [client 2a09:bac0:1000:c48::2e9:73:0] AH01276: Cannot serve directory /home2/mbmudite/tiger388.shop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:23:00.333744 2026] [autoindex:error] [pid 727775:tid 727993] [client 2a09:bac0:1000:c48::2db:d9:0] AH01276: Cannot serve directory /home2/mbmudite/tiger388.shop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.tiger388.shop.
[Thu Jul 30 12:23:00.340095 2026] [autoindex:error] [pid 727775:tid 728032] [client 2a09:bac0:1000:c48::2db:d9:0] AH01276: Cannot serve directory /home2/mbmudite/tiger388.shop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://mail.tiger388.shop.
[Thu Jul 30 12:23:00.352762 2026] [autoindex:error] [pid 727775:tid 727973] [client 2a09:bac0:1000:c48::2e9:73:0] AH01276: Cannot serve directory /home2/mbmudite/tiger388.shop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://tiger388.shop.
[Thu Jul 30 12:23:00.366783 2026] [autoindex:error] [pid 727775:tid 728027] [client 2a09:bac0:1000:c48::2e9:73:0] AH01276: Cannot serve directory /home2/mbmudite/ok.tiger388.shop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://ok.tiger388.shop.
[Thu Jul 30 12:23:00.510630 2026] [security2:error] [pid 727775:tid 727800] [remote 216.73.216.152:14970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuIdMDCZkc4BvDXnoDNkQAALhg"]
[Thu Jul 30 12:23:00.590757 2026] [security2:error] [pid 727775:tid 727968] [client 142.93.53.183:52308] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/generic/citationStyleLanguage/lib/vendor/seboettg/citeproc-php/src/Seboettg/CiteProc/Rendering/Choose/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIdMDCZkc4BvDXnoDNkgAAAD8"]
[Thu Jul 30 12:23:00.985686 2026] [security2:error] [pid 727775:tid 728024] [client 142.93.53.183:52495] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/generic/citationStyleLanguage/lib/vendor/seboettg/citeproc-php/src/Seboettg/CiteProc/Rendering/Choose/SEOBARBAR_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIdMDCZkc4BvDXnoDNnAAAAHc"]
[Thu Jul 30 12:23:01.213073 2026] [security2:error] [pid 727775:tid 727918] [client 123.245.84.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIdMDCZkc4BvDXnoDNmQAADSI"]
[Thu Jul 30 12:23:01.380579 2026] [security2:error] [pid 727775:tid 727927] [client 142.93.53.183:52696] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/generic/citationStyleLanguage/lib/vendor/seboettg/citeproc-php/src/Seboettg/CiteProc/Rendering/Choose/SEOBARBAR_DATA/alfacgiapi/py.alfa"] [unique_id "amuIdcDCZkc4BvDXnoDNpwAAABY"]
[Thu Jul 30 12:23:01.760813 2026] [security2:error] [pid 727775:tid 727998] [client 57.141.0.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuIdcDCZkc4BvDXnoDNoAAAAF0"]
[Thu Jul 30 12:23:01.795079 2026] [security2:error] [pid 727775:tid 727931] [client 142.93.53.183:52862] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/OJS/files/temp/505/alfacgiapi/perl.alfa"] [unique_id "amuIdcDCZkc4BvDXnoDNsAAAABo"]
[Thu Jul 30 12:23:02.278483 2026] [security2:error] [pid 727775:tid 727908] [client 142.93.53.183:53072] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/files/temp/505/alfacgiapi/perl.alfa"] [unique_id "amuIdsDCZkc4BvDXnoDNtgAAAAM"]
[Thu Jul 30 12:23:02.483050 2026] [security2:error] [pid 727775:tid 727957] [client 175.30.48.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIdsDCZkc4BvDXnoDNsgAANB0"]
[Thu Jul 30 12:23:02.517222 2026] [security2:error] [pid 727775:tid 727913] [client 20.91.199.21:47295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/lufix.php"] [unique_id "amuIdsDCZkc4BvDXnoDNuwAAAAg"]
[Thu Jul 30 12:23:02.687807 2026] [security2:error] [pid 727775:tid 728019] [client 176.29.242.55:2139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.toscanamall.com"] [uri "/fi/product.php"] [unique_id "amuIdsDCZkc4BvDXnoDNugAAAHI"]
[Thu Jul 30 12:23:02.688326 2026] [security2:error] [pid 727775:tid 727920] [client 142.93.53.183:53256] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/OJS/files/temp/505/alfacgiapi/bash.alfa"] [unique_id "amuIdsDCZkc4BvDXnoDNvQAAAA8"]
[Thu Jul 30 12:23:03.072627 2026] [security2:error] [pid 727775:tid 727936] [client 142.93.53.183:53424] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/files/temp/505/alfacgiapi/bash.alfa"] [unique_id "amuId8DCZkc4BvDXnoDNxAAAAB8"]
[Thu Jul 30 12:23:03.150264 2026] [security2:error] [pid 727775:tid 727986] [client 20.91.199.21:47643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/Geforce.php"] [unique_id "amuId8DCZkc4BvDXnoDNxwAAAFE"]
[Thu Jul 30 12:23:03.259901 2026] [security2:error] [pid 727775:tid 728001] [client 3.229.164.203:4795] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2016/11/88ab90a4828189a2b222831bbe60a3fd-400x196@2x.jpg"] [unique_id "amuId8DCZkc4BvDXnoDNyAAAAGA"]
[Thu Jul 30 12:23:03.486933 2026] [security2:error] [pid 727775:tid 727949] [client 123.245.84.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuId8DCZkc4BvDXnoDNxgAALCo"]
[Thu Jul 30 12:23:03.529233 2026] [security2:error] [pid 727775:tid 728032] [client 142.93.53.183:53607] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/OJS/files/temp/505/alfacgiapi/py.alfa"] [unique_id "amuId8DCZkc4BvDXnoDN0QAAAH8"]
[Thu Jul 30 12:23:03.911665 2026] [security2:error] [pid 727775:tid 727914] [client 142.93.53.183:53765] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/files/temp/505/alfacgiapi/py.alfa"] [unique_id "amuId8DCZkc4BvDXnoDN1QAAAAk"]
[Thu Jul 30 12:23:04.113827 2026] [security2:error] [pid 727775:tid 727973] [client 20.91.199.21:47253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/a4.php"] [unique_id "amuIeMDCZkc4BvDXnoDN2gAAAEQ"]
[Thu Jul 30 12:23:04.291188 2026] [security2:error] [pid 727775:tid 728005] [client 142.93.53.183:53921] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/themes/bootstrap3/bootstrap/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIeMDCZkc4BvDXnoDN3AAAAGQ"]
[Thu Jul 30 12:23:04.665066 2026] [security2:error] [pid 727775:tid 727991] [client 142.93.53.183:54080] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/themes/bootstrap3/bootstrap/SEOBARBAR_DATA/alfacgiapi/py.alfa"] [unique_id "amuIeMDCZkc4BvDXnoDN5AAAAFY"]
[Thu Jul 30 12:23:05.043025 2026] [security2:error] [pid 727775:tid 728028] [client 175.30.48.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIeMDCZkc4BvDXnoDN5QAAeyw"]
[Thu Jul 30 12:23:05.046875 2026] [security2:error] [pid 727775:tid 727998] [client 142.93.53.183:54249] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/themes/bootstrap3/bootstrap/SEOBARBAR_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIecDCZkc4BvDXnoDN7AAAAF0"]
[Thu Jul 30 12:23:05.335528 2026] [security2:error] [pid 727775:tid 727985] [client 20.91.199.21:47294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/accueil.php"] [unique_id "amuIecDCZkc4BvDXnoDN7QAAAFA"]
[Thu Jul 30 12:23:05.425667 2026] [security2:error] [pid 727775:tid 727988] [client 142.93.53.183:54413] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/fonts/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIecDCZkc4BvDXnoDN8QAAAFM"]
[Thu Jul 30 12:23:05.942967 2026] [security2:error] [pid 727775:tid 727968] [client 142.93.53.183:54663] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/fonts/SEOBARBAR_DATA/alfacgiapi/py.alfa"] [unique_id "amuIecDCZkc4BvDXnoDN_gAAAD8"]
[Thu Jul 30 12:23:05.980549 2026] [security2:error] [pid 727775:tid 728009] [client 20.91.199.21:46722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/dashboard.php"] [unique_id "amuIecDCZkc4BvDXnoDN_wAAAGg"]
[Thu Jul 30 12:23:06.015783 2026] [security2:error] [pid 727775:tid 728026] [client 123.245.84.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIecDCZkc4BvDXnoDN-AAAeTI"]
[Thu Jul 30 12:23:06.044880 2026] [core:notice] [pid 727775:tid 728027] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:06.323701 2026] [security2:error] [pid 727775:tid 727821] [remote 216.73.216.152:25630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuIesDCZkc4BvDXnoDOBwAAIi0"]
[Thu Jul 30 12:23:06.338723 2026] [security2:error] [pid 727775:tid 727906] [client 142.93.53.183:54829] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/fonts/SEOBARBAR_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIesDCZkc4BvDXnoDOCAAAAAE"]
[Thu Jul 30 12:23:06.548631 2026] [core:notice] [pid 727775:tid 727924] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:06.729659 2026] [security2:error] [pid 727775:tid 727943] [client 142.93.53.183:54985] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/jurnal/files/contexts/3/library/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIesDCZkc4BvDXnoDOEwAAACY"]
[Thu Jul 30 12:23:06.757961 2026] [security2:error] [pid 727775:tid 727921] [client 213.152.161.118:39154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuIesDCZkc4BvDXnoDOFAAAABA"]
[Thu Jul 30 12:23:06.758070 2026] [security2:error] [pid 727775:tid 727921] [client 213.152.161.118:39154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuIesDCZkc4BvDXnoDOFAAAABA"]
[Thu Jul 30 12:23:07.062721 2026] [security2:error] [pid 727775:tid 727909] [client 185.191.171.12:13284] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/12/14/beneficiarios-com-nis-final-3-recebem-nesta-quarta-14-auxilio-brasil/"] [unique_id "amuIe8DCZkc4BvDXnoDOGwAAAAQ"]
[Thu Jul 30 12:23:07.062859 2026] [security2:error] [pid 727775:tid 727909] [client 185.191.171.12:13284] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/12/14/beneficiarios-com-nis-final-3-recebem-nesta-quarta-14-auxilio-brasil/"] [unique_id "amuIe8DCZkc4BvDXnoDOGwAAAAQ"]
[Thu Jul 30 12:23:07.112756 2026] [security2:error] [pid 727775:tid 727950] [client 142.93.53.183:55154] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/jurnal/files/contexts/3/library/SEOBARBAR_DATA/alfacgiapi/py.alfa"] [unique_id "amuIe8DCZkc4BvDXnoDOHwAAAC0"]
[Thu Jul 30 12:23:07.436555 2026] [security2:error] [pid 727775:tid 727985] [client 175.30.48.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIe8DCZkc4BvDXnoDOIAAAUEk"]
[Thu Jul 30 12:23:07.501528 2026] [security2:error] [pid 727775:tid 728015] [client 142.93.53.183:55301] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/jurnal/files/contexts/3/library/SEOBARBAR_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIe8DCZkc4BvDXnoDOJQAAAG4"]
[Thu Jul 30 12:23:07.900092 2026] [security2:error] [pid 727775:tid 727986] [client 142.93.53.183:55487] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/header/.tmb/ALFA_DATA/HYBRID_THEORY/hybridcgiapi/perl.alfa"] [unique_id "amuIe8DCZkc4BvDXnoDOKgAAAFE"]
[Thu Jul 30 12:23:07.957281 2026] [security2:error] [pid 727775:tid 727970] [client 172.213.232.128:4824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/themes/aahana/json.php"] [unique_id "amuIe8DCZkc4BvDXnoDOLgAAAEE"]
[Thu Jul 30 12:23:08.279485 2026] [security2:error] [pid 727775:tid 727976] [client 142.93.53.183:55665] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/header/.tmb/ALFA_DATA/HYBRID_THEORY/hybridcgiapi/py.alfa"] [unique_id "amuIfMDCZkc4BvDXnoDOMgAAAEc"]
[Thu Jul 30 12:23:08.645524 2026] [security2:error] [pid 727775:tid 727959] [client 20.91.199.21:47620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/radio.php"] [unique_id "amuIfMDCZkc4BvDXnoDOOAAAADY"]
[Thu Jul 30 12:23:08.676322 2026] [security2:error] [pid 727775:tid 728026] [client 142.93.53.183:55842] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/header/.tmb/ALFA_DATA/HYBRID_THEORY/hybridcgiapi/bash.alfa"] [unique_id "amuIfMDCZkc4BvDXnoDOPAAAAHk"]
[Thu Jul 30 12:23:08.677671 2026] [security2:error] [pid 727775:tid 727993] [client 172.213.232.128:8400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/plugins/awesome-coming-soon/come.php"] [unique_id "amuIfMDCZkc4BvDXnoDOPQAAAFg"]
[Thu Jul 30 12:23:09.060437 2026] [security2:error] [pid 727775:tid 727911] [client 142.93.53.183:56016] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/header/.tmb/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIfcDCZkc4BvDXnoDOQQAAAAY"]
[Thu Jul 30 12:23:09.419414 2026] [security2:error] [pid 727775:tid 728031] [client 172.202.44.182:48415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/wk/index.php"] [unique_id "amuIfcDCZkc4BvDXnoDORwAAAH4"]
[Thu Jul 30 12:23:09.451064 2026] [security2:error] [pid 727775:tid 727940] [client 142.93.53.183:56188] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/header/.tmb/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuIfcDCZkc4BvDXnoDOSAAAACM"]
[Thu Jul 30 12:23:09.489825 2026] [security2:error] [pid 727775:tid 728021] [client 123.245.84.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIfcDCZkc4BvDXnoDOQgAAdEU"]
[Thu Jul 30 12:23:09.839062 2026] [security2:error] [pid 727775:tid 727962] [client 142.93.53.183:56370] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/header/.tmb/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIfcDCZkc4BvDXnoDOTwAAADk"]
[Thu Jul 30 12:23:10.079619 2026] [security2:error] [pid 727775:tid 727851] [remote 47.128.28.104:16464] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/moncler-jacket-39/"] [unique_id "amuIfsDCZkc4BvDXnoDOVQAAA0s"]
[Thu Jul 30 12:23:10.123556 2026] [security2:error] [pid 727775:tid 728020] [client 172.237.109.114:20205] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.env.old"] [unique_id "amuIfsDCZkc4BvDXnoDOXQAAAHM"]
[Thu Jul 30 12:23:10.150737 2026] [security2:error] [pid 727775:tid 727947] [client 172.237.109.114:49833] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.env"] [unique_id "amuIfsDCZkc4BvDXnoDOYQAAACo"]
[Thu Jul 30 12:23:10.234361 2026] [security2:error] [pid 727775:tid 727979] [client 142.93.53.183:56531] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/litespeed-cache/alfacgiapi/perl.alfa"] [unique_id "amuIfsDCZkc4BvDXnoDOYgAAAEo"]
[Thu Jul 30 12:23:10.502521 2026] [core:notice] [pid 727775:tid 727919] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:10.628436 2026] [security2:error] [pid 727775:tid 727936] [client 142.93.53.183:56705] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/themes/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIfsDCZkc4BvDXnoDOagAAAB8"]
[Thu Jul 30 12:23:10.676172 2026] [security2:error] [pid 727775:tid 727956] [client 172.237.109.114:56185] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIfsDCZkc4BvDXnoDOVAAAADM"]
[Thu Jul 30 12:23:10.749505 2026] [security2:error] [pid 727775:tid 727981] [client 172.237.109.114:41784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIfsDCZkc4BvDXnoDOXAAAAEw"]
[Thu Jul 30 12:23:10.758156 2026] [security2:error] [pid 727775:tid 728007] [client 172.237.109.114:23833] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIfsDCZkc4BvDXnoDOWAAAAGY"]
[Thu Jul 30 12:23:10.765441 2026] [security2:error] [pid 727775:tid 727944] [client 172.237.109.114:34614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIfsDCZkc4BvDXnoDOVwAAACc"]
[Thu Jul 30 12:23:10.773383 2026] [security2:error] [pid 727775:tid 727997] [client 172.237.109.114:55271] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIfsDCZkc4BvDXnoDOWQAAAFw"]
[Thu Jul 30 12:23:10.775576 2026] [security2:error] [pid 727775:tid 727955] [client 172.237.109.114:43117] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIfsDCZkc4BvDXnoDOVgAAADI"]
[Thu Jul 30 12:23:10.775617 2026] [security2:error] [pid 727775:tid 727915] [client 172.237.109.114:51749] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIfsDCZkc4BvDXnoDOWwAAAAo"]
[Thu Jul 30 12:23:10.792808 2026] [security2:error] [pid 727775:tid 728003] [client 172.237.109.114:62701] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIfsDCZkc4BvDXnoDOWgAAAGI"]
[Thu Jul 30 12:23:10.833378 2026] [security2:error] [pid 727775:tid 727909] [client 172.237.109.114:41327] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIfsDCZkc4BvDXnoDOYAAAAAQ"]
[Thu Jul 30 12:23:10.840078 2026] [security2:error] [pid 727775:tid 727905] [client 172.237.109.114:56569] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIfsDCZkc4BvDXnoDOXgAAAAA"]
[Thu Jul 30 12:23:11.014817 2026] [security2:error] [pid 727775:tid 727918] [client 142.93.53.183:56876] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/ID3/WOLFSHELL/razorcgiapi/perl.haxor"] [unique_id "amuIf8DCZkc4BvDXnoDOcgAAAA0"]
[Thu Jul 30 12:23:11.033241 2026] [security2:error] [pid 727775:tid 727983] [client 175.30.48.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIfsDCZkc4BvDXnoDOawAATmU"]
[Thu Jul 30 12:23:11.438247 2026] [security2:error] [pid 727775:tid 727963] [client 142.93.53.183:57075] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/ID3/WOLFSHELL/razorcgiapi/py.haxor"] [unique_id "amuIf8DCZkc4BvDXnoDOegAAADo"]
[Thu Jul 30 12:23:11.664049 2026] [security2:error] [pid 727775:tid 727971] [client 172.213.232.128:23030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/plugins/wp-conflg.php"] [unique_id "amuIf8DCZkc4BvDXnoDOfwAAAEI"]
[Thu Jul 30 12:23:11.775689 2026] [security2:error] [pid 727775:tid 727995] [client 91.92.41.115:52131] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.ojq.udi.temporary.site"] [uri "/.env"] [unique_id "amuIf8DCZkc4BvDXnoDOgAAAAFo"]
[Thu Jul 30 12:23:11.840814 2026] [security2:error] [pid 727775:tid 728021] [client 142.93.53.183:57251] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/ID3/WOLFSHELL/razorcgiapi/bash.haxor"] [unique_id "amuIf8DCZkc4BvDXnoDOhAAAAHQ"]
[Thu Jul 30 12:23:12.227400 2026] [security2:error] [pid 727775:tid 727990] [client 175.30.48.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIf8DCZkc4BvDXnoDOiAAAVXY"]
[Thu Jul 30 12:23:12.241097 2026] [security2:error] [pid 727775:tid 728023] [client 142.93.53.183:57429] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/rest-api/fields/WOLFSHELL/razorcgiapi/perl.haxor"] [unique_id "amuIgMDCZkc4BvDXnoDOjQAAAHY"]
[Thu Jul 30 12:23:12.483888 2026] [security2:error] [pid 727775:tid 728014] [client 57.141.0.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuIf8DCZkc4BvDXnoDOhwAAAG0"]
[Thu Jul 30 12:23:12.492088 2026] [security2:error] [pid 727775:tid 728028] [client 192.178.15.67:42505] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuIgMDCZkc4BvDXnoDOkQAAAHs"]
[Thu Jul 30 12:23:12.625655 2026] [security2:error] [pid 727775:tid 727957] [client 142.93.53.183:57593] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/rest-api/fields/WOLFSHELL/razorcgiapi/py.haxor"] [unique_id "amuIgMDCZkc4BvDXnoDOlAAAADQ"]
[Thu Jul 30 12:23:12.897694 2026] [security2:error] [pid 727775:tid 727927] [client 20.91.199.21:47242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/wpsml-sys.php"] [unique_id "amuIgMDCZkc4BvDXnoDOnAAAABY"]
[Thu Jul 30 12:23:12.907764 2026] [security2:error] [pid 727775:tid 727908] [client 172.202.44.182:48394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/av.php"] [unique_id "amuIgMDCZkc4BvDXnoDOngAAAAM"]
[Thu Jul 30 12:23:13.007196 2026] [security2:error] [pid 727775:tid 727981] [client 142.93.53.183:57754] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/rest-api/fields/WOLFSHELL/razorcgiapi/bash.haxor"] [unique_id "amuIgcDCZkc4BvDXnoDOnwAAAEw"]
[Thu Jul 30 12:23:13.239036 2026] [security2:error] [pid 727775:tid 727938] [client 123.245.84.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIgMDCZkc4BvDXnoDOnQAAIWY"]
[Thu Jul 30 12:23:13.545105 2026] [security2:error] [pid 727775:tid 727972] [client 142.93.53.183:57957] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/themes/alfacgiapi/perl.alfa"] [unique_id "amuIgcDCZkc4BvDXnoDOqQAAAEM"]
[Thu Jul 30 12:23:13.757305 2026] [security2:error] [pid 727775:tid 727955] [client 57.141.0.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuIgcDCZkc4BvDXnoDOogAAADI"]
[Thu Jul 30 12:23:13.780122 2026] [security2:error] [pid 727775:tid 728001] [client 20.91.199.21:47669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/02.php"] [unique_id "amuIgcDCZkc4BvDXnoDOqgAAAGA"]
[Thu Jul 30 12:23:13.926218 2026] [security2:error] [pid 727775:tid 727974] [client 142.93.53.183:58129] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/themes/hello-elementor/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIgcDCZkc4BvDXnoDOsAAAAEU"]
[Thu Jul 30 12:23:13.957777 2026] [security2:error] [pid 727775:tid 727931] [client 172.213.232.128:7918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/Requests/about.php"] [unique_id "amuIgcDCZkc4BvDXnoDOsQAAABo"]
[Thu Jul 30 12:23:14.016115 2026] [security2:error] [pid 727775:tid 727886] [remote 54.37.118.86:22126] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "dhowcruisedinner.com"] [uri "/marina-glass-boat.html"] [unique_id "amuIgsDCZkc4BvDXnoDOswAAIG4"]
[Thu Jul 30 12:23:14.016275 2026] [security2:error] [pid 727775:tid 727937] [client 54.37.118.86:22126] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dhowcruisedinner.com"] [uri "/marina-glass-boat.html"] [unique_id "amuIgsDCZkc4BvDXnoDOswAAIG4"]
[Thu Jul 30 12:23:14.308131 2026] [security2:error] [pid 727775:tid 728013] [client 142.93.53.183:58305] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/themes/hello-elementor/alfacgiapi/perl.alfa"] [unique_id "amuIgsDCZkc4BvDXnoDOuwAAAGw"]
[Thu Jul 30 12:23:14.363195 2026] [security2:error] [pid 727775:tid 728009] [client 20.91.199.21:47262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/infos.php"] [unique_id "amuIgsDCZkc4BvDXnoDOvQAAAGg"]
[Thu Jul 30 12:23:14.702765 2026] [security2:error] [pid 727775:tid 727992] [client 142.93.53.183:58482] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/themes/twentytwentyone/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIgsDCZkc4BvDXnoDOxQAAAFc"]
[Thu Jul 30 12:23:15.061819 2026] [security2:error] [pid 727775:tid 727940] [client 175.30.48.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIgsDCZkc4BvDXnoDOxgAAI2M"]
[Thu Jul 30 12:23:15.112430 2026] [security2:error] [pid 727775:tid 727950] [client 142.93.53.183:58665] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/themes/twentytwentyone/alfacgiapi/perl.alfa"] [unique_id "amuIg8DCZkc4BvDXnoDOywAAAC0"]
[Thu Jul 30 12:23:15.187326 2026] [security2:error] [pid 727775:tid 727968] [client 172.202.44.182:48387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/mini.php"] [unique_id "amuIg8DCZkc4BvDXnoDOzwAAAD8"]
[Thu Jul 30 12:23:15.466604 2026] [security2:error] [pid 727775:tid 727960] [client 185.191.171.2:16088] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2020/10/30/policia-prende-grupo-suspeito-de-traficar-drogas-da-bolivia-em-joao-pessoa/"] [unique_id "amuIg8DCZkc4BvDXnoDO1AAAADc"]
[Thu Jul 30 12:23:15.466761 2026] [security2:error] [pid 727775:tid 727960] [client 185.191.171.2:16088] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2020/10/30/policia-prende-grupo-suspeito-de-traficar-drogas-da-bolivia-em-joao-pessoa/"] [unique_id "amuIg8DCZkc4BvDXnoDO1AAAADc"]
[Thu Jul 30 12:23:15.508551 2026] [security2:error] [pid 727775:tid 727920] [client 142.93.53.183:58841] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/themes/twentytwentythree/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIg8DCZkc4BvDXnoDO1QAAAA8"]
[Thu Jul 30 12:23:15.908737 2026] [security2:error] [pid 727775:tid 727915] [client 142.93.53.183:59012] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/themes/twentytwentythree/alfacgiapi/perl.alfa"] [unique_id "amuIg8DCZkc4BvDXnoDO4wAAAAo"]
[Thu Jul 30 12:23:16.052746 2026] [security2:error] [pid 727775:tid 727913] [client 123.245.84.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIg8DCZkc4BvDXnoDO2QAACHk"]
[Thu Jul 30 12:23:16.180543 2026] [security2:error] [pid 727775:tid 727978] [client 172.213.232.128:7924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/style-engine/about.php"] [unique_id "amuIhMDCZkc4BvDXnoDO6wAAAEk"]
[Thu Jul 30 12:23:16.312208 2026] [security2:error] [pid 727775:tid 727931] [client 142.93.53.183:59191] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/themes/twentytwentytwo/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIhMDCZkc4BvDXnoDO7wAAABo"]
[Thu Jul 30 12:23:16.692431 2026] [security2:error] [pid 727775:tid 727966] [client 142.93.53.183:59367] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/themes/twentytwentytwo/alfacgiapi/perl.alfa"] [unique_id "amuIhMDCZkc4BvDXnoDO-QAAAD0"]
[Thu Jul 30 12:23:16.806520 2026] [security2:error] [pid 727775:tid 727941] [client 172.213.232.128:8841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/rest-api/about.php"] [unique_id "amuIhMDCZkc4BvDXnoDO-gAAACQ"]
[Thu Jul 30 12:23:16.863333 2026] [security2:error] [pid 727775:tid 727989] [client 20.91.199.21:47636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/updates.php"] [unique_id "amuIhMDCZkc4BvDXnoDO_gAAAFQ"]
[Thu Jul 30 12:23:17.084771 2026] [security2:error] [pid 727775:tid 727971] [client 142.93.53.183:59545] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/upgrade/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIhcDCZkc4BvDXnoDO_wAAAEI"]
[Thu Jul 30 12:23:17.302114 2026] [security2:error] [pid 727775:tid 728013] [client 172.202.44.182:53120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/aa.php"] [unique_id "amuIhcDCZkc4BvDXnoDPBQAAAGw"]
[Thu Jul 30 12:23:17.462354 2026] [security2:error] [pid 727775:tid 727982] [client 142.93.53.183:59716] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/upgrade/alfacgiapi/perl.alfa"] [unique_id "amuIhcDCZkc4BvDXnoDPCwAAAE0"]
[Thu Jul 30 12:23:17.509441 2026] [security2:error] [pid 727775:tid 728024] [client 175.30.48.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIhcDCZkc4BvDXnoDPAAAAdyc"]
[Thu Jul 30 12:23:17.742428 2026] [security2:error] [pid 727775:tid 727991] [client 20.91.199.21:47281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/user.php"] [unique_id "amuIhcDCZkc4BvDXnoDPDwAAAFY"]
[Thu Jul 30 12:23:18.077807 2026] [security2:error] [pid 727775:tid 727961] [client 142.93.53.183:59993] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIhsDCZkc4BvDXnoDPFAAAADg"]
[Thu Jul 30 12:23:18.461746 2026] [security2:error] [pid 727775:tid 728007] [client 142.93.53.183:60171] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/alfacgiapi/perl.alfa"] [unique_id "amuIhsDCZkc4BvDXnoDPHQAAAGY"]
[Thu Jul 30 12:23:18.492298 2026] [security2:error] [pid 727775:tid 727957] [client 20.91.199.21:47666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/admin-ajax.php"] [unique_id "amuIhsDCZkc4BvDXnoDPHwAAADQ"]
[Thu Jul 30 12:23:18.494336 2026] [security2:error] [pid 727775:tid 728028] [client 123.245.84.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIhsDCZkc4BvDXnoDPFQAAexg"]
[Thu Jul 30 12:23:18.501689 2026] [security2:error] [pid 727775:tid 727979] [client 172.202.44.182:55847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/w.php"] [unique_id "amuIhsDCZkc4BvDXnoDPIAAAAEo"]
[Thu Jul 30 12:23:18.863945 2026] [security2:error] [pid 727775:tid 727958] [client 142.93.53.183:60347] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/01/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIhsDCZkc4BvDXnoDPJQAAADU"]
[Thu Jul 30 12:23:19.092578 2026] [security2:error] [pid 727775:tid 727977] [client 20.91.199.21:47240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/alfa.php"] [unique_id "amuIh8DCZkc4BvDXnoDPKQAAAEg"]
[Thu Jul 30 12:23:19.244832 2026] [security2:error] [pid 727775:tid 727930] [client 172.213.232.128:23005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuIh8DCZkc4BvDXnoDPKwAAABk"]
[Thu Jul 30 12:23:19.366747 2026] [security2:error] [pid 727775:tid 727999] [client 142.93.53.183:60590] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/01/alfacgiapi/perl.alfa"] [unique_id "amuIh8DCZkc4BvDXnoDPLwAAAF4"]
[Thu Jul 30 12:23:19.750893 2026] [security2:error] [pid 727775:tid 727916] [client 142.93.53.183:60755] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/02/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIh8DCZkc4BvDXnoDPNAAAAAs"]
[Thu Jul 30 12:23:19.974403 2026] [security2:error] [pid 727775:tid 727949] [client 172.213.232.128:22668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/banners/about.php"] [unique_id "amuIh8DCZkc4BvDXnoDPOAAAACw"]
[Thu Jul 30 12:23:20.109372 2026] [security2:error] [pid 727775:tid 727952] [client 172.202.44.182:53137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/admin.php"] [unique_id "amuIiMDCZkc4BvDXnoDPPgAAAC8"]
[Thu Jul 30 12:23:20.138181 2026] [security2:error] [pid 727775:tid 727973] [client 142.93.53.183:60913] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/02/alfacgiapi/perl.alfa"] [unique_id "amuIiMDCZkc4BvDXnoDPPwAAAEQ"]
[Thu Jul 30 12:23:20.456676 2026] [security2:error] [pid 727775:tid 727954] [client 175.30.48.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIiMDCZkc4BvDXnoDPQAAAMSA"]
[Thu Jul 30 12:23:20.517043 2026] [security2:error] [pid 727775:tid 728006] [client 142.93.53.183:61105] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/03/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIiMDCZkc4BvDXnoDPSAAAAGU"]
[Thu Jul 30 12:23:20.899525 2026] [security2:error] [pid 727775:tid 727968] [client 142.93.53.183:61294] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/03/alfacgiapi/perl.alfa"] [unique_id "amuIiMDCZkc4BvDXnoDPVAAAAD8"]
[Thu Jul 30 12:23:21.095415 2026] [security2:error] [pid 727775:tid 728017] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuIicDCZkc4BvDXnoDPWgAAAHA"]
[Thu Jul 30 12:23:21.095510 2026] [security2:error] [pid 727775:tid 728017] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuIicDCZkc4BvDXnoDPWgAAAHA"]
[Thu Jul 30 12:23:21.295537 2026] [security2:error] [pid 727775:tid 727979] [client 142.93.53.183:61476] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/04/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIicDCZkc4BvDXnoDPWwAAAEo"]
[Thu Jul 30 12:23:21.337698 2026] [security2:error] [pid 727775:tid 728003] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuIicDCZkc4BvDXnoDPXQAAAGI"]
[Thu Jul 30 12:23:21.337786 2026] [security2:error] [pid 727775:tid 728003] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuIicDCZkc4BvDXnoDPXQAAAGI"]
[Thu Jul 30 12:23:21.359419 2026] [security2:error] [pid 727775:tid 727820] [remote 57.141.0.54:55820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/674008491/feed/rss2/"] [unique_id "amuIicDCZkc4BvDXnoDPXwAAFiw"]
[Thu Jul 30 12:23:21.586608 2026] [security2:error] [pid 727775:tid 728019] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/xstelth.php"] [unique_id "amuIicDCZkc4BvDXnoDPZwAAAHI"]
[Thu Jul 30 12:23:21.586717 2026] [security2:error] [pid 727775:tid 728019] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/xstelth.php"] [unique_id "amuIicDCZkc4BvDXnoDPZwAAAHI"]
[Thu Jul 30 12:23:21.589400 2026] [security2:error] [pid 727775:tid 728025] [client 172.202.44.182:52775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuIicDCZkc4BvDXnoDPaAAAAHg"]
[Thu Jul 30 12:23:21.687081 2026] [security2:error] [pid 727775:tid 727944] [client 142.93.53.183:61647] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/04/alfacgiapi/perl.alfa"] [unique_id "amuIicDCZkc4BvDXnoDPagAAACc"]
[Thu Jul 30 12:23:21.820263 2026] [security2:error] [pid 727775:tid 727999] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/584062352875874akp.php"] [unique_id "amuIicDCZkc4BvDXnoDPawAAAF4"]
[Thu Jul 30 12:23:21.820423 2026] [security2:error] [pid 727775:tid 727999] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/584062352875874akp.php"] [unique_id "amuIicDCZkc4BvDXnoDPawAAAF4"]
[Thu Jul 30 12:23:22.077389 2026] [security2:error] [pid 727775:tid 727932] [client 142.93.53.183:61825] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/05/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIisDCZkc4BvDXnoDPcAAAABs"]
[Thu Jul 30 12:23:22.092479 2026] [security2:error] [pid 727775:tid 728031] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/newfile.php"] [unique_id "amuIisDCZkc4BvDXnoDPcQAAAH4"]
[Thu Jul 30 12:23:22.092574 2026] [security2:error] [pid 727775:tid 728031] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/newfile.php"] [unique_id "amuIisDCZkc4BvDXnoDPcQAAAH4"]
[Thu Jul 30 12:23:22.327337 2026] [security2:error] [pid 727775:tid 727966] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/tBEZGQz.php"] [unique_id "amuIisDCZkc4BvDXnoDPdwAAAD0"]
[Thu Jul 30 12:23:22.327449 2026] [security2:error] [pid 727775:tid 727966] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/tBEZGQz.php"] [unique_id "amuIisDCZkc4BvDXnoDPdwAAAD0"]
[Thu Jul 30 12:23:22.460605 2026] [security2:error] [pid 727775:tid 727989] [client 142.93.53.183:62005] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/05/alfacgiapi/perl.alfa"] [unique_id "amuIisDCZkc4BvDXnoDPeAAAAFQ"]
[Thu Jul 30 12:23:22.471138 2026] [security2:error] [pid 727775:tid 727934] [client 123.245.84.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIisDCZkc4BvDXnoDPdgAAHT8"]
[Thu Jul 30 12:23:22.592014 2026] [core:error] [pid 727775:tid 727984] [client 20.91.199.21:47239] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:23:22.592034 2026] [core:error] [pid 727775:tid 727984] [client 20.91.199.21:47239] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:23:22.644372 2026] [security2:error] [pid 727775:tid 728016] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/phpinfo"] [unique_id "amuIisDCZkc4BvDXnoDPgQAAAG8"]
[Thu Jul 30 12:23:22.775572 2026] [security2:error] [pid 727775:tid 727946] [client 172.213.232.128:8321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/about.php"] [unique_id "amuIisDCZkc4BvDXnoDPggAAACk"]
[Thu Jul 30 12:23:22.838865 2026] [security2:error] [pid 727775:tid 727992] [client 142.93.53.183:62177] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/06/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIisDCZkc4BvDXnoDPgwAAAFc"]
[Thu Jul 30 12:23:22.898903 2026] [security2:error] [pid 727775:tid 727964] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/drykl.php"] [unique_id "amuIisDCZkc4BvDXnoDPhAAAADs"]
[Thu Jul 30 12:23:22.899014 2026] [security2:error] [pid 727775:tid 727964] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/drykl.php"] [unique_id "amuIisDCZkc4BvDXnoDPhAAAADs"]
[Thu Jul 30 12:23:23.080824 2026] [security2:error] [pid 727775:tid 727969] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/wp-admin/css/colors/blue/"] [unique_id "amuIi8DCZkc4BvDXnoDPiAAAAEA"]
[Thu Jul 30 12:23:23.232780 2026] [security2:error] [pid 727775:tid 727950] [client 142.93.53.183:62344] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/06/alfacgiapi/perl.alfa"] [unique_id "amuIi8DCZkc4BvDXnoDPjQAAAC0"]
[Thu Jul 30 12:23:23.349474 2026] [security2:error] [pid 727775:tid 727940] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/ls.php"] [unique_id "amuIi8DCZkc4BvDXnoDPjgAAACM"]
[Thu Jul 30 12:23:23.349625 2026] [security2:error] [pid 727775:tid 727940] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/ls.php"] [unique_id "amuIi8DCZkc4BvDXnoDPjgAAACM"]
[Thu Jul 30 12:23:23.510501 2026] [security2:error] [pid 727775:tid 728014] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/dx.php"] [unique_id "amuIi8DCZkc4BvDXnoDPkgAAAG0"]
[Thu Jul 30 12:23:23.510599 2026] [security2:error] [pid 727775:tid 728014] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/dx.php"] [unique_id "amuIi8DCZkc4BvDXnoDPkgAAAG0"]
[Thu Jul 30 12:23:23.617623 2026] [security2:error] [pid 727775:tid 727929] [client 142.93.53.183:62529] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/07/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIi8DCZkc4BvDXnoDPlwAAABg"]
[Thu Jul 30 12:23:23.727673 2026] [security2:error] [pid 727775:tid 727947] [client 172.213.232.128:8330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/.well-known/about.php"] [unique_id "amuIi8DCZkc4BvDXnoDPmAAAACo"]
[Thu Jul 30 12:23:23.780039 2026] [security2:error] [pid 727775:tid 727987] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/mac.php"] [unique_id "amuIi8DCZkc4BvDXnoDPmQAAAFI"]
[Thu Jul 30 12:23:23.780142 2026] [security2:error] [pid 727775:tid 727987] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/mac.php"] [unique_id "amuIi8DCZkc4BvDXnoDPmQAAAFI"]
[Thu Jul 30 12:23:23.922516 2026] [security2:error] [pid 727775:tid 728003] [client 213.152.161.118:36648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuIi8DCZkc4BvDXnoDPmgAAAGI"]
[Thu Jul 30 12:23:23.922612 2026] [security2:error] [pid 727775:tid 728003] [client 213.152.161.118:36648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuIi8DCZkc4BvDXnoDPmgAAAGI"]
[Thu Jul 30 12:23:24.037221 2026] [security2:error] [pid 727775:tid 727957] [client 20.91.199.21:47273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/hehe.php"] [unique_id "amuIjMDCZkc4BvDXnoDPngAAADQ"]
[Thu Jul 30 12:23:24.077464 2026] [security2:error] [pid 727775:tid 727938] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/485.php"] [unique_id "amuIjMDCZkc4BvDXnoDPnwAAACE"]
[Thu Jul 30 12:23:24.077583 2026] [security2:error] [pid 727775:tid 727938] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/485.php"] [unique_id "amuIjMDCZkc4BvDXnoDPnwAAACE"]
[Thu Jul 30 12:23:24.191099 2026] [security2:error] [pid 727775:tid 727955] [client 142.93.53.183:62820] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/07/alfacgiapi/perl.alfa"] [unique_id "amuIjMDCZkc4BvDXnoDPowAAADI"]
[Thu Jul 30 12:23:24.314321 2026] [security2:error] [pid 727775:tid 728011] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/gelio1.php"] [unique_id "amuIjMDCZkc4BvDXnoDPpgAAAGo"]
[Thu Jul 30 12:23:24.314433 2026] [security2:error] [pid 727775:tid 728011] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/gelio1.php"] [unique_id "amuIjMDCZkc4BvDXnoDPpgAAAGo"]
[Thu Jul 30 12:23:24.578047 2026] [security2:error] [pid 727775:tid 727905] [client 142.93.53.183:62970] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/08/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIjMDCZkc4BvDXnoDPrAAAAAA"]
[Thu Jul 30 12:23:24.641496 2026] [security2:error] [pid 727775:tid 727974] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/lp6.php"] [unique_id "amuIjMDCZkc4BvDXnoDPrgAAAEU"]
[Thu Jul 30 12:23:24.641609 2026] [security2:error] [pid 727775:tid 727974] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/lp6.php"] [unique_id "amuIjMDCZkc4BvDXnoDPrgAAAEU"]
[Thu Jul 30 12:23:24.870794 2026] [security2:error] [pid 727775:tid 727981] [client 175.30.48.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIjMDCZkc4BvDXnoDPqwAATFQ"]
[Thu Jul 30 12:23:24.876838 2026] [security2:error] [pid 727775:tid 727959] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuIjMDCZkc4BvDXnoDPsgAAADY"]
[Thu Jul 30 12:23:24.876956 2026] [security2:error] [pid 727775:tid 727959] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuIjMDCZkc4BvDXnoDPsgAAADY"]
[Thu Jul 30 12:23:24.914443 2026] [security2:error] [pid 727775:tid 728025] [client 2a03:2880:f800:5:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuIjMDCZkc4BvDXnoDPpQAAeEw"]
[Thu Jul 30 12:23:24.971070 2026] [security2:error] [pid 727775:tid 727917] [client 142.93.53.183:63161] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/08/alfacgiapi/perl.alfa"] [unique_id "amuIjMDCZkc4BvDXnoDPswAAAAw"]
[Thu Jul 30 12:23:25.205755 2026] [security2:error] [pid 727775:tid 727984] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/wp-includes/sodium_compat/"] [unique_id "amuIjcDCZkc4BvDXnoDPuwAAAE8"]
[Thu Jul 30 12:23:25.355684 2026] [security2:error] [pid 727775:tid 728006] [client 142.93.53.183:63353] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/09/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIjcDCZkc4BvDXnoDPwAAAAGU"]
[Thu Jul 30 12:23:25.370261 2026] [security2:error] [pid 727775:tid 727990] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/w3llscc.php"] [unique_id "amuIjcDCZkc4BvDXnoDPwQAAAFU"]
[Thu Jul 30 12:23:25.370361 2026] [security2:error] [pid 727775:tid 727990] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/w3llscc.php"] [unique_id "amuIjcDCZkc4BvDXnoDPwQAAAFU"]
[Thu Jul 30 12:23:25.505053 2026] [security2:error] [pid 727775:tid 728005] [client 20.91.199.21:47256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/rk2.php"] [unique_id "amuIjcDCZkc4BvDXnoDPwgAAAGQ"]
[Thu Jul 30 12:23:25.603101 2026] [security2:error] [pid 727775:tid 727973] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/miru3.php"] [unique_id "amuIjcDCZkc4BvDXnoDPxwAAAEQ"]
[Thu Jul 30 12:23:25.603190 2026] [security2:error] [pid 727775:tid 727973] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/miru3.php"] [unique_id "amuIjcDCZkc4BvDXnoDPxwAAAEQ"]
[Thu Jul 30 12:23:25.741386 2026] [security2:error] [pid 727775:tid 727935] [client 142.93.53.183:63553] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/09/alfacgiapi/perl.alfa"] [unique_id "amuIjcDCZkc4BvDXnoDPzQAAAB4"]
[Thu Jul 30 12:23:25.861418 2026] [security2:error] [pid 727775:tid 727929] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/autoload_classmap.php"] [unique_id "amuIjcDCZkc4BvDXnoDPzwAAABg"]
[Thu Jul 30 12:23:25.861551 2026] [security2:error] [pid 727775:tid 727929] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/autoload_classmap.php"] [unique_id "amuIjcDCZkc4BvDXnoDPzwAAABg"]
[Thu Jul 30 12:23:25.877642 2026] [security2:error] [pid 727775:tid 727948] [client 172.213.232.128:22978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/Text/about.php"] [unique_id "amuIjcDCZkc4BvDXnoDP0gAAACs"]
[Thu Jul 30 12:23:25.981081 2026] [security2:error] [pid 727775:tid 727921] [client 123.245.84.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIjcDCZkc4BvDXnoDPyAAAEEs"]
[Thu Jul 30 12:23:26.181283 2026] [security2:error] [pid 727775:tid 727965] [client 142.93.53.183:63754] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/10/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIjsDCZkc4BvDXnoDP2AAAADw"]
[Thu Jul 30 12:23:26.581175 2026] [security2:error] [pid 727775:tid 727937] [client 142.93.53.183:63941] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/10/alfacgiapi/perl.alfa"] [unique_id "amuIjsDCZkc4BvDXnoDP4gAAACA"]
[Thu Jul 30 12:23:26.978296 2026] [security2:error] [pid 727775:tid 727949] [client 142.93.53.183:64134] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/11/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIjsDCZkc4BvDXnoDP6gAAACw"]
[Thu Jul 30 12:23:27.331739 2026] [security2:error] [pid 727775:tid 727941] [client 20.91.199.21:47247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/setup-config.php"] [unique_id "amuIj8DCZkc4BvDXnoDP9wAAACQ"]
[Thu Jul 30 12:23:27.359318 2026] [security2:error] [pid 727775:tid 728008] [client 142.93.53.183:64325] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/11/alfacgiapi/perl.alfa"] [unique_id "amuIj8DCZkc4BvDXnoDP-AAAAGc"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Thu Jul 30 12:23:27.765751 2026] [security2:error] [pid 727775:tid 728002] [client 142.93.53.183:64494] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/12/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIj8DCZkc4BvDXnoDP_gAAAGE"]
[Thu Jul 30 12:23:28.150201 2026] [security2:error] [pid 727775:tid 727948] [client 172.213.232.128:8351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuIkMDCZkc4BvDXnoDQBQAAACs"]
[Thu Jul 30 12:23:28.160886 2026] [security2:error] [pid 727775:tid 727960] [client 142.93.53.183:64729] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/12/alfacgiapi/perl.alfa"] [unique_id "amuIkMDCZkc4BvDXnoDQBgAAADc"]
[Thu Jul 30 12:23:28.396360 2026] [security2:error] [pid 727775:tid 727972] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/wp-content/"] [unique_id "amuIkMDCZkc4BvDXnoDQEQAAAEM"]
[Thu Jul 30 12:23:28.542029 2026] [security2:error] [pid 727775:tid 727938] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-content/themes/index.php"] [unique_id "amuIkMDCZkc4BvDXnoDQFAAAACE"]
[Thu Jul 30 12:23:28.542161 2026] [security2:error] [pid 727775:tid 727938] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-content/themes/index.php"] [unique_id "amuIkMDCZkc4BvDXnoDQFAAAACE"]
[Thu Jul 30 12:23:28.548027 2026] [security2:error] [pid 727775:tid 727970] [client 142.93.53.183:64938] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIkMDCZkc4BvDXnoDQFQAAAEE"]
[Thu Jul 30 12:23:28.774054 2026] [security2:error] [pid 727775:tid 728028] [client 20.91.199.21:47626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/a7.php"] [unique_id "amuIkMDCZkc4BvDXnoDQGwAAAHs"]
[Thu Jul 30 12:23:28.787401 2026] [security2:error] [pid 727775:tid 727965] [client 175.30.48.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIkMDCZkc4BvDXnoDQEwAAPE4"]
[Thu Jul 30 12:23:28.824426 2026] [security2:error] [pid 727775:tid 727905] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/av.php"] [unique_id "amuIkMDCZkc4BvDXnoDQHQAAAAA"]
[Thu Jul 30 12:23:28.824510 2026] [security2:error] [pid 727775:tid 727905] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/av.php"] [unique_id "amuIkMDCZkc4BvDXnoDQHQAAAAA"]
[Thu Jul 30 12:23:28.938168 2026] [security2:error] [pid 727775:tid 727985] [client 142.93.53.183:65132] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/alfacgiapi/perl.alfa"] [unique_id "amuIkMDCZkc4BvDXnoDQIQAAAFA"]
[Thu Jul 30 12:23:29.054804 2026] [core:notice] [pid 727775:tid 727991] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:29.118628 2026] [security2:error] [pid 727775:tid 727975] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/wp-includes/l10n/"] [unique_id "amuIkcDCZkc4BvDXnoDQJAAAAEY"]
[Thu Jul 30 12:23:29.289678 2026] [security2:error] [pid 727775:tid 727959] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/wordpress/wp-admin/maint/"] [unique_id "amuIkcDCZkc4BvDXnoDQKAAAADY"]
[Thu Jul 30 12:23:29.328734 2026] [security2:error] [pid 727775:tid 727989] [client 142.93.53.183:65328] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/ID3/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIkcDCZkc4BvDXnoDQLAAAAFQ"]
[Thu Jul 30 12:23:29.438486 2026] [security2:error] [pid 727775:tid 727906] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/tiny.php"] [unique_id "amuIkcDCZkc4BvDXnoDQMgAAAAE"]
[Thu Jul 30 12:23:29.438577 2026] [security2:error] [pid 727775:tid 727906] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/tiny.php"] [unique_id "amuIkcDCZkc4BvDXnoDQMgAAAAE"]
[Thu Jul 30 12:23:29.642451 2026] [security2:error] [pid 727775:tid 727919] [client 172.202.44.182:55808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/m.php"] [unique_id "amuIkcDCZkc4BvDXnoDQNQAAAA4"]
[Thu Jul 30 12:23:29.674787 2026] [security2:error] [pid 727775:tid 727964] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuIkcDCZkc4BvDXnoDQNwAAADs"]
[Thu Jul 30 12:23:29.674870 2026] [security2:error] [pid 727775:tid 727964] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuIkcDCZkc4BvDXnoDQNwAAADs"]
[Thu Jul 30 12:23:29.727747 2026] [security2:error] [pid 727775:tid 728022] [client 142.93.53.183:49153] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/ID3/alfacgiapi/perl.alfa"] [unique_id "amuIkcDCZkc4BvDXnoDQOAAAAHU"]
[Thu Jul 30 12:23:29.820917 2026] [security2:error] [pid 727775:tid 727925] [client 123.245.84.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIkcDCZkc4BvDXnoDQNAAAFHQ"]
[Thu Jul 30 12:23:29.912165 2026] [security2:error] [pid 727775:tid 727994] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/zrrhj.php"] [unique_id "amuIkcDCZkc4BvDXnoDQQgAAAFk"]
[Thu Jul 30 12:23:29.912263 2026] [security2:error] [pid 727775:tid 727994] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/zrrhj.php"] [unique_id "amuIkcDCZkc4BvDXnoDQQgAAAFk"]
[Thu Jul 30 12:23:29.917232 2026] [security2:error] [pid 727775:tid 727984] [client 20.91.199.21:47638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/f7.php"] [unique_id "amuIkcDCZkc4BvDXnoDQQwAAAE8"]
[Thu Jul 30 12:23:30.089055 2026] [core:error] [pid 727775:tid 727887] [remote 216.73.216.227:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:23:30.089082 2026] [core:error] [pid 727775:tid 727887] [remote 216.73.216.227:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:23:30.112650 2026] [security2:error] [pid 727775:tid 727940] [client 142.93.53.183:49383] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/IXR/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIksDCZkc4BvDXnoDQRQAAACM"]
[Thu Jul 30 12:23:30.181538 2026] [security2:error] [pid 727775:tid 727962] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuIksDCZkc4BvDXnoDQRgAAADk"]
[Thu Jul 30 12:23:30.181650 2026] [security2:error] [pid 727775:tid 727962] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuIksDCZkc4BvDXnoDQRgAAADk"]
[Thu Jul 30 12:23:30.414966 2026] [security2:error] [pid 727775:tid 727957] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wpgum.php"] [unique_id "amuIksDCZkc4BvDXnoDQTgAAADQ"]
[Thu Jul 30 12:23:30.415067 2026] [security2:error] [pid 727775:tid 727957] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wpgum.php"] [unique_id "amuIksDCZkc4BvDXnoDQTgAAADQ"]
[Thu Jul 30 12:23:30.490906 2026] [security2:error] [pid 727775:tid 728004] [client 142.93.53.183:49590] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/IXR/alfacgiapi/perl.alfa"] [unique_id "amuIksDCZkc4BvDXnoDQUAAAAGM"]
[Thu Jul 30 12:23:30.494134 2026] [security2:error] [pid 727775:tid 727956] [client 23.23.214.190:9493] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2017/03/distribuidora-e-interditada-e-mais-de-700-botijoes-de-gas-de-cozinha-sao-apreendidos-em-jp-90x60.png"] [unique_id "amuIksDCZkc4BvDXnoDQUQAAADM"]
[Thu Jul 30 12:23:30.715104 2026] [security2:error] [pid 727775:tid 727910] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/ywwbf.php"] [unique_id "amuIksDCZkc4BvDXnoDQUgAAAAU"]
[Thu Jul 30 12:23:30.715229 2026] [security2:error] [pid 727775:tid 727910] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/ywwbf.php"] [unique_id "amuIksDCZkc4BvDXnoDQUgAAAAU"]
[Thu Jul 30 12:23:30.871004 2026] [security2:error] [pid 727775:tid 727936] [client 142.93.53.183:49767] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/PHPMailer/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIksDCZkc4BvDXnoDQVQAAAB8"]
[Thu Jul 30 12:23:31.060223 2026] [security2:error] [pid 727775:tid 727974] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/xoldj.php"] [unique_id "amuIk8DCZkc4BvDXnoDQXQAAAEU"]
[Thu Jul 30 12:23:31.060343 2026] [security2:error] [pid 727775:tid 727974] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/xoldj.php"] [unique_id "amuIk8DCZkc4BvDXnoDQXQAAAEU"]
[Thu Jul 30 12:23:31.265308 2026] [security2:error] [pid 727775:tid 727991] [client 142.93.53.183:49937] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/PHPMailer/alfacgiapi/perl.alfa"] [unique_id "amuIk8DCZkc4BvDXnoDQYQAAAFY"]
[Thu Jul 30 12:23:31.324460 2026] [security2:error] [pid 727775:tid 727907] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/f35.php"] [unique_id "amuIk8DCZkc4BvDXnoDQYgAAAAI"]
[Thu Jul 30 12:23:31.324591 2026] [security2:error] [pid 727775:tid 727907] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/f35.php"] [unique_id "amuIk8DCZkc4BvDXnoDQYgAAAAI"]
[Thu Jul 30 12:23:31.519929 2026] [security2:error] [pid 727775:tid 728030] [client 172.213.232.128:7391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/img/about.php"] [unique_id "amuIk8DCZkc4BvDXnoDQawAAAH0"]
[Thu Jul 30 12:23:31.558649 2026] [security2:error] [pid 727775:tid 727934] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/gk.php"] [unique_id "amuIk8DCZkc4BvDXnoDQbQAAAB0"]
[Thu Jul 30 12:23:31.558808 2026] [security2:error] [pid 727775:tid 727934] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/gk.php"] [unique_id "amuIk8DCZkc4BvDXnoDQbQAAAB0"]
[Thu Jul 30 12:23:31.647101 2026] [security2:error] [pid 727775:tid 727949] [client 142.93.53.183:50144] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/Requests/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIk8DCZkc4BvDXnoDQbgAAACw"]
[Thu Jul 30 12:23:31.678157 2026] [security2:error] [pid 727775:tid 727930] [client 175.30.48.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIk8DCZkc4BvDXnoDQZAAAGQE"]
[Thu Jul 30 12:23:31.797752 2026] [security2:error] [pid 727775:tid 727946] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/584062352875874akp.php"] [unique_id "amuIk8DCZkc4BvDXnoDQcAAAACk"]
[Thu Jul 30 12:23:31.797886 2026] [security2:error] [pid 727775:tid 727946] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/584062352875874akp.php"] [unique_id "amuIk8DCZkc4BvDXnoDQcAAAACk"]
[Thu Jul 30 12:23:32.065447 2026] [security2:error] [pid 727775:tid 727912] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wper3.php"] [unique_id "amuIlMDCZkc4BvDXnoDQeAAAAAc"]
[Thu Jul 30 12:23:32.065564 2026] [security2:error] [pid 727775:tid 727912] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wper3.php"] [unique_id "amuIlMDCZkc4BvDXnoDQeAAAAAc"]
[Thu Jul 30 12:23:32.156126 2026] [security2:error] [pid 727775:tid 727798] [remote 74.7.241.60:43142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/article.php"] [unique_id "amuIlMDCZkc4BvDXnoDQeQAAMRY"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/1784117929_IMG_3676.jpg
[Thu Jul 30 12:23:32.275765 2026] [security2:error] [pid 727775:tid 727916] [client 172.213.232.128:8362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/languages/about.php"] [unique_id "amuIlMDCZkc4BvDXnoDQegAAAAs"]
[Thu Jul 30 12:23:32.327274 2026] [security2:error] [pid 727775:tid 727967] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/bthil.php"] [unique_id "amuIlMDCZkc4BvDXnoDQfAAAAD4"]
[Thu Jul 30 12:23:32.327395 2026] [security2:error] [pid 727775:tid 727967] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/bthil.php"] [unique_id "amuIlMDCZkc4BvDXnoDQfAAAAD4"]
[Thu Jul 30 12:23:32.386077 2026] [security2:error] [pid 727775:tid 727924] [client 142.93.53.183:50521] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/Requests/alfacgiapi/perl.alfa"] [unique_id "amuIlMDCZkc4BvDXnoDQfQAAABM"]
[Thu Jul 30 12:23:32.561049 2026] [security2:error] [pid 727775:tid 728012] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wyzer1.php"] [unique_id "amuIlMDCZkc4BvDXnoDQhQAAAGs"]
[Thu Jul 30 12:23:32.561179 2026] [security2:error] [pid 727775:tid 728012] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wyzer1.php"] [unique_id "amuIlMDCZkc4BvDXnoDQhQAAAGs"]
[Thu Jul 30 12:23:32.641319 2026] [security2:error] [pid 727775:tid 727927] [client 20.91.199.21:47623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/nw.php"] [unique_id "amuIlMDCZkc4BvDXnoDQhgAAABY"]
[Thu Jul 30 12:23:32.643958 2026] [security2:error] [pid 727775:tid 728005] [client 123.245.84.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIlMDCZkc4BvDXnoDQewAAZHE"]
[Thu Jul 30 12:23:32.796990 2026] [security2:error] [pid 727775:tid 728018] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/mh.php"] [unique_id "amuIlMDCZkc4BvDXnoDQhwAAAHE"]
[Thu Jul 30 12:23:32.797104 2026] [security2:error] [pid 727775:tid 728018] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/mh.php"] [unique_id "amuIlMDCZkc4BvDXnoDQhwAAAHE"]
[Thu Jul 30 12:23:32.811480 2026] [security2:error] [pid 727775:tid 727960] [client 142.93.53.183:50715] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIlMDCZkc4BvDXnoDQiAAAADc"]
[Thu Jul 30 12:23:32.850114 2026] [security2:error] [pid 727775:tid 728003] [client 172.213.232.128:22693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/customize/about.php"] [unique_id "amuIlMDCZkc4BvDXnoDQiQAAAGI"]
[Thu Jul 30 12:23:33.063101 2026] [security2:error] [pid 727775:tid 727938] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuIlcDCZkc4BvDXnoDQkQAAACE"]
[Thu Jul 30 12:23:33.063212 2026] [security2:error] [pid 727775:tid 727938] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuIlcDCZkc4BvDXnoDQkQAAACE"]
[Thu Jul 30 12:23:33.192460 2026] [security2:error] [pid 727775:tid 728011] [client 142.93.53.183:50939] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/alfacgiapi/perl.alfa"] [unique_id "amuIlcDCZkc4BvDXnoDQkwAAAGo"]
[Thu Jul 30 12:23:33.321897 2026] [security2:error] [pid 727775:tid 728000] [client 158.158.45.59:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/1.php"] [unique_id "amuIlcDCZkc4BvDXnoDQlAAAAF8"]
[Thu Jul 30 12:23:33.322039 2026] [security2:error] [pid 727775:tid 728000] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/1.php"] [unique_id "amuIlcDCZkc4BvDXnoDQlAAAAF8"]
[Thu Jul 30 12:23:33.322156 2026] [security2:error] [pid 727775:tid 728000] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/1.php"] [unique_id "amuIlcDCZkc4BvDXnoDQlAAAAF8"]
[Thu Jul 30 12:23:33.428021 2026] [security2:error] [pid 727775:tid 727928] [client 172.213.232.128:22281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes.bak/html-api/about.php"] [unique_id "amuIlcDCZkc4BvDXnoDQlgAAABc"]
[Thu Jul 30 12:23:33.575489 2026] [security2:error] [pid 727775:tid 727937] [client 142.93.53.183:51130] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/Cache/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIlcDCZkc4BvDXnoDQnAAAACA"]
[Thu Jul 30 12:23:33.575658 2026] [security2:error] [pid 727775:tid 727978] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/chosen.php"] [unique_id "amuIlcDCZkc4BvDXnoDQmwAAAEk"]
[Thu Jul 30 12:23:33.575761 2026] [security2:error] [pid 727775:tid 727978] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/chosen.php"] [unique_id "amuIlcDCZkc4BvDXnoDQmwAAAEk"]
[Thu Jul 30 12:23:33.845162 2026] [security2:error] [pid 727775:tid 728027] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/sd.php"] [unique_id "amuIlcDCZkc4BvDXnoDQnwAAAHo"]
[Thu Jul 30 12:23:33.845282 2026] [security2:error] [pid 727775:tid 728027] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/sd.php"] [unique_id "amuIlcDCZkc4BvDXnoDQnwAAAHo"]
[Thu Jul 30 12:23:33.964832 2026] [security2:error] [pid 727775:tid 727951] [client 142.93.53.183:51330] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/Cache/alfacgiapi/perl.alfa"] [unique_id "amuIlcDCZkc4BvDXnoDQoQAAAC4"]
[Thu Jul 30 12:23:34.080184 2026] [security2:error] [pid 727775:tid 727906] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/z60.php"] [unique_id "amuIlsDCZkc4BvDXnoDQpQAAAAE"]
[Thu Jul 30 12:23:34.080284 2026] [security2:error] [pid 727775:tid 727906] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/z60.php"] [unique_id "amuIlsDCZkc4BvDXnoDQpQAAAAE"]
[Thu Jul 30 12:23:34.129322 2026] [security2:error] [pid 727775:tid 727943] [client 172.213.232.128:22717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/widgets/about.php"] [unique_id "amuIlsDCZkc4BvDXnoDQqQAAACY"]
[Thu Jul 30 12:23:34.344030 2026] [security2:error] [pid 727775:tid 727941] [client 142.93.53.183:51548] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/Content/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIlsDCZkc4BvDXnoDQqwAAACQ"]
[Thu Jul 30 12:23:34.359063 2026] [security2:error] [pid 727775:tid 727933] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/home.php"] [unique_id "amuIlsDCZkc4BvDXnoDQrAAAABw"]
[Thu Jul 30 12:23:34.359206 2026] [security2:error] [pid 727775:tid 727933] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/home.php"] [unique_id "amuIlsDCZkc4BvDXnoDQrAAAABw"]
[Thu Jul 30 12:23:34.525757 2026] [security2:error] [pid 727775:tid 727934] [client 175.30.48.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIlsDCZkc4BvDXnoDQqgAAHQw"]
[Thu Jul 30 12:23:34.601342 2026] [security2:error] [pid 727775:tid 727998] [client 20.91.199.21:47280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/ova.php"] [unique_id "amuIlsDCZkc4BvDXnoDQrQAAAF0"]
[Thu Jul 30 12:23:34.610791 2026] [security2:error] [pid 727775:tid 727950] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/ws58.php"] [unique_id "amuIlsDCZkc4BvDXnoDQsAAAAC0"]
[Thu Jul 30 12:23:34.610871 2026] [security2:error] [pid 727775:tid 727950] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/ws58.php"] [unique_id "amuIlsDCZkc4BvDXnoDQsAAAAC0"]
[Thu Jul 30 12:23:34.720875 2026] [security2:error] [pid 727775:tid 727983] [client 142.93.53.183:51732] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/Content/alfacgiapi/perl.alfa"] [unique_id "amuIlsDCZkc4BvDXnoDQtgAAAE4"]
[Thu Jul 30 12:23:34.748456 2026] [security2:error] [pid 727775:tid 727925] [client 172.213.232.128:7379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/IXR/about.php"] [unique_id "amuIlsDCZkc4BvDXnoDQtwAAABQ"]
[Thu Jul 30 12:23:34.847627 2026] [security2:error] [pid 727775:tid 728021] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/gulu.php"] [unique_id "amuIlsDCZkc4BvDXnoDQuQAAAHQ"]
[Thu Jul 30 12:23:34.847719 2026] [security2:error] [pid 727775:tid 728021] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/gulu.php"] [unique_id "amuIlsDCZkc4BvDXnoDQuQAAAHQ"]
[Thu Jul 30 12:23:35.102461 2026] [security2:error] [pid 727775:tid 727996] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuIl8DCZkc4BvDXnoDQugAAAFs"]
[Thu Jul 30 12:23:35.102598 2026] [security2:error] [pid 727775:tid 727996] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuIl8DCZkc4BvDXnoDQugAAAFs"]
[Thu Jul 30 12:23:35.103856 2026] [security2:error] [pid 727775:tid 727948] [client 142.93.53.183:51926] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/Content/Type/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIl8DCZkc4BvDXnoDQuwAAACs"]
[Thu Jul 30 12:23:35.335390 2026] [security2:error] [pid 727775:tid 727908] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wpls.php"] [unique_id "amuIl8DCZkc4BvDXnoDQxAAAAAM"]
[Thu Jul 30 12:23:35.335532 2026] [security2:error] [pid 727775:tid 727908] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wpls.php"] [unique_id "amuIl8DCZkc4BvDXnoDQxAAAAAM"]
[Thu Jul 30 12:23:35.493949 2026] [security2:error] [pid 727775:tid 727955] [client 142.93.53.183:52126] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/Content/Type/alfacgiapi/perl.alfa"] [unique_id "amuIl8DCZkc4BvDXnoDQxgAAADI"]
[Thu Jul 30 12:23:35.496214 2026] [security2:error] [pid 727775:tid 727988] [client 123.245.84.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIl8DCZkc4BvDXnoDQwQAAUxQ"]
[Thu Jul 30 12:23:35.506684 2026] [security2:error] [pid 727775:tid 727963] [client 172.202.44.182:52768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuIl8DCZkc4BvDXnoDQwwAAADo"]
[Thu Jul 30 12:23:35.574252 2026] [security2:error] [pid 727775:tid 727938] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/php.php"] [unique_id "amuIl8DCZkc4BvDXnoDQyAAAACE"]
[Thu Jul 30 12:23:35.574408 2026] [security2:error] [pid 727775:tid 727938] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/php.php"] [unique_id "amuIl8DCZkc4BvDXnoDQyAAAACE"]
[Thu Jul 30 12:23:35.724378 2026] [security2:error] [pid 727775:tid 727962] [client 20.91.199.21:47625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/robots.php"] [unique_id "amuIl8DCZkc4BvDXnoDQ0AAAADk"]
[Thu Jul 30 12:23:35.882898 2026] [security2:error] [pid 727775:tid 727937] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/100.php"] [unique_id "amuIl8DCZkc4BvDXnoDQ1QAAACA"]
[Thu Jul 30 12:23:35.883034 2026] [security2:error] [pid 727775:tid 727937] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/100.php"] [unique_id "amuIl8DCZkc4BvDXnoDQ1QAAACA"]
[Thu Jul 30 12:23:35.883409 2026] [security2:error] [pid 727775:tid 727978] [client 142.93.53.183:52324] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/Decode/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIl8DCZkc4BvDXnoDQ1gAAAEk"]
[Thu Jul 30 12:23:36.120480 2026] [security2:error] [pid 727775:tid 727931] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/BDKR28WP.php"] [unique_id "amuImMDCZkc4BvDXnoDQ1wAAABo"]
[Thu Jul 30 12:23:36.120595 2026] [security2:error] [pid 727775:tid 727931] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/BDKR28WP.php"] [unique_id "amuImMDCZkc4BvDXnoDQ1wAAABo"]
[Thu Jul 30 12:23:36.258810 2026] [core:notice] [pid 727775:tid 728014] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:36.281309 2026] [security2:error] [pid 727775:tid 727951] [client 142.93.53.183:52509] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/Decode/alfacgiapi/perl.alfa"] [unique_id "amuImMDCZkc4BvDXnoDQ4AAAAC4"]
[Thu Jul 30 12:23:36.372062 2026] [security2:error] [pid 727775:tid 727999] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/browse.php"] [unique_id "amuImMDCZkc4BvDXnoDQ4gAAAF4"]
[Thu Jul 30 12:23:36.372170 2026] [security2:error] [pid 727775:tid 727999] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/browse.php"] [unique_id "amuImMDCZkc4BvDXnoDQ4gAAAF4"]
[Thu Jul 30 12:23:36.636102 2026] [security2:error] [pid 727775:tid 727946] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-good.php"] [unique_id "amuImMDCZkc4BvDXnoDQ5gAAACk"]
[Thu Jul 30 12:23:36.636273 2026] [security2:error] [pid 727775:tid 727946] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-good.php"] [unique_id "amuImMDCZkc4BvDXnoDQ5gAAACk"]
[Thu Jul 30 12:23:36.677289 2026] [security2:error] [pid 727775:tid 727930] [client 142.93.53.183:52690] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/Decode/HTML/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuImMDCZkc4BvDXnoDQ6gAAABk"]
[Thu Jul 30 12:23:36.736472 2026] [security2:error] [pid 727775:tid 727906] [client 172.213.232.128:4176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/js/about.php"] [unique_id "amuImMDCZkc4BvDXnoDQ7QAAAAE"]
[Thu Jul 30 12:23:36.894534 2026] [security2:error] [pid 727775:tid 727973] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/8573.php"] [unique_id "amuImMDCZkc4BvDXnoDQ7wAAAEQ"]
[Thu Jul 30 12:23:36.894640 2026] [security2:error] [pid 727775:tid 727973] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/8573.php"] [unique_id "amuImMDCZkc4BvDXnoDQ7wAAAEQ"]
[Thu Jul 30 12:23:37.078101 2026] [security2:error] [pid 727775:tid 727922] [client 142.93.53.183:52896] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/Decode/HTML/alfacgiapi/perl.alfa"] [unique_id "amuImcDCZkc4BvDXnoDQ8wAAABE"]
[Thu Jul 30 12:23:37.148150 2026] [security2:error] [pid 727775:tid 727967] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-admin/install.php"] [unique_id "amuImcDCZkc4BvDXnoDQ9AAAAD4"]
[Thu Jul 30 12:23:37.148267 2026] [security2:error] [pid 727775:tid 727967] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-admin/install.php"] [unique_id "amuImcDCZkc4BvDXnoDQ9AAAAD4"]
[Thu Jul 30 12:23:37.381116 2026] [security2:error] [pid 727775:tid 727920] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/classwithtostring.php"] [unique_id "amuImcDCZkc4BvDXnoDQ-wAAAA8"]
[Thu Jul 30 12:23:37.381233 2026] [security2:error] [pid 727775:tid 727920] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/classwithtostring.php"] [unique_id "amuImcDCZkc4BvDXnoDQ-wAAAA8"]
[Thu Jul 30 12:23:37.461261 2026] [security2:error] [pid 727775:tid 727984] [client 142.93.53.183:53073] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/HTTP/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuImcDCZkc4BvDXnoDQ_AAAAE8"]
[Thu Jul 30 12:23:37.614859 2026] [security2:error] [pid 727775:tid 727921] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/ohct.php"] [unique_id "amuImcDCZkc4BvDXnoDRAAAAABA"]
[Thu Jul 30 12:23:37.614967 2026] [security2:error] [pid 727775:tid 727921] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/ohct.php"] [unique_id "amuImcDCZkc4BvDXnoDRAAAAABA"]
[Thu Jul 30 12:23:37.641205 2026] [security2:error] [pid 727775:tid 727949] [client 43.166.247.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuImMDCZkc4BvDXnoDQ5QAAACw"]
[Thu Jul 30 12:23:37.643042 2026] [security2:error] [pid 727775:tid 727950] [client 20.91.199.21:47290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/alf.php"] [unique_id "amuImcDCZkc4BvDXnoDRAgAAAC0"]
[Thu Jul 30 12:23:37.714413 2026] [security2:error] [pid 727775:tid 728018] [client 172.213.232.128:4576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amuImcDCZkc4BvDXnoDRBwAAAHE"]
[Thu Jul 30 12:23:37.935045 2026] [security2:error] [pid 727775:tid 727910] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/bless.php"] [unique_id "amuImcDCZkc4BvDXnoDRDAAAAAU"]
[Thu Jul 30 12:23:37.935174 2026] [security2:error] [pid 727775:tid 727910] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/bless.php"] [unique_id "amuImcDCZkc4BvDXnoDRDAAAAAU"]
[Thu Jul 30 12:23:37.937454 2026] [security2:error] [pid 727775:tid 728028] [client 142.93.53.183:53285] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/HTTP/alfacgiapi/perl.alfa"] [unique_id "amuImcDCZkc4BvDXnoDRDQAAAHs"]
[Thu Jul 30 12:23:38.170504 2026] [security2:error] [pid 727775:tid 727944] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/about.php"] [unique_id "amuImsDCZkc4BvDXnoDRDgAAACc"]
[Thu Jul 30 12:23:38.170618 2026] [security2:error] [pid 727775:tid 727944] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/about.php"] [unique_id "amuImsDCZkc4BvDXnoDRDgAAACc"]
[Thu Jul 30 12:23:38.314647 2026] [security2:error] [pid 727775:tid 727911] [client 142.93.53.183:53450] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/Net/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuImsDCZkc4BvDXnoDRFQAAAAY"]
[Thu Jul 30 12:23:38.376306 2026] [security2:error] [pid 727775:tid 727965] [client 20.91.199.21:47292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/feedback.php"] [unique_id "amuImsDCZkc4BvDXnoDRFgAAADw"]
[Thu Jul 30 12:23:38.401762 2026] [security2:error] [pid 727775:tid 727905] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuImsDCZkc4BvDXnoDRFwAAAAA"]
[Thu Jul 30 12:23:38.401878 2026] [security2:error] [pid 727775:tid 727905] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuImsDCZkc4BvDXnoDRFwAAAAA"]
[Thu Jul 30 12:23:38.613888 2026] [security2:error] [pid 727775:tid 728032] [client 172.213.232.128:15557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/pomo/about.php"] [unique_id "amuImsDCZkc4BvDXnoDRGAAAAH8"]
[Thu Jul 30 12:23:38.639328 2026] [security2:error] [pid 727775:tid 728025] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/ta0ol.php"] [unique_id "amuImsDCZkc4BvDXnoDRGQAAAHg"]
[Thu Jul 30 12:23:38.639449 2026] [security2:error] [pid 727775:tid 728025] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/ta0ol.php"] [unique_id "amuImsDCZkc4BvDXnoDRGQAAAHg"]
[Thu Jul 30 12:23:38.717512 2026] [security2:error] [pid 727775:tid 727918] [client 142.93.53.183:53607] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/Net/alfacgiapi/perl.alfa"] [unique_id "amuImsDCZkc4BvDXnoDRGgAAAA0"]
[Thu Jul 30 12:23:38.875689 2026] [security2:error] [pid 727775:tid 727999] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/sa.php7"] [unique_id "amuImsDCZkc4BvDXnoDRIQAAAF4"]
[Thu Jul 30 12:23:38.875770 2026] [security2:error] [pid 727775:tid 727999] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/sa.php7"] [unique_id "amuImsDCZkc4BvDXnoDRIQAAAF4"]
[Thu Jul 30 12:23:39.095596 2026] [security2:error] [pid 727775:tid 727971] [client 142.93.53.183:53780] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/Parse/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIm8DCZkc4BvDXnoDRIgAAAEI"]
[Thu Jul 30 12:23:39.134805 2026] [security2:error] [pid 727775:tid 728016] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-class.php"] [unique_id "amuIm8DCZkc4BvDXnoDRIwAAAG8"]
[Thu Jul 30 12:23:39.134908 2026] [security2:error] [pid 727775:tid 728016] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-class.php"] [unique_id "amuIm8DCZkc4BvDXnoDRIwAAAG8"]
[Thu Jul 30 12:23:39.311429 2026] [security2:error] [pid 727775:tid 727995] [client 172.213.232.128:4183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/block-patterns/about.php"] [unique_id "amuIm8DCZkc4BvDXnoDRJgAAAFo"]
[Thu Jul 30 12:23:39.401764 2026] [security2:error] [pid 727775:tid 728006] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/8.php"] [unique_id "amuIm8DCZkc4BvDXnoDRLwAAAGU"]
[Thu Jul 30 12:23:39.401863 2026] [security2:error] [pid 727775:tid 728006] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/8.php"] [unique_id "amuIm8DCZkc4BvDXnoDRLwAAAGU"]
[Thu Jul 30 12:23:39.475214 2026] [security2:error] [pid 727775:tid 727967] [client 142.93.53.183:53923] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/Parse/alfacgiapi/perl.alfa"] [unique_id "amuIm8DCZkc4BvDXnoDRMAAAAD4"]
[Thu Jul 30 12:23:39.637000 2026] [security2:error] [pid 727775:tid 728010] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/bootstrap.php"] [unique_id "amuIm8DCZkc4BvDXnoDRNwAAAGk"]
[Thu Jul 30 12:23:39.637091 2026] [security2:error] [pid 727775:tid 728010] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/bootstrap.php"] [unique_id "amuIm8DCZkc4BvDXnoDRNwAAAGk"]
[Thu Jul 30 12:23:39.859157 2026] [security2:error] [pid 727775:tid 727996] [client 142.93.53.183:54078] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/XML/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIm8DCZkc4BvDXnoDROQAAAFs"]
[Thu Jul 30 12:23:40.240457 2026] [security2:error] [pid 727775:tid 727956] [client 142.93.53.183:54245] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/XML/alfacgiapi/perl.alfa"] [unique_id "amuInMDCZkc4BvDXnoDRQwAAADM"]
[Thu Jul 30 12:23:40.270872 2026] [security2:error] [pid 727775:tid 727986] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-blog-header.php"] [unique_id "amuInMDCZkc4BvDXnoDRRAAAAFE"]
[Thu Jul 30 12:23:40.270987 2026] [security2:error] [pid 727775:tid 727986] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-blog-header.php"] [unique_id "amuInMDCZkc4BvDXnoDRRAAAAFE"]
[Thu Jul 30 12:23:40.295433 2026] [security2:error] [pid 727775:tid 728018] [client 172.202.44.182:53167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/classwithtostring.php"] [unique_id "amuInMDCZkc4BvDXnoDRRQAAAHE"]
[Thu Jul 30 12:23:40.503092 2026] [security2:error] [pid 727775:tid 728001] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/aa.php"] [unique_id "amuInMDCZkc4BvDXnoDRTQAAAGA"]
[Thu Jul 30 12:23:40.503203 2026] [security2:error] [pid 727775:tid 728001] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/aa.php"] [unique_id "amuInMDCZkc4BvDXnoDRTQAAAGA"]
[Thu Jul 30 12:23:40.653776 2026] [security2:error] [pid 727775:tid 727913] [client 142.93.53.183:54426] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/Text/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuInMDCZkc4BvDXnoDRTwAAAAg"]
[Thu Jul 30 12:23:40.744672 2026] [security2:error] [pid 727775:tid 727940] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/tx79.php"] [unique_id "amuInMDCZkc4BvDXnoDRUAAAACM"]
[Thu Jul 30 12:23:40.744821 2026] [security2:error] [pid 727775:tid 727940] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/tx79.php"] [unique_id "amuInMDCZkc4BvDXnoDRUAAAACM"]
[Thu Jul 30 12:23:40.978657 2026] [security2:error] [pid 727775:tid 727978] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/motu.php"] [unique_id "amuInMDCZkc4BvDXnoDRVQAAAEk"]
[Thu Jul 30 12:23:40.978756 2026] [security2:error] [pid 727775:tid 727978] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/motu.php"] [unique_id "amuInMDCZkc4BvDXnoDRVQAAAEk"]
[Thu Jul 30 12:23:41.046169 2026] [security2:error] [pid 727775:tid 727965] [client 142.93.53.183:54591] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/Text/alfacgiapi/perl.alfa"] [unique_id "amuIncDCZkc4BvDXnoDRWQAAADw"]
[Thu Jul 30 12:23:41.212925 2026] [security2:error] [pid 727775:tid 727918] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-head.php"] [unique_id "amuIncDCZkc4BvDXnoDRWwAAAA0"]
[Thu Jul 30 12:23:41.213042 2026] [security2:error] [pid 727775:tid 727918] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-head.php"] [unique_id "amuIncDCZkc4BvDXnoDRWwAAAA0"]
[Thu Jul 30 12:23:41.281040 2026] [security2:error] [pid 727775:tid 727952] [client 20.91.199.21:47282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/gettest.php"] [unique_id "amuIncDCZkc4BvDXnoDRXAAAAC8"]
[Thu Jul 30 12:23:41.439345 2026] [security2:error] [pid 727775:tid 727914] [client 142.93.53.183:54745] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/Text/Diff/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIncDCZkc4BvDXnoDRXQAAAAk"]
[Thu Jul 30 12:23:41.449822 2026] [security2:error] [pid 727775:tid 728027] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuIncDCZkc4BvDXnoDRXgAAAHo"]
[Thu Jul 30 12:23:41.449907 2026] [security2:error] [pid 727775:tid 728027] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuIncDCZkc4BvDXnoDRXgAAAHo"]
[Thu Jul 30 12:23:41.645719 2026] [security2:error] [pid 727775:tid 728025] [client 172.202.44.182:53179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/gmo.php"] [unique_id "amuIncDCZkc4BvDXnoDRZQAAAHg"]
[Thu Jul 30 12:23:41.680653 2026] [security2:error] [pid 727775:tid 727995] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/60856e3a4findex.php"] [unique_id "amuIncDCZkc4BvDXnoDRZgAAAFo"]
[Thu Jul 30 12:23:41.680748 2026] [security2:error] [pid 727775:tid 727995] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/60856e3a4findex.php"] [unique_id "amuIncDCZkc4BvDXnoDRZgAAAFo"]
[Thu Jul 30 12:23:41.819169 2026] [security2:error] [pid 727775:tid 727964] [client 142.93.53.183:54899] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/Text/Diff/alfacgiapi/perl.alfa"] [unique_id "amuIncDCZkc4BvDXnoDRZwAAADs"]
[Thu Jul 30 12:23:41.919027 2026] [security2:error] [pid 727775:tid 728008] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-the.php"] [unique_id "amuIncDCZkc4BvDXnoDRaAAAAGc"]
[Thu Jul 30 12:23:41.919138 2026] [security2:error] [pid 727775:tid 728008] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-the.php"] [unique_id "amuIncDCZkc4BvDXnoDRaAAAAGc"]
[Thu Jul 30 12:23:42.150974 2026] [security2:error] [pid 727775:tid 727930] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp.php"] [unique_id "amuInsDCZkc4BvDXnoDRcAAAABk"]
[Thu Jul 30 12:23:42.151099 2026] [security2:error] [pid 727775:tid 727930] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp.php"] [unique_id "amuInsDCZkc4BvDXnoDRcAAAABk"]
[Thu Jul 30 12:23:42.219202 2026] [security2:error] [pid 727775:tid 728015] [client 142.93.53.183:55074] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/Text/Diff/Engine/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuInsDCZkc4BvDXnoDRcgAAAG4"]
[Thu Jul 30 12:23:42.231595 2026] [security2:error] [pid 727775:tid 727919] [client 38.190.144.4:56620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuInsDCZkc4BvDXnoDRcwAAAA4"]
[Thu Jul 30 12:23:42.231713 2026] [security2:error] [pid 727775:tid 727919] [client 38.190.144.4:56620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuInsDCZkc4BvDXnoDRcwAAAA4"]
[Thu Jul 30 12:23:42.357139 2026] [security2:error] [pid 727775:tid 727924] [client 20.91.199.21:47232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/maint.php"] [unique_id "amuInsDCZkc4BvDXnoDRdAAAABM"]
[Thu Jul 30 12:23:42.385412 2026] [security2:error] [pid 727775:tid 728010] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/users.php"] [unique_id "amuInsDCZkc4BvDXnoDRdQAAAGk"]
[Thu Jul 30 12:23:42.385528 2026] [security2:error] [pid 727775:tid 728010] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/users.php"] [unique_id "amuInsDCZkc4BvDXnoDRdQAAAGk"]
[Thu Jul 30 12:23:42.611232 2026] [security2:error] [pid 727775:tid 727927] [client 142.93.53.183:55253] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/Text/Diff/Engine/alfacgiapi/perl.alfa"] [unique_id "amuInsDCZkc4BvDXnoDRfAAAABY"]
[Thu Jul 30 12:23:42.618422 2026] [security2:error] [pid 727775:tid 727948] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/tinysd.php"] [unique_id "amuInsDCZkc4BvDXnoDRfQAAACs"]
[Thu Jul 30 12:23:42.618546 2026] [security2:error] [pid 727775:tid 727948] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/tinysd.php"] [unique_id "amuInsDCZkc4BvDXnoDRfQAAACs"]
[Thu Jul 30 12:23:42.865792 2026] [security2:error] [pid 727775:tid 727977] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/ws78.php"] [unique_id "amuInsDCZkc4BvDXnoDRfgAAAEg"]
[Thu Jul 30 12:23:42.865907 2026] [security2:error] [pid 727775:tid 727977] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/ws78.php"] [unique_id "amuInsDCZkc4BvDXnoDRfgAAAEg"]
[Thu Jul 30 12:23:42.877900 2026] [security2:error] [pid 727775:tid 727921] [client 172.202.44.182:52793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/wp-content/languages/index.php"] [unique_id "amuInsDCZkc4BvDXnoDRfwAAABA"]
[Thu Jul 30 12:23:43.021039 2026] [security2:error] [pid 727775:tid 728026] [client 142.93.53.183:55421] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/Text/Diff/Renderer/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIn8DCZkc4BvDXnoDRgAAAAHk"]
[Thu Jul 30 12:23:43.072656 2026] [security2:error] [pid 727775:tid 727925] [client 20.91.199.21:46724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/files.php"] [unique_id "amuIn8DCZkc4BvDXnoDRhAAAABQ"]
[Thu Jul 30 12:23:43.101353 2026] [security2:error] [pid 727775:tid 728003] [client 172.213.232.128:22313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/updraft/about.php"] [unique_id "amuIn8DCZkc4BvDXnoDRhQAAAGI"]
[Thu Jul 30 12:23:43.136563 2026] [security2:error] [pid 727775:tid 727938] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/elp.php"] [unique_id "amuIn8DCZkc4BvDXnoDRhgAAACE"]
[Thu Jul 30 12:23:43.136686 2026] [security2:error] [pid 727775:tid 727938] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/elp.php"] [unique_id "amuIn8DCZkc4BvDXnoDRhgAAACE"]
[Thu Jul 30 12:23:43.406336 2026] [security2:error] [pid 727775:tid 727940] [client 142.93.53.183:55589] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/Text/Diff/Renderer/alfacgiapi/perl.alfa"] [unique_id "amuIn8DCZkc4BvDXnoDRigAAACM"]
[Thu Jul 30 12:23:43.430423 2026] [security2:error] [pid 727775:tid 727944] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/atomlib.php"] [unique_id "amuIn8DCZkc4BvDXnoDRiwAAACc"]
[Thu Jul 30 12:23:43.430540 2026] [security2:error] [pid 727775:tid 727944] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/atomlib.php"] [unique_id "amuIn8DCZkc4BvDXnoDRiwAAACc"]
[Thu Jul 30 12:23:43.686348 2026] [security2:error] [pid 727775:tid 727931] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wyzer3.php"] [unique_id "amuIn8DCZkc4BvDXnoDRmQAAABo"]
[Thu Jul 30 12:23:43.686426 2026] [security2:error] [pid 727775:tid 727931] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wyzer3.php"] [unique_id "amuIn8DCZkc4BvDXnoDRmQAAABo"]
[Thu Jul 30 12:23:43.797235 2026] [security2:error] [pid 727775:tid 727918] [client 142.93.53.183:55750] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/assets/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIn8DCZkc4BvDXnoDRnQAAAA0"]
[Thu Jul 30 12:23:43.923095 2026] [security2:error] [pid 727775:tid 727914] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/max.php"] [unique_id "amuIn8DCZkc4BvDXnoDRnwAAAAk"]
[Thu Jul 30 12:23:43.923207 2026] [security2:error] [pid 727775:tid 727914] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/max.php"] [unique_id "amuIn8DCZkc4BvDXnoDRnwAAAAk"]
[Thu Jul 30 12:23:43.963404 2026] [security2:error] [pid 727775:tid 727966] [client 172.237.109.114:27453] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.env.backup"] [unique_id "amuIn8DCZkc4BvDXnoDRoQAAAD0"]
[Thu Jul 30 12:23:43.974579 2026] [security2:error] [pid 727775:tid 727997] [client 172.237.109.114:49465] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.env"] [unique_id "amuIn8DCZkc4BvDXnoDRpQAAAFw"]
[Thu Jul 30 12:23:43.993541 2026] [security2:error] [pid 727775:tid 728029] [client 172.237.109.114:33213] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.env.bak"] [unique_id "amuIn8DCZkc4BvDXnoDRrAAAAHw"]
[Thu Jul 30 12:23:44.011828 2026] [security2:error] [pid 727775:tid 727906] [client 172.237.109.114:11779] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.env.old"] [unique_id "amuIoMDCZkc4BvDXnoDRrwAAAAE"]
[Thu Jul 30 12:23:44.135264 2026] [security2:error] [pid 727775:tid 727985] [client 172.202.44.182:53150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/wp-the.php"] [unique_id "amuIoMDCZkc4BvDXnoDRuAAAAFA"]
[Thu Jul 30 12:23:44.161829 2026] [security2:error] [pid 727775:tid 727968] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/ftde.php"] [unique_id "amuIoMDCZkc4BvDXnoDRuwAAAD8"]
[Thu Jul 30 12:23:44.161987 2026] [security2:error] [pid 727775:tid 727968] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/ftde.php"] [unique_id "amuIoMDCZkc4BvDXnoDRuwAAAD8"]
[Thu Jul 30 12:23:44.193110 2026] [security2:error] [pid 727775:tid 727992] [client 142.93.53.183:55924] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/assets/alfacgiapi/perl.alfa"] [unique_id "amuIoMDCZkc4BvDXnoDRvQAAAFc"]
[Thu Jul 30 12:23:44.235475 2026] [security2:error] [pid 727775:tid 728011] [client 57.141.0.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuIn8DCZkc4BvDXnoDRjwAAAGo"]
[Thu Jul 30 12:23:44.579651 2026] [security2:error] [pid 727775:tid 728012] [client 142.93.53.183:56104] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/block-patterns/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIoMDCZkc4BvDXnoDRwQAAAGs"]
[Thu Jul 30 12:23:44.585133 2026] [core:notice] [pid 727775:tid 727844] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:44.688756 2026] [security2:error] [pid 727775:tid 728007] [client 172.213.232.128:15579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "amuIoMDCZkc4BvDXnoDRyAAAAGY"]
[Thu Jul 30 12:23:44.956419 2026] [security2:error] [pid 727775:tid 727938] [client 142.93.53.183:56297] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/block-patterns/alfacgiapi/perl.alfa"] [unique_id "amuIoMDCZkc4BvDXnoDRygAAACE"]
[Thu Jul 30 12:23:45.080867 2026] [security2:error] [pid 727775:tid 728020] [client 20.91.199.21:46760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/gecko.php"] [unique_id "amuIocDCZkc4BvDXnoDRywAAAHM"]
[Thu Jul 30 12:23:45.333711 2026] [security2:error] [pid 727775:tid 727991] [client 172.237.109.114:31797] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIn8DCZkc4BvDXnoDRowAAAFY"]
[Thu Jul 30 12:23:45.337577 2026] [security2:error] [pid 727775:tid 728014] [client 172.237.109.114:15072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIn8DCZkc4BvDXnoDRogAAAG0"]
[Thu Jul 30 12:23:45.345642 2026] [security2:error] [pid 727775:tid 728009] [client 172.237.109.114:1721] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIn8DCZkc4BvDXnoDRpgAAAGg"]
[Thu Jul 30 12:23:45.345764 2026] [security2:error] [pid 727775:tid 727928] [client 142.93.53.183:56472] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/block-supports/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIocDCZkc4BvDXnoDR1AAAABc"]
[Thu Jul 30 12:23:45.348100 2026] [security2:error] [pid 727775:tid 728027] [client 172.237.109.114:35325] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIn8DCZkc4BvDXnoDRoAAAAHo"]
[Thu Jul 30 12:23:45.350854 2026] [security2:error] [pid 727775:tid 727959] [client 172.237.109.114:46760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIn8DCZkc4BvDXnoDRpwAAADY"]
[Thu Jul 30 12:23:45.358541 2026] [security2:error] [pid 727775:tid 728016] [client 172.237.109.114:7270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIn8DCZkc4BvDXnoDRqQAAAG8"]
[Thu Jul 30 12:23:45.364643 2026] [security2:error] [pid 727775:tid 727999] [client 172.237.109.114:50626] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIn8DCZkc4BvDXnoDRpAAAAF4"]
[Thu Jul 30 12:23:45.371359 2026] [security2:error] [pid 727775:tid 727936] [client 172.237.109.114:53708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIn8DCZkc4BvDXnoDRqAAAAB8"]
[Thu Jul 30 12:23:45.374885 2026] [security2:error] [pid 727775:tid 727953] [client 172.237.109.114:15664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIn8DCZkc4BvDXnoDRqwAAADA"]
[Thu Jul 30 12:23:45.376132 2026] [security2:error] [pid 727775:tid 727982] [client 172.237.109.114:2287] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIoMDCZkc4BvDXnoDRsQAAAE0"]
[Thu Jul 30 12:23:45.378202 2026] [security2:error] [pid 727775:tid 727951] [client 172.237.109.114:56722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIn8DCZkc4BvDXnoDRqgAAAC4"]
[Thu Jul 30 12:23:45.379525 2026] [security2:error] [pid 727775:tid 728008] [client 172.237.109.114:64240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIoMDCZkc4BvDXnoDRsgAAAGc"]
[Thu Jul 30 12:23:45.379757 2026] [security2:error] [pid 727775:tid 727964] [client 172.237.109.114:35237] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIoMDCZkc4BvDXnoDRsAAAADs"]
[Thu Jul 30 12:23:45.380016 2026] [security2:error] [pid 727775:tid 728025] [client 172.237.109.114:27337] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIn8DCZkc4BvDXnoDRrQAAAHg"]
[Thu Jul 30 12:23:45.393621 2026] [security2:error] [pid 727775:tid 727995] [client 172.237.109.114:51352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIoMDCZkc4BvDXnoDRrgAAAFo"]
[Thu Jul 30 12:23:45.395065 2026] [security2:error] [pid 727775:tid 728013] [client 172.237.109.114:24801] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIoMDCZkc4BvDXnoDRswAAAGw"]
[Thu Jul 30 12:23:45.751564 2026] [security2:error] [pid 727775:tid 727967] [client 142.93.53.183:56645] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/block-supports/alfacgiapi/perl.alfa"] [unique_id "amuIocDCZkc4BvDXnoDR3AAAAD4"]
[Thu Jul 30 12:23:45.929633 2026] [security2:error] [pid 727775:tid 727981] [client 172.213.232.128:9874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/themes/about.php"] [unique_id "amuIocDCZkc4BvDXnoDR4wAAAEw"]
[Thu Jul 30 12:23:46.001232 2026] [core:notice] [pid 727775:tid 727993] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:46.058447 2026] [security2:error] [pid 727775:tid 727945] [client 57.141.0.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuIocDCZkc4BvDXnoDR2AAAACg"]
[Thu Jul 30 12:23:46.138088 2026] [security2:error] [pid 727775:tid 727970] [client 142.93.53.183:56812] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIosDCZkc4BvDXnoDR5QAAAEE"]
[Thu Jul 30 12:23:46.445324 2026] [security2:error] [pid 727775:tid 727916] [client 20.91.199.21:47291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/zwso.php"] [unique_id "amuIosDCZkc4BvDXnoDR7AAAAAs"]
[Thu Jul 30 12:23:46.665255 2026] [security2:error] [pid 727775:tid 727923] [client 172.213.232.128:15561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/includes/about.php"] [unique_id "amuIosDCZkc4BvDXnoDR7QAAABI"]
[Thu Jul 30 12:23:46.691419 2026] [security2:error] [pid 727775:tid 727950] [client 142.93.53.183:57069] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/alfacgiapi/perl.alfa"] [unique_id "amuIosDCZkc4BvDXnoDR7gAAAC0"]
[Thu Jul 30 12:23:46.826159 2026] [security2:error] [pid 727775:tid 727938] [client 3.221.222.168:59368] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2019/07/47c2cb97-e98a-4382-9285-6ea8f9d72211-560x420.jpg"] [unique_id "amuIosDCZkc4BvDXnoDR-AAAACE"]
[Thu Jul 30 12:23:47.106612 2026] [security2:error] [pid 727775:tid 727957] [client 142.93.53.183:57241] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/archives/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIo8DCZkc4BvDXnoDR-QAAADQ"]
[Thu Jul 30 12:23:47.237837 2026] [security2:error] [pid 727775:tid 728011] [client 172.202.44.182:35797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/404.php"] [unique_id "amuIo8DCZkc4BvDXnoDR_QAAAGo"]
[Thu Jul 30 12:23:47.498617 2026] [security2:error] [pid 727775:tid 728031] [client 142.93.53.183:57427] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/archives/alfacgiapi/perl.alfa"] [unique_id "amuIo8DCZkc4BvDXnoDSAQAAAH4"]
[Thu Jul 30 12:23:47.930493 2026] [core:error] [pid 727775:tid 727989] [client 158.173.25.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://appliancerepairservice.one/
[Thu Jul 30 12:23:47.930515 2026] [core:error] [pid 727775:tid 727989] [client 158.173.25.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://appliancerepairservice.one/
[Thu Jul 30 12:23:48.042257 2026] [security2:error] [pid 727775:tid 727944] [client 142.93.53.183:57670] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/audio/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIpMDCZkc4BvDXnoDSFwAAACc"]
[Thu Jul 30 12:23:48.206156 2026] [security2:error] [pid 727775:tid 728027] [client 20.91.199.21:47285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/13.php"] [unique_id "amuIpMDCZkc4BvDXnoDSIAAAAHo"]
[Thu Jul 30 12:23:48.266445 2026] [security2:error] [pid 727775:tid 728029] [client 57.141.0.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuIpMDCZkc4BvDXnoDSFAAAAHw"]
[Thu Jul 30 12:23:48.427462 2026] [security2:error] [pid 727775:tid 727994] [client 142.93.53.183:57837] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/audio/alfacgiapi/perl.alfa"] [unique_id "amuIpMDCZkc4BvDXnoDSJwAAAFk"]
[Thu Jul 30 12:23:48.530152 2026] [security2:error] [pid 727775:tid 727930] [client 172.213.232.128:22340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/images/about.php"] [unique_id "amuIpMDCZkc4BvDXnoDSKAAAABk"]
[Thu Jul 30 12:23:48.793621 2026] [security2:error] [pid 727775:tid 728005] [client 17.22.237.155:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuIpMDCZkc4BvDXnoDSLAAAAGQ"]
[Thu Jul 30 12:23:48.811490 2026] [security2:error] [pid 727775:tid 727950] [client 142.93.53.183:57999] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/avatar/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIpMDCZkc4BvDXnoDSMAAAAC0"]
[Thu Jul 30 12:23:48.967494 2026] [security2:error] [pid 727775:tid 727927] [client 20.91.199.21:47660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/ava.php"] [unique_id "amuIpMDCZkc4BvDXnoDSNQAAABY"]
[Thu Jul 30 12:23:49.136146 2026] [security2:error] [pid 727775:tid 728023] [client 184.75.223.195:33762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuIpcDCZkc4BvDXnoDSNwAAAHY"]
[Thu Jul 30 12:23:49.136252 2026] [security2:error] [pid 727775:tid 728023] [client 184.75.223.195:33762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuIpcDCZkc4BvDXnoDSNwAAAHY"]
[Thu Jul 30 12:23:49.187467 2026] [security2:error] [pid 727775:tid 728001] [client 142.93.53.183:58170] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/avatar/alfacgiapi/perl.alfa"] [unique_id "amuIpcDCZkc4BvDXnoDSOAAAAGA"]
[Thu Jul 30 12:23:49.519858 2026] [security2:error] [pid 727775:tid 727938] [client 172.213.232.128:4979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/blogs.dir/about.php"] [unique_id "amuIpcDCZkc4BvDXnoDSRQAAACE"]
[Thu Jul 30 12:23:49.562836 2026] [security2:error] [pid 727775:tid 727999] [client 142.93.53.183:58335] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/block/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIpcDCZkc4BvDXnoDSRgAAAF4"]
[Thu Jul 30 12:23:49.566350 2026] [security2:error] [pid 727775:tid 727920] [client 2a03:2880:f800:10:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuIpMDCZkc4BvDXnoDSNAAAD1U"]
[Thu Jul 30 12:23:49.749136 2026] [security2:error] [pid 727775:tid 727890] [remote 57.141.0.58:36064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/7374488921/feed/rss2/"] [unique_id "amuIpcDCZkc4BvDXnoDSSgAAH3I"]
[Thu Jul 30 12:23:49.827531 2026] [security2:error] [pid 727775:tid 727995] [client 20.91.199.21:46737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/main.php"] [unique_id "amuIpcDCZkc4BvDXnoDSSwAAAFo"]
[Thu Jul 30 12:23:49.891834 2026] [security2:error] [pid 727775:tid 727975] [client 172.202.44.182:42001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/init.php"] [unique_id "amuIpcDCZkc4BvDXnoDSUwAAAEY"]
[Thu Jul 30 12:23:49.935769 2026] [security2:error] [pid 727775:tid 727907] [client 142.93.53.183:58474] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/block/alfacgiapi/perl.alfa"] [unique_id "amuIpcDCZkc4BvDXnoDSVwAAAAI"]
[Thu Jul 30 12:23:50.330249 2026] [security2:error] [pid 727775:tid 727973] [client 142.93.53.183:58633] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/button/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIpsDCZkc4BvDXnoDSXAAAAEQ"]
[Thu Jul 30 12:23:50.458598 2026] [security2:error] [pid 727775:tid 727968] [client 20.91.199.21:47272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/wp-file.php"] [unique_id "amuIpsDCZkc4BvDXnoDSYwAAAD8"]
[Thu Jul 30 12:23:50.486406 2026] [security2:error] [pid 727775:tid 727970] [client 85.204.70.116:64896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bkv.gpl.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuIpsDCZkc4BvDXnoDSZAAAAEE"]
[Thu Jul 30 12:23:50.486489 2026] [security2:error] [pid 727775:tid 727970] [client 85.204.70.116:64896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bkv.gpl.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuIpsDCZkc4BvDXnoDSZAAAAEE"]
[Thu Jul 30 12:23:50.722762 2026] [security2:error] [pid 727775:tid 727998] [client 142.93.53.183:58796] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/button/alfacgiapi/perl.alfa"] [unique_id "amuIpsDCZkc4BvDXnoDSZQAAAF0"]
[Thu Jul 30 12:23:51.125120 2026] [security2:error] [pid 727775:tid 728018] [client 142.93.53.183:58935] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/buttons/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIp8DCZkc4BvDXnoDScAAAAHE"]
[Thu Jul 30 12:23:51.435919 2026] [security2:error] [pid 727775:tid 728004] [client 20.91.199.21:47258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/wp-signin.php"] [unique_id "amuIp8DCZkc4BvDXnoDScgAAAGM"]
[Thu Jul 30 12:23:51.522060 2026] [security2:error] [pid 727775:tid 727957] [client 142.93.53.183:59105] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/buttons/alfacgiapi/perl.alfa"] [unique_id "amuIp8DCZkc4BvDXnoDSeQAAADQ"]
[Thu Jul 30 12:23:51.920410 2026] [security2:error] [pid 727775:tid 727940] [client 142.93.53.183:59240] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/calendar/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIp8DCZkc4BvDXnoDSegAAACM"]
[Thu Jul 30 12:23:51.991000 2026] [core:notice] [pid 727775:tid 727947] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:52.243773 2026] [security2:error] [pid 727775:tid 727916] [client 172.213.232.128:4982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/images/about.php"] [unique_id "amuIqMDCZkc4BvDXnoDSggAAAAs"]
[Thu Jul 30 12:23:52.301185 2026] [security2:error] [pid 727775:tid 727911] [client 142.93.53.183:59364] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/calendar/alfacgiapi/perl.alfa"] [unique_id "amuIqMDCZkc4BvDXnoDSgwAAAAY"]
[Thu Jul 30 12:23:52.383948 2026] [security2:error] [pid 727775:tid 727943] [client 172.202.44.182:35779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/file5.php"] [unique_id "amuIqMDCZkc4BvDXnoDShAAAACY"]
[Thu Jul 30 12:23:52.535048 2026] [security2:error] [pid 727775:tid 728009] [client 20.91.199.21:47234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/simi.php"] [unique_id "amuIqMDCZkc4BvDXnoDSigAAAGg"]
[Thu Jul 30 12:23:52.724640 2026] [security2:error] [pid 727775:tid 727936] [client 142.93.53.183:59512] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/categories/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIqMDCZkc4BvDXnoDSjAAAAB8"]
[Thu Jul 30 12:23:53.124958 2026] [security2:error] [pid 727775:tid 727952] [client 142.93.53.183:59634] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/categories/alfacgiapi/perl.alfa"] [unique_id "amuIqcDCZkc4BvDXnoDSkwAAAC8"]
[Thu Jul 30 12:23:53.172572 2026] [security2:error] [pid 727775:tid 727908] [client 172.213.232.128:16358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/about.php"] [unique_id "amuIqcDCZkc4BvDXnoDSlAAAAAM"]
[Thu Jul 30 12:23:53.531464 2026] [security2:error] [pid 727775:tid 727918] [client 142.93.53.183:59781] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/code/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIqcDCZkc4BvDXnoDSmQAAAA0"]
[Thu Jul 30 12:23:53.761599 2026] [security2:error] [pid 727775:tid 727973] [client 172.213.232.128:38941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/cgi-bin/about.php"] [unique_id "amuIqcDCZkc4BvDXnoDSoAAAAEQ"]
[Thu Jul 30 12:23:53.842629 2026] [security2:error] [pid 727775:tid 727785] [remote 47.128.112.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.112.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/view/98"] [unique_id "amuIqcDCZkc4BvDXnoDSnQAAPQk"]
[Thu Jul 30 12:23:53.910386 2026] [security2:error] [pid 727775:tid 727968] [client 142.93.53.183:59931] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/code/alfacgiapi/perl.alfa"] [unique_id "amuIqcDCZkc4BvDXnoDSoQAAAD8"]
[Thu Jul 30 12:23:54.068452 2026] [core:notice] [pid 727775:tid 727815] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:54.288947 2026] [security2:error] [pid 727775:tid 727960] [client 142.93.53.183:60073] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/column/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIqsDCZkc4BvDXnoDSqQAAADc"]
[Thu Jul 30 12:23:54.384196 2026] [core:notice] [pid 727775:tid 727804] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:54.391700 2026] [security2:error] [pid 727775:tid 727791] [remote 47.128.112.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.112.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/---call---/page/page/css-name-font.css"] [unique_id "amuIqsDCZkc4BvDXnoDSqwAALA8"], referer: https://www.jipkl.com/index.php/JIPKL/article/view/98
[Thu Jul 30 12:23:54.494927 2026] [security2:error] [pid 727775:tid 727990] [client 20.91.199.21:47631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/wp-conf.php"] [unique_id "amuIqsDCZkc4BvDXnoDSrwAAAFU"]
[Thu Jul 30 12:23:54.610699 2026] [core:notice] [pid 727775:tid 727793] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:54.634011 2026] [core:notice] [pid 727775:tid 727813] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:54.652936 2026] [core:notice] [pid 727775:tid 727800] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:54.687457 2026] [security2:error] [pid 727775:tid 727947] [client 142.93.53.183:60224] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/column/alfacgiapi/perl.alfa"] [unique_id "amuIqsDCZkc4BvDXnoDSuQAAACo"]
[Thu Jul 30 12:23:54.968114 2026] [core:notice] [pid 727775:tid 727796] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:55.032286 2026] [core:notice] [pid 727775:tid 727982] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:55.093413 2026] [security2:error] [pid 727775:tid 728013] [client 142.93.53.183:60352] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/columns/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIq8DCZkc4BvDXnoDSvwAAAGw"]
[Thu Jul 30 12:23:55.281368 2026] [core:notice] [pid 727775:tid 727790] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:55.476283 2026] [security2:error] [pid 727775:tid 727995] [client 142.93.53.183:60493] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/columns/alfacgiapi/perl.alfa"] [unique_id "amuIq8DCZkc4BvDXnoDSyAAAAFo"]
[Thu Jul 30 12:23:55.556664 2026] [security2:error] [pid 727775:tid 728014] [client 172.213.232.128:4627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/gallery/about.php"] [unique_id "amuIq8DCZkc4BvDXnoDSyQAAAG0"]
[Thu Jul 30 12:23:55.692094 2026] [security2:error] [pid 727775:tid 727958] [client 172.202.44.182:42013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amuIq8DCZkc4BvDXnoDSzwAAADU"]
[Thu Jul 30 12:23:55.722484 2026] [core:notice] [pid 727775:tid 727969] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:55.862196 2026] [security2:error] [pid 727775:tid 727919] [client 142.93.53.183:60625] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comment-author-name/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIq8DCZkc4BvDXnoDS0gAAAA4"]
[Thu Jul 30 12:23:55.874872 2026] [security2:error] [pid 727775:tid 727799] [remote 97.74.87.194:51600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-468361c2.glb.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuIq8DCZkc4BvDXnoDS1AAAHxc"]
[Thu Jul 30 12:23:56.006341 2026] [core:notice] [pid 727775:tid 727805] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:56.242411 2026] [security2:error] [pid 727775:tid 728022] [client 142.93.53.183:60783] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comment-author-name/alfacgiapi/perl.alfa"] [unique_id "amuIrMDCZkc4BvDXnoDS3gAAAHU"]
[Thu Jul 30 12:23:56.654810 2026] [core:notice] [pid 727775:tid 727948] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:56.720289 2026] [security2:error] [pid 727775:tid 727984] [client 57.141.0.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuIrMDCZkc4BvDXnoDS4QAAAE8"]
[Thu Jul 30 12:23:56.736796 2026] [security2:error] [pid 727775:tid 727977] [client 142.93.53.183:60971] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comment-content/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIrMDCZkc4BvDXnoDS5wAAAEg"]
[Thu Jul 30 12:23:57.164698 2026] [security2:error] [pid 727775:tid 727974] [client 142.93.53.183:61132] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comment-content/alfacgiapi/perl.alfa"] [unique_id "amuIrcDCZkc4BvDXnoDS7AAAAEU"]
[Thu Jul 30 12:23:57.352171 2026] [core:notice] [pid 727775:tid 727926] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:57.574383 2026] [security2:error] [pid 727775:tid 727980] [client 172.202.44.182:17481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/shell.php"] [unique_id "amuIrcDCZkc4BvDXnoDS9AAAAEs"]
[Thu Jul 30 12:23:57.647818 2026] [core:notice] [pid 727775:tid 727922] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:57.709038 2026] [security2:error] [pid 727775:tid 728000] [client 142.93.53.183:61326] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comment-date/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIrcDCZkc4BvDXnoDS9gAAAF8"]
[Thu Jul 30 12:23:58.030910 2026] [security2:error] [pid 727775:tid 727963] [client 20.91.199.21:47266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/WZGHHra0r3.php"] [unique_id "amuIrsDCZkc4BvDXnoDS_QAAADo"]
[Thu Jul 30 12:23:58.064078 2026] [core:notice] [pid 727775:tid 727838] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:58.087125 2026] [core:notice] [pid 727775:tid 727931] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:58.090711 2026] [security2:error] [pid 727775:tid 728025] [client 142.93.53.183:61443] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comment-date/alfacgiapi/perl.alfa"] [unique_id "amuIrsDCZkc4BvDXnoDTAgAAAHg"]
[Thu Jul 30 12:23:58.463119 2026] [security2:error] [pid 727775:tid 727971] [client 142.93.53.183:61600] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comment-edit-link/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIrsDCZkc4BvDXnoDTCgAAAEI"]
[Thu Jul 30 12:23:58.574623 2026] [security2:error] [pid 727775:tid 727909] [client 2a03:2880:f800:b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuIrsDCZkc4BvDXnoDS_gAABDk"]
[Thu Jul 30 12:23:58.678567 2026] [security2:error] [pid 727775:tid 727964] [client 20.91.199.21:47642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/bala.php"] [unique_id "amuIrsDCZkc4BvDXnoDTDgAAADs"]
[Thu Jul 30 12:23:58.839927 2026] [security2:error] [pid 727775:tid 727933] [client 142.93.53.183:61721] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comment-edit-link/alfacgiapi/perl.alfa"] [unique_id "amuIrsDCZkc4BvDXnoDTEgAAABw"]
[Thu Jul 30 12:23:59.121334 2026] [core:notice] [pid 727775:tid 728030] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:59.219576 2026] [security2:error] [pid 727775:tid 727968] [client 142.93.53.183:61858] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comment-reply-link/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIr8DCZkc4BvDXnoDTFwAAAD8"]
[Thu Jul 30 12:23:59.497823 2026] [security2:error] [pid 727775:tid 727835] [remote 57.141.0.33:29298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/63798190810/feed/rss2/"] [unique_id "amuIr8DCZkc4BvDXnoDTHwAAaTs"]
[Thu Jul 30 12:23:59.606654 2026] [security2:error] [pid 727775:tid 728007] [client 142.93.53.183:61989] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comment-reply-link/alfacgiapi/perl.alfa"] [unique_id "amuIr8DCZkc4BvDXnoDTIAAAAGY"]
[Thu Jul 30 12:23:59.669610 2026] [security2:error] [pid 727775:tid 727935] [client 20.91.199.21:47618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/bk.php"] [unique_id "amuIr8DCZkc4BvDXnoDTIQAAAB4"]
[Thu Jul 30 12:23:59.995049 2026] [security2:error] [pid 727775:tid 728004] [client 142.93.53.183:62103] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comment-template/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIr8DCZkc4BvDXnoDTKAAAAGM"]
[Thu Jul 30 12:24:00.000342 2026] [security2:error] [pid 727775:tid 728020] [client 87.101.92.171:56294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.92.101.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuIr8DCZkc4BvDXnoDTKQAAAHM"]
[Thu Jul 30 12:24:00.000429 2026] [security2:error] [pid 727775:tid 728020] [client 87.101.92.171:56294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuIr8DCZkc4BvDXnoDTKQAAAHM"]
[Thu Jul 30 12:24:00.110251 2026] [security2:error] [pid 727775:tid 727826] [remote 57.141.0.67:64552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/cicee/article/view/9398/4174"] [unique_id "amuIsMDCZkc4BvDXnoDTKgAACjI"]
[Thu Jul 30 12:24:00.113538 2026] [security2:error] [pid 727775:tid 727925] [client 172.202.44.182:42037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/f35.php"] [unique_id "amuIsMDCZkc4BvDXnoDTKwAAABQ"]
[Thu Jul 30 12:24:00.392386 2026] [security2:error] [pid 727775:tid 728024] [client 142.93.53.183:62229] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comment-template/alfacgiapi/perl.alfa"] [unique_id "amuIsMDCZkc4BvDXnoDTLwAAAHc"]
[Thu Jul 30 12:24:00.410403 2026] [security2:error] [pid 727775:tid 727972] [client 20.91.199.21:47662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/ahax.php"] [unique_id "amuIsMDCZkc4BvDXnoDTMAAAAEM"]
[Thu Jul 30 12:24:00.843595 2026] [security2:error] [pid 727775:tid 728009] [client 142.93.53.183:62362] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comments/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIsMDCZkc4BvDXnoDTNQAAAGg"]
[Thu Jul 30 12:24:01.136281 2026] [core:notice] [pid 727775:tid 727926] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:24:01.311758 2026] [security2:error] [pid 727775:tid 727936] [client 142.93.53.183:62492] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comments/alfacgiapi/perl.alfa"] [unique_id "amuIscDCZkc4BvDXnoDTRAAAAB8"]
[Thu Jul 30 12:24:01.344206 2026] [security2:error] [pid 727775:tid 728031] [client 2a03:2880:f800:c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuIsMDCZkc4BvDXnoDTNAAAfjE"]
[Thu Jul 30 12:24:01.701442 2026] [security2:error] [pid 727775:tid 728032] [client 142.93.53.183:62599] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comments-pagination/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIscDCZkc4BvDXnoDTTQAAAH8"]
[Thu Jul 30 12:24:02.147889 2026] [security2:error] [pid 727775:tid 727998] [client 142.93.53.183:62743] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comments-pagination/alfacgiapi/perl.alfa"] [unique_id "amuIssDCZkc4BvDXnoDTVwAAAF0"]
[Thu Jul 30 12:24:02.496925 2026] [security2:error] [pid 727775:tid 727921] [client 23.21.250.48:60806] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2018/09/mae-romulo.jpg"] [unique_id "amuIssDCZkc4BvDXnoDTWQAAABA"]
[Thu Jul 30 12:24:02.533753 2026] [security2:error] [pid 727775:tid 727949] [client 142.93.53.183:62858] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comments-pagination-next/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIssDCZkc4BvDXnoDTWwAAACw"]
[Thu Jul 30 12:24:02.924209 2026] [security2:error] [pid 727775:tid 728004] [client 142.93.53.183:62962] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comments-pagination-next/alfacgiapi/perl.alfa"] [unique_id "amuIssDCZkc4BvDXnoDTZQAAAGM"]
[Thu Jul 30 12:24:03.022423 2026] [security2:error] [pid 727775:tid 727993] [client 172.213.232.128:16366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuIs8DCZkc4BvDXnoDTZgAAAFg"]
[Thu Jul 30 12:24:03.272786 2026] [core:notice] [pid 727775:tid 728017] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:24:03.310266 2026] [security2:error] [pid 727775:tid 727937] [client 142.93.53.183:63051] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comments-pagination-numbers/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIs8DCZkc4BvDXnoDTbwAAACA"]
[Thu Jul 30 12:24:03.693070 2026] [security2:error] [pid 727775:tid 728008] [client 142.93.53.183:63167] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comments-pagination-numbers/alfacgiapi/perl.alfa"] [unique_id "amuIs8DCZkc4BvDXnoDTgAAAAGc"]
[Thu Jul 30 12:24:03.705184 2026] [security2:error] [pid 727775:tid 727982] [client 57.141.0.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuIs8DCZkc4BvDXnoDTcwAAAE0"]
[Thu Jul 30 12:24:03.751694 2026] [core:notice] [pid 727775:tid 727975] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:24:03.753548 2026] [security2:error] [pid 727775:tid 727975] [client 34.165.207.64:1024] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.nordeste1.com"] [uri "/category/brasil/feed/"] [unique_id "amuIs8DCZkc4BvDXnoDTgQAAAEY"]
[Thu Jul 30 12:24:03.812042 2026] [security2:error] [pid 727775:tid 728009] [client 172.213.232.128:10283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/css/about.php"] [unique_id "amuIs8DCZkc4BvDXnoDTggAAAGg"]
[Thu Jul 30 12:24:04.075109 2026] [security2:error] [pid 727775:tid 727934] [client 142.93.53.183:63274] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comments-pagination-previous/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuItMDCZkc4BvDXnoDThQAAAB0"]
[Thu Jul 30 12:24:04.091627 2026] [core:notice] [pid 727775:tid 728000] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:24:04.313949 2026] [security2:error] [pid 727775:tid 728030] [client 172.202.44.182:17511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/new.php"] [unique_id "amuItMDCZkc4BvDXnoDTjgAAAH0"]
[Thu Jul 30 12:24:04.314416 2026] [core:notice] [pid 727775:tid 727952] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:24:04.471074 2026] [security2:error] [pid 727775:tid 727918] [client 142.93.53.183:63403] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comments-pagination-previous/alfacgiapi/perl.alfa"] [unique_id "amuItMDCZkc4BvDXnoDTkAAAAA0"]
[Thu Jul 30 12:24:04.570016 2026] [security2:error] [pid 727775:tid 727936] [client 95.108.213.97:64518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuItMDCZkc4BvDXnoDTjQAAAB8"]
[Thu Jul 30 12:24:04.857683 2026] [security2:error] [pid 727775:tid 727930] [client 142.93.53.183:63529] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comments-title/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuItMDCZkc4BvDXnoDTnQAAABk"]
[Thu Jul 30 12:24:05.103677 2026] [security2:error] [pid 727775:tid 727864] [remote 198.38.94.67:59836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.94.38.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.zjp.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuItcDCZkc4BvDXnoDTowAAdFg"]
[Thu Jul 30 12:24:05.327603 2026] [security2:error] [pid 727775:tid 728020] [client 142.93.53.183:63689] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comments-title/alfacgiapi/perl.alfa"] [unique_id "amuItcDCZkc4BvDXnoDTqwAAAHM"]
[Thu Jul 30 12:24:05.781595 2026] [security2:error] [pid 727775:tid 727937] [client 142.93.53.183:63858] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/cover/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuItcDCZkc4BvDXnoDTswAAACA"]
[Thu Jul 30 12:24:06.174283 2026] [security2:error] [pid 727775:tid 728001] [client 142.93.53.183:63989] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content-new/ai1wm-backups/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuItsDCZkc4BvDXnoDTuAAAAGA"]
[Thu Jul 30 12:24:06.555047 2026] [security2:error] [pid 727775:tid 727976] [client 142.93.53.183:64097] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content-new/ai1wm-backups/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuItsDCZkc4BvDXnoDTzQAAAEc"]
[Thu Jul 30 12:24:06.859451 2026] [security2:error] [pid 727775:tid 727997] [client 172.202.44.182:17518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/adminfuns.php"] [unique_id "amuItsDCZkc4BvDXnoDT1wAAAFw"]
[Thu Jul 30 12:24:06.969966 2026] [security2:error] [pid 727775:tid 727919] [client 142.93.53.183:64243] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content-new/ai1wm-backups/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuItsDCZkc4BvDXnoDT2AAAAA4"]
[Thu Jul 30 12:24:07.014375 2026] [security2:error] [pid 727775:tid 727942] [client 66.249.73.97:59578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuItsDCZkc4BvDXnoDTzgAAACU"]
[Thu Jul 30 12:24:07.123863 2026] [core:notice] [pid 727775:tid 727963] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:24:07.327772 2026] [security2:error] [pid 727775:tid 727992] [client 66.249.79.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.legalsnaps.info"] [uri "/index.php"] [unique_id "amuIt8DCZkc4BvDXnoDT3AAAAFc"]
[Thu Jul 30 12:24:07.359743 2026] [security2:error] [pid 727775:tid 728032] [client 142.93.53.183:64378] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/ai1wm-backups/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIt8DCZkc4BvDXnoDT4QAAAH8"]
[Thu Jul 30 12:24:07.741281 2026] [security2:error] [pid 727775:tid 728022] [client 142.93.53.183:64522] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/ai1wm-backups/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIt8DCZkc4BvDXnoDT5wAAAHU"]
[Thu Jul 30 12:24:08.123576 2026] [security2:error] [pid 727775:tid 728012] [client 142.93.53.183:64666] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/ai1wm-backups/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuIuMDCZkc4BvDXnoDT8QAAAGs"]
[Thu Jul 30 12:24:08.306902 2026] [security2:error] [pid 727775:tid 728025] [client 172.213.232.128:10251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/images/about.php"] [unique_id "amuIuMDCZkc4BvDXnoDT8wAAAHg"]
[Thu Jul 30 12:24:08.573192 2026] [security2:error] [pid 727775:tid 728006] [client 142.93.53.183:64831] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/cover/alfacgiapi/perl.alfa"] [unique_id "amuIuMDCZkc4BvDXnoDT-wAAAGU"]
[Thu Jul 30 12:24:08.573858 2026] [security2:error] [pid 727775:tid 727792] [remote 57.141.0.52:61770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/640974427/feed/rss2/"] [unique_id "amuIuMDCZkc4BvDXnoDT_AAAMxA"]
[Thu Jul 30 12:24:08.776672 2026] [security2:error] [pid 727775:tid 727986] [client 172.202.44.182:42039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/fm.php"] [unique_id "amuIuMDCZkc4BvDXnoDT_QAAAFE"]
[Thu Jul 30 12:24:08.950684 2026] [security2:error] [pid 727775:tid 727925] [client 142.93.53.183:64945] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/details/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIuMDCZkc4BvDXnoDUAgAAABQ"]
[Thu Jul 30 12:24:09.330194 2026] [security2:error] [pid 727775:tid 727909] [client 142.93.53.183:65065] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/details/alfacgiapi/perl.alfa"] [unique_id "amuIucDCZkc4BvDXnoDUCQAAAAQ"]
[Thu Jul 30 12:24:09.816821 2026] [security2:error] [pid 727775:tid 727946] [client 142.93.53.183:65221] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/embed/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIucDCZkc4BvDXnoDUEgAAACk"]
[Thu Jul 30 12:24:10.172708 2026] [core:notice] [pid 727775:tid 728008] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:24:10.204588 2026] [security2:error] [pid 727775:tid 727969] [client 142.93.53.183:65341] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/embed/alfacgiapi/perl.alfa"] [unique_id "amuIusDCZkc4BvDXnoDUHwAAAEA"]
[Thu Jul 30 12:24:10.305085 2026] [security2:error] [pid 727775:tid 727793] [remote 40.77.167.28:42509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/12812638002258/indexf.php"] [unique_id "amuIusDCZkc4BvDXnoDUHAAAGRE"]
[Thu Jul 30 12:24:10.593891 2026] [security2:error] [pid 727775:tid 727954] [client 142.93.53.183:65470] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/file/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIusDCZkc4BvDXnoDUJgAAADE"]
[Thu Jul 30 12:24:10.957368 2026] [core:notice] [pid 727775:tid 728025] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:24:10.989443 2026] [security2:error] [pid 727775:tid 727927] [client 142.93.53.183:49210] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/file/alfacgiapi/perl.alfa"] [unique_id "amuIusDCZkc4BvDXnoDULAAAABY"]
[Thu Jul 30 12:24:11.407168 2026] [security2:error] [pid 727775:tid 727940] [client 142.93.53.183:49339] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/footnotes/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIu8DCZkc4BvDXnoDUMwAAACM"]
[Thu Jul 30 12:24:11.440369 2026] [security2:error] [pid 727775:tid 727973] [client 172.202.44.182:17639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/file.php"] [unique_id "amuIu8DCZkc4BvDXnoDUNAAAAEQ"]
[Thu Jul 30 12:24:11.794223 2026] [security2:error] [pid 727775:tid 727905] [client 142.93.53.183:49473] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/footnotes/alfacgiapi/perl.alfa"] [unique_id "amuIu8DCZkc4BvDXnoDUOwAAAAA"]
[Thu Jul 30 12:24:12.191124 2026] [security2:error] [pid 727775:tid 727982] [client 142.93.53.183:49602] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/freeform/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIvMDCZkc4BvDXnoDUQgAAAE0"]
[Thu Jul 30 12:24:12.576280 2026] [security2:error] [pid 727775:tid 727934] [client 142.93.53.183:49739] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/freeform/alfacgiapi/perl.alfa"] [unique_id "amuIvMDCZkc4BvDXnoDURgAAAB0"]
[Thu Jul 30 12:24:12.977213 2026] [core:notice] [pid 727775:tid 727805] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:24:13.172948 2026] [security2:error] [pid 727775:tid 727985] [client 142.93.53.183:49946] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/gallery/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIvcDCZkc4BvDXnoDUTgAAAFA"]
[Thu Jul 30 12:24:13.201141 2026] [core:notice] [pid 727775:tid 727941] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:24:13.559819 2026] [security2:error] [pid 727775:tid 727939] [client 142.93.53.183:50070] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/gallery/alfacgiapi/perl.alfa"] [unique_id "amuIvcDCZkc4BvDXnoDUVgAAACI"]
[Thu Jul 30 12:24:13.960189 2026] [security2:error] [pid 727775:tid 727994] [client 142.93.53.183:50195] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/group/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIvcDCZkc4BvDXnoDUXgAAAFk"]
[Thu Jul 30 12:24:14.343101 2026] [security2:error] [pid 727775:tid 728026] [client 142.93.53.183:50323] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/group/alfacgiapi/perl.alfa"] [unique_id "amuIvsDCZkc4BvDXnoDUZgAAAHk"]
[Thu Jul 30 12:24:14.556758 2026] [security2:error] [pid 727775:tid 727818] [remote 157.55.39.49:40193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.39.55.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/183299856812/indexf.php"] [unique_id "amuIvsDCZkc4BvDXnoDUZQAAMSo"]
[Thu Jul 30 12:24:14.721510 2026] [security2:error] [pid 727775:tid 728003] [client 142.93.53.183:50453] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/heading/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIvsDCZkc4BvDXnoDUawAAAGI"]
[Thu Jul 30 12:24:15.125569 2026] [security2:error] [pid 727775:tid 727943] [client 142.93.53.183:50583] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/heading/alfacgiapi/perl.alfa"] [unique_id "amuIv8DCZkc4BvDXnoDUcgAAACY"]
[Thu Jul 30 12:24:15.499371 2026] [security2:error] [pid 727775:tid 727972] [client 142.93.53.183:50722] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/home-link/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIv8DCZkc4BvDXnoDUeQAAAEM"]
[Thu Jul 30 12:24:15.763147 2026] [security2:error] [pid 727775:tid 727911] [client 172.202.44.182:42004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/bolt.php"] [unique_id "amuIv8DCZkc4BvDXnoDUfgAAAAY"]
[Thu Jul 30 12:24:15.890923 2026] [security2:error] [pid 727775:tid 727926] [client 142.93.53.183:50841] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/home-link/alfacgiapi/perl.alfa"] [unique_id "amuIv8DCZkc4BvDXnoDUhAAAABU"]
[Thu Jul 30 12:24:16.123890 2026] [security2:error] [pid 727775:tid 727942] [client 87.101.92.171:45290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.92.101.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuIwMDCZkc4BvDXnoDUhgAAACU"]
[Thu Jul 30 12:24:16.124022 2026] [security2:error] [pid 727775:tid 727942] [client 87.101.92.171:45290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuIwMDCZkc4BvDXnoDUhgAAACU"]
[Thu Jul 30 12:24:16.158233 2026] [core:notice] [pid 727775:tid 727916] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:24:16.250001 2026] [core:notice] [pid 727775:tid 727999] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:24:16.289886 2026] [security2:error] [pid 727775:tid 727963] [client 142.93.53.183:50981] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/html/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIwMDCZkc4BvDXnoDUjAAAADo"]
[Thu Jul 30 12:24:16.583510 2026] [security2:error] [pid 727775:tid 727931] [client 172.213.232.128:7341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/.well-known/pki-validation/cloud.php"] [unique_id "amuIwMDCZkc4BvDXnoDUkAAAABo"]
[Thu Jul 30 12:24:16.665766 2026] [security2:error] [pid 727775:tid 727939] [client 142.93.53.183:51117] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/html/alfacgiapi/perl.alfa"] [unique_id "amuIwMDCZkc4BvDXnoDUkQAAACI"]
[Thu Jul 30 12:24:16.909570 2026] [security2:error] [pid 727775:tid 728022] [client 87.101.92.171:56244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.92.101.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuIwMDCZkc4BvDXnoDUmAAAAHU"]
[Thu Jul 30 12:24:16.909677 2026] [security2:error] [pid 727775:tid 728022] [client 87.101.92.171:56244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuIwMDCZkc4BvDXnoDUmAAAAHU"]
[Thu Jul 30 12:24:16.941673 2026] [security2:error] [pid 727775:tid 727952] [client 172.202.44.182:17528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/3.php"] [unique_id "amuIwMDCZkc4BvDXnoDUmQAAAC8"]
[Thu Jul 30 12:24:17.046695 2026] [security2:error] [pid 727775:tid 727935] [client 142.93.53.183:51251] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/image/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIwcDCZkc4BvDXnoDUmgAAAB4"]
[Thu Jul 30 12:24:17.424620 2026] [security2:error] [pid 727775:tid 727958] [client 142.93.53.183:51374] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/image/alfacgiapi/perl.alfa"] [unique_id "amuIwcDCZkc4BvDXnoDUoQAAADU"]
[Thu Jul 30 12:24:17.827868 2026] [security2:error] [pid 727775:tid 728028] [client 142.93.53.183:51481] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/latest-comments/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIwcDCZkc4BvDXnoDUpQAAAHs"]
[Thu Jul 30 12:24:17.998144 2026] [security2:error] [pid 727775:tid 727984] [client 38.190.144.4:58339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuIwcDCZkc4BvDXnoDUqQAAAE8"]
[Thu Jul 30 12:24:17.998270 2026] [security2:error] [pid 727775:tid 727984] [client 38.190.144.4:58339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuIwcDCZkc4BvDXnoDUqQAAAE8"]
[Thu Jul 30 12:24:18.205393 2026] [security2:error] [pid 727775:tid 727996] [client 142.93.53.183:51590] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/latest-comments/alfacgiapi/perl.alfa"] [unique_id "amuIwsDCZkc4BvDXnoDUqgAAAFs"]
[Thu Jul 30 12:24:18.587561 2026] [security2:error] [pid 727775:tid 727943] [client 142.93.53.183:51695] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/latest-posts/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIwsDCZkc4BvDXnoDUsgAAACY"]
[Thu Jul 30 12:24:18.978091 2026] [security2:error] [pid 727775:tid 727927] [client 142.93.53.183:51810] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/latest-posts/alfacgiapi/perl.alfa"] [unique_id "amuIwsDCZkc4BvDXnoDUvQAAABY"]
[Thu Jul 30 12:24:19.372230 2026] [security2:error] [pid 727775:tid 727909] [client 74.7.241.137:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "webdisk.meg.gzj.temporary.site"] [uri "/___proxy_subdomain_webdisk/cgi-sys/404.html"] [unique_id "amuIw8DCZkc4BvDXnoDUxAAAAAQ"]
[Thu Jul 30 12:24:19.373933 2026] [security2:error] [pid 727775:tid 727913] [client 74.7.241.137:43856] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "webdisk.meg.gzj.temporary.site"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuIw8DCZkc4BvDXnoDUwgAACDQ"]
[Thu Jul 30 12:24:19.390171 2026] [security2:error] [pid 727775:tid 727908] [client 142.93.53.183:51936] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/legacy-widget/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIw8DCZkc4BvDXnoDUxQAAAAM"]
[Thu Jul 30 12:24:19.891990 2026] [security2:error] [pid 727775:tid 728030] [client 142.93.53.183:52072] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/legacy-widget/alfacgiapi/perl.alfa"] [unique_id "amuIw8DCZkc4BvDXnoDU0QAAAH0"]
[Thu Jul 30 12:24:20.274348 2026] [security2:error] [pid 727775:tid 728008] [client 142.93.53.183:52201] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/list/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIxMDCZkc4BvDXnoDU2QAAAGc"]
[Thu Jul 30 12:24:20.669657 2026] [security2:error] [pid 727775:tid 728007] [client 142.93.53.183:52320] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/list/alfacgiapi/perl.alfa"] [unique_id "amuIxMDCZkc4BvDXnoDU4AAAAGY"]
[Thu Jul 30 12:24:21.078565 2026] [security2:error] [pid 727775:tid 727994] [client 172.213.232.128:22371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/.well-known/acme-challenge/cloud.php"] [unique_id "amuIxcDCZkc4BvDXnoDU7AAAAFk"]
[Thu Jul 30 12:24:21.100440 2026] [security2:error] [pid 727775:tid 728025] [client 142.93.53.183:52444] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/list-item/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIxcDCZkc4BvDXnoDU7QAAAHg"]
[Thu Jul 30 12:24:21.285566 2026] [security2:error] [pid 727775:tid 727926] [client 172.202.44.182:42026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/222.php"] [unique_id "amuIxcDCZkc4BvDXnoDU7gAAABU"]
[Thu Jul 30 12:24:21.488224 2026] [security2:error] [pid 727775:tid 727947] [client 142.93.53.183:52560] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/list-item/alfacgiapi/perl.alfa"] [unique_id "amuIxcDCZkc4BvDXnoDU7wAAACo"]
[Thu Jul 30 12:24:21.535808 2026] [security2:error] [pid 727775:tid 727851] [remote 57.141.0.22:20936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuIxcDCZkc4BvDXnoDU8gAAK0s"]
[Thu Jul 30 12:24:21.737629 2026] [security2:error] [pid 727775:tid 727973] [client 172.213.232.128:20492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/network/cloud.php"] [unique_id "amuIxcDCZkc4BvDXnoDU9wAAAEQ"]
[Thu Jul 30 12:24:21.900613 2026] [security2:error] [pid 727775:tid 727937] [client 142.93.53.183:52687] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/loginout/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIxcDCZkc4BvDXnoDU-AAAACA"]
[Thu Jul 30 12:24:22.272853 2026] [security2:error] [pid 727775:tid 727914] [client 142.93.53.183:52797] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/loginout/alfacgiapi/perl.alfa"] [unique_id "amuIxsDCZkc4BvDXnoDVAgAAAAk"]
[Thu Jul 30 12:24:22.362652 2026] [security2:error] [pid 727775:tid 727986] [client 20.203.148.31:45833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/011i.php"] [unique_id "amuIxsDCZkc4BvDXnoDVAwAAAFE"]
[Thu Jul 30 12:24:22.541089 2026] [security2:error] [pid 727775:tid 727912] [client 172.213.232.128:22364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/cloud.php"] [unique_id "amuIxsDCZkc4BvDXnoDVBAAAAAc"]
[Thu Jul 30 12:24:22.657709 2026] [security2:error] [pid 727775:tid 727944] [client 142.93.53.183:52903] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/media-text/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIxsDCZkc4BvDXnoDVDAAAACc"]
[Thu Jul 30 12:24:23.047534 2026] [security2:error] [pid 727775:tid 727972] [client 172.202.44.182:17600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amuIx8DCZkc4BvDXnoDVDQAAAEM"]
[Thu Jul 30 12:24:23.072698 2026] [security2:error] [pid 727775:tid 727916] [client 142.93.53.183:53014] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/media-text/alfacgiapi/perl.alfa"] [unique_id "amuIx8DCZkc4BvDXnoDVDgAAAAs"]
[Thu Jul 30 12:24:23.456070 2026] [security2:error] [pid 727775:tid 727939] [client 142.93.53.183:53118] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/missing/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIx8DCZkc4BvDXnoDVGQAAACI"]
[Thu Jul 30 12:24:23.842823 2026] [security2:error] [pid 727775:tid 727952] [client 142.93.53.183:53220] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/missing/alfacgiapi/perl.alfa"] [unique_id "amuIx8DCZkc4BvDXnoDVIAAAAC8"]
[Thu Jul 30 12:24:23.889270 2026] [security2:error] [pid 727775:tid 727960] [client 20.203.148.31:44773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/03a005685d.php"] [unique_id "amuIx8DCZkc4BvDXnoDVIQAAADc"]
[Thu Jul 30 12:24:24.123346 2026] [security2:error] [pid 727775:tid 727855] [remote 157.55.39.49:14554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.39.55.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/column/shibutanijisseki/article.php"] [unique_id "amuIyMDCZkc4BvDXnoDVIgAAf08"]
[Thu Jul 30 12:24:24.219145 2026] [security2:error] [pid 727775:tid 727923] [client 172.202.44.182:17630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amuIyMDCZkc4BvDXnoDVJgAAABI"]
[Thu Jul 30 12:24:24.225901 2026] [security2:error] [pid 727775:tid 727949] [client 142.93.53.183:53331] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/more/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIyMDCZkc4BvDXnoDVJwAAACw"]
[Thu Jul 30 12:24:24.548391 2026] [security2:error] [pid 727775:tid 728012] [client 20.203.148.31:47148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/403.php"] [unique_id "amuIyMDCZkc4BvDXnoDVLAAAAGs"]
[Thu Jul 30 12:24:24.628031 2026] [security2:error] [pid 727775:tid 727990] [client 142.93.53.183:53444] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/more/alfacgiapi/perl.alfa"] [unique_id "amuIyMDCZkc4BvDXnoDVLQAAAFU"]
[Thu Jul 30 12:24:25.030022 2026] [security2:error] [pid 727775:tid 727993] [client 142.93.53.183:53565] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/navigation/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIycDCZkc4BvDXnoDVNgAAAFg"]
[Thu Jul 30 12:24:25.104015 2026] [security2:error] [pid 727775:tid 727957] [client 127.0.0.1:31236] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuIycDCZkc4BvDXnoDVOQAAADQ"]
[Thu Jul 30 12:24:25.104026 2026] [security2:error] [pid 727775:tid 727978] [client 127.0.0.1:31232] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.aws.gzj.temporary.site"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuIycDCZkc4BvDXnoDVOAAAAEk"]
[Thu Jul 30 12:24:25.104106 2026] [security2:error] [pid 727775:tid 727947] [client 74.7.244.37:42700] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.aws.gzj.temporary.site"] [uri "/robots.txt"] [unique_id "amuIycDCZkc4BvDXnoDVNwAAKmk"]
[Thu Jul 30 12:24:25.421844 2026] [security2:error] [pid 727775:tid 727927] [client 142.93.53.183:53677] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/navigation/alfacgiapi/perl.alfa"] [unique_id "amuIycDCZkc4BvDXnoDVRAAAABY"]
[Thu Jul 30 12:24:25.747999 2026] [security2:error] [pid 727775:tid 727967] [client 172.202.44.182:17635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/wp-content/admin.php"] [unique_id "amuIycDCZkc4BvDXnoDVSwAAAD4"]
[Thu Jul 30 12:24:25.830190 2026] [security2:error] [pid 727775:tid 727913] [client 142.93.53.183:53783] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/navigation-link/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIycDCZkc4BvDXnoDVTQAAAAg"]
[Thu Jul 30 12:24:25.895343 2026] [security2:error] [pid 727775:tid 727995] [client 172.213.232.128:15519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/cgi-bin/cloud.php"] [unique_id "amuIycDCZkc4BvDXnoDVUwAAAFo"]
[Thu Jul 30 12:24:25.981224 2026] [security2:error] [pid 727775:tid 727964] [client 20.203.148.31:44749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/404.php"] [unique_id "amuIycDCZkc4BvDXnoDVWAAAADs"]
[Thu Jul 30 12:24:26.216074 2026] [security2:error] [pid 727775:tid 727939] [client 142.93.53.183:53912] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/navigation-link/alfacgiapi/perl.alfa"] [unique_id "amuIysDCZkc4BvDXnoDVWQAAACI"]
[Thu Jul 30 12:24:26.268007 2026] [core:notice] [pid 727775:tid 727854] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:24:26.438544 2026] [security2:error] [pid 727775:tid 728022] [client 172.213.232.128:4658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/updates.php"] [unique_id "amuIysDCZkc4BvDXnoDVYgAAAHU"]
[Thu Jul 30 12:24:26.596393 2026] [security2:error] [pid 727775:tid 728007] [client 142.93.53.183:54034] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/navigation-submenu/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIysDCZkc4BvDXnoDVZAAAAGY"]
[Thu Jul 30 12:24:26.666743 2026] [security2:error] [pid 727775:tid 727952] [client 20.203.148.31:44745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/aa.php"] [unique_id "amuIysDCZkc4BvDXnoDVZQAAAC8"]
[Thu Jul 30 12:24:26.915501 2026] [security2:error] [pid 727775:tid 727971] [client 38.190.144.4:58831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuIysDCZkc4BvDXnoDVbAAAAEI"]
[Thu Jul 30 12:24:26.915638 2026] [security2:error] [pid 727775:tid 727971] [client 38.190.144.4:58831] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuIysDCZkc4BvDXnoDVbAAAAEI"]
[Thu Jul 30 12:24:26.970960 2026] [mpm_event:notice] [pid 8929:tid 8929] AH00493: SIGUSR1 received. Doing graceful restart
[Thu Jul 30 12:24:28.057593 2026] [:notice] [pid 642290:tid 642290] [host root@sh00085.hostgator.com] mod_lsapi: Selfstarter 642290 stopped
[Thu Jul 30 12:24:30.384724 2026] [lsapi:notice] [pid 8929:tid 8929] mod_lsapi: version 1.1-92
[Thu Jul 30 12:24:30.387771 2026] [:notice] [pid 738754:tid 738754] [host root@sh00085.hostgator.com] mod_lsapi: Selfstarter 738754 started
[Thu Jul 30 12:24:30.760582 2026] [ssl:warn] [pid 8929:tid 8929] AH01909: localhost:8443:0 server certificate does NOT include an ID which matches the server name
[Thu Jul 30 12:24:30.767823 2026] [qos:notice] [pid 8929:tid 8929] mod_qos(007): calculated MaxClients/MaxRequestWorkers (max connections): 6144, applied limit: 2048 (QS_MaxClients)
[Thu Jul 30 12:24:30.946963 2026] [http2:info] [pid 8929:tid 8929] AH03090: mod_http2 (v2.0.42, feats=CHPRIO+SHA256+INVHD+DWINS, nghttp2 1.69.0), initializing...
[Thu Jul 30 12:24:30.950485 2026] [mpm_event:notice] [pid 8929:tid 8929] AH00489: Apache/2.4.68 (cPanel) OpenSSL/3.5.5 Apache mod_qos/11.76 mod_bwlimited/1.4 mod_fcgid/2.3.9 mod_rbld2.0 configured -- resuming normal operations
[Thu Jul 30 12:24:30.950509 2026] [core:notice] [pid 8929:tid 8929] AH00094: Command line: '/usr/sbin/httpd'
[Thu Jul 30 12:24:31.996044 2026] [http2:info] [pid 738779:tid 738779] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 12:24:32.009624 2026] [security2:error] [pid 738779:tid 738909] [client 142.93.53.183:54165] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/navigation-submenu/alfacgiapi/perl.alfa"] [unique_id "amuI0Pxa4UbeLxj1SWW0BAAAAIU"]
[Thu Jul 30 12:24:32.179257 2026] [security2:error] [pid 738779:tid 738913] [client 172.213.232.128:16012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/css/cloud.php"] [unique_id "amuI0Pxa4UbeLxj1SWW0EwAAAIk"]
[Thu Jul 30 12:24:32.399467 2026] [security2:error] [pid 738779:tid 738970] [client 142.93.53.183:55708] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/nextpage/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI0Pxa4UbeLxj1SWW0LwAAAMI"]
[Thu Jul 30 12:24:32.598081 2026] [core:notice] [pid 738779:tid 738989] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:24:32.781162 2026] [security2:error] [pid 738779:tid 738997] [client 142.93.53.183:55807] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/nextpage/alfacgiapi/perl.alfa"] [unique_id "amuI0Pxa4UbeLxj1SWW0NwAAAN0"]
[Thu Jul 30 12:24:32.873945 2026] [security2:error] [pid 738779:tid 738959] [client 57.141.0.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuI0Pxa4UbeLxj1SWW0JgAAALc"]
[Thu Jul 30 12:24:32.880422 2026] [security2:error] [pid 738779:tid 738960] [client 57.141.0.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuI0Pxa4UbeLxj1SWW0KQAAALg"]
[Thu Jul 30 12:24:33.160065 2026] [security2:error] [pid 738779:tid 739020] [client 142.93.53.183:55929] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/page-list/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI0fxa4UbeLxj1SWW0QQAAAPQ"]
[Thu Jul 30 12:24:33.175902 2026] [security2:error] [pid 738779:tid 739019] [client 57.141.0.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuI0fxa4UbeLxj1SWW0QAAAAPM"]
[Thu Jul 30 12:24:33.236382 2026] [security2:error] [pid 738779:tid 738798] [remote 74.7.241.60:54004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/article.php"] [unique_id "amuI0fxa4UbeLxj1SWW0QgAA8BI"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/1784117929_IMG_3676.jpg
[Thu Jul 30 12:24:33.257494 2026] [security2:error] [pid 738779:tid 739015] [client 172.213.232.128:20049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/user/cloud.php"] [unique_id "amuI0fxa4UbeLxj1SWW0QwAAAO8"]
[Thu Jul 30 12:24:33.469118 2026] [security2:error] [pid 738779:tid 738929] [client 2a03:2880:f800:12:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuI0Pxa4UbeLxj1SWW0MgAAmQ0"]
[Thu Jul 30 12:24:33.538830 2026] [security2:error] [pid 738779:tid 739023] [client 146.103.110.13:50914] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "146.103.110.13" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "seven-stars-shop.com"] [uri "/wp-comments-post.php"] [unique_id "amuI0fxa4UbeLxj1SWW0SgAAAPc"], referer: https://seven-stars-shop.com/hello-world/
[Thu Jul 30 12:24:33.538998 2026] [security2:error] [pid 738779:tid 739023] [client 146.103.110.13:50914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "seven-stars-shop.com"] [uri "/wp-comments-post.php"] [unique_id "amuI0fxa4UbeLxj1SWW0SgAAAPc"], referer: https://seven-stars-shop.com/hello-world/
[Thu Jul 30 12:24:33.539476 2026] [security2:error] [pid 738779:tid 738910] [client 142.93.53.183:56034] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/page-list/alfacgiapi/perl.alfa"] [unique_id "amuI0fxa4UbeLxj1SWW0SwAAAIY"]
[Thu Jul 30 12:24:33.763692 2026] [security2:error] [pid 738779:tid 738927] [client 2a03:2880:f800:13:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuI0Pxa4UbeLxj1SWW0NgAAlw4"]
[Thu Jul 30 12:24:33.922144 2026] [security2:error] [pid 738779:tid 738917] [client 142.93.53.183:56131] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/page-list-item/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI0fxa4UbeLxj1SWW0TwAAAI0"]
[Thu Jul 30 12:24:34.311459 2026] [security2:error] [pid 738779:tid 738975] [client 142.93.53.183:56213] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/page-list-item/alfacgiapi/perl.alfa"] [unique_id "amuI0vxa4UbeLxj1SWW0XAAAAMc"]
[Thu Jul 30 12:24:34.491047 2026] [security2:error] [pid 738779:tid 738980] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuI0vxa4UbeLxj1SWW0YgAAAMw"]
[Thu Jul 30 12:24:34.491210 2026] [security2:error] [pid 738779:tid 738980] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuI0vxa4UbeLxj1SWW0YgAAAMw"]
[Thu Jul 30 12:24:34.691137 2026] [security2:error] [pid 738779:tid 738985] [client 142.93.53.183:56292] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/paragraph/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI0vxa4UbeLxj1SWW0ZwAAANE"]
[Thu Jul 30 12:24:34.847040 2026] [security2:error] [pid 738779:tid 738955] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuI0vxa4UbeLxj1SWW0agAAALM"]
[Thu Jul 30 12:24:34.847152 2026] [security2:error] [pid 738779:tid 738955] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuI0vxa4UbeLxj1SWW0agAAALM"]
[Thu Jul 30 12:24:35.072354 2026] [security2:error] [pid 738779:tid 738992] [client 142.93.53.183:56378] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/paragraph/alfacgiapi/perl.alfa"] [unique_id "amuI0_xa4UbeLxj1SWW0cQAAANg"]
[Thu Jul 30 12:24:35.216427 2026] [security2:error] [pid 738779:tid 738999] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/x.php"] [unique_id "amuI0_xa4UbeLxj1SWW0cgAAAN8"]
[Thu Jul 30 12:24:35.216560 2026] [security2:error] [pid 738779:tid 738999] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/x.php"] [unique_id "amuI0_xa4UbeLxj1SWW0cgAAAN8"]
[Thu Jul 30 12:24:35.244125 2026] [security2:error] [pid 738779:tid 738914] [client 20.203.148.31:47142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/aafewc0k.php"] [unique_id "amuI0_xa4UbeLxj1SWW0cwAAAIo"]
[Thu Jul 30 12:24:35.320990 2026] [security2:error] [pid 727775:tid 728010] [client 172.202.44.182:35776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/wp-configs.php"] [unique_id "amuI08DCZkc4BvDXnoDVbQAAAGk"]
[Thu Jul 30 12:24:35.321165 2026] [log_config:warn] [pid 727775:tid 728010] (32)Broken pipe: [client 172.202.44.182:35776] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --suffix=-bytes_log
[Thu Jul 30 12:24:35.321177 2026] [log_config:warn] [pid 727775:tid 728010] (32)Broken pipe: [client 172.202.44.182:35776] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --mainout=/etc/apache2/logs/access_log
[Thu Jul 30 12:24:35.450453 2026] [security2:error] [pid 738779:tid 739004] [client 142.93.53.183:56474] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/pattern/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI0_xa4UbeLxj1SWW0eAAAAOQ"]
[Thu Jul 30 12:24:35.524682 2026] [security2:error] [pid 738779:tid 739000] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/mgrr.php"] [unique_id "amuI0_xa4UbeLxj1SWW0fAAAAOA"]
[Thu Jul 30 12:24:35.524801 2026] [security2:error] [pid 738779:tid 739000] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/mgrr.php"] [unique_id "amuI0_xa4UbeLxj1SWW0fAAAAOA"]
[Thu Jul 30 12:24:35.632248 2026] [core:notice] [pid 738779:tid 738815] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:24:35.829240 2026] [security2:error] [pid 738779:tid 739018] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/domvf.php"] [unique_id "amuI0_xa4UbeLxj1SWW0ggAAAPI"]
[Thu Jul 30 12:24:35.829352 2026] [security2:error] [pid 738779:tid 739018] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/domvf.php"] [unique_id "amuI0_xa4UbeLxj1SWW0ggAAAPI"]
[Thu Jul 30 12:24:35.842119 2026] [security2:error] [pid 738779:tid 739022] [client 142.93.53.183:56572] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/pattern/alfacgiapi/perl.alfa"] [unique_id "amuI0_xa4UbeLxj1SWW0gwAAAPY"]
[Thu Jul 30 12:24:36.162208 2026] [security2:error] [pid 738779:tid 739036] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/yup.php"] [unique_id "amuI1Pxa4UbeLxj1SWW0jQAAAQQ"]
[Thu Jul 30 12:24:36.162320 2026] [security2:error] [pid 738779:tid 739036] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/yup.php"] [unique_id "amuI1Pxa4UbeLxj1SWW0jQAAAQQ"]
[Thu Jul 30 12:24:36.215800 2026] [security2:error] [pid 738779:tid 738937] [client 142.93.53.183:56675] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-author/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI1Pxa4UbeLxj1SWW0jgAAAKE"]
[Thu Jul 30 12:24:36.445220 2026] [security2:error] [pid 738779:tid 738927] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/X.php"] [unique_id "amuI1Pxa4UbeLxj1SWW0jwAAAJc"]
[Thu Jul 30 12:24:36.445361 2026] [security2:error] [pid 738779:tid 738927] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/X.php"] [unique_id "amuI1Pxa4UbeLxj1SWW0jwAAAJc"]
[Thu Jul 30 12:24:36.492777 2026] [security2:error] [pid 738779:tid 738958] [client 172.213.232.128:43624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/img/cloud.php"] [unique_id "amuI1Pxa4UbeLxj1SWW0kAAAALY"]
[Thu Jul 30 12:24:36.596931 2026] [security2:error] [pid 738779:tid 738943] [client 142.93.53.183:56775] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-author/alfacgiapi/perl.alfa"] [unique_id "amuI1Pxa4UbeLxj1SWW0lAAAAKc"]
[Thu Jul 30 12:24:36.622158 2026] [security2:error] [pid 738779:tid 739031] [client 38.190.144.4:33419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuI1Pxa4UbeLxj1SWW0mAAAAP8"]
[Thu Jul 30 12:24:36.622276 2026] [security2:error] [pid 738779:tid 739031] [client 38.190.144.4:33419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuI1Pxa4UbeLxj1SWW0mAAAAP8"]
[Thu Jul 30 12:24:36.725094 2026] [security2:error] [pid 738779:tid 738964] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amuI1Pxa4UbeLxj1SWW0nAAAALw"]
[Thu Jul 30 12:24:36.725215 2026] [security2:error] [pid 738779:tid 738964] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amuI1Pxa4UbeLxj1SWW0nAAAALw"]
[Thu Jul 30 12:24:36.975343 2026] [security2:error] [pid 738779:tid 738945] [client 142.93.53.183:56876] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-author-biography/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI1Pxa4UbeLxj1SWW0nQAAAKk"]
[Thu Jul 30 12:24:37.025665 2026] [security2:error] [pid 738779:tid 738946] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/gec.php"] [unique_id "amuI1fxa4UbeLxj1SWW0nwAAAKo"]
[Thu Jul 30 12:24:37.025791 2026] [security2:error] [pid 738779:tid 738946] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/gec.php"] [unique_id "amuI1fxa4UbeLxj1SWW0nwAAAKo"]
[Thu Jul 30 12:24:37.318113 2026] [security2:error] [pid 738779:tid 738985] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/sky.php"] [unique_id "amuI1fxa4UbeLxj1SWW0qQAAANE"]
[Thu Jul 30 12:24:37.318230 2026] [security2:error] [pid 738779:tid 738985] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/sky.php"] [unique_id "amuI1fxa4UbeLxj1SWW0qQAAANE"]
[Thu Jul 30 12:24:37.351588 2026] [security2:error] [pid 738779:tid 738986] [client 142.93.53.183:56964] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-author-biography/alfacgiapi/perl.alfa"] [unique_id "amuI1fxa4UbeLxj1SWW0qgAAANI"]
[Thu Jul 30 12:24:37.590182 2026] [security2:error] [pid 738779:tid 738991] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/fffm.php"] [unique_id "amuI1fxa4UbeLxj1SWW0rwAAANc"]
[Thu Jul 30 12:24:37.590362 2026] [security2:error] [pid 738779:tid 738991] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/fffm.php"] [unique_id "amuI1fxa4UbeLxj1SWW0rwAAANc"]
[Thu Jul 30 12:24:37.639762 2026] [security2:error] [pid 738779:tid 738966] [client 146.103.110.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "smoke-tfhk.com"] [uri "/index.php"] [unique_id "amuI1Pxa4UbeLxj1SWW0mwAAAL4"], referer: http://smoke-tfhk.com/hello-world/
[Thu Jul 30 12:24:37.734179 2026] [security2:error] [pid 738779:tid 739000] [client 142.93.53.183:57035] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-author-name/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI1fxa4UbeLxj1SWW0tAAAAOA"]
[Thu Jul 30 12:24:37.871928 2026] [security2:error] [pid 738779:tid 739005] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/sixxis.php"] [unique_id "amuI1fxa4UbeLxj1SWW0tQAAAOU"]
[Thu Jul 30 12:24:37.872078 2026] [security2:error] [pid 738779:tid 739005] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/sixxis.php"] [unique_id "amuI1fxa4UbeLxj1SWW0tQAAAOU"]
[Thu Jul 30 12:24:37.919150 2026] [core:notice] [pid 738779:tid 738978] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:24:37.974918 2026] [security2:error] [pid 738779:tid 738981] [client 185.191.171.14:58486] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/03/02/walber-virgolino-avisa-que-preferencias-de-bolsonaro-na-paraiba-nao-dividem-nem-enfraquecem-direita-votamos-no-projeto/"] [unique_id "amuI1fxa4UbeLxj1SWW0twAAAM0"]
[Thu Jul 30 12:24:37.975108 2026] [security2:error] [pid 738779:tid 738981] [client 185.191.171.14:58486] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/03/02/walber-virgolino-avisa-que-preferencias-de-bolsonaro-na-paraiba-nao-dividem-nem-enfraquecem-direita-votamos-no-projeto/"] [unique_id "amuI1fxa4UbeLxj1SWW0twAAAM0"]
[Thu Jul 30 12:24:38.124707 2026] [security2:error] [pid 738779:tid 739009] [client 142.93.53.183:57075] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-author-name/alfacgiapi/perl.alfa"] [unique_id "amuI1vxa4UbeLxj1SWW0uwAAAOk"]
[Thu Jul 30 12:24:38.150029 2026] [security2:error] [pid 738779:tid 739021] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/yj09.php"] [unique_id "amuI1vxa4UbeLxj1SWW0vAAAAPU"]
[Thu Jul 30 12:24:38.150142 2026] [security2:error] [pid 738779:tid 739021] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/yj09.php"] [unique_id "amuI1vxa4UbeLxj1SWW0vAAAAPU"]
[Thu Jul 30 12:24:38.178223 2026] [security2:error] [pid 738779:tid 739034] [client 20.203.148.31:47800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/abcd.php"] [unique_id "amuI1vxa4UbeLxj1SWW0vgAAAQI"]
[Thu Jul 30 12:24:38.468111 2026] [security2:error] [pid 738779:tid 739030] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/k.php"] [unique_id "amuI1vxa4UbeLxj1SWW0wgAAAP4"]
[Thu Jul 30 12:24:38.468238 2026] [security2:error] [pid 738779:tid 739030] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/k.php"] [unique_id "amuI1vxa4UbeLxj1SWW0wgAAAP4"]
[Thu Jul 30 12:24:38.512834 2026] [security2:error] [pid 738779:tid 739023] [client 142.93.53.183:57122] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-comments-form/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI1vxa4UbeLxj1SWW0wwAAAPc"]
[Thu Jul 30 12:24:38.567693 2026] [security2:error] [pid 738779:tid 739028] [client 172.202.44.182:14132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/php.php"] [unique_id "amuI1vxa4UbeLxj1SWW0xAAAAPw"]
[Thu Jul 30 12:24:38.753255 2026] [security2:error] [pid 738779:tid 738952] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/k2.php"] [unique_id "amuI1vxa4UbeLxj1SWW0ywAAALA"]
[Thu Jul 30 12:24:38.753350 2026] [security2:error] [pid 738779:tid 738952] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/k2.php"] [unique_id "amuI1vxa4UbeLxj1SWW0ywAAALA"]
[Thu Jul 30 12:24:38.886596 2026] [security2:error] [pid 738779:tid 738962] [client 142.93.53.183:57156] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-comments-form/alfacgiapi/perl.alfa"] [unique_id "amuI1vxa4UbeLxj1SWW0zgAAALo"]
[Thu Jul 30 12:24:39.025667 2026] [security2:error] [pid 738779:tid 738969] [client 172.213.232.128:14252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "amuI1_xa4UbeLxj1SWW00AAAAME"]
[Thu Jul 30 12:24:39.064281 2026] [security2:error] [pid 738779:tid 738923] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/w.php"] [unique_id "amuI1_xa4UbeLxj1SWW01AAAAJM"]
[Thu Jul 30 12:24:39.064429 2026] [security2:error] [pid 738779:tid 738923] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/w.php"] [unique_id "amuI1_xa4UbeLxj1SWW01AAAAJM"]
[Thu Jul 30 12:24:39.221357 2026] [security2:error] [pid 738779:tid 739036] [client 52.167.144.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "itrnetwork.org"] [uri "/index.php"] [unique_id "amuI1vxa4UbeLxj1SWW0zwABBDM"], referer: https://itrnetwork.org/category/photography/
[Thu Jul 30 12:24:39.266337 2026] [security2:error] [pid 738779:tid 738930] [client 142.93.53.183:57202] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-content/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI1_xa4UbeLxj1SWW03gAAAJo"]
[Thu Jul 30 12:24:39.351093 2026] [security2:error] [pid 738779:tid 738987] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/fpwch.php"] [unique_id "amuI1_xa4UbeLxj1SWW03wAAANM"]
[Thu Jul 30 12:24:39.351215 2026] [security2:error] [pid 738779:tid 738987] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/fpwch.php"] [unique_id "amuI1_xa4UbeLxj1SWW03wAAANM"]
[Thu Jul 30 12:24:39.646503 2026] [security2:error] [pid 738779:tid 738994] [client 142.93.53.183:57244] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-content/alfacgiapi/perl.alfa"] [unique_id "amuI1_xa4UbeLxj1SWW04AAAANo"]
[Thu Jul 30 12:24:39.700078 2026] [security2:error] [pid 738779:tid 738997] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/w2025.php"] [unique_id "amuI1_xa4UbeLxj1SWW05AAAAN0"]
[Thu Jul 30 12:24:39.700175 2026] [security2:error] [pid 738779:tid 738997] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/w2025.php"] [unique_id "amuI1_xa4UbeLxj1SWW05AAAAN0"]
[Thu Jul 30 12:24:39.984724 2026] [security2:error] [pid 738779:tid 738992] [client 172.213.232.128:4704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/images/cloud.php"] [unique_id "amuI1_xa4UbeLxj1SWW06wAAANg"]
[Thu Jul 30 12:24:39.986490 2026] [security2:error] [pid 738779:tid 739011] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/FWAZ.php"] [unique_id "amuI1_xa4UbeLxj1SWW07AAAAOs"]
[Thu Jul 30 12:24:39.986587 2026] [security2:error] [pid 738779:tid 739011] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/FWAZ.php"] [unique_id "amuI1_xa4UbeLxj1SWW07AAAAOs"]
[Thu Jul 30 12:24:40.028586 2026] [security2:error] [pid 738779:tid 738948] [client 142.93.53.183:57281] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-date/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI2Pxa4UbeLxj1SWW07QAAAKw"]
[Thu Jul 30 12:24:40.057701 2026] [security2:error] [pid 738779:tid 738918] [client 20.203.148.31:47806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/about.php"] [unique_id "amuI2Pxa4UbeLxj1SWW07gAAAI4"]
[Thu Jul 30 12:24:40.078318 2026] [security2:error] [pid 738779:tid 739003] [client 220.181.108.101:41423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.108.181.220.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/aded-a-accompagne-et-appuye-le-comite-de-pilotage-rbc-de-la-zs-duvira-dans-le-processus-delaboration-et-de-la-mise-en-oeuvre-dun-plan-daction-2024/index.php"] [unique_id "amuI1_xa4UbeLxj1SWW06QAAAOM"]
[Thu Jul 30 12:24:40.272640 2026] [security2:error] [pid 738779:tid 739012] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/qterm.php"] [unique_id "amuI2Pxa4UbeLxj1SWW08wAAAOw"]
[Thu Jul 30 12:24:40.272751 2026] [security2:error] [pid 738779:tid 739012] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/qterm.php"] [unique_id "amuI2Pxa4UbeLxj1SWW08wAAAOw"]
[Thu Jul 30 12:24:40.422101 2026] [security2:error] [pid 738779:tid 739008] [client 142.93.53.183:57321] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-date/alfacgiapi/perl.alfa"] [unique_id "amuI2Pxa4UbeLxj1SWW09wAAAOg"]
[Thu Jul 30 12:24:40.507416 2026] [security2:error] [pid 738779:tid 739030] [client 119.249.100.53:60906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.100.249.119.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/aded-a-accompagne-et-appuye-le-comite-de-pilotage-rbc-de-la-zs-duvira-dans-le-processus-delaboration-et-de-la-mise-en-oeuvre-dun-plan-daction-2024/index.php"] [unique_id "amuI2Pxa4UbeLxj1SWW0-AAAAP4"]
[Thu Jul 30 12:24:40.546221 2026] [security2:error] [pid 738779:tid 739033] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/blurbs.php"] [unique_id "amuI2Pxa4UbeLxj1SWW0-QAAAQE"]
[Thu Jul 30 12:24:40.546340 2026] [security2:error] [pid 738779:tid 739033] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/blurbs.php"] [unique_id "amuI2Pxa4UbeLxj1SWW0-QAAAQE"]
[Thu Jul 30 12:24:40.638534 2026] [security2:error] [pid 738779:tid 739027] [client 172.213.232.128:4713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/avaa.php"] [unique_id "amuI2Pxa4UbeLxj1SWW0-wAAAPs"]
[Thu Jul 30 12:24:40.668810 2026] [security2:error] [pid 738779:tid 739009] [client 172.202.44.182:17498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/wp-includes/index.php"] [unique_id "amuI2Pxa4UbeLxj1SWW0_AAAAOk"]
[Thu Jul 30 12:24:40.812692 2026] [security2:error] [pid 738779:tid 738917] [client 142.93.53.183:57362] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-excerpt/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI2Pxa4UbeLxj1SWW1AQAAAI0"]
[Thu Jul 30 12:24:40.832705 2026] [security2:error] [pid 738779:tid 738958] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-ws68.php"] [unique_id "amuI2Pxa4UbeLxj1SWW1BAAAALY"]
[Thu Jul 30 12:24:40.832781 2026] [security2:error] [pid 738779:tid 738958] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-ws68.php"] [unique_id "amuI2Pxa4UbeLxj1SWW1BAAAALY"]
[Thu Jul 30 12:24:40.869867 2026] [security2:error] [pid 738779:tid 739031] [client 119.249.100.116:35182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.100.249.119.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/aded-a-accompagne-et-appuye-le-comite-de-pilotage-rbc-de-la-zs-duvira-dans-le-processus-delaboration-et-de-la-mise-en-oeuvre-dun-plan-daction-2024/index.php"] [unique_id "amuI2Pxa4UbeLxj1SWW1BQAAAP8"]
[Thu Jul 30 12:24:40.999718 2026] [security2:error] [pid 738779:tid 738843] [remote 57.141.0.49:50322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuI2Pxa4UbeLxj1SWW1CQAAhT8"]
[Thu Jul 30 12:24:41.104079 2026] [security2:error] [pid 738779:tid 738965] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/xyn.php"] [unique_id "amuI2fxa4UbeLxj1SWW1CgAAAL0"]
[Thu Jul 30 12:24:41.104223 2026] [security2:error] [pid 738779:tid 738965] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/xyn.php"] [unique_id "amuI2fxa4UbeLxj1SWW1CgAAAL0"]
[Thu Jul 30 12:24:41.202730 2026] [security2:error] [pid 738779:tid 738973] [client 142.93.53.183:57408] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-excerpt/alfacgiapi/perl.alfa"] [unique_id "amuI2fxa4UbeLxj1SWW1CwAAAMU"]
[Thu Jul 30 12:24:41.386678 2026] [security2:error] [pid 738779:tid 738979] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/ccc.php"] [unique_id "amuI2fxa4UbeLxj1SWW1EgAAAMs"]
[Thu Jul 30 12:24:41.386796 2026] [security2:error] [pid 738779:tid 738979] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/ccc.php"] [unique_id "amuI2fxa4UbeLxj1SWW1EgAAAMs"]
[Thu Jul 30 12:24:41.593793 2026] [security2:error] [pid 738779:tid 738983] [client 142.93.53.183:57442] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-featured-image/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI2fxa4UbeLxj1SWW1FAAAAM8"]
[Thu Jul 30 12:24:41.728558 2026] [security2:error] [pid 738779:tid 738977] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/get.php"] [unique_id "amuI2fxa4UbeLxj1SWW1GAAAAMk"]
[Thu Jul 30 12:24:41.728717 2026] [security2:error] [pid 738779:tid 738977] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/get.php"] [unique_id "amuI2fxa4UbeLxj1SWW1GAAAAMk"]
[Thu Jul 30 12:24:41.967252 2026] [security2:error] [pid 738779:tid 738996] [client 142.93.53.183:57486] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-featured-image/alfacgiapi/perl.alfa"] [unique_id "amuI2fxa4UbeLxj1SWW1IAAAANw"]
[Thu Jul 30 12:24:42.058922 2026] [security2:error] [pid 738779:tid 738953] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/images.php"] [unique_id "amuI2vxa4UbeLxj1SWW1IQAAALE"]
[Thu Jul 30 12:24:42.059055 2026] [security2:error] [pid 738779:tid 738953] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/images.php"] [unique_id "amuI2vxa4UbeLxj1SWW1IQAAALE"]
[Thu Jul 30 12:24:42.317387 2026] [security2:error] [pid 738779:tid 738968] [client 172.202.44.182:17503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/wp-admin/a.php"] [unique_id "amuI2vxa4UbeLxj1SWW1KQAAAMA"]
[Thu Jul 30 12:24:42.339923 2026] [security2:error] [pid 738779:tid 739000] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/alls.php"] [unique_id "amuI2vxa4UbeLxj1SWW1KgAAAOA"]
[Thu Jul 30 12:24:42.340064 2026] [security2:error] [pid 738779:tid 739000] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/alls.php"] [unique_id "amuI2vxa4UbeLxj1SWW1KgAAAOA"]
[Thu Jul 30 12:24:42.358781 2026] [security2:error] [pid 738779:tid 739011] [client 142.93.53.183:57520] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-navigation-link/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI2vxa4UbeLxj1SWW1KwAAAOs"]
[Thu Jul 30 12:24:42.506334 2026] [security2:error] [pid 738779:tid 738970] [client 2a03:2880:f800:2:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuI2fxa4UbeLxj1SWW1HwAAwkY"]
[Thu Jul 30 12:24:42.659420 2026] [security2:error] [pid 738779:tid 739012] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/coffexium.php"] [unique_id "amuI2vxa4UbeLxj1SWW1MwAAAOw"]
[Thu Jul 30 12:24:42.659530 2026] [security2:error] [pid 738779:tid 739012] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/coffexium.php"] [unique_id "amuI2vxa4UbeLxj1SWW1MwAAAOw"]
[Thu Jul 30 12:24:42.660411 2026] [core:notice] [pid 738779:tid 738981] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:24:42.734205 2026] [security2:error] [pid 738779:tid 739021] [client 142.93.53.183:57557] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-navigation-link/alfacgiapi/perl.alfa"] [unique_id "amuI2vxa4UbeLxj1SWW1NAAAAPU"]
[Thu Jul 30 12:24:42.744956 2026] [security2:error] [pid 738779:tid 739002] [client 57.141.0.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuI2vxa4UbeLxj1SWW1JQAAAOI"]
[Thu Jul 30 12:24:42.948993 2026] [security2:error] [pid 738779:tid 739028] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/red.php"] [unique_id "amuI2vxa4UbeLxj1SWW1OwAAAPw"]
[Thu Jul 30 12:24:42.949113 2026] [security2:error] [pid 738779:tid 739028] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/red.php"] [unique_id "amuI2vxa4UbeLxj1SWW1OwAAAPw"]
[Thu Jul 30 12:24:43.067101 2026] [security2:error] [pid 738779:tid 738957] [client 172.213.232.128:12338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/images/cloud.php"] [unique_id "amuI2_xa4UbeLxj1SWW1PAAAALU"]
[Thu Jul 30 12:24:43.124464 2026] [security2:error] [pid 738779:tid 738915] [client 142.93.53.183:57582] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-template/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI2_xa4UbeLxj1SWW1PQAAAIs"]
[Thu Jul 30 12:24:43.220997 2026] [security2:error] [pid 738779:tid 739008] [client 20.203.148.31:45273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/admin.php"] [unique_id "amuI2_xa4UbeLxj1SWW1PwAAAOg"]
[Thu Jul 30 12:24:43.356058 2026] [security2:error] [pid 738779:tid 738944] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-includes/sodium_compat/"] [unique_id "amuI2_xa4UbeLxj1SWW1QAAAAKg"]
[Thu Jul 30 12:24:43.497817 2026] [security2:error] [pid 738779:tid 738921] [client 142.93.53.183:57616] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-template/alfacgiapi/perl.alfa"] [unique_id "amuI2_xa4UbeLxj1SWW1SAAAAJE"]
[Thu Jul 30 12:24:43.526750 2026] [security2:error] [pid 738779:tid 738969] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amuI2_xa4UbeLxj1SWW1SgAAAME"]
[Thu Jul 30 12:24:43.526852 2026] [security2:error] [pid 738779:tid 738969] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amuI2_xa4UbeLxj1SWW1SgAAAME"]
[Thu Jul 30 12:24:43.781183 2026] [core:notice] [pid 738779:tid 738861] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:24:43.814504 2026] [security2:error] [pid 738779:tid 738946] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-includes/Text/"] [unique_id "amuI2_xa4UbeLxj1SWW1TwAAAKo"]
[Thu Jul 30 12:24:43.867794 2026] [security2:error] [pid 738779:tid 738973] [client 172.213.232.128:23332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/js/widgets/cloud.php"] [unique_id "amuI2_xa4UbeLxj1SWW1UAAAAMU"]
[Thu Jul 30 12:24:43.875471 2026] [security2:error] [pid 738779:tid 738919] [client 142.93.53.183:57641] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-terms/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI2_xa4UbeLxj1SWW1UQAAAI8"]
[Thu Jul 30 12:24:43.983187 2026] [security2:error] [pid 738779:tid 739036] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-content/uploads/"] [unique_id "amuI2_xa4UbeLxj1SWW1VgAAAQQ"]
[Thu Jul 30 12:24:44.011502 2026] [security2:error] [pid 738779:tid 738967] [client 20.203.148.31:46510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/adminfuns.php"] [unique_id "amuI3Pxa4UbeLxj1SWW1WgAAAL8"]
[Thu Jul 30 12:24:44.125972 2026] [security2:error] [pid 738779:tid 738956] [client 172.202.44.182:42035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuI3Pxa4UbeLxj1SWW1WwAAALQ"]
[Thu Jul 30 12:24:44.144915 2026] [security2:error] [pid 738779:tid 738990] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-content/index.php"] [unique_id "amuI3Pxa4UbeLxj1SWW1XAAAANY"]
[Thu Jul 30 12:24:44.145101 2026] [security2:error] [pid 738779:tid 738990] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-content/index.php"] [unique_id "amuI3Pxa4UbeLxj1SWW1XAAAANY"]
[Thu Jul 30 12:24:44.249852 2026] [security2:error] [pid 738779:tid 738950] [client 142.93.53.183:57680] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-terms/alfacgiapi/perl.alfa"] [unique_id "amuI3Pxa4UbeLxj1SWW1XgAAAK4"]
[Thu Jul 30 12:24:44.432376 2026] [security2:error] [pid 738779:tid 738997] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/admin.php"] [unique_id "amuI3Pxa4UbeLxj1SWW1YAAAAN0"]
[Thu Jul 30 12:24:44.432490 2026] [security2:error] [pid 738779:tid 738997] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/admin.php"] [unique_id "amuI3Pxa4UbeLxj1SWW1YAAAAN0"]
[Thu Jul 30 12:24:44.640500 2026] [security2:error] [pid 738779:tid 739007] [client 142.93.53.183:57706] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-title/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI3Pxa4UbeLxj1SWW1ZwAAAOc"]
[Thu Jul 30 12:24:44.680186 2026] [security2:error] [pid 738779:tid 738991] [client 172.213.232.128:36347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/Requests/Text/admin.php"] [unique_id "amuI3Pxa4UbeLxj1SWW1aAAAANc"]
[Thu Jul 30 12:24:44.715872 2026] [security2:error] [pid 738779:tid 738992] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/177.php"] [unique_id "amuI3Pxa4UbeLxj1SWW1agAAANg"]
[Thu Jul 30 12:24:44.715966 2026] [security2:error] [pid 738779:tid 738992] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/177.php"] [unique_id "amuI3Pxa4UbeLxj1SWW1agAAANg"]
[Thu Jul 30 12:24:45.016895 2026] [security2:error] [pid 738779:tid 738978] [client 142.93.53.183:57741] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-title/alfacgiapi/perl.alfa"] [unique_id "amuI3fxa4UbeLxj1SWW1cQAAAMo"]
[Thu Jul 30 12:24:45.023777 2026] [security2:error] [pid 738779:tid 738981] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/199.php"] [unique_id "amuI3fxa4UbeLxj1SWW1cwAAAM0"]
[Thu Jul 30 12:24:45.023864 2026] [security2:error] [pid 738779:tid 738981] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/199.php"] [unique_id "amuI3fxa4UbeLxj1SWW1cwAAAM0"]
[Thu Jul 30 12:24:45.255879 2026] [security2:error] [pid 738779:tid 738989] [client 172.213.232.128:36334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "amuI3fxa4UbeLxj1SWW1eAAAANU"]
[Thu Jul 30 12:24:45.329489 2026] [security2:error] [pid 738779:tid 739030] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/file52.php"] [unique_id "amuI3fxa4UbeLxj1SWW1fAAAAP4"]
[Thu Jul 30 12:24:45.329612 2026] [security2:error] [pid 738779:tid 739030] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/file52.php"] [unique_id "amuI3fxa4UbeLxj1SWW1fAAAAP4"]
[Thu Jul 30 12:24:45.354137 2026] [security2:error] [pid 738779:tid 738994] [client 20.203.148.31:39643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/albin.php"] [unique_id "amuI3fxa4UbeLxj1SWW1fQAAANo"]
[Thu Jul 30 12:24:45.406015 2026] [security2:error] [pid 738779:tid 739009] [client 142.93.53.183:57775] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/preformatted/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI3fxa4UbeLxj1SWW1fgAAAOk"]
[Thu Jul 30 12:24:45.411740 2026] [security2:error] [pid 738779:tid 739019] [client 40.77.167.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "itrnetwork.org"] [uri "/index.php"] [unique_id "amuI3fxa4UbeLxj1SWW1dgAA81s"], referer: https://itrnetwork.org/category/photography/
[Thu Jul 30 12:24:45.677099 2026] [security2:error] [pid 738779:tid 739018] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/geck.php"] [unique_id "amuI3fxa4UbeLxj1SWW1hgAAAPI"]
[Thu Jul 30 12:24:45.677216 2026] [security2:error] [pid 738779:tid 739018] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/geck.php"] [unique_id "amuI3fxa4UbeLxj1SWW1hgAAAPI"]
[Thu Jul 30 12:24:45.798153 2026] [security2:error] [pid 738779:tid 738949] [client 142.93.53.183:57812] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/preformatted/alfacgiapi/perl.alfa"] [unique_id "amuI3fxa4UbeLxj1SWW1iAAAAK0"]
[Thu Jul 30 12:24:45.970499 2026] [security2:error] [pid 738779:tid 738932] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/biufile.php"] [unique_id "amuI3fxa4UbeLxj1SWW1jAAAAJw"]
[Thu Jul 30 12:24:45.970625 2026] [security2:error] [pid 738779:tid 738932] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/biufile.php"] [unique_id "amuI3fxa4UbeLxj1SWW1jAAAAJw"]
[Thu Jul 30 12:24:46.171493 2026] [security2:error] [pid 738779:tid 738983] [client 142.93.53.183:57846] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/pullquote/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI3vxa4UbeLxj1SWW1lAAAAM8"]
[Thu Jul 30 12:24:46.246534 2026] [security2:error] [pid 738779:tid 738955] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/dejavu.php"] [unique_id "amuI3vxa4UbeLxj1SWW1lQAAALM"]
[Thu Jul 30 12:24:46.246639 2026] [security2:error] [pid 738779:tid 738955] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/dejavu.php"] [unique_id "amuI3vxa4UbeLxj1SWW1lQAAALM"]
[Thu Jul 30 12:24:46.345580 2026] [security2:error] [pid 738779:tid 739029] [client 172.202.44.182:13510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/wp-admin.php"] [unique_id "amuI3vxa4UbeLxj1SWW1lgAAAP0"]
[Thu Jul 30 12:24:46.511078 2026] [security2:error] [pid 738779:tid 738954] [client 57.141.0.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuI3vxa4UbeLxj1SWW1mQAAALI"]
[Thu Jul 30 12:24:46.531662 2026] [security2:error] [pid 738779:tid 738951] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/aaf.php"] [unique_id "amuI3vxa4UbeLxj1SWW1mgAAAK8"]
[Thu Jul 30 12:24:46.531780 2026] [security2:error] [pid 738779:tid 738951] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/aaf.php"] [unique_id "amuI3vxa4UbeLxj1SWW1mgAAAK8"]
[Thu Jul 30 12:24:46.552643 2026] [security2:error] [pid 738779:tid 738912] [client 142.93.53.183:57865] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/pullquote/alfacgiapi/perl.alfa"] [unique_id "amuI3vxa4UbeLxj1SWW1nQAAAIg"]
[Thu Jul 30 12:24:46.832803 2026] [security2:error] [pid 738779:tid 739004] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/ha.php"] [unique_id "amuI3vxa4UbeLxj1SWW1ogAAAOQ"]
[Thu Jul 30 12:24:46.832900 2026] [security2:error] [pid 738779:tid 739004] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/ha.php"] [unique_id "amuI3vxa4UbeLxj1SWW1ogAAAOQ"]
[Thu Jul 30 12:24:46.875212 2026] [security2:error] [pid 738779:tid 738961] [client 172.213.232.128:12306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/includes/cloud.php"] [unique_id "amuI3vxa4UbeLxj1SWW1owAAALk"]
[Thu Jul 30 12:24:46.929654 2026] [security2:error] [pid 738779:tid 739006] [client 142.93.53.183:57892] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/query/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI3vxa4UbeLxj1SWW1pAAAAOY"]
[Thu Jul 30 12:24:47.123755 2026] [security2:error] [pid 738779:tid 738993] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/hur.php"] [unique_id "amuI3_xa4UbeLxj1SWW1qAAAANk"]
[Thu Jul 30 12:24:47.123865 2026] [security2:error] [pid 738779:tid 738993] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/hur.php"] [unique_id "amuI3_xa4UbeLxj1SWW1qAAAANk"]
[Thu Jul 30 12:24:47.271791 2026] [security2:error] [pid 738779:tid 738930] [client 20.203.148.31:47747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/amfsqvgv.php"] [unique_id "amuI3_xa4UbeLxj1SWW1rAAAAJo"]
[Thu Jul 30 12:24:47.279715 2026] [security2:error] [pid 738779:tid 739001] [client 172.202.44.182:17500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/size.php"] [unique_id "amuI3_xa4UbeLxj1SWW1rQAAAOE"]
[Thu Jul 30 12:24:47.310856 2026] [security2:error] [pid 738779:tid 738970] [client 142.93.53.183:57920] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/query/alfacgiapi/perl.alfa"] [unique_id "amuI3_xa4UbeLxj1SWW1rgAAAMI"]
[Thu Jul 30 12:24:47.346276 2026] [security2:error] [pid 738779:tid 738959] [client 66.249.66.8:44373] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "mogomogolessons4.com"] [uri "/robots.txt"] [unique_id "amuI3_xa4UbeLxj1SWW1rwAAALc"]
[Thu Jul 30 12:24:47.403737 2026] [security2:error] [pid 738779:tid 738978] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/h02ugyh.php"] [unique_id "amuI3_xa4UbeLxj1SWW1sAAAAMo"]
[Thu Jul 30 12:24:47.403847 2026] [security2:error] [pid 738779:tid 738978] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/h02ugyh.php"] [unique_id "amuI3_xa4UbeLxj1SWW1sAAAAMo"]
[Thu Jul 30 12:24:47.704000 2026] [security2:error] [pid 738779:tid 738989] [client 142.93.53.183:57954] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/query-no-results/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI3_xa4UbeLxj1SWW1uAAAANU"]
[Thu Jul 30 12:24:47.715740 2026] [security2:error] [pid 738779:tid 739030] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/155.php"] [unique_id "amuI3_xa4UbeLxj1SWW1uQAAAP4"]
[Thu Jul 30 12:24:47.715820 2026] [security2:error] [pid 738779:tid 739030] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/155.php"] [unique_id "amuI3_xa4UbeLxj1SWW1uQAAAP4"]
[Thu Jul 30 12:24:47.985498 2026] [security2:error] [pid 738779:tid 738913] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/ops.php"] [unique_id "amuI3_xa4UbeLxj1SWW1ugAAAIk"]
[Thu Jul 30 12:24:47.985650 2026] [security2:error] [pid 738779:tid 738913] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/ops.php"] [unique_id "amuI3_xa4UbeLxj1SWW1ugAAAIk"]
[Thu Jul 30 12:24:48.091618 2026] [security2:error] [pid 738779:tid 739025] [client 142.93.53.183:57982] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/query-no-results/alfacgiapi/perl.alfa"] [unique_id "amuI4Pxa4UbeLxj1SWW1vAAAAPk"]
[Thu Jul 30 12:24:48.254191 2026] [security2:error] [pid 738779:tid 738936] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/ingfo.php"] [unique_id "amuI4Pxa4UbeLxj1SWW1xAAAAKA"]
[Thu Jul 30 12:24:48.254299 2026] [security2:error] [pid 738779:tid 738936] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/ingfo.php"] [unique_id "amuI4Pxa4UbeLxj1SWW1xAAAAKA"]
[Thu Jul 30 12:24:48.321149 2026] [security2:error] [pid 738779:tid 738926] [client 172.213.232.128:14260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/css/colors/blue/cloud.php"] [unique_id "amuI4Pxa4UbeLxj1SWW1xQAAAJY"]
[Thu Jul 30 12:24:48.397082 2026] [security2:error] [pid 738779:tid 738890] [remote 165.101.188.2:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.188.101.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "echomemoversalain.casa"] [uri "/wp/wp-login.php"] [unique_id "amuI4Pxa4UbeLxj1SWW1wAABAW4"]
[Thu Jul 30 12:24:48.470411 2026] [security2:error] [pid 738779:tid 738921] [client 142.93.53.183:58009] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/query-pagination/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI4Pxa4UbeLxj1SWW1xgAAAJE"]
[Thu Jul 30 12:24:48.528168 2026] [security2:error] [pid 738779:tid 738971] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/error_log.php"] [unique_id "amuI4Pxa4UbeLxj1SWW1xwAAAMM"]
[Thu Jul 30 12:24:48.528297 2026] [security2:error] [pid 738779:tid 738971] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/error_log.php"] [unique_id "amuI4Pxa4UbeLxj1SWW1xwAAAMM"]
[Thu Jul 30 12:24:48.852412 2026] [security2:error] [pid 738779:tid 738975] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/koala.php"] [unique_id "amuI4Pxa4UbeLxj1SWW1zgAAAMc"]
[Thu Jul 30 12:24:48.852534 2026] [security2:error] [pid 738779:tid 738975] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/koala.php"] [unique_id "amuI4Pxa4UbeLxj1SWW1zgAAAMc"]
[Thu Jul 30 12:24:48.858827 2026] [security2:error] [pid 738779:tid 738933] [client 142.93.53.183:58039] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/query-pagination/alfacgiapi/perl.alfa"] [unique_id "amuI4Pxa4UbeLxj1SWW1zwAAAJ0"]
[Thu Jul 30 12:24:49.015361 2026] [security2:error] [pid 738779:tid 738909] [client 172.213.232.128:18971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/cloud.php"] [unique_id "amuI4fxa4UbeLxj1SWW10AAAAIU"]
[Thu Jul 30 12:24:49.025360 2026] [security2:error] [pid 738779:tid 738924] [client 38.190.144.4:59900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuI4fxa4UbeLxj1SWW10QAAAJQ"]
[Thu Jul 30 12:24:49.025512 2026] [security2:error] [pid 738779:tid 738924] [client 38.190.144.4:59900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuI4fxa4UbeLxj1SWW10QAAAJQ"]
[Thu Jul 30 12:24:49.173458 2026] [security2:error] [pid 738779:tid 738979] [client 172.202.44.182:17605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/wp-includes/wp-class.php"] [unique_id "amuI4fxa4UbeLxj1SWW11AAAAMs"]
[Thu Jul 30 12:24:49.175233 2026] [security2:error] [pid 738779:tid 738910] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/mac.php"] [unique_id "amuI4fxa4UbeLxj1SWW11QAAAIY"]
[Thu Jul 30 12:24:49.175330 2026] [security2:error] [pid 738779:tid 738910] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/mac.php"] [unique_id "amuI4fxa4UbeLxj1SWW11QAAAIY"]
[Thu Jul 30 12:24:49.201466 2026] [security2:error] [pid 738779:tid 738940] [client 20.226.5.174:4612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/n9z13o5s.php"] [unique_id "amuI4fxa4UbeLxj1SWW11wAAAKQ"]
[Thu Jul 30 12:24:49.232219 2026] [security2:error] [pid 738779:tid 738956] [client 142.93.53.183:58067] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/query-pagination-next/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI4fxa4UbeLxj1SWW12QAAALQ"]
[Thu Jul 30 12:24:49.499048 2026] [security2:error] [pid 738779:tid 738966] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/wefile.php"] [unique_id "amuI4fxa4UbeLxj1SWW13QAAAL4"]
[Thu Jul 30 12:24:49.499159 2026] [security2:error] [pid 738779:tid 738966] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/wefile.php"] [unique_id "amuI4fxa4UbeLxj1SWW13QAAAL4"]
[Thu Jul 30 12:24:49.625043 2026] [security2:error] [pid 738779:tid 738914] [client 142.93.53.183:58089] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/query-pagination-next/alfacgiapi/perl.alfa"] [unique_id "amuI4fxa4UbeLxj1SWW14QAAAIo"]
[Thu Jul 30 12:24:49.885326 2026] [security2:error] [pid 738779:tid 738978] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-includes/blocks/post-comments-form/"] [unique_id "amuI4fxa4UbeLxj1SWW16AAAAMo"]
[Thu Jul 30 12:24:50.013148 2026] [security2:error] [pid 738779:tid 738928] [client 142.93.53.183:58112] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/query-pagination-numbers/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI4vxa4UbeLxj1SWW16QAAAJg"]
[Thu Jul 30 12:24:50.092117 2026] [security2:error] [pid 738779:tid 738931] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-admin/js/"] [unique_id "amuI4vxa4UbeLxj1SWW16gAAAJs"]
[Thu Jul 30 12:24:50.173277 2026] [security2:error] [pid 738779:tid 739005] [client 47.128.32.123:31642] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "club4.au"] [uri "/robots.txt"] [unique_id "amuI4vxa4UbeLxj1SWW17gAAAOU"]
[Thu Jul 30 12:24:50.275884 2026] [security2:error] [pid 738779:tid 739022] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/makeasmtp.php"] [unique_id "amuI4vxa4UbeLxj1SWW19gAAAPY"]
[Thu Jul 30 12:24:50.276006 2026] [security2:error] [pid 738779:tid 739022] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/makeasmtp.php"] [unique_id "amuI4vxa4UbeLxj1SWW19gAAAPY"]
[Thu Jul 30 12:24:50.406130 2026] [security2:error] [pid 738779:tid 739017] [client 142.93.53.183:58138] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/query-pagination-numbers/alfacgiapi/perl.alfa"] [unique_id "amuI4vxa4UbeLxj1SWW1-AAAAPE"]
[Thu Jul 30 12:24:50.406494 2026] [security2:error] [pid 738779:tid 739020] [client 20.226.5.174:4621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-content/uploads/2014/03/smile.php"] [unique_id "amuI4vxa4UbeLxj1SWW19wAAAPQ"]
[Thu Jul 30 12:24:50.565165 2026] [security2:error] [pid 738779:tid 738959] [client 172.202.44.182:14087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/403.php"] [unique_id "amuI4vxa4UbeLxj1SWW1-QAAALc"]
[Thu Jul 30 12:24:50.567075 2026] [security2:error] [pid 738779:tid 739023] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/2P.php"] [unique_id "amuI4vxa4UbeLxj1SWW1-gAAAPc"]
[Thu Jul 30 12:24:50.567149 2026] [security2:error] [pid 738779:tid 739023] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/2P.php"] [unique_id "amuI4vxa4UbeLxj1SWW1-gAAAPc"]
[Thu Jul 30 12:24:50.739004 2026] [security2:error] [pid 738779:tid 739036] [client 20.203.148.31:46485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/ant.php"] [unique_id "amuI4vxa4UbeLxj1SWW1_gAAAQQ"]
[Thu Jul 30 12:24:50.796629 2026] [security2:error] [pid 738779:tid 738943] [client 142.93.53.183:58168] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/query-pagination-previous/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI4vxa4UbeLxj1SWW2AwAAAKc"]
[Thu Jul 30 12:24:50.867141 2026] [security2:error] [pid 738779:tid 739033] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/.well-known/about.php"] [unique_id "amuI4vxa4UbeLxj1SWW2BAAAAQE"]
[Thu Jul 30 12:24:50.867250 2026] [security2:error] [pid 738779:tid 739033] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/.well-known/about.php"] [unique_id "amuI4vxa4UbeLxj1SWW2BAAAAQE"]
[Thu Jul 30 12:24:51.149100 2026] [security2:error] [pid 738779:tid 738947] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuI4_xa4UbeLxj1SWW2BgAAAKs"]
[Thu Jul 30 12:24:51.149219 2026] [security2:error] [pid 738779:tid 738947] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuI4_xa4UbeLxj1SWW2BgAAAKs"]
[Thu Jul 30 12:24:51.187712 2026] [security2:error] [pid 738779:tid 738969] [client 142.93.53.183:58188] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/query-pagination-previous/alfacgiapi/perl.alfa"] [unique_id "amuI4_xa4UbeLxj1SWW2CgAAAME"]
[Thu Jul 30 12:24:51.428009 2026] [security2:error] [pid 738779:tid 738940] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/system_log.php"] [unique_id "amuI4_xa4UbeLxj1SWW2EQAAAKQ"]
[Thu Jul 30 12:24:51.428115 2026] [security2:error] [pid 738779:tid 738940] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/system_log.php"] [unique_id "amuI4_xa4UbeLxj1SWW2EQAAAKQ"]
[Thu Jul 30 12:24:51.580563 2026] [security2:error] [pid 738779:tid 738988] [client 142.93.53.183:58213] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/query-title/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI4_xa4UbeLxj1SWW2EgAAANQ"]
[Thu Jul 30 12:24:51.713620 2026] [security2:error] [pid 738779:tid 738985] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/"] [unique_id "amuI4_xa4UbeLxj1SWW2EwAAANE"]
[Thu Jul 30 12:24:51.867668 2026] [security2:error] [pid 738779:tid 738954] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/colors/modern/"] [unique_id "amuI4_xa4UbeLxj1SWW2FwAAALI"]
[Thu Jul 30 12:24:51.971374 2026] [security2:error] [pid 738779:tid 738963] [client 142.93.53.183:58239] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/query-title/alfacgiapi/perl.alfa"] [unique_id "amuI4_xa4UbeLxj1SWW2GwAAALs"]
[Thu Jul 30 12:24:52.024687 2026] [security2:error] [pid 738779:tid 739004] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/crgio.php"] [unique_id "amuI5Pxa4UbeLxj1SWW2HwAAAOQ"]
[Thu Jul 30 12:24:52.024789 2026] [security2:error] [pid 738779:tid 739004] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/crgio.php"] [unique_id "amuI5Pxa4UbeLxj1SWW2HwAAAOQ"]
[Thu Jul 30 12:24:52.127297 2026] [security2:error] [pid 738779:tid 739029] [client 20.226.5.174:4321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/ini.php"] [unique_id "amuI5Pxa4UbeLxj1SWW2IAAAAP0"]
[Thu Jul 30 12:24:52.306717 2026] [security2:error] [pid 738779:tid 738993] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/pucci.php"] [unique_id "amuI5Pxa4UbeLxj1SWW2IQAAANk"]
[Thu Jul 30 12:24:52.306828 2026] [security2:error] [pid 738779:tid 738993] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/pucci.php"] [unique_id "amuI5Pxa4UbeLxj1SWW2IQAAANk"]
[Thu Jul 30 12:24:52.429334 2026] [security2:error] [pid 738779:tid 739003] [client 172.213.232.128:23343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/updates.php"] [unique_id "amuI5Pxa4UbeLxj1SWW2KAAAAOM"]
[Thu Jul 30 12:24:52.557100 2026] [security2:error] [pid 738779:tid 738928] [client 142.93.53.183:58266] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/quote/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI5Pxa4UbeLxj1SWW2KQAAAJg"]
[Thu Jul 30 12:24:52.594514 2026] [security2:error] [pid 738779:tid 738982] [client 20.203.148.31:46521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/appreciators.php"] [unique_id "amuI5Pxa4UbeLxj1SWW2KwAAAM4"]
[Thu Jul 30 12:24:52.601715 2026] [security2:error] [pid 738779:tid 739005] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-includes/blocks/details/"] [unique_id "amuI5Pxa4UbeLxj1SWW2KgAAAOU"]
[Thu Jul 30 12:24:52.759632 2026] [security2:error] [pid 738779:tid 739021] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-includes/blocks/audio/"] [unique_id "amuI5Pxa4UbeLxj1SWW2LwAAAPU"]
[Thu Jul 30 12:24:52.918835 2026] [security2:error] [pid 738779:tid 739010] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-temp.php"] [unique_id "amuI5Pxa4UbeLxj1SWW2NQAAAOo"]
[Thu Jul 30 12:24:52.918923 2026] [security2:error] [pid 738779:tid 739010] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-temp.php"] [unique_id "amuI5Pxa4UbeLxj1SWW2NQAAAOo"]
[Thu Jul 30 12:24:52.930958 2026] [security2:error] [pid 738779:tid 739017] [client 142.93.53.183:58292] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/quote/alfacgiapi/perl.alfa"] [unique_id "amuI5Pxa4UbeLxj1SWW2NwAAAPE"]
[Thu Jul 30 12:24:52.991547 2026] [security2:error] [pid 738779:tid 738929] [client 49.13.24.81:45962] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuI5Pxa4UbeLxj1SWW2PQAAAJk"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:24:53.069539 2026] [security2:error] [pid 738779:tid 738983] [client 172.202.44.182:14111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amuI5fxa4UbeLxj1SWW2RgAAAM8"]
[Thu Jul 30 12:24:53.248788 2026] [security2:error] [pid 738779:tid 739008] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuI5fxa4UbeLxj1SWW2RwAAAOg"]
[Thu Jul 30 12:24:53.248919 2026] [security2:error] [pid 738779:tid 739008] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuI5fxa4UbeLxj1SWW2RwAAAOg"]
[Thu Jul 30 12:24:53.313039 2026] [security2:error] [pid 738779:tid 739033] [client 142.93.53.183:58313] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/read-more/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI5fxa4UbeLxj1SWW2SAAAAQE"]
[Thu Jul 30 12:24:53.401939 2026] [core:notice] [pid 738779:tid 738926] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:24:53.410222 2026] [security2:error] [pid 738779:tid 738926] [client 49.13.24.81:45964] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuI5fxa4UbeLxj1SWW2SgAAAJY"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:24:53.533353 2026] [security2:error] [pid 738779:tid 738909] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/puc.php"] [unique_id "amuI5fxa4UbeLxj1SWW2UQAAAIU"]
[Thu Jul 30 12:24:53.533479 2026] [security2:error] [pid 738779:tid 738909] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/puc.php"] [unique_id "amuI5fxa4UbeLxj1SWW2UQAAAIU"]
[Thu Jul 30 12:24:53.629727 2026] [security2:error] [pid 738779:tid 738944] [client 172.237.109.114:47264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuI5Pxa4UbeLxj1SWW2QAAAAKg"]
[Thu Jul 30 12:24:53.635310 2026] [security2:error] [pid 738779:tid 739036] [client 172.237.109.114:50213] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuI5Pxa4UbeLxj1SWW2PwAAAQQ"]
[Thu Jul 30 12:24:53.639209 2026] [security2:error] [pid 738779:tid 739009] [client 172.237.109.114:29712] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuI5Pxa4UbeLxj1SWW2PAAAAOk"]
[Thu Jul 30 12:24:53.648262 2026] [security2:error] [pid 738779:tid 739035] [client 172.237.109.114:15279] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuI5Pxa4UbeLxj1SWW2OAAAAQM"]
[Thu Jul 30 12:24:53.650171 2026] [security2:error] [pid 738779:tid 738916] [client 172.237.109.114:14663] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuI5Pxa4UbeLxj1SWW2QQAAAIw"]
[Thu Jul 30 12:24:53.652515 2026] [security2:error] [pid 738779:tid 739025] [client 172.237.109.114:54793] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuI5Pxa4UbeLxj1SWW2QgAAAPk"]
[Thu Jul 30 12:24:53.656964 2026] [security2:error] [pid 738779:tid 738959] [client 172.237.109.114:29255] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuI5Pxa4UbeLxj1SWW2OQAAALc"]
[Thu Jul 30 12:24:53.664392 2026] [security2:error] [pid 738779:tid 739023] [client 172.237.109.114:41250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuI5Pxa4UbeLxj1SWW2OgAAAPc"]
[Thu Jul 30 12:24:53.705752 2026] [security2:error] [pid 738779:tid 738967] [client 142.93.53.183:58341] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/read-more/alfacgiapi/perl.alfa"] [unique_id "amuI5fxa4UbeLxj1SWW2UgAAAL8"]
[Thu Jul 30 12:24:53.801627 2026] [security2:error] [pid 738779:tid 738979] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/dx.php"] [unique_id "amuI5fxa4UbeLxj1SWW2UwAAAMs"]
[Thu Jul 30 12:24:53.801741 2026] [security2:error] [pid 738779:tid 738979] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/dx.php"] [unique_id "amuI5fxa4UbeLxj1SWW2UwAAAMs"]
[Thu Jul 30 12:24:53.878182 2026] [security2:error] [pid 738779:tid 738937] [client 185.191.171.15:62466] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/11/21/lula-tem-alta-apos-internacao-para-retirada-de-lesao-na-laringe-no-domingo-20/"] [unique_id "amuI5fxa4UbeLxj1SWW2VQAAAKE"]
[Thu Jul 30 12:24:53.878381 2026] [security2:error] [pid 738779:tid 738937] [client 185.191.171.15:62466] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/11/21/lula-tem-alta-apos-internacao-para-retirada-de-lesao-na-laringe-no-domingo-20/"] [unique_id "amuI5fxa4UbeLxj1SWW2VQAAAKE"]
[Thu Jul 30 12:24:54.029378 2026] [security2:error] [pid 738779:tid 738985] [client 49.13.24.81:45972] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuI5vxa4UbeLxj1SWW2XAAAANE"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:24:54.091942 2026] [security2:error] [pid 738779:tid 738965] [client 20.203.148.31:39651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/archive.php"] [unique_id "amuI5vxa4UbeLxj1SWW2XgAAAL0"]
[Thu Jul 30 12:24:54.096329 2026] [security2:error] [pid 738779:tid 739004] [client 142.93.53.183:58364] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/rss/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI5vxa4UbeLxj1SWW2XwAAAOQ"]
[Thu Jul 30 12:24:54.104448 2026] [security2:error] [pid 738779:tid 738963] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-includes/Requests/"] [unique_id "amuI5vxa4UbeLxj1SWW2XQAAALs"]
[Thu Jul 30 12:24:54.259230 2026] [security2:error] [pid 738779:tid 739000] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/7.php"] [unique_id "amuI5vxa4UbeLxj1SWW2YQAAAOA"]
[Thu Jul 30 12:24:54.259386 2026] [security2:error] [pid 738779:tid 739000] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/7.php"] [unique_id "amuI5vxa4UbeLxj1SWW2YQAAAOA"]
[Thu Jul 30 12:24:54.486887 2026] [security2:error] [pid 738779:tid 739003] [client 142.93.53.183:58388] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/rss/alfacgiapi/perl.alfa"] [unique_id "amuI5vxa4UbeLxj1SWW2aAAAAOM"]
[Thu Jul 30 12:24:54.493501 2026] [security2:error] [pid 738779:tid 738994] [client 172.213.232.128:36299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/libraries/legacy/updates.php"] [unique_id "amuI5vxa4UbeLxj1SWW2aQAAANo"]
[Thu Jul 30 12:24:54.537134 2026] [security2:error] [pid 738779:tid 738928] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/8.php"] [unique_id "amuI5vxa4UbeLxj1SWW2cAAAAJg"]
[Thu Jul 30 12:24:54.537258 2026] [security2:error] [pid 738779:tid 738928] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/8.php"] [unique_id "amuI5vxa4UbeLxj1SWW2cAAAAJg"]
[Thu Jul 30 12:24:54.816358 2026] [security2:error] [pid 738779:tid 739014] [client 74.248.24.145:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.heiakujawir.com"] [uri "/1.php"] [unique_id "amuI5vxa4UbeLxj1SWW2cQAAAO4"]
[Thu Jul 30 12:24:54.816474 2026] [security2:error] [pid 738779:tid 739014] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/1.php"] [unique_id "amuI5vxa4UbeLxj1SWW2cQAAAO4"]
[Thu Jul 30 12:24:54.816577 2026] [security2:error] [pid 738779:tid 739014] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/1.php"] [unique_id "amuI5vxa4UbeLxj1SWW2cQAAAO4"]
[Thu Jul 30 12:24:54.866706 2026] [security2:error] [pid 738779:tid 739016] [client 142.93.53.183:58407] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/search/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI5vxa4UbeLxj1SWW2cgAAAPA"]
[Thu Jul 30 12:24:55.044748 2026] [security2:error] [pid 738779:tid 739022] [client 172.213.232.128:8841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/libraries/phpmailer/updates.php"] [unique_id "amuI5_xa4UbeLxj1SWW2eQAAAPY"]
[Thu Jul 30 12:24:55.093853 2026] [security2:error] [pid 738779:tid 738943] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/about.php"] [unique_id "amuI5_xa4UbeLxj1SWW2ewAAAKc"]
[Thu Jul 30 12:24:55.093953 2026] [security2:error] [pid 738779:tid 738943] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/about.php"] [unique_id "amuI5_xa4UbeLxj1SWW2ewAAAKc"]
[Thu Jul 30 12:24:55.238145 2026] [security2:error] [pid 738779:tid 738913] [client 20.203.148.31:47979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/as.php"] [unique_id "amuI5_xa4UbeLxj1SWW2fAAAAIk"]
[Thu Jul 30 12:24:55.254114 2026] [security2:error] [pid 738779:tid 738941] [client 142.93.53.183:58437] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/search/alfacgiapi/perl.alfa"] [unique_id "amuI5_xa4UbeLxj1SWW2fQAAAKU"]
[Thu Jul 30 12:24:55.420655 2026] [security2:error] [pid 738779:tid 738936] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/admin.php"] [unique_id "amuI5_xa4UbeLxj1SWW2fwAAAKA"]
[Thu Jul 30 12:24:55.420765 2026] [security2:error] [pid 738779:tid 738936] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/admin.php"] [unique_id "amuI5_xa4UbeLxj1SWW2fwAAAKA"]
[Thu Jul 30 12:24:55.643497 2026] [security2:error] [pid 738779:tid 738949] [client 142.93.53.183:58454] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/separator/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI5_xa4UbeLxj1SWW2hgAAAK0"]
[Thu Jul 30 12:24:55.710777 2026] [security2:error] [pid 738779:tid 738962] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/edit.php"] [unique_id "amuI5_xa4UbeLxj1SWW2hwAAALo"]
[Thu Jul 30 12:24:55.710883 2026] [security2:error] [pid 738779:tid 738962] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/edit.php"] [unique_id "amuI5_xa4UbeLxj1SWW2hwAAALo"]
[Thu Jul 30 12:24:55.988679 2026] [security2:error] [pid 738779:tid 739035] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-content/admin.php"] [unique_id "amuI5_xa4UbeLxj1SWW2jAAAAQM"]
[Thu Jul 30 12:24:55.988797 2026] [security2:error] [pid 738779:tid 739035] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-content/admin.php"] [unique_id "amuI5_xa4UbeLxj1SWW2jAAAAQM"]
[Thu Jul 30 12:24:56.034045 2026] [security2:error] [pid 738779:tid 738959] [client 142.93.53.183:58476] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/separator/alfacgiapi/perl.alfa"] [unique_id "amuI6Pxa4UbeLxj1SWW2jQAAALc"]
[Thu Jul 30 12:24:56.072559 2026] [security2:error] [pid 738779:tid 738925] [client 172.213.232.128:8910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/libraries/vendor/updates.php"] [unique_id "amuI6Pxa4UbeLxj1SWW2jgAAAJU"]
[Thu Jul 30 12:24:56.268034 2026] [security2:error] [pid 738779:tid 738937] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/inputs.php"] [unique_id "amuI6Pxa4UbeLxj1SWW2kgAAAKE"]
[Thu Jul 30 12:24:56.268166 2026] [security2:error] [pid 738779:tid 738937] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/inputs.php"] [unique_id "amuI6Pxa4UbeLxj1SWW2kgAAAKE"]
[Thu Jul 30 12:24:56.424521 2026] [security2:error] [pid 738779:tid 738987] [client 142.93.53.183:58501] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/shortcode/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI6Pxa4UbeLxj1SWW2kwAAANM"]
[Thu Jul 30 12:24:56.538610 2026] [security2:error] [pid 738779:tid 739004] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/av.php"] [unique_id "amuI6Pxa4UbeLxj1SWW2mgAAAOQ"]
[Thu Jul 30 12:24:56.538696 2026] [security2:error] [pid 738779:tid 739004] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/av.php"] [unique_id "amuI6Pxa4UbeLxj1SWW2mgAAAOQ"]
[Thu Jul 30 12:24:56.751778 2026] [security2:error] [pid 738779:tid 738966] [client 20.203.148.31:39650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/atomlib.php"] [unique_id "amuI6Pxa4UbeLxj1SWW2ngAAAL4"]
[Thu Jul 30 12:24:56.809971 2026] [security2:error] [pid 738779:tid 738918] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/classwithtostring.php"] [unique_id "amuI6Pxa4UbeLxj1SWW2nwAAAI4"]
[Thu Jul 30 12:24:56.810123 2026] [security2:error] [pid 738779:tid 738918] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/classwithtostring.php"] [unique_id "amuI6Pxa4UbeLxj1SWW2nwAAAI4"]
[Thu Jul 30 12:24:56.812093 2026] [security2:error] [pid 738779:tid 738968] [client 142.93.53.183:58520] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/shortcode/alfacgiapi/perl.alfa"] [unique_id "amuI6Pxa4UbeLxj1SWW2oAAAAMA"]
[Thu Jul 30 12:24:57.068512 2026] [security2:error] [pid 738779:tid 738947] [client 20.226.5.174:4301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/img/xleet.php"] [unique_id "amuI6fxa4UbeLxj1SWW2pAAAAKs"]
[Thu Jul 30 12:24:57.088870 2026] [security2:error] [pid 738779:tid 738930] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuI6fxa4UbeLxj1SWW2pQAAAJo"]
[Thu Jul 30 12:24:57.088955 2026] [security2:error] [pid 738779:tid 738930] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuI6fxa4UbeLxj1SWW2pQAAAJo"]
[Thu Jul 30 12:24:57.187395 2026] [security2:error] [pid 738779:tid 738998] [client 142.93.53.183:58550] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/site-logo/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI6fxa4UbeLxj1SWW2rAAAAN4"]
[Thu Jul 30 12:24:57.382107 2026] [security2:error] [pid 738779:tid 739014] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-blog.php"] [unique_id "amuI6fxa4UbeLxj1SWW2rQAAAO4"]
[Thu Jul 30 12:24:57.382223 2026] [security2:error] [pid 738779:tid 739014] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-blog.php"] [unique_id "amuI6fxa4UbeLxj1SWW2rQAAAO4"]
[Thu Jul 30 12:24:57.580108 2026] [security2:error] [pid 738779:tid 739029] [client 20.203.148.31:39663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/autoload_classmap.php"] [unique_id "amuI6fxa4UbeLxj1SWW2sQAAAP0"]
[Thu Jul 30 12:24:57.580821 2026] [security2:error] [pid 738779:tid 738960] [client 142.93.53.183:58569] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/site-logo/alfacgiapi/perl.alfa"] [unique_id "amuI6fxa4UbeLxj1SWW2sgAAALg"]
[Thu Jul 30 12:24:57.601873 2026] [security2:error] [pid 738779:tid 738964] [client 172.213.232.128:6886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/alfa-rex.php7"] [unique_id "amuI6fxa4UbeLxj1SWW2tQAAALw"]
[Thu Jul 30 12:24:57.681430 2026] [security2:error] [pid 738779:tid 739030] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-includes/js/jquery/"] [unique_id "amuI6fxa4UbeLxj1SWW2twAAAP4"]
[Thu Jul 30 12:24:57.828500 2026] [security2:error] [pid 738779:tid 738911] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-content/admin.php"] [unique_id "amuI6fxa4UbeLxj1SWW2uAAAAIc"]
[Thu Jul 30 12:24:57.828646 2026] [security2:error] [pid 738779:tid 738911] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-content/admin.php"] [unique_id "amuI6fxa4UbeLxj1SWW2uAAAAIc"]
[Thu Jul 30 12:24:57.971463 2026] [security2:error] [pid 738779:tid 738941] [client 142.93.53.183:58592] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/site-tagline/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI6fxa4UbeLxj1SWW2uQAAAKU"]
[Thu Jul 30 12:24:58.099175 2026] [security2:error] [pid 738779:tid 738926] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/adminfuns.php"] [unique_id "amuI6vxa4UbeLxj1SWW2vgAAAJY"]
[Thu Jul 30 12:24:58.099286 2026] [security2:error] [pid 738779:tid 738926] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/adminfuns.php"] [unique_id "amuI6vxa4UbeLxj1SWW2vgAAAJY"]
[Thu Jul 30 12:24:58.257356 2026] [security2:error] [pid 738779:tid 738942] [client 20.203.148.31:47944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/bb.php"] [unique_id "amuI6vxa4UbeLxj1SWW2wgAAAKY"]
[Thu Jul 30 12:24:58.347353 2026] [security2:error] [pid 738779:tid 738952] [client 172.213.232.128:8899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/alfanew.php"] [unique_id "amuI6vxa4UbeLxj1SWW2wwAAALA"]
[Thu Jul 30 12:24:58.359560 2026] [security2:error] [pid 738779:tid 738962] [client 142.93.53.183:58612] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/site-tagline/alfacgiapi/perl.alfa"] [unique_id "amuI6vxa4UbeLxj1SWW2xAAAALo"]
[Thu Jul 30 12:24:58.408599 2026] [security2:error] [pid 738779:tid 739031] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/goods.php"] [unique_id "amuI6vxa4UbeLxj1SWW2xQAAAP8"]
[Thu Jul 30 12:24:58.408699 2026] [security2:error] [pid 738779:tid 739031] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/goods.php"] [unique_id "amuI6vxa4UbeLxj1SWW2xQAAAP8"]
[Thu Jul 30 12:24:58.693438 2026] [security2:error] [pid 738779:tid 738910] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/ms-edit.php"] [unique_id "amuI6vxa4UbeLxj1SWW20QAAAIY"]
[Thu Jul 30 12:24:58.693546 2026] [security2:error] [pid 738779:tid 738910] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/ms-edit.php"] [unique_id "amuI6vxa4UbeLxj1SWW20QAAAIY"]
[Thu Jul 30 12:24:58.738960 2026] [security2:error] [pid 738779:tid 738955] [client 142.93.53.183:58638] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/site-title/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI6vxa4UbeLxj1SWW20wAAALM"]
[Thu Jul 30 12:24:58.877755 2026] [core:error] [pid 738779:tid 738956] [client 74.7.244.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:24:58.877777 2026] [core:error] [pid 738779:tid 738956] [client 74.7.244.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:24:58.877912 2026] [security2:error] [pid 738779:tid 738956] [client 74.7.244.51:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.kfo.lku.temporary.site"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amuI6vxa4UbeLxj1SWW21gAAALQ"]
[Thu Jul 30 12:24:58.878487 2026] [security2:error] [pid 738779:tid 738944] [client 74.7.244.51:60864] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.kfo.lku.temporary.site"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amuI6vxa4UbeLxj1SWW21AAAqCo"]
[Thu Jul 30 12:24:58.978787 2026] [security2:error] [pid 738779:tid 738954] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/222.php"] [unique_id "amuI6vxa4UbeLxj1SWW21wAAALI"]
[Thu Jul 30 12:24:58.978935 2026] [security2:error] [pid 738779:tid 738954] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/222.php"] [unique_id "amuI6vxa4UbeLxj1SWW21wAAALI"]
[Thu Jul 30 12:24:59.058130 2026] [security2:error] [pid 738779:tid 739023] [client 20.203.148.31:39633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/bnm.php"] [unique_id "amuI6_xa4UbeLxj1SWW22AAAAPc"]
[Thu Jul 30 12:24:59.081199 2026] [security2:error] [pid 738779:tid 738975] [client 20.226.5.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuI6vxa4UbeLxj1SWW2yAAAAMc"]
[Thu Jul 30 12:24:59.112394 2026] [security2:error] [pid 738779:tid 739026] [client 127.0.0.1:35972] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.mth.gzj.temporary.site"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuI6_xa4UbeLxj1SWW22gAAAPo"]
[Thu Jul 30 12:24:59.112394 2026] [security2:error] [pid 738779:tid 738999] [client 127.0.0.1:35978] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuI6_xa4UbeLxj1SWW22wAAAN8"]
[Thu Jul 30 12:24:59.112480 2026] [security2:error] [pid 738779:tid 738988] [client 74.7.175.129:43344] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.mth.gzj.temporary.site"] [uri "/robots.txt"] [unique_id "amuI6_xa4UbeLxj1SWW22QAA1Cs"]
[Thu Jul 30 12:24:59.116863 2026] [security2:error] [pid 738779:tid 738937] [client 172.213.232.128:12300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/plugins/Cache/Cache.php"] [unique_id "amuI6_xa4UbeLxj1SWW23AAAAKE"]
[Thu Jul 30 12:24:59.128095 2026] [security2:error] [pid 738779:tid 738965] [client 142.93.53.183:58661] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/site-title/alfacgiapi/perl.alfa"] [unique_id "amuI6_xa4UbeLxj1SWW23QAAAL0"]
[Thu Jul 30 12:24:59.194135 2026] [security2:error] [pid 738779:tid 739032] [client 74.7.175.191:57160] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bnd.gpl.temporary.site"] [uri "/robots.txt"] [unique_id "amuI6_xa4UbeLxj1SWW24QAAAQA"]
[Thu Jul 30 12:24:59.264308 2026] [security2:error] [pid 738779:tid 738994] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/cgi-bin/index.php"] [unique_id "amuI6_xa4UbeLxj1SWW26AAAANo"]
[Thu Jul 30 12:24:59.264395 2026] [security2:error] [pid 738779:tid 738994] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/cgi-bin/index.php"] [unique_id "amuI6_xa4UbeLxj1SWW26AAAANo"]
[Thu Jul 30 12:24:59.519606 2026] [security2:error] [pid 738779:tid 739005] [client 142.93.53.183:58686] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/social-link/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI6_xa4UbeLxj1SWW26gAAAOU"]
[Thu Jul 30 12:24:59.564786 2026] [security2:error] [pid 738779:tid 739013] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-includes/css/dist/"] [unique_id "amuI6_xa4UbeLxj1SWW26wAAAO0"]
[Thu Jul 30 12:24:59.698916 2026] [security2:error] [pid 738779:tid 739029] [client 20.226.5.174:4295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/server.php"] [unique_id "amuI6_xa4UbeLxj1SWW28gAAAP0"]
[Thu Jul 30 12:24:59.718553 2026] [security2:error] [pid 738779:tid 739017] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/BDKR28WP.php"] [unique_id "amuI6_xa4UbeLxj1SWW29gAAAPE"]
[Thu Jul 30 12:24:59.718634 2026] [security2:error] [pid 738779:tid 739017] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/BDKR28WP.php"] [unique_id "amuI6_xa4UbeLxj1SWW29gAAAPE"]
[Thu Jul 30 12:24:59.909198 2026] [security2:error] [pid 738779:tid 738939] [client 142.93.53.183:58707] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/social-link/alfacgiapi/perl.alfa"] [unique_id "amuI6_xa4UbeLxj1SWW29wAAAKM"]
[Thu Jul 30 12:25:00.007206 2026] [security2:error] [pid 738779:tid 739030] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-includes/l10n/"] [unique_id "amuI6_xa4UbeLxj1SWW2-AAAAP4"]
[Thu Jul 30 12:25:00.160918 2026] [security2:error] [pid 738779:tid 738911] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-content/uploads/"] [unique_id "amuI7Pxa4UbeLxj1SWW2-QAAAIc"]
[Thu Jul 30 12:25:00.296760 2026] [security2:error] [pid 738779:tid 739019] [client 142.93.53.183:58733] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/social-links/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI7Pxa4UbeLxj1SWW3AwAAAPM"]
[Thu Jul 30 12:25:00.302393 2026] [security2:error] [pid 738779:tid 738971] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/wp.php"] [unique_id "amuI7Pxa4UbeLxj1SWW3BAAAAMM"]
[Thu Jul 30 12:25:00.302470 2026] [security2:error] [pid 738779:tid 738971] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/wp.php"] [unique_id "amuI7Pxa4UbeLxj1SWW3BAAAAMM"]
[Thu Jul 30 12:25:00.536274 2026] [security2:error] [pid 738779:tid 738930] [client 20.203.148.31:47891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/bootstrap.php"] [unique_id "amuI7Pxa4UbeLxj1SWW3BQAAAJo"]
[Thu Jul 30 12:25:00.637102 2026] [security2:error] [pid 738779:tid 738974] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/abcd.php"] [unique_id "amuI7Pxa4UbeLxj1SWW3BgAAAMY"]
[Thu Jul 30 12:25:00.637275 2026] [security2:error] [pid 738779:tid 738974] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/abcd.php"] [unique_id "amuI7Pxa4UbeLxj1SWW3BgAAAMY"]
[Thu Jul 30 12:25:00.647227 2026] [security2:error] [pid 738779:tid 738952] [client 172.213.232.128:36300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/js/widgets/about.php7"] [unique_id "amuI7Pxa4UbeLxj1SWW3BwAAALA"]
[Thu Jul 30 12:25:00.672219 2026] [security2:error] [pid 738779:tid 739031] [client 142.93.53.183:58758] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/social-links/alfacgiapi/perl.alfa"] [unique_id "amuI7Pxa4UbeLxj1SWW3CAAAAP8"]
[Thu Jul 30 12:25:00.914698 2026] [security2:error] [pid 738779:tid 738986] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/a1.php"] [unique_id "amuI7Pxa4UbeLxj1SWW3EAAAANI"]
[Thu Jul 30 12:25:00.914841 2026] [security2:error] [pid 738779:tid 738986] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/a1.php"] [unique_id "amuI7Pxa4UbeLxj1SWW3EAAAANI"]
[Thu Jul 30 12:25:01.021078 2026] [security2:error] [pid 738779:tid 738962] [client 20.226.5.174:4306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/.well-known/pki-validation/wp-config.php"] [unique_id "amuI7fxa4UbeLxj1SWW3EQAAALo"]
[Thu Jul 30 12:25:01.046859 2026] [security2:error] [pid 738779:tid 738945] [client 142.93.53.183:58783] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/spacer/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI7fxa4UbeLxj1SWW3EgAAAKk"]
[Thu Jul 30 12:25:01.147124 2026] [security2:error] [pid 738779:tid 738967] [client 111.113.88.206:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuI7Pxa4UbeLxj1SWW3DgAAAL8"]
[Thu Jul 30 12:25:01.150629 2026] [security2:error] [pid 738779:tid 738990] [client 172.213.232.128:18950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-p.php7"] [unique_id "amuI7fxa4UbeLxj1SWW3FgAAANY"]
[Thu Jul 30 12:25:01.193970 2026] [security2:error] [pid 738779:tid 738987] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amuI7fxa4UbeLxj1SWW3FwAAANM"]
[Thu Jul 30 12:25:01.194106 2026] [security2:error] [pid 738779:tid 738987] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amuI7fxa4UbeLxj1SWW3FwAAANM"]
[Thu Jul 30 12:25:01.440126 2026] [security2:error] [pid 738779:tid 739006] [client 142.93.53.183:58802] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/spacer/alfacgiapi/perl.alfa"] [unique_id "amuI7fxa4UbeLxj1SWW3HwAAAOY"]
[Thu Jul 30 12:25:01.507475 2026] [security2:error] [pid 738779:tid 738966] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/cgi-bin/admin.php"] [unique_id "amuI7fxa4UbeLxj1SWW3JAAAAL4"]
[Thu Jul 30 12:25:01.507588 2026] [security2:error] [pid 738779:tid 738966] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/cgi-bin/admin.php"] [unique_id "amuI7fxa4UbeLxj1SWW3JAAAAL4"]
[Thu Jul 30 12:25:01.698604 2026] [security2:error] [pid 738779:tid 738944] [client 57.141.0.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuI7fxa4UbeLxj1SWW3FQAAAKg"]
[Thu Jul 30 12:25:01.798440 2026] [security2:error] [pid 738779:tid 739003] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-content/"] [unique_id "amuI7fxa4UbeLxj1SWW3KQAAAOM"]
[Thu Jul 30 12:25:01.815113 2026] [security2:error] [pid 738779:tid 738997] [client 142.93.53.183:58829] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/table/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI7fxa4UbeLxj1SWW3KgAAAN0"]
[Thu Jul 30 12:25:01.938257 2026] [security2:error] [pid 738779:tid 739005] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/simple.php"] [unique_id "amuI7fxa4UbeLxj1SWW3LgAAAOU"]
[Thu Jul 30 12:25:01.938363 2026] [security2:error] [pid 738779:tid 739005] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/simple.php"] [unique_id "amuI7fxa4UbeLxj1SWW3LgAAAOU"]
[Thu Jul 30 12:25:02.196425 2026] [security2:error] [pid 738779:tid 738998] [client 142.93.53.183:58854] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/table/alfacgiapi/perl.alfa"] [unique_id "amuI7vxa4UbeLxj1SWW3LwAAAN4"]
[Thu Jul 30 12:25:02.240533 2026] [security2:error] [pid 738779:tid 738982] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/xxx.php"] [unique_id "amuI7vxa4UbeLxj1SWW3MAAAAM4"]
[Thu Jul 30 12:25:02.240648 2026] [security2:error] [pid 738779:tid 738982] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/xxx.php"] [unique_id "amuI7vxa4UbeLxj1SWW3MAAAAM4"]
[Thu Jul 30 12:25:02.476766 2026] [security2:error] [pid 738779:tid 738956] [client 20.203.148.31:46498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/buy.php"] [unique_id "amuI7vxa4UbeLxj1SWW3NwAAALQ"]
[Thu Jul 30 12:25:02.562184 2026] [security2:error] [pid 738779:tid 738960] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/hypo.php"] [unique_id "amuI7vxa4UbeLxj1SWW3OAAAALg"]
[Thu Jul 30 12:25:02.562288 2026] [security2:error] [pid 738779:tid 738960] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/hypo.php"] [unique_id "amuI7vxa4UbeLxj1SWW3OAAAALg"]
[Thu Jul 30 12:25:02.580551 2026] [security2:error] [pid 738779:tid 738989] [client 142.93.53.183:58878] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/tag-cloud/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI7vxa4UbeLxj1SWW3OQAAANU"]
[Thu Jul 30 12:25:02.760469 2026] [security2:error] [pid 738779:tid 739028] [client 172.213.232.128:19005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/repeater.php"] [unique_id "amuI7vxa4UbeLxj1SWW3OwAAAPw"]
[Thu Jul 30 12:25:02.865335 2026] [security2:error] [pid 738779:tid 738913] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/colors/blue/"] [unique_id "amuI7vxa4UbeLxj1SWW3PwAAAIk"]
[Thu Jul 30 12:25:02.955256 2026] [security2:error] [pid 738779:tid 738953] [client 142.93.53.183:58912] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/paymethod/manual/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI7vxa4UbeLxj1SWW3QwAAALE"]
[Thu Jul 30 12:25:03.058890 2026] [security2:error] [pid 738779:tid 739008] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/chosen.php"] [unique_id "amuI7_xa4UbeLxj1SWW3RAAAAOg"]
[Thu Jul 30 12:25:03.059032 2026] [security2:error] [pid 738779:tid 739008] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/chosen.php"] [unique_id "amuI7_xa4UbeLxj1SWW3RAAAAOg"]
[Thu Jul 30 12:25:03.136950 2026] [security2:error] [pid 738779:tid 738935] [client 20.203.148.31:44967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/chosen.php"] [unique_id "amuI7_xa4UbeLxj1SWW3RQAAAJ8"]
[Thu Jul 30 12:25:03.282186 2026] [security2:error] [pid 738779:tid 738921] [client 213.180.203.82:38612] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "spacexpress.africa"] [uri "/robots.txt"] [unique_id "amuI7_xa4UbeLxj1SWW3SgAAAJE"]
[Thu Jul 30 12:25:03.347616 2026] [security2:error] [pid 738779:tid 739007] [client 142.93.53.183:58932] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/paymethod/manual/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuI7_xa4UbeLxj1SWW3TAAAAOc"]
[Thu Jul 30 12:25:03.406291 2026] [security2:error] [pid 738779:tid 738924] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-includes/block-bindings/"] [unique_id "amuI7_xa4UbeLxj1SWW3TwAAAJQ"]
[Thu Jul 30 12:25:03.578675 2026] [security2:error] [pid 738779:tid 738962] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/als.php"] [unique_id "amuI7_xa4UbeLxj1SWW3VgAAALo"]
[Thu Jul 30 12:25:03.578795 2026] [security2:error] [pid 738779:tid 738962] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/als.php"] [unique_id "amuI7_xa4UbeLxj1SWW3VgAAALo"]
[Thu Jul 30 12:25:03.673425 2026] [security2:error] [pid 738779:tid 739015] [client 20.226.5.174:4314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-content/themes/twentytwentyfive/flower.php"] [unique_id "amuI7_xa4UbeLxj1SWW3VwAAAO8"]
[Thu Jul 30 12:25:03.734519 2026] [security2:error] [pid 738779:tid 738945] [client 142.93.53.183:58959] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/paymethod/manual/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuI7_xa4UbeLxj1SWW3WAAAAKk"]
[Thu Jul 30 12:25:03.844248 2026] [security2:error] [pid 738779:tid 738926] [client 2a03:2880:f800:20:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuI7_xa4UbeLxj1SWW3SAAAlkE"]
[Thu Jul 30 12:25:03.862854 2026] [security2:error] [pid 738779:tid 739023] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/pol.php"] [unique_id "amuI7_xa4UbeLxj1SWW3XAAAAPc"]
[Thu Jul 30 12:25:03.862959 2026] [security2:error] [pid 738779:tid 739023] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/pol.php"] [unique_id "amuI7_xa4UbeLxj1SWW3XAAAAPc"]
[Thu Jul 30 12:25:04.102266 2026] [core:notice] [pid 738779:tid 738910] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:25:04.113567 2026] [security2:error] [pid 738779:tid 738966] [client 142.93.53.183:58981] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/home/jancox/alfacgiapi/perl.alfa"] [unique_id "amuI8Pxa4UbeLxj1SWW3YQAAAL4"]
[Thu Jul 30 12:25:04.114077 2026] [security2:error] [pid 738779:tid 738999] [client 172.213.232.128:23324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/repeater.php"] [unique_id "amuI8Pxa4UbeLxj1SWW3YgAAAN8"]
[Thu Jul 30 12:25:04.135145 2026] [security2:error] [pid 738779:tid 739001] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/file5.php"] [unique_id "amuI8Pxa4UbeLxj1SWW3YwAAAOE"]
[Thu Jul 30 12:25:04.135238 2026] [security2:error] [pid 738779:tid 739001] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/file5.php"] [unique_id "amuI8Pxa4UbeLxj1SWW3YwAAAOE"]
[Thu Jul 30 12:25:04.445321 2026] [security2:error] [pid 738779:tid 739002] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/file.php"] [unique_id "amuI8Pxa4UbeLxj1SWW3cQAAAOI"]
[Thu Jul 30 12:25:04.445419 2026] [security2:error] [pid 738779:tid 739002] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/file.php"] [unique_id "amuI8Pxa4UbeLxj1SWW3cQAAAOI"]
[Thu Jul 30 12:25:04.500121 2026] [security2:error] [pid 738779:tid 739014] [client 142.93.53.183:59017] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/home/jancox/alfacgiapi/bash.alfa"] [unique_id "amuI8Pxa4UbeLxj1SWW3cgAAAO4"]
[Thu Jul 30 12:25:04.742434 2026] [security2:error] [pid 738779:tid 739022] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/admin.php"] [unique_id "amuI8Pxa4UbeLxj1SWW3cwAAAPY"]
[Thu Jul 30 12:25:04.742541 2026] [security2:error] [pid 738779:tid 739022] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/admin.php"] [unique_id "amuI8Pxa4UbeLxj1SWW3cwAAAPY"]
[Thu Jul 30 12:25:04.878808 2026] [security2:error] [pid 738779:tid 738963] [client 57.141.0.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuI8Pxa4UbeLxj1SWW3aQAAALs"]
[Thu Jul 30 12:25:04.893279 2026] [security2:error] [pid 738779:tid 739017] [client 142.93.53.183:59046] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/home/jancox/alfacgiapi/py.alfa"] [unique_id "amuI8Pxa4UbeLxj1SWW3dwAAAPE"]
[Thu Jul 30 12:25:04.978467 2026] [security2:error] [pid 738779:tid 738992] [client 20.226.5.174:4325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-admin/xleet.php"] [unique_id "amuI8Pxa4UbeLxj1SWW3eAAAANg"]
[Thu Jul 30 12:25:05.025784 2026] [security2:error] [pid 738779:tid 738943] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/aa2.php"] [unique_id "amuI8fxa4UbeLxj1SWW3fAAAAKc"]
[Thu Jul 30 12:25:05.025870 2026] [security2:error] [pid 738779:tid 738943] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/aa2.php"] [unique_id "amuI8fxa4UbeLxj1SWW3fAAAAKc"]
[Thu Jul 30 12:25:05.195875 2026] [security2:error] [pid 738779:tid 738982] [client 20.203.148.31:43472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/class-wp-image.php"] [unique_id "amuI8fxa4UbeLxj1SWW3fgAAAM4"]
[Thu Jul 30 12:25:05.281281 2026] [security2:error] [pid 738779:tid 738915] [client 142.93.53.183:59081] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/cms/wp-content/jancox/alfacgiapi/perl.alfa"] [unique_id "amuI8fxa4UbeLxj1SWW3fwAAAIs"]
[Thu Jul 30 12:25:05.301631 2026] [security2:error] [pid 738779:tid 738946] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/ccou.php"] [unique_id "amuI8fxa4UbeLxj1SWW3gAAAAKo"]
[Thu Jul 30 12:25:05.301716 2026] [security2:error] [pid 738779:tid 738946] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/ccou.php"] [unique_id "amuI8fxa4UbeLxj1SWW3gAAAAKo"]
[Thu Jul 30 12:25:05.579782 2026] [security2:error] [pid 738779:tid 738974] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/dr.php"] [unique_id "amuI8fxa4UbeLxj1SWW3iAAAAMY"]
[Thu Jul 30 12:25:05.579921 2026] [security2:error] [pid 738779:tid 738974] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/dr.php"] [unique_id "amuI8fxa4UbeLxj1SWW3iAAAAMY"]
[Thu Jul 30 12:25:05.656361 2026] [security2:error] [pid 738779:tid 739007] [client 142.93.53.183:59111] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/cms/wp-content/jancox/alfacgiapi/bash.alfa"] [unique_id "amuI8fxa4UbeLxj1SWW3iQAAAOc"]
[Thu Jul 30 12:25:05.919302 2026] [security2:error] [pid 738779:tid 738940] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/xamp.php"] [unique_id "amuI8fxa4UbeLxj1SWW3jgAAAKQ"]
[Thu Jul 30 12:25:05.919443 2026] [security2:error] [pid 738779:tid 738940] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/xamp.php"] [unique_id "amuI8fxa4UbeLxj1SWW3jgAAAKQ"]
[Thu Jul 30 12:25:06.048321 2026] [security2:error] [pid 738779:tid 739018] [client 142.93.53.183:59139] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/cms/wp-content/jancox/alfacgiapi/py.alfa"] [unique_id "amuI8vxa4UbeLxj1SWW3kQAAAPI"]
[Thu Jul 30 12:25:06.181230 2026] [security2:error] [pid 738779:tid 739036] [client 20.226.5.174:4288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/shell1.php"] [unique_id "amuI8vxa4UbeLxj1SWW3lgAAAQQ"]
[Thu Jul 30 12:25:06.200618 2026] [security2:error] [pid 738779:tid 739023] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/bless.php"] [unique_id "amuI8vxa4UbeLxj1SWW3lwAAAPc"]
[Thu Jul 30 12:25:06.200728 2026] [security2:error] [pid 738779:tid 739023] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/bless.php"] [unique_id "amuI8vxa4UbeLxj1SWW3lwAAAPc"]
[Thu Jul 30 12:25:06.440467 2026] [security2:error] [pid 738779:tid 738937] [client 142.93.53.183:59164] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/crm_documents/expenses/10/cache/alfacgiapi/perl.alfa"] [unique_id "amuI8vxa4UbeLxj1SWW3mQAAAKE"]
[Thu Jul 30 12:25:06.484616 2026] [security2:error] [pid 738779:tid 738973] [client 172.213.232.128:8932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/repeater.php"] [unique_id "amuI8vxa4UbeLxj1SWW3nwAAAMU"]
[Thu Jul 30 12:25:06.488432 2026] [security2:error] [pid 738779:tid 738987] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/file25.php"] [unique_id "amuI8vxa4UbeLxj1SWW3oAAAANM"]
[Thu Jul 30 12:25:06.488523 2026] [security2:error] [pid 738779:tid 738987] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/file25.php"] [unique_id "amuI8vxa4UbeLxj1SWW3oAAAANM"]
[Thu Jul 30 12:25:06.809098 2026] [security2:error] [pid 738779:tid 738922] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/file6.php"] [unique_id "amuI8vxa4UbeLxj1SWW3pQAAAJI"]
[Thu Jul 30 12:25:06.809214 2026] [security2:error] [pid 738779:tid 738922] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/file6.php"] [unique_id "amuI8vxa4UbeLxj1SWW3pQAAAJI"]
[Thu Jul 30 12:25:06.832360 2026] [security2:error] [pid 738779:tid 738970] [client 142.93.53.183:59188] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/crm_documents/expenses/10/cache/alfacgiapi/bash.alfa"] [unique_id "amuI8vxa4UbeLxj1SWW3pwAAAMI"]
[Thu Jul 30 12:25:07.111432 2026] [security2:error] [pid 738779:tid 739005] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/a2.php"] [unique_id "amuI8_xa4UbeLxj1SWW3qwAAAOU"]
[Thu Jul 30 12:25:07.111540 2026] [security2:error] [pid 738779:tid 739005] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/a2.php"] [unique_id "amuI8_xa4UbeLxj1SWW3qwAAAOU"]
[Thu Jul 30 12:25:07.221186 2026] [security2:error] [pid 738779:tid 739022] [client 142.93.53.183:59217] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/crm_documents/expenses/10/cache/alfacgiapi/py.alfa"] [unique_id "amuI8_xa4UbeLxj1SWW3rwAAAPY"]
[Thu Jul 30 12:25:07.388065 2026] [security2:error] [pid 738779:tid 738991] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/file15.php"] [unique_id "amuI8_xa4UbeLxj1SWW3sgAAANc"]
[Thu Jul 30 12:25:07.388186 2026] [security2:error] [pid 738779:tid 738991] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/file15.php"] [unique_id "amuI8_xa4UbeLxj1SWW3sgAAANc"]
[Thu Jul 30 12:25:07.611919 2026] [security2:error] [pid 738779:tid 738941] [client 142.93.53.183:59245] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/PJPSQ_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI8_xa4UbeLxj1SWW3uwAAAKU"]
[Thu Jul 30 12:25:07.672498 2026] [security2:error] [pid 738779:tid 738939] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/f35.php"] [unique_id "amuI8_xa4UbeLxj1SWW3vAAAAKM"]
[Thu Jul 30 12:25:07.672610 2026] [security2:error] [pid 738779:tid 738939] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/f35.php"] [unique_id "amuI8_xa4UbeLxj1SWW3vAAAAKM"]
[Thu Jul 30 12:25:07.737879 2026] [security2:error] [pid 738779:tid 738993] [client 20.226.5.174:4290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-set.php"] [unique_id "amuI8_xa4UbeLxj1SWW3wQAAANk"]
[Thu Jul 30 12:25:07.932409 2026] [security2:error] [pid 738779:tid 739017] [client 20.203.148.31:48083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/classsmtps.php"] [unique_id "amuI8_xa4UbeLxj1SWW3wgAAAPE"]
[Thu Jul 30 12:25:07.977735 2026] [security2:error] [pid 738779:tid 738923] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-load.php"] [unique_id "amuI8_xa4UbeLxj1SWW3wwAAAJM"]
[Thu Jul 30 12:25:07.977829 2026] [security2:error] [pid 738779:tid 738923] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-load.php"] [unique_id "amuI8_xa4UbeLxj1SWW3wwAAAJM"]
[Thu Jul 30 12:25:08.002393 2026] [security2:error] [pid 738779:tid 738949] [client 142.93.53.183:59272] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/PJPSQ_DATA/alfacgiapi/py.alfa"] [unique_id "amuI9Pxa4UbeLxj1SWW3xAAAAK0"]
[Thu Jul 30 12:25:08.247492 2026] [security2:error] [pid 738779:tid 738959] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/xwpg.php"] [unique_id "amuI9Pxa4UbeLxj1SWW3ywAAALc"]
[Thu Jul 30 12:25:08.247637 2026] [security2:error] [pid 738779:tid 738959] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/xwpg.php"] [unique_id "amuI9Pxa4UbeLxj1SWW3ywAAALc"]
[Thu Jul 30 12:25:08.393252 2026] [security2:error] [pid 738779:tid 738986] [client 142.93.53.183:59301] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/PJPSQ_DATA/alfacgiapi/bash.alfa"] [unique_id "amuI9Pxa4UbeLxj1SWW3zAAAANI"]
[Thu Jul 30 12:25:08.528373 2026] [security2:error] [pid 738779:tid 738930] [client 20.203.148.31:48620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/classwithtostring.php"] [unique_id "amuI9Pxa4UbeLxj1SWW3zQAAAJo"]
[Thu Jul 30 12:25:08.582012 2026] [security2:error] [pid 738779:tid 738967] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-includes/assets/"] [unique_id "amuI9Pxa4UbeLxj1SWW30QAAAL8"]
[Thu Jul 30 12:25:08.657111 2026] [security2:error] [pid 738779:tid 738933] [client 47.98.96.52:57434] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/2024/03/logo-light-1.png"] [unique_id "amuI9Pxa4UbeLxj1SWW30gAAAJ0"]
[Thu Jul 30 12:25:08.758645 2026] [security2:error] [pid 738779:tid 738954] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/colors/sunrise/"] [unique_id "amuI9Pxa4UbeLxj1SWW31wAAALI"]
[Thu Jul 30 12:25:08.772447 2026] [security2:error] [pid 738779:tid 738937] [client 142.93.53.183:59324] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/journal/files/PJPSQ_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI9Pxa4UbeLxj1SWW32AAAAKE"]
[Thu Jul 30 12:25:08.926796 2026] [security2:error] [pid 738779:tid 738912] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/xstelth.php"] [unique_id "amuI9Pxa4UbeLxj1SWW32QAAAIg"]
[Thu Jul 30 12:25:08.926920 2026] [security2:error] [pid 738779:tid 738912] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/xstelth.php"] [unique_id "amuI9Pxa4UbeLxj1SWW32QAAAIg"]
[Thu Jul 30 12:25:08.951310 2026] [security2:error] [pid 738779:tid 739015] [client 20.226.5.174:4324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/.well-known/makeasmtp.php"] [unique_id "amuI9Pxa4UbeLxj1SWW32gAAAO8"]
[Thu Jul 30 12:25:09.151235 2026] [security2:error] [pid 738779:tid 738968] [client 142.93.53.183:59352] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/journal/files/PJPSQ_DATA/alfacgiapi/py.alfa"] [unique_id "amuI9fxa4UbeLxj1SWW33wAAAMA"]
[Thu Jul 30 12:25:09.202814 2026] [security2:error] [pid 738779:tid 738984] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "amuI9fxa4UbeLxj1SWW34AAAANA"]
[Thu Jul 30 12:25:09.202948 2026] [security2:error] [pid 738779:tid 738984] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "amuI9fxa4UbeLxj1SWW34AAAANA"]
[Thu Jul 30 12:25:09.291107 2026] [security2:error] [pid 738779:tid 738958] [client 20.203.148.31:43969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/config.php"] [unique_id "amuI9fxa4UbeLxj1SWW35AAAALY"]
[Thu Jul 30 12:25:09.489923 2026] [security2:error] [pid 738779:tid 738931] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/aaa.php"] [unique_id "amuI9fxa4UbeLxj1SWW35gAAAJs"]
[Thu Jul 30 12:25:09.490072 2026] [security2:error] [pid 738779:tid 738931] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/aaa.php"] [unique_id "amuI9fxa4UbeLxj1SWW35gAAAJs"]
[Thu Jul 30 12:25:09.528940 2026] [security2:error] [pid 738779:tid 738997] [client 142.93.53.183:59379] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/journal/files/PJPSQ_DATA/alfacgiapi/bash.alfa"] [unique_id "amuI9fxa4UbeLxj1SWW35wAAAN0"]
[Thu Jul 30 12:25:09.763394 2026] [security2:error] [pid 738779:tid 738947] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/gecko.php"] [unique_id "amuI9fxa4UbeLxj1SWW37QAAAKs"]
[Thu Jul 30 12:25:09.763493 2026] [security2:error] [pid 738779:tid 738947] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/gecko.php"] [unique_id "amuI9fxa4UbeLxj1SWW37QAAAKs"]
[Thu Jul 30 12:25:09.805203 2026] [security2:error] [pid 738779:tid 739032] [client 2a03:2880:f800:21:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuI9fxa4UbeLxj1SWW33gABAGw"]
[Thu Jul 30 12:25:09.908623 2026] [security2:error] [pid 738779:tid 738996] [client 142.93.53.183:59409] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/jancox/alfacgiapi/perl.alfa"] [unique_id "amuI9fxa4UbeLxj1SWW38wAAANw"]
[Thu Jul 30 12:25:10.038528 2026] [security2:error] [pid 738779:tid 739011] [client 20.226.5.174:4296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/oauth.php"] [unique_id "amuI9vxa4UbeLxj1SWW39AAAAOs"]
[Thu Jul 30 12:25:10.059150 2026] [security2:error] [pid 738779:tid 739022] [client 20.203.148.31:45037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/core.php"] [unique_id "amuI9vxa4UbeLxj1SWW39QAAAPY"]
[Thu Jul 30 12:25:10.092083 2026] [security2:error] [pid 738779:tid 738960] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/pbck.php"] [unique_id "amuI9vxa4UbeLxj1SWW39wAAALg"]
[Thu Jul 30 12:25:10.092163 2026] [security2:error] [pid 738779:tid 738960] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/pbck.php"] [unique_id "amuI9vxa4UbeLxj1SWW39wAAALg"]
[Thu Jul 30 12:25:10.156894 2026] [security2:error] [pid 738779:tid 739005] [client 38.190.144.4:60947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuI9vxa4UbeLxj1SWW3-gAAAOU"]
[Thu Jul 30 12:25:10.157043 2026] [security2:error] [pid 738779:tid 739005] [client 38.190.144.4:60947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuI9vxa4UbeLxj1SWW3-gAAAOU"]
[Thu Jul 30 12:25:10.299278 2026] [security2:error] [pid 738779:tid 739033] [client 142.93.53.183:59435] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/jancox/alfacgiapi/bash.alfa"] [unique_id "amuI9vxa4UbeLxj1SWW3-wAAAQE"]
[Thu Jul 30 12:25:10.363052 2026] [security2:error] [pid 738779:tid 738935] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/xiugai.php"] [unique_id "amuI9vxa4UbeLxj1SWW3_wAAAJ8"]
[Thu Jul 30 12:25:10.363150 2026] [security2:error] [pid 738779:tid 738935] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/xiugai.php"] [unique_id "amuI9vxa4UbeLxj1SWW3_wAAAJ8"]
[Thu Jul 30 12:25:10.688523 2026] [security2:error] [pid 738779:tid 738911] [client 142.93.53.183:59468] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/asoee/alfacgiapi/perl.alfa"] [unique_id "amuI9vxa4UbeLxj1SWW4BgAAAIc"]
[Thu Jul 30 12:25:10.700087 2026] [security2:error] [pid 738779:tid 738940] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/e.php"] [unique_id "amuI9vxa4UbeLxj1SWW4BwAAAKQ"]
[Thu Jul 30 12:25:10.700164 2026] [security2:error] [pid 738779:tid 738940] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/e.php"] [unique_id "amuI9vxa4UbeLxj1SWW4BwAAAKQ"]
[Thu Jul 30 12:25:11.040245 2026] [security2:error] [pid 738779:tid 738945] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/adminner.php"] [unique_id "amuI9_xa4UbeLxj1SWW4DAAAAKk"]
[Thu Jul 30 12:25:11.040351 2026] [security2:error] [pid 738779:tid 738945] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/adminner.php"] [unique_id "amuI9_xa4UbeLxj1SWW4DAAAAKk"]
[Thu Jul 30 12:25:11.068460 2026] [security2:error] [pid 738779:tid 738990] [client 142.93.53.183:59492] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/asoee/alfacgiapi/py.alfa"] [unique_id "amuI9_xa4UbeLxj1SWW4DQAAANY"]
[Thu Jul 30 12:25:11.165131 2026] [core:notice] [pid 738779:tid 738903] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:25:11.269555 2026] [security2:error] [pid 738779:tid 738915] [client 20.52.54.143:10218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wk/index.php"] [unique_id "amuI9_xa4UbeLxj1SWW4FgAAAIs"]
[Thu Jul 30 12:25:11.383632 2026] [security2:error] [pid 738779:tid 738984] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/file1221.php"] [unique_id "amuI9_xa4UbeLxj1SWW4JAAAANA"]
[Thu Jul 30 12:25:11.383733 2026] [security2:error] [pid 738779:tid 738984] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/file1221.php"] [unique_id "amuI9_xa4UbeLxj1SWW4JAAAANA"]
[Thu Jul 30 12:25:11.447131 2026] [security2:error] [pid 738779:tid 738970] [client 142.93.53.183:59518] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/asoee/alfacgiapi/bash.alfa"] [unique_id "amuI9_xa4UbeLxj1SWW4JwAAAMI"]
[Thu Jul 30 12:25:11.480769 2026] [security2:error] [pid 738779:tid 738926] [client 121.29.149.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuI9_xa4UbeLxj1SWW4DgAAAJY"]
[Thu Jul 30 12:25:11.641456 2026] [security2:error] [pid 738779:tid 739030] [client 2a03:2880:f800:39:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuI9_xa4UbeLxj1SWW4CwAA_nw"]
[Thu Jul 30 12:25:11.662065 2026] [security2:error] [pid 738779:tid 738996] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/inx.php"] [unique_id "amuI9_xa4UbeLxj1SWW4MQAAANw"]
[Thu Jul 30 12:25:11.662166 2026] [security2:error] [pid 738779:tid 738996] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/inx.php"] [unique_id "amuI9_xa4UbeLxj1SWW4MQAAANw"]
[Thu Jul 30 12:25:11.778534 2026] [security2:error] [pid 738779:tid 738985] [client 57.141.0.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuI9_xa4UbeLxj1SWW4FQAAANE"]
[Thu Jul 30 12:25:11.832157 2026] [security2:error] [pid 738779:tid 739024] [client 142.93.53.183:59546] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/jancox/alfacgiapi/py.alfa"] [unique_id "amuI9_xa4UbeLxj1SWW4MgAAAPg"]
[Thu Jul 30 12:25:11.939778 2026] [autoindex:error] [pid 738779:tid 738983] [client 20.226.5.174:0] AH01276: Cannot serve directory /home1/ncozztte/public_html/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:25:11.951192 2026] [security2:error] [pid 738779:tid 739027] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/qqqa.php"] [unique_id "amuI9_xa4UbeLxj1SWW4OgAAAPs"]
[Thu Jul 30 12:25:11.951279 2026] [security2:error] [pid 738779:tid 739027] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/qqqa.php"] [unique_id "amuI9_xa4UbeLxj1SWW4OgAAAPs"]
[Thu Jul 30 12:25:12.082462 2026] [security2:error] [pid 738779:tid 738932] [client 20.203.148.31:48139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/css.php"] [unique_id "amuI-Pxa4UbeLxj1SWW4OwAAAJw"]
[Thu Jul 30 12:25:12.221654 2026] [security2:error] [pid 738779:tid 738917] [client 142.93.53.183:59569] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/client_assets/src/scss/7Syndicate/oxnixcgiapi/perl.oxnix"] [unique_id "amuI-Pxa4UbeLxj1SWW4QgAAAI0"]
[Thu Jul 30 12:25:12.249126 2026] [security2:error] [pid 738779:tid 738940] [client 20.226.5.174:4291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/cgi-bin/upfile.php"] [unique_id "amuI-Pxa4UbeLxj1SWW4QwAAAKQ"]
[Thu Jul 30 12:25:12.288905 2026] [security2:error] [pid 738779:tid 738924] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/reviall.php"] [unique_id "amuI-Pxa4UbeLxj1SWW4RAAAAJQ"]
[Thu Jul 30 12:25:12.289023 2026] [security2:error] [pid 738779:tid 738924] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/reviall.php"] [unique_id "amuI-Pxa4UbeLxj1SWW4RAAAAJQ"]
[Thu Jul 30 12:25:12.568564 2026] [security2:error] [pid 738779:tid 738933] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/404.php"] [unique_id "amuI-Pxa4UbeLxj1SWW4SQAAAJ0"]
[Thu Jul 30 12:25:12.568706 2026] [security2:error] [pid 738779:tid 738933] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/404.php"] [unique_id "amuI-Pxa4UbeLxj1SWW4SQAAAJ0"]
[Thu Jul 30 12:25:12.613836 2026] [security2:error] [pid 738779:tid 738975] [client 142.93.53.183:59593] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/client_assets/src/scss/7Syndicate/oxnixcgiapi/bash.oxnix"] [unique_id "amuI-Pxa4UbeLxj1SWW4SgAAAMc"]
[Thu Jul 30 12:25:12.670465 2026] [security2:error] [pid 738779:tid 738982] [client 111.113.88.206:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuI-Pxa4UbeLxj1SWW4RQAAAM4"]
[Thu Jul 30 12:25:12.840954 2026] [security2:error] [pid 738779:tid 738958] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/bolt.php"] [unique_id "amuI-Pxa4UbeLxj1SWW4VwAAALY"]
[Thu Jul 30 12:25:12.841088 2026] [security2:error] [pid 738779:tid 738958] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/bolt.php"] [unique_id "amuI-Pxa4UbeLxj1SWW4VwAAALY"]
[Thu Jul 30 12:25:12.988873 2026] [security2:error] [pid 738779:tid 738914] [client 142.93.53.183:59612] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/client_assets/src/scss/7Syndicate/oxnixcgiapi/py.oxnix"] [unique_id "amuI-Pxa4UbeLxj1SWW4WAAAAIo"]
[Thu Jul 30 12:25:13.152945 2026] [security2:error] [pid 738779:tid 738964] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/File.php"] [unique_id "amuI-fxa4UbeLxj1SWW4YgAAALw"]
[Thu Jul 30 12:25:13.153075 2026] [security2:error] [pid 738779:tid 738964] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/File.php"] [unique_id "amuI-fxa4UbeLxj1SWW4YgAAALw"]
[Thu Jul 30 12:25:13.380686 2026] [security2:error] [pid 738779:tid 738993] [client 142.93.53.183:59638] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/classes/article/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI-fxa4UbeLxj1SWW4ZwAAANk"]
[Thu Jul 30 12:25:13.426534 2026] [security2:error] [pid 738779:tid 738949] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/fi22.php"] [unique_id "amuI-fxa4UbeLxj1SWW4aAAAAK0"]
[Thu Jul 30 12:25:13.426646 2026] [security2:error] [pid 738779:tid 738949] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/fi22.php"] [unique_id "amuI-fxa4UbeLxj1SWW4aAAAAK0"]
[Thu Jul 30 12:25:13.436926 2026] [security2:error] [pid 738779:tid 738970] [client 20.226.5.174:4326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/upload_file1.php"] [unique_id "amuI-fxa4UbeLxj1SWW4aQAAAMI"]
[Thu Jul 30 12:25:13.580655 2026] [security2:error] [pid 738779:tid 738989] [client 20.52.54.143:10216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/av.php"] [unique_id "amuI-fxa4UbeLxj1SWW4gAAAANU"]
[Thu Jul 30 12:25:13.660952 2026] [security2:error] [pid 738779:tid 738948] [client 121.29.149.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuI-fxa4UbeLxj1SWW4ZgAAAKw"]
[Thu Jul 30 12:25:13.702717 2026] [security2:error] [pid 738779:tid 739001] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/zero.php"] [unique_id "amuI-fxa4UbeLxj1SWW4hAAAAOE"]
[Thu Jul 30 12:25:13.702803 2026] [security2:error] [pid 738779:tid 739001] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/zero.php"] [unique_id "amuI-fxa4UbeLxj1SWW4hAAAAOE"]
[Thu Jul 30 12:25:13.768653 2026] [security2:error] [pid 738779:tid 738987] [client 142.93.53.183:59663] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/classes/article/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuI-fxa4UbeLxj1SWW4iQAAANM"]
[Thu Jul 30 12:25:13.995201 2026] [security2:error] [pid 738779:tid 739013] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/1xmomo.php"] [unique_id "amuI-fxa4UbeLxj1SWW4kQAAAO0"]
[Thu Jul 30 12:25:13.995285 2026] [security2:error] [pid 738779:tid 739013] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/1xmomo.php"] [unique_id "amuI-fxa4UbeLxj1SWW4kQAAAO0"]
[Thu Jul 30 12:25:14.141670 2026] [security2:error] [pid 738779:tid 738913] [client 142.93.53.183:59698] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/classes/article/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuI-vxa4UbeLxj1SWW4nQAAAIk"]
[Thu Jul 30 12:25:14.180925 2026] [security2:error] [pid 738779:tid 739034] [client 20.52.54.143:9348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/mini.php"] [unique_id "amuI-vxa4UbeLxj1SWW4nwAAAQI"]
[Thu Jul 30 12:25:14.282304 2026] [security2:error] [pid 738779:tid 738917] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/fmws.php"] [unique_id "amuI-vxa4UbeLxj1SWW4rwAAAI0"]
[Thu Jul 30 12:25:14.282394 2026] [security2:error] [pid 738779:tid 738917] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/fmws.php"] [unique_id "amuI-vxa4UbeLxj1SWW4rwAAAI0"]
[Thu Jul 30 12:25:14.497197 2026] [security2:error] [pid 738779:tid 738970] [client 20.226.5.174:4350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/rafa.php"] [unique_id "amuI-vxa4UbeLxj1SWW4swAAAMI"]
[Thu Jul 30 12:25:14.537222 2026] [security2:error] [pid 738779:tid 738965] [client 142.93.53.183:59727] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/jancox/alfacgiapi/perl.alfa"] [unique_id "amuI-vxa4UbeLxj1SWW4tAAAAL0"]
[Thu Jul 30 12:25:14.550760 2026] [security2:error] [pid 738779:tid 738968] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuI-vxa4UbeLxj1SWW4tgAAAMA"]
[Thu Jul 30 12:25:14.550845 2026] [security2:error] [pid 738779:tid 738968] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuI-vxa4UbeLxj1SWW4tgAAAMA"]
[Thu Jul 30 12:25:14.836666 2026] [security2:error] [pid 738779:tid 738992] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/hp2.php"] [unique_id "amuI-vxa4UbeLxj1SWW40wAAANg"]
[Thu Jul 30 12:25:14.836772 2026] [security2:error] [pid 738779:tid 738992] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/hp2.php"] [unique_id "amuI-vxa4UbeLxj1SWW40wAAANg"]
[Thu Jul 30 12:25:14.881621 2026] [security2:error] [pid 738779:tid 738950] [client 111.113.88.206:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuI-vxa4UbeLxj1SWW4tQAAAK4"]
[Thu Jul 30 12:25:14.927346 2026] [security2:error] [pid 738779:tid 739028] [client 142.93.53.183:59749] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/jancox/alfacgiapi/bash.alfa"] [unique_id "amuI-vxa4UbeLxj1SWW41QAAAPw"]
[Thu Jul 30 12:25:14.971520 2026] [security2:error] [pid 738779:tid 738986] [client 20.203.148.31:48107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/database.php"] [unique_id "amuI-vxa4UbeLxj1SWW41gAAANI"]
[Thu Jul 30 12:25:14.997649 2026] [security2:error] [pid 738779:tid 739005] [client 98.84.60.17:22273] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2018/06/WhatsApp-Image-2018-06-30-at-21.42.37-1-768x1024.jpeg"] [unique_id "amuI-vxa4UbeLxj1SWW42AAAAOU"]
[Thu Jul 30 12:25:15.107127 2026] [security2:error] [pid 738779:tid 738948] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/aabb.php"] [unique_id "amuI-_xa4UbeLxj1SWW43AAAAKw"]
[Thu Jul 30 12:25:15.107260 2026] [security2:error] [pid 738779:tid 738948] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/aabb.php"] [unique_id "amuI-_xa4UbeLxj1SWW43AAAAKw"]
[Thu Jul 30 12:25:15.266595 2026] [security2:error] [pid 738779:tid 739031] [client 20.52.54.143:10198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/aa.php"] [unique_id "amuI-_xa4UbeLxj1SWW43gAAAP8"]
[Thu Jul 30 12:25:15.315261 2026] [security2:error] [pid 738779:tid 738927] [client 142.93.53.183:59780] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/jancox/alfacgiapi/py.alfa"] [unique_id "amuI-_xa4UbeLxj1SWW46AAAAJc"]
[Thu Jul 30 12:25:15.404531 2026] [security2:error] [pid 738779:tid 738926] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/1254xx.php"] [unique_id "amuI-_xa4UbeLxj1SWW48wAAAJY"]
[Thu Jul 30 12:25:15.404627 2026] [security2:error] [pid 738779:tid 738926] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/1254xx.php"] [unique_id "amuI-_xa4UbeLxj1SWW48wAAAJY"]
[Thu Jul 30 12:25:15.690615 2026] [security2:error] [pid 738779:tid 738993] [client 142.93.53.183:59801] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/client_assets/vendors/jquery.sparkline/src/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI-_xa4UbeLxj1SWW4_AAAANk"]
[Thu Jul 30 12:25:15.752632 2026] [security2:error] [pid 738779:tid 738943] [client 20.203.148.31:48170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/db.php"] [unique_id "amuI-_xa4UbeLxj1SWW4_gAAAKc"]
[Thu Jul 30 12:25:15.756063 2026] [security2:error] [pid 738779:tid 738938] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "amuI-_xa4UbeLxj1SWW4_wAAAKI"]
[Thu Jul 30 12:25:15.756149 2026] [security2:error] [pid 738779:tid 738938] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "amuI-_xa4UbeLxj1SWW4_wAAAKI"]
[Thu Jul 30 12:25:15.888542 2026] [security2:error] [pid 738779:tid 739021] [client 121.29.149.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuI-_xa4UbeLxj1SWW4-AAAAPU"]
[Thu Jul 30 12:25:15.929748 2026] [security2:error] [pid 738779:tid 738989] [client 20.52.54.143:10234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/w.php"] [unique_id "amuI-_xa4UbeLxj1SWW5CAAAANU"]
[Thu Jul 30 12:25:16.028624 2026] [security2:error] [pid 738779:tid 738955] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/pms297.php"] [unique_id "amuI_Pxa4UbeLxj1SWW5CQAAALM"]
[Thu Jul 30 12:25:16.028731 2026] [security2:error] [pid 738779:tid 738955] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/pms297.php"] [unique_id "amuI_Pxa4UbeLxj1SWW5CQAAALM"]
[Thu Jul 30 12:25:16.083762 2026] [security2:error] [pid 738779:tid 738945] [client 142.93.53.183:59823] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/client_assets/vendors/jquery.sparkline/src/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuI_Pxa4UbeLxj1SWW5CgAAAKk"]
[Thu Jul 30 12:25:16.299300 2026] [security2:error] [pid 738779:tid 738933] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/1PJcpMFsD8B.php"] [unique_id "amuI_Pxa4UbeLxj1SWW5FQAAAJ0"]
[Thu Jul 30 12:25:16.299445 2026] [security2:error] [pid 738779:tid 738933] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/1PJcpMFsD8B.php"] [unique_id "amuI_Pxa4UbeLxj1SWW5FQAAAJ0"]
[Thu Jul 30 12:25:16.387139 2026] [security2:error] [pid 738779:tid 738952] [client 20.203.148.31:46645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/default.php"] [unique_id "amuI_Pxa4UbeLxj1SWW5HAAAALA"]
[Thu Jul 30 12:25:16.474281 2026] [security2:error] [pid 738779:tid 738937] [client 142.93.53.183:59851] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/client_assets/vendors/jquery.sparkline/src/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuI_Pxa4UbeLxj1SWW5HgAAAKE"]
[Thu Jul 30 12:25:16.545539 2026] [core:notice] [pid 738779:tid 738829] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:25:16.575079 2026] [security2:error] [pid 738779:tid 738964] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "amuI_Pxa4UbeLxj1SWW5IwAAALw"]
[Thu Jul 30 12:25:16.575186 2026] [security2:error] [pid 738779:tid 738964] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "amuI_Pxa4UbeLxj1SWW5IwAAALw"]
[Thu Jul 30 12:25:16.711372 2026] [security2:error] [pid 738779:tid 739009] [client 20.52.54.143:10186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/admin.php"] [unique_id "amuI_Pxa4UbeLxj1SWW5KAAAAOk"]
[Thu Jul 30 12:25:16.859961 2026] [security2:error] [pid 738779:tid 738932] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "amuI_Pxa4UbeLxj1SWW5LQAAAJw"]
[Thu Jul 30 12:25:16.860125 2026] [security2:error] [pid 738779:tid 738932] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "amuI_Pxa4UbeLxj1SWW5LQAAAJw"]
[Thu Jul 30 12:25:16.862406 2026] [security2:error] [pid 738779:tid 738992] [client 142.93.53.183:59877] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/uploads/.well-known/acme-challenge/hvp/data-manual/7Syndicate/oxnixcgiapi/perl.oxnix"] [unique_id "amuI_Pxa4UbeLxj1SWW5LwAAANg"]
[Thu Jul 30 12:25:17.100530 2026] [security2:error] [pid 738779:tid 739035] [client 111.113.88.206:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuI_Pxa4UbeLxj1SWW5LAAAAQM"]
[Thu Jul 30 12:25:17.138961 2026] [security2:error] [pid 738779:tid 738999] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuI_fxa4UbeLxj1SWW5PQAAAN8"]
[Thu Jul 30 12:25:17.139093 2026] [security2:error] [pid 738779:tid 738999] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuI_fxa4UbeLxj1SWW5PQAAAN8"]
[Thu Jul 30 12:25:17.255629 2026] [security2:error] [pid 738779:tid 738916] [client 142.93.53.183:59901] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/uploads/.well-known/acme-challenge/hvp/data-manual/7Syndicate/oxnixcgiapi/bash.oxnix"] [unique_id "amuI_fxa4UbeLxj1SWW5RgAAAIw"]
[Thu Jul 30 12:25:17.345502 2026] [security2:error] [pid 738779:tid 738986] [client 20.226.5.174:4316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-admin/maint/src_api.php"] [unique_id "amuI_fxa4UbeLxj1SWW5SwAAANI"]
[Thu Jul 30 12:25:17.410264 2026] [security2:error] [pid 738779:tid 738963] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/dyui.php"] [unique_id "amuI_fxa4UbeLxj1SWW5UgAAALs"]
[Thu Jul 30 12:25:17.410390 2026] [security2:error] [pid 738779:tid 738963] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/dyui.php"] [unique_id "amuI_fxa4UbeLxj1SWW5UgAAALs"]
[Thu Jul 30 12:25:17.509588 2026] [core:notice] [pid 738779:tid 739008] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:25:17.643180 2026] [security2:error] [pid 738779:tid 738910] [client 142.93.53.183:59931] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/uploads/.well-known/acme-challenge/hvp/data-manual/7Syndicate/oxnixcgiapi/py.oxnix"] [unique_id "amuI_fxa4UbeLxj1SWW5XQAAAIY"]
[Thu Jul 30 12:25:17.682785 2026] [security2:error] [pid 738779:tid 738991] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/ho.php"] [unique_id "amuI_fxa4UbeLxj1SWW5YgAAANc"]
[Thu Jul 30 12:25:17.682898 2026] [security2:error] [pid 738779:tid 738991] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/ho.php"] [unique_id "amuI_fxa4UbeLxj1SWW5YgAAANc"]
[Thu Jul 30 12:25:17.765225 2026] [security2:error] [pid 738779:tid 739019] [client 20.52.54.143:10223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuI_fxa4UbeLxj1SWW5ZgAAAPM"]
[Thu Jul 30 12:25:17.971204 2026] [security2:error] [pid 738779:tid 739022] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/66b867516c8f01.php"] [unique_id "amuI_fxa4UbeLxj1SWW5agAAAPY"]
[Thu Jul 30 12:25:17.971298 2026] [security2:error] [pid 738779:tid 739022] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/66b867516c8f01.php"] [unique_id "amuI_fxa4UbeLxj1SWW5agAAAPY"]
[Thu Jul 30 12:25:18.035222 2026] [security2:error] [pid 738779:tid 739025] [client 142.93.53.183:59956] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/uploads/volunteers/SEOBARBAR_1337/barbarpride/perl.alfa"] [unique_id "amuI_vxa4UbeLxj1SWW5bwAAAPk"]
[Thu Jul 30 12:25:18.241758 2026] [security2:error] [pid 738779:tid 738989] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/ext.php"] [unique_id "amuI_vxa4UbeLxj1SWW5cwAAANU"]
[Thu Jul 30 12:25:18.241856 2026] [security2:error] [pid 738779:tid 738989] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/ext.php"] [unique_id "amuI_vxa4UbeLxj1SWW5cwAAANU"]
[Thu Jul 30 12:25:18.322592 2026] [security2:error] [pid 738779:tid 738942] [client 20.203.148.31:46642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/dropdown.php"] [unique_id "amuI_vxa4UbeLxj1SWW5dwAAAKY"]
[Thu Jul 30 12:25:18.428046 2026] [security2:error] [pid 738779:tid 738967] [client 142.93.53.183:59980] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/uploads/volunteers/SEOBARBAR_1337/barbarpride/bash.alfa"] [unique_id "amuI_vxa4UbeLxj1SWW5ewAAAL8"]
[Thu Jul 30 12:25:18.525853 2026] [security2:error] [pid 738779:tid 739017] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "amuI_vxa4UbeLxj1SWW5fwAAAPE"]
[Thu Jul 30 12:25:18.525952 2026] [security2:error] [pid 738779:tid 739017] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "amuI_vxa4UbeLxj1SWW5fwAAAPE"]
[Thu Jul 30 12:25:18.799397 2026] [security2:error] [pid 738779:tid 738983] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/xy9brdftkyivz9ij6rusmsCdefault.php"] [unique_id "amuI_vxa4UbeLxj1SWW5jAAAAM8"]
[Thu Jul 30 12:25:18.799498 2026] [security2:error] [pid 738779:tid 738983] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/xy9brdftkyivz9ij6rusmsCdefault.php"] [unique_id "amuI_vxa4UbeLxj1SWW5jAAAAM8"]
[Thu Jul 30 12:25:18.819737 2026] [security2:error] [pid 738779:tid 739013] [client 142.93.53.183:60002] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/uploads/volunteers/SEOBARBAR_1337/barbarpride/py.alfa"] [unique_id "amuI_vxa4UbeLxj1SWW5jgAAAO0"]
[Thu Jul 30 12:25:19.000079 2026] [security2:error] [pid 738779:tid 739028] [client 20.203.148.31:43953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/edit.php"] [unique_id "amuI_vxa4UbeLxj1SWW5mAAAAPw"]
[Thu Jul 30 12:25:19.065047 2026] [security2:error] [pid 738779:tid 738926] [client 20.226.5.174:4298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/atomlib.php"] [unique_id "amuI__xa4UbeLxj1SWW5mQAAAJY"]
[Thu Jul 30 12:25:19.074030 2026] [security2:error] [pid 738779:tid 738943] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/584062352875874akp.php"] [unique_id "amuI__xa4UbeLxj1SWW5mwAAAKc"]
[Thu Jul 30 12:25:19.074162 2026] [security2:error] [pid 738779:tid 738943] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/584062352875874akp.php"] [unique_id "amuI__xa4UbeLxj1SWW5mwAAAKc"]
[Thu Jul 30 12:25:19.209092 2026] [security2:error] [pid 738779:tid 738951] [client 142.93.53.183:60026] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/uploads/volunteers/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI__xa4UbeLxj1SWW5pgAAAK8"]
[Thu Jul 30 12:25:19.390677 2026] [security2:error] [pid 738779:tid 738967] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/diidi.php"] [unique_id "amuI__xa4UbeLxj1SWW5rgAAAL8"]
[Thu Jul 30 12:25:19.390758 2026] [security2:error] [pid 738779:tid 738967] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/diidi.php"] [unique_id "amuI__xa4UbeLxj1SWW5rgAAAL8"]
[Thu Jul 30 12:25:19.443417 2026] [security2:error] [pid 738779:tid 738855] [remote 57.141.0.34:49946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/390124662/feed/rss2/"] [unique_id "amuI__xa4UbeLxj1SWW5rwAAk0s"]
[Thu Jul 30 12:25:19.599390 2026] [security2:error] [pid 738779:tid 738973] [client 142.93.53.183:60056] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/uploads/volunteers/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuI__xa4UbeLxj1SWW5tAAAAMU"]
[Thu Jul 30 12:25:19.668944 2026] [security2:error] [pid 738779:tid 739006] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/clarebypas.php"] [unique_id "amuI__xa4UbeLxj1SWW5tgAAAOY"]
[Thu Jul 30 12:25:19.669062 2026] [security2:error] [pid 738779:tid 739006] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/clarebypas.php"] [unique_id "amuI__xa4UbeLxj1SWW5tgAAAOY"]
[Thu Jul 30 12:25:19.990128 2026] [security2:error] [pid 738779:tid 738991] [client 142.93.53.183:60081] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/uploads/volunteers/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuI__xa4UbeLxj1SWW5xQAAANc"]
[Thu Jul 30 12:25:20.001397 2026] [security2:error] [pid 738779:tid 738939] [client 57.141.0.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuI__xa4UbeLxj1SWW5rQAAAKM"]
[Thu Jul 30 12:25:20.017820 2026] [core:notice] [pid 738779:tid 738862] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:25:20.021489 2026] [security2:error] [pid 738779:tid 738910] [client 195.63.29.16:14456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "deltaedu.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuI__xa4UbeLxj1SWW5wwAAhk4"], referer: https://deltaedu.net/wp-admin/admin-ajax.php?action=tnp&na=s
[Thu Jul 30 12:25:20.150746 2026] [security2:error] [pid 738779:tid 739002] [client 20.203.148.31:43961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/f35.php"] [unique_id "amuJAPxa4UbeLxj1SWW5ywAAAOI"]
[Thu Jul 30 12:25:20.363540 2026] [security2:error] [pid 738779:tid 739033] [client 142.93.53.183:60110] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/uploads/.well-known/acme-challenge/SEOBARBAR_1337/barbarpride/perl.alfa"] [unique_id "amuJAPxa4UbeLxj1SWW50wAAAQE"]
[Thu Jul 30 12:25:20.449774 2026] [security2:error] [pid 738779:tid 739013] [client 20.226.5.174:4338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-trackback.php"] [unique_id "amuJAPxa4UbeLxj1SWW53wAAAO0"]
[Thu Jul 30 12:25:20.597008 2026] [core:notice] [pid 738779:tid 738850] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:25:20.740668 2026] [security2:error] [pid 738779:tid 739016] [client 142.93.53.183:60134] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/uploads/.well-known/acme-challenge/SEOBARBAR_1337/barbarpride/bash.alfa"] [unique_id "amuJAPxa4UbeLxj1SWW5_AAAAPA"]
[Thu Jul 30 12:25:21.130362 2026] [security2:error] [pid 738779:tid 738925] [client 142.93.53.183:60158] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/uploads/.well-known/acme-challenge/SEOBARBAR_1337/barbarpride/py.alfa"] [unique_id "amuJAfxa4UbeLxj1SWW6DAAAAJU"]
[Thu Jul 30 12:25:21.482606 2026] [security2:error] [pid 738779:tid 738986] [client 20.52.54.143:10210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/m.php"] [unique_id "amuJAfxa4UbeLxj1SWW6JwAAANI"]
[Thu Jul 30 12:25:21.521115 2026] [security2:error] [pid 738779:tid 739019] [client 142.93.53.183:60186] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/.well-known/acme-challenge/hvp/data-manual/7Syndicate/oxnixcgiapi/perl.oxnix"] [unique_id "amuJAfxa4UbeLxj1SWW6KgAAAPM"]
[Thu Jul 30 12:25:21.910752 2026] [security2:error] [pid 738779:tid 738948] [client 142.93.53.183:60211] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/.well-known/acme-challenge/hvp/data-manual/7Syndicate/oxnixcgiapi/bash.oxnix"] [unique_id "amuJAfxa4UbeLxj1SWW6NwAAAKw"]
[Thu Jul 30 12:25:22.209109 2026] [security2:error] [pid 738779:tid 739005] [client 57.141.0.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJAfxa4UbeLxj1SWW6NAAAAOU"]
[Thu Jul 30 12:25:22.302180 2026] [security2:error] [pid 738779:tid 739022] [client 142.93.53.183:60236] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/.well-known/acme-challenge/hvp/data-manual/7Syndicate/oxnixcgiapi/py.oxnix"] [unique_id "amuJAvxa4UbeLxj1SWW6UQAAAPY"]
[Thu Jul 30 12:25:22.420174 2026] [security2:error] [pid 738779:tid 738946] [client 20.226.5.174:4318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "amuJAvxa4UbeLxj1SWW6VQAAAKo"]
[Thu Jul 30 12:25:22.566214 2026] [security2:error] [pid 738779:tid 738944] [client 20.52.54.143:9358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuJAvxa4UbeLxj1SWW6UAAAAKg"]
[Thu Jul 30 12:25:22.693640 2026] [security2:error] [pid 738779:tid 738975] [client 142.93.53.183:60267] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/volunteers/SEOBARBAR_1337/barbarpride/perl.alfa"] [unique_id "amuJAvxa4UbeLxj1SWW6agAAAMc"]
[Thu Jul 30 12:25:23.073830 2026] [security2:error] [pid 738779:tid 738922] [client 20.203.148.31:46634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/f7.php"] [unique_id "amuJA_xa4UbeLxj1SWW6fgAAAJI"]
[Thu Jul 30 12:25:23.083855 2026] [security2:error] [pid 738779:tid 738929] [client 142.93.53.183:60295] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/volunteers/SEOBARBAR_1337/barbarpride/bash.alfa"] [unique_id "amuJA_xa4UbeLxj1SWW6fwAAAJk"]
[Thu Jul 30 12:25:23.474482 2026] [security2:error] [pid 738779:tid 738971] [client 142.93.53.183:60309] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/volunteers/SEOBARBAR_1337/barbarpride/py.alfa"] [unique_id "amuJA_xa4UbeLxj1SWW6lQAAAMM"]
[Thu Jul 30 12:25:23.530841 2026] [security2:error] [pid 738779:tid 739023] [client 111.113.88.206:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJA_xa4UbeLxj1SWW6iAAAAPc"]
[Thu Jul 30 12:25:23.864969 2026] [security2:error] [pid 738779:tid 739014] [client 142.93.53.183:60326] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/volunteers/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJA_xa4UbeLxj1SWW6oQAAAO4"]
[Thu Jul 30 12:25:24.179360 2026] [security2:error] [pid 738779:tid 738912] [client 38.190.144.4:61445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJBPxa4UbeLxj1SWW6rgAAAIg"]
[Thu Jul 30 12:25:24.179457 2026] [security2:error] [pid 738779:tid 738912] [client 38.190.144.4:61445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJBPxa4UbeLxj1SWW6rgAAAIg"]
[Thu Jul 30 12:25:24.255216 2026] [security2:error] [pid 738779:tid 738911] [client 142.93.53.183:60341] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/volunteers/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJBPxa4UbeLxj1SWW6tAAAAIc"]
[Thu Jul 30 12:25:24.539286 2026] [security2:error] [pid 738779:tid 739035] [client 121.29.149.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJBPxa4UbeLxj1SWW6rwAAAQM"]
[Thu Jul 30 12:25:24.646154 2026] [security2:error] [pid 738779:tid 738919] [client 142.93.53.183:60358] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/volunteers/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJBPxa4UbeLxj1SWW6vgAAAI8"]
[Thu Jul 30 12:25:24.906549 2026] [core:notice] [pid 738779:tid 738966] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:25:25.037202 2026] [security2:error] [pid 738779:tid 738913] [client 142.93.53.183:60375] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/.well-known/acme-challenge/SEOBARBAR_1337/barbarpride/perl.alfa"] [unique_id "amuJBfxa4UbeLxj1SWW6yQAAAIk"]
[Thu Jul 30 12:25:25.427418 2026] [security2:error] [pid 738779:tid 738998] [client 142.93.53.183:60388] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/.well-known/acme-challenge/SEOBARBAR_1337/barbarpride/bash.alfa"] [unique_id "amuJBfxa4UbeLxj1SWW6zwAAAN4"]
[Thu Jul 30 12:25:25.706508 2026] [security2:error] [pid 738779:tid 738992] [client 111.113.88.206:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJBfxa4UbeLxj1SWW6zgAAANg"]
[Thu Jul 30 12:25:25.819500 2026] [security2:error] [pid 738779:tid 738977] [client 142.93.53.183:60400] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/.well-known/acme-challenge/SEOBARBAR_1337/barbarpride/py.alfa"] [unique_id "amuJBfxa4UbeLxj1SWW61gAAAMk"]
[Thu Jul 30 12:25:25.826458 2026] [security2:error] [pid 738779:tid 738954] [client 20.226.5.174:4309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/doc.php/"] [unique_id "amuJBfxa4UbeLxj1SWW61wAAALI"]
[Thu Jul 30 12:25:26.209125 2026] [security2:error] [pid 738779:tid 738975] [client 142.93.53.183:60418] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/tag-cloud/alfacgiapi/perl.alfa"] [unique_id "amuJBvxa4UbeLxj1SWW62wAAAMc"]
[Thu Jul 30 12:25:26.599553 2026] [security2:error] [pid 738779:tid 738951] [client 142.93.53.183:60430] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/template-part/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJBvxa4UbeLxj1SWW64wAAAK8"]
[Thu Jul 30 12:25:26.762304 2026] [security2:error] [pid 738779:tid 738955] [client 121.29.149.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJBvxa4UbeLxj1SWW64QAAALM"]
[Thu Jul 30 12:25:26.913375 2026] [security2:error] [pid 738779:tid 738909] [client 20.226.5.174:4304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/error_exception.php"] [unique_id "amuJBvxa4UbeLxj1SWW68wAAAIU"]
[Thu Jul 30 12:25:26.986443 2026] [security2:error] [pid 738779:tid 738919] [client 142.93.53.183:60441] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/template-part/alfacgiapi/perl.alfa"] [unique_id "amuJBvxa4UbeLxj1SWW69AAAAI8"]
[Thu Jul 30 12:25:27.131796 2026] [security2:error] [pid 738779:tid 738934] [client 57.141.0.9:60022] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuJBvxa4UbeLxj1SWW67gAAnhc"], referer: https://igetvape-australia.com/product/iget-bar-pro-blackberry-pomegranate-cherry/?add-to-cart=102
[Thu Jul 30 12:25:27.379162 2026] [security2:error] [pid 738779:tid 739022] [client 142.93.53.183:60459] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/term-description/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJB_xa4UbeLxj1SWW6_wAAAPY"]
[Thu Jul 30 12:25:27.766414 2026] [security2:error] [pid 738779:tid 738993] [client 142.93.53.183:60474] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/term-description/alfacgiapi/perl.alfa"] [unique_id "amuJB_xa4UbeLxj1SWW7CwAAANk"]
[Thu Jul 30 12:25:27.924143 2026] [proxy:error] [pid 738779:tid 738967] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:25:27.924194 2026] [proxy_http:error] [pid 738779:tid 738967] [client 20.52.54.143:10220] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:25:27.924962 2026] [proxy:error] [pid 738779:tid 738967] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:25:27.925026 2026] [proxy_http:error] [pid 738779:tid 738967] [client 20.52.54.143:10220] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:25:27.930580 2026] [security2:error] [pid 738779:tid 739009] [client 111.113.88.206:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJB_xa4UbeLxj1SWW7BwAAAOk"]
[Thu Jul 30 12:25:28.126835 2026] [security2:error] [pid 738779:tid 739016] [client 57.141.0.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJB_xa4UbeLxj1SWW7AgAAAPA"]
[Thu Jul 30 12:25:28.146169 2026] [security2:error] [pid 738779:tid 739003] [client 142.93.53.183:60484] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/text-columns/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJCPxa4UbeLxj1SWW7FgAAAOM"]
[Thu Jul 30 12:25:28.518684 2026] [security2:error] [pid 738779:tid 738934] [client 142.93.53.183:60498] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/text-columns/alfacgiapi/perl.alfa"] [unique_id "amuJCPxa4UbeLxj1SWW7KgAAAJ4"]
[Thu Jul 30 12:25:28.763488 2026] [security2:error] [pid 738779:tid 738930] [client 20.226.5.174:4299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/infos.php"] [unique_id "amuJCPxa4UbeLxj1SWW7OAAAAJo"]
[Thu Jul 30 12:25:28.894057 2026] [security2:error] [pid 738779:tid 739011] [client 142.93.53.183:60517] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/verse/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJCPxa4UbeLxj1SWW7OQAAAOs"]
[Thu Jul 30 12:25:28.959990 2026] [security2:error] [pid 738779:tid 738947] [client 121.29.149.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJCPxa4UbeLxj1SWW7MQAAAKs"]
[Thu Jul 30 12:25:29.051445 2026] [security2:error] [pid 738779:tid 738987] [client 20.52.54.143:9347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/classwithtostring.php"] [unique_id "amuJCfxa4UbeLxj1SWW7PwAAANM"]
[Thu Jul 30 12:25:29.287336 2026] [security2:error] [pid 738779:tid 738943] [client 142.93.53.183:60531] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/verse/alfacgiapi/perl.alfa"] [unique_id "amuJCfxa4UbeLxj1SWW7RAAAAKc"]
[Thu Jul 30 12:25:29.591940 2026] [security2:error] [pid 738779:tid 739027] [client 20.52.54.143:10205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/gmo.php"] [unique_id "amuJCfxa4UbeLxj1SWW7SQAAAPs"]
[Thu Jul 30 12:25:29.677402 2026] [security2:error] [pid 738779:tid 738991] [client 142.93.53.183:60546] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/video/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJCfxa4UbeLxj1SWW7SwAAANc"]
[Thu Jul 30 12:25:30.067077 2026] [security2:error] [pid 738779:tid 739024] [client 142.93.53.183:60562] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/video/alfacgiapi/perl.alfa"] [unique_id "amuJCvxa4UbeLxj1SWW7VAAAAPg"]
[Thu Jul 30 12:25:30.085167 2026] [security2:error] [pid 738779:tid 738968] [client 111.113.88.206:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJCfxa4UbeLxj1SWW7TwAAAMA"]
[Thu Jul 30 12:25:30.239786 2026] [security2:error] [pid 738779:tid 738956] [client 20.226.5.174:4322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/contact.php"] [unique_id "amuJCvxa4UbeLxj1SWW7VgAAALQ"]
[Thu Jul 30 12:25:30.297104 2026] [security2:error] [pid 738779:tid 739028] [client 20.52.54.143:9359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/languages/index.php"] [unique_id "amuJCvxa4UbeLxj1SWW7WgAAAPw"]
[Thu Jul 30 12:25:30.455067 2026] [security2:error] [pid 738779:tid 738982] [client 142.93.53.183:60579] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/widget-group/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJCvxa4UbeLxj1SWW7XAAAAM4"]
[Thu Jul 30 12:25:30.788885 2026] [security2:error] [pid 738779:tid 738997] [client 20.52.54.143:10196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-the.php"] [unique_id "amuJCvxa4UbeLxj1SWW7ZQAAAN0"]
[Thu Jul 30 12:25:30.849874 2026] [security2:error] [pid 738779:tid 738972] [client 142.93.53.183:60593] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/widget-group/alfacgiapi/perl.alfa"] [unique_id "amuJCvxa4UbeLxj1SWW7ZgAAAMQ"]
[Thu Jul 30 12:25:31.092807 2026] [security2:error] [pid 738779:tid 738966] [client 121.29.149.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJCvxa4UbeLxj1SWW7YQAAAL4"]
[Thu Jul 30 12:25:31.240102 2026] [security2:error] [pid 738779:tid 738944] [client 142.93.53.183:60608] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/certificates/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJC_xa4UbeLxj1SWW7bQAAAKg"]
[Thu Jul 30 12:25:31.311267 2026] [security2:error] [pid 738779:tid 738981] [client 20.52.54.143:9362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/404.php"] [unique_id "amuJC_xa4UbeLxj1SWW7dwAAAM0"]
[Thu Jul 30 12:25:31.519198 2026] [security2:error] [pid 738779:tid 738926] [client 20.226.5.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJC_xa4UbeLxj1SWW7cAAAAJY"]
[Thu Jul 30 12:25:31.629004 2026] [security2:error] [pid 738779:tid 739032] [client 142.93.53.183:60624] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/certificates/alfacgiapi/perl.alfa"] [unique_id "amuJC_xa4UbeLxj1SWW7fwAAAQA"]
[Thu Jul 30 12:25:32.002642 2026] [security2:error] [pid 738779:tid 738994] [client 142.93.53.183:60640] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/css/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJDPxa4UbeLxj1SWW7hAAAANo"]
[Thu Jul 30 12:25:32.135287 2026] [security2:error] [pid 738779:tid 738961] [client 20.226.5.174:4166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/user.php"] [unique_id "amuJDPxa4UbeLxj1SWW7iAAAALk"]
[Thu Jul 30 12:25:32.168243 2026] [security2:error] [pid 738779:tid 738984] [client 111.113.88.206:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJC_xa4UbeLxj1SWW7gwAAANA"]
[Thu Jul 30 12:25:32.232275 2026] [security2:error] [pid 738779:tid 738843] [remote 57.141.0.12:57332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuJDPxa4UbeLxj1SWW7jAAApD8"]
[Thu Jul 30 12:25:32.380774 2026] [security2:error] [pid 738779:tid 738974] [client 142.93.53.183:60652] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/css/alfacgiapi/perl.alfa"] [unique_id "amuJDPxa4UbeLxj1SWW7jQAAAMY"]
[Thu Jul 30 12:25:32.771279 2026] [security2:error] [pid 738779:tid 738960] [client 142.93.53.183:60667] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/customize/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJDPxa4UbeLxj1SWW7lgAAALg"]
[Thu Jul 30 12:25:33.162340 2026] [security2:error] [pid 738779:tid 738939] [client 142.93.53.183:60683] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/customize/alfacgiapi/perl.alfa"] [unique_id "amuJDfxa4UbeLxj1SWW7oAAAAKM"]
[Thu Jul 30 12:25:33.208538 2026] [security2:error] [pid 738779:tid 738945] [client 121.29.149.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJDPxa4UbeLxj1SWW7mQAAAKk"]
[Thu Jul 30 12:25:33.549912 2026] [security2:error] [pid 738779:tid 738977] [client 142.93.53.183:60703] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/fonts/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJDfxa4UbeLxj1SWW7qgAAAMk"]
[Thu Jul 30 12:25:33.584261 2026] [security2:error] [pid 738779:tid 739017] [client 20.52.54.143:9345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/init.php"] [unique_id "amuJDfxa4UbeLxj1SWW7rAAAAPE"]
[Thu Jul 30 12:25:33.609095 2026] [security2:error] [pid 738779:tid 739026] [client 87.101.92.171:53760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.92.101.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuJDfxa4UbeLxj1SWW7rQAAAPo"]
[Thu Jul 30 12:25:33.609183 2026] [security2:error] [pid 738779:tid 739026] [client 87.101.92.171:53760] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuJDfxa4UbeLxj1SWW7rQAAAPo"]
[Thu Jul 30 12:25:33.728429 2026] [security2:error] [pid 738779:tid 739022] [client 20.226.5.174:4310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/env.php"] [unique_id "amuJDfxa4UbeLxj1SWW7sQAAAPY"]
[Thu Jul 30 12:25:33.930618 2026] [security2:error] [pid 738779:tid 738986] [client 142.93.53.183:60721] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/fonts/alfacgiapi/perl.alfa"] [unique_id "amuJDfxa4UbeLxj1SWW7sgAAANI"]
[Thu Jul 30 12:25:34.318350 2026] [security2:error] [pid 738779:tid 738956] [client 142.93.53.183:60736] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/html-api/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJDvxa4UbeLxj1SWW7wAAAALQ"]
[Thu Jul 30 12:25:34.482425 2026] [security2:error] [pid 738779:tid 738963] [client 111.113.88.206:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJDvxa4UbeLxj1SWW7twAAALs"]
[Thu Jul 30 12:25:34.544120 2026] [security2:error] [pid 738779:tid 738917] [client 20.52.54.143:10192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/file5.php"] [unique_id "amuJDvxa4UbeLxj1SWW7xQAAAI0"]
[Thu Jul 30 12:25:34.701819 2026] [security2:error] [pid 738779:tid 738965] [client 142.93.53.183:60751] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/html-api/alfacgiapi/perl.alfa"] [unique_id "amuJDvxa4UbeLxj1SWW7xgAAAL0"]
[Thu Jul 30 12:25:34.854194 2026] [security2:error] [pid 738779:tid 739036] [client 20.226.5.174:4302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-content/uploads/de_fb_uploads/b.php"] [unique_id "amuJDvxa4UbeLxj1SWW7ygAAAQQ"]
[Thu Jul 30 12:25:35.096273 2026] [security2:error] [pid 738779:tid 738987] [client 142.93.53.183:60769] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/images/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJD_xa4UbeLxj1SWW70gAAANM"]
[Thu Jul 30 12:25:35.162932 2026] [security2:error] [pid 738779:tid 739023] [client 20.52.54.143:10215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amuJD_xa4UbeLxj1SWW71AAAAPc"]
[Thu Jul 30 12:25:35.216534 2026] [security2:error] [pid 738779:tid 738860] [remote 74.7.241.60:45446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/js/article.php"] [unique_id "amuJD_xa4UbeLxj1SWW71QAAmFA"], referer: https://aded-rdc.org/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/js/bootstrap.bundle.min.js
[Thu Jul 30 12:25:35.484079 2026] [security2:error] [pid 738779:tid 739025] [client 142.93.53.183:60780] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/images/alfacgiapi/perl.alfa"] [unique_id "amuJD_xa4UbeLxj1SWW73QAAAPk"]
[Thu Jul 30 12:25:35.540595 2026] [security2:error] [pid 738779:tid 738966] [client 57.141.0.32:46190] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuJD_xa4UbeLxj1SWW72QAAvlI"], referer: https://igetvape-australia.com/product/alibarbar-ingot-mango-magic-9000-puffs/?add-to-cart=934
[Thu Jul 30 12:25:35.873694 2026] [security2:error] [pid 738779:tid 739003] [client 142.93.53.183:60793] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/js/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJD_xa4UbeLxj1SWW75QAAAOM"]
[Thu Jul 30 12:25:35.901857 2026] [security2:error] [pid 738779:tid 739006] [client 20.226.5.174:4315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/.well-known//index.php"] [unique_id "amuJD_xa4UbeLxj1SWW75gAAAOY"]
[Thu Jul 30 12:25:36.204602 2026] [security2:error] [pid 738779:tid 738991] [client 74.7.241.167:43316] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "webdisk.tereasshop.com"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuJEPxa4UbeLxj1SWW77AAAANc"]
[Thu Jul 30 12:25:36.266734 2026] [security2:error] [pid 738779:tid 739018] [client 142.93.53.183:60811] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/js/alfacgiapi/perl.alfa"] [unique_id "amuJEPxa4UbeLxj1SWW77wAAAPI"]
[Thu Jul 30 12:25:36.423937 2026] [security2:error] [pid 738779:tid 738943] [client 20.52.54.143:9363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/shell.php"] [unique_id "amuJEPxa4UbeLxj1SWW78gAAAKc"]
[Thu Jul 30 12:25:36.657382 2026] [security2:error] [pid 738779:tid 738979] [client 142.93.53.183:60827] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/php-compat/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJEPxa4UbeLxj1SWW7-wAAAMs"]
[Thu Jul 30 12:25:37.048535 2026] [security2:error] [pid 738779:tid 738916] [client 142.93.53.183:60845] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/php-compat/alfacgiapi/perl.alfa"] [unique_id "amuJEfxa4UbeLxj1SWW8BQAAAIw"]
[Thu Jul 30 12:25:37.168014 2026] [security2:error] [pid 738779:tid 738972] [client 20.52.54.143:9406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/f35.php"] [unique_id "amuJEfxa4UbeLxj1SWW8EQAAAMQ"]
[Thu Jul 30 12:25:37.420743 2026] [security2:error] [pid 738779:tid 738871] [remote 57.141.0.12:57344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuJEfxa4UbeLxj1SWW8FQAAwls"]
[Thu Jul 30 12:25:37.438758 2026] [security2:error] [pid 738779:tid 739032] [client 142.93.53.183:60864] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/pomo/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJEfxa4UbeLxj1SWW8FgAAAQA"]
[Thu Jul 30 12:25:37.831017 2026] [security2:error] [pid 738779:tid 738921] [client 142.93.53.183:60880] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/pomo/alfacgiapi/perl.alfa"] [unique_id "amuJEfxa4UbeLxj1SWW8GwAAAJE"]
[Thu Jul 30 12:25:37.853401 2026] [security2:error] [pid 738779:tid 738938] [client 20.226.5.174:4335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/blog/wp-content/plugins/ubh/up.php"] [unique_id "amuJEfxa4UbeLxj1SWW8HAAAAKI"]
[Thu Jul 30 12:25:38.051071 2026] [security2:error] [pid 738779:tid 738914] [client 20.52.54.143:10204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/new.php"] [unique_id "amuJEvxa4UbeLxj1SWW8IQAAAIo"]
[Thu Jul 30 12:25:38.221258 2026] [security2:error] [pid 738779:tid 738976] [client 142.93.53.183:60898] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/rest-api/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJEvxa4UbeLxj1SWW8JQAAAMg"]
[Thu Jul 30 12:25:38.414695 2026] [security2:error] [pid 738779:tid 738918] [client 3.212.219.113:23257] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/arquivos/noticias/189/d78ded98b499c41640a963a2c580e3f6.jpg"] [unique_id "amuJEvxa4UbeLxj1SWW8JwAAAI4"]
[Thu Jul 30 12:25:38.600190 2026] [security2:error] [pid 738779:tid 738962] [client 142.93.53.183:60915] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/rest-api/alfacgiapi/perl.alfa"] [unique_id "amuJEvxa4UbeLxj1SWW8MQAAALo"]
[Thu Jul 30 12:25:38.985614 2026] [security2:error] [pid 738779:tid 739015] [client 142.93.53.183:60932] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/sitemaps/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJEvxa4UbeLxj1SWW8QwAAAO8"]
[Thu Jul 30 12:25:38.991605 2026] [security2:error] [pid 738779:tid 738927] [client 172.237.109.114:54763] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/api/.env"] [unique_id "amuJEvxa4UbeLxj1SWW8RAAAAJc"]
[Thu Jul 30 12:25:39.077024 2026] [security2:error] [pid 738779:tid 738925] [client 20.226.5.174:4313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/edit.php"] [unique_id "amuJE_xa4UbeLxj1SWW8RQAAAJU"]
[Thu Jul 30 12:25:39.091951 2026] [security2:error] [pid 738779:tid 738998] [client 20.52.54.143:9349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/adminfuns.php"] [unique_id "amuJE_xa4UbeLxj1SWW8RgAAAN4"]
[Thu Jul 30 12:25:39.347384 2026] [security2:error] [pid 738779:tid 738947] [client 172.237.109.114:51618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJEvxa4UbeLxj1SWW8QgAAAKs"]
[Thu Jul 30 12:25:39.374709 2026] [security2:error] [pid 738779:tid 739009] [client 142.93.53.183:60948] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/sitemaps/alfacgiapi/perl.alfa"] [unique_id "amuJE_xa4UbeLxj1SWW8TgAAAOk"]
[Thu Jul 30 12:25:39.618643 2026] [core:notice] [pid 738779:tid 738873] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:25:39.766613 2026] [security2:error] [pid 738779:tid 738990] [client 142.93.53.183:60964] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/sodium_compat/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJE_xa4UbeLxj1SWW8VwAAANY"]
[Thu Jul 30 12:25:39.836810 2026] [proxy:error] [pid 738779:tid 738910] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:25:39.836890 2026] [proxy_http:error] [pid 738779:tid 738910] [client 20.52.54.143:10203] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:25:39.837489 2026] [proxy:error] [pid 738779:tid 738910] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:25:39.837537 2026] [proxy_http:error] [pid 738779:tid 738910] [client 20.52.54.143:10203] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:25:39.878703 2026] [core:notice] [pid 738779:tid 738891] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:25:40.155939 2026] [security2:error] [pid 738779:tid 739007] [client 142.93.53.183:60984] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/sodium_compat/alfacgiapi/perl.alfa"] [unique_id "amuJFPxa4UbeLxj1SWW8dgAAAOc"]
[Thu Jul 30 12:25:40.530088 2026] [security2:error] [pid 738779:tid 739032] [client 142.93.53.183:60999] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/style-engine/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJFPxa4UbeLxj1SWW8gAAAAQA"]
[Thu Jul 30 12:25:40.545139 2026] [security2:error] [pid 738779:tid 739001] [client 20.226.5.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJFPxa4UbeLxj1SWW8fQAAAOE"]
[Thu Jul 30 12:25:40.586194 2026] [security2:error] [pid 738779:tid 738959] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.dl.truckersofeuropes3mod.com"] [uri "/"] [unique_id "amuJFPxa4UbeLxj1SWW8hAAAALc"]
[Thu Jul 30 12:25:40.923122 2026] [security2:error] [pid 738779:tid 738917] [client 142.93.53.183:61020] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/style-engine/alfacgiapi/perl.alfa"] [unique_id "amuJFPxa4UbeLxj1SWW8oQAAAI0"]
[Thu Jul 30 12:25:41.164326 2026] [security2:error] [pid 738779:tid 738941] [client 20.226.5.174:4162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/locks.php"] [unique_id "amuJFfxa4UbeLxj1SWW8qwAAAKU"]
[Thu Jul 30 12:25:41.313751 2026] [security2:error] [pid 738779:tid 738926] [client 142.93.53.183:61037] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/theme-compat/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJFfxa4UbeLxj1SWW8sAAAAJY"]
[Thu Jul 30 12:25:41.706423 2026] [security2:error] [pid 738779:tid 738951] [client 142.93.53.183:61056] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/theme-compat/alfacgiapi/perl.alfa"] [unique_id "amuJFfxa4UbeLxj1SWW8wQAAAK8"]
[Thu Jul 30 12:25:41.711652 2026] [proxy:error] [pid 738779:tid 739016] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:25:41.711737 2026] [proxy_http:error] [pid 738779:tid 739016] [client 20.52.54.143:10229] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:25:41.712300 2026] [proxy:error] [pid 738779:tid 739016] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:25:41.712351 2026] [proxy_http:error] [pid 738779:tid 739016] [client 20.52.54.143:10229] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:25:41.845063 2026] [security2:error] [pid 738779:tid 738953] [client 17.241.227.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuJFfxa4UbeLxj1SWW8wAAAALE"]
[Thu Jul 30 12:25:41.847654 2026] [security2:error] [pid 738779:tid 738976] [client 68.235.38.2:32976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.38.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuJFfxa4UbeLxj1SWW8xQAAAMg"]
[Thu Jul 30 12:25:41.847753 2026] [security2:error] [pid 738779:tid 738976] [client 68.235.38.2:32976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuJFfxa4UbeLxj1SWW8xQAAAMg"]
[Thu Jul 30 12:25:42.091870 2026] [security2:error] [pid 738779:tid 738965] [client 142.93.53.183:61071] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/widgets/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJFvxa4UbeLxj1SWW81wAAAL0"]
[Thu Jul 30 12:25:42.156404 2026] [core:notice] [pid 738779:tid 738928] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:25:42.396377 2026] [security2:error] [pid 738779:tid 738998] [client 20.52.54.143:10226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/fm.php"] [unique_id "amuJFvxa4UbeLxj1SWW87AAAAN4"]
[Thu Jul 30 12:25:42.485244 2026] [security2:error] [pid 738779:tid 738921] [client 142.93.53.183:61090] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/widgets/alfacgiapi/perl.alfa"] [unique_id "amuJFvxa4UbeLxj1SWW87gAAAJE"]
[Thu Jul 30 12:25:42.508207 2026] [security2:error] [pid 738779:tid 738937] [client 38.190.144.4:64405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJFvxa4UbeLxj1SWW87wAAAKE"]
[Thu Jul 30 12:25:42.508339 2026] [security2:error] [pid 738779:tid 738937] [client 38.190.144.4:64405] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJFvxa4UbeLxj1SWW87wAAAKE"]
[Thu Jul 30 12:25:42.863078 2026] [security2:error] [pid 738779:tid 738910] [client 87.101.92.171:46536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.92.101.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuJFvxa4UbeLxj1SWW89QAAAIY"]
[Thu Jul 30 12:25:42.863185 2026] [security2:error] [pid 738779:tid 738910] [client 87.101.92.171:46536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuJFvxa4UbeLxj1SWW89QAAAIY"]
[Thu Jul 30 12:25:42.876322 2026] [security2:error] [pid 738779:tid 738952] [client 142.93.53.183:61109] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2020/12/alfacgiapi/perl.alfa"] [unique_id "amuJFvxa4UbeLxj1SWW89gAAALA"]
[Thu Jul 30 12:25:43.222918 2026] [security2:error] [pid 738779:tid 738919] [client 20.226.5.174:4165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/alfa-rex1.php"] [unique_id "amuJF_xa4UbeLxj1SWW8_wAAAI8"]
[Thu Jul 30 12:25:43.264226 2026] [security2:error] [pid 738779:tid 738965] [client 142.93.53.183:61121] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/alfacgiapi/perl.alfa"] [unique_id "amuJF_xa4UbeLxj1SWW9AAAAAL0"]
[Thu Jul 30 12:25:43.608050 2026] [security2:error] [pid 738779:tid 739005] [client 111.113.88.206:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJF_xa4UbeLxj1SWW9AQAAAOU"]
[Thu Jul 30 12:25:43.657414 2026] [security2:error] [pid 738779:tid 738993] [client 142.93.53.183:61136] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/updraft/alfacgiapi/perl.alfa"] [unique_id "amuJF_xa4UbeLxj1SWW9BwAAANk"]
[Thu Jul 30 12:25:44.048005 2026] [security2:error] [pid 738779:tid 738971] [client 142.93.53.183:61150] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/library/alfacgiapi/perl.alfa"] [unique_id "amuJGPxa4UbeLxj1SWW9EwAAAMM"]
[Thu Jul 30 12:25:44.435995 2026] [security2:error] [pid 738779:tid 739026] [client 142.93.53.183:61168] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/library/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJGPxa4UbeLxj1SWW9GwAAAPo"]
[Thu Jul 30 12:25:44.829602 2026] [security2:error] [pid 738779:tid 738978] [client 142.93.53.183:61185] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJGPxa4UbeLxj1SWW9JQAAAMo"]
[Thu Jul 30 12:25:45.039911 2026] [core:notice] [pid 738779:tid 738794] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:25:45.065865 2026] [proxy:error] [pid 738779:tid 738933] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:25:45.065936 2026] [proxy_http:error] [pid 738779:tid 738933] [client 20.52.54.143:10219] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:25:45.066508 2026] [proxy:error] [pid 738779:tid 738933] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:25:45.066554 2026] [proxy_http:error] [pid 738779:tid 738933] [client 20.52.54.143:10219] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:25:45.134828 2026] [security2:error] [pid 738779:tid 738941] [client 20.226.5.174:4178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-content/uploads/gfwisone.php"] [unique_id "amuJGfxa4UbeLxj1SWW9LwAAAKU"]
[Thu Jul 30 12:25:45.218650 2026] [security2:error] [pid 738779:tid 739029] [client 142.93.53.183:61197] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/vendor/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJGfxa4UbeLxj1SWW9MgAAAP0"]
[Thu Jul 30 12:25:45.324388 2026] [core:notice] [pid 738779:tid 738805] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:25:45.610489 2026] [security2:error] [pid 738779:tid 739013] [client 142.93.53.183:61211] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/cache/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJGfxa4UbeLxj1SWW9PAAAAO0"]
[Thu Jul 30 12:25:45.908267 2026] [security2:error] [pid 738779:tid 738980] [client 20.52.54.143:9366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/file.php"] [unique_id "amuJGfxa4UbeLxj1SWW9QwAAAMw"]
[Thu Jul 30 12:25:45.999468 2026] [security2:error] [pid 738779:tid 738925] [client 142.93.53.183:61237] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/cache/alfacgiapi/perl.alfa"] [unique_id "amuJGfxa4UbeLxj1SWW9RQAAAJU"]
[Thu Jul 30 12:25:46.389412 2026] [security2:error] [pid 738779:tid 738931] [client 142.93.53.183:61249] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/-/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJGvxa4UbeLxj1SWW9UQAAAJs"]
[Thu Jul 30 12:25:46.511851 2026] [security2:error] [pid 738779:tid 738987] [client 20.226.5.174:4204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/rex/l/flower.php"] [unique_id "amuJGvxa4UbeLxj1SWW9WQAAANM"]
[Thu Jul 30 12:25:46.783050 2026] [security2:error] [pid 738779:tid 738933] [client 142.93.53.183:61261] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/-/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJGvxa4UbeLxj1SWW9XwAAAJ0"]
[Thu Jul 30 12:25:46.962283 2026] [proxy:error] [pid 738779:tid 739002] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:25:46.962370 2026] [proxy_http:error] [pid 738779:tid 739002] [client 20.52.54.143:9350] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:25:46.963071 2026] [proxy:error] [pid 738779:tid 739002] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:25:46.963121 2026] [proxy_http:error] [pid 738779:tid 739002] [client 20.52.54.143:9350] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:25:47.172795 2026] [security2:error] [pid 738779:tid 738994] [client 142.93.53.183:61273] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/alfacgiapi/perl.alfa"] [unique_id "amuJG_xa4UbeLxj1SWW9ZwAAANo"]
[Thu Jul 30 12:25:47.563713 2026] [security2:error] [pid 738779:tid 739005] [client 142.93.53.183:61288] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/upload/alfacgiapi/perl.alfa"] [unique_id "amuJG_xa4UbeLxj1SWW9cQAAAOU"]
[Thu Jul 30 12:25:47.633789 2026] [security2:error] [pid 738779:tid 738969] [client 20.52.54.143:9354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/bolt.php"] [unique_id "amuJG_xa4UbeLxj1SWW9cgAAAME"]
[Thu Jul 30 12:25:47.926138 2026] [security2:error] [pid 738779:tid 738966] [client 20.226.5.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJG_xa4UbeLxj1SWW9eQAAAL4"]
[Thu Jul 30 12:25:47.951884 2026] [security2:error] [pid 738779:tid 739021] [client 142.93.53.183:61304] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/upload/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJG_xa4UbeLxj1SWW9egAAAPU"]
[Thu Jul 30 12:25:48.001216 2026] [security2:error] [pid 738779:tid 738928] [client 57.141.0.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJG_xa4UbeLxj1SWW9awAAAJg"]
[Thu Jul 30 12:25:48.345601 2026] [security2:error] [pid 738779:tid 739001] [client 142.93.53.183:61316] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/alfacgiapi/perl.alfa"] [unique_id "amuJHPxa4UbeLxj1SWW9gQAAAOE"]
[Thu Jul 30 12:25:48.546285 2026] [security2:error] [pid 738779:tid 738954] [client 20.52.54.143:10237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/3.php"] [unique_id "amuJHPxa4UbeLxj1SWW9hgAAALI"]
[Thu Jul 30 12:25:48.735883 2026] [security2:error] [pid 738779:tid 738983] [client 142.93.53.183:61329] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJHPxa4UbeLxj1SWW9jQAAAM8"]
[Thu Jul 30 12:25:48.819862 2026] [security2:error] [pid 738779:tid 738948] [client 213.152.161.118:51756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuJHPxa4UbeLxj1SWW9jgAAAKw"]
[Thu Jul 30 12:25:48.819970 2026] [security2:error] [pid 738779:tid 738948] [client 213.152.161.118:51756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuJHPxa4UbeLxj1SWW9jgAAAKw"]
[Thu Jul 30 12:25:49.116399 2026] [security2:error] [pid 738779:tid 738915] [client 142.93.53.183:61336] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/upload/alfacgiapi/perl.alfa"] [unique_id "amuJHfxa4UbeLxj1SWW9kgAAAIs"]
[Thu Jul 30 12:25:49.123733 2026] [security2:error] [pid 738779:tid 739008] [client 20.226.5.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJHPxa4UbeLxj1SWW9hQAAAOg"]
[Thu Jul 30 12:25:49.471391 2026] [security2:error] [pid 738779:tid 738995] [client 20.226.5.174:4189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-admin/user/post.php"] [unique_id "amuJHfxa4UbeLxj1SWW9lgAAANs"]
[Thu Jul 30 12:25:49.516740 2026] [security2:error] [pid 738779:tid 738922] [client 142.93.53.183:61353] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/upload/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJHfxa4UbeLxj1SWW9lwAAAJI"]
[Thu Jul 30 12:25:49.670462 2026] [security2:error] [pid 738779:tid 738982] [client 20.52.54.143:9390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/222.php"] [unique_id "amuJHfxa4UbeLxj1SWW9nAAAAM4"]
[Thu Jul 30 12:25:49.907505 2026] [security2:error] [pid 738779:tid 738920] [client 142.93.53.183:61362] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/uploads/alfacgiapi/perl.alfa"] [unique_id "amuJHfxa4UbeLxj1SWW9oQAAAJA"]
[Thu Jul 30 12:25:50.298145 2026] [security2:error] [pid 738779:tid 739024] [client 142.93.53.183:61373] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/uploads/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJHvxa4UbeLxj1SWW9qwAAAPg"]
[Thu Jul 30 12:25:50.303254 2026] [security2:error] [pid 738779:tid 739007] [client 20.52.54.143:9388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amuJHvxa4UbeLxj1SWW9rAAAAOc"]
[Thu Jul 30 12:25:50.689048 2026] [security2:error] [pid 738779:tid 738963] [client 142.93.53.183:61380] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/js/alfacgiapi/perl.alfa"] [unique_id "amuJHvxa4UbeLxj1SWW9sQAAALs"]
[Thu Jul 30 12:25:50.737049 2026] [security2:error] [pid 738779:tid 738964] [client 2a03:2880:f800:13:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJHvxa4UbeLxj1SWW9owAAvDE"]
[Thu Jul 30 12:25:50.869951 2026] [security2:error] [pid 738779:tid 738980] [client 114.119.149.92:28495] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jesus.claims"] [uri "/bg_home"] [unique_id "amuJHvxa4UbeLxj1SWW9tgAAAMw"], referer: https://www.jesus.claims/bg_home
[Thu Jul 30 12:25:51.079359 2026] [security2:error] [pid 738779:tid 738959] [client 142.93.53.183:61388] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/js/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJH_xa4UbeLxj1SWW9twAAALc"]
[Thu Jul 30 12:25:51.256848 2026] [security2:error] [pid 738779:tid 738942] [client 20.52.54.143:9954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amuJH_xa4UbeLxj1SWW9vwAAAKY"]
[Thu Jul 30 12:25:51.470363 2026] [security2:error] [pid 738779:tid 738923] [client 142.93.53.183:61400] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/js/uploads/alfacgiapi/perl.alfa"] [unique_id "amuJH_xa4UbeLxj1SWW9wwAAAJM"]
[Thu Jul 30 12:25:51.699549 2026] [security2:error] [pid 738779:tid 738839] [remote 57.141.0.25:59836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amuJH_xa4UbeLxj1SWW9ygAA4Ds"]
[Thu Jul 30 12:25:51.737464 2026] [security2:error] [pid 738779:tid 738930] [client 20.226.5.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJH_xa4UbeLxj1SWW9vQAAAJo"]
[Thu Jul 30 12:25:51.859359 2026] [security2:error] [pid 738779:tid 738914] [client 142.93.53.183:61407] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/js/uploads/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJH_xa4UbeLxj1SWW90AAAAIo"]
[Thu Jul 30 12:25:52.248674 2026] [security2:error] [pid 738779:tid 738913] [client 142.93.53.183:61418] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/js/plugins/alfacgiapi/perl.alfa"] [unique_id "amuJIPxa4UbeLxj1SWW93AAAAIk"]
[Thu Jul 30 12:25:52.357224 2026] [proxy:error] [pid 738779:tid 738949] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:25:52.357304 2026] [proxy_http:error] [pid 738779:tid 738949] [client 20.52.54.143:9943] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:25:52.357863 2026] [proxy:error] [pid 738779:tid 738949] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:25:52.357907 2026] [proxy_http:error] [pid 738779:tid 738949] [client 20.52.54.143:9943] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:25:52.428625 2026] [security2:error] [pid 738779:tid 738994] [client 20.226.5.174:4118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/file5.php"] [unique_id "amuJIPxa4UbeLxj1SWW94gAAANo"]
[Thu Jul 30 12:25:52.641772 2026] [security2:error] [pid 738779:tid 738920] [client 142.93.53.183:61425] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/js/plugins/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJIPxa4UbeLxj1SWW95QAAAJA"]
[Thu Jul 30 12:25:53.022843 2026] [security2:error] [pid 738779:tid 739031] [client 142.93.53.183:61436] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/js/themes/alfacgiapi/perl.alfa"] [unique_id "amuJIfxa4UbeLxj1SWW97AAAAP8"]
[Thu Jul 30 12:25:53.407259 2026] [security2:error] [pid 738779:tid 739016] [client 142.93.53.183:61444] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/js/themes/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJIfxa4UbeLxj1SWW-BQAAAPA"]
[Thu Jul 30 12:25:53.798162 2026] [security2:error] [pid 738779:tid 738936] [client 142.93.53.183:61457] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/js/upgrade/alfacgiapi/perl.alfa"] [unique_id "amuJIfxa4UbeLxj1SWW-DQAAAKA"]
[Thu Jul 30 12:25:53.862001 2026] [autoindex:error] [pid 738779:tid 738933] [client 20.226.5.174:0] AH01276: Cannot serve directory /home1/ncozztte/public_html/wp-includes/Text/Diff/Engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:25:54.186437 2026] [security2:error] [pid 738779:tid 739004] [client 142.93.53.183:61471] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/js/upgrade/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJIvxa4UbeLxj1SWW-FAAAAOQ"]
[Thu Jul 30 12:25:54.281937 2026] [autoindex:error] [pid 738779:tid 738965] [client 20.226.5.174:0] AH01276: Cannot serve directory /home1/ncozztte/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:25:54.331855 2026] [security2:error] [pid 738779:tid 738967] [client 38.190.144.4:64897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJIvxa4UbeLxj1SWW-GwAAAL8"]
[Thu Jul 30 12:25:54.333270 2026] [security2:error] [pid 738779:tid 738967] [client 38.190.144.4:64897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJIvxa4UbeLxj1SWW-GwAAAL8"]
[Thu Jul 30 12:25:54.579429 2026] [security2:error] [pid 738779:tid 738957] [client 142.93.53.183:61482] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/js/updraft/alfacgiapi/perl.alfa"] [unique_id "amuJIvxa4UbeLxj1SWW-HwAAALU"]
[Thu Jul 30 12:25:54.957431 2026] [security2:error] [pid 738779:tid 738950] [client 142.93.53.183:61495] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/js/updraft/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJIvxa4UbeLxj1SWW-JwAAAK4"]
[Thu Jul 30 12:25:55.239948 2026] [security2:error] [pid 738779:tid 738920] [client 20.226.5.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJIvxa4UbeLxj1SWW-IgAAAJA"]
[Thu Jul 30 12:25:55.344778 2026] [security2:error] [pid 738779:tid 738980] [client 142.93.53.183:61503] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/js/plugins/library/alfacgiapi/perl.alfa"] [unique_id "amuJI_xa4UbeLxj1SWW-LgAAAMw"]
[Thu Jul 30 12:25:55.735593 2026] [security2:error] [pid 738779:tid 738971] [client 142.93.53.183:61512] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/js/plugins/library/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJI_xa4UbeLxj1SWW-NwAAAMM"]
[Thu Jul 30 12:25:55.854929 2026] [security2:error] [pid 738779:tid 739020] [client 20.226.5.174:4120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/query-standard-post.php"] [unique_id "amuJI_xa4UbeLxj1SWW-OwAAAPQ"]
[Thu Jul 30 12:25:56.003012 2026] [security2:error] [pid 738779:tid 739025] [client 57.141.0.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJI_xa4UbeLxj1SWW-MQAAAPk"]
[Thu Jul 30 12:25:56.111259 2026] [security2:error] [pid 738779:tid 738983] [client 142.93.53.183:61523] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/css/alfacgiapi/perl.alfa"] [unique_id "amuJJPxa4UbeLxj1SWW-PwAAAM8"]
[Thu Jul 30 12:25:56.501126 2026] [security2:error] [pid 738779:tid 739014] [client 142.93.53.183:61530] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/css/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJJPxa4UbeLxj1SWW-SAAAAO4"]
[Thu Jul 30 12:25:56.891359 2026] [security2:error] [pid 738779:tid 738979] [client 142.93.53.183:61537] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/css/uploads/alfacgiapi/perl.alfa"] [unique_id "amuJJPxa4UbeLxj1SWW-VAAAAMs"]
[Thu Jul 30 12:25:57.111078 2026] [security2:error] [pid 738779:tid 738913] [client 50.6.43.217:57590] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/1.jpg"] [unique_id "amuJJfxa4UbeLxj1SWW-VgAAAIk"]
[Thu Jul 30 12:25:57.121661 2026] [security2:error] [pid 738779:tid 739028] [client 50.6.43.217:57596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/2.jpg"] [unique_id "amuJJfxa4UbeLxj1SWW-VwAAAPw"]
[Thu Jul 30 12:25:57.131698 2026] [security2:error] [pid 738779:tid 738967] [client 50.6.43.217:57606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/3.jpg"] [unique_id "amuJJfxa4UbeLxj1SWW-WAAAAL8"]
[Thu Jul 30 12:25:57.268664 2026] [security2:error] [pid 738779:tid 738991] [client 52.238.199.152:51376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/gmo.php"] [unique_id "amuJJfxa4UbeLxj1SWW-XAAAANc"]
[Thu Jul 30 12:25:57.279949 2026] [security2:error] [pid 738779:tid 738972] [client 142.93.53.183:61548] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/css/uploads/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJJfxa4UbeLxj1SWW-XQAAAMQ"]
[Thu Jul 30 12:25:57.673068 2026] [security2:error] [pid 738779:tid 738989] [client 142.93.53.183:61553] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/css/plugins/alfacgiapi/perl.alfa"] [unique_id "amuJJfxa4UbeLxj1SWW-YwAAANU"]
[Thu Jul 30 12:25:58.065103 2026] [security2:error] [pid 738779:tid 738963] [client 142.93.53.183:61560] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/css/plugins/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJJvxa4UbeLxj1SWW-agAAALs"]
[Thu Jul 30 12:25:58.427589 2026] [security2:error] [pid 738779:tid 738921] [client 20.226.5.174:4116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-includes/images/include.php"] [unique_id "amuJJvxa4UbeLxj1SWW-cAAAAJE"]
[Thu Jul 30 12:25:58.454646 2026] [security2:error] [pid 738779:tid 738929] [client 142.93.53.183:61567] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/css/themes/alfacgiapi/perl.alfa"] [unique_id "amuJJvxa4UbeLxj1SWW-cQAAAJk"]
[Thu Jul 30 12:25:58.511930 2026] [security2:error] [pid 738779:tid 738927] [client 111.113.88.206:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJJvxa4UbeLxj1SWW-awAAAJc"]
[Thu Jul 30 12:25:58.670860 2026] [security2:error] [pid 738779:tid 738946] [client 52.238.199.152:51359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/nakrip.php"] [unique_id "amuJJvxa4UbeLxj1SWW-dgAAAKo"]
[Thu Jul 30 12:25:58.769714 2026] [core:notice] [pid 738779:tid 738925] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:25:58.846491 2026] [security2:error] [pid 738779:tid 738973] [client 142.93.53.183:61570] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/css/themes/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJJvxa4UbeLxj1SWW-ewAAAMU"]
[Thu Jul 30 12:25:59.232899 2026] [security2:error] [pid 738779:tid 738948] [client 142.93.53.183:61579] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/css/upgrade/alfacgiapi/perl.alfa"] [unique_id "amuJJ_xa4UbeLxj1SWW-gAAAAKw"]
[Thu Jul 30 12:25:59.240115 2026] [proxy:error] [pid 738779:tid 738976] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:25:59.240167 2026] [proxy_http:error] [pid 738779:tid 738976] [client 185.247.137.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.koinjp189.com:2052
[Thu Jul 30 12:25:59.240733 2026] [proxy:error] [pid 738779:tid 738976] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:25:59.240775 2026] [proxy_http:error] [pid 738779:tid 738976] [client 185.247.137.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.koinjp189.com:2052
[Thu Jul 30 12:25:59.265535 2026] [security2:error] [pid 738779:tid 738958] [client 20.52.54.143:10191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/admin.php"] [unique_id "amuJJ_xa4UbeLxj1SWW-ggAAALY"]
[Thu Jul 30 12:25:59.366761 2026] [security2:error] [pid 738779:tid 738953] [client 20.226.5.174:4124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/--wp-lgj.php"] [unique_id "amuJJ_xa4UbeLxj1SWW-hgAAALE"]
[Thu Jul 30 12:25:59.626095 2026] [security2:error] [pid 738779:tid 738941] [client 142.93.53.183:61582] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/css/upgrade/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJJ_xa4UbeLxj1SWW-iwAAAKU"]
[Thu Jul 30 12:25:59.802069 2026] [security2:error] [pid 738779:tid 738933] [client 52.238.199.152:18238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/radio.php"] [unique_id "amuJJ_xa4UbeLxj1SWW-jwAAAJ0"]
[Thu Jul 30 12:26:00.016808 2026] [security2:error] [pid 738779:tid 738918] [client 142.93.53.183:61587] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/css/updraft/alfacgiapi/perl.alfa"] [unique_id "amuJKPxa4UbeLxj1SWW-kAAAAI4"]
[Thu Jul 30 12:26:00.089890 2026] [security2:error] [pid 738779:tid 739028] [client 20.52.54.143:9965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-configs.php"] [unique_id "amuJKPxa4UbeLxj1SWW-lQAAAPw"]
[Thu Jul 30 12:26:00.149685 2026] [security2:error] [pid 738779:tid 738894] [remote 198.38.94.67:52924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.94.38.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/wp-login.php"] [unique_id "amuJKPxa4UbeLxj1SWW-lgAA_nI"]
[Thu Jul 30 12:26:00.407546 2026] [security2:error] [pid 738779:tid 738964] [client 142.93.53.183:61593] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/css/updraft/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJKPxa4UbeLxj1SWW-mgAAALw"]
[Thu Jul 30 12:26:00.779721 2026] [security2:error] [pid 738779:tid 738924] [client 142.93.53.183:61598] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/css/plugins/library/alfacgiapi/perl.alfa"] [unique_id "amuJKPxa4UbeLxj1SWW-oAAAAJQ"]
[Thu Jul 30 12:26:01.173058 2026] [security2:error] [pid 738779:tid 738923] [client 142.93.53.183:61605] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/css/plugins/library/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJKfxa4UbeLxj1SWW-qAAAAJM"]
[Thu Jul 30 12:26:01.446829 2026] [security2:error] [pid 738779:tid 739005] [client 20.52.54.143:9936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/php.php"] [unique_id "amuJKfxa4UbeLxj1SWW-sgAAAOU"]
[Thu Jul 30 12:26:01.564074 2026] [security2:error] [pid 738779:tid 739000] [client 142.93.53.183:61610] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/.well-known/alfacgiapi/perl.alfa"] [unique_id "amuJKfxa4UbeLxj1SWW-tgAAAOA"]
[Thu Jul 30 12:26:01.916776 2026] [security2:error] [pid 738779:tid 739020] [client 20.226.5.174:4125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-p.php"] [unique_id "amuJKfxa4UbeLxj1SWW-vgAAAPQ"]
[Thu Jul 30 12:26:01.954535 2026] [security2:error] [pid 738779:tid 738936] [client 142.93.53.183:61614] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/.well-known/acme-challenge/alfacgiapi/perl.alfa"] [unique_id "amuJKfxa4UbeLxj1SWW-vwAAAKA"]
[Thu Jul 30 12:26:02.172615 2026] [security2:error] [pid 738779:tid 738987] [client 52.238.199.152:51339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-singin.php"] [unique_id "amuJKvxa4UbeLxj1SWW-xAAAANM"]
[Thu Jul 30 12:26:02.344995 2026] [security2:error] [pid 738779:tid 738974] [client 142.93.53.183:61616] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/.well-known/pki-validation/alfacgiapi/perl.alfa"] [unique_id "amuJKvxa4UbeLxj1SWW-xQAAAMY"]
[Thu Jul 30 12:26:02.735644 2026] [security2:error] [pid 738779:tid 739002] [client 142.93.53.183:61620] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/.tmb/alfacgiapi/perl.alfa"] [unique_id "amuJKvxa4UbeLxj1SWW-zAAAAOI"]
[Thu Jul 30 12:26:02.946154 2026] [security2:error] [pid 738779:tid 739028] [client 74.7.244.42:33686] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.bitcoinfungibletoken.com"] [uri "/robots.txt"] [unique_id "amuJKvxa4UbeLxj1SWW-0gAA_H8"]
[Thu Jul 30 12:26:03.116463 2026] [security2:error] [pid 738779:tid 738980] [client 142.93.53.183:61623] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/.quarantine/alfacgiapi/perl.alfa"] [unique_id "amuJK_xa4UbeLxj1SWW-2gAAAMw"]
[Thu Jul 30 12:26:03.497494 2026] [security2:error] [pid 738779:tid 739001] [client 142.93.53.183:61625] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/.quarantine/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJK_xa4UbeLxj1SWW-6AAAAOE"]
[Thu Jul 30 12:26:03.722897 2026] [security2:error] [pid 738779:tid 738917] [client 20.226.5.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJK_xa4UbeLxj1SWW-3QAAAI0"]
[Thu Jul 30 12:26:03.819517 2026] [core:notice] [pid 738779:tid 738796] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:03.876039 2026] [security2:error] [pid 738779:tid 739016] [client 142.93.53.183:61630] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/cgi-bin/alfacgiapi/perl.alfa"] [unique_id "amuJK_xa4UbeLxj1SWW-8AAAAPA"]
[Thu Jul 30 12:26:04.107910 2026] [security2:error] [pid 738779:tid 738952] [client 20.52.54.143:9945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/index.php"] [unique_id "amuJLPxa4UbeLxj1SWW--AAAALA"]
[Thu Jul 30 12:26:04.266941 2026] [security2:error] [pid 738779:tid 738910] [client 142.93.53.183:61636] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/images/alfacgiapi/perl.alfa"] [unique_id "amuJLPxa4UbeLxj1SWW--gAAAIY"]
[Thu Jul 30 12:26:04.276828 2026] [security2:error] [pid 738779:tid 739000] [client 43.172.197.47:40546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.197.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/10/19/bon-plan-shopping-braderie-kookai-automne-2013-23-au-26-oct/"] [unique_id "amuJLPxa4UbeLxj1SWW-9QAAAOA"]
[Thu Jul 30 12:26:04.326014 2026] [security2:error] [pid 738779:tid 738976] [client 20.226.5.174:4110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-admin/css/colors/ectoplasm/flower.php"] [unique_id "amuJLPxa4UbeLxj1SWW--wAAAMg"]
[Thu Jul 30 12:26:04.658841 2026] [security2:error] [pid 738779:tid 738982] [client 142.93.53.183:61639] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/components/alfacgiapi/perl.alfa"] [unique_id "amuJLPxa4UbeLxj1SWW_AgAAAM4"]
[Thu Jul 30 12:26:04.837205 2026] [security2:error] [pid 738779:tid 739008] [client 52.238.199.152:51330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/as.php"] [unique_id "amuJLPxa4UbeLxj1SWW_BQAAAOg"]
[Thu Jul 30 12:26:04.934040 2026] [security2:error] [pid 738779:tid 738913] [client 20.52.54.143:9950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/a.php"] [unique_id "amuJLPxa4UbeLxj1SWW_CQAAAIk"]
[Thu Jul 30 12:26:05.048351 2026] [security2:error] [pid 738779:tid 738956] [client 142.93.53.183:61643] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/components/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJLfxa4UbeLxj1SWW_DwAAALQ"]
[Thu Jul 30 12:26:05.063996 2026] [core:notice] [pid 738779:tid 738949] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:05.073207 2026] [security2:error] [pid 738779:tid 738949] [client 43.173.174.21:43830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/10/19/bon-plan-shopping-braderie-kookai-automne-2013-23-au-26-oct/"] [unique_id "amuJLfxa4UbeLxj1SWW_EAAAAK0"], referer: https://carnetdeshopping.com/index.php/2013/10/19/bon-plan-shopping-braderie-kookai-automne-2013-23-au-26-oct/
[Thu Jul 30 12:26:05.198230 2026] [security2:error] [pid 738779:tid 738933] [client 38.190.144.4:65387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJLfxa4UbeLxj1SWW_EQAAAJ0"]
[Thu Jul 30 12:26:05.198435 2026] [security2:error] [pid 738779:tid 738933] [client 38.190.144.4:65387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJLfxa4UbeLxj1SWW_EQAAAJ0"]
[Thu Jul 30 12:26:05.273858 2026] [core:notice] [pid 738779:tid 738981] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:05.436443 2026] [security2:error] [pid 738779:tid 738963] [client 142.93.53.183:61648] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wordpress/alfacgiapi/perl.alfa"] [unique_id "amuJLfxa4UbeLxj1SWW_FwAAALs"]
[Thu Jul 30 12:26:05.644357 2026] [security2:error] [pid 738779:tid 739013] [client 20.226.5.174:4123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amuJLfxa4UbeLxj1SWW_HAAAAO0"]
[Thu Jul 30 12:26:05.827735 2026] [security2:error] [pid 738779:tid 738954] [client 142.93.53.183:61651] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp/alfacgiapi/perl.alfa"] [unique_id "amuJLfxa4UbeLxj1SWW_HgAAALI"]
[Thu Jul 30 12:26:06.203909 2026] [security2:error] [pid 738779:tid 739005] [client 50.6.43.217:34162] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/1.jpg"] [unique_id "amuJLvxa4UbeLxj1SWW_LQAAAOU"]
[Thu Jul 30 12:26:06.207567 2026] [security2:error] [pid 738779:tid 739003] [client 142.93.53.183:61659] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/blog/alfacgiapi/perl.alfa"] [unique_id "amuJLvxa4UbeLxj1SWW_LwAAAOM"]
[Thu Jul 30 12:26:06.213139 2026] [security2:error] [pid 738779:tid 739016] [client 50.6.43.217:34168] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/2.jpg"] [unique_id "amuJLvxa4UbeLxj1SWW_MAAAAPA"]
[Thu Jul 30 12:26:06.222621 2026] [security2:error] [pid 738779:tid 738973] [client 50.6.43.217:34172] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/3.jpg"] [unique_id "amuJLvxa4UbeLxj1SWW_MQAAAMU"]
[Thu Jul 30 12:26:06.477136 2026] [security2:error] [pid 738779:tid 738929] [client 52.238.199.152:18218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/x.php"] [unique_id "amuJLvxa4UbeLxj1SWW_OAAAAJk"]
[Thu Jul 30 12:26:06.594684 2026] [security2:error] [pid 738779:tid 739004] [client 142.93.53.183:61663] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/new/alfacgiapi/perl.alfa"] [unique_id "amuJLvxa4UbeLxj1SWW_QgAAAOQ"]
[Thu Jul 30 12:26:06.743183 2026] [proxy:error] [pid 738779:tid 738988] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:06.743257 2026] [proxy_http:error] [pid 738779:tid 738988] [client 20.52.54.143:10177] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:06.743885 2026] [proxy:error] [pid 738779:tid 738988] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:06.743929 2026] [proxy_http:error] [pid 738779:tid 738988] [client 20.52.54.143:10177] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:06.943217 2026] [security2:error] [pid 738779:tid 738925] [client 20.226.5.174:4112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/autoload_classmap.php"] [unique_id "amuJLvxa4UbeLxj1SWW_SAAAAJU"]
[Thu Jul 30 12:26:06.983847 2026] [security2:error] [pid 738779:tid 738998] [client 142.93.53.183:61669] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/new/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJLvxa4UbeLxj1SWW_SgAAAN4"]
[Thu Jul 30 12:26:07.376223 2026] [security2:error] [pid 738779:tid 739007] [client 142.93.53.183:61676] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/old/alfacgiapi/perl.alfa"] [unique_id "amuJL_xa4UbeLxj1SWW_TwAAAOc"]
[Thu Jul 30 12:26:07.766967 2026] [security2:error] [pid 738779:tid 738971] [client 142.93.53.183:61685] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/old/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJL_xa4UbeLxj1SWW_VwAAAMM"]
[Thu Jul 30 12:26:08.157686 2026] [security2:error] [pid 738779:tid 738917] [client 142.93.53.183:61691] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/backup/alfacgiapi/perl.alfa"] [unique_id "amuJMPxa4UbeLxj1SWW_XgAAAI0"]
[Thu Jul 30 12:26:08.233563 2026] [autoindex:error] [pid 738779:tid 739035] [client 20.226.5.174:4100] AH01276: Cannot serve directory /home1/ncozztte/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:26:08.531155 2026] [security2:error] [pid 738779:tid 738930] [client 20.226.5.174:4100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-content/plugins/rxxdfx/xleet.php"] [unique_id "amuJMPxa4UbeLxj1SWW_aAAAAJo"]
[Thu Jul 30 12:26:08.540462 2026] [security2:error] [pid 738779:tid 739010] [client 142.93.53.183:61705] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/backup/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJMPxa4UbeLxj1SWW_aQAAAOo"]
[Thu Jul 30 12:26:08.677053 2026] [security2:error] [pid 738779:tid 738997] [client 74.7.175.130:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-26e591d8.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuJMPxa4UbeLxj1SWW_YwAAAN0"]
[Thu Jul 30 12:26:08.677820 2026] [security2:error] [pid 738779:tid 738926] [client 74.7.175.130:52994] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-26e591d8.glb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuJMPxa4UbeLxj1SWW_YQAAlio"]
[Thu Jul 30 12:26:08.916568 2026] [security2:error] [pid 738779:tid 739020] [client 142.93.53.183:61712] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/ojs/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJMPxa4UbeLxj1SWW_cwAAAPQ"]
[Thu Jul 30 12:26:09.297376 2026] [security2:error] [pid 738779:tid 738925] [client 142.93.53.183:61722] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/ojs/alfacgiapi/perl.alfa"] [unique_id "amuJMfxa4UbeLxj1SWW_fwAAAJU"]
[Thu Jul 30 12:26:09.627483 2026] [security2:error] [pid 738779:tid 739019] [client 20.226.5.174:4126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/module.tag.idv1.php"] [unique_id "amuJMfxa4UbeLxj1SWW_iQAAAPM"]
[Thu Jul 30 12:26:09.672343 2026] [security2:error] [pid 738779:tid 738981] [client 142.93.53.183:61730] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/laravel/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJMfxa4UbeLxj1SWW_iwAAAM0"]
[Thu Jul 30 12:26:10.062966 2026] [security2:error] [pid 738779:tid 739001] [client 142.93.53.183:61739] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/laravel/alfacgiapi/perl.alfa"] [unique_id "amuJMvxa4UbeLxj1SWW_kwAAAOE"]
[Thu Jul 30 12:26:10.451462 2026] [security2:error] [pid 738779:tid 738923] [client 142.93.53.183:61744] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/-/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJMvxa4UbeLxj1SWW_mAAAAJM"]
[Thu Jul 30 12:26:10.465494 2026] [proxy:error] [pid 738779:tid 738927] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:10.465579 2026] [proxy_http:error] [pid 738779:tid 738927] [client 20.52.54.143:9928] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:10.466503 2026] [proxy:error] [pid 738779:tid 738927] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:10.466573 2026] [proxy_http:error] [pid 738779:tid 738927] [client 20.52.54.143:9928] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:10.728375 2026] [core:notice] [pid 738779:tid 738844] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:10.844376 2026] [security2:error] [pid 738779:tid 738930] [client 142.93.53.183:61754] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/includes/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJMvxa4UbeLxj1SWW_oQAAAJo"]
[Thu Jul 30 12:26:11.196137 2026] [security2:error] [pid 738779:tid 739021] [client 20.240.254.167:11824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.254.240.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/71.php"] [unique_id "amuJM_xa4UbeLxj1SWW_qgAAAPU"]
[Thu Jul 30 12:26:11.196276 2026] [security2:error] [pid 738779:tid 739021] [client 20.240.254.167:11824] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/71.php"] [unique_id "amuJM_xa4UbeLxj1SWW_qgAAAPU"]
[Thu Jul 30 12:26:11.235335 2026] [security2:error] [pid 738779:tid 738926] [client 142.93.53.183:61758] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/alfacgiapi/perl.alfa"] [unique_id "amuJM_xa4UbeLxj1SWW_qwAAAJY"]
[Thu Jul 30 12:26:11.292763 2026] [security2:error] [pid 738779:tid 738924] [client 50.6.43.217:55350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuJMvxa4UbeLxj1SWW_lwAAAJQ"]
[Thu Jul 30 12:26:11.510396 2026] [security2:error] [pid 738779:tid 738961] [client 20.240.254.167:11528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.254.240.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/72.php"] [unique_id "amuJM_xa4UbeLxj1SWW_sgAAALk"]
[Thu Jul 30 12:26:11.510494 2026] [security2:error] [pid 738779:tid 738961] [client 20.240.254.167:11528] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/72.php"] [unique_id "amuJM_xa4UbeLxj1SWW_sgAAALk"]
[Thu Jul 30 12:26:11.611785 2026] [security2:error] [pid 738779:tid 739030] [client 20.226.5.174:4121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/packed.php"] [unique_id "amuJM_xa4UbeLxj1SWW_tAAAAP4"]
[Thu Jul 30 12:26:11.626300 2026] [security2:error] [pid 738779:tid 738929] [client 142.93.53.183:61768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/app/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJM_xa4UbeLxj1SWW_tQAAAJk"]
[Thu Jul 30 12:26:11.735890 2026] [security2:error] [pid 738779:tid 738948] [client 20.52.54.143:9947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuJM_xa4UbeLxj1SWW_uQAAAKw"]
[Thu Jul 30 12:26:11.820613 2026] [security2:error] [pid 738779:tid 739008] [client 20.240.254.167:11835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.254.240.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/70.php"] [unique_id "amuJM_xa4UbeLxj1SWW_vgAAAOg"]
[Thu Jul 30 12:26:11.820703 2026] [security2:error] [pid 738779:tid 739008] [client 20.240.254.167:11835] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/70.php"] [unique_id "amuJM_xa4UbeLxj1SWW_vgAAAOg"]
[Thu Jul 30 12:26:12.013582 2026] [security2:error] [pid 738779:tid 738918] [client 142.93.53.183:61774] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/app/alfacgiapi/perl.alfa"] [unique_id "amuJNPxa4UbeLxj1SWW_vwAAAI4"]
[Thu Jul 30 12:26:12.036110 2026] [security2:error] [pid 738779:tid 738952] [client 50.6.43.217:58904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuJM_xa4UbeLxj1SWW_rwAAALA"]
[Thu Jul 30 12:26:12.149924 2026] [security2:error] [pid 738779:tid 738909] [client 20.240.254.167:11834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.254.240.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/69.php"] [unique_id "amuJNPxa4UbeLxj1SWW_wwAAAIU"]
[Thu Jul 30 12:26:12.150038 2026] [security2:error] [pid 738779:tid 738909] [client 20.240.254.167:11834] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/69.php"] [unique_id "amuJNPxa4UbeLxj1SWW_wwAAAIU"]
[Thu Jul 30 12:26:12.348163 2026] [security2:error] [pid 738779:tid 738933] [client 52.238.199.152:51353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/item.php"] [unique_id "amuJNPxa4UbeLxj1SWW_ygAAAJ0"]
[Thu Jul 30 12:26:12.388544 2026] [security2:error] [pid 738779:tid 738989] [client 142.93.53.183:61783] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/image/alfacgiapi/perl.alfa"] [unique_id "amuJNPxa4UbeLxj1SWW_ywAAANU"]
[Thu Jul 30 12:26:12.506272 2026] [security2:error] [pid 738779:tid 739015] [client 20.240.254.167:11526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.254.240.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/68.php"] [unique_id "amuJNPxa4UbeLxj1SWW_zAAAAO8"]
[Thu Jul 30 12:26:12.506384 2026] [security2:error] [pid 738779:tid 739015] [client 20.240.254.167:11526] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/68.php"] [unique_id "amuJNPxa4UbeLxj1SWW_zAAAAO8"]
[Thu Jul 30 12:26:12.783567 2026] [security2:error] [pid 738779:tid 738954] [client 142.93.53.183:61795] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/asset/alfacgiapi/perl.alfa"] [unique_id "amuJNPxa4UbeLxj1SWW_0wAAALI"]
[Thu Jul 30 12:26:12.862225 2026] [security2:error] [pid 738779:tid 738934] [client 20.240.254.167:11832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.254.240.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/66.php"] [unique_id "amuJNPxa4UbeLxj1SWW_1gAAAJ4"]
[Thu Jul 30 12:26:12.862338 2026] [security2:error] [pid 738779:tid 738934] [client 20.240.254.167:11832] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/66.php"] [unique_id "amuJNPxa4UbeLxj1SWW_1gAAAJ4"]
[Thu Jul 30 12:26:12.984873 2026] [security2:error] [pid 738779:tid 738920] [client 20.226.5.174:4099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-includes/css/F0x.php"] [unique_id "amuJNPxa4UbeLxj1SWW_2AAAAJA"]
[Thu Jul 30 12:26:13.172948 2026] [security2:error] [pid 738779:tid 738917] [client 142.93.53.183:61804] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/asset/css/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJNfxa4UbeLxj1SWW_3QAAAI0"]
[Thu Jul 30 12:26:13.178386 2026] [security2:error] [pid 738779:tid 738985] [client 20.240.254.167:11792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.254.240.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/67.php"] [unique_id "amuJNfxa4UbeLxj1SWW_3gAAANE"]
[Thu Jul 30 12:26:13.178472 2026] [security2:error] [pid 738779:tid 738985] [client 20.240.254.167:11792] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/67.php"] [unique_id "amuJNfxa4UbeLxj1SWW_3gAAANE"]
[Thu Jul 30 12:26:13.501295 2026] [security2:error] [pid 738779:tid 739014] [client 20.240.254.167:11800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.254.240.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/65.php"] [unique_id "amuJNfxa4UbeLxj1SWW_5QAAAO4"]
[Thu Jul 30 12:26:13.501389 2026] [security2:error] [pid 738779:tid 739014] [client 20.240.254.167:11800] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/65.php"] [unique_id "amuJNfxa4UbeLxj1SWW_5QAAAO4"]
[Thu Jul 30 12:26:13.519381 2026] [security2:error] [pid 738779:tid 738975] [client 52.238.199.152:51337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/app.php"] [unique_id "amuJNfxa4UbeLxj1SWW_5gAAAMc"]
[Thu Jul 30 12:26:13.563383 2026] [security2:error] [pid 738779:tid 738946] [client 142.93.53.183:61817] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/asset/css/alfacgiapi/perl.alfa"] [unique_id "amuJNfxa4UbeLxj1SWW_6AAAAKo"]
[Thu Jul 30 12:26:13.835217 2026] [security2:error] [pid 738779:tid 738976] [client 20.240.254.167:11777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.254.240.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/64.php"] [unique_id "amuJNfxa4UbeLxj1SWW_7AAAAMg"]
[Thu Jul 30 12:26:13.835319 2026] [security2:error] [pid 738779:tid 738976] [client 20.240.254.167:11777] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/64.php"] [unique_id "amuJNfxa4UbeLxj1SWW_7AAAAMg"]
[Thu Jul 30 12:26:13.953893 2026] [security2:error] [pid 738779:tid 738953] [client 142.93.53.183:61828] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/asset/media/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJNfxa4UbeLxj1SWW_7wAAALE"]
[Thu Jul 30 12:26:14.153610 2026] [security2:error] [pid 738779:tid 739021] [client 20.226.5.174:4134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/view.php"] [unique_id "amuJNvxa4UbeLxj1SWW_8QAAAPU"]
[Thu Jul 30 12:26:14.196094 2026] [security2:error] [pid 738779:tid 738988] [client 20.240.254.167:11789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.254.240.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/63.php"] [unique_id "amuJNvxa4UbeLxj1SWW_8gAAANQ"]
[Thu Jul 30 12:26:14.196190 2026] [security2:error] [pid 738779:tid 738988] [client 20.240.254.167:11789] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/63.php"] [unique_id "amuJNvxa4UbeLxj1SWW_8gAAANQ"]
[Thu Jul 30 12:26:14.231380 2026] [core:notice] [pid 738779:tid 738854] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:14.326028 2026] [security2:error] [pid 738779:tid 738948] [client 52.238.199.152:18239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/k.php"] [unique_id "amuJNvxa4UbeLxj1SWW_-AAAAKw"]
[Thu Jul 30 12:26:14.344249 2026] [security2:error] [pid 738779:tid 739005] [client 142.93.53.183:61844] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/asset/media/alfacgiapi/perl.alfa"] [unique_id "amuJNvxa4UbeLxj1SWW_-QAAAOU"]
[Thu Jul 30 12:26:14.462905 2026] [core:notice] [pid 738779:tid 738877] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:14.556217 2026] [security2:error] [pid 738779:tid 739012] [client 20.240.254.167:11828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.254.240.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/62.php"] [unique_id "amuJNvxa4UbeLxj1SWW__wAAAOw"]
[Thu Jul 30 12:26:14.556327 2026] [security2:error] [pid 738779:tid 739012] [client 20.240.254.167:11828] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/62.php"] [unique_id "amuJNvxa4UbeLxj1SWW__wAAAOw"]
[Thu Jul 30 12:26:14.735397 2026] [security2:error] [pid 738779:tid 739015] [client 142.93.53.183:61858] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/js/alfacgiapi/perl.alfa"] [unique_id "amuJNvxa4UbeLxj1SWXAAAAAAO8"]
[Thu Jul 30 12:26:14.879186 2026] [security2:error] [pid 738779:tid 739029] [client 74.7.230.10:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.airevoduct.ltd"] [uri "/index.php"] [unique_id "amuJNvxa4UbeLxj1SWW__gAA_V4"]
[Thu Jul 30 12:26:14.879234 2026] [security2:error] [pid 738779:tid 739029] [client 74.7.230.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.airevoduct.ltd"] [uri "/index.php"] [unique_id "amuJNvxa4UbeLxj1SWW__gAA_V4"]
[Thu Jul 30 12:26:14.955816 2026] [security2:error] [pid 738779:tid 739001] [client 20.240.254.167:11782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.254.240.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/61.php"] [unique_id "amuJNvxa4UbeLxj1SWXABAAAAOE"]
[Thu Jul 30 12:26:14.955938 2026] [security2:error] [pid 738779:tid 739001] [client 20.240.254.167:11782] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/61.php"] [unique_id "amuJNvxa4UbeLxj1SWXABAAAAOE"]
[Thu Jul 30 12:26:15.126110 2026] [security2:error] [pid 738779:tid 738993] [client 142.93.53.183:61870] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/css/alfacgiapi/perl.alfa"] [unique_id "amuJN_xa4UbeLxj1SWXACAAAANk"]
[Thu Jul 30 12:26:15.200087 2026] [security2:error] [pid 738779:tid 738989] [client 38.190.144.4:40789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJN_xa4UbeLxj1SWXACQAAANU"]
[Thu Jul 30 12:26:15.200216 2026] [security2:error] [pid 738779:tid 738989] [client 38.190.144.4:40789] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJN_xa4UbeLxj1SWXACQAAANU"]
[Thu Jul 30 12:26:15.285996 2026] [security2:error] [pid 738779:tid 739033] [client 52.238.199.152:51349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-fmfile.php"] [unique_id "amuJN_xa4UbeLxj1SWXACwAAAQE"]
[Thu Jul 30 12:26:15.307270 2026] [security2:error] [pid 738779:tid 738917] [client 20.240.254.167:11793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.254.240.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/60.php"] [unique_id "amuJN_xa4UbeLxj1SWXADAAAAI0"]
[Thu Jul 30 12:26:15.307363 2026] [security2:error] [pid 738779:tid 738917] [client 20.240.254.167:11793] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/60.php"] [unique_id "amuJN_xa4UbeLxj1SWXADAAAAI0"]
[Thu Jul 30 12:26:15.328924 2026] [security2:error] [pid 738779:tid 738928] [client 20.226.5.174:4164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-includes/blocks/site-title/index.php"] [unique_id "amuJN_xa4UbeLxj1SWXADQAAAJg"]
[Thu Jul 30 12:26:15.506618 2026] [security2:error] [pid 738779:tid 738945] [client 20.52.54.143:10182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin.php"] [unique_id "amuJN_xa4UbeLxj1SWXAFAAAAKk"]
[Thu Jul 30 12:26:15.516613 2026] [security2:error] [pid 738779:tid 738930] [client 142.93.53.183:61878] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/css/images/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJN_xa4UbeLxj1SWXAFQAAAJo"]
[Thu Jul 30 12:26:15.819566 2026] [security2:error] [pid 738779:tid 738919] [client 158.158.76.106:25279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuJN_xa4UbeLxj1SWXAGQAAAI8"]
[Thu Jul 30 12:26:15.819683 2026] [security2:error] [pid 738779:tid 738919] [client 158.158.76.106:25279] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "shorewooddaycare.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuJN_xa4UbeLxj1SWXAGQAAAI8"]
[Thu Jul 30 12:26:15.907186 2026] [security2:error] [pid 738779:tid 738926] [client 142.93.53.183:61887] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/css/images/alfacgiapi/perl.alfa"] [unique_id "amuJN_xa4UbeLxj1SWXAGgAAAJY"]
[Thu Jul 30 12:26:16.049036 2026] [security2:error] [pid 738779:tid 738959] [client 74.7.230.10:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "airevoduct.ltd"] [uri "/index.php"] [unique_id "amuJN_xa4UbeLxj1SWXAGAAAt2A"], referer: https://www.airevoduct.ltd/robots.txt
[Thu Jul 30 12:26:16.064547 2026] [autoindex:error] [pid 738779:tid 738958] [client 139.28.219.70:48380] AH01276: Cannot serve directory /home2/tvsnyxte/public_html/website_f8c1eb2c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:26:16.206567 2026] [autoindex:error] [pid 738779:tid 738961] [client 139.28.219.70:48380] AH01276: Cannot serve directory /home2/tvsnyxte/public_html/website_f8c1eb2c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:26:16.297862 2026] [security2:error] [pid 738779:tid 738953] [client 142.93.53.183:61899] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/css/themes/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJOPxa4UbeLxj1SWXAIwAAALE"]
[Thu Jul 30 12:26:16.344623 2026] [security2:error] [pid 738779:tid 739006] [client 139.28.219.70:48380] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "spadealist.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuJOPxa4UbeLxj1SWXAJAAAAOY"]
[Thu Jul 30 12:26:16.617262 2026] [core:notice] [pid 738779:tid 739030] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:16.656135 2026] [security2:error] [pid 738779:tid 738918] [client 139.28.219.70:48384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spadealist.com"] [uri "/xmlrpc.php"] [unique_id "amuJOPxa4UbeLxj1SWXALAAAAI4"]
[Thu Jul 30 12:26:16.687996 2026] [security2:error] [pid 738779:tid 738972] [client 142.93.53.183:61908] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/css/themes/alfacgiapi/perl.alfa"] [unique_id "amuJOPxa4UbeLxj1SWXALQAAAMQ"]
[Thu Jul 30 12:26:16.826666 2026] [security2:error] [pid 738779:tid 738943] [client 158.158.76.106:4278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuJOPxa4UbeLxj1SWXALgAAAKc"]
[Thu Jul 30 12:26:16.826775 2026] [security2:error] [pid 738779:tid 738943] [client 158.158.76.106:4278] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "shorewooddaycare.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuJOPxa4UbeLxj1SWXALgAAAKc"]
[Thu Jul 30 12:26:16.861649 2026] [core:notice] [pid 738779:tid 739025] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:16.986791 2026] [autoindex:error] [pid 738779:tid 739036] [client 139.28.219.70:48396] AH01276: Cannot serve directory /home2/tvsnyxte/public_html/website_f8c1eb2c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:26:17.067928 2026] [security2:error] [pid 738779:tid 738980] [client 142.93.53.183:61919] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/administrator/alfacgiapi/perl.alfa"] [unique_id "amuJOfxa4UbeLxj1SWXANwAAAMw"]
[Thu Jul 30 12:26:17.146365 2026] [security2:error] [pid 738779:tid 738955] [client 139.28.219.70:48396] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "spadealist.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuJOfxa4UbeLxj1SWXAPQAAALM"]
[Thu Jul 30 12:26:17.436940 2026] [security2:error] [pid 738779:tid 739004] [client 52.238.199.152:18206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wi.php"] [unique_id "amuJOfxa4UbeLxj1SWXAQgAAAOQ"]
[Thu Jul 30 12:26:17.451461 2026] [security2:error] [pid 738779:tid 738923] [client 142.93.53.183:61928] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/vendor/ALFA_DATA/perl.alfa"] [unique_id "amuJOfxa4UbeLxj1SWXAQwAAAJM"]
[Thu Jul 30 12:26:17.468756 2026] [security2:error] [pid 738779:tid 739008] [client 139.28.219.70:48404] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "spadealist.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuJOfxa4UbeLxj1SWXARAAAAOg"]
[Thu Jul 30 12:26:17.492403 2026] [security2:error] [pid 738779:tid 738890] [remote 216.73.216.152:25997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuJOfxa4UbeLxj1SWXASAAAwW4"]
[Thu Jul 30 12:26:17.589655 2026] [security2:error] [pid 738779:tid 739005] [client 20.52.54.143:9971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/size.php"] [unique_id "amuJOfxa4UbeLxj1SWXASQAAAOU"]
[Thu Jul 30 12:26:17.735294 2026] [security2:error] [pid 738779:tid 738966] [client 139.28.219.70:48408] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "spadealist.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuJOfxa4UbeLxj1SWXATQAAAL4"]
[Thu Jul 30 12:26:17.742813 2026] [security2:error] [pid 738779:tid 738888] [remote 57.141.0.65:26454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/56555984686/feed/rss2/"] [unique_id "amuJOfxa4UbeLxj1SWXATgAAkGw"]
[Thu Jul 30 12:26:17.842429 2026] [security2:error] [pid 738779:tid 739024] [client 142.93.53.183:61936] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/vendor/alfacgiapi/alfacgiapi/perl.alfa"] [unique_id "amuJOfxa4UbeLxj1SWXATwAAAPg"]
[Thu Jul 30 12:26:17.952217 2026] [security2:error] [pid 738779:tid 738951] [client 74.7.244.37:45720] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.revolutionary-technologies.com"] [uri "/index.php"] [unique_id "amuJN_xa4UbeLxj1SWXAFgAAr2I"]
[Thu Jul 30 12:26:17.996166 2026] [security2:error] [pid 738779:tid 739011] [client 139.28.219.70:48416] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "spadealist.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuJOfxa4UbeLxj1SWXAUAAAAOs"]
[Thu Jul 30 12:26:18.233691 2026] [security2:error] [pid 738779:tid 738959] [client 142.93.53.183:61945] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/vendor/phpunit/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJOvxa4UbeLxj1SWXAVwAAALc"]
[Thu Jul 30 12:26:18.256955 2026] [security2:error] [pid 738779:tid 738958] [client 139.28.219.70:48430] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "spadealist.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuJOvxa4UbeLxj1SWXAWAAAALY"]
[Thu Jul 30 12:26:18.316732 2026] [security2:error] [pid 738779:tid 739023] [client 85.208.96.208:48314] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/12/09/analise-selecao-brasileira-nao-entendeu-o-jogo-e-fez-tudo-o-que-a-croacia-quis/"] [unique_id "amuJOvxa4UbeLxj1SWXAWQAAAPc"]
[Thu Jul 30 12:26:18.316893 2026] [security2:error] [pid 738779:tid 739023] [client 85.208.96.208:48314] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/12/09/analise-selecao-brasileira-nao-entendeu-o-jogo-e-fez-tudo-o-que-a-croacia-quis/"] [unique_id "amuJOvxa4UbeLxj1SWXAWQAAAPc"]
[Thu Jul 30 12:26:18.527558 2026] [security2:error] [pid 738779:tid 738961] [client 139.28.219.70:48446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "spadealist.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuJOvxa4UbeLxj1SWXAWwAAALk"]
[Thu Jul 30 12:26:18.618252 2026] [security2:error] [pid 738779:tid 738996] [client 142.93.53.183:61956] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/vendor/phpunit/alfacgiapi/perl.alfa"] [unique_id "amuJOvxa4UbeLxj1SWXAYQAAANw"]
[Thu Jul 30 12:26:18.703939 2026] [security2:error] [pid 738779:tid 739014] [client 20.52.54.143:9977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/wp-class.php"] [unique_id "amuJOvxa4UbeLxj1SWXAYwAAAO4"]
[Thu Jul 30 12:26:18.809017 2026] [security2:error] [pid 738779:tid 738916] [client 139.28.219.70:48460] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "spadealist.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuJOvxa4UbeLxj1SWXAZAAAAIw"]
[Thu Jul 30 12:26:19.011897 2026] [security2:error] [pid 738779:tid 739030] [client 142.93.53.183:61968] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/vendor/phpspec/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJO_xa4UbeLxj1SWXAZgAAAP4"]
[Thu Jul 30 12:26:19.064492 2026] [security2:error] [pid 738779:tid 738972] [client 139.28.219.70:48466] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "spadealist.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuJO_xa4UbeLxj1SWXAagAAAMQ"]
[Thu Jul 30 12:26:19.310364 2026] [security2:error] [pid 738779:tid 738999] [client 20.52.54.143:9381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/403.php"] [unique_id "amuJO_xa4UbeLxj1SWXAbwAAAN8"]
[Thu Jul 30 12:26:19.320604 2026] [security2:error] [pid 738779:tid 738942] [client 139.28.219.70:48478] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "spadealist.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuJO_xa4UbeLxj1SWXAcAAAAKY"]
[Thu Jul 30 12:26:19.401788 2026] [security2:error] [pid 738779:tid 738978] [client 142.93.53.183:61977] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/vendor/phpspec/alfacgiapi/perl.alfa"] [unique_id "amuJO_xa4UbeLxj1SWXAcQAAAMo"]
[Thu Jul 30 12:26:19.519007 2026] [security2:error] [pid 738779:tid 738994] [client 158.158.76.106:40099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/wp-login.php"] [unique_id "amuJO_xa4UbeLxj1SWXAbgAAANo"]
[Thu Jul 30 12:26:19.519269 2026] [security2:error] [pid 738779:tid 738994] [client 158.158.76.106:40099] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "shorewooddaycare.com"] [uri "/wp-login.php"] [unique_id "amuJO_xa4UbeLxj1SWXAbgAAANo"]
[Thu Jul 30 12:26:19.595754 2026] [security2:error] [pid 738779:tid 739028] [client 139.28.219.70:48480] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "spadealist.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuJO_xa4UbeLxj1SWXAdAAAAPw"]
[Thu Jul 30 12:26:19.793137 2026] [security2:error] [pid 738779:tid 739001] [client 142.93.53.183:61990] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/vendor/mpdf/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJO_xa4UbeLxj1SWXAegAAAOE"]
[Thu Jul 30 12:26:19.872218 2026] [security2:error] [pid 738779:tid 738971] [client 139.28.219.70:48494] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "spadealist.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuJO_xa4UbeLxj1SWXAewAAAMM"]
[Thu Jul 30 12:26:20.132125 2026] [security2:error] [pid 738779:tid 739004] [client 37.120.155.179:33478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.155.120.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuJPPxa4UbeLxj1SWXAfAAAAOQ"]
[Thu Jul 30 12:26:20.132228 2026] [security2:error] [pid 738779:tid 739004] [client 37.120.155.179:33478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuJPPxa4UbeLxj1SWXAfAAAAOQ"]
[Thu Jul 30 12:26:20.136871 2026] [security2:error] [pid 738779:tid 738964] [client 2a03:2880:f800:19:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJO_xa4UbeLxj1SWXAcgAAvAU"]
[Thu Jul 30 12:26:20.141296 2026] [security2:error] [pid 738779:tid 738969] [client 139.28.219.70:48496] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "spadealist.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuJPPxa4UbeLxj1SWXAfwAAAME"]
[Thu Jul 30 12:26:20.183171 2026] [security2:error] [pid 738779:tid 738927] [client 142.93.53.183:62001] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/vendor/mpdf/alfacgiapi/perl.alfa"] [unique_id "amuJPPxa4UbeLxj1SWXAgQAAAJc"]
[Thu Jul 30 12:26:20.231512 2026] [security2:error] [pid 738779:tid 739013] [client 20.52.54.143:10179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amuJPPxa4UbeLxj1SWXAhQAAAO0"]
[Thu Jul 30 12:26:20.573904 2026] [security2:error] [pid 738779:tid 739024] [client 142.93.53.183:62010] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2022/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJPPxa4UbeLxj1SWXAigAAAPg"]
[Thu Jul 30 12:26:20.633263 2026] [security2:error] [pid 738779:tid 739026] [client 52.238.199.152:38855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/php8.php"] [unique_id "amuJPPxa4UbeLxj1SWXAiwAAAPo"]
[Thu Jul 30 12:26:20.912709 2026] [core:notice] [pid 738779:tid 739005] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:20.965117 2026] [security2:error] [pid 738779:tid 738924] [client 142.93.53.183:62019] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2022/alfacgiapi/perl.alfa"] [unique_id "amuJPPxa4UbeLxj1SWXAlgAAAJQ"]
[Thu Jul 30 12:26:21.039163 2026] [security2:error] [pid 738779:tid 738975] [client 20.52.54.143:9980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/as.php"] [unique_id "amuJPfxa4UbeLxj1SWXAlwAAAMc"]
[Thu Jul 30 12:26:21.355243 2026] [security2:error] [pid 738779:tid 738921] [client 142.93.53.183:62030] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2023/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJPfxa4UbeLxj1SWXAnwAAAJE"]
[Thu Jul 30 12:26:21.745739 2026] [security2:error] [pid 738779:tid 738925] [client 142.93.53.183:62044] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2023/alfacgiapi/perl.alfa"] [unique_id "amuJPfxa4UbeLxj1SWXApAAAAJU"]
[Thu Jul 30 12:26:21.994334 2026] [security2:error] [pid 738779:tid 739021] [client 20.52.54.143:9952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/includes/index.php"] [unique_id "amuJPfxa4UbeLxj1SWXAqAAAAPU"]
[Thu Jul 30 12:26:22.038388 2026] [security2:error] [pid 738779:tid 738957] [client 52.238.199.152:18199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/tes.php"] [unique_id "amuJPvxa4UbeLxj1SWXAqwAAALU"]
[Thu Jul 30 12:26:22.133941 2026] [security2:error] [pid 738779:tid 738956] [client 142.93.53.183:62051] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/build/assets/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJPvxa4UbeLxj1SWXArQAAALQ"]
[Thu Jul 30 12:26:22.512818 2026] [security2:error] [pid 738779:tid 738944] [client 142.93.53.183:62063] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/build/assets/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJPvxa4UbeLxj1SWXAuAAAAKg"]
[Thu Jul 30 12:26:22.658008 2026] [security2:error] [pid 738779:tid 738931] [client 158.158.76.106:40124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/red.php"] [unique_id "amuJPvxa4UbeLxj1SWXAuQAAAJs"]
[Thu Jul 30 12:26:22.658126 2026] [security2:error] [pid 738779:tid 738931] [client 158.158.76.106:40124] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "shorewooddaycare.com"] [uri "/red.php"] [unique_id "amuJPvxa4UbeLxj1SWXAuQAAAJs"]
[Thu Jul 30 12:26:22.902253 2026] [security2:error] [pid 738779:tid 738990] [client 142.93.53.183:62070] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/build/assets/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJPvxa4UbeLxj1SWXAwAAAANY"]
[Thu Jul 30 12:26:23.291198 2026] [security2:error] [pid 738779:tid 738977] [client 142.93.53.183:62084] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/KITABISACOM1337/kitabisacom1337api/perl.haxor"] [unique_id "amuJP_xa4UbeLxj1SWXAxQAAAMk"]
[Thu Jul 30 12:26:23.684688 2026] [security2:error] [pid 738779:tid 738993] [client 142.93.53.183:62091] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/KITABISACOM1337/kitabisacom1337api/py.haxor"] [unique_id "amuJP_xa4UbeLxj1SWXAygAAANk"]
[Thu Jul 30 12:26:23.701805 2026] [security2:error] [pid 738779:tid 738920] [client 20.52.54.143:9932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amuJP_xa4UbeLxj1SWXAywAAAJA"]
[Thu Jul 30 12:26:24.073908 2026] [security2:error] [pid 738779:tid 738968] [client 142.93.53.183:62101] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/KITABISACOM1337/kitabisacom1337api/bash.haxor"] [unique_id "amuJQPxa4UbeLxj1SWXA1AAAAMA"]
[Thu Jul 30 12:26:24.197136 2026] [core:error] [pid 738779:tid 738937] [client 74.7.228.43:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:26:24.197171 2026] [core:error] [pid 738779:tid 738937] [client 74.7.228.43:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:26:24.197309 2026] [security2:error] [pid 738779:tid 738937] [client 74.7.228.43:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.fnm.gzj.temporary.site"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "amuJQPxa4UbeLxj1SWXA1wAAAKE"]
[Thu Jul 30 12:26:24.197840 2026] [security2:error] [pid 738779:tid 738997] [client 74.7.228.43:49164] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.fnm.gzj.temporary.site"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuJQPxa4UbeLxj1SWXA1QAA3Rg"]
[Thu Jul 30 12:26:24.219061 2026] [security2:error] [pid 738779:tid 739018] [client 2a03:2880:f800:7:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJP_xa4UbeLxj1SWXAyQAA8gQ"]
[Thu Jul 30 12:26:24.462198 2026] [security2:error] [pid 738779:tid 739027] [client 142.93.53.183:62112] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/storage/files/shares/KITABISACOM1337/kitabisacom1337api/perl.haxor"] [unique_id "amuJQPxa4UbeLxj1SWXA2wAAAPs"]
[Thu Jul 30 12:26:24.482050 2026] [security2:error] [pid 738779:tid 739009] [client 20.52.54.143:10177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/plugins.php"] [unique_id "amuJQPxa4UbeLxj1SWXA3AAAAOk"]
[Thu Jul 30 12:26:24.579259 2026] [security2:error] [pid 738779:tid 738961] [client 46.232.235.5:41006] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.greensparkle.net"] [uri "/.env"] [unique_id "amuJQPxa4UbeLxj1SWXA4AAAALk"]
[Thu Jul 30 12:26:24.853562 2026] [security2:error] [pid 738779:tid 738984] [client 142.93.53.183:62122] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/storage/files/shares/KITABISACOM1337/kitabisacom1337api/py.haxor"] [unique_id "amuJQPxa4UbeLxj1SWXA5AAAANA"]
[Thu Jul 30 12:26:25.246021 2026] [security2:error] [pid 738779:tid 739021] [client 142.93.53.183:62131] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/storage/files/shares/KITABISACOM1337/kitabisacom1337api/bash.haxor"] [unique_id "amuJQfxa4UbeLxj1SWXA6gAAAPU"]
[Thu Jul 30 12:26:25.572218 2026] [security2:error] [pid 738779:tid 738988] [client 20.52.54.143:9955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/js/index.php"] [unique_id "amuJQfxa4UbeLxj1SWXA9wAAANQ"]
[Thu Jul 30 12:26:25.633752 2026] [security2:error] [pid 738779:tid 738991] [client 142.93.53.183:62139] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/SUPERBONE/perl.alfa"] [unique_id "amuJQfxa4UbeLxj1SWXA-QAAANc"]
[Thu Jul 30 12:26:25.669714 2026] [authz_core:error] [pid 738779:tid 738995] [client 46.232.235.5:41032] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.env
[Thu Jul 30 12:26:25.689171 2026] [authz_core:error] [pid 738779:tid 739015] [client 46.232.235.5:41044] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.env
[Thu Jul 30 12:26:25.999194 2026] [authz_core:error] [pid 738779:tid 738949] [client 46.232.235.5:41058] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.git
[Thu Jul 30 12:26:26.009866 2026] [security2:error] [pid 738779:tid 738927] [client 142.93.53.183:62152] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/SUPERBONE/py.alfa"] [unique_id "amuJQvxa4UbeLxj1SWXBBAAAAJc"]
[Thu Jul 30 12:26:26.026645 2026] [authz_core:error] [pid 738779:tid 738964] [client 46.232.235.5:41072] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.git
[Thu Jul 30 12:26:26.295153 2026] [security2:error] [pid 738779:tid 738977] [client 20.52.54.143:9960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/go.php"] [unique_id "amuJQvxa4UbeLxj1SWXBBgAAAMk"]
[Thu Jul 30 12:26:26.388007 2026] [security2:error] [pid 738779:tid 738917] [client 142.93.53.183:62161] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/SUPERBONE/bash.alfa"] [unique_id "amuJQvxa4UbeLxj1SWXBBwAAAI0"]
[Thu Jul 30 12:26:26.477550 2026] [security2:error] [pid 738779:tid 738989] [client 38.190.144.4:50003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJQvxa4UbeLxj1SWXBCwAAANU"]
[Thu Jul 30 12:26:26.477660 2026] [security2:error] [pid 738779:tid 738989] [client 38.190.144.4:50003] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJQvxa4UbeLxj1SWXBCwAAANU"]
[Thu Jul 30 12:26:26.777144 2026] [security2:error] [pid 738779:tid 738946] [client 142.93.53.183:62171] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/Mr-G4cor/haxorcgiapi/perl.haxor"] [unique_id "amuJQvxa4UbeLxj1SWXBEQAAAKo"]
[Thu Jul 30 12:26:26.982342 2026] [authz_core:error] [pid 738779:tid 738992] [client 46.232.235.5:41076] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.env
[Thu Jul 30 12:26:27.058509 2026] [authz_core:error] [pid 738779:tid 739003] [client 46.232.235.5:41082] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.git
[Thu Jul 30 12:26:27.168038 2026] [security2:error] [pid 738779:tid 738945] [client 142.93.53.183:62180] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/Mr-G4cor/haxorcgiapi/py.haxor"] [unique_id "amuJQ_xa4UbeLxj1SWXBHQAAAKk"]
[Thu Jul 30 12:26:27.319158 2026] [security2:error] [pid 738779:tid 738970] [client 2a03:2880:f800:20:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJQvxa4UbeLxj1SWXBEAAAwiI"]
[Thu Jul 30 12:26:27.490133 2026] [security2:error] [pid 738779:tid 739009] [client 20.52.54.143:10187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/test1.php"] [unique_id "amuJQ_xa4UbeLxj1SWXBIwAAAOk"]
[Thu Jul 30 12:26:27.558478 2026] [security2:error] [pid 738779:tid 738987] [client 142.93.53.183:62190] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/AZZ_DATA/hackermancgiapi/perl.hackerman"] [unique_id "amuJQ_xa4UbeLxj1SWXBJwAAANM"]
[Thu Jul 30 12:26:27.937070 2026] [security2:error] [pid 738779:tid 738991] [client 142.93.53.183:62200] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/AZZ_DATA/hackermancgiapi/bash.hackerman"] [unique_id "amuJQ_xa4UbeLxj1SWXBLgAAANc"]
[Thu Jul 30 12:26:28.324088 2026] [security2:error] [pid 738779:tid 738969] [client 142.93.53.183:62208] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/D0R4H4X0R/haxorcgiapi/perl.haxor"] [unique_id "amuJRPxa4UbeLxj1SWXBOgAAAME"]
[Thu Jul 30 12:26:28.401663 2026] [security2:error] [pid 738779:tid 738916] [client 57.141.0.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJQ_xa4UbeLxj1SWXBLQAAAIw"]
[Thu Jul 30 12:26:28.697716 2026] [security2:error] [pid 738779:tid 738919] [client 142.93.53.183:62215] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/D0R4H4X0R/haxorcgiapi/bash.haxor"] [unique_id "amuJRPxa4UbeLxj1SWXBRgAAAI8"]
[Thu Jul 30 12:26:29.087193 2026] [security2:error] [pid 738779:tid 738997] [client 142.93.53.183:62222] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/Mr-G4cor/haxorcgiapi/bash.haxor"] [unique_id "amuJRfxa4UbeLxj1SWXBSgAAAN0"]
[Thu Jul 30 12:26:29.394399 2026] [security2:error] [pid 738779:tid 738920] [client 52.238.199.152:38880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/about.php"] [unique_id "amuJRfxa4UbeLxj1SWXBUAAAAJA"]
[Thu Jul 30 12:26:29.480101 2026] [security2:error] [pid 738779:tid 738945] [client 142.93.53.183:62236] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/WOLFSHELL/razorcgiapi/perl.haxor"] [unique_id "amuJRfxa4UbeLxj1SWXBUQAAAKk"]
[Thu Jul 30 12:26:29.534330 2026] [core:notice] [pid 738779:tid 738836] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:29.812609 2026] [core:notice] [pid 738779:tid 738849] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:29.886369 2026] [security2:error] [pid 738779:tid 738936] [client 142.93.53.183:62245] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/WOLFSHELL/razorcgiapi/py.haxor"] [unique_id "amuJRfxa4UbeLxj1SWXBXAAAAKA"]
[Thu Jul 30 12:26:30.276759 2026] [security2:error] [pid 738779:tid 739030] [client 142.93.53.183:62253] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/WOLFSHELL/razorcgiapi/bash.haxor"] [unique_id "amuJRvxa4UbeLxj1SWXBZQAAAP4"]
[Thu Jul 30 12:26:30.381218 2026] [proxy:error] [pid 738779:tid 738938] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:30.381307 2026] [proxy_http:error] [pid 738779:tid 738938] [client 20.52.54.143:9922] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:30.381863 2026] [proxy:error] [pid 738779:tid 738938] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:30.381905 2026] [proxy_http:error] [pid 738779:tid 738938] [client 20.52.54.143:9922] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:30.666043 2026] [security2:error] [pid 738779:tid 738981] [client 142.93.53.183:62262] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/includes/1337_DATA/perl.alfa"] [unique_id "amuJRvxa4UbeLxj1SWXBagAAAM0"]
[Thu Jul 30 12:26:31.058734 2026] [security2:error] [pid 738779:tid 739017] [client 142.93.53.183:62271] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/blocks/badges/db/1337_DATA/perl.alfa"] [unique_id "amuJR_xa4UbeLxj1SWXBcQAAAPE"]
[Thu Jul 30 12:26:31.439154 2026] [security2:error] [pid 738779:tid 739008] [client 142.93.53.183:62278] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/1337_DATA/perl.alfa"] [unique_id "amuJR_xa4UbeLxj1SWXBegAAAOg"]
[Thu Jul 30 12:26:31.822359 2026] [security2:error] [pid 738779:tid 738973] [client 142.93.53.183:62287] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/section/1337_DATA/perl.alfa"] [unique_id "amuJR_xa4UbeLxj1SWXBjQAAAMU"]
[Thu Jul 30 12:26:32.156864 2026] [security2:error] [pid 738779:tid 738958] [client 57.141.0.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJR_xa4UbeLxj1SWXBgQAAALY"]
[Thu Jul 30 12:26:32.212294 2026] [security2:error] [pid 738779:tid 738985] [client 57.141.0.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJR_xa4UbeLxj1SWXBhwAAANE"]
[Thu Jul 30 12:26:32.214344 2026] [security2:error] [pid 738779:tid 739023] [client 142.93.53.183:62292] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/admin/1337_DATA/perl.alfa"] [unique_id "amuJSPxa4UbeLxj1SWXBnAAAAPc"]
[Thu Jul 30 12:26:32.281846 2026] [security2:error] [pid 738779:tid 738916] [client 20.52.54.143:10208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/images/index.php"] [unique_id "amuJSPxa4UbeLxj1SWXBnQAAAIw"]
[Thu Jul 30 12:26:32.605126 2026] [security2:error] [pid 738779:tid 738936] [client 142.93.53.183:62300] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/1337_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJSPxa4UbeLxj1SWXBpAAAAKA"]
[Thu Jul 30 12:26:32.748862 2026] [security2:error] [pid 738779:tid 739000] [client 123.232.132.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJSPxa4UbeLxj1SWXBnwAA4Fo"]
[Thu Jul 30 12:26:32.859498 2026] [security2:error] [pid 738779:tid 738877] [remote 167.71.218.184:50514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.218.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wce.gzj.temporary.site"] [uri "/wp-login.php"] [unique_id "amuJSPxa4UbeLxj1SWXBrAAAlWE"]
[Thu Jul 30 12:26:32.995851 2026] [security2:error] [pid 738779:tid 739028] [client 142.93.53.183:62309] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/1337_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJSPxa4UbeLxj1SWXBrwAAAPw"]
[Thu Jul 30 12:26:33.230654 2026] [proxy:error] [pid 738779:tid 738933] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:33.230733 2026] [proxy_http:error] [pid 738779:tid 738933] [client 20.52.54.143:9975] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:33.231520 2026] [proxy:error] [pid 738779:tid 738933] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:33.231574 2026] [proxy_http:error] [pid 738779:tid 738933] [client 20.52.54.143:9975] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:33.386382 2026] [security2:error] [pid 738779:tid 738990] [client 142.93.53.183:62318] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/1337_DATA/alfacgiapi/py.alfa"] [unique_id "amuJSfxa4UbeLxj1SWXBuQAAANY"]
[Thu Jul 30 12:26:33.486742 2026] [security2:error] [pid 738779:tid 738991] [client 157.49.37.179:56362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJRvxa4UbeLxj1SWXBcAAAANc"], referer: http://pkf.jo
[Thu Jul 30 12:26:33.487431 2026] [security2:error] [pid 738779:tid 739026] [client 102.66.149.193:52815] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJR_xa4UbeLxj1SWXBiwAAAPo"], referer: http://pkf.jo
[Thu Jul 30 12:26:33.487731 2026] [security2:error] [pid 738779:tid 738982] [client 203.223.89.75:39336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJRvxa4UbeLxj1SWXBYAAAAM4"], referer: http://pkf.jo
[Thu Jul 30 12:26:33.681600 2026] [core:error] [pid 738779:tid 738939] [client 74.7.228.33:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:26:33.681622 2026] [core:error] [pid 738779:tid 738939] [client 74.7.228.33:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:26:33.681770 2026] [security2:error] [pid 738779:tid 738939] [client 74.7.228.33:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.emberleafweeddeliverydispensary.delivery"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amuJSfxa4UbeLxj1SWXBwwAAAKM"]
[Thu Jul 30 12:26:33.682370 2026] [security2:error] [pid 738779:tid 738912] [client 74.7.228.33:36364] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.emberleafweeddeliverydispensary.delivery"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuJSfxa4UbeLxj1SWXBwQAAiGo"]
[Thu Jul 30 12:26:33.777234 2026] [security2:error] [pid 738779:tid 738973] [client 142.93.53.183:62326] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/HOKIDATA/hokicgiapi/perl.hoki"] [unique_id "amuJSfxa4UbeLxj1SWXBxwAAAMU"]
[Thu Jul 30 12:26:34.165298 2026] [security2:error] [pid 738779:tid 739018] [client 142.93.53.183:62336] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/HOKIDATA/hokicgiapi/bash.hoki"] [unique_id "amuJSvxa4UbeLxj1SWXBzgAAAPI"]
[Thu Jul 30 12:26:34.174382 2026] [security2:error] [pid 738779:tid 739022] [client 20.52.54.143:10236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/asd.php"] [unique_id "amuJSvxa4UbeLxj1SWXBzwAAAPY"]
[Thu Jul 30 12:26:34.192825 2026] [security2:error] [pid 738779:tid 738955] [client 52.238.199.152:38862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/headers.php"] [unique_id "amuJSvxa4UbeLxj1SWXB0AAAALM"]
[Thu Jul 30 12:26:34.558082 2026] [security2:error] [pid 738779:tid 738920] [client 142.93.53.183:62343] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/SEOBARBAR_1337/barbarpride/bash.alfa"] [unique_id "amuJSvxa4UbeLxj1SWXB2AAAAJA"]
[Thu Jul 30 12:26:34.830260 2026] [security2:error] [pid 738779:tid 738891] [remote 74.7.241.59:46426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuJSvxa4UbeLxj1SWXB3gAAjG8"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/theme-builder/documents
[Thu Jul 30 12:26:34.837816 2026] [security2:error] [pid 738779:tid 739009] [client 20.52.54.143:9958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/customize/index.php"] [unique_id "amuJSvxa4UbeLxj1SWXB4AAAAOk"]
[Thu Jul 30 12:26:34.950226 2026] [security2:error] [pid 738779:tid 738932] [client 142.93.53.183:62349] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/SEOBARBAR_1337/barbarpride/perl.alfa"] [unique_id "amuJSvxa4UbeLxj1SWXB5AAAAJw"]
[Thu Jul 30 12:26:35.073137 2026] [security2:error] [pid 738779:tid 739006] [client 74.7.230.38:40884] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.newyorkgiantsfootball.live.qsv.hfl.temporary.site"] [uri "/robots.txt"] [unique_id "amuJS_xa4UbeLxj1SWXB5gAAAOY"]
[Thu Jul 30 12:26:35.212677 2026] [authz_core:error] [pid 738779:tid 738972] [client 46.232.235.5:44112] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.env
[Thu Jul 30 12:26:35.329409 2026] [security2:error] [pid 738779:tid 739029] [client 142.93.53.183:62355] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/SEOBARBAR_1337/barbarpride/py.alfa"] [unique_id "amuJS_xa4UbeLxj1SWXB6QAAAP0"]
[Thu Jul 30 12:26:35.359801 2026] [authz_core:error] [pid 738779:tid 738938] [client 46.232.235.5:44122] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.env
[Thu Jul 30 12:26:35.714558 2026] [security2:error] [pid 738779:tid 738998] [client 142.93.53.183:62360] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/HYBRID_THEORY/hybridcgiapi/perl.alfa"] [unique_id "amuJS_xa4UbeLxj1SWXB8gAAAN4"]
[Thu Jul 30 12:26:36.056147 2026] [security2:error] [pid 738779:tid 738903] [remote 74.7.241.60:48418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/js/article.php"] [unique_id "amuJTPxa4UbeLxj1SWXB-gAAw3s"], referer: https://aded-rdc.org/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/js/bootstrap.bundle.min.js
[Thu Jul 30 12:26:36.083103 2026] [security2:error] [pid 738779:tid 738947] [client 52.238.199.152:62676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/admin.php"] [unique_id "amuJTPxa4UbeLxj1SWXB_AAAAKs"]
[Thu Jul 30 12:26:36.085709 2026] [autoindex:error] [pid 738779:tid 738918] [client 150.109.119.38:56288] AH01276: Cannot serve directory /home2/evmudite/public_html/wp/wp-content/plugins/wp-google-map-plugin/assets/images/icons/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:26:36.095078 2026] [security2:error] [pid 738779:tid 738991] [client 142.93.53.183:62363] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/HYBRID_THEORY/hybridcgiapi/py.alfa"] [unique_id "amuJTPxa4UbeLxj1SWXB_QAAANc"]
[Thu Jul 30 12:26:36.481715 2026] [security2:error] [pid 738779:tid 738954] [client 142.93.53.183:62367] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/HYBRID_THEORY/hybridcgiapi/bash.alfa"] [unique_id "amuJTPxa4UbeLxj1SWXCAwAAALI"]
[Thu Jul 30 12:26:36.487655 2026] [security2:error] [pid 738779:tid 738963] [client 20.52.54.143:9951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amuJTPxa4UbeLxj1SWXCBQAAALs"]
[Thu Jul 30 12:26:36.857955 2026] [security2:error] [pid 738779:tid 738964] [client 142.93.53.183:62369] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/HOST_DATA/kucrutcgiapi/perl.kucrut"] [unique_id "amuJTPxa4UbeLxj1SWXCBwAAALw"]
[Thu Jul 30 12:26:36.950692 2026] [authz_core:error] [pid 738779:tid 739033] [client 46.232.235.5:44144] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.git
[Thu Jul 30 12:26:36.966427 2026] [authz_core:error] [pid 738779:tid 739026] [client 46.232.235.5:44138] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.git
[Thu Jul 30 12:26:37.029881 2026] [security2:error] [pid 738779:tid 738906] [remote 216.73.216.152:25997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuJTfxa4UbeLxj1SWXCEQAAwX4"]
[Thu Jul 30 12:26:37.231885 2026] [security2:error] [pid 738779:tid 738917] [client 142.93.53.183:62374] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/HOST_DATA/kucrutcgiapi/py.kucrut"] [unique_id "amuJTfxa4UbeLxj1SWXCEwAAAI0"]
[Thu Jul 30 12:26:37.391624 2026] [security2:error] [pid 738779:tid 738783] [remote 57.141.0.27:44234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/83915116186/feed/rss2/"] [unique_id "amuJTfxa4UbeLxj1SWXCFwAA0gM"]
[Thu Jul 30 12:26:37.426677 2026] [security2:error] [pid 738779:tid 739016] [client 20.52.54.143:9969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/atomlib.php"] [unique_id "amuJTfxa4UbeLxj1SWXCGAAAAPA"]
[Thu Jul 30 12:26:37.613149 2026] [security2:error] [pid 738779:tid 739009] [client 142.93.53.183:62375] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/HOST_DATA/kucrutcgiapi/bash.kucrut"] [unique_id "amuJTfxa4UbeLxj1SWXCHwAAAOk"]
[Thu Jul 30 12:26:37.996489 2026] [security2:error] [pid 738779:tid 739012] [client 142.93.53.183:62381] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/7Syndicate/oxnixcgiapi/perl.oxnix"] [unique_id "amuJTfxa4UbeLxj1SWXCJgAAAOw"]
[Thu Jul 30 12:26:38.153131 2026] [security2:error] [pid 738779:tid 738929] [client 38.190.144.4:50492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJTvxa4UbeLxj1SWXCLQAAAJk"]
[Thu Jul 30 12:26:38.153286 2026] [security2:error] [pid 738779:tid 738929] [client 38.190.144.4:50492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJTvxa4UbeLxj1SWXCLQAAAJk"]
[Thu Jul 30 12:26:38.386706 2026] [security2:error] [pid 738779:tid 739025] [client 142.93.53.183:62383] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/7Syndicate/oxnixcgiapi/py.oxnix"] [unique_id "amuJTvxa4UbeLxj1SWXCLgAAAPk"]
[Thu Jul 30 12:26:38.396048 2026] [proxy:error] [pid 738779:tid 738999] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:38.396126 2026] [proxy_http:error] [pid 738779:tid 738999] [client 20.52.54.143:9968] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:38.396764 2026] [proxy:error] [pid 738779:tid 738999] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:38.396810 2026] [proxy_http:error] [pid 738779:tid 738999] [client 20.52.54.143:9968] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:38.465364 2026] [security2:error] [pid 738779:tid 738932] [client 52.238.199.152:38796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/flower.php"] [unique_id "amuJTvxa4UbeLxj1SWXCMAAAAJw"]
[Thu Jul 30 12:26:38.571535 2026] [security2:error] [pid 738779:tid 739031] [client 2a03:2880:f800:2e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJTfxa4UbeLxj1SWXCIgAA_3M"]
[Thu Jul 30 12:26:38.778670 2026] [security2:error] [pid 738779:tid 739021] [client 142.93.53.183:62387] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/7Syndicate/oxnixcgiapi/bash.oxnix"] [unique_id "amuJTvxa4UbeLxj1SWXCNwAAAPU"]
[Thu Jul 30 12:26:38.845672 2026] [security2:error] [pid 738779:tid 738990] [client 74.7.175.166:43560] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "arabiandubaisafari.com"] [uri "/robots.txt"] [unique_id "amuJTvxa4UbeLxj1SWXCOAAA1go"]
[Thu Jul 30 12:26:39.167402 2026] [security2:error] [pid 738779:tid 739019] [client 142.93.53.183:62395] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/admin/controller/extension/extension/ALFA_DATA/perl.alfa"] [unique_id "amuJT_xa4UbeLxj1SWXCPgAAAPM"]
[Thu Jul 30 12:26:39.524938 2026] [proxy:error] [pid 738779:tid 738954] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:39.525037 2026] [proxy_http:error] [pid 738779:tid 738954] [client 20.52.54.143:9923] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:39.525847 2026] [proxy:error] [pid 738779:tid 738954] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:39.525896 2026] [proxy_http:error] [pid 738779:tid 738954] [client 20.52.54.143:9923] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:39.539876 2026] [security2:error] [pid 738779:tid 739005] [client 142.93.53.183:62396] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/files/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJT_xa4UbeLxj1SWXCRQAAAOU"]
[Thu Jul 30 12:26:39.806791 2026] [security2:error] [pid 738779:tid 738909] [client 158.158.76.106:54537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/log.php"] [unique_id "amuJT_xa4UbeLxj1SWXCTAAAAIU"]
[Thu Jul 30 12:26:39.806894 2026] [security2:error] [pid 738779:tid 738909] [client 158.158.76.106:54537] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "shorewooddaycare.com"] [uri "/log.php"] [unique_id "amuJT_xa4UbeLxj1SWXCTAAAAIU"]
[Thu Jul 30 12:26:39.928510 2026] [security2:error] [pid 738779:tid 739018] [client 142.93.53.183:62403] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/templates/beez3/ALFA_DATA/perl.alfa"] [unique_id "amuJT_xa4UbeLxj1SWXCTQAAAPI"]
[Thu Jul 30 12:26:40.000442 2026] [security2:error] [pid 738779:tid 739010] [client 52.238.199.152:62659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "amuJT_xa4UbeLxj1SWXCTgAAAOo"]
[Thu Jul 30 12:26:40.339470 2026] [security2:error] [pid 738779:tid 738959] [client 142.93.53.183:62407] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/tmp_images/alfacgiapi/perl"] [unique_id "amuJUPxa4UbeLxj1SWXCWQAAALc"]
[Thu Jul 30 12:26:40.731499 2026] [security2:error] [pid 738779:tid 738965] [client 142.93.53.183:62412] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/cgialfa/perl.alfa"] [unique_id "amuJUPxa4UbeLxj1SWXCYgAAAL0"]
[Thu Jul 30 12:26:40.860818 2026] [core:notice] [pid 738779:tid 738804] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:41.036586 2026] [core:notice] [pid 738779:tid 738901] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:41.036734 2026] [core:notice] [pid 738779:tid 738806] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:41.036734 2026] [core:notice] [pid 738779:tid 738809] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:41.036896 2026] [core:notice] [pid 738779:tid 738807] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:41.037058 2026] [core:notice] [pid 738779:tid 738808] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:41.092242 2026] [security2:error] [pid 738779:tid 738942] [client 103.122.66.226:33908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJUPxa4UbeLxj1SWXCYwAAAKY"], referer: http://pkf.jo
[Thu Jul 30 12:26:41.120667 2026] [security2:error] [pid 738779:tid 739025] [client 142.93.53.183:62415] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/uploaded/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuJUfxa4UbeLxj1SWXCbgAAAPk"]
[Thu Jul 30 12:26:41.147370 2026] [core:notice] [pid 738779:tid 738813] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:41.147486 2026] [core:notice] [pid 738779:tid 738823] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:41.147522 2026] [core:notice] [pid 738779:tid 738815] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:41.147619 2026] [core:notice] [pid 738779:tid 738818] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:41.147670 2026] [core:notice] [pid 738779:tid 738816] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:41.147711 2026] [core:notice] [pid 738779:tid 738817] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:41.148617 2026] [core:notice] [pid 738779:tid 738819] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:41.367793 2026] [core:notice] [pid 738779:tid 738821] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:41.373183 2026] [security2:error] [pid 738779:tid 738946] [client 150.109.73.51:60594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/camic/$$$call$$$/page/page/css"] [unique_id "amuJUfxa4UbeLxj1SWXCfAAAqik"], referer: https://www.ejournalugj.com/
[Thu Jul 30 12:26:41.511090 2026] [security2:error] [pid 738779:tid 738991] [client 142.93.53.183:62418] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/uploaded/LEVIATHAN/haxorcgiapi/bash.haxor"] [unique_id "amuJUfxa4UbeLxj1SWXCfgAAANc"]
[Thu Jul 30 12:26:41.542037 2026] [core:notice] [pid 738779:tid 738820] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:41.595229 2026] [security2:error] [pid 738779:tid 738979] [client 52.238.199.152:64301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-content.php"] [unique_id "amuJUfxa4UbeLxj1SWXCgAAAAMs"]
[Thu Jul 30 12:26:41.902410 2026] [security2:error] [pid 738779:tid 738934] [client 142.93.53.183:62425] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/uploaded/LEVIATHAN/haxorcgiapi/py.haxor"] [unique_id "amuJUfxa4UbeLxj1SWXChwAAAJ4"]
[Thu Jul 30 12:26:42.292464 2026] [security2:error] [pid 738779:tid 738958] [client 142.93.53.183:62430] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/vendor/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuJUvxa4UbeLxj1SWXCjAAAALY"]
[Thu Jul 30 12:26:42.379130 2026] [proxy:error] [pid 738779:tid 738964] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:42.379363 2026] [proxy_http:error] [pid 738779:tid 738964] [client 74.7.175.169:46656] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:42.379922 2026] [proxy:error] [pid 738779:tid 738964] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:42.379964 2026] [proxy_http:error] [pid 738779:tid 738964] [client 74.7.175.169:46656] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:42.380114 2026] [security2:error] [pid 738779:tid 738964] [client 74.7.175.169:46656] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "cpcontacts.abudhabifurnituremoverspackers.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuJUvxa4UbeLxj1SWXCkAAAALw"]
[Thu Jul 30 12:26:42.559654 2026] [security2:error] [pid 738779:tid 738937] [client 52.238.199.152:38846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/function.php"] [unique_id "amuJUvxa4UbeLxj1SWXCkQAAAKE"]
[Thu Jul 30 12:26:42.666014 2026] [security2:error] [pid 738779:tid 739027] [client 142.93.53.183:62435] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/vendor/LEVIATHAN/haxorcgiapi/bash.haxor"] [unique_id "amuJUvxa4UbeLxj1SWXCkgAAAPs"]
[Thu Jul 30 12:26:42.745175 2026] [security2:error] [pid 738779:tid 739003] [client 145.239.10.137:34896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/Jcrop.php"] [unique_id "amuJUvxa4UbeLxj1SWXClAAAAOM"], referer: http://dhowcruisedinner.com/Jcrop.php
[Thu Jul 30 12:26:42.873869 2026] [security2:error] [pid 738779:tid 739032] [client 20.52.54.143:9970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amuJUvxa4UbeLxj1SWXCmwAAAQA"]
[Thu Jul 30 12:26:43.039689 2026] [security2:error] [pid 738779:tid 738915] [client 142.93.53.183:62438] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/vendor/LEVIATHAN/haxorcgiapi/py.haxor"] [unique_id "amuJU_xa4UbeLxj1SWXCnAAAAIs"]
[Thu Jul 30 12:26:43.267290 2026] [core:notice] [pid 738779:tid 738829] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:43.418015 2026] [security2:error] [pid 738779:tid 738996] [client 142.93.53.183:62441] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/LEVIATHAN/haxorcgiapi/bash.haxor"] [unique_id "amuJU_xa4UbeLxj1SWXCpAAAANw"]
[Thu Jul 30 12:26:43.496457 2026] [proxy:error] [pid 738779:tid 738956] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:43.496535 2026] [proxy_http:error] [pid 738779:tid 738956] [client 20.52.54.143:10217] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:43.497100 2026] [proxy:error] [pid 738779:tid 738956] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:43.497146 2026] [proxy_http:error] [pid 738779:tid 738956] [client 20.52.54.143:10217] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:43.809891 2026] [security2:error] [pid 738779:tid 738936] [client 142.93.53.183:62445] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/LEVIATHAN/haxorcgiapi/py.haxor"] [unique_id "amuJU_xa4UbeLxj1SWXCpwAAAKA"]
[Thu Jul 30 12:26:44.199483 2026] [security2:error] [pid 738779:tid 738998] [client 142.93.53.183:62449] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/generic/tinymce/langs/j/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJVPxa4UbeLxj1SWXCsQAAAN4"]
[Thu Jul 30 12:26:44.388935 2026] [security2:error] [pid 738779:tid 739030] [client 57.141.0.53:62386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuJVPxa4UbeLxj1SWXCsAAA_jk"], referer: https://igetvape-australia.com/product/iget-bar-strawberry-lychee-ice/?add-to-cart=132
[Thu Jul 30 12:26:44.390398 2026] [security2:error] [pid 738779:tid 739001] [client 20.100.169.152:44141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuJVPxa4UbeLxj1SWXCtgAAAOE"]
[Thu Jul 30 12:26:44.390493 2026] [security2:error] [pid 738779:tid 739001] [client 20.100.169.152:44141] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuJVPxa4UbeLxj1SWXCtgAAAOE"]
[Thu Jul 30 12:26:44.453662 2026] [security2:error] [pid 738779:tid 738918] [client 37.120.155.179:54988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.155.120.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuJVPxa4UbeLxj1SWXCugAAAI4"]
[Thu Jul 30 12:26:44.453743 2026] [security2:error] [pid 738779:tid 738918] [client 37.120.155.179:54988] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuJVPxa4UbeLxj1SWXCugAAAI4"]
[Thu Jul 30 12:26:44.481720 2026] [proxy:error] [pid 738779:tid 738994] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:44.481786 2026] [proxy_http:error] [pid 738779:tid 738994] [client 20.52.54.143:9959] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:44.482362 2026] [proxy:error] [pid 738779:tid 738994] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:44.482406 2026] [proxy_http:error] [pid 738779:tid 738994] [client 20.52.54.143:9959] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:44.589258 2026] [security2:error] [pid 738779:tid 738982] [client 142.93.53.183:62452] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/generic/tinymce/langs/j/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJVPxa4UbeLxj1SWXCvAAAAM4"]
[Thu Jul 30 12:26:44.712944 2026] [security2:error] [pid 738779:tid 738939] [client 20.100.169.152:62985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuJVPxa4UbeLxj1SWXCvQAAAKM"]
[Thu Jul 30 12:26:44.713077 2026] [security2:error] [pid 738779:tid 738939] [client 20.100.169.152:62985] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuJVPxa4UbeLxj1SWXCvQAAAKM"]
[Thu Jul 30 12:26:44.977478 2026] [security2:error] [pid 738779:tid 738971] [client 142.93.53.183:62456] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/generic/tinymce/langs/j/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJVPxa4UbeLxj1SWXCxAAAAMM"]
[Thu Jul 30 12:26:45.014575 2026] [security2:error] [pid 738779:tid 738911] [client 20.100.169.152:44097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/x.php"] [unique_id "amuJVfxa4UbeLxj1SWXCxQAAAIc"]
[Thu Jul 30 12:26:45.014659 2026] [security2:error] [pid 738779:tid 738911] [client 20.100.169.152:44097] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/x.php"] [unique_id "amuJVfxa4UbeLxj1SWXCxQAAAIc"]
[Thu Jul 30 12:26:45.295178 2026] [security2:error] [pid 738779:tid 738973] [client 52.238.199.152:55067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/chosen.php"] [unique_id "amuJVfxa4UbeLxj1SWXCxgAAAMU"]
[Thu Jul 30 12:26:45.317138 2026] [security2:error] [pid 738779:tid 738969] [client 20.100.169.152:63025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/mgrr.php"] [unique_id "amuJVfxa4UbeLxj1SWXCxwAAAME"]
[Thu Jul 30 12:26:45.317225 2026] [security2:error] [pid 738779:tid 738969] [client 20.100.169.152:63025] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/mgrr.php"] [unique_id "amuJVfxa4UbeLxj1SWXCxwAAAME"]
[Thu Jul 30 12:26:45.352571 2026] [security2:error] [pid 738779:tid 738964] [client 142.93.53.183:62458] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/cache/SASKRA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJVfxa4UbeLxj1SWXCyAAAALw"]
[Thu Jul 30 12:26:45.452194 2026] [core:notice] [pid 738779:tid 738844] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:45.570743 2026] [security2:error] [pid 738779:tid 738842] [remote 97.74.87.194:36524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ladiessecretdepartment.com"] [uri "/wp-login.php"] [unique_id "amuJVfxa4UbeLxj1SWXC0QAA6z4"]
[Thu Jul 30 12:26:45.616069 2026] [security2:error] [pid 738779:tid 738961] [client 20.100.169.152:62998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/domvf.php"] [unique_id "amuJVfxa4UbeLxj1SWXC0wAAALk"]
[Thu Jul 30 12:26:45.616155 2026] [security2:error] [pid 738779:tid 738961] [client 20.100.169.152:62998] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/domvf.php"] [unique_id "amuJVfxa4UbeLxj1SWXC0wAAALk"]
[Thu Jul 30 12:26:45.638166 2026] [proxy:error] [pid 738779:tid 738968] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:45.638233 2026] [proxy_http:error] [pid 738779:tid 738968] [client 20.52.54.143:9962] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:45.638778 2026] [proxy:error] [pid 738779:tid 738968] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:45.638821 2026] [proxy_http:error] [pid 738779:tid 738968] [client 20.52.54.143:9962] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:45.733868 2026] [security2:error] [pid 738779:tid 738970] [client 142.93.53.183:62463] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/cache/SASKRA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJVfxa4UbeLxj1SWXC2gAAAMI"]
[Thu Jul 30 12:26:45.741300 2026] [security2:error] [pid 738779:tid 738959] [client 158.158.76.106:13410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/edit.php"] [unique_id "amuJVfxa4UbeLxj1SWXC2wAAALc"]
[Thu Jul 30 12:26:45.741404 2026] [security2:error] [pid 738779:tid 738959] [client 158.158.76.106:13410] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "shorewooddaycare.com"] [uri "/edit.php"] [unique_id "amuJVfxa4UbeLxj1SWXC2wAAALc"]
[Thu Jul 30 12:26:45.928165 2026] [security2:error] [pid 738779:tid 738972] [client 20.100.169.152:44121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/yup.php"] [unique_id "amuJVfxa4UbeLxj1SWXC3gAAAMQ"]
[Thu Jul 30 12:26:45.928255 2026] [security2:error] [pid 738779:tid 738972] [client 20.100.169.152:44121] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/yup.php"] [unique_id "amuJVfxa4UbeLxj1SWXC3gAAAMQ"]
[Thu Jul 30 12:26:45.951569 2026] [security2:error] [pid 738779:tid 738983] [client 47.128.52.103:42800] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "nordeste1.com"] [uri "/robots.txt"] [unique_id "amuJVfxa4UbeLxj1SWXC4AAAAM8"]
[Thu Jul 30 12:26:46.121218 2026] [security2:error] [pid 738779:tid 738995] [client 142.93.53.183:62468] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/cache/SASKRA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJVvxa4UbeLxj1SWXC5gAAANs"]
[Thu Jul 30 12:26:46.238020 2026] [security2:error] [pid 738779:tid 738933] [client 20.100.169.152:63005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/X.php"] [unique_id "amuJVvxa4UbeLxj1SWXC6gAAAJ0"]
[Thu Jul 30 12:26:46.238104 2026] [security2:error] [pid 738779:tid 738933] [client 20.100.169.152:63005] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/X.php"] [unique_id "amuJVvxa4UbeLxj1SWXC6gAAAJ0"]
[Thu Jul 30 12:26:46.439595 2026] [core:notice] [pid 738779:tid 738910] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:46.442187 2026] [security2:error] [pid 738779:tid 739031] [client 20.52.54.143:9931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/inputs.php"] [unique_id "amuJVvxa4UbeLxj1SWXC7AAAAP8"]
[Thu Jul 30 12:26:46.511260 2026] [security2:error] [pid 738779:tid 739007] [client 142.93.53.183:62470] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/cache/cache/SASKRA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJVvxa4UbeLxj1SWXC8wAAAOc"]
[Thu Jul 30 12:26:46.537276 2026] [security2:error] [pid 738779:tid 738946] [client 20.100.169.152:48852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amuJVvxa4UbeLxj1SWXC9AAAAKo"]
[Thu Jul 30 12:26:46.537414 2026] [security2:error] [pid 738779:tid 738946] [client 20.100.169.152:48852] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amuJVvxa4UbeLxj1SWXC9AAAAKo"]
[Thu Jul 30 12:26:46.618763 2026] [security2:error] [pid 738779:tid 739036] [client 52.238.199.152:38869] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "womenclothingbox.com"] [uri "/1.php"] [unique_id "amuJVvxa4UbeLxj1SWXC9QAAAQQ"]
[Thu Jul 30 12:26:46.618896 2026] [security2:error] [pid 738779:tid 739036] [client 52.238.199.152:38869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/1.php"] [unique_id "amuJVvxa4UbeLxj1SWXC9QAAAQQ"]
[Thu Jul 30 12:26:46.840202 2026] [security2:error] [pid 738779:tid 738939] [client 20.100.169.152:63036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/gec.php"] [unique_id "amuJVvxa4UbeLxj1SWXC-gAAAKM"]
[Thu Jul 30 12:26:46.840320 2026] [security2:error] [pid 738779:tid 738939] [client 20.100.169.152:63036] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/gec.php"] [unique_id "amuJVvxa4UbeLxj1SWXC-gAAAKM"]
[Thu Jul 30 12:26:46.899074 2026] [security2:error] [pid 738779:tid 738989] [client 142.93.53.183:62472] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/cache/cache/SASKRA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJVvxa4UbeLxj1SWXC-wAAANU"]
[Thu Jul 30 12:26:46.905759 2026] [proxy:error] [pid 738779:tid 739019] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:46.905830 2026] [proxy_http:error] [pid 738779:tid 739019] [client 158.173.77.34:36469] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:46.906411 2026] [proxy:error] [pid 738779:tid 739019] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:46.906455 2026] [proxy_http:error] [pid 738779:tid 739019] [client 158.173.77.34:36469] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:46.906525 2026] [security2:error] [pid 738779:tid 739019] [client 158.173.77.34:36469] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.seven-stars-shop.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuJVvxa4UbeLxj1SWXC_AAAAPM"]
[Thu Jul 30 12:26:47.145292 2026] [security2:error] [pid 738779:tid 739018] [client 20.100.169.152:44153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/sky.php"] [unique_id "amuJV_xa4UbeLxj1SWXDBgAAAPI"]
[Thu Jul 30 12:26:47.145461 2026] [security2:error] [pid 738779:tid 739018] [client 20.100.169.152:44153] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/sky.php"] [unique_id "amuJV_xa4UbeLxj1SWXDBgAAAPI"]
[Thu Jul 30 12:26:47.281291 2026] [security2:error] [pid 738779:tid 738964] [client 142.93.53.183:62474] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/cache/cache/SASKRA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJV_xa4UbeLxj1SWXDBwAAALw"]
[Thu Jul 30 12:26:47.446479 2026] [security2:error] [pid 738779:tid 738924] [client 20.100.169.152:63003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/fffm.php"] [unique_id "amuJV_xa4UbeLxj1SWXDCwAAAJQ"]
[Thu Jul 30 12:26:47.446597 2026] [security2:error] [pid 738779:tid 738924] [client 20.100.169.152:63003] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/fffm.php"] [unique_id "amuJV_xa4UbeLxj1SWXDCwAAAJQ"]
[Thu Jul 30 12:26:47.667861 2026] [security2:error] [pid 738779:tid 738950] [client 142.93.53.183:62476] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/vendor/fonts/ALOK_DATA/alokcgiapi/perl.alfa"] [unique_id "amuJV_xa4UbeLxj1SWXDFAAAAK4"]
[Thu Jul 30 12:26:47.747766 2026] [security2:error] [pid 738779:tid 738973] [client 38.190.144.4:50981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJV_xa4UbeLxj1SWXDFQAAAMU"]
[Thu Jul 30 12:26:47.747921 2026] [security2:error] [pid 738779:tid 738973] [client 38.190.144.4:50981] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJV_xa4UbeLxj1SWXDFQAAAMU"]
[Thu Jul 30 12:26:47.755965 2026] [security2:error] [pid 738779:tid 738976] [client 20.100.169.152:63011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/sixxis.php"] [unique_id "amuJV_xa4UbeLxj1SWXDFgAAAMg"]
[Thu Jul 30 12:26:47.756069 2026] [security2:error] [pid 738779:tid 738976] [client 20.100.169.152:63011] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/sixxis.php"] [unique_id "amuJV_xa4UbeLxj1SWXDFgAAAMg"]
[Thu Jul 30 12:26:47.761953 2026] [security2:error] [pid 738779:tid 738909] [client 52.238.199.152:18209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/lv.php"] [unique_id "amuJV_xa4UbeLxj1SWXDFwAAAIU"]
[Thu Jul 30 12:26:47.984369 2026] [core:error] [pid 738779:tid 738927] [client 13.222.80.67:46772] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:26:47.984396 2026] [core:error] [pid 738779:tid 738927] [client 13.222.80.67:46772] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:26:48.046800 2026] [security2:error] [pid 738779:tid 739006] [client 142.93.53.183:62480] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/vendor/fonts/ALOK_DATA/alokcgiapi/bash.alfa"] [unique_id "amuJWPxa4UbeLxj1SWXDHAAAAOY"]
[Thu Jul 30 12:26:48.082255 2026] [security2:error] [pid 738779:tid 738922] [client 20.100.169.152:63018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/yj09.php"] [unique_id "amuJWPxa4UbeLxj1SWXDHgAAAJI"]
[Thu Jul 30 12:26:48.082348 2026] [security2:error] [pid 738779:tid 738922] [client 20.100.169.152:63018] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/yj09.php"] [unique_id "amuJWPxa4UbeLxj1SWXDHgAAAJI"]
[Thu Jul 30 12:26:48.382834 2026] [security2:error] [pid 738779:tid 738984] [client 20.100.169.152:44112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/k.php"] [unique_id "amuJWPxa4UbeLxj1SWXDIgAAANA"]
[Thu Jul 30 12:26:48.382955 2026] [security2:error] [pid 738779:tid 738984] [client 20.100.169.152:44112] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/k.php"] [unique_id "amuJWPxa4UbeLxj1SWXDIgAAANA"]
[Thu Jul 30 12:26:48.433512 2026] [security2:error] [pid 738779:tid 739028] [client 142.93.53.183:62483] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/vendor/fonts/ALOK_DATA/alokcgiapi/py.alfa"] [unique_id "amuJWPxa4UbeLxj1SWXDIwAAAPw"]
[Thu Jul 30 12:26:48.509863 2026] [security2:error] [pid 738779:tid 738929] [client 144.172.94.198:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "buyfluoxetine.store"] [uri "/.env"] [unique_id "amuJWPxa4UbeLxj1SWXDJAAAAJk"]
[Thu Jul 30 12:26:48.684824 2026] [security2:error] [pid 738779:tid 738938] [client 20.100.169.152:62979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/k2.php"] [unique_id "amuJWPxa4UbeLxj1SWXDLgAAAKI"]
[Thu Jul 30 12:26:48.684907 2026] [security2:error] [pid 738779:tid 738938] [client 20.100.169.152:62979] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/k2.php"] [unique_id "amuJWPxa4UbeLxj1SWXDLgAAAKI"]
[Thu Jul 30 12:26:48.823627 2026] [security2:error] [pid 738779:tid 739017] [client 142.93.53.183:62488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-admin/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJWPxa4UbeLxj1SWXDMAAAAPE"]
[Thu Jul 30 12:26:48.839631 2026] [security2:error] [pid 738779:tid 738998] [client 52.238.199.152:62677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/css.php"] [unique_id "amuJWPxa4UbeLxj1SWXDMQAAAN4"]
[Thu Jul 30 12:26:48.908023 2026] [core:notice] [pid 738779:tid 738879] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:49.007363 2026] [security2:error] [pid 738779:tid 738944] [client 20.100.169.152:62983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/w.php"] [unique_id "amuJWfxa4UbeLxj1SWXDMwAAAKg"]
[Thu Jul 30 12:26:49.007480 2026] [security2:error] [pid 738779:tid 738944] [client 20.100.169.152:62983] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/w.php"] [unique_id "amuJWfxa4UbeLxj1SWXDMwAAAKg"]
[Thu Jul 30 12:26:49.176887 2026] [core:notice] [pid 738779:tid 738880] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:49.214462 2026] [security2:error] [pid 738779:tid 739019] [client 142.93.53.183:62493] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-admin/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJWfxa4UbeLxj1SWXDPAAAAPM"]
[Thu Jul 30 12:26:49.321852 2026] [security2:error] [pid 738779:tid 738928] [client 20.100.169.152:44105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/fpwch.php"] [unique_id "amuJWfxa4UbeLxj1SWXDPQAAAJg"]
[Thu Jul 30 12:26:49.321997 2026] [security2:error] [pid 738779:tid 738928] [client 20.100.169.152:44105] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/fpwch.php"] [unique_id "amuJWfxa4UbeLxj1SWXDPQAAAJg"]
[Thu Jul 30 12:26:49.593658 2026] [security2:error] [pid 738779:tid 738960] [client 142.93.53.183:62499] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/block-patterns/jancox/alfacgiapi/perl.alfa"] [unique_id "amuJWfxa4UbeLxj1SWXDRAAAALg"]
[Thu Jul 30 12:26:49.621429 2026] [security2:error] [pid 738779:tid 739033] [client 20.100.169.152:63017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/w2025.php"] [unique_id "amuJWfxa4UbeLxj1SWXDRQAAAQE"]
[Thu Jul 30 12:26:49.621530 2026] [security2:error] [pid 738779:tid 739033] [client 20.100.169.152:63017] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/w2025.php"] [unique_id "amuJWfxa4UbeLxj1SWXDRQAAAQE"]
[Thu Jul 30 12:26:49.697859 2026] [security2:error] [pid 738779:tid 739015] [client 2a03:2880:f800:41:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJWfxa4UbeLxj1SWXDNAAA71g"]
[Thu Jul 30 12:26:49.921531 2026] [security2:error] [pid 738779:tid 739035] [client 20.100.169.152:44159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/FWAZ.php"] [unique_id "amuJWfxa4UbeLxj1SWXDSQAAAQM"]
[Thu Jul 30 12:26:49.921645 2026] [security2:error] [pid 738779:tid 739035] [client 20.100.169.152:44159] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/FWAZ.php"] [unique_id "amuJWfxa4UbeLxj1SWXDSQAAAQM"]
[Thu Jul 30 12:26:49.980531 2026] [security2:error] [pid 738779:tid 739022] [client 142.93.53.183:62503] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/block-patterns/jancox/alfacgiapi/py.alfa"] [unique_id "amuJWfxa4UbeLxj1SWXDSgAAAPY"]
[Thu Jul 30 12:26:50.220970 2026] [security2:error] [pid 738779:tid 739000] [client 20.100.169.152:63028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/qterm.php"] [unique_id "amuJWvxa4UbeLxj1SWXDVAAAAOA"]
[Thu Jul 30 12:26:50.221078 2026] [security2:error] [pid 738779:tid 739000] [client 20.100.169.152:63028] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/qterm.php"] [unique_id "amuJWvxa4UbeLxj1SWXDVAAAAOA"]
[Thu Jul 30 12:26:50.292452 2026] [security2:error] [pid 738779:tid 738951] [client 52.238.199.152:38882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/gecko.php"] [unique_id "amuJWvxa4UbeLxj1SWXDVQAAAK8"]
[Thu Jul 30 12:26:50.305755 2026] [security2:error] [pid 738779:tid 739014] [client 144.172.94.198:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "buyfluoxetine.store"] [uri "/.env.backup"] [unique_id "amuJWvxa4UbeLxj1SWXDVgAAAO4"]
[Thu Jul 30 12:26:50.370719 2026] [security2:error] [pid 738779:tid 739012] [client 142.93.53.183:62506] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/block-patterns/jancox/alfacgiapi/bash.alfa"] [unique_id "amuJWvxa4UbeLxj1SWXDWAAAAOw"]
[Thu Jul 30 12:26:50.373062 2026] [security2:error] [pid 738779:tid 738972] [client 139.28.219.70:50620] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "supreme-hydraulics.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuJWvxa4UbeLxj1SWXDWQAAAMQ"]
[Thu Jul 30 12:26:50.533122 2026] [security2:error] [pid 738779:tid 738996] [client 20.100.169.152:61558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/blurbs.php"] [unique_id "amuJWvxa4UbeLxj1SWXDWgAAANw"]
[Thu Jul 30 12:26:50.533230 2026] [security2:error] [pid 738779:tid 738996] [client 20.100.169.152:61558] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/blurbs.php"] [unique_id "amuJWvxa4UbeLxj1SWXDWgAAANw"]
[Thu Jul 30 12:26:50.699415 2026] [security2:error] [pid 738779:tid 738950] [client 57.141.0.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJWvxa4UbeLxj1SWXDTgAAAK4"]
[Thu Jul 30 12:26:50.761477 2026] [security2:error] [pid 738779:tid 738942] [client 142.93.53.183:62509] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/themes/twentytwentyfive/assets/css/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJWvxa4UbeLxj1SWXDYwAAAKY"]
[Thu Jul 30 12:26:50.911953 2026] [security2:error] [pid 738779:tid 738936] [client 158.158.76.106:13384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/plugins.php"] [unique_id "amuJWvxa4UbeLxj1SWXDZgAAAKA"]
[Thu Jul 30 12:26:50.912072 2026] [security2:error] [pid 738779:tid 738936] [client 158.158.76.106:13384] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "shorewooddaycare.com"] [uri "/plugins.php"] [unique_id "amuJWvxa4UbeLxj1SWXDZgAAAKA"]
[Thu Jul 30 12:26:50.978756 2026] [security2:error] [pid 738779:tid 738949] [client 20.100.169.152:62977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/wp-ws68.php"] [unique_id "amuJWvxa4UbeLxj1SWXDZwAAAK0"]
[Thu Jul 30 12:26:50.978864 2026] [security2:error] [pid 738779:tid 738949] [client 20.100.169.152:62977] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/wp-ws68.php"] [unique_id "amuJWvxa4UbeLxj1SWXDZwAAAK0"]
[Thu Jul 30 12:26:51.081257 2026] [security2:error] [pid 738779:tid 738940] [client 20.52.54.143:10232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/index.php"] [unique_id "amuJW_xa4UbeLxj1SWXDaAAAAKQ"]
[Thu Jul 30 12:26:51.151967 2026] [security2:error] [pid 738779:tid 739007] [client 142.93.53.183:62514] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/themes/twentytwentyfive/assets/css/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJW_xa4UbeLxj1SWXDagAAAOc"]
[Thu Jul 30 12:26:51.441117 2026] [security2:error] [pid 738779:tid 738930] [client 20.100.169.152:63031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/xyn.php"] [unique_id "amuJW_xa4UbeLxj1SWXDdAAAAJo"]
[Thu Jul 30 12:26:51.441225 2026] [security2:error] [pid 738779:tid 738930] [client 20.100.169.152:63031] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/xyn.php"] [unique_id "amuJW_xa4UbeLxj1SWXDdAAAAJo"]
[Thu Jul 30 12:26:51.541437 2026] [security2:error] [pid 738779:tid 739033] [client 142.93.53.183:62517] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/themes/twentytwentyfive/assets/css/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJW_xa4UbeLxj1SWXDdQAAAQE"]
[Thu Jul 30 12:26:51.758688 2026] [security2:error] [pid 738779:tid 738911] [client 20.52.54.143:9941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/network/index.php"] [unique_id "amuJW_xa4UbeLxj1SWXDgAAAAIc"]
[Thu Jul 30 12:26:51.809083 2026] [security2:error] [pid 738779:tid 738973] [client 20.100.169.152:63023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/ccc.php"] [unique_id "amuJW_xa4UbeLxj1SWXDgQAAAMU"]
[Thu Jul 30 12:26:51.809187 2026] [security2:error] [pid 738779:tid 738973] [client 20.100.169.152:63023] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/ccc.php"] [unique_id "amuJW_xa4UbeLxj1SWXDgQAAAMU"]
[Thu Jul 30 12:26:51.933367 2026] [security2:error] [pid 738779:tid 738970] [client 142.93.53.183:62521] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2016/09/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJW_xa4UbeLxj1SWXDgwAAAMI"]
[Thu Jul 30 12:26:52.297989 2026] [security2:error] [pid 738779:tid 738995] [client 139.28.219.70:54240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "supreme-hydraulics.com"] [uri "/xmlrpc.php"] [unique_id "amuJXPxa4UbeLxj1SWXDkAAAANs"]
[Thu Jul 30 12:26:52.298087 2026] [security2:error] [pid 738779:tid 738995] [client 139.28.219.70:54240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "supreme-hydraulics.com"] [uri "/xmlrpc.php"] [unique_id "amuJXPxa4UbeLxj1SWXDkAAAANs"]
[Thu Jul 30 12:26:52.324070 2026] [security2:error] [pid 738779:tid 739025] [client 142.93.53.183:62524] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2016/09/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJXPxa4UbeLxj1SWXDkQAAAPk"]
[Thu Jul 30 12:26:52.408240 2026] [security2:error] [pid 738779:tid 738936] [client 20.100.169.152:62999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/get.php"] [unique_id "amuJXPxa4UbeLxj1SWXDkgAAAKA"]
[Thu Jul 30 12:26:52.408353 2026] [security2:error] [pid 738779:tid 738936] [client 20.100.169.152:62999] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/get.php"] [unique_id "amuJXPxa4UbeLxj1SWXDkgAAAKA"]
[Thu Jul 30 12:26:52.521810 2026] [security2:error] [pid 738779:tid 738938] [client 37.120.155.179:51614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.155.120.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuJXPxa4UbeLxj1SWXDlAAAAKI"]
[Thu Jul 30 12:26:52.521887 2026] [security2:error] [pid 738779:tid 738938] [client 37.120.155.179:51614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuJXPxa4UbeLxj1SWXDlAAAAKI"]
[Thu Jul 30 12:26:52.568949 2026] [security2:error] [pid 738779:tid 738950] [client 20.52.54.143:10221] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/1.php"] [unique_id "amuJXPxa4UbeLxj1SWXDlgAAAK4"]
[Thu Jul 30 12:26:52.569095 2026] [security2:error] [pid 738779:tid 738950] [client 20.52.54.143:10221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/1.php"] [unique_id "amuJXPxa4UbeLxj1SWXDlgAAAK4"]
[Thu Jul 30 12:26:52.711264 2026] [security2:error] [pid 738779:tid 739009] [client 142.93.53.183:62529] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2016/09/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJXPxa4UbeLxj1SWXDmgAAAOk"]
[Thu Jul 30 12:26:52.770878 2026] [security2:error] [pid 738779:tid 738965] [client 52.238.199.152:64288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/xmlrpc.php"] [unique_id "amuJXPxa4UbeLxj1SWXDnQAAAL0"]
[Thu Jul 30 12:26:52.986859 2026] [security2:error] [pid 738779:tid 738918] [client 20.100.169.152:63027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/images.php"] [unique_id "amuJXPxa4UbeLxj1SWXDoAAAAI4"]
[Thu Jul 30 12:26:52.987022 2026] [security2:error] [pid 738779:tid 738918] [client 20.100.169.152:63027] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/images.php"] [unique_id "amuJXPxa4UbeLxj1SWXDoAAAAI4"]
[Thu Jul 30 12:26:52.988206 2026] [security2:error] [pid 738779:tid 738964] [client 162.141.167.36:53026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.nxt.udi.temporary.site"] [uri "/index.php"] [unique_id "amuJXPxa4UbeLxj1SWXDnwAAALw"]
[Thu Jul 30 12:26:53.105240 2026] [security2:error] [pid 738779:tid 739029] [client 142.93.53.183:62533] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2018/11/1337_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJXfxa4UbeLxj1SWXDoQAAAP0"]
[Thu Jul 30 12:26:53.422535 2026] [security2:error] [pid 738779:tid 739005] [client 20.100.169.152:44108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/alls.php"] [unique_id "amuJXfxa4UbeLxj1SWXDqgAAAOU"]
[Thu Jul 30 12:26:53.422687 2026] [security2:error] [pid 738779:tid 739005] [client 20.100.169.152:44108] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/alls.php"] [unique_id "amuJXfxa4UbeLxj1SWXDqgAAAOU"]
[Thu Jul 30 12:26:53.493218 2026] [security2:error] [pid 738779:tid 738963] [client 142.93.53.183:62536] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2018/11/1337_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJXfxa4UbeLxj1SWXDqwAAALs"]
[Thu Jul 30 12:26:53.808281 2026] [security2:error] [pid 738779:tid 739036] [client 185.191.171.2:57984] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2021/08/11/saque-do-auxilio-emergencial-e-liberado-para-nascidos-em-julho/"] [unique_id "amuJXfxa4UbeLxj1SWXDrwAAAQQ"]
[Thu Jul 30 12:26:53.808429 2026] [security2:error] [pid 738779:tid 739036] [client 185.191.171.2:57984] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2021/08/11/saque-do-auxilio-emergencial-e-liberado-para-nascidos-em-julho/"] [unique_id "amuJXfxa4UbeLxj1SWXDrwAAAQQ"]
[Thu Jul 30 12:26:53.886578 2026] [security2:error] [pid 738779:tid 738954] [client 142.93.53.183:62543] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2018/11/1337_DATA/alfacgiapi/py.alfa"] [unique_id "amuJXfxa4UbeLxj1SWXDtAAAALI"]
[Thu Jul 30 12:26:54.007067 2026] [security2:error] [pid 738779:tid 739034] [client 20.100.169.152:63020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/coffexium.php"] [unique_id "amuJXvxa4UbeLxj1SWXDtQAAAQI"]
[Thu Jul 30 12:26:54.007209 2026] [security2:error] [pid 738779:tid 739034] [client 20.100.169.152:63020] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/coffexium.php"] [unique_id "amuJXvxa4UbeLxj1SWXDtQAAAQI"]
[Thu Jul 30 12:26:54.074069 2026] [security2:error] [pid 738779:tid 738939] [client 20.52.54.143:9948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/plugin.php"] [unique_id "amuJXvxa4UbeLxj1SWXDtgAAAKM"]
[Thu Jul 30 12:26:54.276854 2026] [security2:error] [pid 738779:tid 738920] [client 142.93.53.183:62549] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/wp-file-manager/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJXvxa4UbeLxj1SWXDugAAAJA"]
[Thu Jul 30 12:26:54.324045 2026] [security2:error] [pid 738779:tid 738937] [client 20.100.169.152:63024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/red.php"] [unique_id "amuJXvxa4UbeLxj1SWXDuwAAAKE"]
[Thu Jul 30 12:26:54.324138 2026] [security2:error] [pid 738779:tid 738937] [client 20.100.169.152:63024] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/red.php"] [unique_id "amuJXvxa4UbeLxj1SWXDuwAAAKE"]
[Thu Jul 30 12:26:54.668959 2026] [security2:error] [pid 738779:tid 738970] [client 142.93.53.183:62554] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/wp-file-manager/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJXvxa4UbeLxj1SWXDvwAAAMI"]
[Thu Jul 30 12:26:54.873581 2026] [security2:error] [pid 738779:tid 738952] [client 144.172.94.198:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "buyfluoxetine.store"] [uri "/.env.bak"] [unique_id "amuJXvxa4UbeLxj1SWXDxwAAALA"]
[Thu Jul 30 12:26:54.879532 2026] [security2:error] [pid 738779:tid 738959] [client 20.100.169.152:44119] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/___proxy_subdomain_webmail/wp-includes/sodium_compat/"] [unique_id "amuJXvxa4UbeLxj1SWXDwwAAALc"]
[Thu Jul 30 12:26:54.955215 2026] [security2:error] [pid 738779:tid 738905] [remote 103.57.220.209:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.57.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "laduchessecollections.com"] [uri "/wp-login.php"] [unique_id "amuJXvxa4UbeLxj1SWXDyQAArH0"]
[Thu Jul 30 12:26:55.058361 2026] [security2:error] [pid 738779:tid 738983] [client 142.93.53.183:62558] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/wp-file-manager/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJX_xa4UbeLxj1SWXDygAAAM8"]
[Thu Jul 30 12:26:55.288124 2026] [security2:error] [pid 738779:tid 738984] [client 20.100.169.152:44119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amuJX_xa4UbeLxj1SWXDywAAANA"]
[Thu Jul 30 12:26:55.288247 2026] [security2:error] [pid 738779:tid 738984] [client 20.100.169.152:44119] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amuJX_xa4UbeLxj1SWXDywAAANA"]
[Thu Jul 30 12:26:55.447367 2026] [security2:error] [pid 738779:tid 738988] [client 142.93.53.183:62560] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/media/uploads/Events/2022/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJX_xa4UbeLxj1SWXD0gAAANQ"]
[Thu Jul 30 12:26:55.718782 2026] [security2:error] [pid 738779:tid 738953] [client 20.52.54.143:9946] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.lilyinspires.com"] [uri "/1.php"] [unique_id "amuJX_xa4UbeLxj1SWXD1AAAALE"]
[Thu Jul 30 12:26:55.718924 2026] [security2:error] [pid 738779:tid 738953] [client 20.52.54.143:9946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/1.php"] [unique_id "amuJX_xa4UbeLxj1SWXD1AAAALE"]
[Thu Jul 30 12:26:55.826811 2026] [security2:error] [pid 738779:tid 738913] [client 142.93.53.183:62563] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/media/uploads/Events/2022/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJX_xa4UbeLxj1SWXD1QAAAIk"]
[Thu Jul 30 12:26:55.965381 2026] [security2:error] [pid 738779:tid 738991] [client 20.100.169.152:44111] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/___proxy_subdomain_webmail/wp-includes/Text/"] [unique_id "amuJX_xa4UbeLxj1SWXD2QAAANc"]
[Thu Jul 30 12:26:56.003136 2026] [security2:error] [pid 738779:tid 738786] [remote 5.39.1.234:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "portugalvisaapplicationcenterinislamabad.site"] [uri "/"] [unique_id "amuJYPxa4UbeLxj1SWXD3QAAugY"]
[Thu Jul 30 12:26:56.003303 2026] [security2:error] [pid 738779:tid 738962] [client 5.39.1.234:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "portugalvisaapplicationcenterinislamabad.site"] [uri "/"] [unique_id "amuJYPxa4UbeLxj1SWXD3QAAugY"]
[Thu Jul 30 12:26:56.208784 2026] [security2:error] [pid 738779:tid 739003] [client 142.93.53.183:62565] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/media/uploads/Events/2022/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJYPxa4UbeLxj1SWXD3gAAAOM"]
[Thu Jul 30 12:26:56.479647 2026] [security2:error] [pid 738779:tid 738994] [client 20.100.169.152:44111] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/___proxy_subdomain_webmail/wp-content/uploads/"] [unique_id "amuJYPxa4UbeLxj1SWXD5QAAANo"]
[Thu Jul 30 12:26:56.589799 2026] [security2:error] [pid 738779:tid 738947] [client 142.93.53.183:62569] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/modules/imce/src/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJYPxa4UbeLxj1SWXD6QAAAKs"]
[Thu Jul 30 12:26:56.629102 2026] [security2:error] [pid 738779:tid 738963] [client 20.100.169.152:44111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/wp-content/index.php"] [unique_id "amuJYPxa4UbeLxj1SWXD6gAAALs"]
[Thu Jul 30 12:26:56.629246 2026] [security2:error] [pid 738779:tid 738963] [client 20.100.169.152:44111] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/wp-content/index.php"] [unique_id "amuJYPxa4UbeLxj1SWXD6gAAALs"]
[Thu Jul 30 12:26:56.980023 2026] [security2:error] [pid 738779:tid 738926] [client 142.93.53.183:62570] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/modules/imce/src/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJYPxa4UbeLxj1SWXD7gAAAJY"]
[Thu Jul 30 12:26:57.306287 2026] [security2:error] [pid 738779:tid 739035] [client 20.100.169.152:63039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/admin.php"] [unique_id "amuJYfxa4UbeLxj1SWXD8gAAAQM"]
[Thu Jul 30 12:26:57.306410 2026] [security2:error] [pid 738779:tid 739035] [client 20.100.169.152:63039] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/admin.php"] [unique_id "amuJYfxa4UbeLxj1SWXD8gAAAQM"]
[Thu Jul 30 12:26:57.330437 2026] [security2:error] [pid 738779:tid 738997] [client 3.86.177.101:50762] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "mediaspawn.com"] [uri "/"] [unique_id "amuJYfxa4UbeLxj1SWXD8wAAAN0"]
[Thu Jul 30 12:26:57.353280 2026] [security2:error] [pid 738779:tid 738920] [client 142.93.53.183:62574] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/modules/imce/src/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJYfxa4UbeLxj1SWXD9AAAAJA"]
[Thu Jul 30 12:26:57.413818 2026] [security2:error] [pid 738779:tid 738919] [client 52.238.199.152:38833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/f35.php"] [unique_id "amuJYfxa4UbeLxj1SWXD9QAAAI8"]
[Thu Jul 30 12:26:57.744085 2026] [security2:error] [pid 738779:tid 738976] [client 142.93.53.183:62577] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/modules/ctools/modules/ctools_entity_mask/tests/modules/entity_mask_test/config/install/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJYfxa4UbeLxj1SWXD_QAAAMg"]
[Thu Jul 30 12:26:58.124278 2026] [security2:error] [pid 738779:tid 738949] [client 142.93.53.183:62579] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/modules/ctools/modules/ctools_entity_mask/tests/modules/entity_mask_test/config/install/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJYvxa4UbeLxj1SWXECgAAAK0"]
[Thu Jul 30 12:26:58.359060 2026] [security2:error] [pid 738779:tid 738967] [client 20.100.169.152:62982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/177.php"] [unique_id "amuJYvxa4UbeLxj1SWXEDAAAAL8"]
[Thu Jul 30 12:26:58.359174 2026] [security2:error] [pid 738779:tid 738967] [client 20.100.169.152:62982] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/177.php"] [unique_id "amuJYvxa4UbeLxj1SWXEDAAAAL8"]
[Thu Jul 30 12:26:58.372717 2026] [security2:error] [pid 738779:tid 738988] [client 52.238.199.152:38856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/autoload_classmap.php"] [unique_id "amuJYvxa4UbeLxj1SWXEDQAAANQ"]
[Thu Jul 30 12:26:58.508889 2026] [security2:error] [pid 738779:tid 738940] [client 142.93.53.183:62581] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/modules/ctools/modules/ctools_entity_mask/tests/modules/entity_mask_test/config/install/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJYvxa4UbeLxj1SWXEEQAAAKQ"]
[Thu Jul 30 12:26:58.510200 2026] [security2:error] [pid 738779:tid 738996] [client 38.190.144.4:51479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJYvxa4UbeLxj1SWXEEgAAANw"]
[Thu Jul 30 12:26:58.510346 2026] [security2:error] [pid 738779:tid 738996] [client 38.190.144.4:51479] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJYvxa4UbeLxj1SWXEEgAAANw"]
[Thu Jul 30 12:26:58.552678 2026] [security2:error] [pid 738779:tid 739028] [client 57.141.0.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJYfxa4UbeLxj1SWXEAwAAAPw"]
[Thu Jul 30 12:26:58.621409 2026] [security2:error] [pid 738779:tid 738975] [client 127.0.0.1:56934] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuJYvxa4UbeLxj1SWXEFwAAAMc"]
[Thu Jul 30 12:26:58.621467 2026] [security2:error] [pid 738779:tid 739031] [client 74.7.175.157:40260] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.greensparkle.net"] [uri "/robots.txt"] [unique_id "amuJYvxa4UbeLxj1SWXEFgAA_xc"]
[Thu Jul 30 12:26:58.642460 2026] [security2:error] [pid 738779:tid 739017] [client 158.158.76.106:54007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/style.php"] [unique_id "amuJYvxa4UbeLxj1SWXEGAAAAPE"]
[Thu Jul 30 12:26:58.642545 2026] [security2:error] [pid 738779:tid 739017] [client 158.158.76.106:54007] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "shorewooddaycare.com"] [uri "/style.php"] [unique_id "amuJYvxa4UbeLxj1SWXEGAAAAPE"]
[Thu Jul 30 12:26:58.778217 2026] [security2:error] [pid 738779:tid 738953] [client 20.52.54.143:9967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/gg.php"] [unique_id "amuJYvxa4UbeLxj1SWXEGgAAALE"]
[Thu Jul 30 12:26:58.882667 2026] [security2:error] [pid 738779:tid 738982] [client 142.93.53.183:62582] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/themes/xve/templates/content/news/LEVIATHAN/cgihaxor/perl.haxor"] [unique_id "amuJYvxa4UbeLxj1SWXEHgAAAM4"]
[Thu Jul 30 12:26:59.026759 2026] [security2:error] [pid 738779:tid 738917] [client 47.128.122.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuJYvxa4UbeLxj1SWXEHQAAAI0"]
[Thu Jul 30 12:26:59.276766 2026] [security2:error] [pid 738779:tid 739018] [client 142.93.53.183:62588] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/themes/xve/templates/content/news/LEVIATHAN/cgihaxor/py.haxor"] [unique_id "amuJY_xa4UbeLxj1SWXEOwAAAPI"]
[Thu Jul 30 12:26:59.406444 2026] [proxy:error] [pid 738779:tid 739004] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:59.406516 2026] [proxy_http:error] [pid 738779:tid 739004] [client 20.52.54.143:9976] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:59.407070 2026] [proxy:error] [pid 738779:tid 739004] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:59.407116 2026] [proxy_http:error] [pid 738779:tid 739004] [client 20.52.54.143:9976] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:59.632882 2026] [security2:error] [pid 738779:tid 739013] [client 52.238.199.152:48514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/NewFile.php"] [unique_id "amuJY_xa4UbeLxj1SWXESAAAAO0"]
[Thu Jul 30 12:26:59.667957 2026] [security2:error] [pid 738779:tid 738911] [client 142.93.53.183:62592] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/themes/xve/templates/content/news/LEVIATHAN/cgihaxor/bash.haxor"] [unique_id "amuJY_xa4UbeLxj1SWXESQAAAIc"]
[Thu Jul 30 12:27:00.049944 2026] [security2:error] [pid 738779:tid 739015] [client 142.93.53.183:62596] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/templates/blogus/bootstrap/css/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJZPxa4UbeLxj1SWXEUAAAAO8"]
[Thu Jul 30 12:27:00.301300 2026] [security2:error] [pid 738779:tid 738915] [client 20.52.54.143:10194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp.php"] [unique_id "amuJZPxa4UbeLxj1SWXEUQAAAIs"]
[Thu Jul 30 12:27:00.433124 2026] [security2:error] [pid 738779:tid 738951] [client 142.93.53.183:62600] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/templates/blogus/bootstrap/css/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJZPxa4UbeLxj1SWXEVQAAAK8"]
[Thu Jul 30 12:27:00.733556 2026] [security2:error] [pid 738779:tid 739032] [client 52.238.199.152:38878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/xx.php"] [unique_id "amuJZPxa4UbeLxj1SWXEWQAAAQA"]
[Thu Jul 30 12:27:00.823911 2026] [security2:error] [pid 738779:tid 739025] [client 142.93.53.183:62603] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/templates/blogus/bootstrap/css/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJZPxa4UbeLxj1SWXEWgAAAPk"]
[Thu Jul 30 12:27:00.900450 2026] [security2:error] [pid 738779:tid 738980] [client 20.100.169.152:44146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/199.php"] [unique_id "amuJZPxa4UbeLxj1SWXEXgAAAMw"]
[Thu Jul 30 12:27:00.900532 2026] [security2:error] [pid 738779:tid 738980] [client 20.100.169.152:44146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/199.php"] [unique_id "amuJZPxa4UbeLxj1SWXEXgAAAMw"]
[Thu Jul 30 12:27:01.099158 2026] [security2:error] [pid 738779:tid 738991] [client 158.158.76.106:44926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/plugins.php"] [unique_id "amuJZfxa4UbeLxj1SWXEYgAAANc"]
[Thu Jul 30 12:27:01.099268 2026] [security2:error] [pid 738779:tid 738991] [client 158.158.76.106:44926] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "shorewooddaycare.com"] [uri "/plugins.php"] [unique_id "amuJZfxa4UbeLxj1SWXEYgAAANc"]
[Thu Jul 30 12:27:01.172234 2026] [core:notice] [pid 738779:tid 738940] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:01.200238 2026] [security2:error] [pid 738779:tid 739008] [client 142.93.53.183:62608] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-admin/user/xxxTYPOxxx/typocgiapi/perl.typo"] [unique_id "amuJZfxa4UbeLxj1SWXEZAAAAOg"]
[Thu Jul 30 12:27:01.308624 2026] [security2:error] [pid 738779:tid 738913] [client 20.52.54.143:10193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuJZfxa4UbeLxj1SWXEZQAAAIk"]
[Thu Jul 30 12:27:01.577479 2026] [security2:error] [pid 738779:tid 739030] [client 142.93.53.183:62611] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-admin/user/xxxTYPOxxx/typocgiapi/bash.typo"] [unique_id "amuJZfxa4UbeLxj1SWXEbQAAAP4"]
[Thu Jul 30 12:27:01.729296 2026] [security2:error] [pid 738779:tid 738987] [client 20.100.169.152:44101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/file52.php"] [unique_id "amuJZfxa4UbeLxj1SWXEbwAAANM"]
[Thu Jul 30 12:27:01.729441 2026] [security2:error] [pid 738779:tid 738987] [client 20.100.169.152:44101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/file52.php"] [unique_id "amuJZfxa4UbeLxj1SWXEbwAAANM"]
[Thu Jul 30 12:27:01.966352 2026] [security2:error] [pid 738779:tid 738917] [client 142.93.53.183:62617] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-admin/user/xxxTYPOxxx/typocgiapi/py.typo"] [unique_id "amuJZfxa4UbeLxj1SWXEdAAAAI0"]
[Thu Jul 30 12:27:02.285004 2026] [security2:error] [pid 738779:tid 739006] [client 144.172.94.198:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "buyfluoxetine.store"] [uri "/.env.old"] [unique_id "amuJZvxa4UbeLxj1SWXEewAAAOY"]
[Thu Jul 30 12:27:02.322760 2026] [security2:error] [pid 738779:tid 738855] [remote 52.54.95.127:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "flixon.net"] [uri "/"] [unique_id "amuJZvxa4UbeLxj1SWXEfAAA9Es"]
[Thu Jul 30 12:27:02.337673 2026] [security2:error] [pid 738779:tid 739033] [client 20.100.169.152:44143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/geck.php"] [unique_id "amuJZvxa4UbeLxj1SWXEfQAAAQE"]
[Thu Jul 30 12:27:02.337765 2026] [security2:error] [pid 738779:tid 739033] [client 20.100.169.152:44143] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/geck.php"] [unique_id "amuJZvxa4UbeLxj1SWXEfQAAAQE"]
[Thu Jul 30 12:27:02.355083 2026] [security2:error] [pid 738779:tid 738971] [client 142.93.53.183:62620] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/vendor/phpunit/phpunit/build/bin/7Syndicate/oxnixcgiapi/perl.oxnix"] [unique_id "amuJZvxa4UbeLxj1SWXEfgAAAMM"]
[Thu Jul 30 12:27:02.412159 2026] [security2:error] [pid 738779:tid 738914] [client 20.52.54.143:9360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/file.php"] [unique_id "amuJZvxa4UbeLxj1SWXEggAAAIo"]
[Thu Jul 30 12:27:02.742971 2026] [security2:error] [pid 738779:tid 738924] [client 142.93.53.183:62624] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/vendor/phpunit/phpunit/build/bin/7Syndicate/oxnixcgiapi/bash.oxnix"] [unique_id "amuJZvxa4UbeLxj1SWXEigAAAJQ"]
[Thu Jul 30 12:27:02.748106 2026] [security2:error] [pid 738779:tid 738979] [client 20.100.169.152:63001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/biufile.php"] [unique_id "amuJZvxa4UbeLxj1SWXEiwAAAMs"]
[Thu Jul 30 12:27:02.748216 2026] [security2:error] [pid 738779:tid 738979] [client 20.100.169.152:63001] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/biufile.php"] [unique_id "amuJZvxa4UbeLxj1SWXEiwAAAMs"]
[Thu Jul 30 12:27:02.823707 2026] [security2:error] [pid 738779:tid 739035] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuJZvxa4UbeLxj1SWXEiAAAAQM"]
[Thu Jul 30 12:27:02.823845 2026] [security2:error] [pid 738779:tid 739035] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuJZvxa4UbeLxj1SWXEiAAAAQM"]
[Thu Jul 30 12:27:03.026603 2026] [security2:error] [pid 738779:tid 738845] [remote 40.77.167.51:56206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/JPA"] [unique_id "amuJZ_xa4UbeLxj1SWXEjwAA6kE"]
[Thu Jul 30 12:27:03.079661 2026] [security2:error] [pid 738779:tid 739014] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuJZ_xa4UbeLxj1SWXElQAAAO4"]
[Thu Jul 30 12:27:03.079762 2026] [security2:error] [pid 738779:tid 739014] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuJZ_xa4UbeLxj1SWXElQAAAO4"]
[Thu Jul 30 12:27:03.136376 2026] [security2:error] [pid 738779:tid 738952] [client 142.93.53.183:62626] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/vendor/phpunit/phpunit/build/bin/7Syndicate/oxnixcgiapi/py.oxnix"] [unique_id "amuJZ_xa4UbeLxj1SWXElgAAALA"]
[Thu Jul 30 12:27:03.178703 2026] [security2:error] [pid 738779:tid 738941] [client 20.100.169.152:44150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/dejavu.php"] [unique_id "amuJZ_xa4UbeLxj1SWXEmAAAAKU"]
[Thu Jul 30 12:27:03.178792 2026] [security2:error] [pid 738779:tid 738941] [client 20.100.169.152:44150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/dejavu.php"] [unique_id "amuJZ_xa4UbeLxj1SWXEmAAAAKU"]
[Thu Jul 30 12:27:03.328166 2026] [security2:error] [pid 738779:tid 739022] [client 43.173.174.201:53528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.174.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/03/10/carnet-de-shopping-fete-ses-3-ans-et-vous-gate-la-semaine-prochaine/"] [unique_id "amuJZ_xa4UbeLxj1SWXElAAAAPY"]
[Thu Jul 30 12:27:03.335077 2026] [security2:error] [pid 738779:tid 738968] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/xstelth.php"] [unique_id "amuJZ_xa4UbeLxj1SWXEmQAAAMA"]
[Thu Jul 30 12:27:03.335155 2026] [security2:error] [pid 738779:tid 738968] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/xstelth.php"] [unique_id "amuJZ_xa4UbeLxj1SWXEmQAAAMA"]
[Thu Jul 30 12:27:03.394055 2026] [security2:error] [pid 738779:tid 738976] [client 43.173.173.236:58322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.173.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/02/17/au-hasard-de-la-toile-15/"] [unique_id "amuJZ_xa4UbeLxj1SWXElwAAAMg"]
[Thu Jul 30 12:27:03.500198 2026] [security2:error] [pid 738779:tid 738980] [client 20.100.169.152:63037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/aaf.php"] [unique_id "amuJZ_xa4UbeLxj1SWXEnAAAAMw"]
[Thu Jul 30 12:27:03.500310 2026] [security2:error] [pid 738779:tid 738980] [client 20.100.169.152:63037] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/aaf.php"] [unique_id "amuJZ_xa4UbeLxj1SWXEnAAAAMw"]
[Thu Jul 30 12:27:03.527049 2026] [security2:error] [pid 738779:tid 738936] [client 142.93.53.183:62628] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/packet/7Syndicate/oxnixcgiapi/perl.oxnix"] [unique_id "amuJZ_xa4UbeLxj1SWXEnwAAAKA"]
[Thu Jul 30 12:27:03.605530 2026] [security2:error] [pid 738779:tid 738988] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/584062352875874akp.php"] [unique_id "amuJZ_xa4UbeLxj1SWXEowAAANQ"]
[Thu Jul 30 12:27:03.605635 2026] [security2:error] [pid 738779:tid 738988] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/584062352875874akp.php"] [unique_id "amuJZ_xa4UbeLxj1SWXEowAAANQ"]
[Thu Jul 30 12:27:03.741295 2026] [security2:error] [pid 738779:tid 738922] [client 20.52.54.143:10224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/user/index.php"] [unique_id "amuJZ_xa4UbeLxj1SWXEpwAAAJI"]
[Thu Jul 30 12:27:03.817235 2026] [security2:error] [pid 738779:tid 738948] [client 20.100.169.152:44102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/ha.php"] [unique_id "amuJZ_xa4UbeLxj1SWXEqAAAAKw"]
[Thu Jul 30 12:27:03.817339 2026] [security2:error] [pid 738779:tid 738948] [client 20.100.169.152:44102] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/ha.php"] [unique_id "amuJZ_xa4UbeLxj1SWXEqAAAAKw"]
[Thu Jul 30 12:27:03.917774 2026] [security2:error] [pid 738779:tid 739031] [client 142.93.53.183:62631] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/packet/7Syndicate/oxnixcgiapi/bash.oxnix"] [unique_id "amuJZ_xa4UbeLxj1SWXEqQAAAP8"]
[Thu Jul 30 12:27:04.052413 2026] [core:notice] [pid 738779:tid 739003] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:04.058008 2026] [security2:error] [pid 738779:tid 739003] [client 43.173.174.253:51130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/03/10/carnet-de-shopping-fete-ses-3-ans-et-vous-gate-la-semaine-prochaine/"] [unique_id "amuJaPxa4UbeLxj1SWXErQAAAOM"], referer: https://carnetdeshopping.com/index.php/2012/03/10/carnet-de-shopping-fete-ses-3-ans-et-vous-gate-la-semaine-prochaine/
[Thu Jul 30 12:27:04.059731 2026] [core:notice] [pid 738779:tid 738953] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:04.065785 2026] [security2:error] [pid 738779:tid 738953] [client 43.172.198.222:44844] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/02/17/au-hasard-de-la-toile-15/"] [unique_id "amuJaPxa4UbeLxj1SWXErgAAALE"], referer: https://carnetdeshopping.com/index.php/2014/02/17/au-hasard-de-la-toile-15/
[Thu Jul 30 12:27:04.140503 2026] [security2:error] [pid 738779:tid 738982] [client 20.100.169.152:62993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/hur.php"] [unique_id "amuJaPxa4UbeLxj1SWXErwAAAM4"]
[Thu Jul 30 12:27:04.140619 2026] [security2:error] [pid 738779:tid 738982] [client 20.100.169.152:62993] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/hur.php"] [unique_id "amuJaPxa4UbeLxj1SWXErwAAAM4"]
[Thu Jul 30 12:27:04.180200 2026] [security2:error] [pid 738779:tid 738909] [client 57.141.0.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJZ_xa4UbeLxj1SWXEogAAAIU"]
[Thu Jul 30 12:27:04.305800 2026] [security2:error] [pid 738779:tid 739001] [client 142.93.53.183:62636] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/lib/lang/locale/th_TH/LC_MESSAGES/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJaPxa4UbeLxj1SWXEtQAAAOE"]
[Thu Jul 30 12:27:04.488707 2026] [security2:error] [pid 738779:tid 738918] [client 20.100.169.152:62990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/h02ugyh.php"] [unique_id "amuJaPxa4UbeLxj1SWXEtgAAAI4"]
[Thu Jul 30 12:27:04.488860 2026] [security2:error] [pid 738779:tid 738918] [client 20.100.169.152:62990] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/h02ugyh.php"] [unique_id "amuJaPxa4UbeLxj1SWXEtgAAAI4"]
[Thu Jul 30 12:27:04.511495 2026] [security2:error] [pid 738779:tid 738925] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/newfile.php"] [unique_id "amuJaPxa4UbeLxj1SWXEtwAAAJU"]
[Thu Jul 30 12:27:04.511593 2026] [security2:error] [pid 738779:tid 738925] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/newfile.php"] [unique_id "amuJaPxa4UbeLxj1SWXEtwAAAJU"]
[Thu Jul 30 12:27:04.588740 2026] [security2:error] [pid 738779:tid 739007] [client 103.188.52.54:42010] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJaPxa4UbeLxj1SWXEtAAAAOc"], referer: http://pkf.jo
[Thu Jul 30 12:27:04.699019 2026] [security2:error] [pid 738779:tid 739024] [client 142.93.53.183:62639] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/lib/lang/locale/th_TH/LC_MESSAGES/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJaPxa4UbeLxj1SWXEvgAAAPg"]
[Thu Jul 30 12:27:04.779258 2026] [security2:error] [pid 738779:tid 738943] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/tBEZGQz.php"] [unique_id "amuJaPxa4UbeLxj1SWXEwQAAAKc"]
[Thu Jul 30 12:27:04.779350 2026] [security2:error] [pid 738779:tid 738943] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/tBEZGQz.php"] [unique_id "amuJaPxa4UbeLxj1SWXEwQAAAKc"]
[Thu Jul 30 12:27:04.800907 2026] [security2:error] [pid 738779:tid 738954] [client 20.100.169.152:44107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/155.php"] [unique_id "amuJaPxa4UbeLxj1SWXEwgAAALI"]
[Thu Jul 30 12:27:04.801008 2026] [security2:error] [pid 738779:tid 738954] [client 20.100.169.152:44107] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/155.php"] [unique_id "amuJaPxa4UbeLxj1SWXEwgAAALI"]
[Thu Jul 30 12:27:05.015661 2026] [proxy:error] [pid 738779:tid 738917] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:27:05.015757 2026] [proxy_http:error] [pid 738779:tid 738917] [client 20.52.54.143:9920] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:27:05.016474 2026] [proxy:error] [pid 738779:tid 738917] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:27:05.016525 2026] [proxy_http:error] [pid 738779:tid 738917] [client 20.52.54.143:9920] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:27:05.036257 2026] [security2:error] [pid 738779:tid 738956] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "tiger388.shop"] [uri "/cgi-sys/404.html"] [unique_id "amuJafxa4UbeLxj1SWXExQAAALQ"]
[Thu Jul 30 12:27:05.089549 2026] [security2:error] [pid 738779:tid 739004] [client 142.93.53.183:62641] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/lib/lang/locale/th_TH/LC_MESSAGES/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJafxa4UbeLxj1SWXEyQAAAOQ"]
[Thu Jul 30 12:27:05.106083 2026] [security2:error] [pid 738779:tid 738911] [client 20.100.169.152:63007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/ops.php"] [unique_id "amuJafxa4UbeLxj1SWXEygAAAIc"]
[Thu Jul 30 12:27:05.106182 2026] [security2:error] [pid 738779:tid 738911] [client 20.100.169.152:63007] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/ops.php"] [unique_id "amuJafxa4UbeLxj1SWXEygAAAIc"]
[Thu Jul 30 12:27:05.146666 2026] [security2:error] [pid 738779:tid 738969] [client 223.184.237.53:22596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJaPxa4UbeLxj1SWXEwwAAAME"], referer: http://pkf.jo
[Thu Jul 30 12:27:05.235734 2026] [security2:error] [pid 738779:tid 738859] [remote 103.255.134.61:51146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-login.php"] [unique_id "amuJafxa4UbeLxj1SWXEywAA608"]
[Thu Jul 30 12:27:05.309362 2026] [security2:error] [pid 738779:tid 738973] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/drykl.php"] [unique_id "amuJafxa4UbeLxj1SWXEzwAAAMU"]
[Thu Jul 30 12:27:05.309453 2026] [security2:error] [pid 738779:tid 738973] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/drykl.php"] [unique_id "amuJafxa4UbeLxj1SWXEzwAAAMU"]
[Thu Jul 30 12:27:05.474808 2026] [security2:error] [pid 738779:tid 738935] [client 20.100.169.152:63010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/ingfo.php"] [unique_id "amuJafxa4UbeLxj1SWXE0AAAAJ8"]
[Thu Jul 30 12:27:05.474911 2026] [security2:error] [pid 738779:tid 738935] [client 20.100.169.152:63010] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/ingfo.php"] [unique_id "amuJafxa4UbeLxj1SWXE0AAAAJ8"]
[Thu Jul 30 12:27:05.479959 2026] [security2:error] [pid 738779:tid 739015] [client 142.93.53.183:62645] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/admin/admin_template/default/assets/fonts/ONIC_ESPORT/haxorcgiapi/perl.haxor"] [unique_id "amuJafxa4UbeLxj1SWXE0QAAAO8"]
[Thu Jul 30 12:27:05.617212 2026] [security2:error] [pid 738779:tid 739000] [client 20.52.54.143:9957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amuJafxa4UbeLxj1SWXE1AAAAOA"]
[Thu Jul 30 12:27:05.723356 2026] [security2:error] [pid 738779:tid 739032] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "tiger388.shop"] [uri "/cgi-sys/404.html"] [unique_id "amuJafxa4UbeLxj1SWXE2wAAAQA"]
[Thu Jul 30 12:27:05.783429 2026] [security2:error] [pid 738779:tid 738999] [client 20.100.169.152:44104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/error_log.php"] [unique_id "amuJafxa4UbeLxj1SWXE3AAAAN8"]
[Thu Jul 30 12:27:05.783582 2026] [security2:error] [pid 738779:tid 738999] [client 20.100.169.152:44104] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/error_log.php"] [unique_id "amuJafxa4UbeLxj1SWXE3AAAAN8"]
[Thu Jul 30 12:27:05.797906 2026] [security2:error] [pid 738779:tid 738915] [client 75.174.89.119:60784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJafxa4UbeLxj1SWXE0gAAAIs"], referer: http://pkf.jo
[Thu Jul 30 12:27:05.858223 2026] [security2:error] [pid 738779:tid 738949] [client 142.93.53.183:62648] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/admin/admin_template/default/assets/fonts/ONIC_ESPORT/haxorcgiapi/py.haxor"] [unique_id "amuJafxa4UbeLxj1SWXE3QAAAK0"]
[Thu Jul 30 12:27:06.021946 2026] [security2:error] [pid 738779:tid 738940] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/ls.php"] [unique_id "amuJavxa4UbeLxj1SWXE5AAAAKQ"]
[Thu Jul 30 12:27:06.022057 2026] [security2:error] [pid 738779:tid 738940] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/ls.php"] [unique_id "amuJavxa4UbeLxj1SWXE5AAAAKQ"]
[Thu Jul 30 12:27:06.092283 2026] [security2:error] [pid 738779:tid 738910] [client 57.141.0.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuJafxa4UbeLxj1SWXE4AAAAIY"]
[Thu Jul 30 12:27:06.102642 2026] [security2:error] [pid 738779:tid 738962] [client 20.100.169.152:44129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/koala.php"] [unique_id "amuJavxa4UbeLxj1SWXE6AAAALo"]
[Thu Jul 30 12:27:06.102789 2026] [security2:error] [pid 738779:tid 738962] [client 20.100.169.152:44129] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/koala.php"] [unique_id "amuJavxa4UbeLxj1SWXE6AAAALo"]
[Thu Jul 30 12:27:06.254828 2026] [security2:error] [pid 738779:tid 738953] [client 74.7.175.176:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.progroup.jo"] [uri "/cgi-sys/404.html"] [unique_id "amuJavxa4UbeLxj1SWXE6wAAALE"]
[Thu Jul 30 12:27:06.255450 2026] [security2:error] [pid 738779:tid 738985] [client 74.7.175.176:45734] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.progroup.jo"] [uri "/robots.txt"] [unique_id "amuJavxa4UbeLxj1SWXE6QAA0WM"]
[Thu Jul 30 12:27:06.261536 2026] [security2:error] [pid 738779:tid 738967] [client 142.93.53.183:62653] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/admin/admin_template/default/assets/fonts/ONIC_ESPORT/haxorcgiapi/bash.haxor"] [unique_id "amuJavxa4UbeLxj1SWXE7QAAAL8"]
[Thu Jul 30 12:27:06.411794 2026] [security2:error] [pid 738779:tid 738965] [client 20.100.169.152:44157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/mac.php"] [unique_id "amuJavxa4UbeLxj1SWXE8QAAAL0"]
[Thu Jul 30 12:27:06.411892 2026] [security2:error] [pid 738779:tid 738965] [client 20.100.169.152:44157] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/mac.php"] [unique_id "amuJavxa4UbeLxj1SWXE8QAAAL0"]
[Thu Jul 30 12:27:06.465343 2026] [security2:error] [pid 738779:tid 738975] [client 20.52.54.143:9399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/index/function.php"] [unique_id "amuJavxa4UbeLxj1SWXE8gAAAMc"]
[Thu Jul 30 12:27:06.476519 2026] [security2:error] [pid 738779:tid 738918] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/dx.php"] [unique_id "amuJavxa4UbeLxj1SWXE8wAAAI4"]
[Thu Jul 30 12:27:06.476597 2026] [security2:error] [pid 738779:tid 738918] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/dx.php"] [unique_id "amuJavxa4UbeLxj1SWXE8wAAAI4"]
[Thu Jul 30 12:27:06.651802 2026] [security2:error] [pid 738779:tid 739020] [client 142.93.53.183:62654] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/config/1337_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJavxa4UbeLxj1SWXE9wAAAPQ"]
[Thu Jul 30 12:27:06.717181 2026] [security2:error] [pid 738779:tid 738944] [client 20.100.169.152:63029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/wefile.php"] [unique_id "amuJavxa4UbeLxj1SWXE-AAAAKg"]
[Thu Jul 30 12:27:06.717283 2026] [security2:error] [pid 738779:tid 738944] [client 20.100.169.152:63029] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/wefile.php"] [unique_id "amuJavxa4UbeLxj1SWXE-AAAAKg"]
[Thu Jul 30 12:27:06.860878 2026] [security2:error] [pid 738779:tid 739010] [client 74.7.244.19:44216] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.uqr.djb.temporary.site"] [uri "/index.php"] [unique_id "amuJafxa4UbeLxj1SWXE0wAA6lw"]
[Thu Jul 30 12:27:06.877819 2026] [security2:error] [pid 738779:tid 738876] [remote 159.223.76.255:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.76.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vanguardlegalassociates.team"] [uri "/wp-login.php"] [unique_id "amuJavxa4UbeLxj1SWXE_QAA5WA"]
[Thu Jul 30 12:27:07.040842 2026] [security2:error] [pid 738779:tid 738917] [client 142.93.53.183:62656] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/config/1337_DATA/alfacgiapi/py.alfa"] [unique_id "amuJa_xa4UbeLxj1SWXE_wAAAI0"]
[Thu Jul 30 12:27:07.054852 2026] [security2:error] [pid 738779:tid 738934] [client 20.100.169.152:62981] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/___proxy_subdomain_webmail/wp-includes/blocks/post-comments-form/"] [unique_id "amuJa_xa4UbeLxj1SWXE_gAAAJ4"]
[Thu Jul 30 12:27:07.391062 2026] [security2:error] [pid 738779:tid 739015] [client 20.100.169.152:62981] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/___proxy_subdomain_webmail/wp-admin/js/"] [unique_id "amuJa_xa4UbeLxj1SWXFDgAAAO8"]
[Thu Jul 30 12:27:07.433339 2026] [security2:error] [pid 738779:tid 739000] [client 142.93.53.183:62657] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/config/1337_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJa_xa4UbeLxj1SWXFEAAAAOA"]
[Thu Jul 30 12:27:07.542575 2026] [security2:error] [pid 738779:tid 738959] [client 20.100.169.152:62981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/makeasmtp.php"] [unique_id "amuJa_xa4UbeLxj1SWXFEQAAALc"]
[Thu Jul 30 12:27:07.542687 2026] [security2:error] [pid 738779:tid 738959] [client 20.100.169.152:62981] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/makeasmtp.php"] [unique_id "amuJa_xa4UbeLxj1SWXFEQAAALc"]
[Thu Jul 30 12:27:07.820972 2026] [security2:error] [pid 738779:tid 738980] [client 142.93.53.183:62662] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/images/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJa_xa4UbeLxj1SWXFFwAAAMw"]
[Thu Jul 30 12:27:07.827293 2026] [security2:error] [pid 738779:tid 738976] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/mac.php"] [unique_id "amuJa_xa4UbeLxj1SWXFGQAAAMg"]
[Thu Jul 30 12:27:07.827401 2026] [security2:error] [pid 738779:tid 738976] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/mac.php"] [unique_id "amuJa_xa4UbeLxj1SWXFGQAAAMg"]
[Thu Jul 30 12:27:07.955490 2026] [security2:error] [pid 738779:tid 738983] [client 20.100.169.152:44110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/2P.php"] [unique_id "amuJa_xa4UbeLxj1SWXFHAAAAM8"]
[Thu Jul 30 12:27:07.955600 2026] [security2:error] [pid 738779:tid 738983] [client 20.100.169.152:44110] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/2P.php"] [unique_id "amuJa_xa4UbeLxj1SWXFHAAAAM8"]
[Thu Jul 30 12:27:08.020598 2026] [security2:error] [pid 738779:tid 738893] [remote 57.141.0.62:24728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuJa_xa4UbeLxj1SWXFFgAAnHE"]
[Thu Jul 30 12:27:08.073110 2026] [security2:error] [pid 738779:tid 738981] [client 144.172.94.198:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "buyfluoxetine.store"] [uri "/backup/.env"] [unique_id "amuJbPxa4UbeLxj1SWXFHQAAAM0"]
[Thu Jul 30 12:27:08.114191 2026] [security2:error] [pid 738779:tid 739008] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/485.php"] [unique_id "amuJbPxa4UbeLxj1SWXFHgAAAOg"]
[Thu Jul 30 12:27:08.114287 2026] [security2:error] [pid 738779:tid 739008] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/485.php"] [unique_id "amuJbPxa4UbeLxj1SWXFHgAAAOg"]
[Thu Jul 30 12:27:08.193956 2026] [security2:error] [pid 738779:tid 739032] [client 85.208.96.206:34138] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/12/11/lula-sera-diplomado-nesta-segunda-no-tse-com-discurso-e-280-convidados/"] [unique_id "amuJbPxa4UbeLxj1SWXFIgAAAQA"]
[Thu Jul 30 12:27:08.194071 2026] [security2:error] [pid 738779:tid 739032] [client 85.208.96.206:34138] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/12/11/lula-sera-diplomado-nesta-segunda-no-tse-com-discurso-e-280-convidados/"] [unique_id "amuJbPxa4UbeLxj1SWXFIgAAAQA"]
[Thu Jul 30 12:27:08.212886 2026] [security2:error] [pid 738779:tid 739031] [client 142.93.53.183:62664] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/images/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJbPxa4UbeLxj1SWXFJAAAAP8"]
[Thu Jul 30 12:27:08.259186 2026] [security2:error] [pid 738779:tid 738964] [client 20.100.169.152:44142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/.well-known/about.php"] [unique_id "amuJbPxa4UbeLxj1SWXFJwAAALw"]
[Thu Jul 30 12:27:08.259298 2026] [security2:error] [pid 738779:tid 738964] [client 20.100.169.152:44142] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/.well-known/about.php"] [unique_id "amuJbPxa4UbeLxj1SWXFJwAAALw"]
[Thu Jul 30 12:27:08.364305 2026] [security2:error] [pid 738779:tid 738990] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/gelio1.php"] [unique_id "amuJbPxa4UbeLxj1SWXFKwAAANY"]
[Thu Jul 30 12:27:08.364421 2026] [security2:error] [pid 738779:tid 738990] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/gelio1.php"] [unique_id "amuJbPxa4UbeLxj1SWXFKwAAANY"]
[Thu Jul 30 12:27:08.375440 2026] [security2:error] [pid 738779:tid 739026] [client 57.141.0.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuJbPxa4UbeLxj1SWXFJgAAAPo"]
[Thu Jul 30 12:27:08.564759 2026] [security2:error] [pid 738779:tid 738912] [client 20.100.169.152:63006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuJbPxa4UbeLxj1SWXFLgAAAIg"]
[Thu Jul 30 12:27:08.564879 2026] [security2:error] [pid 738779:tid 738912] [client 20.100.169.152:63006] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuJbPxa4UbeLxj1SWXFLgAAAIg"]
[Thu Jul 30 12:27:08.605017 2026] [security2:error] [pid 738779:tid 738931] [client 142.93.53.183:62668] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/v1/assets/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJbPxa4UbeLxj1SWXFLwAAAJs"]
[Thu Jul 30 12:27:08.646586 2026] [security2:error] [pid 738779:tid 738965] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/lp6.php"] [unique_id "amuJbPxa4UbeLxj1SWXFMAAAAL0"]
[Thu Jul 30 12:27:08.646683 2026] [security2:error] [pid 738779:tid 738965] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/lp6.php"] [unique_id "amuJbPxa4UbeLxj1SWXFMAAAAL0"]
[Thu Jul 30 12:27:08.865237 2026] [security2:error] [pid 738779:tid 738926] [client 20.100.169.152:44149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/system_log.php"] [unique_id "amuJbPxa4UbeLxj1SWXFOQAAAJY"]
[Thu Jul 30 12:27:08.865368 2026] [security2:error] [pid 738779:tid 738926] [client 20.100.169.152:44149] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/system_log.php"] [unique_id "amuJbPxa4UbeLxj1SWXFOQAAAJY"]
[Thu Jul 30 12:27:08.896495 2026] [security2:error] [pid 738779:tid 739030] [client 52.238.199.152:38861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/plugins.php"] [unique_id "amuJbPxa4UbeLxj1SWXFOgAAAP4"]
[Thu Jul 30 12:27:08.995515 2026] [security2:error] [pid 738779:tid 738943] [client 142.93.53.183:62672] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/v1/assets/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJbPxa4UbeLxj1SWXFOwAAAKc"]
[Thu Jul 30 12:27:09.200453 2026] [security2:error] [pid 738779:tid 738928] [client 20.100.169.152:63014] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/___proxy_subdomain_webmail/wp-admin/css/"] [unique_id "amuJbfxa4UbeLxj1SWXFPwAAAJg"]
[Thu Jul 30 12:27:09.226912 2026] [core:notice] [pid 738779:tid 738781] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:09.276058 2026] [security2:error] [pid 738779:tid 738939] [client 216.73.216.144:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ciunews.com"] [uri "/index.php"] [unique_id "amuJbfxa4UbeLxj1SWXFPgAAAKM"]
[Thu Jul 30 12:27:09.312007 2026] [proxy:error] [pid 738779:tid 738914] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:27:09.312095 2026] [proxy_http:error] [pid 738779:tid 738914] [client 20.52.54.143:9974] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:27:09.312645 2026] [proxy:error] [pid 738779:tid 738914] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:27:09.312688 2026] [proxy_http:error] [pid 738779:tid 738914] [client 20.52.54.143:9974] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:27:09.386563 2026] [security2:error] [pid 738779:tid 739027] [client 142.93.53.183:62681] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/v1/assets/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJbfxa4UbeLxj1SWXFSQAAAPs"]
[Thu Jul 30 12:27:09.417693 2026] [security2:error] [pid 738779:tid 739000] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuJbfxa4UbeLxj1SWXFSwAAAOA"]
[Thu Jul 30 12:27:09.417785 2026] [security2:error] [pid 738779:tid 739000] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuJbfxa4UbeLxj1SWXFSwAAAOA"]
[Thu Jul 30 12:27:09.544358 2026] [core:notice] [pid 738779:tid 738941] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:09.559501 2026] [security2:error] [pid 738779:tid 739036] [client 20.100.169.152:63014] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/___proxy_subdomain_webmail/wp-admin/css/colors/modern/"] [unique_id "amuJbfxa4UbeLxj1SWXFTAAAAQQ"]
[Thu Jul 30 12:27:09.692889 2026] [security2:error] [pid 738779:tid 738999] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "tiger388.shop"] [uri "/cgi-sys/404.html"] [unique_id "amuJbfxa4UbeLxj1SWXFUQAAAN8"]
[Thu Jul 30 12:27:09.720233 2026] [security2:error] [pid 738779:tid 738995] [client 20.100.169.152:63014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/crgio.php"] [unique_id "amuJbfxa4UbeLxj1SWXFVQAAANs"]
[Thu Jul 30 12:27:09.720341 2026] [security2:error] [pid 738779:tid 738995] [client 20.100.169.152:63014] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/crgio.php"] [unique_id "amuJbfxa4UbeLxj1SWXFVQAAANs"]
[Thu Jul 30 12:27:09.756757 2026] [security2:error] [pid 738779:tid 738959] [client 52.238.199.152:38860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/xxx.php"] [unique_id "amuJbfxa4UbeLxj1SWXFVgAAALc"]
[Thu Jul 30 12:27:09.774406 2026] [security2:error] [pid 738779:tid 738983] [client 142.93.53.183:62688] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/v1/vendor/phpunit/php-code-coverage/src/Report/Html/Renderer/Template/js/cache/GUNDAMAPI/perl.alfa"] [unique_id "amuJbfxa4UbeLxj1SWXFVwAAAM8"]
[Thu Jul 30 12:27:09.838235 2026] [security2:error] [pid 738779:tid 738932] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/w3llscc.php"] [unique_id "amuJbfxa4UbeLxj1SWXFWAAAAJw"]
[Thu Jul 30 12:27:09.838355 2026] [security2:error] [pid 738779:tid 738932] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/w3llscc.php"] [unique_id "amuJbfxa4UbeLxj1SWXFWAAAAJw"]
[Thu Jul 30 12:27:09.958937 2026] [core:notice] [pid 738779:tid 738906] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:10.084059 2026] [security2:error] [pid 738779:tid 739017] [client 20.100.169.152:44133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/pucci.php"] [unique_id "amuJbvxa4UbeLxj1SWXFXQAAAPE"]
[Thu Jul 30 12:27:10.084173 2026] [security2:error] [pid 738779:tid 739017] [client 20.100.169.152:44133] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/pucci.php"] [unique_id "amuJbvxa4UbeLxj1SWXFXQAAAPE"]
[Thu Jul 30 12:27:10.099817 2026] [security2:error] [pid 738779:tid 738946] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/miru3.php"] [unique_id "amuJbvxa4UbeLxj1SWXFXgAAAKo"]
[Thu Jul 30 12:27:10.099952 2026] [security2:error] [pid 738779:tid 738946] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/miru3.php"] [unique_id "amuJbvxa4UbeLxj1SWXFXgAAAKo"]
[Thu Jul 30 12:27:10.133295 2026] [core:notice] [pid 738779:tid 739032] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:10.164799 2026] [security2:error] [pid 738779:tid 738964] [client 142.93.53.183:62690] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/v1/vendor/phpunit/php-code-coverage/src/Report/Html/Renderer/Template/js/cache/GUNDAMAPI/py.alfa"] [unique_id "amuJbvxa4UbeLxj1SWXFYAAAALw"]
[Thu Jul 30 12:27:10.371635 2026] [security2:error] [pid 738779:tid 738929] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/autoload_classmap.php"] [unique_id "amuJbvxa4UbeLxj1SWXFZQAAAJk"]
[Thu Jul 30 12:27:10.371731 2026] [security2:error] [pid 738779:tid 738929] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/autoload_classmap.php"] [unique_id "amuJbvxa4UbeLxj1SWXFZQAAAJk"]
[Thu Jul 30 12:27:10.517951 2026] [security2:error] [pid 738779:tid 738917] [client 2a03:2880:f800:1b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJbfxa4UbeLxj1SWXFSAAAjXc"]
[Thu Jul 30 12:27:10.536469 2026] [security2:error] [pid 738779:tid 738984] [client 20.100.169.152:48892] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/___proxy_subdomain_webmail/wp-includes/blocks/details/"] [unique_id "amuJbvxa4UbeLxj1SWXFaAAAANA"]
[Thu Jul 30 12:27:10.559785 2026] [security2:error] [pid 738779:tid 738912] [client 142.93.53.183:62692] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/v1/vendor/phpunit/php-code-coverage/src/Report/Html/Renderer/Template/js/cache/GUNDAMAPI/bash.alfa"] [unique_id "amuJbvxa4UbeLxj1SWXFaQAAAIg"]
[Thu Jul 30 12:27:10.562213 2026] [proxy:error] [pid 738779:tid 739031] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:27:10.562287 2026] [proxy_http:error] [pid 738779:tid 739031] [client 20.52.54.143:10231] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:27:10.562827 2026] [proxy:error] [pid 738779:tid 739031] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:27:10.562869 2026] [proxy_http:error] [pid 738779:tid 739031] [client 20.52.54.143:10231] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:27:10.869986 2026] [security2:error] [pid 738779:tid 739021] [client 20.100.169.152:48892] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/___proxy_subdomain_webmail/wp-includes/blocks/audio/"] [unique_id "amuJbvxa4UbeLxj1SWXFbwAAAPU"]
[Thu Jul 30 12:27:10.945764 2026] [security2:error] [pid 738779:tid 739011] [client 142.93.53.183:62697] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/build/assets/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJbvxa4UbeLxj1SWXFcwAAAOs"]
[Thu Jul 30 12:27:11.023663 2026] [security2:error] [pid 738779:tid 738962] [client 20.100.169.152:48892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/wp-temp.php"] [unique_id "amuJb_xa4UbeLxj1SWXFdAAAALo"]
[Thu Jul 30 12:27:11.023808 2026] [security2:error] [pid 738779:tid 738962] [client 20.100.169.152:48892] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/wp-temp.php"] [unique_id "amuJb_xa4UbeLxj1SWXFdAAAALo"]
[Thu Jul 30 12:27:11.043379 2026] [security2:error] [pid 738779:tid 738782] [remote 47.128.27.46:37386] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/nike-aj1-air-jordan-1-low-christmas-white-red/"] [unique_id "amuJb_xa4UbeLxj1SWXFdgAAwwI"]
[Thu Jul 30 12:27:11.045168 2026] [security2:error] [pid 738779:tid 739010] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "tiger388.shop"] [uri "/cgi-sys/404.html"] [unique_id "amuJb_xa4UbeLxj1SWXFdQAAAOo"]
[Thu Jul 30 12:27:11.194167 2026] [security2:error] [pid 738779:tid 739005] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/wp-content/themes/index.php"] [unique_id "amuJb_xa4UbeLxj1SWXFdwAAAOU"]
[Thu Jul 30 12:27:11.194326 2026] [security2:error] [pid 738779:tid 739005] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/wp-content/themes/index.php"] [unique_id "amuJb_xa4UbeLxj1SWXFdwAAAOU"]
[Thu Jul 30 12:27:11.225651 2026] [security2:error] [pid 738779:tid 738975] [client 52.238.199.152:17759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/css.php"] [unique_id "amuJb_xa4UbeLxj1SWXFeAAAAMc"]
[Thu Jul 30 12:27:11.288939 2026] [security2:error] [pid 738779:tid 738960] [client 20.52.54.143:9224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/aaa.php"] [unique_id "amuJb_xa4UbeLxj1SWXFfAAAALg"]
[Thu Jul 30 12:27:11.339579 2026] [security2:error] [pid 738779:tid 738934] [client 142.93.53.183:62699] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/build/assets/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJb_xa4UbeLxj1SWXFfgAAAJ4"]
[Thu Jul 30 12:27:11.462530 2026] [security2:error] [pid 738779:tid 739013] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/av.php"] [unique_id "amuJb_xa4UbeLxj1SWXFggAAAO0"]
[Thu Jul 30 12:27:11.462632 2026] [security2:error] [pid 738779:tid 739013] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/av.php"] [unique_id "amuJb_xa4UbeLxj1SWXFggAAAO0"]
[Thu Jul 30 12:27:11.465179 2026] [security2:error] [pid 738779:tid 738911] [client 20.100.169.152:44158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/wp-admin/js/index.php"] [unique_id "amuJb_xa4UbeLxj1SWXFgwAAAIc"]
[Thu Jul 30 12:27:11.465254 2026] [security2:error] [pid 738779:tid 738911] [client 20.100.169.152:44158] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/wp-admin/js/index.php"] [unique_id "amuJb_xa4UbeLxj1SWXFgwAAAIc"]
[Thu Jul 30 12:27:11.714197 2026] [security2:error] [pid 738779:tid 738997] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "tiger388.shop"] [uri "/cgi-sys/404.html"] [unique_id "amuJb_xa4UbeLxj1SWXFhAAAAN0"]
[Thu Jul 30 12:27:11.727386 2026] [security2:error] [pid 738779:tid 738935] [client 142.93.53.183:62705] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/build/assets/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJb_xa4UbeLxj1SWXFhQAAAJ8"]
[Thu Jul 30 12:27:11.815389 2026] [security2:error] [pid 738779:tid 739015] [client 20.100.169.152:44126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/puc.php"] [unique_id "amuJb_xa4UbeLxj1SWXFiQAAAO8"]
[Thu Jul 30 12:27:11.815492 2026] [security2:error] [pid 738779:tid 739015] [client 20.100.169.152:44126] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/puc.php"] [unique_id "amuJb_xa4UbeLxj1SWXFiQAAAO8"]
[Thu Jul 30 12:27:11.852221 2026] [security2:error] [pid 738779:tid 738972] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "tiger388.shop"] [uri "/cgi-sys/404.html"] [unique_id "amuJb_xa4UbeLxj1SWXFigAAAMQ"]
[Thu Jul 30 12:27:11.991806 2026] [security2:error] [pid 738779:tid 739002] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/tiny.php"] [unique_id "amuJb_xa4UbeLxj1SWXFjgAAAOI"]
[Thu Jul 30 12:27:11.991921 2026] [security2:error] [pid 738779:tid 739002] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/tiny.php"] [unique_id "amuJb_xa4UbeLxj1SWXFjgAAAOI"]
[Thu Jul 30 12:27:12.120864 2026] [security2:error] [pid 738779:tid 738915] [client 142.93.53.183:62709] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/vendor/swagger-api/swagger-ui/src/core/presets/base/plugins/form-components/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJcPxa4UbeLxj1SWXFkAAAAIs"]
[Thu Jul 30 12:27:12.145275 2026] [security2:error] [pid 738779:tid 738959] [client 20.100.169.152:44144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/dx.php"] [unique_id "amuJcPxa4UbeLxj1SWXFkQAAALc"]
[Thu Jul 30 12:27:12.145369 2026] [security2:error] [pid 738779:tid 738959] [client 20.100.169.152:44144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/dx.php"] [unique_id "amuJcPxa4UbeLxj1SWXFkQAAALc"]
[Thu Jul 30 12:27:12.437723 2026] [security2:error] [pid 738779:tid 738941] [client 20.52.54.143:9964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/getid3-core.php"] [unique_id "amuJcPxa4UbeLxj1SWXFlQAAAKU"]
[Thu Jul 30 12:27:12.500637 2026] [security2:error] [pid 738779:tid 738981] [client 20.100.169.152:48861] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/___proxy_subdomain_webmail/wp-includes/Requests/"] [unique_id "amuJcPxa4UbeLxj1SWXFlwAAAM0"]
[Thu Jul 30 12:27:12.511679 2026] [security2:error] [pid 738779:tid 738933] [client 142.93.53.183:62714] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/vendor/swagger-api/swagger-ui/src/core/presets/base/plugins/form-components/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJcPxa4UbeLxj1SWXFnQAAAJ0"]
[Thu Jul 30 12:27:12.705637 2026] [security2:error] [pid 738779:tid 738966] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuJcPxa4UbeLxj1SWXFngAAAL4"]
[Thu Jul 30 12:27:12.705785 2026] [security2:error] [pid 738779:tid 738966] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuJcPxa4UbeLxj1SWXFngAAAL4"]
[Thu Jul 30 12:27:12.799012 2026] [security2:error] [pid 738779:tid 739029] [client 20.100.169.152:48861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/7.php"] [unique_id "amuJcPxa4UbeLxj1SWXFowAAAP0"]
[Thu Jul 30 12:27:12.799131 2026] [security2:error] [pid 738779:tid 739029] [client 20.100.169.152:48861] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/7.php"] [unique_id "amuJcPxa4UbeLxj1SWXFowAAAP0"]
[Thu Jul 30 12:27:12.878809 2026] [security2:error] [pid 738779:tid 738895] [remote 57.141.0.3:22556] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "thdinfinity.com"] [uri "/search/4627290655/feed/rss2/"] [unique_id "amuJcPxa4UbeLxj1SWXFqAAAsXM"]
[Thu Jul 30 12:27:12.903722 2026] [security2:error] [pid 738779:tid 739031] [client 142.93.53.183:62717] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/vendor/swagger-api/swagger-ui/src/core/presets/base/plugins/form-components/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJcPxa4UbeLxj1SWXFqQAAAP8"]
[Thu Jul 30 12:27:12.987509 2026] [security2:error] [pid 738779:tid 738918] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/zrrhj.php"] [unique_id "amuJcPxa4UbeLxj1SWXFqgAAAI4"]
[Thu Jul 30 12:27:12.987630 2026] [security2:error] [pid 738779:tid 738918] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/zrrhj.php"] [unique_id "amuJcPxa4UbeLxj1SWXFqgAAAI4"]
[Thu Jul 30 12:27:13.068754 2026] [security2:error] [pid 738779:tid 738988] [client 20.52.54.143:9935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/adminer.php"] [unique_id "amuJcfxa4UbeLxj1SWXFrgAAANQ"]
[Thu Jul 30 12:27:13.107666 2026] [security2:error] [pid 738779:tid 739007] [client 20.100.169.152:48876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/8.php"] [unique_id "amuJcfxa4UbeLxj1SWXFrwAAAOc"]
[Thu Jul 30 12:27:13.107754 2026] [security2:error] [pid 738779:tid 739007] [client 20.100.169.152:48876] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/8.php"] [unique_id "amuJcfxa4UbeLxj1SWXFrwAAAOc"]
[Thu Jul 30 12:27:13.137498 2026] [security2:error] [pid 738779:tid 739003] [client 169.224.38.239:20408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJcPxa4UbeLxj1SWXFpAAAAOM"], referer: http://pkf.jo
[Thu Jul 30 12:27:13.172406 2026] [security2:error] [pid 738779:tid 739026] [client 36.32.3.152:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJcPxa4UbeLxj1SWXFnwAA-go"]
[Thu Jul 30 12:27:13.241641 2026] [security2:error] [pid 738779:tid 739018] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuJcfxa4UbeLxj1SWXFsAAAAPI"]
[Thu Jul 30 12:27:13.241750 2026] [security2:error] [pid 738779:tid 739018] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuJcfxa4UbeLxj1SWXFsAAAAPI"]
[Thu Jul 30 12:27:13.282691 2026] [security2:error] [pid 738779:tid 738963] [client 142.93.53.183:62721] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJcfxa4UbeLxj1SWXFsQAAALs"]
[Thu Jul 30 12:27:13.413180 2026] [security2:error] [pid 738779:tid 738952] [client 52.238.199.152:38908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "amuJcfxa4UbeLxj1SWXFtQAAALA"]
[Thu Jul 30 12:27:13.470623 2026] [security2:error] [pid 738779:tid 738975] [client 20.100.169.152:48884] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/1.php"] [unique_id "amuJcfxa4UbeLxj1SWXFtgAAAMc"]
[Thu Jul 30 12:27:13.470752 2026] [security2:error] [pid 738779:tid 738975] [client 20.100.169.152:48884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/1.php"] [unique_id "amuJcfxa4UbeLxj1SWXFtgAAAMc"]
[Thu Jul 30 12:27:13.470845 2026] [security2:error] [pid 738779:tid 738975] [client 20.100.169.152:48884] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/1.php"] [unique_id "amuJcfxa4UbeLxj1SWXFtgAAAMc"]
[Thu Jul 30 12:27:13.490750 2026] [core:notice] [pid 738779:tid 738922] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:13.495894 2026] [security2:error] [pid 738779:tid 738943] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/wpgum.php"] [unique_id "amuJcfxa4UbeLxj1SWXFuAAAAKc"]
[Thu Jul 30 12:27:13.495967 2026] [security2:error] [pid 738779:tid 738943] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/wpgum.php"] [unique_id "amuJcfxa4UbeLxj1SWXFuAAAAKc"]
[Thu Jul 30 12:27:13.669152 2026] [security2:error] [pid 738779:tid 739013] [client 142.93.53.183:62727] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJcfxa4UbeLxj1SWXFvAAAAO0"]
[Thu Jul 30 12:27:13.758875 2026] [proxy:error] [pid 738779:tid 738986] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:27:13.758964 2026] [proxy_http:error] [pid 738779:tid 738986] [client 20.52.54.143:10227] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:27:13.759525 2026] [proxy:error] [pid 738779:tid 738986] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:27:13.759570 2026] [proxy_http:error] [pid 738779:tid 738986] [client 20.52.54.143:10227] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:27:13.826557 2026] [security2:error] [pid 738779:tid 738939] [client 20.100.169.152:48865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/about.php"] [unique_id "amuJcfxa4UbeLxj1SWXFvgAAAKM"]
[Thu Jul 30 12:27:13.826667 2026] [security2:error] [pid 738779:tid 738939] [client 20.100.169.152:48865] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/about.php"] [unique_id "amuJcfxa4UbeLxj1SWXFvgAAAKM"]
[Thu Jul 30 12:27:14.058524 2026] [security2:error] [pid 738779:tid 739016] [client 142.93.53.183:62736] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/vendor/livewire/plugins/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJcvxa4UbeLxj1SWXFxAAAAPA"]
[Thu Jul 30 12:27:14.215462 2026] [security2:error] [pid 738779:tid 738935] [client 52.238.199.152:38848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuJcvxa4UbeLxj1SWXFxgAAAJ8"]
[Thu Jul 30 12:27:14.238110 2026] [security2:error] [pid 738779:tid 738945] [client 20.100.169.152:44138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/admin.php"] [unique_id "amuJcvxa4UbeLxj1SWXFxwAAAKk"]
[Thu Jul 30 12:27:14.238198 2026] [security2:error] [pid 738779:tid 738945] [client 20.100.169.152:44138] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/admin.php"] [unique_id "amuJcvxa4UbeLxj1SWXFxwAAAKk"]
[Thu Jul 30 12:27:14.448175 2026] [security2:error] [pid 738779:tid 738936] [client 142.93.53.183:62740] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/vendor/livewire/plugins/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJcvxa4UbeLxj1SWXFywAAAKA"]
[Thu Jul 30 12:27:14.552862 2026] [security2:error] [pid 738779:tid 738983] [client 20.100.169.152:61538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/edit.php"] [unique_id "amuJcvxa4UbeLxj1SWXFzAAAAM8"]
[Thu Jul 30 12:27:14.552991 2026] [security2:error] [pid 738779:tid 738983] [client 20.100.169.152:61538] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/edit.php"] [unique_id "amuJcvxa4UbeLxj1SWXFzAAAAM8"]
[Thu Jul 30 12:27:14.839897 2026] [security2:error] [pid 738779:tid 738990] [client 142.93.53.183:62746] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/vendor/livewire/plugins/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJcvxa4UbeLxj1SWXF0AAAANY"]
[Thu Jul 30 12:27:15.048529 2026] [security2:error] [pid 738779:tid 738805] [remote 192.250.239.173:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.239.250.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "azeempinksalt.com"] [uri "/wp-login.php"] [unique_id "amuJc_xa4UbeLxj1SWXF1AAAhhk"]
[Thu Jul 30 12:27:15.230403 2026] [security2:error] [pid 738779:tid 739019] [client 142.93.53.183:62748] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/template/lightweight/fonts/Raleway/ONIC_ESPORT/haxorcgiapi/perl.haxor"] [unique_id "amuJc_xa4UbeLxj1SWXF2AAAAPM"]
[Thu Jul 30 12:27:15.487851 2026] [security2:error] [pid 738779:tid 738965] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/ywwbf.php"] [unique_id "amuJc_xa4UbeLxj1SWXF3wAAAL0"]
[Thu Jul 30 12:27:15.487939 2026] [security2:error] [pid 738779:tid 738965] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/ywwbf.php"] [unique_id "amuJc_xa4UbeLxj1SWXF3wAAAL0"]
[Thu Jul 30 12:27:15.622068 2026] [security2:error] [pid 738779:tid 738950] [client 142.93.53.183:62752] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/template/lightweight/fonts/Raleway/ONIC_ESPORT/haxorcgiapi/py.haxor"] [unique_id "amuJc_xa4UbeLxj1SWXF4AAAAK4"]
[Thu Jul 30 12:27:15.660420 2026] [security2:error] [pid 738779:tid 738929] [client 52.238.199.152:38899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-admin/images/index.php"] [unique_id "amuJc_xa4UbeLxj1SWXF5AAAAJk"]
[Thu Jul 30 12:27:16.012794 2026] [security2:error] [pid 738779:tid 738962] [client 142.93.53.183:62753] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/template/lightweight/fonts/Raleway/ONIC_ESPORT/haxorcgiapi/bash.haxor"] [unique_id "amuJdPxa4UbeLxj1SWXF5wAAALo"]
[Thu Jul 30 12:27:16.218946 2026] [security2:error] [pid 738779:tid 738931] [client 36.32.3.152:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJc_xa4UbeLxj1SWXF5QAAmx0"]
[Thu Jul 30 12:27:16.341168 2026] [security2:error] [pid 738779:tid 738917] [client 20.52.54.143:10209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/alfa.php"] [unique_id "amuJdPxa4UbeLxj1SWXF7gAAAI0"]
[Thu Jul 30 12:27:16.400794 2026] [security2:error] [pid 738779:tid 739024] [client 142.93.53.183:62757] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/tmp_images/alfacgiapi/perl.alfa"] [unique_id "amuJdPxa4UbeLxj1SWXF7wAAAPg"]
[Thu Jul 30 12:27:16.782267 2026] [security2:error] [pid 738779:tid 738954] [client 142.93.53.183:62761] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/elementor/includes/elements/cache/mr_skk/alfacgiapi/perl.alfa"] [unique_id "amuJdPxa4UbeLxj1SWXF-AAAALI"]
[Thu Jul 30 12:27:17.023971 2026] [security2:error] [pid 738779:tid 738958] [client 103.215.74.26:41722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-login.php"] [unique_id "amuJdPxa4UbeLxj1SWXF9wAAALY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:27:17.165088 2026] [security2:error] [pid 738779:tid 738935] [client 142.93.53.183:62764] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/languages/plugins/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJdfxa4UbeLxj1SWXF_wAAAJ8"]
[Thu Jul 30 12:27:17.215271 2026] [security2:error] [pid 738779:tid 738911] [client 2a03:2880:f800:3d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJdPxa4UbeLxj1SWXF8wAAhxs"]
[Thu Jul 30 12:27:17.267905 2026] [security2:error] [pid 738779:tid 738995] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/xoldj.php"] [unique_id "amuJdfxa4UbeLxj1SWXGAwAAANs"]
[Thu Jul 30 12:27:17.268031 2026] [security2:error] [pid 738779:tid 738995] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/xoldj.php"] [unique_id "amuJdfxa4UbeLxj1SWXGAwAAANs"]
[Thu Jul 30 12:27:17.558301 2026] [security2:error] [pid 738779:tid 738915] [client 142.93.53.183:62766] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/languages/plugins/SEOBARBAR_DATA/alfacgiapi/py.alfa"] [unique_id "amuJdfxa4UbeLxj1SWXGBAAAAIs"]
[Thu Jul 30 12:27:17.646382 2026] [security2:error] [pid 738779:tid 739036] [client 52.238.199.152:17777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-admin/network/about.php"] [unique_id "amuJdfxa4UbeLxj1SWXGCAAAAQQ"]
[Thu Jul 30 12:27:17.786918 2026] [security2:error] [pid 738779:tid 738942] [client 103.215.74.26:41730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/blog/wp-login.php"] [unique_id "amuJdfxa4UbeLxj1SWXGDAAAAKY"], referer: https://carnetdeshopping.com/blog/
[Thu Jul 30 12:27:17.875183 2026] [security2:error] [pid 738779:tid 739028] [client 52.91.80.94:50078] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "milfordauto.com"] [uri "/"] [unique_id "amuJdfxa4UbeLxj1SWXGDQAAAPw"]
[Thu Jul 30 12:27:17.949038 2026] [security2:error] [pid 738779:tid 738933] [client 142.93.53.183:62769] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/languages/plugins/SEOBARBAR_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJdfxa4UbeLxj1SWXGDgAAAJ0"]
[Thu Jul 30 12:27:18.021135 2026] [core:error] [pid 738779:tid 738966] [client 158.173.25.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://appliancerepairservice.one/
[Thu Jul 30 12:27:18.021158 2026] [core:error] [pid 738779:tid 738966] [client 158.173.25.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://appliancerepairservice.one/
[Thu Jul 30 12:27:18.336484 2026] [security2:error] [pid 738779:tid 738965] [client 142.93.53.183:62771] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/timeline-awesome/public/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJdvxa4UbeLxj1SWXGGAAAAL0"]
[Thu Jul 30 12:27:18.535479 2026] [security2:error] [pid 738779:tid 739001] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/f35.php"] [unique_id "amuJdvxa4UbeLxj1SWXGGgAAAOE"]
[Thu Jul 30 12:27:18.535600 2026] [security2:error] [pid 738779:tid 739001] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/f35.php"] [unique_id "amuJdvxa4UbeLxj1SWXGGgAAAOE"]
[Thu Jul 30 12:27:18.552595 2026] [security2:error] [pid 738779:tid 738953] [client 103.215.74.26:41740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wordpress/wp-login.php"] [unique_id "amuJdvxa4UbeLxj1SWXGGwAAALE"], referer: https://carnetdeshopping.com/wordpress/
[Thu Jul 30 12:27:18.574267 2026] [proxy:error] [pid 738779:tid 738984] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:27:18.574341 2026] [proxy_http:error] [pid 738779:tid 738984] [client 20.52.54.143:10176] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:27:18.574884 2026] [proxy:error] [pid 738779:tid 738984] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:27:18.574927 2026] [proxy_http:error] [pid 738779:tid 738984] [client 20.52.54.143:10176] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:27:18.634045 2026] [security2:error] [pid 738779:tid 739031] [client 36.32.3.152:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJdvxa4UbeLxj1SWXGFQAA_zQ"]
[Thu Jul 30 12:27:18.730254 2026] [security2:error] [pid 738779:tid 739011] [client 142.93.53.183:62772] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/timeline-awesome/public/SEOBARBAR_DATA/alfacgiapi/py.alfa"] [unique_id "amuJdvxa4UbeLxj1SWXGIAAAAOs"]
[Thu Jul 30 12:27:18.774777 2026] [core:notice] [pid 738779:tid 738959] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:18.864429 2026] [security2:error] [pid 738779:tid 738926] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/gk.php"] [unique_id "amuJdvxa4UbeLxj1SWXGIgAAAJY"]
[Thu Jul 30 12:27:18.864573 2026] [security2:error] [pid 738779:tid 738926] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/gk.php"] [unique_id "amuJdvxa4UbeLxj1SWXGIgAAAJY"]
[Thu Jul 30 12:27:19.021804 2026] [security2:error] [pid 738779:tid 738957] [client 52.238.199.152:59076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/xpw.php"] [unique_id "amuJd_xa4UbeLxj1SWXGJgAAALU"]
[Thu Jul 30 12:27:19.120897 2026] [security2:error] [pid 738779:tid 738952] [client 142.93.53.183:62777] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/timeline-awesome/public/SEOBARBAR_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJd_xa4UbeLxj1SWXGJwAAALA"]
[Thu Jul 30 12:27:19.165050 2026] [security2:error] [pid 738779:tid 738931] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/584062352875874akp.php"] [unique_id "amuJd_xa4UbeLxj1SWXGKAAAAJs"]
[Thu Jul 30 12:27:19.165148 2026] [security2:error] [pid 738779:tid 738931] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/584062352875874akp.php"] [unique_id "amuJd_xa4UbeLxj1SWXGKAAAAJs"]
[Thu Jul 30 12:27:19.335596 2026] [security2:error] [pid 738779:tid 739010] [client 103.215.74.26:41744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp/wp-login.php"] [unique_id "amuJd_xa4UbeLxj1SWXGLAAAAOo"], referer: https://carnetdeshopping.com/wp/
[Thu Jul 30 12:27:19.439714 2026] [security2:error] [pid 738779:tid 739006] [client 20.52.54.143:9983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amuJd_xa4UbeLxj1SWXGMAAAAOY"]
[Thu Jul 30 12:27:19.463575 2026] [security2:error] [pid 738779:tid 738986] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/wper3.php"] [unique_id "amuJd_xa4UbeLxj1SWXGMQAAANI"]
[Thu Jul 30 12:27:19.463670 2026] [security2:error] [pid 738779:tid 738986] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/wper3.php"] [unique_id "amuJd_xa4UbeLxj1SWXGMQAAANI"]
[Thu Jul 30 12:27:19.494039 2026] [security2:error] [pid 738779:tid 738934] [client 142.93.53.183:62780] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/pubIds/doi/locale/cs_CZ/ERENUSE/Erencgiapi/perl.Eren"] [unique_id "amuJd_xa4UbeLxj1SWXGMgAAAJ4"]
[Thu Jul 30 12:27:19.731440 2026] [security2:error] [pid 738779:tid 738973] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/bthil.php"] [unique_id "amuJd_xa4UbeLxj1SWXGNgAAAMU"]
[Thu Jul 30 12:27:19.731539 2026] [security2:error] [pid 738779:tid 738973] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/bthil.php"] [unique_id "amuJd_xa4UbeLxj1SWXGNgAAAMU"]
[Thu Jul 30 12:27:19.884725 2026] [security2:error] [pid 738779:tid 739015] [client 142.93.53.183:62786] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/pubIds/doi/locale/cs_CZ/ERENUSE/Erencgiapi/py.Eren"] [unique_id "amuJd_xa4UbeLxj1SWXGNwAAAO8"]
[Thu Jul 30 12:27:20.013044 2026] [security2:error] [pid 738779:tid 738911] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/wyzer1.php"] [unique_id "amuJePxa4UbeLxj1SWXGPgAAAIc"]
[Thu Jul 30 12:27:20.013151 2026] [security2:error] [pid 738779:tid 738911] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/wyzer1.php"] [unique_id "amuJePxa4UbeLxj1SWXGPgAAAIc"]
[Thu Jul 30 12:27:20.101460 2026] [security2:error] [pid 738779:tid 738978] [client 103.215.74.26:41760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/cms/wp-login.php"] [unique_id "amuJePxa4UbeLxj1SWXGQgAAAMo"], referer: https://carnetdeshopping.com/cms/
[Thu Jul 30 12:27:20.258661 2026] [security2:error] [pid 738779:tid 739008] [client 142.93.53.183:62791] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/pubIds/doi/locale/cs_CZ/ERENUSE/Erencgiapi/bash.Eren"] [unique_id "amuJePxa4UbeLxj1SWXGRgAAAOg"]
[Thu Jul 30 12:27:20.307960 2026] [security2:error] [pid 738779:tid 739025] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/mh.php"] [unique_id "amuJePxa4UbeLxj1SWXGRwAAAPk"]
[Thu Jul 30 12:27:20.308080 2026] [security2:error] [pid 738779:tid 739025] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/mh.php"] [unique_id "amuJePxa4UbeLxj1SWXGRwAAAPk"]
[Thu Jul 30 12:27:20.395296 2026] [security2:error] [pid 738779:tid 738935] [client 20.52.54.143:9953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuJePxa4UbeLxj1SWXGSQAAAJ8"]
[Thu Jul 30 12:27:20.651826 2026] [security2:error] [pid 738779:tid 738927] [client 142.93.53.183:62792] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/files/journals/2/articles/566/submission/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuJePxa4UbeLxj1SWXGTgAAAJc"]
[Thu Jul 30 12:27:20.697499 2026] [security2:error] [pid 738779:tid 738812] [remote 36.32.3.152:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJePxa4UbeLxj1SWXGSAABACA"]
[Thu Jul 30 12:27:20.863595 2026] [security2:error] [pid 738779:tid 738933] [client 103.215.74.26:41764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/site/wp-login.php"] [unique_id "amuJePxa4UbeLxj1SWXGUgAAAJ0"], referer: https://carnetdeshopping.com/site/
[Thu Jul 30 12:27:21.040275 2026] [security2:error] [pid 738779:tid 738955] [client 142.93.53.183:62797] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/files/journals/2/articles/566/submission/LEVIATHAN/haxorcgiapi/py.haxor"] [unique_id "amuJefxa4UbeLxj1SWXGVgAAALM"]
[Thu Jul 30 12:27:21.072002 2026] [security2:error] [pid 738779:tid 738909] [client 20.52.54.143:9355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amuJefxa4UbeLxj1SWXGVwAAAIU"]
[Thu Jul 30 12:27:21.268560 2026] [security2:error] [pid 738779:tid 738970] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuJefxa4UbeLxj1SWXGWgAAAMI"]
[Thu Jul 30 12:27:21.268660 2026] [security2:error] [pid 738779:tid 738970] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuJefxa4UbeLxj1SWXGWgAAAMI"]
[Thu Jul 30 12:27:21.412325 2026] [security2:error] [pid 738779:tid 738999] [client 52.238.199.152:38864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-cron.php"] [unique_id "amuJefxa4UbeLxj1SWXGXgAAAN8"]
[Thu Jul 30 12:27:21.433111 2026] [security2:error] [pid 738779:tid 739031] [client 142.93.53.183:62799] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/files/journals/2/articles/566/submission/LEVIATHAN/haxorcgiapi/bash.haxor"] [unique_id "amuJefxa4UbeLxj1SWXGXwAAAP8"]
[Thu Jul 30 12:27:21.518759 2026] [security2:error] [pid 738779:tid 739011] [client 172.213.244.85:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "tiger388.shop"] [uri "/1.php"] [unique_id "amuJefxa4UbeLxj1SWXGYAAAAOs"]
[Thu Jul 30 12:27:21.518890 2026] [security2:error] [pid 738779:tid 739011] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/1.php"] [unique_id "amuJefxa4UbeLxj1SWXGYAAAAOs"]
[Thu Jul 30 12:27:21.519039 2026] [security2:error] [pid 738779:tid 739011] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/1.php"] [unique_id "amuJefxa4UbeLxj1SWXGYAAAAOs"]
[Thu Jul 30 12:27:21.590782 2026] [core:notice] [pid 738779:tid 738981] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:21.613230 2026] [security2:error] [pid 738779:tid 739016] [client 57.141.0.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "journeywomenscenter.org"] [uri "/index.php"] [unique_id "amuJd_xa4UbeLxj1SWXGPQAAAPA"]
[Thu Jul 30 12:27:21.629400 2026] [security2:error] [pid 738779:tid 738953] [client 103.215.74.26:41774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/main/wp-login.php"] [unique_id "amuJefxa4UbeLxj1SWXGZQAAALE"], referer: https://carnetdeshopping.com/main/
[Thu Jul 30 12:27:21.814246 2026] [security2:error] [pid 738779:tid 738971] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/chosen.php"] [unique_id "amuJefxa4UbeLxj1SWXGaQAAAMM"]
[Thu Jul 30 12:27:21.814352 2026] [security2:error] [pid 738779:tid 738971] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/chosen.php"] [unique_id "amuJefxa4UbeLxj1SWXGaQAAAMM"]
[Thu Jul 30 12:27:22.063596 2026] [security2:error] [pid 738779:tid 738917] [client 57.141.0.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuJefxa4UbeLxj1SWXGbQAAAI0"]
[Thu Jul 30 12:27:22.066565 2026] [security2:error] [pid 738779:tid 738943] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/sd.php"] [unique_id "amuJevxa4UbeLxj1SWXGcgAAAKc"]
[Thu Jul 30 12:27:22.066653 2026] [security2:error] [pid 738779:tid 738943] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/sd.php"] [unique_id "amuJevxa4UbeLxj1SWXGcgAAAKc"]
[Thu Jul 30 12:27:22.086043 2026] [security2:error] [pid 738779:tid 738952] [client 142.93.53.183:62806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toscanamall.com"] [uri "/kcfinder/upload.php"] [unique_id "amuJefxa4UbeLxj1SWXGagAAALA"]
[Thu Jul 30 12:27:22.189276 2026] [security2:error] [pid 738779:tid 738958] [client 62.102.148.166:59484] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuJevxa4UbeLxj1SWXGcwAAALY"]
[Thu Jul 30 12:27:22.189389 2026] [security2:error] [pid 738779:tid 738958] [client 62.102.148.166:59484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuJevxa4UbeLxj1SWXGcwAAALY"]
[Thu Jul 30 12:27:22.279944 2026] [security2:error] [pid 738779:tid 738923] [client 142.93.53.183:62806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toscanamall.com"] [uri "/admin/kcfinder/upload.php"] [unique_id "amuJevxa4UbeLxj1SWXGdAAAAJM"]
[Thu Jul 30 12:27:22.342820 2026] [security2:error] [pid 738779:tid 738914] [client 103.215.74.26:41778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/new/wp-login.php"] [unique_id "amuJevxa4UbeLxj1SWXGeAAAAIo"], referer: https://carnetdeshopping.com/new/
[Thu Jul 30 12:27:22.356236 2026] [security2:error] [pid 738779:tid 738997] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/z60.php"] [unique_id "amuJevxa4UbeLxj1SWXGeQAAAN0"]
[Thu Jul 30 12:27:22.356330 2026] [security2:error] [pid 738779:tid 738997] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/z60.php"] [unique_id "amuJevxa4UbeLxj1SWXGeQAAAN0"]
[Thu Jul 30 12:27:22.473030 2026] [security2:error] [pid 738779:tid 738911] [client 142.93.53.183:62806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toscanamall.com"] [uri "/js/kcfinder/upload.php"] [unique_id "amuJevxa4UbeLxj1SWXGegAAAIc"]
[Thu Jul 30 12:27:22.619060 2026] [security2:error] [pid 738779:tid 739010] [client 20.52.54.143:9933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/edit.php"] [unique_id "amuJevxa4UbeLxj1SWXGfgAAAOo"]
[Thu Jul 30 12:27:22.640721 2026] [security2:error] [pid 738779:tid 738951] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/home.php"] [unique_id "amuJevxa4UbeLxj1SWXGfwAAAK8"]
[Thu Jul 30 12:27:22.640814 2026] [security2:error] [pid 738779:tid 738951] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/home.php"] [unique_id "amuJevxa4UbeLxj1SWXGfwAAAK8"]
[Thu Jul 30 12:27:22.667106 2026] [security2:error] [pid 738779:tid 738948] [client 142.93.53.183:62806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toscanamall.com"] [uri "/lists/admin/plugins/CKEditorPlugin/kcfinder/upload.php"] [unique_id "amuJevxa4UbeLxj1SWXGgAAAAKw"]
[Thu Jul 30 12:27:22.804106 2026] [security2:error] [pid 738779:tid 738940] [client 37.120.155.179:59944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.155.120.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuJevxa4UbeLxj1SWXGgQAAAKQ"]
[Thu Jul 30 12:27:22.804234 2026] [security2:error] [pid 738779:tid 738940] [client 37.120.155.179:59944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuJevxa4UbeLxj1SWXGgQAAAKQ"]
[Thu Jul 30 12:27:22.819019 2026] [security2:error] [pid 738779:tid 738841] [remote 74.7.241.59:35652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuJevxa4UbeLxj1SWXGggAA6D0"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/theme-builder/documents
[Thu Jul 30 12:27:22.859081 2026] [security2:error] [pid 738779:tid 738942] [client 142.93.53.183:62806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toscanamall.com"] [uri "/css/kcfinder/upload.php"] [unique_id "amuJevxa4UbeLxj1SWXGhAAAAKY"]
[Thu Jul 30 12:27:22.877579 2026] [security2:error] [pid 738779:tid 738976] [client 103.215.74.26:62824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-login.php"] [unique_id "amuJevxa4UbeLxj1SWXGhQAAAMg"], referer: http://carnetdeshopping.com/
[Thu Jul 30 12:27:23.052295 2026] [security2:error] [pid 738779:tid 739028] [client 142.93.53.183:62806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toscanamall.com"] [uri "/assets/kcfinder/upload.php"] [unique_id "amuJe_xa4UbeLxj1SWXGiQAAAPw"]
[Thu Jul 30 12:27:23.245543 2026] [security2:error] [pid 738779:tid 738921] [client 142.93.53.183:62806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toscanamall.com"] [uri "/vendor/kcfinder/upload.php"] [unique_id "amuJe_xa4UbeLxj1SWXGjQAAAJE"]
[Thu Jul 30 12:27:23.325757 2026] [proxy:error] [pid 738779:tid 739032] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:27:23.325836 2026] [proxy_http:error] [pid 738779:tid 739032] [client 20.52.54.143:10123] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:27:23.326405 2026] [proxy:error] [pid 738779:tid 739032] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:27:23.326450 2026] [proxy_http:error] [pid 738779:tid 739032] [client 20.52.54.143:10123] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:27:23.377810 2026] [security2:error] [pid 738779:tid 738955] [client 103.215.74.26:62826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/blog/wp-login.php"] [unique_id "amuJe_xa4UbeLxj1SWXGkAAAALM"], referer: http://carnetdeshopping.com/blog/
[Thu Jul 30 12:27:23.438138 2026] [security2:error] [pid 738779:tid 738912] [client 142.93.53.183:62806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toscanamall.com"] [uri "/js/vendor/kcfinder/upload.php"] [unique_id "amuJe_xa4UbeLxj1SWXGkwAAAIg"]
[Thu Jul 30 12:27:23.484045 2026] [security2:error] [pid 738779:tid 739025] [client 38.190.144.4:52477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJe_xa4UbeLxj1SWXGlgAAAPk"]
[Thu Jul 30 12:27:23.484167 2026] [security2:error] [pid 738779:tid 739025] [client 38.190.144.4:52477] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJe_xa4UbeLxj1SWXGlgAAAPk"]
[Thu Jul 30 12:27:23.632129 2026] [security2:error] [pid 738779:tid 738947] [client 142.93.53.183:62806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toscanamall.com"] [uri "/ckeditor/kcfinder/upload.php"] [unique_id "amuJe_xa4UbeLxj1SWXGlwAAAKs"]
[Thu Jul 30 12:27:23.712490 2026] [security2:error] [pid 738779:tid 738929] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/ws58.php"] [unique_id "amuJe_xa4UbeLxj1SWXGnAAAAJk"]
[Thu Jul 30 12:27:23.712591 2026] [security2:error] [pid 738779:tid 738929] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/ws58.php"] [unique_id "amuJe_xa4UbeLxj1SWXGnAAAAJk"]
[Thu Jul 30 12:27:23.825702 2026] [security2:error] [pid 738779:tid 738920] [client 142.93.53.183:62806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toscanamall.com"] [uri "/webboard/plugins/editors/kcfinder/upload.php"] [unique_id "amuJe_xa4UbeLxj1SWXGngAAAJA"]
[Thu Jul 30 12:27:23.871530 2026] [security2:error] [pid 738779:tid 739016] [client 103.215.74.26:62840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wordpress/wp-login.php"] [unique_id "amuJe_xa4UbeLxj1SWXGnwAAAPA"], referer: http://carnetdeshopping.com/wordpress/
[Thu Jul 30 12:27:23.963355 2026] [security2:error] [pid 738779:tid 738860] [remote 151.158.180.11:47826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.180.158.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gkc.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuJe_xa4UbeLxj1SWXGpgAAqFA"]
[Thu Jul 30 12:27:23.981564 2026] [core:notice] [pid 738779:tid 738845] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:23.986359 2026] [security2:error] [pid 738779:tid 738963] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/gulu.php"] [unique_id "amuJe_xa4UbeLxj1SWXGqAAAALs"]
[Thu Jul 30 12:27:23.986440 2026] [security2:error] [pid 738779:tid 738963] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/gulu.php"] [unique_id "amuJe_xa4UbeLxj1SWXGqAAAALs"]
[Thu Jul 30 12:27:24.011708 2026] [security2:error] [pid 738779:tid 739019] [client 36.32.3.152:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJe_xa4UbeLxj1SWXGmwAA800"]
[Thu Jul 30 12:27:24.019449 2026] [security2:error] [pid 738779:tid 738930] [client 142.93.53.183:62806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toscanamall.com"] [uri "/admin/editor/kcfinder/upload.php"] [unique_id "amuJfPxa4UbeLxj1SWXGqQAAAJo"]
[Thu Jul 30 12:27:24.025456 2026] [security2:error] [pid 738779:tid 738858] [remote 65.60.36.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.36.60.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "megasuppliesdistrict.com"] [uri "/wp-login.php"] [unique_id "amuJfPxa4UbeLxj1SWXGqgAAzU4"]
[Thu Jul 30 12:27:24.085182 2026] [core:notice] [pid 738779:tid 738985] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:24.212779 2026] [security2:error] [pid 738779:tid 738975] [client 142.93.53.183:62806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toscanamall.com"] [uri "/ckeditor/plugins/kcfinder/upload.php"] [unique_id "amuJfPxa4UbeLxj1SWXGrwAAAMc"]
[Thu Jul 30 12:27:24.289415 2026] [security2:error] [pid 738779:tid 738917] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuJfPxa4UbeLxj1SWXGsAAAAI0"]
[Thu Jul 30 12:27:24.289526 2026] [security2:error] [pid 738779:tid 738917] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuJfPxa4UbeLxj1SWXGsAAAAI0"]
[Thu Jul 30 12:27:24.350123 2026] [security2:error] [pid 738779:tid 738986] [client 103.215.74.26:62850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp/wp-login.php"] [unique_id "amuJfPxa4UbeLxj1SWXGsQAAANI"], referer: http://carnetdeshopping.com/wp/
[Thu Jul 30 12:27:24.406556 2026] [security2:error] [pid 738779:tid 738962] [client 142.93.53.183:62806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toscanamall.com"] [uri "/admin-panel/vendor/kcfinder/upload.php"] [unique_id "amuJfPxa4UbeLxj1SWXGsgAAALo"]
[Thu Jul 30 12:27:24.567775 2026] [security2:error] [pid 738779:tid 738973] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/wpls.php"] [unique_id "amuJfPxa4UbeLxj1SWXGtwAAAMU"]
[Thu Jul 30 12:27:24.567873 2026] [security2:error] [pid 738779:tid 738973] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/wpls.php"] [unique_id "amuJfPxa4UbeLxj1SWXGtwAAAMU"]
[Thu Jul 30 12:27:24.599614 2026] [security2:error] [pid 738779:tid 738958] [client 142.93.53.183:62806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toscanamall.com"] [uri "/assets/plugin/kcfinder/upload.php"] [unique_id "amuJfPxa4UbeLxj1SWXGuAAAALY"]
[Thu Jul 30 12:27:24.792579 2026] [security2:error] [pid 738779:tid 739035] [client 142.93.53.183:62806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toscanamall.com"] [uri "/plugins/kcfinder/upload.php"] [unique_id "amuJfPxa4UbeLxj1SWXGvwAAAQM"]
[Thu Jul 30 12:27:24.807577 2026] [mpm_event:notice] [pid 8929:tid 8929] AH00493: SIGUSR1 received. Doing graceful restart
[Thu Jul 30 12:27:24.859827 2026] [security2:error] [pid 738779:tid 738924] [client 52.238.199.152:41254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/cah.php"] [unique_id "amuJfPxa4UbeLxj1SWXGwAAAAJQ"]
[Thu Jul 30 12:27:25.398904 2026] [security2:error] [pid 738779:tid 738863] [remote 57.141.0.17:49066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuJffxa4UbeLxj1SWXGwQAAoVM"], referer: https://igetvape-australia.com/product-category/iget-bar-pro/?add-to-cart=112
[Thu Jul 30 12:27:25.891011 2026] [:notice] [pid 738754:tid 738754] [host root@sh00085.hostgator.com] mod_lsapi: Selfstarter 738754 stopped
[Thu Jul 30 12:27:28.220860 2026] [lsapi:notice] [pid 8929:tid 8929] mod_lsapi: version 1.1-92
[Thu Jul 30 12:27:28.223609 2026] [:notice] [pid 751894:tid 751894] [host root@sh00085.hostgator.com] mod_lsapi: Selfstarter 751894 started
[Thu Jul 30 12:27:28.615653 2026] [ssl:warn] [pid 8929:tid 8929] AH01909: localhost:8443:0 server certificate does NOT include an ID which matches the server name
[Thu Jul 30 12:27:28.623001 2026] [qos:notice] [pid 8929:tid 8929] mod_qos(007): calculated MaxClients/MaxRequestWorkers (max connections): 6144, applied limit: 2048 (QS_MaxClients)
[Thu Jul 30 12:27:28.790809 2026] [http2:info] [pid 8929:tid 8929] AH03090: mod_http2 (v2.0.42, feats=CHPRIO+SHA256+INVHD+DWINS, nghttp2 1.69.0), initializing...
[Thu Jul 30 12:27:28.794153 2026] [mpm_event:notice] [pid 8929:tid 8929] AH00489: Apache/2.4.68 (cPanel) OpenSSL/3.5.5 Apache mod_qos/11.76 mod_bwlimited/1.4 mod_fcgid/2.3.9 mod_rbld2.0 configured -- resuming normal operations
[Thu Jul 30 12:27:28.794172 2026] [core:notice] [pid 8929:tid 8929] AH00094: Command line: '/usr/sbin/httpd'
[Thu Jul 30 12:27:29.840411 2026] [http2:info] [pid 751901:tid 751901] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 12:27:29.868502 2026] [security2:error] [pid 751901:tid 752032] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/php.php"] [unique_id "amuJgSrT982lovRn7gmxCAAAAAE"]
[Thu Jul 30 12:27:29.868814 2026] [security2:error] [pid 751901:tid 752031] [client 103.215.74.26:62856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/cms/wp-login.php"] [unique_id "amuJgSrT982lovRn7gmxBwAAAAA"], referer: http://carnetdeshopping.com/cms/
[Thu Jul 30 12:27:29.868882 2026] [security2:error] [pid 751901:tid 752032] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/php.php"] [unique_id "amuJgSrT982lovRn7gmxCAAAAAE"]
[Thu Jul 30 12:27:29.869809 2026] [core:notice] [pid 751901:tid 752037] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:29.870624 2026] [security2:error] [pid 751901:tid 752039] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuJgSrT982lovRn7gmxCwAAAAg"]
[Thu Jul 30 12:27:29.870763 2026] [security2:error] [pid 751901:tid 752039] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuJgSrT982lovRn7gmxCwAAAAg"]
[Thu Jul 30 12:27:29.964844 2026] [security2:error] [pid 751901:tid 752048] [client 103.82.26.211:55527] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.tereasshop.com"] [uri "/___proxy_subdomain_cpcalendars/"] [unique_id "amuJgSrT982lovRn7gmxEAAAABE"]
[Thu Jul 30 12:27:30.060727 2026] [security2:error] [pid 751901:tid 751908] [remote 216.73.216.152:40909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuJgirT982lovRn7gmxFgAAGQY"]
[Thu Jul 30 12:27:30.120360 2026] [security2:error] [pid 751901:tid 752042] [client 52.238.199.152:41244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/cong.php"] [unique_id "amuJgirT982lovRn7gmxIgAAAAs"]
[Thu Jul 30 12:27:30.121229 2026] [security2:error] [pid 751901:tid 752083] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/100.php"] [unique_id "amuJgirT982lovRn7gmxKAAAADQ"]
[Thu Jul 30 12:27:30.121294 2026] [security2:error] [pid 751901:tid 752080] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuJgirT982lovRn7gmxKQAAADE"]
[Thu Jul 30 12:27:30.121456 2026] [security2:error] [pid 751901:tid 752083] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/100.php"] [unique_id "amuJgirT982lovRn7gmxKAAAADQ"]
[Thu Jul 30 12:27:30.121633 2026] [security2:error] [pid 751901:tid 752080] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuJgirT982lovRn7gmxKQAAADE"]
[Thu Jul 30 12:27:30.123158 2026] [core:notice] [pid 751901:tid 751917] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:30.317295 2026] [security2:error] [pid 751901:tid 752100] [client 103.82.26.211:55982] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.tereasshop.com"] [uri "/___proxy_subdomain_cpcalendars/wp-json/batch/v1"] [unique_id "amuJgirT982lovRn7gmxOQAAAEU"]
[Thu Jul 30 12:27:30.352702 2026] [security2:error] [pid 751901:tid 752114] [client 103.215.74.26:62858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/site/wp-login.php"] [unique_id "amuJgirT982lovRn7gmxOgAAAFM"], referer: http://carnetdeshopping.com/site/
[Thu Jul 30 12:27:30.375706 2026] [security2:error] [pid 751901:tid 752118] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuJgirT982lovRn7gmxPQAAAFc"]
[Thu Jul 30 12:27:30.375816 2026] [security2:error] [pid 751901:tid 752118] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuJgirT982lovRn7gmxPQAAAFc"]
[Thu Jul 30 12:27:30.380784 2026] [security2:error] [pid 751901:tid 751918] [remote 57.141.0.5:37904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/index/login"] [unique_id "amuJgirT982lovRn7gmxJwAAGxA"]
[Thu Jul 30 12:27:30.392005 2026] [security2:error] [pid 751901:tid 752043] [client 220.181.108.103:45077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.108.181.220.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/ELTERA/user/register"] [unique_id "amuJgSrT982lovRn7gmxDAAAAAw"]
[Thu Jul 30 12:27:30.483374 2026] [security2:error] [pid 751901:tid 752040] [client 36.32.3.152:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJgirT982lovRn7gmxJAAACQ4"]
[Thu Jul 30 12:27:30.611334 2026] [security2:error] [pid 751901:tid 752146] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/media.php"] [unique_id "amuJgirT982lovRn7gmxSwAAAHM"]
[Thu Jul 30 12:27:30.611472 2026] [security2:error] [pid 751901:tid 752146] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/media.php"] [unique_id "amuJgirT982lovRn7gmxSwAAAHM"]
[Thu Jul 30 12:27:30.692889 2026] [proxy:error] [pid 751901:tid 752045] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:27:30.692954 2026] [proxy_http:error] [pid 751901:tid 752045] [client 20.52.54.143:10201] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:27:30.693593 2026] [proxy:error] [pid 751901:tid 752045] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:27:30.693638 2026] [proxy_http:error] [pid 751901:tid 752045] [client 20.52.54.143:10201] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:27:30.781498 2026] [security2:error] [pid 751901:tid 752091] [client 57.141.0.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJgirT982lovRn7gmxMAAAADw"]
[Thu Jul 30 12:27:30.868658 2026] [security2:error] [pid 751901:tid 752039] [client 103.215.74.26:62864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/main/wp-login.php"] [unique_id "amuJgirT982lovRn7gmxTwAAAAg"], referer: http://carnetdeshopping.com/main/
[Thu Jul 30 12:27:31.014748 2026] [security2:error] [pid 751901:tid 752119] [client 57.141.0.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJgirT982lovRn7gmxPgAAAFg"]
[Thu Jul 30 12:27:31.097214 2026] [security2:error] [pid 751901:tid 752031] [client 119.249.100.110:27400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.100.249.119.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/ELTERA/user/register"] [unique_id "amuJgirT982lovRn7gmxTgAAAAA"]
[Thu Jul 30 12:27:31.149887 2026] [security2:error] [pid 751901:tid 752076] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/images.php"] [unique_id "amuJgyrT982lovRn7gmxVwAAAC0"]
[Thu Jul 30 12:27:31.150012 2026] [security2:error] [pid 751901:tid 752076] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/images.php"] [unique_id "amuJgyrT982lovRn7gmxVwAAAC0"]
[Thu Jul 30 12:27:31.209161 2026] [security2:error] [pid 751901:tid 752149] [client 38.190.144.4:52975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJgyrT982lovRn7gmxWAAAAHY"]
[Thu Jul 30 12:27:31.210593 2026] [security2:error] [pid 751901:tid 752149] [client 38.190.144.4:52975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJgyrT982lovRn7gmxWAAAAHY"]
[Thu Jul 30 12:27:31.404632 2026] [security2:error] [pid 751901:tid 752081] [client 103.215.74.26:62876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/new/wp-login.php"] [unique_id "amuJgyrT982lovRn7gmxWgAAADI"], referer: http://carnetdeshopping.com/new/
[Thu Jul 30 12:27:31.606512 2026] [security2:error] [pid 751901:tid 752065] [client 20.52.54.143:10178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/sf.php"] [unique_id "amuJgyrT982lovRn7gmxYgAAACI"]
[Thu Jul 30 12:27:31.987165 2026] [security2:error] [pid 751901:tid 752083] [client 119.249.100.177:21305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.100.249.119.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/ELTERA/user/register"] [unique_id "amuJgyrT982lovRn7gmxWwAAADQ"]
[Thu Jul 30 12:27:32.128923 2026] [core:notice] [pid 751901:tid 751937] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:32.147364 2026] [core:notice] [pid 751901:tid 752046] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:32.354134 2026] [security2:error] [pid 751901:tid 751941] [remote 216.73.216.152:40909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuJhCrT982lovRn7gmxcwAADCc"]
[Thu Jul 30 12:27:32.373659 2026] [security2:error] [pid 751901:tid 752099] [client 85.208.96.211:44350] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/01/22/comunicado-streaming-das-radios-rural-e-cultura-passam-por-manutencao-e-ficam-fora-do-ar/"] [unique_id "amuJhCrT982lovRn7gmxdAAAAEQ"]
[Thu Jul 30 12:27:32.373827 2026] [security2:error] [pid 751901:tid 752099] [client 85.208.96.211:44350] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/01/22/comunicado-streaming-das-radios-rural-e-cultura-passam-por-manutencao-e-ficam-fora-do-ar/"] [unique_id "amuJhCrT982lovRn7gmxdAAAAEQ"]
[Thu Jul 30 12:27:32.465579 2026] [proxy:error] [pid 751901:tid 752103] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:27:32.465674 2026] [proxy_http:error] [pid 751901:tid 752103] [client 20.52.54.143:9387] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:27:32.466611 2026] [proxy:error] [pid 751901:tid 752103] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:27:32.466683 2026] [proxy_http:error] [pid 751901:tid 752103] [client 20.52.54.143:9387] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:27:32.621799 2026] [security2:error] [pid 751901:tid 752100] [client 220.167.233.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJhCrT982lovRn7gmxcgAARSY"]
[Thu Jul 30 12:27:32.642445 2026] [security2:error] [pid 751901:tid 752137] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/BDKR28WP.php"] [unique_id "amuJhCrT982lovRn7gmxfgAAAGo"]
[Thu Jul 30 12:27:32.642573 2026] [security2:error] [pid 751901:tid 752137] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/BDKR28WP.php"] [unique_id "amuJhCrT982lovRn7gmxfgAAAGo"]
[Thu Jul 30 12:27:32.934967 2026] [security2:error] [pid 751901:tid 752142] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/browse.php"] [unique_id "amuJhCrT982lovRn7gmxgAAAAG8"]
[Thu Jul 30 12:27:32.935376 2026] [security2:error] [pid 751901:tid 752142] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/browse.php"] [unique_id "amuJhCrT982lovRn7gmxgAAAAG8"]
[Thu Jul 30 12:27:33.243557 2026] [security2:error] [pid 751901:tid 752057] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/wp-good.php"] [unique_id "amuJhSrT982lovRn7gmxhwAAABo"]
[Thu Jul 30 12:27:33.243696 2026] [security2:error] [pid 751901:tid 752057] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/wp-good.php"] [unique_id "amuJhSrT982lovRn7gmxhwAAABo"]
[Thu Jul 30 12:27:33.267384 2026] [security2:error] [pid 751901:tid 752062] [client 20.52.54.143:9978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wso.php"] [unique_id "amuJhSrT982lovRn7gmxiAAAAB8"]
[Thu Jul 30 12:27:33.557236 2026] [security2:error] [pid 751901:tid 752085] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/8573.php"] [unique_id "amuJhSrT982lovRn7gmxigAAADY"]
[Thu Jul 30 12:27:33.557382 2026] [security2:error] [pid 751901:tid 752085] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/8573.php"] [unique_id "amuJhSrT982lovRn7gmxigAAADY"]
[Thu Jul 30 12:27:33.830005 2026] [security2:error] [pid 751901:tid 752069] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/wp-admin/install.php"] [unique_id "amuJhSrT982lovRn7gmxkgAAACY"]
[Thu Jul 30 12:27:33.830128 2026] [security2:error] [pid 751901:tid 752069] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/wp-admin/install.php"] [unique_id "amuJhSrT982lovRn7gmxkgAAACY"]
[Thu Jul 30 12:27:33.930476 2026] [security2:error] [pid 751901:tid 752125] [client 5.161.75.7:29620] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuJhCrT982lovRn7gmxegAAAF4"], referer: https://globalmarks.pk/
[Thu Jul 30 12:27:34.060305 2026] [security2:error] [pid 751901:tid 752035] [client 20.52.54.143:9979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/ioxi-o.php"] [unique_id "amuJhirT982lovRn7gmxkwAAAAQ"]
[Thu Jul 30 12:27:34.135449 2026] [core:notice] [pid 751901:tid 752119] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:34.143823 2026] [security2:error] [pid 751901:tid 752039] [client 220.167.233.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJhSrT982lovRn7gmxkQAACC4"]
[Thu Jul 30 12:27:34.216863 2026] [security2:error] [pid 751901:tid 752068] [client 52.238.199.152:59085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/Sanskrit.php"] [unique_id "amuJhirT982lovRn7gmxnAAAACU"]
[Thu Jul 30 12:27:34.295330 2026] [security2:error] [pid 751901:tid 752042] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/classwithtostring.php"] [unique_id "amuJhirT982lovRn7gmxnQAAAAs"]
[Thu Jul 30 12:27:34.295432 2026] [security2:error] [pid 751901:tid 752042] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/classwithtostring.php"] [unique_id "amuJhirT982lovRn7gmxnQAAAAs"]
[Thu Jul 30 12:27:34.570771 2026] [security2:error] [pid 751901:tid 752075] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/ohct.php"] [unique_id "amuJhirT982lovRn7gmxngAAACw"]
[Thu Jul 30 12:27:34.570938 2026] [security2:error] [pid 751901:tid 752075] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/ohct.php"] [unique_id "amuJhirT982lovRn7gmxngAAACw"]
[Thu Jul 30 12:27:34.860853 2026] [security2:error] [pid 751901:tid 752088] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/bless.php"] [unique_id "amuJhirT982lovRn7gmxpQAAADk"]
[Thu Jul 30 12:27:34.860994 2026] [security2:error] [pid 751901:tid 752088] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/bless.php"] [unique_id "amuJhirT982lovRn7gmxpQAAADk"]
[Thu Jul 30 12:27:35.138694 2026] [security2:error] [pid 751901:tid 752140] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/about.php"] [unique_id "amuJhyrT982lovRn7gmxpwAAAG0"]
[Thu Jul 30 12:27:35.138801 2026] [security2:error] [pid 751901:tid 752140] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/about.php"] [unique_id "amuJhyrT982lovRn7gmxpwAAAG0"]
[Thu Jul 30 12:27:35.355822 2026] [security2:error] [pid 751901:tid 752078] [client 52.238.199.152:59087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/ms-edit.php"] [unique_id "amuJhyrT982lovRn7gmxrwAAAC8"]
[Thu Jul 30 12:27:35.386386 2026] [security2:error] [pid 751901:tid 752107] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuJhyrT982lovRn7gmxsAAAAEw"]
[Thu Jul 30 12:27:35.386470 2026] [security2:error] [pid 751901:tid 752107] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuJhyrT982lovRn7gmxsAAAAEw"]
[Thu Jul 30 12:27:35.444423 2026] [security2:error] [pid 751901:tid 751955] [remote 68.67.112.200:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "fantasynamelist.com"] [uri "/robots.txt"] [unique_id "amuJhyrT982lovRn7gmxsQAAEzU"]
[Thu Jul 30 12:27:35.654663 2026] [security2:error] [pid 751901:tid 752103] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/ta0ol.php"] [unique_id "amuJhyrT982lovRn7gmxtAAAAEg"]
[Thu Jul 30 12:27:35.654805 2026] [security2:error] [pid 751901:tid 752103] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/ta0ol.php"] [unique_id "amuJhyrT982lovRn7gmxtAAAAEg"]
[Thu Jul 30 12:27:35.875630 2026] [security2:error] [pid 751901:tid 752060] [client 220.167.233.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJhyrT982lovRn7gmxsgAAHTY"]
[Thu Jul 30 12:27:36.105969 2026] [core:notice] [pid 751901:tid 752148] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:36.708430 2026] [security2:error] [pid 751901:tid 752062] [client 20.52.54.143:9966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/file56.php"] [unique_id "amuJiCrT982lovRn7gmxxAAAAB8"]
[Thu Jul 30 12:27:36.757728 2026] [security2:error] [pid 751901:tid 752054] [client 103.143.50.219:39072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJiCrT982lovRn7gmxwgAAABc"], referer: http://pkf.jo
[Thu Jul 30 12:27:37.208883 2026] [security2:error] [pid 751901:tid 751967] [remote 74.7.241.60:52164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/article.php"] [unique_id "amuJiSrT982lovRn7gmx0AAAI0E"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/1784117929_IMG_3676.jpg
[Thu Jul 30 12:27:37.280933 2026] [security2:error] [pid 751901:tid 752081] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/sa.php7"] [unique_id "amuJiSrT982lovRn7gmx1AAAADI"]
[Thu Jul 30 12:27:37.281112 2026] [security2:error] [pid 751901:tid 752081] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/sa.php7"] [unique_id "amuJiSrT982lovRn7gmx1AAAADI"]
[Thu Jul 30 12:27:37.283837 2026] [security2:error] [pid 751901:tid 752033] [client 220.167.233.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJiCrT982lovRn7gmxygAAAj8"]
[Thu Jul 30 12:27:37.351527 2026] [security2:error] [pid 751901:tid 752068] [client 94.205.206.193:57324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJiSrT982lovRn7gmxzgAAACU"], referer: http://pkf.jo
[Thu Jul 30 12:27:37.440061 2026] [security2:error] [pid 751901:tid 752079] [client 52.238.199.152:18288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/function.php"] [unique_id "amuJiSrT982lovRn7gmx2QAAADA"]
[Thu Jul 30 12:27:37.471257 2026] [security2:error] [pid 751901:tid 752064] [client 20.52.54.143:9352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amuJiSrT982lovRn7gmx2gAAACE"]
[Thu Jul 30 12:27:37.542870 2026] [security2:error] [pid 751901:tid 752092] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/wp-class.php"] [unique_id "amuJiSrT982lovRn7gmx3gAAAD0"]
[Thu Jul 30 12:27:37.542992 2026] [security2:error] [pid 751901:tid 752092] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/wp-class.php"] [unique_id "amuJiSrT982lovRn7gmx3gAAAD0"]
[Thu Jul 30 12:27:37.813295 2026] [security2:error] [pid 751901:tid 752037] [client 2a03:2880:f800:28:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJiSrT982lovRn7gmxzwAABkA"]
[Thu Jul 30 12:27:37.829392 2026] [security2:error] [pid 751901:tid 752115] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/8.php"] [unique_id "amuJiSrT982lovRn7gmx5AAAAFQ"]
[Thu Jul 30 12:27:37.829508 2026] [security2:error] [pid 751901:tid 752115] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/8.php"] [unique_id "amuJiSrT982lovRn7gmx5AAAAFQ"]
[Thu Jul 30 12:27:37.894128 2026] [security2:error] [pid 751901:tid 752114] [client 127.0.0.1:25514] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuJiSrT982lovRn7gmx5gAAAFM"]
[Thu Jul 30 12:27:37.894264 2026] [security2:error] [pid 751901:tid 752098] [client 74.7.228.39:41338] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.progroupdoha.com"] [uri "/robots.txt"] [unique_id "amuJiSrT982lovRn7gmx5QAAQ0g"]
[Thu Jul 30 12:27:38.096753 2026] [security2:error] [pid 751901:tid 752129] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/bootstrap.php"] [unique_id "amuJiirT982lovRn7gmx7QAAAGI"]
[Thu Jul 30 12:27:38.096883 2026] [security2:error] [pid 751901:tid 752129] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/bootstrap.php"] [unique_id "amuJiirT982lovRn7gmx7QAAAGI"]
[Thu Jul 30 12:27:38.133866 2026] [security2:error] [pid 751901:tid 752058] [client 103.215.74.26:56126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-login.php"] [unique_id "amuJiirT982lovRn7gmx7gAAABs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:27:38.317941 2026] [security2:error] [pid 751901:tid 752128] [client 46.191.152.215:55655] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJiirT982lovRn7gmx7AAAAGE"], referer: http://pkf.jo
[Thu Jul 30 12:27:38.568690 2026] [security2:error] [pid 751901:tid 752040] [client 220.167.233.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJiirT982lovRn7gmx7wAACUs"]
[Thu Jul 30 12:27:38.615390 2026] [security2:error] [pid 751901:tid 752136] [client 52.238.199.152:51546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/ee.php"] [unique_id "amuJiirT982lovRn7gmx9gAAAGk"]
[Thu Jul 30 12:27:38.629136 2026] [security2:error] [pid 751901:tid 752083] [client 74.7.244.15:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-a21e6513.evk.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuJiSrT982lovRn7gmx3QAAADQ"]
[Thu Jul 30 12:27:38.629857 2026] [security2:error] [pid 751901:tid 752080] [client 74.7.244.15:51520] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-a21e6513.evk.gpl.temporary.site"] [uri "/robots.txt"] [unique_id "amuJiSrT982lovRn7gmx2wAAMUU"]
[Thu Jul 30 12:27:38.687788 2026] [security2:error] [pid 751901:tid 752148] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/wp-blog-header.php"] [unique_id "amuJiirT982lovRn7gmx9wAAAHU"]
[Thu Jul 30 12:27:38.687903 2026] [security2:error] [pid 751901:tid 752148] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/wp-blog-header.php"] [unique_id "amuJiirT982lovRn7gmx9wAAAHU"]
[Thu Jul 30 12:27:38.885163 2026] [core:notice] [pid 751901:tid 752150] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:38.966567 2026] [security2:error] [pid 751901:tid 752091] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/aa.php"] [unique_id "amuJiirT982lovRn7gmyAAAAADw"]
[Thu Jul 30 12:27:38.966678 2026] [security2:error] [pid 751901:tid 752091] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/aa.php"] [unique_id "amuJiirT982lovRn7gmyAAAAADw"]
[Thu Jul 30 12:27:39.246289 2026] [security2:error] [pid 751901:tid 752117] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/tx79.php"] [unique_id "amuJiyrT982lovRn7gmyBAAAAFY"]
[Thu Jul 30 12:27:39.246444 2026] [security2:error] [pid 751901:tid 752117] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/tx79.php"] [unique_id "amuJiyrT982lovRn7gmyBAAAAFY"]
[Thu Jul 30 12:27:39.528695 2026] [security2:error] [pid 751901:tid 752076] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/motu.php"] [unique_id "amuJiyrT982lovRn7gmyCAAAAC0"]
[Thu Jul 30 12:27:39.528789 2026] [security2:error] [pid 751901:tid 752076] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/motu.php"] [unique_id "amuJiyrT982lovRn7gmyCAAAAC0"]
[Thu Jul 30 12:27:39.616823 2026] [security2:error] [pid 751901:tid 752103] [client 20.52.54.143:9942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/css/index.php"] [unique_id "amuJiyrT982lovRn7gmyDAAAAEg"]
[Thu Jul 30 12:27:39.827798 2026] [security2:error] [pid 751901:tid 752073] [client 127.0.0.1:25554] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuJiyrT982lovRn7gmyEAAAACo"]
[Thu Jul 30 12:27:39.827825 2026] [security2:error] [pid 751901:tid 752084] [client 127.0.0.1:25540] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.ghggeneralcontracting.com"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuJiyrT982lovRn7gmyDwAAADU"]
[Thu Jul 30 12:27:39.828228 2026] [security2:error] [pid 751901:tid 752042] [client 74.7.228.58:33806] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.ghggeneralcontracting.com"] [uri "/robots.txt"] [unique_id "amuJiyrT982lovRn7gmyDgAAC1Q"]
[Thu Jul 30 12:27:39.910895 2026] [security2:error] [pid 751901:tid 752094] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/wp-head.php"] [unique_id "amuJiyrT982lovRn7gmyFgAAAD8"]
[Thu Jul 30 12:27:39.911009 2026] [security2:error] [pid 751901:tid 752094] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/wp-head.php"] [unique_id "amuJiyrT982lovRn7gmyFgAAAD8"]
[Thu Jul 30 12:27:40.162402 2026] [security2:error] [pid 751901:tid 752104] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuJjCrT982lovRn7gmyHgAAAEk"]
[Thu Jul 30 12:27:40.162537 2026] [security2:error] [pid 751901:tid 752104] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuJjCrT982lovRn7gmyHgAAAEk"]
[Thu Jul 30 12:27:40.164901 2026] [security2:error] [pid 751901:tid 752075] [client 220.167.233.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJiyrT982lovRn7gmyEQAALFU"]
[Thu Jul 30 12:27:40.417942 2026] [security2:error] [pid 751901:tid 752110] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/60856e3a4findex.php"] [unique_id "amuJjCrT982lovRn7gmyHwAAAE8"]
[Thu Jul 30 12:27:40.418087 2026] [security2:error] [pid 751901:tid 752110] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/60856e3a4findex.php"] [unique_id "amuJjCrT982lovRn7gmyHwAAAE8"]
[Thu Jul 30 12:27:40.687761 2026] [security2:error] [pid 751901:tid 752098] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/wp-the.php"] [unique_id "amuJjCrT982lovRn7gmyJgAAAEM"]
[Thu Jul 30 12:27:40.687929 2026] [security2:error] [pid 751901:tid 752098] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/wp-the.php"] [unique_id "amuJjCrT982lovRn7gmyJgAAAEM"]
[Thu Jul 30 12:27:40.927558 2026] [core:notice] [pid 751901:tid 752059] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:40.937617 2026] [security2:error] [pid 751901:tid 752106] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/wp.php"] [unique_id "amuJjCrT982lovRn7gmyKAAAAEs"]
[Thu Jul 30 12:27:40.937710 2026] [security2:error] [pid 751901:tid 752106] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/wp.php"] [unique_id "amuJjCrT982lovRn7gmyKAAAAEs"]
[Thu Jul 30 12:27:41.204111 2026] [core:error] [pid 751901:tid 752083] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:27:41.204140 2026] [core:error] [pid 751901:tid 752083] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:27:41.208392 2026] [security2:error] [pid 751901:tid 752151] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/users.php"] [unique_id "amuJjSrT982lovRn7gmyOAAAAHg"]
[Thu Jul 30 12:27:41.208489 2026] [security2:error] [pid 751901:tid 752151] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/users.php"] [unique_id "amuJjSrT982lovRn7gmyOAAAAHg"]
[Thu Jul 30 12:27:41.226342 2026] [core:error] [pid 751901:tid 752152] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:27:41.226359 2026] [core:error] [pid 751901:tid 752152] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:27:41.259497 2026] [core:error] [pid 751901:tid 752046] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:27:41.259517 2026] [core:error] [pid 751901:tid 752046] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:27:41.450573 2026] [core:notice] [pid 751901:tid 752072] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:41.469884 2026] [security2:error] [pid 751901:tid 752093] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/tinysd.php"] [unique_id "amuJjSrT982lovRn7gmySAAAAD4"]
[Thu Jul 30 12:27:41.470004 2026] [security2:error] [pid 751901:tid 752093] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/tinysd.php"] [unique_id "amuJjSrT982lovRn7gmySAAAAD4"]
[Thu Jul 30 12:27:41.700558 2026] [security2:error] [pid 751901:tid 752141] [client 220.167.233.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJjSrT982lovRn7gmyQwAAbl8"]
[Thu Jul 30 12:27:41.759559 2026] [security2:error] [pid 751901:tid 752051] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/ws78.php"] [unique_id "amuJjSrT982lovRn7gmyUQAAABQ"]
[Thu Jul 30 12:27:41.759679 2026] [security2:error] [pid 751901:tid 752051] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/ws78.php"] [unique_id "amuJjSrT982lovRn7gmyUQAAABQ"]
[Thu Jul 30 12:27:42.009217 2026] [security2:error] [pid 751901:tid 752068] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/elp.php"] [unique_id "amuJjirT982lovRn7gmyVQAAACU"]
[Thu Jul 30 12:27:42.009343 2026] [security2:error] [pid 751901:tid 752068] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/elp.php"] [unique_id "amuJjirT982lovRn7gmyVQAAACU"]
[Thu Jul 30 12:27:42.164495 2026] [security2:error] [pid 751901:tid 752035] [client 38.190.144.4:53470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJjirT982lovRn7gmyXAAAAAQ"]
[Thu Jul 30 12:27:42.165991 2026] [security2:error] [pid 751901:tid 752035] [client 38.190.144.4:53470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJjirT982lovRn7gmyXAAAAAQ"]
[Thu Jul 30 12:27:42.264804 2026] [security2:error] [pid 751901:tid 752102] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/atomlib.php"] [unique_id "amuJjirT982lovRn7gmyXQAAAEc"]
[Thu Jul 30 12:27:42.264907 2026] [security2:error] [pid 751901:tid 752102] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/atomlib.php"] [unique_id "amuJjirT982lovRn7gmyXQAAAEc"]
[Thu Jul 30 12:27:42.311797 2026] [core:notice] [pid 751901:tid 752005] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:42.564228 2026] [security2:error] [pid 751901:tid 752113] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/wyzer3.php"] [unique_id "amuJjirT982lovRn7gmyYwAAAFI"]
[Thu Jul 30 12:27:42.564346 2026] [security2:error] [pid 751901:tid 752113] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/wyzer3.php"] [unique_id "amuJjirT982lovRn7gmyYwAAAFI"]
[Thu Jul 30 12:27:42.791582 2026] [security2:error] [pid 751901:tid 752109] [client 20.52.54.143:9934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/edit.php"] [unique_id "amuJjirT982lovRn7gmyagAAAE4"]
[Thu Jul 30 12:27:42.844961 2026] [security2:error] [pid 751901:tid 752122] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/max.php"] [unique_id "amuJjirT982lovRn7gmyawAAAFs"]
[Thu Jul 30 12:27:42.845094 2026] [security2:error] [pid 751901:tid 752122] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/max.php"] [unique_id "amuJjirT982lovRn7gmyawAAAFs"]
[Thu Jul 30 12:27:42.905481 2026] [core:notice] [pid 751901:tid 752131] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:43.121194 2026] [security2:error] [pid 751901:tid 752152] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/ftde.php"] [unique_id "amuJjyrT982lovRn7gmycQAAAHk"]
[Thu Jul 30 12:27:43.121301 2026] [security2:error] [pid 751901:tid 752152] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/ftde.php"] [unique_id "amuJjyrT982lovRn7gmycQAAAHk"]
[Thu Jul 30 12:27:44.053504 2026] [security2:error] [pid 751901:tid 752036] [client 20.52.54.143:10195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/2.php"] [unique_id "amuJkCrT982lovRn7gmyhgAAAAU"]
[Thu Jul 30 12:27:45.348628 2026] [security2:error] [pid 751901:tid 752123] [client 20.52.54.143:9961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "amuJkSrT982lovRn7gmypQAAAFw"]
[Thu Jul 30 12:27:45.700214 2026] [security2:error] [pid 751901:tid 752060] [client 52.238.199.152:48525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/new.php"] [unique_id "amuJkSrT982lovRn7gmyqAAAAB0"]
[Thu Jul 30 12:27:45.897206 2026] [security2:error] [pid 751901:tid 752151] [client 20.52.54.143:9929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/mah.php"] [unique_id "amuJkSrT982lovRn7gmysgAAAHg"]
[Thu Jul 30 12:27:45.985112 2026] [security2:error] [pid 751901:tid 752155] [client 57.141.0.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuJkSrT982lovRn7gmyrwAAAHw"]
[Thu Jul 30 12:27:46.591514 2026] [core:notice] [pid 751901:tid 751915] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:46.995202 2026] [security2:error] [pid 751901:tid 752119] [client 38.250.241.96:60726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJkirT982lovRn7gmyvQAAAFg"], referer: http://pkf.jo
[Thu Jul 30 12:27:47.161758 2026] [security2:error] [pid 751901:tid 752093] [client 34.44.142.114:43616] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "shop-kent.com"] [uri "/index.php"] [unique_id "amuJkirT982lovRn7gmyvgAAPg8"]
[Thu Jul 30 12:27:47.706684 2026] [security2:error] [pid 751901:tid 752044] [client 20.52.54.143:9356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/send.php"] [unique_id "amuJkyrT982lovRn7gmy1QAAAA0"]
[Thu Jul 30 12:27:47.819435 2026] [security2:error] [pid 751901:tid 751925] [remote 216.73.216.152:33686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuJkyrT982lovRn7gmy0gAAGhc"]
[Thu Jul 30 12:27:48.127493 2026] [security2:error] [pid 751901:tid 752107] [client 34.44.142.114:43616] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "shop-kent.com"] [uri "/index.php"] [unique_id "amuJkyrT982lovRn7gmyzQAATBU"]
[Thu Jul 30 12:27:48.306958 2026] [security2:error] [pid 751901:tid 752116] [client 20.52.54.143:10185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amuJlCrT982lovRn7gmy4wAAAFU"]
[Thu Jul 30 12:27:48.882550 2026] [proxy:error] [pid 751901:tid 752136] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:27:48.882645 2026] [proxy_http:error] [pid 751901:tid 752136] [client 20.52.54.143:10181] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:27:48.883507 2026] [proxy:error] [pid 751901:tid 752136] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:27:48.883566 2026] [proxy_http:error] [pid 751901:tid 752136] [client 20.52.54.143:10181] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:27:49.931697 2026] [core:notice] [pid 751901:tid 752073] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:50.086016 2026] [security2:error] [pid 751901:tid 752056] [client 34.44.142.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "shop-kent.com"] [uri "/index.php"] [unique_id "amuJlSrT982lovRn7gmy-AAAABk"]
[Thu Jul 30 12:27:50.347369 2026] [security2:error] [pid 751901:tid 752049] [client 52.238.199.152:59132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-config.php"] [unique_id "amuJlirT982lovRn7gmzCwAAABI"]
[Thu Jul 30 12:27:50.909642 2026] [security2:error] [pid 751901:tid 752082] [client 20.52.54.143:10184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/about.php"] [unique_id "amuJlirT982lovRn7gmzFQAAADM"]
[Thu Jul 30 12:27:51.314911 2026] [security2:error] [pid 751901:tid 752106] [client 52.238.199.152:17807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-conflg.php"] [unique_id "amuJlyrT982lovRn7gmzHgAAAEs"]
[Thu Jul 30 12:27:51.455501 2026] [security2:error] [pid 751901:tid 752060] [client 37.120.155.179:54720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.155.120.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuJlyrT982lovRn7gmzIAAAAB0"]
[Thu Jul 30 12:27:51.455610 2026] [security2:error] [pid 751901:tid 752060] [client 37.120.155.179:54720] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuJlyrT982lovRn7gmzIAAAAB0"]
[Thu Jul 30 12:27:51.505131 2026] [security2:error] [pid 751901:tid 752035] [client 23.251.146.115:2385] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "lark-shop.com"] [uri "/index.php"] [unique_id "amuJlirT982lovRn7gmzDAAABAM"]
[Thu Jul 30 12:27:51.872858 2026] [core:notice] [pid 751901:tid 752154] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:52.311252 2026] [security2:error] [pid 751901:tid 752135] [client 2a03:2880:f800:e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJlyrT982lovRn7gmzJwAAaCQ"]
[Thu Jul 30 12:27:52.555159 2026] [core:notice] [pid 751901:tid 752083] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:52.863133 2026] [security2:error] [pid 751901:tid 752054] [client 23.251.146.115:2385] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "lark-shop.com"] [uri "/index.php"] [unique_id "amuJlyrT982lovRn7gmzKwAAFyc"]
[Thu Jul 30 12:27:53.127453 2026] [core:notice] [pid 751901:tid 752051] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:53.834300 2026] [security2:error] [pid 751901:tid 752032] [client 20.52.54.143:9217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/options.php"] [unique_id "amuJmSrT982lovRn7gmzVAAAAAE"]
[Thu Jul 30 12:27:53.997107 2026] [security2:error] [pid 751901:tid 752052] [client 38.190.144.4:53959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJmSrT982lovRn7gmzVgAAABU"]
[Thu Jul 30 12:27:53.999281 2026] [security2:error] [pid 751901:tid 752052] [client 38.190.144.4:53959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJmSrT982lovRn7gmzVgAAABU"]
[Thu Jul 30 12:27:54.445624 2026] [security2:error] [pid 751901:tid 752053] [client 23.251.146.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "lark-shop.com"] [uri "/index.php"] [unique_id "amuJmSrT982lovRn7gmzSgAAABY"]
[Thu Jul 30 12:27:55.243622 2026] [security2:error] [pid 751901:tid 752137] [client 74.7.244.31:36788] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "greensparkle.net"] [uri "/robots.txt"] [unique_id "amuJmyrT982lovRn7gmzbwAAakM"]
[Thu Jul 30 12:27:55.268022 2026] [security2:error] [pid 751901:tid 752145] [client 127.0.0.1:57494] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuJmyrT982lovRn7gmzcAAAAHI"]
[Thu Jul 30 12:27:55.268096 2026] [security2:error] [pid 751901:tid 752048] [client 127.0.0.1:57488] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.bio.djb.temporary.site"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuJmyrT982lovRn7gmzbgAAABE"]
[Thu Jul 30 12:27:55.268156 2026] [security2:error] [pid 751901:tid 752098] [client 74.7.228.39:40622] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.bio.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amuJmyrT982lovRn7gmzbQAAQz8"]
[Thu Jul 30 12:27:55.291536 2026] [security2:error] [pid 751901:tid 752121] [client 20.52.54.143:10180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuJmyrT982lovRn7gmzcQAAAFo"]
[Thu Jul 30 12:27:55.714328 2026] [security2:error] [pid 751901:tid 751974] [remote 184.168.126.180:41414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.126.168.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "supreme-hydraulics.com"] [uri "/wp-login.php"] [unique_id "amuJmyrT982lovRn7gmzeAAAJ0g"]
[Thu Jul 30 12:27:56.076648 2026] [security2:error] [pid 751901:tid 752133] [client 20.52.54.143:9377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-file.php"] [unique_id "amuJnCrT982lovRn7gmzfwAAAGY"]
[Thu Jul 30 12:27:56.487595 2026] [security2:error] [pid 751901:tid 751981] [remote 5.161.62.209:23090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "arabiandubaisafari.com.khw.nyx.temporary.site"] [uri "/.env"] [unique_id "amuJnCrT982lovRn7gmzigAAGU8"]
[Thu Jul 30 12:27:56.698329 2026] [security2:error] [pid 751901:tid 752135] [client 2a03:2880:f800:42:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJnCrT982lovRn7gmzgAAAaEw"]
[Thu Jul 30 12:27:57.150422 2026] [security2:error] [pid 751901:tid 751984] [remote 5.161.62.209:23098] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "arabiantourz.com.khw.nyx.temporary.site"] [uri "/.env"] [unique_id "amuJnSrT982lovRn7gmzlgAAW1I"]
[Thu Jul 30 12:27:57.165386 2026] [security2:error] [pid 751901:tid 751985] [remote 5.161.62.209:23094] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "arabiantourz.com"] [uri "/.env"] [unique_id "amuJnSrT982lovRn7gmzlwAAa1M"]
[Thu Jul 30 12:27:57.569923 2026] [security2:error] [pid 751901:tid 752045] [client 52.238.199.152:40172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "amuJnSrT982lovRn7gmzpAAAAA4"]
[Thu Jul 30 12:27:57.816501 2026] [security2:error] [pid 751901:tid 752100] [client 20.52.54.143:10139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/sid3.php"] [unique_id "amuJnSrT982lovRn7gmzpgAAAEU"]
[Thu Jul 30 12:27:58.244776 2026] [security2:error] [pid 751901:tid 752080] [client 57.141.0.27:29820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "happyspree.app"] [uri "/index.php"] [unique_id "amuJnSrT982lovRn7gmzrQAAMVU"]
[Thu Jul 30 12:27:58.714252 2026] [core:notice] [pid 751901:tid 751994] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:58.843559 2026] [core:notice] [pid 751901:tid 752141] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:59.115761 2026] [security2:error] [pid 751901:tid 752059] [client 2a03:2880:f800:40:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJnirT982lovRn7gmzuQAAHF0"]
[Thu Jul 30 12:27:59.351177 2026] [security2:error] [pid 751901:tid 752023] [remote 208.109.9.173:42618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.9.109.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-login.php"] [unique_id "amuJnyrT982lovRn7gmz2gAAAnk"]
[Thu Jul 30 12:28:00.631571 2026] [security2:error] [pid 751901:tid 751903] [remote 57.141.0.32:26922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5033157679/feed/rss2/"] [unique_id "amuJoCrT982lovRn7gm0AgAAFAE"]
[Thu Jul 30 12:28:00.801798 2026] [core:notice] [pid 751901:tid 752074] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:02.775522 2026] [core:notice] [pid 751901:tid 752068] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:03.312948 2026] [core:notice] [pid 751901:tid 751950] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:03.334771 2026] [security2:error] [pid 751901:tid 752088] [client 52.238.199.152:17972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-includes/customize/chosen.php"] [unique_id "amuJoyrT982lovRn7gm0PAAAADk"]
[Thu Jul 30 12:28:03.754493 2026] [security2:error] [pid 751901:tid 752118] [client 38.190.144.4:54456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJoyrT982lovRn7gm0RAAAAFc"]
[Thu Jul 30 12:28:03.754613 2026] [security2:error] [pid 751901:tid 752118] [client 38.190.144.4:54456] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJoyrT982lovRn7gm0RAAAAFc"]
[Thu Jul 30 12:28:04.422872 2026] [security2:error] [pid 751901:tid 752130] [client 52.238.199.152:17426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-admin/js/autoload_classmap.php"] [unique_id "amuJpCrT982lovRn7gm0SwAAAGM"]
[Thu Jul 30 12:28:04.489625 2026] [core:notice] [pid 751901:tid 752149] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:04.764489 2026] [security2:error] [pid 751901:tid 752144] [client 103.215.74.26:28298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php"] [unique_id "amuJpCrT982lovRn7gm0UwAAAHE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:05.013165 2026] [security2:error] [pid 751901:tid 752077] [client 43.173.180.41:33726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.180.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/01/03/bonne-annee-2012/"] [unique_id "amuJpCrT982lovRn7gm0VAAAAC4"]
[Thu Jul 30 12:28:05.500986 2026] [core:notice] [pid 751901:tid 752106] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:05.554275 2026] [core:notice] [pid 751901:tid 752158] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:05.559667 2026] [security2:error] [pid 751901:tid 752158] [client 43.172.194.119:57926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/01/03/bonne-annee-2012/"] [unique_id "amuJpSrT982lovRn7gm0YgAAAH8"], referer: https://carnetdeshopping.com/index.php/2012/01/03/bonne-annee-2012/
[Thu Jul 30 12:28:05.727542 2026] [security2:error] [pid 751901:tid 752051] [client 52.238.199.152:18091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-includes/Text/autoload_classmap.php"] [unique_id "amuJpSrT982lovRn7gm0aQAAABQ"]
[Thu Jul 30 12:28:06.769971 2026] [security2:error] [pid 751901:tid 752090] [client 52.238.199.152:18084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/manager.php"] [unique_id "amuJpirT982lovRn7gm0ewAAADs"]
[Thu Jul 30 12:28:07.525882 2026] [security2:error] [pid 751901:tid 752042] [client 85.208.96.195:24396] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2021/02/20/robo-perseverance-envia-primeiras-fotos-coloridas-de-marte/"] [unique_id "amuJpyrT982lovRn7gm0gwAAAAs"]
[Thu Jul 30 12:28:07.526026 2026] [security2:error] [pid 751901:tid 752042] [client 85.208.96.195:24396] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2021/02/20/robo-perseverance-envia-primeiras-fotos-coloridas-de-marte/"] [unique_id "amuJpyrT982lovRn7gm0gwAAAAs"]
[Thu Jul 30 12:28:08.336698 2026] [security2:error] [pid 751901:tid 752097] [client 52.238.199.152:17408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-links.php"] [unique_id "amuJqCrT982lovRn7gm0lAAAAEI"]
[Thu Jul 30 12:28:08.840893 2026] [security2:error] [pid 751901:tid 751982] [remote 57.141.0.71:65038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/407345907/feed/rss2/"] [unique_id "amuJqCrT982lovRn7gm0nQAAeVA"]
[Thu Jul 30 12:28:09.866286 2026] [core:notice] [pid 751901:tid 752103] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:10.932939 2026] [security2:error] [pid 751901:tid 752081] [client 57.141.0.2:61608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuJqirT982lovRn7gm0vgAAMls"], referer: https://igetvape-australia.com/?add-to-cart=919
[Thu Jul 30 12:28:11.121165 2026] [security2:error] [pid 751901:tid 752108] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/admin.php"] [unique_id "amuJqyrT982lovRn7gm0ygAAAE0"]
[Thu Jul 30 12:28:11.121285 2026] [security2:error] [pid 751901:tid 752108] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/admin.php"] [unique_id "amuJqyrT982lovRn7gm0ygAAAE0"]
[Thu Jul 30 12:28:11.686334 2026] [security2:error] [pid 751901:tid 752140] [client 52.238.199.152:17593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/fi2.php"] [unique_id "amuJqyrT982lovRn7gm02QAAAG0"]
[Thu Jul 30 12:28:12.473673 2026] [core:notice] [pid 751901:tid 752153] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:12.477575 2026] [security2:error] [pid 751901:tid 752153] [client 103.215.74.26:28320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJrCrT982lovRn7gm05wAAAHo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:12.591873 2026] [security2:error] [pid 751901:tid 752009] [remote 216.73.216.152:33686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuJrCrT982lovRn7gm07gAABWs"]
[Thu Jul 30 12:28:13.053273 2026] [security2:error] [pid 751901:tid 752092] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/ops.php"] [unique_id "amuJrSrT982lovRn7gm09gAAAD0"]
[Thu Jul 30 12:28:13.053389 2026] [security2:error] [pid 751901:tid 752092] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/ops.php"] [unique_id "amuJrSrT982lovRn7gm09gAAAD0"]
[Thu Jul 30 12:28:13.176413 2026] [security2:error] [pid 751901:tid 752012] [remote 151.158.48.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.48.158.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aakmiddleast.com"] [uri "/wp-login.php"] [unique_id "amuJrSrT982lovRn7gm09wAANm4"]
[Thu Jul 30 12:28:13.210142 2026] [core:notice] [pid 751901:tid 752103] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:13.214393 2026] [security2:error] [pid 751901:tid 752103] [client 103.215.74.26:45498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJrSrT982lovRn7gm0-AAAAEg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:13.298068 2026] [security2:error] [pid 751901:tid 752078] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/mac.php"] [unique_id "amuJrSrT982lovRn7gm0-QAAAC8"]
[Thu Jul 30 12:28:13.298222 2026] [security2:error] [pid 751901:tid 752078] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/mac.php"] [unique_id "amuJrSrT982lovRn7gm0-QAAAC8"]
[Thu Jul 30 12:28:13.468933 2026] [security2:error] [pid 751901:tid 752098] [client 52.238.199.152:63379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/0x.php"] [unique_id "amuJrSrT982lovRn7gm0-wAAAEM"]
[Thu Jul 30 12:28:13.567780 2026] [security2:error] [pid 751901:tid 752038] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/colors/modern/"] [unique_id "amuJrSrT982lovRn7gm1AgAAAAc"]
[Thu Jul 30 12:28:13.695699 2026] [security2:error] [pid 751901:tid 752096] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/pucci.php"] [unique_id "amuJrSrT982lovRn7gm1BAAAAEE"]
[Thu Jul 30 12:28:13.695815 2026] [security2:error] [pid 751901:tid 752096] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/pucci.php"] [unique_id "amuJrSrT982lovRn7gm1BAAAAEE"]
[Thu Jul 30 12:28:13.935514 2026] [security2:error] [pid 751901:tid 752095] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/wp-admin/js/index.php"] [unique_id "amuJrSrT982lovRn7gm1BgAAAEA"]
[Thu Jul 30 12:28:13.935622 2026] [security2:error] [pid 751901:tid 752095] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/wp-admin/js/index.php"] [unique_id "amuJrSrT982lovRn7gm1BgAAAEA"]
[Thu Jul 30 12:28:15.080867 2026] [security2:error] [pid 751901:tid 752158] [client 38.190.144.4:54971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJryrT982lovRn7gm1KgAAAH8"]
[Thu Jul 30 12:28:15.082995 2026] [security2:error] [pid 751901:tid 752158] [client 38.190.144.4:54971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJryrT982lovRn7gm1KgAAAH8"]
[Thu Jul 30 12:28:15.425594 2026] [security2:error] [pid 751901:tid 752120] [client 172.237.109.114:38705] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrSrT982lovRn7gm1DQAAAFk"]
[Thu Jul 30 12:28:15.432514 2026] [security2:error] [pid 751901:tid 752082] [client 172.237.109.114:13889] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrSrT982lovRn7gm1EAAAADM"]
[Thu Jul 30 12:28:15.432926 2026] [security2:error] [pid 751901:tid 752112] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/8.php"] [unique_id "amuJryrT982lovRn7gm1LwAAAFE"]
[Thu Jul 30 12:28:15.433097 2026] [security2:error] [pid 751901:tid 752112] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/8.php"] [unique_id "amuJryrT982lovRn7gm1LwAAAFE"]
[Thu Jul 30 12:28:15.440842 2026] [security2:error] [pid 751901:tid 752042] [client 172.237.109.114:17250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrSrT982lovRn7gm1DgAAAAs"]
[Thu Jul 30 12:28:15.460369 2026] [security2:error] [pid 751901:tid 752081] [client 172.237.109.114:57984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrSrT982lovRn7gm1EQAAADI"]
[Thu Jul 30 12:28:15.465154 2026] [security2:error] [pid 751901:tid 752132] [client 172.237.109.114:6210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrirT982lovRn7gm1GQAAAGU"]
[Thu Jul 30 12:28:15.502085 2026] [security2:error] [pid 751901:tid 752074] [client 172.237.109.114:46665] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrSrT982lovRn7gm1DwAAACs"]
[Thu Jul 30 12:28:15.514375 2026] [security2:error] [pid 751901:tid 752124] [client 172.237.109.114:49170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrirT982lovRn7gm1GwAAAF0"]
[Thu Jul 30 12:28:15.522699 2026] [security2:error] [pid 751901:tid 752064] [client 172.237.109.114:58122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrSrT982lovRn7gm1GAAAACE"]
[Thu Jul 30 12:28:15.525238 2026] [security2:error] [pid 751901:tid 752056] [client 172.237.109.114:19638] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrSrT982lovRn7gm1EwAAABk"]
[Thu Jul 30 12:28:15.546224 2026] [security2:error] [pid 751901:tid 752157] [client 172.237.109.114:63403] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrSrT982lovRn7gm1CgAAAH4"]
[Thu Jul 30 12:28:15.548723 2026] [security2:error] [pid 751901:tid 752118] [client 172.237.109.114:6070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrSrT982lovRn7gm1CwAAAFc"]
[Thu Jul 30 12:28:15.552928 2026] [security2:error] [pid 751901:tid 752104] [client 172.237.109.114:16096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrSrT982lovRn7gm1FAAAAEk"]
[Thu Jul 30 12:28:15.567573 2026] [security2:error] [pid 751901:tid 752134] [client 172.237.109.114:27618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrSrT982lovRn7gm1DAAAAGc"]
[Thu Jul 30 12:28:15.594572 2026] [security2:error] [pid 751901:tid 752093] [client 172.237.109.114:11741] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrirT982lovRn7gm1GgAAAD4"]
[Thu Jul 30 12:28:15.603506 2026] [security2:error] [pid 751901:tid 752033] [client 172.237.109.114:41053] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrSrT982lovRn7gm1EgAAAAI"]
[Thu Jul 30 12:28:15.612805 2026] [security2:error] [pid 751901:tid 752108] [client 172.237.109.114:7701] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrSrT982lovRn7gm1FwAAAE0"]
[Thu Jul 30 12:28:15.627178 2026] [security2:error] [pid 751901:tid 752109] [client 172.237.109.114:49659] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrSrT982lovRn7gm1CQAAAE4"]
[Thu Jul 30 12:28:15.631258 2026] [security2:error] [pid 751901:tid 752152] [client 52.238.199.152:63373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/k.php"] [unique_id "amuJryrT982lovRn7gm1MwAAAHk"]
[Thu Jul 30 12:28:15.643011 2026] [security2:error] [pid 751901:tid 752057] [client 172.237.109.114:51836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrSrT982lovRn7gm1CAAAABo"]
[Thu Jul 30 12:28:15.666544 2026] [security2:error] [pid 751901:tid 752122] [client 172.237.109.114:25537] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrSrT982lovRn7gm1FQAAAFs"]
[Thu Jul 30 12:28:15.683518 2026] [security2:error] [pid 751901:tid 752058] [client 172.237.109.114:25186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrSrT982lovRn7gm1FgAAABs"]
[Thu Jul 30 12:28:15.684681 2026] [security2:error] [pid 751901:tid 752115] [client 20.203.133.142:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/1.php"] [unique_id "amuJryrT982lovRn7gm1NwAAAFQ"]
[Thu Jul 30 12:28:15.684790 2026] [security2:error] [pid 751901:tid 752115] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/1.php"] [unique_id "amuJryrT982lovRn7gm1NwAAAFQ"]
[Thu Jul 30 12:28:15.684896 2026] [security2:error] [pid 751901:tid 752115] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/1.php"] [unique_id "amuJryrT982lovRn7gm1NwAAAFQ"]
[Thu Jul 30 12:28:15.939493 2026] [security2:error] [pid 751901:tid 752102] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/wp-content/admin.php"] [unique_id "amuJryrT982lovRn7gm1OwAAAEc"]
[Thu Jul 30 12:28:15.939593 2026] [security2:error] [pid 751901:tid 752102] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/wp-content/admin.php"] [unique_id "amuJryrT982lovRn7gm1OwAAAEc"]
[Thu Jul 30 12:28:16.605680 2026] [security2:error] [pid 751901:tid 752123] [client 52.238.199.152:42952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/gecko-new.php"] [unique_id "amuJsCrT982lovRn7gm1TwAAAFw"]
[Thu Jul 30 12:28:17.589562 2026] [security2:error] [pid 751901:tid 751912] [remote 216.73.216.152:33686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuJsSrT982lovRn7gm1XQAAKwo"]
[Thu Jul 30 12:28:17.980726 2026] [security2:error] [pid 751901:tid 752082] [client 52.238.199.152:51665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/alfanew.php"] [unique_id "amuJsSrT982lovRn7gm1YQAAADM"]
[Thu Jul 30 12:28:18.437443 2026] [security2:error] [pid 751901:tid 752104] [client 85.208.96.211:64146] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/10/29/bolsonaro-afirma-que-vai-respeitar-o-resultado-das-urnas-no-segundo-turno-quem-tiver-mais-voto-leva/"] [unique_id "amuJsirT982lovRn7gm1aQAAAEk"]
[Thu Jul 30 12:28:18.437598 2026] [security2:error] [pid 751901:tid 752104] [client 85.208.96.211:64146] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/10/29/bolsonaro-afirma-que-vai-respeitar-o-resultado-das-urnas-no-segundo-turno-quem-tiver-mais-voto-leva/"] [unique_id "amuJsirT982lovRn7gm1aQAAAEk"]
[Thu Jul 30 12:28:18.928465 2026] [core:notice] [pid 751901:tid 752049] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:18.933518 2026] [security2:error] [pid 751901:tid 752049] [client 103.215.74.26:45508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJsirT982lovRn7gm1cwAAABI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:19.648191 2026] [security2:error] [pid 751901:tid 752043] [client 104.254.90.251:33444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.90.254.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuJsyrT982lovRn7gm1gQAAAAw"]
[Thu Jul 30 12:28:19.648323 2026] [security2:error] [pid 751901:tid 752043] [client 104.254.90.251:33444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuJsyrT982lovRn7gm1gQAAAAw"]
[Thu Jul 30 12:28:19.663489 2026] [core:notice] [pid 751901:tid 752138] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:19.669862 2026] [security2:error] [pid 751901:tid 752138] [client 103.215.74.26:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJsyrT982lovRn7gm1ggAAAGs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:19.822586 2026] [security2:error] [pid 751901:tid 752143] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/wp-content/themes/index.php"] [unique_id "amuJsyrT982lovRn7gm1hgAAAHA"]
[Thu Jul 30 12:28:19.822684 2026] [security2:error] [pid 751901:tid 752143] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/wp-content/themes/index.php"] [unique_id "amuJsyrT982lovRn7gm1hgAAAHA"]
[Thu Jul 30 12:28:20.057391 2026] [security2:error] [pid 751901:tid 752066] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/222.php"] [unique_id "amuJtCrT982lovRn7gm1hwAAACM"]
[Thu Jul 30 12:28:20.057506 2026] [security2:error] [pid 751901:tid 752066] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/222.php"] [unique_id "amuJtCrT982lovRn7gm1hwAAACM"]
[Thu Jul 30 12:28:20.191460 2026] [security2:error] [pid 751901:tid 752142] [client 52.238.199.152:51666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/text.php"] [unique_id "amuJtCrT982lovRn7gm1jQAAAG8"]
[Thu Jul 30 12:28:20.310173 2026] [security2:error] [pid 751901:tid 752048] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/cgi-bin/index.php"] [unique_id "amuJtCrT982lovRn7gm1jwAAABE"]
[Thu Jul 30 12:28:20.310305 2026] [security2:error] [pid 751901:tid 752048] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/cgi-bin/index.php"] [unique_id "amuJtCrT982lovRn7gm1jwAAABE"]
[Thu Jul 30 12:28:20.458860 2026] [core:notice] [pid 751901:tid 752080] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:20.463048 2026] [security2:error] [pid 751901:tid 752080] [client 103.215.74.26:45514] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJtCrT982lovRn7gm1kAAAADE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:20.565668 2026] [security2:error] [pid 751901:tid 752132] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/___proxy_subdomain_webdisk/wp-includes/css/dist/"] [unique_id "amuJtCrT982lovRn7gm1kQAAAGU"]
[Thu Jul 30 12:28:20.705047 2026] [security2:error] [pid 751901:tid 752034] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/___proxy_subdomain_webdisk/wp-includes/l10n/"] [unique_id "amuJtCrT982lovRn7gm1mQAAAAM"]
[Thu Jul 30 12:28:20.840960 2026] [core:notice] [pid 751901:tid 752046] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:20.845624 2026] [security2:error] [pid 751901:tid 752046] [client 182.8.249.15:20146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/camic/article/view/9098"] [unique_id "amuJtCrT982lovRn7gm1kgAAAA8"]
[Thu Jul 30 12:28:20.846081 2026] [security2:error] [pid 751901:tid 752040] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/___proxy_subdomain_webdisk/wp-content/uploads/"] [unique_id "amuJtCrT982lovRn7gm1ngAAAAk"]
[Thu Jul 30 12:28:20.932264 2026] [core:notice] [pid 751901:tid 752152] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:20.999491 2026] [security2:error] [pid 751901:tid 752036] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/raw.php"] [unique_id "amuJtCrT982lovRn7gm1oAAAAAU"]
[Thu Jul 30 12:28:20.999622 2026] [security2:error] [pid 751901:tid 752036] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/raw.php"] [unique_id "amuJtCrT982lovRn7gm1oAAAAAU"]
[Thu Jul 30 12:28:21.089727 2026] [core:notice] [pid 751901:tid 752121] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:21.194408 2026] [core:notice] [pid 751901:tid 752057] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:21.198665 2026] [security2:error] [pid 751901:tid 752057] [client 103.215.74.26:45520] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJtSrT982lovRn7gm1pQAAABo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:21.258449 2026] [security2:error] [pid 751901:tid 752104] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/___proxy_subdomain_webdisk/wp-content/"] [unique_id "amuJtSrT982lovRn7gm1pgAAAEk"]
[Thu Jul 30 12:28:21.383385 2026] [security2:error] [pid 751901:tid 752067] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/simple.php"] [unique_id "amuJtSrT982lovRn7gm1qwAAACQ"]
[Thu Jul 30 12:28:21.383544 2026] [security2:error] [pid 751901:tid 752067] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/simple.php"] [unique_id "amuJtSrT982lovRn7gm1qwAAACQ"]
[Thu Jul 30 12:28:21.638970 2026] [security2:error] [pid 751901:tid 752031] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/xxx.php"] [unique_id "amuJtSrT982lovRn7gm1rAAAAAA"]
[Thu Jul 30 12:28:21.639105 2026] [security2:error] [pid 751901:tid 752031] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/xxx.php"] [unique_id "amuJtSrT982lovRn7gm1rAAAAAA"]
[Thu Jul 30 12:28:21.842280 2026] [security2:error] [pid 751901:tid 752119] [client 52.238.199.152:59076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/f.php"] [unique_id "amuJtSrT982lovRn7gm1swAAAFg"]
[Thu Jul 30 12:28:21.938536 2026] [core:notice] [pid 751901:tid 752068] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:21.943071 2026] [security2:error] [pid 751901:tid 752068] [client 103.215.74.26:45536] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJtSrT982lovRn7gm1tQAAACU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:22.678764 2026] [core:notice] [pid 751901:tid 752099] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:22.682825 2026] [security2:error] [pid 751901:tid 752099] [client 103.215.74.26:45542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJtirT982lovRn7gm1xQAAAEQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:22.898662 2026] [security2:error] [pid 751901:tid 752047] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/file.php"] [unique_id "amuJtirT982lovRn7gm1zAAAABA"]
[Thu Jul 30 12:28:22.898746 2026] [security2:error] [pid 751901:tid 752047] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/file.php"] [unique_id "amuJtirT982lovRn7gm1zAAAABA"]
[Thu Jul 30 12:28:23.170531 2026] [security2:error] [pid 751901:tid 752132] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/wp-load.php"] [unique_id "amuJtyrT982lovRn7gm10QAAAGU"]
[Thu Jul 30 12:28:23.170641 2026] [security2:error] [pid 751901:tid 752132] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/wp-load.php"] [unique_id "amuJtyrT982lovRn7gm10QAAAGU"]
[Thu Jul 30 12:28:23.408105 2026] [security2:error] [pid 751901:tid 752108] [client 139.28.219.70:53388] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kamiliacademy.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuJtyrT982lovRn7gm13AAAAE0"]
[Thu Jul 30 12:28:23.410341 2026] [core:notice] [pid 751901:tid 752153] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:23.415726 2026] [security2:error] [pid 751901:tid 752153] [client 103.215.74.26:32860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJtyrT982lovRn7gm13QAAAHo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:23.462709 2026] [security2:error] [pid 751901:tid 752134] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/___proxy_subdomain_webdisk/wp-includes/assets/"] [unique_id "amuJtyrT982lovRn7gm13gAAAGc"]
[Thu Jul 30 12:28:23.572493 2026] [security2:error] [pid 751901:tid 751944] [remote 74.7.241.59:52372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuJtyrT982lovRn7gm13wAAbio"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/theme-builder/documents
[Thu Jul 30 12:28:23.639629 2026] [security2:error] [pid 751901:tid 752036] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/colors/sunrise/"] [unique_id "amuJtyrT982lovRn7gm14QAAAAU"]
[Thu Jul 30 12:28:23.758733 2026] [security2:error] [pid 751901:tid 751945] [remote 57.141.0.6:40418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/706661964/feed/rss2/"] [unique_id "amuJtyrT982lovRn7gm14gAAAis"]
[Thu Jul 30 12:28:23.801519 2026] [security2:error] [pid 751901:tid 752155] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "amuJtyrT982lovRn7gm14wAAAHw"]
[Thu Jul 30 12:28:23.801643 2026] [security2:error] [pid 751901:tid 752155] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "amuJtyrT982lovRn7gm14wAAAHw"]
[Thu Jul 30 12:28:23.931742 2026] [security2:error] [pid 751901:tid 752109] [client 139.28.219.70:53400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kamiliacademy.com"] [uri "/xmlrpc.php"] [unique_id "amuJtyrT982lovRn7gm16wAAAE4"]
[Thu Jul 30 12:28:24.042502 2026] [security2:error] [pid 751901:tid 752049] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/a.php"] [unique_id "amuJuCrT982lovRn7gm17wAAABI"]
[Thu Jul 30 12:28:24.042649 2026] [security2:error] [pid 751901:tid 752049] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/a.php"] [unique_id "amuJuCrT982lovRn7gm17wAAABI"]
[Thu Jul 30 12:28:24.143550 2026] [core:notice] [pid 751901:tid 752067] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:24.148527 2026] [security2:error] [pid 751901:tid 752067] [client 103.215.74.26:32876] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJuCrT982lovRn7gm18AAAACQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:24.296943 2026] [security2:error] [pid 751901:tid 752119] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/4PJcpMFsD8B.php"] [unique_id "amuJuCrT982lovRn7gm18QAAAFg"]
[Thu Jul 30 12:28:24.297086 2026] [security2:error] [pid 751901:tid 752119] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/4PJcpMFsD8B.php"] [unique_id "amuJuCrT982lovRn7gm18QAAAFg"]
[Thu Jul 30 12:28:24.381747 2026] [security2:error] [pid 751901:tid 752034] [client 2a03:2880:f800:27:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJtyrT982lovRn7gm12wAAAyQ"]
[Thu Jul 30 12:28:24.531992 2026] [security2:error] [pid 751901:tid 752101] [client 180.253.34.69:63253] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "toscanamall.com"] [uri "/admin/login"] [unique_id "amuJuCrT982lovRn7gm1-wAAAEY"]
[Thu Jul 30 12:28:24.671922 2026] [security2:error] [pid 751901:tid 751952] [remote 57.141.0.48:20018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuJuCrT982lovRn7gm1_AAAYTI"]
[Thu Jul 30 12:28:24.835364 2026] [security2:error] [pid 751901:tid 752055] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/aa.php"] [unique_id "amuJuCrT982lovRn7gm1_QAAABg"]
[Thu Jul 30 12:28:24.835490 2026] [security2:error] [pid 751901:tid 752055] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/aa.php"] [unique_id "amuJuCrT982lovRn7gm1_QAAABg"]
[Thu Jul 30 12:28:24.888246 2026] [core:notice] [pid 751901:tid 752123] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:24.892242 2026] [security2:error] [pid 751901:tid 752123] [client 103.215.74.26:32892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJuCrT982lovRn7gm2AQAAAFw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:24.980093 2026] [security2:error] [pid 751901:tid 752121] [client 52.238.199.152:51659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amuJuCrT982lovRn7gm2BQAAAFo"]
[Thu Jul 30 12:28:25.090571 2026] [security2:error] [pid 751901:tid 752139] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/177.php"] [unique_id "amuJuSrT982lovRn7gm2BwAAAGw"]
[Thu Jul 30 12:28:25.090669 2026] [security2:error] [pid 751901:tid 752139] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/177.php"] [unique_id "amuJuSrT982lovRn7gm2BwAAAGw"]
[Thu Jul 30 12:28:25.302385 2026] [security2:error] [pid 751901:tid 752092] [client 74.7.230.50:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.met.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuJtirT982lovRn7gm1wQAAAD0"]
[Thu Jul 30 12:28:25.302414 2026] [security2:error] [pid 751901:tid 752092] [client 74.7.230.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.met.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuJtirT982lovRn7gm1wQAAAD0"]
[Thu Jul 30 12:28:25.303111 2026] [security2:error] [pid 751901:tid 752053] [client 74.7.230.50:55582] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.met.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuJtirT982lovRn7gm1vQAAFh0"]
[Thu Jul 30 12:28:25.345897 2026] [security2:error] [pid 751901:tid 752084] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/coffexium.php"] [unique_id "amuJuSrT982lovRn7gm2CQAAADU"]
[Thu Jul 30 12:28:25.346010 2026] [security2:error] [pid 751901:tid 752084] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/coffexium.php"] [unique_id "amuJuSrT982lovRn7gm2CQAAADU"]
[Thu Jul 30 12:28:25.619385 2026] [security2:error] [pid 751901:tid 752093] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/fffm.php"] [unique_id "amuJuSrT982lovRn7gm2FAAAAD4"]
[Thu Jul 30 12:28:25.619539 2026] [security2:error] [pid 751901:tid 752093] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/fffm.php"] [unique_id "amuJuSrT982lovRn7gm2FAAAAD4"]
[Thu Jul 30 12:28:25.636960 2026] [core:notice] [pid 751901:tid 752151] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:25.641587 2026] [security2:error] [pid 751901:tid 752151] [client 103.215.74.26:32894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJuSrT982lovRn7gm2FQAAAHg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:25.854208 2026] [security2:error] [pid 751901:tid 752076] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/82.php"] [unique_id "amuJuSrT982lovRn7gm2GQAAAC0"]
[Thu Jul 30 12:28:25.854342 2026] [security2:error] [pid 751901:tid 752076] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/82.php"] [unique_id "amuJuSrT982lovRn7gm2GQAAAC0"]
[Thu Jul 30 12:28:26.002182 2026] [security2:error] [pid 751901:tid 752140] [client 52.238.199.152:42964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/hehe.php"] [unique_id "amuJuirT982lovRn7gm2IwAAAG0"]
[Thu Jul 30 12:28:26.004816 2026] [security2:error] [pid 751901:tid 752042] [client 38.190.144.4:55475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJuirT982lovRn7gm2JAAAAAs"]
[Thu Jul 30 12:28:26.004921 2026] [security2:error] [pid 751901:tid 752042] [client 38.190.144.4:55475] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJuirT982lovRn7gm2JAAAAAs"]
[Thu Jul 30 12:28:26.095133 2026] [security2:error] [pid 751901:tid 752104] [client 74.7.230.50:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "met.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuJuSrT982lovRn7gm2IQAAAEk"], referer: https://www.met.nyx.temporary.site/robots.txt
[Thu Jul 30 12:28:26.095922 2026] [security2:error] [pid 751901:tid 752152] [client 74.7.230.50:55592] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "met.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuJuSrT982lovRn7gm2HQAAeTc"], referer: https://www.met.nyx.temporary.site/robots.txt
[Thu Jul 30 12:28:26.118481 2026] [security2:error] [pid 751901:tid 752127] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/config.json.php"] [unique_id "amuJuirT982lovRn7gm2JQAAAGA"]
[Thu Jul 30 12:28:26.118569 2026] [security2:error] [pid 751901:tid 752127] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/config.json.php"] [unique_id "amuJuirT982lovRn7gm2JQAAAGA"]
[Thu Jul 30 12:28:26.358639 2026] [core:notice] [pid 751901:tid 752107] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:26.359391 2026] [security2:error] [pid 751901:tid 752057] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/fpwch.php"] [unique_id "amuJuirT982lovRn7gm2KgAAABo"]
[Thu Jul 30 12:28:26.359500 2026] [security2:error] [pid 751901:tid 752057] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/fpwch.php"] [unique_id "amuJuirT982lovRn7gm2KgAAABo"]
[Thu Jul 30 12:28:26.362789 2026] [security2:error] [pid 751901:tid 752107] [client 103.215.74.26:32896] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJuirT982lovRn7gm2KAAAAEw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:26.608437 2026] [security2:error] [pid 751901:tid 752113] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/xp.php"] [unique_id "amuJuirT982lovRn7gm2NAAAAFI"]
[Thu Jul 30 12:28:26.608572 2026] [security2:error] [pid 751901:tid 752113] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/xp.php"] [unique_id "amuJuirT982lovRn7gm2NAAAAFI"]
[Thu Jul 30 12:28:26.659936 2026] [security2:error] [pid 751901:tid 752097] [client 74.7.244.26:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cpanel.lapakjitu78.com"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amuJuirT982lovRn7gm2NQAAAEI"]
[Thu Jul 30 12:28:27.097232 2026] [core:notice] [pid 751901:tid 752055] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:27.102119 2026] [security2:error] [pid 751901:tid 752055] [client 103.215.74.26:32902] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJuyrT982lovRn7gm2QwAAABg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:27.656628 2026] [security2:error] [pid 751901:tid 752064] [client 139.28.219.70:53416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kamiliacademy.com"] [uri "/xmlrpc.php"] [unique_id "amuJuyrT982lovRn7gm2TgAAACE"]
[Thu Jul 30 12:28:27.656731 2026] [security2:error] [pid 751901:tid 752064] [client 139.28.219.70:53416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kamiliacademy.com"] [uri "/xmlrpc.php"] [unique_id "amuJuyrT982lovRn7gm2TgAAACE"]
[Thu Jul 30 12:28:27.826900 2026] [core:notice] [pid 751901:tid 752080] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:27.832158 2026] [security2:error] [pid 751901:tid 752080] [client 103.215.74.26:32912] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJuyrT982lovRn7gm2TwAAADE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:27.871441 2026] [security2:error] [pid 751901:tid 752118] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/reop3.php"] [unique_id "amuJuyrT982lovRn7gm2UAAAAFc"]
[Thu Jul 30 12:28:27.871592 2026] [security2:error] [pid 751901:tid 752118] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/reop3.php"] [unique_id "amuJuyrT982lovRn7gm2UAAAAFc"]
[Thu Jul 30 12:28:28.133928 2026] [security2:error] [pid 751901:tid 752151] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/___proxy_subdomain_webdisk/wp-includes/Requests/"] [unique_id "amuJvCrT982lovRn7gm2WQAAAHg"]
[Thu Jul 30 12:28:28.183445 2026] [security2:error] [pid 751901:tid 752130] [client 139.28.219.70:53428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kamiliacademy.com"] [uri "/xmlrpc.php"] [unique_id "amuJvCrT982lovRn7gm2WgAAAGM"]
[Thu Jul 30 12:28:28.183551 2026] [security2:error] [pid 751901:tid 752130] [client 139.28.219.70:53428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kamiliacademy.com"] [uri "/xmlrpc.php"] [unique_id "amuJvCrT982lovRn7gm2WgAAAGM"]
[Thu Jul 30 12:28:28.267274 2026] [security2:error] [pid 751901:tid 752125] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/wp.php"] [unique_id "amuJvCrT982lovRn7gm2XwAAAF4"]
[Thu Jul 30 12:28:28.267389 2026] [security2:error] [pid 751901:tid 752125] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/wp.php"] [unique_id "amuJvCrT982lovRn7gm2XwAAAF4"]
[Thu Jul 30 12:28:28.550686 2026] [security2:error] [pid 751901:tid 752127] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/dex.php"] [unique_id "amuJvCrT982lovRn7gm2ZQAAAGA"]
[Thu Jul 30 12:28:28.550781 2026] [security2:error] [pid 751901:tid 752127] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/dex.php"] [unique_id "amuJvCrT982lovRn7gm2ZQAAAGA"]
[Thu Jul 30 12:28:28.583440 2026] [core:notice] [pid 751901:tid 752059] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:28.587534 2026] [security2:error] [pid 751901:tid 752059] [client 103.215.74.26:32914] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJvCrT982lovRn7gm2ZwAAABw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:28.810243 2026] [security2:error] [pid 751901:tid 752049] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/biufile.php"] [unique_id "amuJvCrT982lovRn7gm2aQAAABI"]
[Thu Jul 30 12:28:28.810395 2026] [security2:error] [pid 751901:tid 752049] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/biufile.php"] [unique_id "amuJvCrT982lovRn7gm2aQAAABI"]
[Thu Jul 30 12:28:29.065837 2026] [security2:error] [pid 751901:tid 752103] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/inputs.php"] [unique_id "amuJvSrT982lovRn7gm2dQAAAEg"]
[Thu Jul 30 12:28:29.065916 2026] [security2:error] [pid 751901:tid 752103] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/inputs.php"] [unique_id "amuJvSrT982lovRn7gm2dQAAAEg"]
[Thu Jul 30 12:28:29.322372 2026] [core:notice] [pid 751901:tid 752101] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:29.323053 2026] [security2:error] [pid 751901:tid 752034] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/inputs.php"] [unique_id "amuJvSrT982lovRn7gm2egAAAAM"]
[Thu Jul 30 12:28:29.323188 2026] [security2:error] [pid 751901:tid 752034] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/inputs.php"] [unique_id "amuJvSrT982lovRn7gm2egAAAAM"]
[Thu Jul 30 12:28:29.326815 2026] [security2:error] [pid 751901:tid 752101] [client 103.215.74.26:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJvSrT982lovRn7gm2eQAAAEY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:29.565689 2026] [security2:error] [pid 751901:tid 752137] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/adminfuns.php"] [unique_id "amuJvSrT982lovRn7gm2fwAAAGo"]
[Thu Jul 30 12:28:29.565799 2026] [security2:error] [pid 751901:tid 752137] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/adminfuns.php"] [unique_id "amuJvSrT982lovRn7gm2fwAAAGo"]
[Thu Jul 30 12:28:29.614211 2026] [security2:error] [pid 751901:tid 752041] [client 52.238.199.152:18143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/options.php"] [unique_id "amuJvSrT982lovRn7gm2gAAAAAo"]
[Thu Jul 30 12:28:29.808792 2026] [security2:error] [pid 751901:tid 752143] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/goods.php"] [unique_id "amuJvSrT982lovRn7gm2hAAAAHA"]
[Thu Jul 30 12:28:29.808915 2026] [security2:error] [pid 751901:tid 752143] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/goods.php"] [unique_id "amuJvSrT982lovRn7gm2hAAAAHA"]
[Thu Jul 30 12:28:30.053908 2026] [core:notice] [pid 751901:tid 752055] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:30.059165 2026] [security2:error] [pid 751901:tid 752055] [client 103.215.74.26:32932] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJvirT982lovRn7gm2hwAAABg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:30.063865 2026] [security2:error] [pid 751901:tid 752142] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/about.php"] [unique_id "amuJvirT982lovRn7gm2iQAAAG8"]
[Thu Jul 30 12:28:30.063958 2026] [security2:error] [pid 751901:tid 752142] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/about.php"] [unique_id "amuJvirT982lovRn7gm2iQAAAG8"]
[Thu Jul 30 12:28:30.315692 2026] [security2:error] [pid 751901:tid 752056] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/about.php"] [unique_id "amuJvirT982lovRn7gm2jwAAABk"]
[Thu Jul 30 12:28:30.315804 2026] [security2:error] [pid 751901:tid 752056] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/about.php"] [unique_id "amuJvirT982lovRn7gm2jwAAABk"]
[Thu Jul 30 12:28:30.485667 2026] [security2:error] [pid 751901:tid 752081] [client 52.238.199.152:42996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amuJvirT982lovRn7gm2kAAAADI"]
[Thu Jul 30 12:28:30.539046 2026] [autoindex:error] [pid 751901:tid 752132] [client 43.153.58.28:53984] AH01276: Cannot serve directory /home2/meggzjte/adbacklink.com/bbs/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://adbacklink.com/bbs
[Thu Jul 30 12:28:30.580042 2026] [security2:error] [pid 751901:tid 752064] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/admin.php"] [unique_id "amuJvirT982lovRn7gm2kgAAACE"]
[Thu Jul 30 12:28:30.580137 2026] [security2:error] [pid 751901:tid 752064] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/admin.php"] [unique_id "amuJvirT982lovRn7gm2kgAAACE"]
[Thu Jul 30 12:28:30.799106 2026] [core:notice] [pid 751901:tid 752053] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:30.804682 2026] [security2:error] [pid 751901:tid 752053] [client 103.215.74.26:32948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJvirT982lovRn7gm2mQAAABY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:30.814695 2026] [security2:error] [pid 751901:tid 752151] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/admin.php"] [unique_id "amuJvirT982lovRn7gm2mgAAAHg"]
[Thu Jul 30 12:28:30.814783 2026] [security2:error] [pid 751901:tid 752151] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/admin.php"] [unique_id "amuJvirT982lovRn7gm2mgAAAHg"]
[Thu Jul 30 12:28:31.065261 2026] [security2:error] [pid 751901:tid 752141] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/chosen.php"] [unique_id "amuJvyrT982lovRn7gm2nAAAAG4"]
[Thu Jul 30 12:28:31.065377 2026] [security2:error] [pid 751901:tid 752141] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/chosen.php"] [unique_id "amuJvyrT982lovRn7gm2nAAAAG4"]
[Thu Jul 30 12:28:31.532361 2026] [core:notice] [pid 751901:tid 752061] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:31.537320 2026] [security2:error] [pid 751901:tid 752061] [client 103.215.74.26:32964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJvyrT982lovRn7gm2owAAAB4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:31.871523 2026] [core:notice] [pid 751901:tid 752090] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:32.000003 2026] [security2:error] [pid 751901:tid 752062] [client 188.163.72.169:46516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.72.163.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "voyagegetaways.com"] [uri "/xmlrpc.php"] [unique_id "amuJvyrT982lovRn7gm2rAAAAB8"]
[Thu Jul 30 12:28:32.000151 2026] [security2:error] [pid 751901:tid 752062] [client 188.163.72.169:46516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "voyagegetaways.com"] [uri "/xmlrpc.php"] [unique_id "amuJvyrT982lovRn7gm2rAAAAB8"]
[Thu Jul 30 12:28:32.113701 2026] [security2:error] [pid 751901:tid 752059] [client 52.238.199.152:17939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/images/index.php"] [unique_id "amuJwCrT982lovRn7gm2rwAAABw"]
[Thu Jul 30 12:28:32.290012 2026] [core:notice] [pid 751901:tid 752087] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:32.294141 2026] [security2:error] [pid 751901:tid 752087] [client 103.215.74.26:32978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJwCrT982lovRn7gm2uQAAADg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:32.595431 2026] [security2:error] [pid 751901:tid 751996] [remote 216.73.216.152:5122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuJwCrT982lovRn7gm2vAAAB14"]
[Thu Jul 30 12:28:33.033464 2026] [core:notice] [pid 751901:tid 752066] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:33.037512 2026] [security2:error] [pid 751901:tid 752066] [client 103.215.74.26:42048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJwSrT982lovRn7gm2wwAAACM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:33.757239 2026] [core:notice] [pid 751901:tid 752132] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:33.762006 2026] [security2:error] [pid 751901:tid 752132] [client 103.215.74.26:42058] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJwSrT982lovRn7gm20gAAAGU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:34.035786 2026] [security2:error] [pid 751901:tid 752143] [client 52.238.199.152:43000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-content/uploads/index.php"] [unique_id "amuJwirT982lovRn7gm22wAAAHA"]
[Thu Jul 30 12:28:34.500488 2026] [core:notice] [pid 751901:tid 752156] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:34.505050 2026] [security2:error] [pid 751901:tid 752156] [client 103.215.74.26:42060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJwirT982lovRn7gm24wAAAH0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:34.945251 2026] [security2:error] [pid 751901:tid 752129] [client 118.212.121.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJwirT982lovRn7gm25AAAAGI"]
[Thu Jul 30 12:28:35.022746 2026] [proxy:error] [pid 751901:tid 752059] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:28:35.022807 2026] [proxy_http:error] [pid 751901:tid 752059] [client 18.211.55.47:29157] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:28:35.023963 2026] [proxy:error] [pid 751901:tid 752059] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:28:35.024036 2026] [proxy_http:error] [pid 751901:tid 752059] [client 18.211.55.47:29157] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:28:35.027869 2026] [proxy:error] [pid 751901:tid 752052] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:28:35.027932 2026] [proxy_http:error] [pid 751901:tid 752052] [client 18.211.55.47:54773] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:28:35.028581 2026] [proxy:error] [pid 751901:tid 752052] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:28:35.028634 2026] [proxy_http:error] [pid 751901:tid 752052] [client 18.211.55.47:54773] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:28:35.244934 2026] [core:notice] [pid 751901:tid 752068] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:35.251424 2026] [security2:error] [pid 751901:tid 752068] [client 103.215.74.26:42066] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJwyrT982lovRn7gm29AAAACU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:35.610854 2026] [security2:error] [pid 751901:tid 752103] [client 52.238.199.152:17926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/13.php"] [unique_id "amuJwyrT982lovRn7gm2_AAAAEg"]
[Thu Jul 30 12:28:35.994717 2026] [core:notice] [pid 751901:tid 752075] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:36.002514 2026] [security2:error] [pid 751901:tid 752075] [client 103.215.74.26:42078] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJwyrT982lovRn7gm3BAAAACw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:36.295324 2026] [security2:error] [pid 751901:tid 752146] [client 118.212.121.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJwyrT982lovRn7gm3AAAAAHM"]
[Thu Jul 30 12:28:36.731349 2026] [core:notice] [pid 751901:tid 752147] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:36.735477 2026] [security2:error] [pid 751901:tid 752147] [client 103.215.74.26:42086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJxCrT982lovRn7gm3DQAAAHQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:37.102637 2026] [security2:error] [pid 751901:tid 752040] [client 37.120.155.179:45812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.155.120.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuJxSrT982lovRn7gm3GwAAAAk"]
[Thu Jul 30 12:28:37.102732 2026] [security2:error] [pid 751901:tid 752040] [client 37.120.155.179:45812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuJxSrT982lovRn7gm3GwAAAAk"]
[Thu Jul 30 12:28:37.310790 2026] [security2:error] [pid 751901:tid 752050] [client 52.238.199.152:42995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/inputs.php"] [unique_id "amuJxSrT982lovRn7gm3HgAAABM"]
[Thu Jul 30 12:28:37.454308 2026] [core:notice] [pid 751901:tid 752076] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:37.458540 2026] [security2:error] [pid 751901:tid 752076] [client 103.215.74.26:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "767"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJxSrT982lovRn7gm3IAAAAC0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:37.823461 2026] [security2:error] [pid 751901:tid 752025] [remote 74.7.241.60:41994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/js/article.php"] [unique_id "amuJxSrT982lovRn7gm3KgAAe3s"], referer: https://aded-rdc.org/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/js/bootstrap.bundle.min.js
[Thu Jul 30 12:28:38.047826 2026] [security2:error] [pid 751901:tid 752125] [client 38.190.144.4:55987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJxirT982lovRn7gm3LgAAAF4"]
[Thu Jul 30 12:28:38.047949 2026] [security2:error] [pid 751901:tid 752125] [client 38.190.144.4:55987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJxirT982lovRn7gm3LgAAAF4"]
[Thu Jul 30 12:28:38.196386 2026] [core:notice] [pid 751901:tid 752129] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:38.202887 2026] [security2:error] [pid 751901:tid 752129] [client 103.215.74.26:42106] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJxirT982lovRn7gm3MwAAAGI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:39.828266 2026] [security2:error] [pid 751901:tid 752099] [client 52.238.199.152:49485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/jquery.php"] [unique_id "amuJxyrT982lovRn7gm3UgAAAEQ"]
[Thu Jul 30 12:28:40.295863 2026] [core:notice] [pid 751901:tid 752134] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:40.383900 2026] [autoindex:error] [pid 751901:tid 752093] [client 135.235.139.114:65016] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_6041258f/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Thu Jul 30 12:28:40.458692 2026] [security2:error] [pid 751901:tid 752095] [client 74.7.175.157:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-a97a7679.dlr.djb.temporary.site"] [uri "/index.php"] [unique_id "amuJxyrT982lovRn7gm3SwAAAEA"]
[Thu Jul 30 12:28:40.459570 2026] [security2:error] [pid 751901:tid 752090] [client 74.7.175.157:34026] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-a97a7679.dlr.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amuJxyrT982lovRn7gm3SQAAOw8"]
[Thu Jul 30 12:28:40.874017 2026] [security2:error] [pid 751901:tid 752039] [client 52.238.199.152:49526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/doc.php"] [unique_id "amuJyCrT982lovRn7gm3ZgAAAAg"]
[Thu Jul 30 12:28:41.651938 2026] [security2:error] [pid 751901:tid 752078] [client 57.141.0.51:45114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuJySrT982lovRn7gm3bgAALwE"], referer: https://igetvape-australia.com/product-tag/iget-moon-strawberry-watermelon-ice-5000-puffs/
[Thu Jul 30 12:28:41.959395 2026] [security2:error] [pid 751901:tid 752110] [client 52.238.199.152:49490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/02.php"] [unique_id "amuJySrT982lovRn7gm3dwAAAE8"]
[Thu Jul 30 12:28:42.008600 2026] [security2:error] [pid 751901:tid 752096] [client 118.212.121.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJySrT982lovRn7gm3bwAAAEE"]
[Thu Jul 30 12:28:43.322753 2026] [security2:error] [pid 751901:tid 752083] [client 118.212.121.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJyirT982lovRn7gm3igAAADQ"]
[Thu Jul 30 12:28:43.992184 2026] [core:notice] [pid 751901:tid 752157] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:43.997594 2026] [security2:error] [pid 751901:tid 752157] [client 103.215.74.26:43586] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "780"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJyyrT982lovRn7gm3oAAAAH4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:44.664222 2026] [security2:error] [pid 751901:tid 752067] [client 118.212.121.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJzCrT982lovRn7gm3pAAAACQ"]
[Thu Jul 30 12:28:44.716485 2026] [core:notice] [pid 751901:tid 752131] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:44.720464 2026] [security2:error] [pid 751901:tid 752131] [client 103.215.74.26:43594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJzCrT982lovRn7gm3qwAAAGQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:45.451327 2026] [core:notice] [pid 751901:tid 752060] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:45.455643 2026] [security2:error] [pid 751901:tid 752060] [client 103.215.74.26:43606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJzSrT982lovRn7gm3tgAAAB0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:45.965822 2026] [security2:error] [pid 751901:tid 752137] [client 118.212.121.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJzSrT982lovRn7gm3ugAAAGo"]
[Thu Jul 30 12:28:46.192842 2026] [core:notice] [pid 751901:tid 752124] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:46.196955 2026] [security2:error] [pid 751901:tid 752124] [client 103.215.74.26:43608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJzirT982lovRn7gm3wQAAAF0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:46.934218 2026] [core:notice] [pid 751901:tid 752151] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:46.941299 2026] [security2:error] [pid 751901:tid 752151] [client 103.215.74.26:43620] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJzirT982lovRn7gm3zAAAAHg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:47.267787 2026] [security2:error] [pid 751901:tid 752141] [client 118.212.121.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJzirT982lovRn7gm3zQAAAG4"]
[Thu Jul 30 12:28:47.658389 2026] [core:notice] [pid 751901:tid 752106] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:47.662477 2026] [security2:error] [pid 751901:tid 752106] [client 103.215.74.26:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJzyrT982lovRn7gm32wAAAEs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:47.721824 2026] [security2:error] [pid 751901:tid 752050] [client 38.190.144.4:56481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJzyrT982lovRn7gm33AAAABM"]
[Thu Jul 30 12:28:47.722053 2026] [security2:error] [pid 751901:tid 752050] [client 38.190.144.4:56481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJzyrT982lovRn7gm33AAAABM"]
[Thu Jul 30 12:28:48.384629 2026] [core:notice] [pid 751901:tid 752145] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:48.389621 2026] [security2:error] [pid 751901:tid 752145] [client 103.215.74.26:43640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ0CrT982lovRn7gm35gAAAHI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:48.889417 2026] [security2:error] [pid 751901:tid 752144] [client 2a03:2880:f800:16:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJ0CrT982lovRn7gm35QAAcTk"]
[Thu Jul 30 12:28:49.130716 2026] [core:notice] [pid 751901:tid 752052] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:49.135366 2026] [security2:error] [pid 751901:tid 752052] [client 103.215.74.26:43646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ0SrT982lovRn7gm38AAAABU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:49.866248 2026] [core:notice] [pid 751901:tid 752038] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:49.870991 2026] [security2:error] [pid 751901:tid 752038] [client 103.215.74.26:43660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ0SrT982lovRn7gm3_AAAAAc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:50.272807 2026] [security2:error] [pid 751901:tid 751969] [remote 152.228.213.32:40522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-login.php"] [unique_id "amuJ0irT982lovRn7gm4BgAAKkM"]
[Thu Jul 30 12:28:50.604522 2026] [core:notice] [pid 751901:tid 752114] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:50.608904 2026] [security2:error] [pid 751901:tid 752114] [client 103.215.74.26:43676] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ0irT982lovRn7gm4CwAAAFM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:51.395533 2026] [core:notice] [pid 751901:tid 752077] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:51.400123 2026] [security2:error] [pid 751901:tid 752077] [client 103.215.74.26:43690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ0yrT982lovRn7gm4FgAAAC4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:52.010912 2026] [security2:error] [pid 751901:tid 752130] [client 52.238.199.152:17502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/well-known/admin.php"] [unique_id "amuJ1CrT982lovRn7gm4JQAAAGM"]
[Thu Jul 30 12:28:52.118967 2026] [core:notice] [pid 751901:tid 752109] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:52.123467 2026] [security2:error] [pid 751901:tid 752109] [client 103.215.74.26:43698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ1CrT982lovRn7gm4KAAAAE4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:52.138491 2026] [security2:error] [pid 751901:tid 752141] [client 87.248.116.215:38182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.alseermarine.com"] [uri "/index.php"] [unique_id "amuJ0yrT982lovRn7gm4HQAAAG4"]
[Thu Jul 30 12:28:52.550341 2026] [security2:error] [pid 751901:tid 752058] [client 57.141.0.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJ0yrT982lovRn7gm4IwAAABs"]
[Thu Jul 30 12:28:52.855890 2026] [core:notice] [pid 751901:tid 752068] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:52.860354 2026] [security2:error] [pid 751901:tid 752068] [client 103.215.74.26:43700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ1CrT982lovRn7gm4OQAAACU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:53.024213 2026] [security2:error] [pid 751901:tid 752078] [client 87.248.116.215:38184] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ1CrT982lovRn7gm4MQAAAC8"]
[Thu Jul 30 12:28:53.572700 2026] [core:notice] [pid 751901:tid 752121] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:53.577168 2026] [security2:error] [pid 751901:tid 752121] [client 103.215.74.26:36300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ1SrT982lovRn7gm4SwAAAFo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:54.314200 2026] [core:notice] [pid 751901:tid 752149] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:54.318517 2026] [security2:error] [pid 751901:tid 752149] [client 103.215.74.26:36308] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ1irT982lovRn7gm4WAAAAHY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:54.333096 2026] [security2:error] [pid 751901:tid 752132] [client 118.212.121.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJ1SrT982lovRn7gm4VQAAAGU"]
[Thu Jul 30 12:28:54.586096 2026] [security2:error] [pid 751901:tid 752090] [client 52.238.199.152:18130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/v.php"] [unique_id "amuJ1irT982lovRn7gm4YwAAADs"]
[Thu Jul 30 12:28:55.007046 2026] [security2:error] [pid 751901:tid 751990] [remote 97.74.87.194:33376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koriusa.info"] [uri "/wp-login.php"] [unique_id "amuJ1yrT982lovRn7gm4aAAAc1g"]
[Thu Jul 30 12:28:55.523031 2026] [security2:error] [pid 751901:tid 752151] [client 83.38.36.245:39550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mediaspawn.com"] [uri "/index.php"] [unique_id "amuJ1irT982lovRn7gm4XAAAAHg"]
[Thu Jul 30 12:28:55.540472 2026] [security2:error] [pid 751901:tid 752033] [client 52.238.199.152:40135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/main.php"] [unique_id "amuJ1yrT982lovRn7gm4cgAAAAI"]
[Thu Jul 30 12:28:55.551947 2026] [security2:error] [pid 751901:tid 752040] [client 62.102.148.166:46340] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuJ1yrT982lovRn7gm4dAAAAAk"]
[Thu Jul 30 12:28:55.552048 2026] [security2:error] [pid 751901:tid 752040] [client 62.102.148.166:46340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuJ1yrT982lovRn7gm4dAAAAAk"]
[Thu Jul 30 12:28:55.678702 2026] [security2:error] [pid 751901:tid 752141] [client 118.212.121.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJ1yrT982lovRn7gm4bQAAAG4"]
[Thu Jul 30 12:28:57.058062 2026] [security2:error] [pid 751901:tid 752065] [client 118.212.121.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJ2CrT982lovRn7gm4hQAAACI"]
[Thu Jul 30 12:28:57.628168 2026] [security2:error] [pid 751901:tid 752010] [remote 216.73.216.152:54042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuJ2SrT982lovRn7gm4kwAAMGw"]
[Thu Jul 30 12:28:58.380020 2026] [security2:error] [pid 751901:tid 752120] [client 38.190.144.4:56971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJ2irT982lovRn7gm4ngAAAFk"]
[Thu Jul 30 12:28:58.380172 2026] [security2:error] [pid 751901:tid 752120] [client 38.190.144.4:56971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJ2irT982lovRn7gm4ngAAAFk"]
[Thu Jul 30 12:28:58.831755 2026] [security2:error] [pid 751901:tid 752072] [client 2a03:2880:f800:22:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJ2irT982lovRn7gm4mgAAKXA"]
[Thu Jul 30 12:28:58.959740 2026] [security2:error] [pid 751901:tid 752153] [client 57.141.0.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJ2irT982lovRn7gm4nQAAAHo"]
[Thu Jul 30 12:28:58.974173 2026] [security2:error] [pid 751901:tid 752036] [client 52.238.199.152:40150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/.well-known/file.php"] [unique_id "amuJ2irT982lovRn7gm4pQAAAAU"]
[Thu Jul 30 12:28:59.438962 2026] [security2:error] [pid 751901:tid 752104] [client 118.212.121.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJ2yrT982lovRn7gm4qQAAAEk"]
[Thu Jul 30 12:29:00.105430 2026] [core:notice] [pid 751901:tid 752054] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:00.110863 2026] [security2:error] [pid 751901:tid 752054] [client 103.215.74.26:36310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ3CrT982lovRn7gm4tAAAABc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:00.834236 2026] [core:notice] [pid 751901:tid 752037] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:00.834462 2026] [security2:error] [pid 751901:tid 752067] [client 118.212.121.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJ3CrT982lovRn7gm4vQAAACQ"]
[Thu Jul 30 12:29:00.839273 2026] [security2:error] [pid 751901:tid 752037] [client 103.215.74.26:36320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ3CrT982lovRn7gm4xAAAAAY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:01.368246 2026] [security2:error] [pid 751901:tid 752119] [client 66.249.66.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJ3CrT982lovRn7gm4vAAAWHs"]
[Thu Jul 30 12:29:01.562061 2026] [core:notice] [pid 751901:tid 752158] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:01.566124 2026] [security2:error] [pid 751901:tid 752158] [client 103.215.74.26:36328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ3SrT982lovRn7gm40AAAAH8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:02.071112 2026] [security2:error] [pid 751901:tid 752066] [client 52.238.199.152:17532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "amuJ3irT982lovRn7gm42QAAACM"]
[Thu Jul 30 12:29:02.195097 2026] [security2:error] [pid 751901:tid 752082] [client 118.212.121.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJ3SrT982lovRn7gm41wAAADM"]
[Thu Jul 30 12:29:02.447147 2026] [core:notice] [pid 751901:tid 751912] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:02.452404 2026] [security2:error] [pid 751901:tid 752124] [client 45.38.206.95:63392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/tag/low-boots/\\xc2\\xbbhttp:/www.carnetdeshopping.com/wp-content/uploads/2015/10/bottines-\\xc3\\xa0-enfiler-aimee-topshop.jpg"] [unique_id "amuJ3irT982lovRn7gm42gAAXQo"], referer: https://carnetdeshopping.com/index.php/tag/low-boots/
[Thu Jul 30 12:29:02.521482 2026] [core:notice] [pid 751901:tid 751909] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:02.527184 2026] [security2:error] [pid 751901:tid 752136] [client 45.38.206.95:63406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/tag/low-boots/\\xc2\\xbbhttp:/www.carnetdeshopping.com/wp-content/uploads/2015/10/boots-regane_bocage.jpg"] [unique_id "amuJ3irT982lovRn7gm43gAAaQc"], referer: https://carnetdeshopping.com/index.php/tag/low-boots/
[Thu Jul 30 12:29:02.690037 2026] [core:notice] [pid 751901:tid 751920] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:02.695726 2026] [security2:error] [pid 751901:tid 752147] [client 45.38.206.95:63416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/tag/low-boots/\\xc2\\xbbhttp:/www.carnetdeshopping.com/wp-content/uploads/2015/10/bottines-tryane-mellow-yellow.jpg"] [unique_id "amuJ3irT982lovRn7gm44gAAdBI"], referer: https://carnetdeshopping.com/index.php/tag/low-boots/
[Thu Jul 30 12:29:03.009240 2026] [security2:error] [pid 751901:tid 751921] [remote 57.141.0.19:51306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/589953950/feed/rss2/"] [unique_id "amuJ3yrT982lovRn7gm46QAAcBM"]
[Thu Jul 30 12:29:03.557774 2026] [security2:error] [pid 751901:tid 752109] [client 118.212.121.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJ3yrT982lovRn7gm46gAAAE4"]
[Thu Jul 30 12:29:04.867423 2026] [security2:error] [pid 751901:tid 752062] [client 52.238.199.152:40177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "amuJ4CrT982lovRn7gm5EAAAAB8"]
[Thu Jul 30 12:29:04.956497 2026] [security2:error] [pid 751901:tid 752098] [client 118.212.121.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJ4CrT982lovRn7gm5DAAAAEM"]
[Thu Jul 30 12:29:06.630429 2026] [core:notice] [pid 751901:tid 752111] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:06.747098 2026] [security2:error] [pid 751901:tid 752040] [client 43.166.1.243:49366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.1.166.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/article.php"] [unique_id "amuJ4irT982lovRn7gm5LwAAAAk"]
[Thu Jul 30 12:29:06.890689 2026] [security2:error] [pid 751901:tid 752085] [client 52.238.199.152:56026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-content/file.php"] [unique_id "amuJ4irT982lovRn7gm5OAAAADY"]
[Thu Jul 30 12:29:07.305750 2026] [core:notice] [pid 751901:tid 752037] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:07.309694 2026] [security2:error] [pid 751901:tid 752037] [client 103.215.74.26:5966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ4yrT982lovRn7gm5QgAAAAY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:07.430610 2026] [security2:error] [pid 751901:tid 752071] [client 86.206.72.201:33152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJ4yrT982lovRn7gm5PQAAACg"], referer: http://pkf.jo
[Thu Jul 30 12:29:07.739900 2026] [security2:error] [pid 751901:tid 752075] [client 52.238.199.152:18138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-signup.php"] [unique_id "amuJ4yrT982lovRn7gm5UQAAACw"]
[Thu Jul 30 12:29:07.838722 2026] [security2:error] [pid 751901:tid 752121] [client 201.173.67.215:55509] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJ4yrT982lovRn7gm5SQAAAFo"], referer: http://pkf.jo
[Thu Jul 30 12:29:08.048793 2026] [core:notice] [pid 751901:tid 752084] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:08.054088 2026] [security2:error] [pid 751901:tid 752084] [client 103.215.74.26:5980] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ5CrT982lovRn7gm5VgAAADU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:08.076086 2026] [security2:error] [pid 751901:tid 752139] [client 57.141.0.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJ4yrT982lovRn7gm5SAAAAGw"]
[Thu Jul 30 12:29:08.330235 2026] [security2:error] [pid 751901:tid 752118] [client 103.167.233.58:31008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJ5CrT982lovRn7gm5VQAAAFc"], referer: http://pkf.jo
[Thu Jul 30 12:29:08.598017 2026] [security2:error] [pid 751901:tid 752074] [client 52.238.199.152:45471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-includes/css/index.php"] [unique_id "amuJ5CrT982lovRn7gm5XwAAACs"]
[Thu Jul 30 12:29:08.638782 2026] [core:notice] [pid 751901:tid 751931] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:08.643997 2026] [security2:error] [pid 751901:tid 752117] [client 48.44.107.214:13277] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/tag/low-boots/\\xc2\\xbbhttp:/www.carnetdeshopping.com/wp-content/uploads/2015/10/boots-rosilda-bocage.jpg"] [unique_id "amuJ5CrT982lovRn7gm5WgAAVh0"], referer: https://carnetdeshopping.com/index.php/tag/low-boots/
[Thu Jul 30 12:29:08.779523 2026] [core:notice] [pid 751901:tid 752090] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:08.786594 2026] [security2:error] [pid 751901:tid 752090] [client 103.215.74.26:5990] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ5CrT982lovRn7gm5ZgAAADs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:08.902602 2026] [security2:error] [pid 751901:tid 752106] [client 169.224.125.65:25238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJ5CrT982lovRn7gm5YAAAAEs"], referer: http://pkf.jo
[Thu Jul 30 12:29:09.462121 2026] [security2:error] [pid 751901:tid 752033] [client 197.244.73.187:46386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJ5SrT982lovRn7gm5cQAAAAI"], referer: http://pkf.jo
[Thu Jul 30 12:29:09.535560 2026] [core:notice] [pid 751901:tid 752131] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:09.543279 2026] [security2:error] [pid 751901:tid 752131] [client 103.215.74.26:6002] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ5SrT982lovRn7gm5ewAAAGQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:10.276164 2026] [core:notice] [pid 751901:tid 752066] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:10.280224 2026] [security2:error] [pid 751901:tid 752066] [client 103.215.74.26:6004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ5irT982lovRn7gm5pAAAACM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:11.932768 2026] [core:notice] [pid 751901:tid 751916] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:12.286643 2026] [security2:error] [pid 751901:tid 752035] [client 52.238.199.152:40144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/ge.php"] [unique_id "amuJ6CrT982lovRn7gm6AQAAAAQ"]
[Thu Jul 30 12:29:12.542587 2026] [security2:error] [pid 751901:tid 752107] [client 172.237.109.114:56610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ5yrT982lovRn7gm51QAAAEw"]
[Thu Jul 30 12:29:12.545523 2026] [security2:error] [pid 751901:tid 752154] [client 172.237.109.114:50967] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ5yrT982lovRn7gm52AAAAHs"]
[Thu Jul 30 12:29:12.548239 2026] [security2:error] [pid 751901:tid 752113] [client 172.237.109.114:31255] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ5yrT982lovRn7gm53AAAAFI"]
[Thu Jul 30 12:29:12.609593 2026] [security2:error] [pid 751901:tid 752089] [client 172.237.109.114:8582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ5yrT982lovRn7gm54gAAADo"]
[Thu Jul 30 12:29:12.624796 2026] [security2:error] [pid 751901:tid 752091] [client 172.237.109.114:63064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ5yrT982lovRn7gm55gAAADw"]
[Thu Jul 30 12:29:12.629919 2026] [core:notice] [pid 751901:tid 751928] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:12.633960 2026] [security2:error] [pid 751901:tid 752115] [client 172.237.109.114:29570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ5yrT982lovRn7gm50wAAAFQ"]
[Thu Jul 30 12:29:12.649846 2026] [security2:error] [pid 751901:tid 752039] [client 172.237.109.114:22448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ5yrT982lovRn7gm51AAAAAg"]
[Thu Jul 30 12:29:12.654698 2026] [security2:error] [pid 751901:tid 752108] [client 172.237.109.114:22804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ5yrT982lovRn7gm56AAAAE0"]
[Thu Jul 30 12:29:12.655948 2026] [security2:error] [pid 751901:tid 752050] [client 172.237.109.114:30201] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ5yrT982lovRn7gm53wAAABM"]
[Thu Jul 30 12:29:13.082571 2026] [core:error] [pid 751901:tid 752130] [client 74.7.244.15:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:29:13.082592 2026] [core:error] [pid 751901:tid 752130] [client 74.7.244.15:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:29:13.082696 2026] [security2:error] [pid 751901:tid 752130] [client 74.7.244.15:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.gfy.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "amuJ6SrT982lovRn7gm6FAAAAGM"]
[Thu Jul 30 12:29:13.083403 2026] [security2:error] [pid 751901:tid 752093] [client 74.7.244.15:40296] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.gfy.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "amuJ6SrT982lovRn7gm6EgAAPn8"]
[Thu Jul 30 12:29:13.229180 2026] [security2:error] [pid 751901:tid 752106] [client 172.237.109.114:43285] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ5yrT982lovRn7gm54wAAAEs"]
[Thu Jul 30 12:29:13.232798 2026] [security2:error] [pid 751901:tid 752046] [client 172.237.109.114:10490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ5yrT982lovRn7gm52QAAAA8"]
[Thu Jul 30 12:29:13.260250 2026] [security2:error] [pid 751901:tid 752143] [client 172.237.109.114:24123] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ5yrT982lovRn7gm54AAAAHA"]
[Thu Jul 30 12:29:13.261541 2026] [security2:error] [pid 751901:tid 752104] [client 172.237.109.114:55768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ5yrT982lovRn7gm51wAAAEk"]
[Thu Jul 30 12:29:13.272280 2026] [security2:error] [pid 751901:tid 752111] [client 172.237.109.114:41251] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ5yrT982lovRn7gm55QAAAFA"]
[Thu Jul 30 12:29:13.282708 2026] [security2:error] [pid 751901:tid 752156] [client 172.237.109.114:9166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ5yrT982lovRn7gm52gAAAH0"]
[Thu Jul 30 12:29:13.283103 2026] [security2:error] [pid 751901:tid 752076] [client 172.237.109.114:33311] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ5yrT982lovRn7gm53gAAAC0"]
[Thu Jul 30 12:29:13.420126 2026] [security2:error] [pid 751901:tid 752059] [client 172.237.109.114:63638] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ5yrT982lovRn7gm56QAAABw"]
[Thu Jul 30 12:29:13.468295 2026] [security2:error] [pid 751901:tid 752048] [client 172.237.109.114:55169] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ5yrT982lovRn7gm56wAAABE"]
[Thu Jul 30 12:29:13.476837 2026] [security2:error] [pid 751901:tid 752042] [client 172.237.109.114:25497] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ5yrT982lovRn7gm56gAAAAs"]
[Thu Jul 30 12:29:13.619548 2026] [security2:error] [pid 751901:tid 752158] [client 172.237.109.114:5522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ6CrT982lovRn7gm5_QAAAH8"]
[Thu Jul 30 12:29:13.758846 2026] [security2:error] [pid 751901:tid 752105] [client 57.141.0.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJ6SrT982lovRn7gm6FwAAAEo"]
[Thu Jul 30 12:29:14.085059 2026] [security2:error] [pid 751901:tid 752045] [client 212.237.119.48:24191] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJ6SrT982lovRn7gm6IwAAAA4"], referer: http://pkf.jo
[Thu Jul 30 12:29:15.436331 2026] [security2:error] [pid 751901:tid 752152] [client 52.238.199.152:18115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/goods.php"] [unique_id "amuJ6yrT982lovRn7gm6PAAAAHk"]
[Thu Jul 30 12:29:15.839816 2026] [core:notice] [pid 751901:tid 752076] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:16.059518 2026] [core:notice] [pid 751901:tid 752059] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:16.063725 2026] [security2:error] [pid 751901:tid 752059] [client 103.215.74.26:37478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "767"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ7CrT982lovRn7gm6YgAAABw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:16.399242 2026] [security2:error] [pid 751901:tid 752042] [client 52.238.199.152:57015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/403.php"] [unique_id "amuJ7CrT982lovRn7gm6cAAAAAs"]
[Thu Jul 30 12:29:16.518690 2026] [proxy:error] [pid 751901:tid 751979] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:29:16.518746 2026] [proxy_http:error] [pid 751901:tid 751979] [remote 158.173.67.31:10833] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:29:16.519354 2026] [proxy:error] [pid 751901:tid 751979] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:29:16.519398 2026] [proxy_http:error] [pid 751901:tid 751979] [remote 158.173.67.31:10833] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:29:16.787373 2026] [core:notice] [pid 751901:tid 752129] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:16.794460 2026] [security2:error] [pid 751901:tid 752129] [client 103.215.74.26:37490] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ7CrT982lovRn7gm6dgAAAGI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:16.798088 2026] [security2:error] [pid 751901:tid 752126] [client 66.249.90.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJ7CrT982lovRn7gm6ZQAAAF8"]
[Thu Jul 30 12:29:17.002546 2026] [core:error] [pid 751901:tid 751978] [remote 74.7.175.155:52242] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:29:17.002573 2026] [core:error] [pid 751901:tid 751978] [remote 74.7.175.155:52242] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:29:17.002784 2026] [security2:error] [pid 751901:tid 752031] [client 74.7.175.155:52242] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.ampcloudku.com"] [uri "/index.php"] [unique_id "amuJ7CrT982lovRn7gm6egAAAEw"]
[Thu Jul 30 12:29:17.346526 2026] [security2:error] [pid 751901:tid 752146] [client 52.238.199.152:62941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/public/makeasmtp.php"] [unique_id "amuJ7SrT982lovRn7gm6gAAAAHM"]
[Thu Jul 30 12:29:17.521994 2026] [core:notice] [pid 751901:tid 752066] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:17.526010 2026] [security2:error] [pid 751901:tid 752066] [client 103.215.74.26:37506] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "780"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ7SrT982lovRn7gm6hAAAACM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:18.252541 2026] [core:notice] [pid 751901:tid 752074] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:18.256451 2026] [security2:error] [pid 751901:tid 752074] [client 103.215.74.26:37514] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ7irT982lovRn7gm6kQAAACs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:18.977043 2026] [core:notice] [pid 751901:tid 752067] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:18.983999 2026] [security2:error] [pid 751901:tid 752067] [client 103.215.74.26:37520] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ7irT982lovRn7gm6ngAAACQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:19.112493 2026] [security2:error] [pid 751901:tid 752033] [client 43.173.71.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuJ7irT982lovRn7gm6mwAAAAI"], referer: http://cnpinyin.com/dict1?search=%e9%9f%b3
[Thu Jul 30 12:29:19.702893 2026] [core:notice] [pid 751901:tid 752150] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:19.706865 2026] [security2:error] [pid 751901:tid 752150] [client 103.215.74.26:37526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ7yrT982lovRn7gm6rAAAAHc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:20.390997 2026] [security2:error] [pid 751901:tid 752078] [client 52.238.199.152:17404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/mar.php"] [unique_id "amuJ8CrT982lovRn7gm6tgAAAC8"]
[Thu Jul 30 12:29:20.432148 2026] [core:notice] [pid 751901:tid 752126] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:20.436454 2026] [security2:error] [pid 751901:tid 752126] [client 103.215.74.26:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ8CrT982lovRn7gm6twAAAF8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:21.175210 2026] [core:notice] [pid 751901:tid 752146] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:21.181877 2026] [security2:error] [pid 751901:tid 752146] [client 103.215.74.26:37544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ8SrT982lovRn7gm6wgAAAHM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:21.492610 2026] [security2:error] [pid 751901:tid 752089] [client 2a03:2880:f800:1d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJ8CrT982lovRn7gm6vAAAOmg"]
[Thu Jul 30 12:29:21.556511 2026] [security2:error] [pid 751901:tid 752082] [client 52.238.199.152:57004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/system.php"] [unique_id "amuJ8SrT982lovRn7gm6yAAAADM"]
[Thu Jul 30 12:29:21.611417 2026] [security2:error] [pid 751901:tid 752124] [client 5.29.12.166:1025] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJ8SrT982lovRn7gm6wwAAAF0"], referer: http://pkf.jo
[Thu Jul 30 12:29:21.908662 2026] [core:notice] [pid 751901:tid 752083] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:21.912704 2026] [security2:error] [pid 751901:tid 752083] [client 103.215.74.26:37552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ8SrT982lovRn7gm6zQAAADQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:22.162416 2026] [security2:error] [pid 751901:tid 752145] [client 185.244.152.158:27304] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJ8SrT982lovRn7gm6zAAAAHI"], referer: http://pkf.jo
[Thu Jul 30 12:29:22.573089 2026] [security2:error] [pid 751901:tid 752130] [client 197.248.125.7:52258] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJ8irT982lovRn7gm61AAAAGM"], referer: http://pkf.jo
[Thu Jul 30 12:29:22.802666 2026] [security2:error] [pid 751901:tid 752131] [client 102.68.141.243:56928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJ8irT982lovRn7gm61QAAAGQ"], referer: http://pkf.jo
[Thu Jul 30 12:29:23.036816 2026] [security2:error] [pid 751901:tid 752109] [client 100.26.182.244:41576] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "northyorksheridanmall.com"] [uri "/"] [unique_id "amuJ8yrT982lovRn7gm63wAAAE4"]
[Thu Jul 30 12:29:23.285202 2026] [security2:error] [pid 751901:tid 752065] [client 38.190.144.4:58179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJ8yrT982lovRn7gm66gAAACI"]
[Thu Jul 30 12:29:23.288657 2026] [security2:error] [pid 751901:tid 752065] [client 38.190.144.4:58179] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJ8yrT982lovRn7gm66gAAACI"]
[Thu Jul 30 12:29:23.685875 2026] [security2:error] [pid 751901:tid 752057] [client 52.238.199.152:62923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/lock360.php"] [unique_id "amuJ8yrT982lovRn7gm69AAAABo"]
[Thu Jul 30 12:29:23.997399 2026] [security2:error] [pid 751901:tid 752035] [client 62.102.148.166:40518] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuJ8yrT982lovRn7gm6-AAAAAQ"]
[Thu Jul 30 12:29:23.997526 2026] [security2:error] [pid 751901:tid 752035] [client 62.102.148.166:40518] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuJ8yrT982lovRn7gm6-AAAAAQ"]
[Thu Jul 30 12:29:24.538499 2026] [security2:error] [pid 751901:tid 752158] [client 2a03:2880:f800:f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJ8yrT982lovRn7gm64gAAf2w"]
[Thu Jul 30 12:29:25.191019 2026] [security2:error] [pid 751901:tid 752146] [client 2a03:2880:f800:32:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJ9CrT982lovRn7gm6_wAAc0I"]
[Thu Jul 30 12:29:25.502867 2026] [security2:error] [pid 751901:tid 752116] [client 57.141.0.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJ9CrT982lovRn7gm7CQAAAFU"]
[Thu Jul 30 12:29:27.665149 2026] [core:notice] [pid 751901:tid 752153] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:27.670170 2026] [security2:error] [pid 751901:tid 752153] [client 103.215.74.26:8652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ9yrT982lovRn7gm7RQAAAHo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:27.709828 2026] [security2:error] [pid 751901:tid 752095] [client 57.141.0.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJ9yrT982lovRn7gm7NwAAAEA"]
[Thu Jul 30 12:29:27.822469 2026] [security2:error] [pid 751901:tid 751925] [remote 192.250.239.173:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.239.250.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kbtfinancezambia.com"] [uri "/wp-login.php"] [unique_id "amuJ9yrT982lovRn7gm7TQAAXhc"]
[Thu Jul 30 12:29:28.338355 2026] [security2:error] [pid 751901:tid 752029] [remote 74.7.241.59:55138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuJ-CrT982lovRn7gm7ZAAAOn8"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/forms/actions
[Thu Jul 30 12:29:28.407571 2026] [core:notice] [pid 751901:tid 752043] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:28.412173 2026] [security2:error] [pid 751901:tid 752043] [client 103.215.74.26:8664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ-CrT982lovRn7gm7ZQAAAAw"], referer: https://carnetdeshopping.com/
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Thu Jul 30 12:29:29.132170 2026] [core:notice] [pid 751901:tid 752066] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:29.138046 2026] [security2:error] [pid 751901:tid 752066] [client 103.215.74.26:8668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ-SrT982lovRn7gm7gQAAACM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:29.249250 2026] [security2:error] [pid 751901:tid 752081] [client 52.238.199.152:17345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "amuJ-SrT982lovRn7gm7iAAAADI"]
[Thu Jul 30 12:29:29.884370 2026] [core:notice] [pid 751901:tid 752147] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:29.892267 2026] [security2:error] [pid 751901:tid 752147] [client 103.215.74.26:8672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ-SrT982lovRn7gm7oQAAAHQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:30.622813 2026] [core:notice] [pid 751901:tid 752094] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:30.627236 2026] [security2:error] [pid 751901:tid 752094] [client 103.215.74.26:8682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ-irT982lovRn7gm7tgAAAD8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:30.919188 2026] [security2:error] [pid 751901:tid 752044] [client 66.249.93.1:35407] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuJ-irT982lovRn7gm7tQAAAA0"]
[Thu Jul 30 12:29:30.932545 2026] [security2:error] [pid 751901:tid 752129] [client 52.238.199.152:64430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/mah.php"] [unique_id "amuJ-irT982lovRn7gm7wgAAAGI"]
[Thu Jul 30 12:29:30.970423 2026] [security2:error] [pid 751901:tid 752042] [client 38.190.144.4:58727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJ-irT982lovRn7gm7wwAAAAs"]
[Thu Jul 30 12:29:30.970551 2026] [security2:error] [pid 751901:tid 752042] [client 38.190.144.4:58727] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJ-irT982lovRn7gm7wwAAAAs"]
[Thu Jul 30 12:29:31.269349 2026] [security2:error] [pid 751901:tid 752035] [client 129.222.147.151:57194] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJ-irT982lovRn7gm7wQAAAAQ"], referer: http://pkf.jo
[Thu Jul 30 12:29:31.345441 2026] [core:notice] [pid 751901:tid 752039] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:31.351018 2026] [security2:error] [pid 751901:tid 752039] [client 103.215.74.26:8694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ-yrT982lovRn7gm71wAAAAg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:31.487416 2026] [proxy:error] [pid 751901:tid 752146] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:29:31.487468 2026] [proxy_http:error] [pid 751901:tid 752146] [client 195.96.139.12:41529] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:29:31.488100 2026] [proxy:error] [pid 751901:tid 752146] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:29:31.488158 2026] [proxy_http:error] [pid 751901:tid 752146] [client 195.96.139.12:41529] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:29:32.072824 2026] [core:notice] [pid 751901:tid 752134] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:32.077236 2026] [security2:error] [pid 751901:tid 752134] [client 103.215.74.26:8708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ_CrT982lovRn7gm75AAAAGc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:32.324063 2026] [security2:error] [pid 751901:tid 752045] [client 52.238.199.152:55498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-class.php"] [unique_id "amuJ_CrT982lovRn7gm76wAAAA4"]
[Thu Jul 30 12:29:32.808436 2026] [core:notice] [pid 751901:tid 752154] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:32.812583 2026] [security2:error] [pid 751901:tid 752154] [client 103.215.74.26:8710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ_CrT982lovRn7gm7-gAAAHs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:33.101057 2026] [security2:error] [pid 751901:tid 752051] [client 2a03:2880:f800:15:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJ_CrT982lovRn7gm77QAAFEw"]
[Thu Jul 30 12:29:33.535871 2026] [core:notice] [pid 751901:tid 752063] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:33.540389 2026] [security2:error] [pid 751901:tid 752063] [client 103.215.74.26:37466] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ_SrT982lovRn7gm8DAAAACA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:34.244680 2026] [security2:error] [pid 751901:tid 752125] [client 52.238.199.152:55525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/backup.php"] [unique_id "amuJ_irT982lovRn7gm8HgAAAF4"]
[Thu Jul 30 12:29:34.274535 2026] [core:notice] [pid 751901:tid 752070] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:34.278758 2026] [security2:error] [pid 751901:tid 752070] [client 103.215.74.26:37468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ_irT982lovRn7gm8HwAAACc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:34.296030 2026] [core:notice] [pid 751901:tid 752037] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:34.442548 2026] [core:notice] [pid 751901:tid 752130] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:34.844487 2026] [core:notice] [pid 751901:tid 752101] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:34.972794 2026] [security2:error] [pid 751901:tid 752083] [client 2a03:2880:f800:1a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJ_irT982lovRn7gm8JAAANGM"]
[Thu Jul 30 12:29:35.013282 2026] [core:notice] [pid 751901:tid 752096] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:35.017443 2026] [security2:error] [pid 751901:tid 752096] [client 103.215.74.26:37472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ_yrT982lovRn7gm8OAAAAEE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:35.755030 2026] [core:notice] [pid 751901:tid 752060] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:35.760750 2026] [security2:error] [pid 751901:tid 752060] [client 103.215.74.26:37482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ_yrT982lovRn7gm8RwAAAB0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:35.956063 2026] [security2:error] [pid 751901:tid 752034] [client 52.238.199.152:64406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/default.php"] [unique_id "amuJ_yrT982lovRn7gm8TgAAAAM"]
[Thu Jul 30 12:29:36.487148 2026] [core:notice] [pid 751901:tid 752084] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:36.492383 2026] [security2:error] [pid 751901:tid 752084] [client 103.215.74.26:37498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKACrT982lovRn7gm8VgAAADU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:37.336743 2026] [core:notice] [pid 751901:tid 752153] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:37.343138 2026] [security2:error] [pid 751901:tid 752153] [client 103.215.74.26:37506] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKASrT982lovRn7gm8ZwAAAHo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:37.619395 2026] [security2:error] [pid 751901:tid 752092] [client 52.238.199.152:51524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-admin/maint/about.php"] [unique_id "amuKASrT982lovRn7gm8bAAAAD0"]
[Thu Jul 30 12:29:37.727934 2026] [security2:error] [pid 751901:tid 752056] [client 62.102.148.166:50040] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuKASrT982lovRn7gm8cwAAABk"]
[Thu Jul 30 12:29:37.728044 2026] [security2:error] [pid 751901:tid 752056] [client 62.102.148.166:50040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuKASrT982lovRn7gm8cwAAABk"]
[Thu Jul 30 12:29:37.820100 2026] [security2:error] [pid 751901:tid 752102] [client 20.215.211.95:60370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "black-devil-shop.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuKASrT982lovRn7gm8awAAAEc"]
[Thu Jul 30 12:29:37.820237 2026] [security2:error] [pid 751901:tid 752102] [client 20.215.211.95:60370] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "black-devil-shop.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuKASrT982lovRn7gm8awAAAEc"]
[Thu Jul 30 12:29:38.073276 2026] [core:notice] [pid 751901:tid 752057] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:38.080110 2026] [security2:error] [pid 751901:tid 752057] [client 103.215.74.26:37508] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKAirT982lovRn7gm8egAAABo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:38.405966 2026] [security2:error] [pid 751901:tid 752062] [client 102.210.43.122:46984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuKAirT982lovRn7gm8ewAAAB8"], referer: http://pkf.jo
[Thu Jul 30 12:29:38.823763 2026] [core:notice] [pid 751901:tid 752046] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:38.827547 2026] [security2:error] [pid 751901:tid 752046] [client 103.215.74.26:37512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKAirT982lovRn7gm8iQAAAA8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:38.893501 2026] [security2:error] [pid 751901:tid 752066] [client 89.211.182.169:39378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuKAirT982lovRn7gm8gwAAACM"], referer: http://pkf.jo
[Thu Jul 30 12:29:39.024149 2026] [security2:error] [pid 751901:tid 752156] [client 200.8.79.115:51650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuKAirT982lovRn7gm8hAAAAH0"], referer: http://pkf.jo
[Thu Jul 30 12:29:39.083361 2026] [security2:error] [pid 751901:tid 752114] [client 52.238.199.152:51540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-content/uploads/2022/10/upload.php"] [unique_id "amuKAyrT982lovRn7gm8kAAAAFM"]
[Thu Jul 30 12:29:39.598358 2026] [core:notice] [pid 751901:tid 752118] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:39.602810 2026] [security2:error] [pid 751901:tid 752118] [client 103.215.74.26:37518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "766"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKAyrT982lovRn7gm8lwAAAFc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:39.944062 2026] [security2:error] [pid 751901:tid 752054] [client 52.238.199.152:17537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/ty.php"] [unique_id "amuKAyrT982lovRn7gm8nAAAABc"]
[Thu Jul 30 12:29:40.331159 2026] [core:notice] [pid 751901:tid 752119] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:40.337746 2026] [security2:error] [pid 751901:tid 752119] [client 103.215.74.26:37528] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKBCrT982lovRn7gm8oAAAAFg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:40.930321 2026] [security2:error] [pid 751901:tid 752126] [client 31.22.56.56:61882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuKBCrT982lovRn7gm8pAAAAF8"], referer: http://pkf.jo
[Thu Jul 30 12:29:41.257746 2026] [security2:error] [pid 751901:tid 752073] [client 20.215.211.95:61234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "black-devil-shop.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuKBSrT982lovRn7gm8sQAAACo"]
[Thu Jul 30 12:29:41.257868 2026] [security2:error] [pid 751901:tid 752073] [client 20.215.211.95:61234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "black-devil-shop.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuKBSrT982lovRn7gm8sQAAACo"]
[Thu Jul 30 12:29:41.308006 2026] [security2:error] [pid 751901:tid 751925] [remote 74.7.241.60:59436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/js/article.php"] [unique_id "amuKBSrT982lovRn7gm8sgAAABc"], referer: https://aded-rdc.org/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/js/bootstrap.bundle.min.js
[Thu Jul 30 12:29:41.391677 2026] [security2:error] [pid 751901:tid 752095] [client 151.244.158.232:8468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuKBSrT982lovRn7gm8rAAAAEA"], referer: http://pkf.jo
[Thu Jul 30 12:29:42.094218 2026] [security2:error] [pid 751901:tid 752127] [client 38.190.144.4:59302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKBirT982lovRn7gm8vgAAAGA"]
[Thu Jul 30 12:29:42.094363 2026] [security2:error] [pid 751901:tid 752127] [client 38.190.144.4:59302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKBirT982lovRn7gm8vgAAAGA"]
[Thu Jul 30 12:29:42.645332 2026] [security2:error] [pid 751901:tid 751906] [remote 216.73.216.152:60608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuKBirT982lovRn7gm8zAAAPgQ"]
[Thu Jul 30 12:29:43.075788 2026] [security2:error] [pid 751901:tid 752065] [client 52.238.199.152:55536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/readme.php"] [unique_id "amuKByrT982lovRn7gm81wAAACI"]
[Thu Jul 30 12:29:43.344203 2026] [security2:error] [pid 751901:tid 751946] [remote 57.141.0.47:22150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/458796423/feed/rss2/"] [unique_id "amuKByrT982lovRn7gm85AAAViw"]
[Thu Jul 30 12:29:43.804937 2026] [core:notice] [pid 751901:tid 752044] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:44.384512 2026] [core:notice] [pid 751901:tid 752063] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:45.819433 2026] [security2:error] [pid 751901:tid 752034] [client 20.215.211.95:45154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "black-devil-shop.com"] [uri "/xstelth.php"] [unique_id "amuKCSrT982lovRn7gm9EQAAAAM"]
[Thu Jul 30 12:29:45.819578 2026] [security2:error] [pid 751901:tid 752034] [client 20.215.211.95:45154] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "black-devil-shop.com"] [uri "/xstelth.php"] [unique_id "amuKCSrT982lovRn7gm9EQAAAAM"]
[Thu Jul 30 12:29:45.853058 2026] [core:notice] [pid 751901:tid 752152] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:46.052860 2026] [core:notice] [pid 751901:tid 752153] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:46.059431 2026] [security2:error] [pid 751901:tid 752153] [client 103.215.74.26:35220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "779"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKCirT982lovRn7gm9GQAAAHo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:46.298696 2026] [security2:error] [pid 751901:tid 752126] [client 20.215.211.95:45160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "black-devil-shop.com"] [uri "/584062352875874akp.php"] [unique_id "amuKCirT982lovRn7gm9HQAAAF8"]
[Thu Jul 30 12:29:46.298793 2026] [security2:error] [pid 751901:tid 752126] [client 20.215.211.95:45160] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "black-devil-shop.com"] [uri "/584062352875874akp.php"] [unique_id "amuKCirT982lovRn7gm9HQAAAF8"]
[Thu Jul 30 12:29:46.366782 2026] [security2:error] [pid 751901:tid 752092] [client 102.180.136.138:56334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuKCirT982lovRn7gm9GAAAAD0"], referer: http://pkf.jo
[Thu Jul 30 12:29:46.366814 2026] [core:notice] [pid 751901:tid 751962] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:46.493163 2026] [core:notice] [pid 751901:tid 752121] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:46.784794 2026] [core:notice] [pid 751901:tid 752057] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:46.788500 2026] [security2:error] [pid 751901:tid 752057] [client 103.215.74.26:35236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKCirT982lovRn7gm9KAAAABo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:46.871623 2026] [core:notice] [pid 751901:tid 752100] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:47.520521 2026] [core:notice] [pid 751901:tid 752116] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:47.525492 2026] [security2:error] [pid 751901:tid 752116] [client 103.215.74.26:35250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKCyrT982lovRn7gm9OgAAAFU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:47.574485 2026] [security2:error] [pid 751901:tid 752082] [client 20.215.211.95:4640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "black-devil-shop.com"] [uri "/newfile.php"] [unique_id "amuKCyrT982lovRn7gm9OwAAADM"]
[Thu Jul 30 12:29:47.574585 2026] [security2:error] [pid 751901:tid 752082] [client 20.215.211.95:4640] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "black-devil-shop.com"] [uri "/newfile.php"] [unique_id "amuKCyrT982lovRn7gm9OwAAADM"]
[Thu Jul 30 12:29:47.871736 2026] [security2:error] [pid 751901:tid 752130] [client 52.238.199.152:55515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-admin/options.php"] [unique_id "amuKCyrT982lovRn7gm9QgAAAGM"]
[Thu Jul 30 12:29:48.267180 2026] [core:notice] [pid 751901:tid 752071] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:48.272401 2026] [security2:error] [pid 751901:tid 752071] [client 103.215.74.26:35262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "761"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKDCrT982lovRn7gm9SAAAACg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:48.942748 2026] [security2:error] [pid 751901:tid 752103] [client 62.102.148.166:49088] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuKDCrT982lovRn7gm9WQAAAEg"]
[Thu Jul 30 12:29:48.942847 2026] [security2:error] [pid 751901:tid 752103] [client 62.102.148.166:49088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuKDCrT982lovRn7gm9WQAAAEg"]
[Thu Jul 30 12:29:49.000286 2026] [core:notice] [pid 751901:tid 752109] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:49.005343 2026] [security2:error] [pid 751901:tid 752109] [client 103.215.74.26:35276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKDCrT982lovRn7gm9XQAAAE4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:49.767461 2026] [core:notice] [pid 751901:tid 752116] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:49.774151 2026] [security2:error] [pid 751901:tid 752116] [client 103.215.74.26:35282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKDSrT982lovRn7gm9bQAAAFU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:49.972574 2026] [security2:error] [pid 751901:tid 752031] [client 52.238.199.152:51551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/admin.php7"] [unique_id "amuKDSrT982lovRn7gm9cQAAAAA"]
[Thu Jul 30 12:29:50.508878 2026] [core:notice] [pid 751901:tid 752048] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:50.513020 2026] [security2:error] [pid 751901:tid 752048] [client 103.215.74.26:35296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKDirT982lovRn7gm9eAAAABE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:51.182901 2026] [security2:error] [pid 751901:tid 752132] [client 57.141.0.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuKDirT982lovRn7gm9ewAAAGU"]
[Thu Jul 30 12:29:51.242295 2026] [core:notice] [pid 751901:tid 752117] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:51.251138 2026] [security2:error] [pid 751901:tid 752117] [client 103.215.74.26:35310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKDyrT982lovRn7gm9hQAAAFY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:51.843985 2026] [core:notice] [pid 751901:tid 751998] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:51.984555 2026] [core:notice] [pid 751901:tid 752066] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:51.989721 2026] [security2:error] [pid 751901:tid 752066] [client 103.215.74.26:35326] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKDyrT982lovRn7gm9nwAAACM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:52.300583 2026] [security2:error] [pid 751901:tid 752082] [client 17.241.227.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuKECrT982lovRn7gm9pQAAADM"]
[Thu Jul 30 12:29:52.714281 2026] [core:notice] [pid 751901:tid 752086] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:52.718516 2026] [security2:error] [pid 751901:tid 752086] [client 103.215.74.26:35340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKECrT982lovRn7gm9swAAADc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:52.743639 2026] [security2:error] [pid 751901:tid 752054] [client 20.215.211.95:43122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "black-devil-shop.com"] [uri "/tBEZGQz.php"] [unique_id "amuKECrT982lovRn7gm9tQAAABc"]
[Thu Jul 30 12:29:52.743754 2026] [security2:error] [pid 751901:tid 752054] [client 20.215.211.95:43122] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "black-devil-shop.com"] [uri "/tBEZGQz.php"] [unique_id "amuKECrT982lovRn7gm9tQAAABc"]
[Thu Jul 30 12:29:53.460664 2026] [core:notice] [pid 751901:tid 752092] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:53.465119 2026] [security2:error] [pid 751901:tid 752092] [client 103.215.74.26:36816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKESrT982lovRn7gm9wQAAAD0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:53.500530 2026] [core:notice] [pid 751901:tid 752104] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:53.568300 2026] [security2:error] [pid 751901:tid 752150] [client 172.202.44.182:44362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/chosen.php"] [unique_id "amuKESrT982lovRn7gm9xgAAAHc"]
[Thu Jul 30 12:29:54.038627 2026] [security2:error] [pid 751901:tid 752117] [client 38.190.144.4:24584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKEirT982lovRn7gm9zwAAAFY"]
[Thu Jul 30 12:29:54.038788 2026] [security2:error] [pid 751901:tid 752117] [client 38.190.144.4:24584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKEirT982lovRn7gm9zwAAAFY"]
[Thu Jul 30 12:29:54.187152 2026] [core:notice] [pid 751901:tid 752121] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:54.191200 2026] [security2:error] [pid 751901:tid 752121] [client 103.215.74.26:36824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKEirT982lovRn7gm90AAAAFo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:54.249495 2026] [security2:error] [pid 751901:tid 752043] [client 52.238.199.152:51557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/.well-known/wp-login.php"] [unique_id "amuKESrT982lovRn7gm9zgAAAAw"]
[Thu Jul 30 12:29:55.181615 2026] [security2:error] [pid 751901:tid 752038] [client 172.202.44.182:18697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/xleet.php"] [unique_id "amuKEyrT982lovRn7gm93gAAAAc"]
[Thu Jul 30 12:29:55.488693 2026] [security2:error] [pid 751901:tid 752078] [client 52.238.199.152:63249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amuKEyrT982lovRn7gm95gAAAC8"]
[Thu Jul 30 12:29:56.917468 2026] [security2:error] [pid 751901:tid 752031] [client 172.202.44.182:37201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/ds.php"] [unique_id "amuKFCrT982lovRn7gm99wAAAAA"]
[Thu Jul 30 12:29:56.919038 2026] [security2:error] [pid 751901:tid 752048] [client 85.208.96.194:14002] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/04/12/covid-19-brasil-tem-3116-milhoes-de-casos-e-6613-mil-mortes/"] [unique_id "amuKFCrT982lovRn7gm9-QAAABE"]
[Thu Jul 30 12:29:56.919121 2026] [security2:error] [pid 751901:tid 752048] [client 85.208.96.194:14002] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/04/12/covid-19-brasil-tem-3116-milhoes-de-casos-e-6613-mil-mortes/"] [unique_id "amuKFCrT982lovRn7gm9-QAAABE"]
[Thu Jul 30 12:29:57.262874 2026] [security2:error] [pid 751901:tid 752070] [client 52.238.199.152:41121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-admin/file.php"] [unique_id "amuKFSrT982lovRn7gm9_AAAACc"]
[Thu Jul 30 12:29:58.752840 2026] [security2:error] [pid 751901:tid 752094] [client 172.202.44.182:18733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/f5.php"] [unique_id "amuKFirT982lovRn7gm-KgAAAD8"]
[Thu Jul 30 12:29:58.774616 2026] [security2:error] [pid 751901:tid 752046] [client 52.238.199.152:51580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/bak.php"] [unique_id "amuKFirT982lovRn7gm-KwAAAA8"]
[Thu Jul 30 12:29:58.825681 2026] [security2:error] [pid 751901:tid 752148] [client 50.6.43.217:44384] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuKFirT982lovRn7gm-LAAAAHU"]
[Thu Jul 30 12:29:58.944872 2026] [security2:error] [pid 751901:tid 752036] [client 50.6.43.217:44398] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuKFirT982lovRn7gm-MAAAAAU"]
[Thu Jul 30 12:29:58.948700 2026] [security2:error] [pid 751901:tid 752140] [client 20.215.211.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "black-devil-shop.com"] [uri "/index.php"] [unique_id "amuKFirT982lovRn7gm-FAAAAG0"]
[Thu Jul 30 12:29:58.948730 2026] [security2:error] [pid 751901:tid 752140] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "black-devil-shop.com"] [uri "/index.php"] [unique_id "amuKFirT982lovRn7gm-FAAAAG0"]
[Thu Jul 30 12:29:59.221635 2026] [security2:error] [pid 751901:tid 752126] [client 20.215.211.95:36587] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "black-devil-shop.com"] [uri "/phpinfo"] [unique_id "amuKFirT982lovRn7gm-EgAAADg"]
[Thu Jul 30 12:29:59.484876 2026] [security2:error] [pid 751901:tid 752065] [client 49.13.164.148:45448] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuKFyrT982lovRn7gm-PQAAACI"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:29:59.546141 2026] [security2:error] [pid 751901:tid 752068] [client 20.215.211.95:36587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "black-devil-shop.com"] [uri "/drykl.php"] [unique_id "amuKFyrT982lovRn7gm-QAAAACU"]
[Thu Jul 30 12:29:59.546255 2026] [security2:error] [pid 751901:tid 752068] [client 20.215.211.95:36587] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "black-devil-shop.com"] [uri "/drykl.php"] [unique_id "amuKFyrT982lovRn7gm-QAAAACU"]
[Thu Jul 30 12:29:59.895849 2026] [core:notice] [pid 751901:tid 752079] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:59.900029 2026] [security2:error] [pid 751901:tid 752079] [client 49.13.164.148:45452] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKFyrT982lovRn7gm-TQAAADA"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:29:59.931845 2026] [core:notice] [pid 751901:tid 752040] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:59.936613 2026] [security2:error] [pid 751901:tid 752040] [client 103.215.74.26:36830] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKFyrT982lovRn7gm-TgAAAAk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:00.548913 2026] [security2:error] [pid 751901:tid 752154] [client 49.13.164.148:45458] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuKGCrT982lovRn7gm-YAAAAHs"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:30:00.656490 2026] [core:notice] [pid 751901:tid 752076] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:00.660882 2026] [security2:error] [pid 751901:tid 752076] [client 103.215.74.26:36846] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKGCrT982lovRn7gm-ZQAAAC0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:00.810918 2026] [security2:error] [pid 751901:tid 752096] [client 172.202.44.182:4835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/god4m.php"] [unique_id "amuKGCrT982lovRn7gm-bgAAAEE"]
[Thu Jul 30 12:30:01.228338 2026] [security2:error] [pid 751901:tid 752085] [client 52.238.199.152:63263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/config.php"] [unique_id "amuKGSrT982lovRn7gm-eQAAADY"]
[Thu Jul 30 12:30:01.380099 2026] [core:notice] [pid 751901:tid 752086] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:01.384545 2026] [security2:error] [pid 751901:tid 752086] [client 103.215.74.26:36854] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKGSrT982lovRn7gm-egAAADc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:01.966447 2026] [security2:error] [pid 751901:tid 751977] [remote 107.23.62.75:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "fantasynamelist.com"] [uri "/gods/norse-gods-name-generator/"] [unique_id "amuKGSrT982lovRn7gm-gwAAGUs"]
[Thu Jul 30 12:30:02.135051 2026] [security2:error] [pid 751901:tid 752143] [client 52.238.199.152:41116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-content/uploads/2025/03/themes.php"] [unique_id "amuKGirT982lovRn7gm-igAAAHA"]
[Thu Jul 30 12:30:03.189356 2026] [core:notice] [pid 751901:tid 751980] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:04.141801 2026] [autoindex:error] [pid 751901:tid 752042] [client 20.215.211.95:21355] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_aa23bb9f/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:30:04.142532 2026] [security2:error] [pid 751901:tid 752042] [client 20.215.211.95:21355] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "black-devil-shop.com"] [uri "/cgi-sys/403.html"] [unique_id "amuKHCrT982lovRn7gm-rAAAAAs"]
[Thu Jul 30 12:30:04.304339 2026] [security2:error] [pid 751901:tid 752081] [client 20.215.211.95:21355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "black-devil-shop.com"] [uri "/ls.php"] [unique_id "amuKHCrT982lovRn7gm-tAAAADI"]
[Thu Jul 30 12:30:04.304482 2026] [security2:error] [pid 751901:tid 752081] [client 20.215.211.95:21355] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "black-devil-shop.com"] [uri "/ls.php"] [unique_id "amuKHCrT982lovRn7gm-tAAAADI"]
[Thu Jul 30 12:30:04.488080 2026] [core:notice] [pid 751901:tid 752133] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:04.536519 2026] [security2:error] [pid 751901:tid 752136] [client 66.249.73.97:44191] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuKHCrT982lovRn7gm-rQAAAGk"]
[Thu Jul 30 12:30:04.744890 2026] [security2:error] [pid 751901:tid 752110] [client 172.202.44.182:37226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/info.php"] [unique_id "amuKHCrT982lovRn7gm-ugAAAE8"]
[Thu Jul 30 12:30:06.003188 2026] [security2:error] [pid 751901:tid 752139] [client 52.238.199.152:63258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-activate.php"] [unique_id "amuKHirT982lovRn7gm-1AAAAGw"]
[Thu Jul 30 12:30:06.239791 2026] [security2:error] [pid 751901:tid 752097] [client 38.190.144.4:60354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKHirT982lovRn7gm-2AAAAEI"]
[Thu Jul 30 12:30:06.239931 2026] [security2:error] [pid 751901:tid 752097] [client 38.190.144.4:60354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKHirT982lovRn7gm-2AAAAEI"]
[Thu Jul 30 12:30:07.141799 2026] [security2:error] [pid 751901:tid 752063] [client 52.238.199.152:51581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-file.php"] [unique_id "amuKHyrT982lovRn7gm-5wAAACA"]
[Thu Jul 30 12:30:07.179962 2026] [security2:error] [pid 751901:tid 752146] [client 172.202.44.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "lark-shop.com"] [uri "/index.php"] [unique_id "amuKHirT982lovRn7gm-1wAAAHM"]
[Thu Jul 30 12:30:07.194341 2026] [core:notice] [pid 751901:tid 752149] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:07.198676 2026] [security2:error] [pid 751901:tid 752149] [client 103.215.74.26:46688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKHyrT982lovRn7gm-6QAAAHY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:07.437920 2026] [security2:error] [pid 751901:tid 752085] [client 172.202.44.182:44393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/.__info.php"] [unique_id "amuKHyrT982lovRn7gm-8QAAADY"]
[Thu Jul 30 12:30:07.924827 2026] [core:notice] [pid 751901:tid 752133] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:07.928826 2026] [security2:error] [pid 751901:tid 752133] [client 103.215.74.26:46704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKHyrT982lovRn7gm--gAAAGY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:08.428234 2026] [security2:error] [pid 751901:tid 752107] [client 172.202.44.182:4848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/0.php"] [unique_id "amuKICrT982lovRn7gm_CwAAAEw"]
[Thu Jul 30 12:30:08.629458 2026] [security2:error] [pid 751901:tid 752092] [client 172.237.109.114:33123] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKICrT982lovRn7gm-_AAAAD0"]
[Thu Jul 30 12:30:08.630736 2026] [security2:error] [pid 751901:tid 752090] [client 172.237.109.114:64875] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKICrT982lovRn7gm-_QAAADs"]
[Thu Jul 30 12:30:08.655772 2026] [core:notice] [pid 751901:tid 752137] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:08.659830 2026] [security2:error] [pid 751901:tid 752137] [client 103.215.74.26:46706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "752"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKICrT982lovRn7gm_EAAAAGo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:09.267240 2026] [security2:error] [pid 751901:tid 752147] [client 2a03:2880:f800:27:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuKICrT982lovRn7gm_DQAAdGE"]
[Thu Jul 30 12:30:09.393071 2026] [core:notice] [pid 751901:tid 752123] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:09.400677 2026] [security2:error] [pid 751901:tid 752123] [client 103.215.74.26:46712] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKISrT982lovRn7gm_KwAAAFw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:09.673939 2026] [security2:error] [pid 751901:tid 752033] [client 172.202.44.182:44396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/07.php"] [unique_id "amuKISrT982lovRn7gm_NQAAAAI"]
[Thu Jul 30 12:30:09.743064 2026] [security2:error] [pid 751901:tid 752127] [client 52.238.199.152:51575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/12.php"] [unique_id "amuKISrT982lovRn7gm_NgAAAGA"]
[Thu Jul 30 12:30:10.132445 2026] [core:notice] [pid 751901:tid 752111] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:10.137811 2026] [security2:error] [pid 751901:tid 752111] [client 103.215.74.26:46714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKIirT982lovRn7gm_QAAAAFA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:10.313968 2026] [security2:error] [pid 751901:tid 752066] [client 172.237.109.114:44796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKICrT982lovRn7gm_FQAAACM"]
[Thu Jul 30 12:30:10.402354 2026] [security2:error] [pid 751901:tid 752055] [client 172.237.109.114:34975] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKICrT982lovRn7gm_FgAAABg"]
[Thu Jul 30 12:30:10.413247 2026] [security2:error] [pid 751901:tid 752106] [client 172.237.109.114:60286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKISrT982lovRn7gm_KQAAAEs"]
[Thu Jul 30 12:30:10.415361 2026] [security2:error] [pid 751901:tid 752098] [client 172.237.109.114:27311] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKICrT982lovRn7gm_GAAAAEM"]
[Thu Jul 30 12:30:10.416158 2026] [security2:error] [pid 751901:tid 752120] [client 172.237.109.114:54732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKICrT982lovRn7gm_HQAAAFk"]
[Thu Jul 30 12:30:10.421698 2026] [security2:error] [pid 751901:tid 752105] [client 172.237.109.114:18182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKICrT982lovRn7gm_GwAAAEo"]
[Thu Jul 30 12:30:10.421913 2026] [security2:error] [pid 751901:tid 752077] [client 172.237.109.114:32678] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKICrT982lovRn7gm_GQAAAC4"]
[Thu Jul 30 12:30:10.422493 2026] [security2:error] [pid 751901:tid 752038] [client 172.237.109.114:23478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKICrT982lovRn7gm_HAAAAAc"]
[Thu Jul 30 12:30:10.430294 2026] [security2:error] [pid 751901:tid 752059] [client 172.237.109.114:27488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKICrT982lovRn7gm_HgAAABw"]
[Thu Jul 30 12:30:10.446514 2026] [security2:error] [pid 751901:tid 752109] [client 172.237.109.114:51421] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKICrT982lovRn7gm_FwAAAE4"]
[Thu Jul 30 12:30:10.453992 2026] [security2:error] [pid 751901:tid 752039] [client 172.237.109.114:61687] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKICrT982lovRn7gm_IQAAAAg"]
[Thu Jul 30 12:30:10.459496 2026] [security2:error] [pid 751901:tid 752067] [client 172.237.109.114:40039] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKICrT982lovRn7gm_GgAAACQ"]
[Thu Jul 30 12:30:10.463027 2026] [security2:error] [pid 751901:tid 752035] [client 172.237.109.114:28526] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKISrT982lovRn7gm_KAAAAAQ"]
[Thu Jul 30 12:30:10.463767 2026] [security2:error] [pid 751901:tid 752061] [client 172.237.109.114:51807] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKICrT982lovRn7gm_HwAAAB4"]
[Thu Jul 30 12:30:10.476953 2026] [security2:error] [pid 751901:tid 752128] [client 172.237.109.114:19121] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKICrT982lovRn7gm_JAAAAGE"]
[Thu Jul 30 12:30:10.498376 2026] [security2:error] [pid 751901:tid 752117] [client 172.237.109.114:10603] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKICrT982lovRn7gm_IwAAAFY"]
[Thu Jul 30 12:30:10.499752 2026] [security2:error] [pid 751901:tid 752063] [client 172.237.109.114:65188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKISrT982lovRn7gm_JwAAACA"]
[Thu Jul 30 12:30:10.527014 2026] [security2:error] [pid 751901:tid 752082] [client 172.237.109.114:40736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKICrT982lovRn7gm_JQAAADM"]
[Thu Jul 30 12:30:10.855150 2026] [core:notice] [pid 751901:tid 752107] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:10.862059 2026] [security2:error] [pid 751901:tid 752107] [client 103.215.74.26:46726] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKIirT982lovRn7gm_SwAAAEw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:10.865872 2026] [security2:error] [pid 751901:tid 752095] [client 52.238.199.152:51533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/epinyins.php"] [unique_id "amuKIirT982lovRn7gm_TAAAAEA"]
[Thu Jul 30 12:30:11.426680 2026] [security2:error] [pid 751901:tid 752089] [client 172.202.44.182:44369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/dropdown.php"] [unique_id "amuKIyrT982lovRn7gm_WgAAADo"]
[Thu Jul 30 12:30:11.578987 2026] [core:notice] [pid 751901:tid 752084] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:11.585182 2026] [security2:error] [pid 751901:tid 752084] [client 103.215.74.26:46736] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKIyrT982lovRn7gm_YAAAADU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:11.918885 2026] [core:error] [pid 751901:tid 752040] [client 74.7.244.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:30:11.918915 2026] [core:error] [pid 751901:tid 752040] [client 74.7.244.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:30:11.919059 2026] [security2:error] [pid 751901:tid 752040] [client 74.7.244.59:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.mhh.zzt.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/index.php"] [unique_id "amuKIyrT982lovRn7gm_ZAAAAAk"]
[Thu Jul 30 12:30:11.919755 2026] [security2:error] [pid 751901:tid 752081] [client 74.7.244.59:60960] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.mhh.zzt.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "amuKIyrT982lovRn7gm_YgAAMg8"]
[Thu Jul 30 12:30:12.323910 2026] [core:notice] [pid 751901:tid 752037] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:12.327922 2026] [security2:error] [pid 751901:tid 752037] [client 103.215.74.26:46752] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKJCrT982lovRn7gm_cAAAAAY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:12.493559 2026] [core:error] [pid 751901:tid 751923] [remote 74.7.175.140:39556] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:30:12.493583 2026] [core:error] [pid 751901:tid 751923] [remote 74.7.175.140:39556] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:30:12.493829 2026] [security2:error] [pid 751901:tid 752055] [client 74.7.175.140:39556] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "website-78cdf888.ubp.hmu.temporary.site"] [uri "/index.php"] [unique_id "amuKJCrT982lovRn7gm_cQAAGBU"]
[Thu Jul 30 12:30:12.497071 2026] [security2:error] [pid 751901:tid 752133] [client 85.208.96.200:17264] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/01/26/bandidos-roubam-bancos-e-aterrorizam-cidade-na-pb/"] [unique_id "amuKJCrT982lovRn7gm_cgAAAGY"]
[Thu Jul 30 12:30:12.497167 2026] [security2:error] [pid 751901:tid 752133] [client 85.208.96.200:17264] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/01/26/bandidos-roubam-bancos-e-aterrorizam-cidade-na-pb/"] [unique_id "amuKJCrT982lovRn7gm_cgAAAGY"]
[Thu Jul 30 12:30:12.517549 2026] [security2:error] [pid 751901:tid 752152] [client 172.202.44.182:37200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/makeasmtp.php"] [unique_id "amuKJCrT982lovRn7gm_cwAAAHk"]
[Thu Jul 30 12:30:13.062963 2026] [core:notice] [pid 751901:tid 752042] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:13.067490 2026] [security2:error] [pid 751901:tid 752042] [client 103.215.74.26:47636] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "768"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKJSrT982lovRn7gm_ggAAAAs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:13.620330 2026] [security2:error] [pid 751901:tid 752104] [client 149.22.81.181:12776] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "globalmarks.pk"] [uri "/wp-comments-post.php"] [unique_id "amuKJSrT982lovRn7gm_hgAAAEk"]
[Thu Jul 30 12:30:13.735076 2026] [security2:error] [pid 751901:tid 752100] [client 172.202.44.182:40392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/wp-sigunq.php"] [unique_id "amuKJSrT982lovRn7gm_kwAAAEU"]
[Thu Jul 30 12:30:13.739785 2026] [security2:error] [pid 751901:tid 752104] [client 149.22.81.181:12776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "globalmarks.pk"] [uri "/wp-comments-post.php"] [unique_id "amuKJSrT982lovRn7gm_hgAAAEk"]
[Thu Jul 30 12:30:13.739852 2026] [security2:error] [pid 751901:tid 752104] [client 149.22.81.181:12776] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "globalmarks.pk"] [uri "/wp-comments-post.php"] [unique_id "amuKJSrT982lovRn7gm_hgAAAEk"]
[Thu Jul 30 12:30:13.816380 2026] [core:notice] [pid 751901:tid 752102] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:13.823452 2026] [security2:error] [pid 751901:tid 752102] [client 103.215.74.26:47644] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKJSrT982lovRn7gm_lAAAAEc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:14.558533 2026] [core:notice] [pid 751901:tid 752136] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:14.562658 2026] [security2:error] [pid 751901:tid 752136] [client 103.215.74.26:47650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "781"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKJirT982lovRn7gm_oQAAAGk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:14.564083 2026] [security2:error] [pid 751901:tid 752153] [client 52.238.199.152:17628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "amuKJirT982lovRn7gm_ogAAAHo"]
[Thu Jul 30 12:30:15.033647 2026] [security2:error] [pid 751901:tid 752075] [client 172.202.44.182:4849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/wso112233.php"] [unique_id "amuKJyrT982lovRn7gm_rQAAACw"]
[Thu Jul 30 12:30:15.289321 2026] [core:notice] [pid 751901:tid 752152] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:15.293362 2026] [security2:error] [pid 751901:tid 752152] [client 103.215.74.26:47666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKJyrT982lovRn7gm_tAAAAHk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:16.016093 2026] [core:notice] [pid 751901:tid 752121] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:16.020079 2026] [security2:error] [pid 751901:tid 752121] [client 103.215.74.26:47682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKKCrT982lovRn7gm_wAAAAFo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:16.149440 2026] [security2:error] [pid 751901:tid 752065] [client 172.202.44.182:4810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/alfanew.php"] [unique_id "amuKKCrT982lovRn7gm_wQAAACI"]
[Thu Jul 30 12:30:16.423357 2026] [security2:error] [pid 751901:tid 752107] [client 149.22.81.181:12780] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "globalmarks.pk"] [uri "/wp-comments-post.php"] [unique_id "amuKKCrT982lovRn7gm_yAAAAEw"]
[Thu Jul 30 12:30:16.538610 2026] [security2:error] [pid 751901:tid 752107] [client 149.22.81.181:12780] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "globalmarks.pk"] [uri "/wp-comments-post.php"] [unique_id "amuKKCrT982lovRn7gm_yAAAAEw"]
[Thu Jul 30 12:30:16.733744 2026] [core:notice] [pid 751901:tid 752149] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:16.737521 2026] [security2:error] [pid 751901:tid 752149] [client 103.215.74.26:47684] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKKCrT982lovRn7gm_zQAAAHY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:17.589822 2026] [security2:error] [pid 751901:tid 752113] [client 50.6.43.217:21034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cmplboard.com"] [uri "/public/tools/reg_refetch.php"] [unique_id "amuKGirT982lovRn7gm-hAAAAFI"]
[Thu Jul 30 12:30:17.837142 2026] [security2:error] [pid 751901:tid 752033] [client 172.202.44.182:4812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/fw.php"] [unique_id "amuKKSrT982lovRn7gm_4gAAAAI"]
[Thu Jul 30 12:30:18.327712 2026] [security2:error] [pid 751901:tid 752075] [client 149.22.81.181:2102] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "globalmarks.pk"] [uri "/wp-comments-post.php"] [unique_id "amuKKirT982lovRn7gm_7AAAACw"]
[Thu Jul 30 12:30:18.447873 2026] [security2:error] [pid 751901:tid 752075] [client 149.22.81.181:2102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "globalmarks.pk"] [uri "/wp-comments-post.php"] [unique_id "amuKKirT982lovRn7gm_7AAAACw"]
[Thu Jul 30 12:30:19.081000 2026] [security2:error] [pid 751901:tid 752104] [client 40.77.167.123:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuKKCrT982lovRn7gm_ywAAAEk"]
[Thu Jul 30 12:30:19.180000 2026] [security2:error] [pid 751901:tid 752129] [client 2a03:2880:f800:1e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuKKirT982lovRn7gm_-wAAYjA"]
[Thu Jul 30 12:30:19.458672 2026] [core:notice] [pid 751901:tid 752099] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:19.553122 2026] [security2:error] [pid 751901:tid 752033] [client 40.77.167.123:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuKKyrT982lovRn7gnAFQAAAAI"]
[Thu Jul 30 12:30:19.657108 2026] [security2:error] [pid 751901:tid 752096] [client 52.238.199.152:17553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/system_log.php"] [unique_id "amuKKyrT982lovRn7gnAHgAAAEE"]
[Thu Jul 30 12:30:19.900798 2026] [security2:error] [pid 751901:tid 752062] [client 2a03:2880:f800:35:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuKKyrT982lovRn7gnAFgAAHzo"]
[Thu Jul 30 12:30:20.711475 2026] [security2:error] [pid 751901:tid 752068] [client 172.202.44.182:37194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/wp-login.php"] [unique_id "amuKLCrT982lovRn7gnAQAAAACU"]
[Thu Jul 30 12:30:21.080746 2026] [security2:error] [pid 751901:tid 752148] [client 57.141.0.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuKLCrT982lovRn7gnAPgAAAHU"]
[Thu Jul 30 12:30:21.142530 2026] [security2:error] [pid 751901:tid 752146] [client 52.238.199.152:53519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuKLSrT982lovRn7gnATgAAAHM"]
[Thu Jul 30 12:30:21.674497 2026] [security2:error] [pid 751901:tid 752110] [client 38.190.144.4:60866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKLSrT982lovRn7gnAWQAAAE8"]
[Thu Jul 30 12:30:21.674603 2026] [security2:error] [pid 751901:tid 752110] [client 38.190.144.4:60866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKLSrT982lovRn7gnAWQAAAE8"]
[Thu Jul 30 12:30:22.464686 2026] [core:notice] [pid 751901:tid 752139] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:22.469118 2026] [security2:error] [pid 751901:tid 752139] [client 103.215.74.26:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKLirT982lovRn7gnAZAAAAGw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:22.500694 2026] [security2:error] [pid 751901:tid 752075] [client 52.238.199.152:45329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/ini.php"] [unique_id "amuKLirT982lovRn7gnAZQAAACw"]
[Thu Jul 30 12:30:22.696271 2026] [security2:error] [pid 751901:tid 752109] [client 172.202.44.182:18690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/simple.php"] [unique_id "amuKLirT982lovRn7gnAcQAAAE4"]
[Thu Jul 30 12:30:23.203303 2026] [core:notice] [pid 751901:tid 752155] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:23.207292 2026] [security2:error] [pid 751901:tid 752155] [client 103.215.74.26:30676] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKLyrT982lovRn7gnAegAAAHw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:23.726252 2026] [security2:error] [pid 751901:tid 752138] [client 172.202.44.182:37185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/classsmtps.php"] [unique_id "amuKLyrT982lovRn7gnAhAAAAGs"]
[Thu Jul 30 12:30:23.930095 2026] [core:notice] [pid 751901:tid 752140] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:23.934964 2026] [security2:error] [pid 751901:tid 752140] [client 103.215.74.26:30692] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKLyrT982lovRn7gnAhgAAAG0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:24.657510 2026] [core:notice] [pid 751901:tid 752143] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:24.662579 2026] [security2:error] [pid 751901:tid 752143] [client 103.215.74.26:30704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKMCrT982lovRn7gnAlAAAAHA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:25.266796 2026] [security2:error] [pid 751901:tid 752127] [client 172.202.44.182:37184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/wp-blog-header.php"] [unique_id "amuKMSrT982lovRn7gnApAAAAGA"]
[Thu Jul 30 12:30:25.274617 2026] [core:notice] [pid 751901:tid 752090] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:25.344032 2026] [security2:error] [pid 751901:tid 752097] [client 57.141.0.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuKMCrT982lovRn7gnAmgAAAEI"]
[Thu Jul 30 12:30:25.402468 2026] [core:notice] [pid 751901:tid 752139] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:25.407665 2026] [security2:error] [pid 751901:tid 752139] [client 103.215.74.26:30710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKMSrT982lovRn7gnApgAAAGw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:26.033621 2026] [security2:error] [pid 751901:tid 752112] [client 52.238.199.152:17644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/ok.php"] [unique_id "amuKMirT982lovRn7gnAsQAAAFE"]
[Thu Jul 30 12:30:26.131243 2026] [core:notice] [pid 751901:tid 752044] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:26.135664 2026] [security2:error] [pid 751901:tid 752044] [client 103.215.74.26:30716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKMirT982lovRn7gnAsgAAAA0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:26.234574 2026] [security2:error] [pid 751901:tid 752070] [client 172.202.44.182:4823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/wp-trackback.php"] [unique_id "amuKMirT982lovRn7gnAtgAAACc"]
[Thu Jul 30 12:30:26.418628 2026] [security2:error] [pid 751901:tid 752107] [client 2a03:2880:f800:35:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuKMSrT982lovRn7gnArAAATGY"]
[Thu Jul 30 12:30:26.447479 2026] [core:notice] [pid 751901:tid 752015] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:26.862288 2026] [core:notice] [pid 751901:tid 752106] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:26.867650 2026] [security2:error] [pid 751901:tid 752106] [client 103.215.74.26:30722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKMirT982lovRn7gnAygAAAEs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:26.958556 2026] [security2:error] [pid 751901:tid 752016] [remote 57.141.0.52:47542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amuKMirT982lovRn7gnAywAARHI"]
[Thu Jul 30 12:30:27.173221 2026] [security2:error] [pid 751901:tid 752077] [client 52.238.199.152:17554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-admin/includes/about.php"] [unique_id "amuKMyrT982lovRn7gnAzAAAAC4"]
[Thu Jul 30 12:30:27.582356 2026] [security2:error] [pid 751901:tid 752064] [client 172.202.44.182:40435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/wp-signup.php"] [unique_id "amuKMyrT982lovRn7gnA2AAAACE"]
[Thu Jul 30 12:30:27.582924 2026] [core:notice] [pid 751901:tid 752072] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:27.587264 2026] [security2:error] [pid 751901:tid 752072] [client 103.215.74.26:30732] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKMyrT982lovRn7gnA1wAAACk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:28.311379 2026] [core:notice] [pid 751901:tid 752104] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:28.315744 2026] [security2:error] [pid 751901:tid 752104] [client 103.215.74.26:30744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKNCrT982lovRn7gnA7QAAAEk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:28.563199 2026] [core:notice] [pid 751901:tid 752093] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:29.043423 2026] [core:notice] [pid 751901:tid 752115] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:29.047746 2026] [security2:error] [pid 751901:tid 752115] [client 103.215.74.26:30750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKNSrT982lovRn7gnBAgAAAFQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:29.633950 2026] [security2:error] [pid 751901:tid 752071] [client 52.238.199.152:45334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-configs.php"] [unique_id "amuKNSrT982lovRn7gnBDAAAACg"]
[Thu Jul 30 12:30:29.682291 2026] [security2:error] [pid 751901:tid 752081] [client 217.181.85.93:44234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "deltaedu.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuKNSrT982lovRn7gnBCwAAMgA"], referer: https://deltaedu.net/wp-admin/admin-ajax.php?action=tnp&na=s
[Thu Jul 30 12:30:29.750634 2026] [security2:error] [pid 751901:tid 752036] [client 172.202.44.182:44378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/wp-comments-post.php"] [unique_id "amuKNSrT982lovRn7gnBDQAAAAU"]
[Thu Jul 30 12:30:29.836675 2026] [core:notice] [pid 751901:tid 752076] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:29.840756 2026] [security2:error] [pid 751901:tid 752076] [client 103.215.74.26:30760] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKNSrT982lovRn7gnBDgAAAC0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:29.989990 2026] [security2:error] [pid 751901:tid 752152] [client 2a03:2880:f800:d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuKNSrT982lovRn7gnBBgAAeQU"]
[Thu Jul 30 12:30:30.144633 2026] [security2:error] [pid 751901:tid 752072] [client 195.63.26.171:13792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "deltaedu.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuKNirT982lovRn7gnBFQAAKQ8"], referer: https://deltaedu.net/wp-admin/admin-ajax.php?action=tnp&na=s
[Thu Jul 30 12:30:30.520463 2026] [security2:error] [pid 751901:tid 752034] [client 52.238.199.152:17619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/01.php"] [unique_id "amuKNirT982lovRn7gnBIQAAAAM"]
[Thu Jul 30 12:30:30.626108 2026] [security2:error] [pid 751901:tid 752127] [client 114.119.131.46:22815] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.northyorksheridanmall.com"] [uri "/events"] [unique_id "amuKNirT982lovRn7gnBJAAAAGA"], referer: https://www.northyorksheridanmall.com/events
[Thu Jul 30 12:30:31.105137 2026] [security2:error] [pid 751901:tid 752097] [client 57.141.0.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuKNirT982lovRn7gnBIgAAAEI"]
[Thu Jul 30 12:30:31.303411 2026] [security2:error] [pid 751901:tid 752078] [client 172.202.44.182:18731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/wp-mail.php"] [unique_id "amuKNyrT982lovRn7gnBLgAAAC8"]
[Thu Jul 30 12:30:32.156486 2026] [security2:error] [pid 751901:tid 752122] [client 52.238.199.152:53673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "amuKOCrT982lovRn7gnBTQAAAFs"]
[Thu Jul 30 12:30:32.292539 2026] [core:notice] [pid 751901:tid 752148] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:32.363109 2026] [security2:error] [pid 751901:tid 752058] [client 172.202.44.182:40393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/wp-activate.php"] [unique_id "amuKOCrT982lovRn7gnBUAAAABs"]
[Thu Jul 30 12:30:32.965371 2026] [security2:error] [pid 751901:tid 752092] [client 20.215.191.139:11306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/geju.php"] [unique_id "amuKOCrT982lovRn7gnBWgAAAD0"]
[Thu Jul 30 12:30:33.248087 2026] [security2:error] [pid 751901:tid 752118] [client 52.238.199.152:17614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-admin/css/colors/midnight/colors.php"] [unique_id "amuKOSrT982lovRn7gnBcQAAAFc"]
[Thu Jul 30 12:30:33.317608 2026] [core:notice] [pid 751901:tid 751973] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:33.560172 2026] [security2:error] [pid 751901:tid 752084] [client 172.202.44.182:18738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/post.php"] [unique_id "amuKOSrT982lovRn7gnBfgAAADU"]
[Thu Jul 30 12:30:33.971843 2026] [security2:error] [pid 751901:tid 752052] [client 20.215.191.139:7965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/plugins/about.php"] [unique_id "amuKOSrT982lovRn7gnBggAAABU"]
[Thu Jul 30 12:30:33.994168 2026] [security2:error] [pid 751901:tid 751984] [remote 216.73.216.152:23441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuKOSrT982lovRn7gnBhAAAaFI"]
[Thu Jul 30 12:30:34.787680 2026] [core:notice] [pid 751901:tid 752087] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:34.948018 2026] [security2:error] [pid 751901:tid 752143] [client 172.202.44.182:4807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/wp-2019.php"] [unique_id "amuKOirT982lovRn7gnBlwAAAHA"]
[Thu Jul 30 12:30:35.386928 2026] [core:notice] [pid 751901:tid 752073] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:35.553588 2026] [core:notice] [pid 751901:tid 752111] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:35.557924 2026] [security2:error] [pid 751901:tid 752111] [client 103.215.74.26:34416] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKOyrT982lovRn7gnBoAAAAFA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:35.716871 2026] [security2:error] [pid 751901:tid 752049] [client 85.208.96.195:62438] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/03/24/mulher-descobre-gravidez-na-hora-de-dar-a-luz-e-crianca-nasce-com-quase-5-kg-achava-que-era-pedra-nos-rins/"] [unique_id "amuKOyrT982lovRn7gnBqAAAABI"]
[Thu Jul 30 12:30:35.717040 2026] [security2:error] [pid 751901:tid 752049] [client 85.208.96.195:62438] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/03/24/mulher-descobre-gravidez-na-hora-de-dar-a-luz-e-crianca-nasce-com-quase-5-kg-achava-que-era-pedra-nos-rins/"] [unique_id "amuKOyrT982lovRn7gnBqAAAABI"]
[Thu Jul 30 12:30:35.725345 2026] [security2:error] [pid 751901:tid 752036] [client 38.190.144.4:61394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKOyrT982lovRn7gnBqQAAAAU"]
[Thu Jul 30 12:30:35.725638 2026] [security2:error] [pid 751901:tid 752036] [client 38.190.144.4:61394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKOyrT982lovRn7gnBqQAAAAU"]
[Thu Jul 30 12:30:36.086173 2026] [security2:error] [pid 751901:tid 752140] [client 52.238.199.152:17638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "amuKPCrT982lovRn7gnBqgAAAG0"]
[Thu Jul 30 12:30:36.269012 2026] [security2:error] [pid 751901:tid 752068] [client 172.202.44.182:18735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/hoot.php"] [unique_id "amuKPCrT982lovRn7gnBsgAAACU"]
[Thu Jul 30 12:30:36.280686 2026] [core:notice] [pid 751901:tid 752127] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:36.284762 2026] [security2:error] [pid 751901:tid 752127] [client 103.215.74.26:34420] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKPCrT982lovRn7gnBswAAAGA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:37.006606 2026] [core:notice] [pid 751901:tid 752048] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:37.010566 2026] [security2:error] [pid 751901:tid 752048] [client 103.215.74.26:34430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKPSrT982lovRn7gnBvgAAABE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:38.240505 2026] [security2:error] [pid 751901:tid 752006] [remote 97.74.87.194:45118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/wp-login.php"] [unique_id "amuKPirT982lovRn7gnB2gAAXWg"]
[Thu Jul 30 12:30:38.344929 2026] [security2:error] [pid 751901:tid 752031] [client 52.238.199.152:17596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/db.php"] [unique_id "amuKPirT982lovRn7gnB4QAAAAA"]
[Thu Jul 30 12:30:38.582932 2026] [security2:error] [pid 751901:tid 752019] [remote 216.73.216.152:23441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuKPirT982lovRn7gnB4gAAf3U"]
[Thu Jul 30 12:30:39.091657 2026] [security2:error] [pid 751901:tid 752081] [client 172.202.44.182:18730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/log.php"] [unique_id "amuKPyrT982lovRn7gnB6gAAADI"]
[Thu Jul 30 12:30:39.339300 2026] [security2:error] [pid 751901:tid 752075] [client 20.215.191.139:60660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp.php"] [unique_id "amuKPyrT982lovRn7gnB9gAAACw"]
[Thu Jul 30 12:30:39.687644 2026] [security2:error] [pid 751901:tid 752034] [client 160.20.40.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuKPyrT982lovRn7gnB_AAAAAM"]
[Thu Jul 30 12:30:39.899606 2026] [security2:error] [pid 751901:tid 752112] [client 172.202.44.182:44372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/bak.php"] [unique_id "amuKPyrT982lovRn7gnCAgAAAFE"]
[Thu Jul 30 12:30:39.926666 2026] [security2:error] [pid 751901:tid 752065] [client 52.238.199.152:17607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-admin/pages.php"] [unique_id "amuKPyrT982lovRn7gnCBgAAACI"]
[Thu Jul 30 12:30:41.063072 2026] [security2:error] [pid 751901:tid 752146] [client 20.215.191.139:7029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/aaa.php"] [unique_id "amuKQSrT982lovRn7gnCFgAAAHM"]
[Thu Jul 30 12:30:41.391216 2026] [security2:error] [pid 751901:tid 752116] [client 172.202.44.182:4863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/content.php"] [unique_id "amuKQSrT982lovRn7gnCGgAAAFU"]
[Thu Jul 30 12:30:41.631272 2026] [security2:error] [pid 751901:tid 752117] [client 20.215.191.139:9029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/hoot.php"] [unique_id "amuKQSrT982lovRn7gnCIQAAAFY"]
[Thu Jul 30 12:30:42.257326 2026] [security2:error] [pid 751901:tid 752114] [client 20.215.191.139:8523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/about.php"] [unique_id "amuKQirT982lovRn7gnCMAAAAFM"]
[Thu Jul 30 12:30:42.502018 2026] [security2:error] [pid 751901:tid 751920] [remote 74.7.241.60:59140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/article.php"] [unique_id "amuKQirT982lovRn7gnCNQAAYBI"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/1784117929_IMG_3676.jpg
[Thu Jul 30 12:30:42.798749 2026] [core:notice] [pid 751901:tid 752155] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:42.803421 2026] [security2:error] [pid 751901:tid 752155] [client 103.215.74.26:34444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "741"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKQirT982lovRn7gnCQgAAAHw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:43.212333 2026] [security2:error] [pid 751901:tid 752061] [client 52.238.199.152:18229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-content/admin.php"] [unique_id "amuKQyrT982lovRn7gnCSgAAAB4"]
[Thu Jul 30 12:30:43.217215 2026] [security2:error] [pid 751901:tid 752103] [client 20.215.191.139:6991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/admin.php"] [unique_id "amuKQyrT982lovRn7gnCTAAAAEg"]
[Thu Jul 30 12:30:43.238559 2026] [security2:error] [pid 751901:tid 752091] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuKQyrT982lovRn7gnCTwAAADw"]
[Thu Jul 30 12:30:43.238647 2026] [security2:error] [pid 751901:tid 752091] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuKQyrT982lovRn7gnCTwAAADw"]
[Thu Jul 30 12:30:43.526947 2026] [core:notice] [pid 751901:tid 752096] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:43.531192 2026] [security2:error] [pid 751901:tid 752096] [client 103.215.74.26:12248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKQyrT982lovRn7gnCWAAAAEE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:43.577396 2026] [security2:error] [pid 751901:tid 752080] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuKQyrT982lovRn7gnCXgAAADE"]
[Thu Jul 30 12:30:43.577495 2026] [security2:error] [pid 751901:tid 752080] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuKQyrT982lovRn7gnCXgAAADE"]
[Thu Jul 30 12:30:43.758497 2026] [security2:error] [pid 751901:tid 752058] [client 172.202.44.182:45045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/upfile.php"] [unique_id "amuKQyrT982lovRn7gnCYwAAABs"]
[Thu Jul 30 12:30:43.908135 2026] [security2:error] [pid 751901:tid 752081] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuKQyrT982lovRn7gnCZAAAADI"]
[Thu Jul 30 12:30:43.908224 2026] [security2:error] [pid 751901:tid 752081] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuKQyrT982lovRn7gnCZAAAADI"]
[Thu Jul 30 12:30:44.050565 2026] [security2:error] [pid 751901:tid 752056] [client 20.215.191.139:8211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "amuKRCrT982lovRn7gnCZwAAABk"]
[Thu Jul 30 12:30:44.159791 2026] [security2:error] [pid 751901:tid 752108] [client 52.238.199.152:51351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-load.php"] [unique_id "amuKRCrT982lovRn7gnCawAAAE0"]
[Thu Jul 30 12:30:44.212208 2026] [security2:error] [pid 751901:tid 752034] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/err.php"] [unique_id "amuKRCrT982lovRn7gnCbwAAAAM"]
[Thu Jul 30 12:30:44.212307 2026] [security2:error] [pid 751901:tid 752034] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/err.php"] [unique_id "amuKRCrT982lovRn7gnCbwAAAAM"]
[Thu Jul 30 12:30:44.252762 2026] [core:notice] [pid 751901:tid 752134] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:44.259502 2026] [security2:error] [pid 751901:tid 752134] [client 103.215.74.26:12258] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKRCrT982lovRn7gnCcQAAAGc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:44.510334 2026] [security2:error] [pid 751901:tid 752066] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/img.php"] [unique_id "amuKRCrT982lovRn7gnCcwAAACM"]
[Thu Jul 30 12:30:44.510451 2026] [security2:error] [pid 751901:tid 752066] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/img.php"] [unique_id "amuKRCrT982lovRn7gnCcwAAACM"]
[Thu Jul 30 12:30:44.750710 2026] [security2:error] [pid 751901:tid 752059] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/aa.php"] [unique_id "amuKRCrT982lovRn7gnCewAAABw"]
[Thu Jul 30 12:30:44.750815 2026] [security2:error] [pid 751901:tid 752059] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/aa.php"] [unique_id "amuKRCrT982lovRn7gnCewAAABw"]
[Thu Jul 30 12:30:44.828712 2026] [core:notice] [pid 751901:tid 752052] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:44.839186 2026] [core:notice] [pid 751901:tid 752130] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:44.839961 2026] [security2:error] [pid 751901:tid 752084] [client 172.202.44.182:44377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/bypass.php"] [unique_id "amuKRCrT982lovRn7gnCfgAAADU"]
[Thu Jul 30 12:30:44.854195 2026] [core:notice] [pid 751901:tid 752102] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:44.860878 2026] [core:notice] [pid 751901:tid 752088] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:44.982249 2026] [core:notice] [pid 751901:tid 752050] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:44.989114 2026] [security2:error] [pid 751901:tid 752050] [client 103.215.74.26:12266] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKRCrT982lovRn7gnCgwAAABM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:45.050485 2026] [security2:error] [pid 751901:tid 752147] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/av.php"] [unique_id "amuKRSrT982lovRn7gnChAAAAHQ"]
[Thu Jul 30 12:30:45.050593 2026] [security2:error] [pid 751901:tid 752147] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/av.php"] [unique_id "amuKRSrT982lovRn7gnChAAAAHQ"]
[Thu Jul 30 12:30:45.300259 2026] [security2:error] [pid 751901:tid 752040] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/xa.php"] [unique_id "amuKRSrT982lovRn7gnCkAAAAAk"]
[Thu Jul 30 12:30:45.300385 2026] [security2:error] [pid 751901:tid 752040] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/xa.php"] [unique_id "amuKRSrT982lovRn7gnCkAAAAAk"]
[Thu Jul 30 12:30:45.541637 2026] [security2:error] [pid 751901:tid 752073] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/media.php"] [unique_id "amuKRSrT982lovRn7gnCkQAAACo"]
[Thu Jul 30 12:30:45.541750 2026] [security2:error] [pid 751901:tid 752073] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/media.php"] [unique_id "amuKRSrT982lovRn7gnCkQAAACo"]
[Thu Jul 30 12:30:45.551547 2026] [security2:error] [pid 751901:tid 752031] [client 20.215.191.139:7035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/db-cache.php"] [unique_id "amuKRSrT982lovRn7gnCkgAAAAA"]
[Thu Jul 30 12:30:45.616292 2026] [core:notice] [pid 751901:tid 752092] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:45.642293 2026] [core:notice] [pid 751901:tid 752152] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:45.671849 2026] [core:notice] [pid 751901:tid 752117] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:45.737566 2026] [core:notice] [pid 751901:tid 752046] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:45.741355 2026] [security2:error] [pid 751901:tid 752046] [client 103.215.74.26:12274] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKRSrT982lovRn7gnCnQAAAA8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:45.780152 2026] [security2:error] [pid 751901:tid 752057] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/images.php"] [unique_id "amuKRSrT982lovRn7gnCnwAAABo"]
[Thu Jul 30 12:30:45.780239 2026] [security2:error] [pid 751901:tid 752057] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/images.php"] [unique_id "amuKRSrT982lovRn7gnCnwAAABo"]
[Thu Jul 30 12:30:45.904906 2026] [security2:error] [pid 751901:tid 752121] [client 172.202.44.182:45024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/updates.php"] [unique_id "amuKRSrT982lovRn7gnCoQAAAFo"]
[Thu Jul 30 12:30:45.914839 2026] [core:notice] [pid 751901:tid 752099] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:46.015188 2026] [security2:error] [pid 751901:tid 752140] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/gecko.php"] [unique_id "amuKRirT982lovRn7gnCowAAAG0"]
[Thu Jul 30 12:30:46.015298 2026] [security2:error] [pid 751901:tid 752140] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/gecko.php"] [unique_id "amuKRirT982lovRn7gnCowAAAG0"]
[Thu Jul 30 12:30:46.276588 2026] [security2:error] [pid 751901:tid 752144] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/82.php"] [unique_id "amuKRirT982lovRn7gnCrQAAAHE"]
[Thu Jul 30 12:30:46.276698 2026] [security2:error] [pid 751901:tid 752144] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/82.php"] [unique_id "amuKRirT982lovRn7gnCrQAAAHE"]
[Thu Jul 30 12:30:46.286486 2026] [security2:error] [pid 751901:tid 752081] [client 20.215.191.139:9031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/themes/twentyeleven/functions.php"] [unique_id "amuKRirT982lovRn7gnCrgAAADI"]
[Thu Jul 30 12:30:46.474916 2026] [core:notice] [pid 751901:tid 752079] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:46.478841 2026] [security2:error] [pid 751901:tid 752079] [client 103.215.74.26:12290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKRirT982lovRn7gnCuAAAADA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:46.511904 2026] [security2:error] [pid 751901:tid 752048] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/xstelth.php"] [unique_id "amuKRirT982lovRn7gnCuQAAABE"]
[Thu Jul 30 12:30:46.512013 2026] [security2:error] [pid 751901:tid 752048] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/xstelth.php"] [unique_id "amuKRirT982lovRn7gnCuQAAABE"]
[Thu Jul 30 12:30:46.560334 2026] [security2:error] [pid 751901:tid 752036] [client 52.238.199.152:35996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/as/function.php"] [unique_id "amuKRirT982lovRn7gnCugAAAAU"]
[Thu Jul 30 12:30:46.763927 2026] [security2:error] [pid 751901:tid 752087] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/xp.php"] [unique_id "amuKRirT982lovRn7gnCwQAAADg"]
[Thu Jul 30 12:30:46.764098 2026] [security2:error] [pid 751901:tid 752087] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/xp.php"] [unique_id "amuKRirT982lovRn7gnCwQAAADg"]
[Thu Jul 30 12:30:46.921767 2026] [core:error] [pid 751901:tid 752040] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:30:46.921790 2026] [core:error] [pid 751901:tid 752040] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:30:46.939763 2026] [core:error] [pid 751901:tid 752132] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:30:46.939788 2026] [core:error] [pid 751901:tid 752132] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:30:46.945716 2026] [core:error] [pid 751901:tid 752058] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:30:46.945734 2026] [core:error] [pid 751901:tid 752058] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:30:46.951204 2026] [core:error] [pid 751901:tid 752090] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:30:46.951223 2026] [core:error] [pid 751901:tid 752090] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:30:46.973147 2026] [core:error] [pid 751901:tid 752063] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:30:46.973167 2026] [core:error] [pid 751901:tid 752063] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:30:47.045825 2026] [security2:error] [pid 751901:tid 752051] [client 38.190.144.4:61921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKRyrT982lovRn7gnC3gAAABQ"]
[Thu Jul 30 12:30:47.047859 2026] [security2:error] [pid 751901:tid 752051] [client 38.190.144.4:61921] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKRyrT982lovRn7gnC3gAAABQ"]
[Thu Jul 30 12:30:47.053614 2026] [security2:error] [pid 751901:tid 752085] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/admin.php"] [unique_id "amuKRyrT982lovRn7gnC3wAAADY"]
[Thu Jul 30 12:30:47.053730 2026] [security2:error] [pid 751901:tid 752085] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/admin.php"] [unique_id "amuKRyrT982lovRn7gnC3wAAADY"]
[Thu Jul 30 12:30:47.196800 2026] [core:notice] [pid 751901:tid 752089] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:47.203812 2026] [security2:error] [pid 751901:tid 752089] [client 103.215.74.26:12292] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKRyrT982lovRn7gnC4AAAADo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:47.243298 2026] [security2:error] [pid 751901:tid 752057] [client 43.131.26.226:39194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.26.131.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuKRirT982lovRn7gnC3QAAABo"]
[Thu Jul 30 12:30:47.295226 2026] [security2:error] [pid 751901:tid 752060] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/adminner.php"] [unique_id "amuKRyrT982lovRn7gnC5AAAAB0"]
[Thu Jul 30 12:30:47.295345 2026] [security2:error] [pid 751901:tid 752060] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/adminner.php"] [unique_id "amuKRyrT982lovRn7gnC5AAAAB0"]
[Thu Jul 30 12:30:47.538217 2026] [security2:error] [pid 751901:tid 752127] [client 172.202.44.182:44367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/xmrlpc.php"] [unique_id "amuKRyrT982lovRn7gnC7QAAAGA"]
[Thu Jul 30 12:30:47.545043 2026] [security2:error] [pid 751901:tid 752074] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/a.php"] [unique_id "amuKRyrT982lovRn7gnC7gAAACs"]
[Thu Jul 30 12:30:47.545134 2026] [security2:error] [pid 751901:tid 752074] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/a.php"] [unique_id "amuKRyrT982lovRn7gnC7gAAACs"]
[Thu Jul 30 12:30:47.551564 2026] [security2:error] [pid 751901:tid 752067] [client 20.215.191.139:2410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/themes/oceanwp/functions.php"] [unique_id "amuKRyrT982lovRn7gnC7wAAACQ"]
[Thu Jul 30 12:30:47.786248 2026] [security2:error] [pid 751901:tid 752061] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/k.php"] [unique_id "amuKRyrT982lovRn7gnC_wAAAB4"]
[Thu Jul 30 12:30:47.786357 2026] [security2:error] [pid 751901:tid 752061] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/k.php"] [unique_id "amuKRyrT982lovRn7gnC_wAAAB4"]
[Thu Jul 30 12:30:47.796631 2026] [core:notice] [pid 751901:tid 751959] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:47.951711 2026] [core:notice] [pid 751901:tid 752107] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:47.955885 2026] [security2:error] [pid 751901:tid 752107] [client 103.215.74.26:12300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "773"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKRyrT982lovRn7gnDBQAAAEw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:48.046450 2026] [security2:error] [pid 751901:tid 752106] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/222.php"] [unique_id "amuKSCrT982lovRn7gnDDAAAAEs"]
[Thu Jul 30 12:30:48.046558 2026] [security2:error] [pid 751901:tid 752106] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/222.php"] [unique_id "amuKSCrT982lovRn7gnDDAAAAEs"]
[Thu Jul 30 12:30:48.136105 2026] [core:notice] [pid 751901:tid 751973] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:48.303550 2026] [security2:error] [pid 751901:tid 752085] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/mac.php"] [unique_id "amuKSCrT982lovRn7gnDEgAAADY"]
[Thu Jul 30 12:30:48.303665 2026] [security2:error] [pid 751901:tid 752085] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/mac.php"] [unique_id "amuKSCrT982lovRn7gnDEgAAADY"]
[Thu Jul 30 12:30:48.548475 2026] [security2:error] [pid 751901:tid 752083] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "markmocek.com"] [uri "/cgi-sys/404.html"] [unique_id "amuKSCrT982lovRn7gnDFgAAADQ"]
[Thu Jul 30 12:30:48.588171 2026] [security2:error] [pid 751901:tid 751947] [remote 216.73.216.152:26249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuKSCrT982lovRn7gnDFwAAOi0"]
[Thu Jul 30 12:30:48.618900 2026] [security2:error] [pid 751901:tid 752111] [client 57.141.0.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuKSCrT982lovRn7gnDCwAAAFA"]
[Thu Jul 30 12:30:48.672630 2026] [core:notice] [pid 751901:tid 752143] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:48.676619 2026] [security2:error] [pid 751901:tid 752143] [client 103.215.74.26:12312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKSCrT982lovRn7gnDGAAAAHA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:48.718797 2026] [security2:error] [pid 751901:tid 752054] [client 172.202.44.182:18747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/ae.php"] [unique_id "amuKSCrT982lovRn7gnDGQAAABc"]
[Thu Jul 30 12:30:48.790248 2026] [security2:error] [pid 751901:tid 752144] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "markmocek.com"] [uri "/cgi-sys/404.html"] [unique_id "amuKSCrT982lovRn7gnDGgAAAHE"]
[Thu Jul 30 12:30:48.926341 2026] [security2:error] [pid 751901:tid 752042] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/ops.php"] [unique_id "amuKSCrT982lovRn7gnDIQAAAAs"]
[Thu Jul 30 12:30:48.926471 2026] [security2:error] [pid 751901:tid 752042] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/ops.php"] [unique_id "amuKSCrT982lovRn7gnDIQAAAAs"]
[Thu Jul 30 12:30:49.073115 2026] [security2:error] [pid 751901:tid 752127] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/8.php"] [unique_id "amuKSSrT982lovRn7gnDIgAAAGA"]
[Thu Jul 30 12:30:49.073221 2026] [security2:error] [pid 751901:tid 752127] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/8.php"] [unique_id "amuKSSrT982lovRn7gnDIgAAAGA"]
[Thu Jul 30 12:30:49.366234 2026] [security2:error] [pid 751901:tid 752079] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/FWAZ.php"] [unique_id "amuKSSrT982lovRn7gnDJwAAADA"]
[Thu Jul 30 12:30:49.366334 2026] [security2:error] [pid 751901:tid 752079] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/FWAZ.php"] [unique_id "amuKSSrT982lovRn7gnDJwAAADA"]
[Thu Jul 30 12:30:49.401122 2026] [core:notice] [pid 751901:tid 752067] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:49.404876 2026] [security2:error] [pid 751901:tid 752067] [client 103.215.74.26:12324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKSSrT982lovRn7gnDKQAAACQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:49.612964 2026] [security2:error] [pid 751901:tid 752102] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/biufile.php"] [unique_id "amuKSSrT982lovRn7gnDLwAAAEc"]
[Thu Jul 30 12:30:49.613089 2026] [security2:error] [pid 751901:tid 752102] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/biufile.php"] [unique_id "amuKSSrT982lovRn7gnDLwAAAEc"]
[Thu Jul 30 12:30:49.918908 2026] [security2:error] [pid 751901:tid 752113] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/coffexium.php"] [unique_id "amuKSSrT982lovRn7gnDNAAAAFI"]
[Thu Jul 30 12:30:49.919018 2026] [security2:error] [pid 751901:tid 752113] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/coffexium.php"] [unique_id "amuKSSrT982lovRn7gnDNAAAAFI"]
[Thu Jul 30 12:30:50.058678 2026] [security2:error] [pid 751901:tid 752037] [client 52.238.199.152:35968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/filter.php"] [unique_id "amuKSirT982lovRn7gnDOwAAAAY"]
[Thu Jul 30 12:30:50.133725 2026] [core:notice] [pid 751901:tid 752053] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:50.137644 2026] [security2:error] [pid 751901:tid 752053] [client 103.215.74.26:12326] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKSirT982lovRn7gnDPAAAABY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:50.163834 2026] [security2:error] [pid 751901:tid 752107] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/simple.php"] [unique_id "amuKSirT982lovRn7gnDPQAAAEw"]
[Thu Jul 30 12:30:50.163919 2026] [security2:error] [pid 751901:tid 752107] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/simple.php"] [unique_id "amuKSirT982lovRn7gnDPQAAAEw"]
[Thu Jul 30 12:30:50.301423 2026] [security2:error] [pid 751901:tid 752148] [client 172.202.44.182:4831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/moon.php"] [unique_id "amuKSirT982lovRn7gnDPwAAAHU"]
[Thu Jul 30 12:30:50.401699 2026] [security2:error] [pid 751901:tid 752047] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/fpwch.php"] [unique_id "amuKSirT982lovRn7gnDQAAAABA"]
[Thu Jul 30 12:30:50.401809 2026] [security2:error] [pid 751901:tid 752047] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/fpwch.php"] [unique_id "amuKSirT982lovRn7gnDQAAAABA"]
[Thu Jul 30 12:30:50.659596 2026] [security2:error] [pid 751901:tid 752064] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/dex.php"] [unique_id "amuKSirT982lovRn7gnDSwAAACE"]
[Thu Jul 30 12:30:50.659688 2026] [security2:error] [pid 751901:tid 752064] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/dex.php"] [unique_id "amuKSirT982lovRn7gnDSwAAACE"]
[Thu Jul 30 12:30:50.886629 2026] [core:notice] [pid 751901:tid 752051] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:50.890670 2026] [security2:error] [pid 751901:tid 752051] [client 103.215.74.26:12332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "745"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKSirT982lovRn7gnDUgAAABQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:50.983338 2026] [security2:error] [pid 751901:tid 752057] [client 51.116.238.8:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "markmocek.com"] [uri "/1.php"] [unique_id "amuKSirT982lovRn7gnDWQAAABo"]
[Thu Jul 30 12:30:50.983434 2026] [security2:error] [pid 751901:tid 752057] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/1.php"] [unique_id "amuKSirT982lovRn7gnDWQAAABo"]
[Thu Jul 30 12:30:50.983503 2026] [security2:error] [pid 751901:tid 752057] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/1.php"] [unique_id "amuKSirT982lovRn7gnDWQAAABo"]
[Thu Jul 30 12:30:51.010642 2026] [security2:error] [pid 751901:tid 752092] [client 20.215.191.139:7027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/themes/twentythirteen/functions.php"] [unique_id "amuKSyrT982lovRn7gnDWgAAAD0"]
[Thu Jul 30 12:30:51.171218 2026] [security2:error] [pid 751901:tid 752082] [client 216.73.216.247:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.designmenow.net"] [uri "/public/index.php"] [unique_id "amuKSirT982lovRn7gnDPgAAM08"]
[Thu Jul 30 12:30:51.286491 2026] [security2:error] [pid 751901:tid 752050] [client 172.202.44.182:37218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/blog.php"] [unique_id "amuKSyrT982lovRn7gnDYQAAABM"]
[Thu Jul 30 12:30:51.303185 2026] [security2:error] [pid 751901:tid 752033] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "markmocek.com"] [uri "/cgi-sys/404.html"] [unique_id "amuKSyrT982lovRn7gnDYgAAAAI"]
[Thu Jul 30 12:30:51.563323 2026] [security2:error] [pid 751901:tid 752079] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/config.json.php"] [unique_id "amuKSyrT982lovRn7gnDZwAAADA"]
[Thu Jul 30 12:30:51.563420 2026] [security2:error] [pid 751901:tid 752079] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/config.json.php"] [unique_id "amuKSyrT982lovRn7gnDZwAAADA"]
[Thu Jul 30 12:30:51.607261 2026] [core:notice] [pid 751901:tid 752070] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:51.611165 2026] [security2:error] [pid 751901:tid 752070] [client 103.215.74.26:12342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "737"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKSyrT982lovRn7gnDagAAACc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:51.725907 2026] [security2:error] [pid 751901:tid 752100] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/k2.php"] [unique_id "amuKSyrT982lovRn7gnDbwAAAEU"]
[Thu Jul 30 12:30:51.726010 2026] [security2:error] [pid 751901:tid 752100] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/k2.php"] [unique_id "amuKSyrT982lovRn7gnDbwAAAEU"]
[Thu Jul 30 12:30:51.807756 2026] [security2:error] [pid 751901:tid 752127] [client 20.215.191.139:11580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/themes/kadence/functions.php"] [unique_id "amuKSyrT982lovRn7gnDcAAAAGA"]
[Thu Jul 30 12:30:51.826734 2026] [core:error] [pid 751901:tid 751942] [remote 74.7.244.17:41216] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:30:51.826766 2026] [core:error] [pid 751901:tid 751942] [remote 74.7.244.17:41216] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:30:51.826968 2026] [security2:error] [pid 751901:tid 752084] [client 74.7.244.17:41216] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.website-55933577.ubp.hmu.temporary.site"] [uri "/index.php"] [unique_id "amuKSyrT982lovRn7gnDcQAANSg"]
[Thu Jul 30 12:30:52.039333 2026] [security2:error] [pid 751901:tid 752145] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/raw.php"] [unique_id "amuKTCrT982lovRn7gnDcwAAAHI"]
[Thu Jul 30 12:30:52.039440 2026] [security2:error] [pid 751901:tid 752145] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/raw.php"] [unique_id "amuKTCrT982lovRn7gnDcwAAAHI"]
[Thu Jul 30 12:30:52.286738 2026] [security2:error] [pid 751901:tid 752087] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/wp.php"] [unique_id "amuKTCrT982lovRn7gnDeQAAADg"]
[Thu Jul 30 12:30:52.286845 2026] [security2:error] [pid 751901:tid 752087] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/wp.php"] [unique_id "amuKTCrT982lovRn7gnDeQAAADg"]
[Thu Jul 30 12:30:52.339638 2026] [core:notice] [pid 751901:tid 752103] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:52.343683 2026] [security2:error] [pid 751901:tid 752103] [client 103.215.74.26:12344] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "745"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKTCrT982lovRn7gnDegAAAEg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:52.526732 2026] [security2:error] [pid 751901:tid 752141] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/fffm.php"] [unique_id "amuKTCrT982lovRn7gnDgQAAAG4"]
[Thu Jul 30 12:30:52.526827 2026] [security2:error] [pid 751901:tid 752141] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/fffm.php"] [unique_id "amuKTCrT982lovRn7gnDgQAAAG4"]
[Thu Jul 30 12:30:52.779879 2026] [security2:error] [pid 751901:tid 752049] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/111.php"] [unique_id "amuKTCrT982lovRn7gnDhwAAABI"]
[Thu Jul 30 12:30:52.780041 2026] [security2:error] [pid 751901:tid 752049] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/111.php"] [unique_id "amuKTCrT982lovRn7gnDhwAAABI"]
[Thu Jul 30 12:30:52.858445 2026] [security2:error] [pid 751901:tid 752037] [client 20.215.191.139:11535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/themes/twentytwenty/functions.php"] [unique_id "amuKTCrT982lovRn7gnDiAAAAAY"]
[Thu Jul 30 12:30:53.001638 2026] [security2:error] [pid 751901:tid 752038] [client 172.202.44.182:4818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/ini.php"] [unique_id "amuKTSrT982lovRn7gnDigAAAAc"]
[Thu Jul 30 12:30:53.079204 2026] [core:notice] [pid 751901:tid 752098] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:53.083070 2026] [security2:error] [pid 751901:tid 752098] [client 103.215.74.26:56714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKTSrT982lovRn7gnDjgAAAEM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:53.094484 2026] [security2:error] [pid 751901:tid 752083] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "markmocek.com"] [uri "/cgi-sys/404.html"] [unique_id "amuKTSrT982lovRn7gnDjwAAADQ"]
[Thu Jul 30 12:30:53.234938 2026] [security2:error] [pid 751901:tid 752040] [client 52.238.199.152:17589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/he.php"] [unique_id "amuKTSrT982lovRn7gnDmAAAAAk"]
[Thu Jul 30 12:30:53.260764 2026] [security2:error] [pid 751901:tid 752065] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/ws.php"] [unique_id "amuKTSrT982lovRn7gnDmgAAACI"]
[Thu Jul 30 12:30:53.260898 2026] [security2:error] [pid 751901:tid 752065] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/ws.php"] [unique_id "amuKTSrT982lovRn7gnDmgAAACI"]
[Thu Jul 30 12:30:53.584545 2026] [security2:error] [pid 751901:tid 752135] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/coffee.php"] [unique_id "amuKTSrT982lovRn7gnDngAAAGg"]
[Thu Jul 30 12:30:53.584681 2026] [security2:error] [pid 751901:tid 752135] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/coffee.php"] [unique_id "amuKTSrT982lovRn7gnDngAAAGg"]
[Thu Jul 30 12:30:53.816904 2026] [core:notice] [pid 751901:tid 752139] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:53.820850 2026] [security2:error] [pid 751901:tid 752139] [client 103.215.74.26:56724] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKTSrT982lovRn7gnDogAAAGw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:53.839877 2026] [security2:error] [pid 751901:tid 752158] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/goods.php"] [unique_id "amuKTSrT982lovRn7gnDowAAAH8"]
[Thu Jul 30 12:30:53.840029 2026] [security2:error] [pid 751901:tid 752158] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/goods.php"] [unique_id "amuKTSrT982lovRn7gnDowAAAH8"]
[Thu Jul 30 12:30:53.840055 2026] [security2:error] [pid 751901:tid 752093] [client 172.202.44.182:44390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/admin-ajax.php"] [unique_id "amuKTSrT982lovRn7gnDpAAAAD4"]
[Thu Jul 30 12:30:53.862497 2026] [security2:error] [pid 751901:tid 752074] [client 20.215.191.139:8517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/content.php"] [unique_id "amuKTSrT982lovRn7gnDpQAAACs"]
[Thu Jul 30 12:30:54.079086 2026] [security2:error] [pid 751901:tid 752059] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/about.php"] [unique_id "amuKTirT982lovRn7gnDqAAAABw"]
[Thu Jul 30 12:30:54.079203 2026] [security2:error] [pid 751901:tid 752059] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/about.php"] [unique_id "amuKTirT982lovRn7gnDqAAAABw"]
[Thu Jul 30 12:30:54.080861 2026] [security2:error] [pid 751901:tid 752109] [client 37.120.155.179:56394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.155.120.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuKTirT982lovRn7gnDpwAAAE4"]
[Thu Jul 30 12:30:54.080935 2026] [security2:error] [pid 751901:tid 752109] [client 37.120.155.179:56394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuKTirT982lovRn7gnDpwAAAE4"]
[Thu Jul 30 12:30:54.370805 2026] [security2:error] [pid 751901:tid 752148] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/about.php"] [unique_id "amuKTirT982lovRn7gnDtAAAAHU"]
[Thu Jul 30 12:30:54.370904 2026] [security2:error] [pid 751901:tid 752148] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/about.php"] [unique_id "amuKTirT982lovRn7gnDtAAAAHU"]
[Thu Jul 30 12:30:54.512060 2026] [security2:error] [pid 751901:tid 752100] [client 52.238.199.152:17549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-admin/setup-config.php"] [unique_id "amuKTirT982lovRn7gnDtgAAAEU"]
[Thu Jul 30 12:30:54.571903 2026] [core:notice] [pid 751901:tid 752141] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:54.576215 2026] [security2:error] [pid 751901:tid 752141] [client 103.215.74.26:56738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKTirT982lovRn7gnDtwAAAG4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:54.609762 2026] [security2:error] [pid 751901:tid 752157] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/admin.php"] [unique_id "amuKTirT982lovRn7gnDuAAAAH4"]
[Thu Jul 30 12:30:54.609863 2026] [security2:error] [pid 751901:tid 752157] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/admin.php"] [unique_id "amuKTirT982lovRn7gnDuAAAAH4"]
[Thu Jul 30 12:30:54.709292 2026] [security2:error] [pid 751901:tid 752047] [client 172.202.44.182:18723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/akc.php"] [unique_id "amuKTirT982lovRn7gnDwAAAABA"]
[Thu Jul 30 12:30:54.784594 2026] [security2:error] [pid 751901:tid 752073] [client 38.190.144.4:64407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKTirT982lovRn7gnDwQAAACo"]
[Thu Jul 30 12:30:54.784743 2026] [security2:error] [pid 751901:tid 752073] [client 38.190.144.4:64407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKTirT982lovRn7gnDwQAAACo"]
[Thu Jul 30 12:30:54.852050 2026] [security2:error] [pid 751901:tid 752063] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/inputs.php"] [unique_id "amuKTirT982lovRn7gnDxQAAACA"]
[Thu Jul 30 12:30:54.852159 2026] [security2:error] [pid 751901:tid 752063] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/inputs.php"] [unique_id "amuKTirT982lovRn7gnDxQAAACA"]
[Thu Jul 30 12:30:55.100471 2026] [security2:error] [pid 751901:tid 752092] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/inputs.php"] [unique_id "amuKTyrT982lovRn7gnDxwAAAD0"]
[Thu Jul 30 12:30:55.100583 2026] [security2:error] [pid 751901:tid 752092] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/inputs.php"] [unique_id "amuKTyrT982lovRn7gnDxwAAAD0"]
[Thu Jul 30 12:30:55.303278 2026] [core:notice] [pid 751901:tid 752057] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:55.308098 2026] [security2:error] [pid 751901:tid 752057] [client 103.215.74.26:56742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKTyrT982lovRn7gnDzgAAABo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:55.343864 2026] [security2:error] [pid 751901:tid 752134] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/adminfuns.php"] [unique_id "amuKTyrT982lovRn7gnDzwAAAGc"]
[Thu Jul 30 12:30:55.343953 2026] [security2:error] [pid 751901:tid 752134] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/adminfuns.php"] [unique_id "amuKTyrT982lovRn7gnDzwAAAGc"]
[Thu Jul 30 12:30:55.585747 2026] [security2:error] [pid 751901:tid 752078] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/404.php"] [unique_id "amuKTyrT982lovRn7gnD0wAAAC8"]
[Thu Jul 30 12:30:55.585887 2026] [security2:error] [pid 751901:tid 752078] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/404.php"] [unique_id "amuKTyrT982lovRn7gnD0wAAAC8"]
[Thu Jul 30 12:30:55.685433 2026] [security2:error] [pid 751901:tid 752042] [client 172.202.44.182:18732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/akcc.php"] [unique_id "amuKTyrT982lovRn7gnD2AAAAAs"]
[Thu Jul 30 12:30:55.822879 2026] [security2:error] [pid 751901:tid 752048] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/xxx.php"] [unique_id "amuKTyrT982lovRn7gnD3QAAABE"]
[Thu Jul 30 12:30:55.823003 2026] [security2:error] [pid 751901:tid 752048] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/xxx.php"] [unique_id "amuKTyrT982lovRn7gnD3QAAABE"]
[Thu Jul 30 12:30:55.823411 2026] [security2:error] [pid 751901:tid 752094] [client 52.238.199.152:55100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-content/languages/wp-login.php"] [unique_id "amuKTyrT982lovRn7gnD3gAAAD8"]
[Thu Jul 30 12:30:56.043707 2026] [core:notice] [pid 751901:tid 752067] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:56.047705 2026] [security2:error] [pid 751901:tid 752067] [client 103.215.74.26:56758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKUCrT982lovRn7gnD5AAAACQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:56.312524 2026] [security2:error] [pid 751901:tid 752087] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/classwithtostring.php"] [unique_id "amuKUCrT982lovRn7gnD8AAAADg"]
[Thu Jul 30 12:30:56.312636 2026] [security2:error] [pid 751901:tid 752087] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/classwithtostring.php"] [unique_id "amuKUCrT982lovRn7gnD8AAAADg"]
[Thu Jul 30 12:30:56.370536 2026] [security2:error] [pid 751901:tid 752040] [client 2a03:2880:f800:38:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuKTyrT982lovRn7gnD3AAACUI"]
[Thu Jul 30 12:30:56.507131 2026] [security2:error] [pid 751901:tid 752107] [client 20.215.191.139:11578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/plugins/not/includes/about.php"] [unique_id "amuKUCrT982lovRn7gnD8gAAAEw"]
[Thu Jul 30 12:30:56.557009 2026] [security2:error] [pid 751901:tid 752053] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/234ff.php"] [unique_id "amuKUCrT982lovRn7gnD9gAAABY"]
[Thu Jul 30 12:30:56.557093 2026] [security2:error] [pid 751901:tid 752053] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/234ff.php"] [unique_id "amuKUCrT982lovRn7gnD9gAAABY"]
[Thu Jul 30 12:30:56.769297 2026] [core:notice] [pid 751901:tid 752096] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:56.773624 2026] [security2:error] [pid 751901:tid 752096] [client 103.215.74.26:56772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKUCrT982lovRn7gnD_QAAAEE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:56.866037 2026] [security2:error] [pid 751901:tid 752136] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/133.php"] [unique_id "amuKUCrT982lovRn7gnD_gAAAGk"]
[Thu Jul 30 12:30:56.866142 2026] [security2:error] [pid 751901:tid 752136] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/133.php"] [unique_id "amuKUCrT982lovRn7gnD_gAAAGk"]
[Thu Jul 30 12:30:56.972008 2026] [security2:error] [pid 751901:tid 752116] [client 172.202.44.182:37212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/asasx.php"] [unique_id "amuKUCrT982lovRn7gnD_wAAAFU"]
[Thu Jul 30 12:30:57.135731 2026] [security2:error] [pid 751901:tid 752041] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/wp-ws68.php"] [unique_id "amuKUSrT982lovRn7gnEBgAAAAo"]
[Thu Jul 30 12:30:57.135820 2026] [security2:error] [pid 751901:tid 752041] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/wp-ws68.php"] [unique_id "amuKUSrT982lovRn7gnEBgAAAAo"]
[Thu Jul 30 12:30:57.141301 2026] [core:notice] [pid 751901:tid 752038] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:57.215139 2026] [security2:error] [pid 751901:tid 752063] [client 20.215.191.139:8552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/plugins/simple/simple.php"] [unique_id "amuKUSrT982lovRn7gnEDgAAACA"]
[Thu Jul 30 12:30:57.412217 2026] [security2:error] [pid 751901:tid 752065] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/mgrr.php"] [unique_id "amuKUSrT982lovRn7gnEEgAAACI"]
[Thu Jul 30 12:30:57.412359 2026] [security2:error] [pid 751901:tid 752065] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/mgrr.php"] [unique_id "amuKUSrT982lovRn7gnEEgAAACI"]
[Thu Jul 30 12:30:57.648988 2026] [security2:error] [pid 751901:tid 752035] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/55.php"] [unique_id "amuKUSrT982lovRn7gnEFwAAAAQ"]
[Thu Jul 30 12:30:57.649135 2026] [security2:error] [pid 751901:tid 752035] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/55.php"] [unique_id "amuKUSrT982lovRn7gnEFwAAAAQ"]
[Thu Jul 30 12:30:57.781933 2026] [security2:error] [pid 751901:tid 752105] [client 57.141.0.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuKUSrT982lovRn7gnECgAAAEo"]
[Thu Jul 30 12:30:57.964114 2026] [security2:error] [pid 751901:tid 752079] [client 20.215.191.139:12295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/plugins/wp-theme-editor/include.php"] [unique_id "amuKUSrT982lovRn7gnEHwAAADA"]
[Thu Jul 30 12:30:58.459192 2026] [security2:error] [pid 751901:tid 752125] [client 172.202.44.182:4801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/axx.php"] [unique_id "amuKUirT982lovRn7gnELQAAAF4"]
[Thu Jul 30 12:30:58.654305 2026] [security2:error] [pid 751901:tid 752062] [client 2a03:2880:f800:14:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuKUSrT982lovRn7gnEHgAAHww"]
[Thu Jul 30 12:30:58.711098 2026] [security2:error] [pid 751901:tid 752103] [client 20.215.191.139:13444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/themes/aahana/json.php"] [unique_id "amuKUirT982lovRn7gnEMgAAAEg"]
[Thu Jul 30 12:30:59.031950 2026] [autoindex:error] [pid 751901:tid 752073] [client 43.163.206.70:0] AH01276: Cannot serve directory /home2/mbmudite/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.n1rmalabet88.com
[Thu Jul 30 12:30:59.377835 2026] [security2:error] [pid 751901:tid 752117] [client 172.202.44.182:18717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/berax.php"] [unique_id "amuKUyrT982lovRn7gnESwAAAFY"]
[Thu Jul 30 12:30:59.790644 2026] [security2:error] [pid 751901:tid 751931] [remote 154.38.175.180:55478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.175.38.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-login.php"] [unique_id "amuKUyrT982lovRn7gnEWAAAQB0"]
[Thu Jul 30 12:30:59.825426 2026] [security2:error] [pid 751901:tid 752042] [client 47.128.121.74:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuKUyrT982lovRn7gnETwAAAAs"]
[Thu Jul 30 12:31:00.219548 2026] [security2:error] [pid 751901:tid 752155] [client 172.202.44.182:37197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/build.php"] [unique_id "amuKVCrT982lovRn7gnEXAAAAHw"]
[Thu Jul 30 12:31:01.063942 2026] [security2:error] [pid 751901:tid 751945] [remote 57.141.0.53:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuKVSrT982lovRn7gnEfAAAXSs"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,carbon,denim,polyester,plastic,linen,wood,nylon,lycra,titanium&min_price=300&orderby=rating&rating=5&tax_product_cat=furniture&unfilter=1
[Thu Jul 30 12:31:01.065030 2026] [security2:error] [pid 751901:tid 751962] [remote 57.141.0.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuKVSrT982lovRn7gnEewAAFjw"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,carbon,denim,polyester,plastic,linen,wood,nylon,lycra,titanium&min_price=300&orderby=rating&rating=5&tax_product_cat=furniture&unfilter=1
[Thu Jul 30 12:31:01.352764 2026] [security2:error] [pid 751901:tid 752075] [client 172.202.44.182:44374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/buy.php"] [unique_id "amuKVSrT982lovRn7gnEgAAAACw"]
[Thu Jul 30 12:31:01.398601 2026] [security2:error] [pid 751901:tid 752136] [client 20.215.191.139:12619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/plugins/awesome-coming-soon/come.php"] [unique_id "amuKVSrT982lovRn7gnEiAAAAGk"]
[Thu Jul 30 12:31:01.871275 2026] [core:notice] [pid 751901:tid 752140] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:02.248435 2026] [security2:error] [pid 751901:tid 752082] [client 20.215.191.139:12351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/plugins/wp-conflg.php"] [unique_id "amuKVirT982lovRn7gnEvQAAADM"]
[Thu Jul 30 12:31:02.562751 2026] [core:notice] [pid 751901:tid 752157] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:02.567346 2026] [security2:error] [pid 751901:tid 752157] [client 103.215.74.26:56784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKVirT982lovRn7gnEyAAAAH4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:02.693202 2026] [security2:error] [pid 751901:tid 752062] [client 172.202.44.182:4845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/checkbox.php"] [unique_id "amuKVirT982lovRn7gnEyQAAAB8"]
[Thu Jul 30 12:31:03.158795 2026] [security2:error] [pid 751901:tid 752020] [remote 103.28.36.200:35088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/wp-login.php"] [unique_id "amuKVirT982lovRn7gnEzQAALHY"]
[Thu Jul 30 12:31:03.303767 2026] [core:notice] [pid 751901:tid 752097] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:03.307952 2026] [security2:error] [pid 751901:tid 752097] [client 103.215.74.26:38168] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKVyrT982lovRn7gnE2AAAAEI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:04.952635 2026] [security2:error] [pid 751901:tid 752118] [client 172.202.44.182:4833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/cong.php"] [unique_id "amuKWCrT982lovRn7gnFCgAAAFc"]
[Thu Jul 30 12:31:05.265546 2026] [security2:error] [pid 751901:tid 752082] [client 172.237.109.114:28921] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWCrT982lovRn7gnE-gAAADM"]
[Thu Jul 30 12:31:05.278384 2026] [security2:error] [pid 751901:tid 752074] [client 172.237.109.114:1331] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWCrT982lovRn7gnE8wAAACs"]
[Thu Jul 30 12:31:05.280493 2026] [security2:error] [pid 751901:tid 752115] [client 172.237.109.114:7798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWCrT982lovRn7gnE9QAAAFQ"]
[Thu Jul 30 12:31:05.280517 2026] [security2:error] [pid 751901:tid 752113] [client 172.237.109.114:2077] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWCrT982lovRn7gnE9AAAAFI"]
[Thu Jul 30 12:31:05.284105 2026] [security2:error] [pid 751901:tid 752132] [client 172.237.109.114:44109] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWCrT982lovRn7gnE-wAAAGU"]
[Thu Jul 30 12:31:05.290455 2026] [security2:error] [pid 751901:tid 752031] [client 172.237.109.114:25677] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWCrT982lovRn7gnE-QAAAAA"]
[Thu Jul 30 12:31:05.301101 2026] [security2:error] [pid 751901:tid 752076] [client 172.237.109.114:52333] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWCrT982lovRn7gnE9gAAAC0"]
[Thu Jul 30 12:31:05.305524 2026] [security2:error] [pid 751901:tid 752093] [client 172.237.109.114:18986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWCrT982lovRn7gnE-AAAAD4"]
[Thu Jul 30 12:31:05.315627 2026] [security2:error] [pid 751901:tid 752086] [client 172.237.109.114:44494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWCrT982lovRn7gnE9wAAADc"]
[Thu Jul 30 12:31:05.324152 2026] [security2:error] [pid 751901:tid 752116] [client 172.237.109.114:4963] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWCrT982lovRn7gnE_QAAAFU"]
[Thu Jul 30 12:31:05.330849 2026] [security2:error] [pid 751901:tid 752150] [client 172.237.109.114:38831] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWCrT982lovRn7gnE_AAAAHc"]
[Thu Jul 30 12:31:05.594205 2026] [security2:error] [pid 751901:tid 752048] [client 38.190.144.4:64902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKWSrT982lovRn7gnFIwAAABE"]
[Thu Jul 30 12:31:05.594390 2026] [security2:error] [pid 751901:tid 752048] [client 38.190.144.4:64902] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKWSrT982lovRn7gnFIwAAABE"]
[Thu Jul 30 12:31:06.107133 2026] [security2:error] [pid 751901:tid 752127] [client 172.202.44.182:37210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/file4.php"] [unique_id "amuKWirT982lovRn7gnFQAAAAGA"]
[Thu Jul 30 12:31:06.306396 2026] [security2:error] [pid 751901:tid 752105] [client 172.237.109.114:7409] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWSrT982lovRn7gnFFwAAAEo"]
[Thu Jul 30 12:31:06.329542 2026] [security2:error] [pid 751901:tid 752075] [client 172.237.109.114:60667] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWSrT982lovRn7gnFDQAAACw"]
[Thu Jul 30 12:31:06.333005 2026] [security2:error] [pid 751901:tid 752070] [client 172.237.109.114:9447] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWSrT982lovRn7gnFDgAAACc"]
[Thu Jul 30 12:31:06.338840 2026] [security2:error] [pid 751901:tid 752097] [client 172.237.109.114:21927] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWSrT982lovRn7gnFEwAAAEI"]
[Thu Jul 30 12:31:06.346128 2026] [security2:error] [pid 751901:tid 752114] [client 172.237.109.114:20008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWSrT982lovRn7gnFCwAAAFM"]
[Thu Jul 30 12:31:06.346817 2026] [security2:error] [pid 751901:tid 752050] [client 172.237.109.114:46616] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWSrT982lovRn7gnFFgAAABM"]
[Thu Jul 30 12:31:06.350938 2026] [security2:error] [pid 751901:tid 752037] [client 172.237.109.114:54567] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWSrT982lovRn7gnFDwAAAAY"]
[Thu Jul 30 12:31:06.354555 2026] [security2:error] [pid 751901:tid 752123] [client 172.237.109.114:7545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWSrT982lovRn7gnFDAAAAFw"]
[Thu Jul 30 12:31:06.362855 2026] [security2:error] [pid 751901:tid 752092] [client 172.237.109.114:54134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWSrT982lovRn7gnFGAAAAD0"]
[Thu Jul 30 12:31:06.718838 2026] [security2:error] [pid 751901:tid 752138] [client 43.172.198.133:48938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.198.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/02/08/au-hasard-de-la-toile-32/"] [unique_id "amuKWirT982lovRn7gnFTwAAAGs"]
[Thu Jul 30 12:31:06.924189 2026] [security2:error] [pid 751901:tid 752104] [client 172.202.44.182:4834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/flower.php"] [unique_id "amuKWirT982lovRn7gnFXAAAAEk"]
[Thu Jul 30 12:31:07.086941 2026] [security2:error] [pid 751901:tid 752048] [client 20.215.191.139:42459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "amuKWyrT982lovRn7gnFYgAAABE"]
[Thu Jul 30 12:31:07.434738 2026] [core:notice] [pid 751901:tid 752157] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:07.443043 2026] [security2:error] [pid 751901:tid 752157] [client 43.173.181.164:49624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/02/08/au-hasard-de-la-toile-32/"] [unique_id "amuKWyrT982lovRn7gnFcQAAAH4"], referer: https://carnetdeshopping.com/index.php/2015/02/08/au-hasard-de-la-toile-32/?replytocom=1438
[Thu Jul 30 12:31:07.770430 2026] [security2:error] [pid 751901:tid 752143] [client 172.202.44.182:18708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/form.php"] [unique_id "amuKWyrT982lovRn7gnFeQAAAHA"]
[Thu Jul 30 12:31:07.800120 2026] [security2:error] [pid 751901:tid 752116] [client 119.73.97.132:29775] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuKWyrT982lovRn7gnFbwAAVQc"], referer: https://www.urwru.club/emm-elevate/?preview_id=685&preview_nonce=6cdd8f071f&preview=true&aaeid=1
[Thu Jul 30 12:31:08.163299 2026] [core:notice] [pid 751901:tid 752123] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:08.168909 2026] [core:notice] [pid 751901:tid 752123] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:08.336158 2026] [security2:error] [pid 751901:tid 752032] [client 20.215.191.139:11094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-includes/style-engine/about.php"] [unique_id "amuKXCrT982lovRn7gnFiQAAAAE"]
[Thu Jul 30 12:31:08.424700 2026] [security2:error] [pid 751901:tid 752034] [client 74.7.175.164:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.rvi.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuKWirT982lovRn7gnFYQAAAAM"]
[Thu Jul 30 12:31:08.425453 2026] [security2:error] [pid 751901:tid 752065] [client 74.7.175.164:54242] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.rvi.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuKWirT982lovRn7gnFXwAAIgg"]
[Thu Jul 30 12:31:08.723360 2026] [security2:error] [pid 751901:tid 752147] [client 172.202.44.182:40388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/gecko.php"] [unique_id "amuKXCrT982lovRn7gnFkQAAAHQ"]
[Thu Jul 30 12:31:08.907469 2026] [security2:error] [pid 751901:tid 752064] [client 20.215.191.139:30824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "amuKXCrT982lovRn7gnFpAAAACE"]
[Thu Jul 30 12:31:09.033204 2026] [core:notice] [pid 751901:tid 752107] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:09.040090 2026] [security2:error] [pid 751901:tid 752107] [client 103.215.74.26:38176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKXSrT982lovRn7gnFqAAAAEw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:09.666898 2026] [security2:error] [pid 751901:tid 752084] [client 20.215.191.139:30795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuKXSrT982lovRn7gnFxwAAADU"]
[Thu Jul 30 12:31:10.333520 2026] [security2:error] [pid 751901:tid 752130] [client 45.180.149.224:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuKXSrT982lovRn7gnFwgAAY0Q"], referer: https://allmontecristi.com
[Thu Jul 30 12:31:10.357290 2026] [security2:error] [pid 751901:tid 752051] [client 50.6.43.217:11626] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/1.jpg"] [unique_id "amuKXirT982lovRn7gnF6AAAABQ"]
[Thu Jul 30 12:31:10.368220 2026] [security2:error] [pid 751901:tid 752098] [client 50.6.43.217:11640] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/2.jpg"] [unique_id "amuKXirT982lovRn7gnF6gAAAEM"]
[Thu Jul 30 12:31:10.381485 2026] [security2:error] [pid 751901:tid 752153] [client 50.6.43.217:11652] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/3.jpg"] [unique_id "amuKXirT982lovRn7gnF7QAAAHo"]
[Thu Jul 30 12:31:11.136788 2026] [security2:error] [pid 751901:tid 752000] [remote 47.128.27.35:30148] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/nike-air-jordan-4-retro-leair-max-95-neon/"] [unique_id "amuKXyrT982lovRn7gnGBwAAf2I"]
[Thu Jul 30 12:31:11.170615 2026] [security2:error] [pid 751901:tid 752157] [client 20.215.191.139:3789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/banners/about.php"] [unique_id "amuKXyrT982lovRn7gnGCAAAAH4"]
[Thu Jul 30 12:31:12.164286 2026] [security2:error] [pid 751901:tid 752061] [client 119.73.97.132:29775] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuKXyrT982lovRn7gnGFgAAHmQ"]
[Thu Jul 30 12:31:12.796175 2026] [proxy:error] [pid 751901:tid 752088] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:31:12.796271 2026] [proxy_http:error] [pid 751901:tid 752088] [client 34.233.129.35:65044] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:31:12.796834 2026] [proxy:error] [pid 751901:tid 752088] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:31:12.796875 2026] [proxy_http:error] [pid 751901:tid 752088] [client 34.233.129.35:65044] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:31:12.817658 2026] [proxy:error] [pid 751901:tid 752135] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:31:12.817722 2026] [proxy_http:error] [pid 751901:tid 752135] [client 34.224.175.62:62181] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:31:12.818296 2026] [proxy:error] [pid 751901:tid 752135] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:31:12.818349 2026] [proxy_http:error] [pid 751901:tid 752135] [client 34.224.175.62:62181] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:31:13.002445 2026] [core:notice] [pid 751901:tid 752106] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:13.282754 2026] [fcgid:warn] [pid 751901:tid 752072] (70014)End of file found: [client 152.32.207.42:53114] mod_fcgid: can't get data from http client
[Thu Jul 30 12:31:13.499236 2026] [security2:error] [pid 751901:tid 752150] [client 119.73.97.132:29775] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuKYSrT982lovRn7gnGQwAAd28"]
[Thu Jul 30 12:31:13.829382 2026] [proxy:error] [pid 751901:tid 752121] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:31:13.829447 2026] [proxy_http:error] [pid 751901:tid 752121] [client 152.32.207.42:53122] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:31:13.830308 2026] [proxy:error] [pid 751901:tid 752121] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:31:13.830370 2026] [proxy_http:error] [pid 751901:tid 752121] [client 152.32.207.42:53122] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:31:13.867034 2026] [security2:error] [pid 751901:tid 752079] [client 40.77.167.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuKYSrT982lovRn7gnGRwAAADA"]
[Thu Jul 30 12:31:14.583250 2026] [security2:error] [pid 751901:tid 752077] [client 20.215.191.139:15016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/about.php"] [unique_id "amuKYirT982lovRn7gnGYQAAAC4"]
[Thu Jul 30 12:31:14.695326 2026] [proxy:error] [pid 751901:tid 752134] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:31:14.695396 2026] [proxy_http:error] [pid 751901:tid 752134] [client 152.32.207.42:53126] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:31:14.695942 2026] [proxy:error] [pid 751901:tid 752134] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:31:14.695998 2026] [proxy_http:error] [pid 751901:tid 752134] [client 152.32.207.42:53126] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:31:14.763953 2026] [core:notice] [pid 751901:tid 752071] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:14.768431 2026] [security2:error] [pid 751901:tid 752071] [client 103.215.74.26:5578] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKYirT982lovRn7gnGZwAAACg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:14.822549 2026] [core:notice] [pid 751901:tid 752082] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:15.893497 2026] [security2:error] [pid 751901:tid 752037] [client 172.202.44.182:4852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/kyami.php"] [unique_id "amuKYyrT982lovRn7gnGgAAAAAY"]
[Thu Jul 30 12:31:15.949323 2026] [security2:error] [pid 751901:tid 751911] [remote 114.119.130.27:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "spececigarette.com"] [uri "/robots.txt"] [unique_id "amuKYyrT982lovRn7gnGgQAAXQk"], referer: https://spececigarette.com/robots.txt
[Thu Jul 30 12:31:15.950929 2026] [security2:error] [pid 751901:tid 752093] [client 40.77.167.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuKYyrT982lovRn7gnGeAAAAD4"]
[Thu Jul 30 12:31:16.096570 2026] [proxy:error] [pid 751901:tid 752068] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:31:16.096650 2026] [proxy_http:error] [pid 751901:tid 752068] [client 152.32.207.42:53132] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:31:16.097226 2026] [proxy:error] [pid 751901:tid 752068] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:31:16.097270 2026] [proxy_http:error] [pid 751901:tid 752068] [client 152.32.207.42:53132] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:31:16.387970 2026] [security2:error] [pid 751901:tid 752150] [client 38.190.144.4:65412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKZCrT982lovRn7gnGjAAAAHc"]
[Thu Jul 30 12:31:16.388106 2026] [security2:error] [pid 751901:tid 752150] [client 38.190.144.4:65412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKZCrT982lovRn7gnGjAAAAHc"]
[Thu Jul 30 12:31:16.784914 2026] [security2:error] [pid 751901:tid 752038] [client 172.202.44.182:40389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/manager.php"] [unique_id "amuKZCrT982lovRn7gnGlgAAAAc"]
[Thu Jul 30 12:31:16.855033 2026] [security2:error] [pid 751901:tid 751968] [remote 45.146.192.214:27506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.192.146.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.lxw.gpl.temporary.site"] [uri "/wp-login.php"] [unique_id "amuKZCrT982lovRn7gnGlwAANUI"]
[Thu Jul 30 12:31:17.599558 2026] [proxy:error] [pid 751901:tid 752099] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:31:17.599654 2026] [proxy_http:error] [pid 751901:tid 752099] [client 152.32.207.42:53136] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:31:17.600238 2026] [proxy:error] [pid 751901:tid 752099] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:31:17.600288 2026] [proxy_http:error] [pid 751901:tid 752099] [client 152.32.207.42:53136] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:31:17.635515 2026] [security2:error] [pid 751901:tid 752132] [client 2a03:2880:f800:c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuKZSrT982lovRn7gnGmQAAZQU"]
[Thu Jul 30 12:31:17.703874 2026] [security2:error] [pid 751901:tid 752153] [client 172.202.44.182:31881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/mari.php"] [unique_id "amuKZSrT982lovRn7gnGrAAAAHo"]
[Thu Jul 30 12:31:17.858171 2026] [security2:error] [pid 751901:tid 752106] [client 20.215.191.139:2063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/.well-known/about.php"] [unique_id "amuKZSrT982lovRn7gnGswAAAEs"]
[Thu Jul 30 12:31:17.954626 2026] [security2:error] [pid 751901:tid 752036] [client 87.250.224.218:47690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuKZSrT982lovRn7gnGpwAAAAU"]
[Thu Jul 30 12:31:18.286928 2026] [security2:error] [pid 751901:tid 752097] [client 57.141.0.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuKZSrT982lovRn7gnGqAAAAEI"]
[Thu Jul 30 12:31:18.428758 2026] [core:notice] [pid 751901:tid 752157] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:18.850816 2026] [security2:error] [pid 751901:tid 752037] [client 161.248.56.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuKZirT982lovRn7gnGtQAABhw"], referer: https://allmontecristi.com
[Thu Jul 30 12:31:18.968653 2026] [security2:error] [pid 751901:tid 752079] [client 57.141.0.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuKZirT982lovRn7gnGwQAAADA"]
[Thu Jul 30 12:31:18.991734 2026] [security2:error] [pid 751901:tid 752053] [client 20.215.191.139:9564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuKZirT982lovRn7gnG0AAAABY"]
[Thu Jul 30 12:31:19.021619 2026] [core:notice] [pid 751901:tid 752063] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:19.035127 2026] [core:error] [pid 751901:tid 751903] [remote 74.7.175.132:60538] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:31:19.035143 2026] [core:error] [pid 751901:tid 751903] [remote 74.7.175.132:60538] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:31:19.035384 2026] [security2:error] [pid 751901:tid 752156] [client 74.7.175.132:60538] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "store.carnetdeshopping.com"] [uri "/index.php"] [unique_id "amuKZyrT982lovRn7gnG0gAAfQE"]
[Thu Jul 30 12:31:19.434750 2026] [core:notice] [pid 751901:tid 752116] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:19.609142 2026] [security2:error] [pid 751901:tid 752071] [client 172.202.44.182:18692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/nc4.php"] [unique_id "amuKZyrT982lovRn7gnG3gAAACg"]
[Thu Jul 30 12:31:20.164427 2026] [security2:error] [pid 751901:tid 752126] [client 20.215.191.139:9565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuKaCrT982lovRn7gnG7gAAAF8"]
[Thu Jul 30 12:31:20.488931 2026] [core:notice] [pid 751901:tid 752085] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:20.493490 2026] [security2:error] [pid 751901:tid 752085] [client 103.215.74.26:5584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKaCrT982lovRn7gnG-AAAADY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:20.640904 2026] [cgid:error] [pid 751901:tid 752138] [client 172.202.44.182:0] AH01265: stderr from /home2/dlrdjbte/public_html/website_b749bff5/cgi-bin/: attempt to invoke directory as script
[Thu Jul 30 12:31:20.703843 2026] [security2:error] [pid 751901:tid 752122] [client 20.215.191.139:9578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/img/about.php"] [unique_id "amuKaCrT982lovRn7gnG_gAAAFs"]
[Thu Jul 30 12:31:21.231624 2026] [core:notice] [pid 751901:tid 752091] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:21.236948 2026] [security2:error] [pid 751901:tid 752091] [client 103.215.74.26:5586] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKaSrT982lovRn7gnHCQAAADw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:21.530510 2026] [security2:error] [pid 751901:tid 752119] [client 20.215.191.139:7803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/languages/about.php"] [unique_id "amuKaSrT982lovRn7gnHEAAAAFg"]
[Thu Jul 30 12:31:21.859755 2026] [security2:error] [pid 751901:tid 752154] [client 91.92.41.115:55041] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.azureskyfilms.com"] [uri "/.env"] [unique_id "amuKaSrT982lovRn7gnHFwAAAHs"]
[Thu Jul 30 12:31:21.956033 2026] [core:notice] [pid 751901:tid 752101] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:21.960338 2026] [security2:error] [pid 751901:tid 752101] [client 103.215.74.26:5596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKaSrT982lovRn7gnHGwAAAEY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:22.691158 2026] [core:notice] [pid 751901:tid 752086] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:22.695550 2026] [security2:error] [pid 751901:tid 752086] [client 103.215.74.26:5610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKairT982lovRn7gnHMgAAADc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:23.205541 2026] [security2:error] [pid 751901:tid 752135] [client 91.92.41.115:55130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.azureskyfilms.com"] [uri "/.env"] [unique_id "amuKayrT982lovRn7gnHPQAAAGg"]
[Thu Jul 30 12:31:23.420262 2026] [core:notice] [pid 751901:tid 752146] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:23.424235 2026] [security2:error] [pid 751901:tid 752146] [client 103.215.74.26:3024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKayrT982lovRn7gnHQQAAAHM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:23.829378 2026] [security2:error] [pid 751901:tid 752157] [client 57.141.0.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuKayrT982lovRn7gnHQAAAAH4"]
[Thu Jul 30 12:31:24.051723 2026] [security2:error] [pid 751901:tid 752051] [client 40.77.167.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuKayrT982lovRn7gnHTQAAABQ"]
[Thu Jul 30 12:31:24.146579 2026] [core:notice] [pid 751901:tid 752033] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:24.151483 2026] [security2:error] [pid 751901:tid 752033] [client 103.215.74.26:3030] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "746"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKbCrT982lovRn7gnHYAAAAAI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:24.402647 2026] [security2:error] [pid 751901:tid 752143] [client 20.215.191.139:7695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-includes/customize/about.php"] [unique_id "amuKbCrT982lovRn7gnHZQAAAHA"]
[Thu Jul 30 12:31:24.864202 2026] [core:notice] [pid 751901:tid 752074] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:24.868770 2026] [security2:error] [pid 751901:tid 752074] [client 103.215.74.26:3036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKbCrT982lovRn7gnHcgAAACs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:25.113523 2026] [core:notice] [pid 751901:tid 751978] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:25.602774 2026] [core:notice] [pid 751901:tid 752077] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:25.607201 2026] [security2:error] [pid 751901:tid 752077] [client 103.215.74.26:3040] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKbSrT982lovRn7gnHgwAAAC4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:25.736220 2026] [security2:error] [pid 751901:tid 752078] [client 2a03:2880:f800:24:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuKbSrT982lovRn7gnHewAAL0U"]
[Thu Jul 30 12:31:26.027222 2026] [security2:error] [pid 751901:tid 752084] [client 194.26.202.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "kbaagency.com"] [uri "/index.php"] [unique_id "amuKbSrT982lovRn7gnHjgAANVY"], referer: https://kbaagency.com/
[Thu Jul 30 12:31:26.225488 2026] [proxy:error] [pid 751901:tid 752002] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:31:26.225541 2026] [proxy_http:error] [pid 751901:tid 752002] [remote 74.7.244.29:48220] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:31:26.226112 2026] [proxy:error] [pid 751901:tid 752002] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:31:26.226157 2026] [proxy_http:error] [pid 751901:tid 752002] [remote 74.7.244.29:48220] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:31:26.246330 2026] [security2:error] [pid 751901:tid 752072] [client 20.215.191.139:31189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-includes.bak/html-api/about.php"] [unique_id "amuKbirT982lovRn7gnHnAAAACk"]
[Thu Jul 30 12:31:26.338227 2026] [core:notice] [pid 751901:tid 752033] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:26.344877 2026] [security2:error] [pid 751901:tid 752033] [client 103.215.74.26:3046] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKbirT982lovRn7gnHnQAAAAI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:26.788875 2026] [security2:error] [pid 751901:tid 752096] [client 216.73.216.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.investigations.worldofwhiskers.com"] [uri "/index.php"] [unique_id "amuKbSrT982lovRn7gnHkAAAQVk"]
[Thu Jul 30 12:31:27.070761 2026] [core:notice] [pid 751901:tid 752087] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:27.077504 2026] [security2:error] [pid 751901:tid 752087] [client 103.215.74.26:3056] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKbyrT982lovRn7gnHqwAAADg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:27.162371 2026] [security2:error] [pid 751901:tid 752050] [client 57.141.0.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuKbirT982lovRn7gnHoAAAABM"]
[Thu Jul 30 12:31:27.213276 2026] [security2:error] [pid 751901:tid 752085] [client 37.65.175.59:9624] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.eot"] [unique_id "amuKbyrT982lovRn7gnHrwAAADY"]
[Thu Jul 30 12:31:27.256927 2026] [security2:error] [pid 751901:tid 752089] [client 5.59.109.28:47654] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.woff"] [unique_id "amuKbyrT982lovRn7gnHswAAADo"]
[Thu Jul 30 12:31:27.400602 2026] [security2:error] [pid 751901:tid 752138] [client 81.34.140.222:46642] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.woff2"] [unique_id "amuKbyrT982lovRn7gnHtwAAAGs"]
[Thu Jul 30 12:31:27.411916 2026] [security2:error] [pid 751901:tid 752103] [client 92.40.176.6:57037] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.eot"] [unique_id "amuKbyrT982lovRn7gnHuAAAAEg"]
[Thu Jul 30 12:31:27.444939 2026] [security2:error] [pid 751901:tid 752109] [client 38.190.144.4:49532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKbyrT982lovRn7gnHuQAAAE4"]
[Thu Jul 30 12:31:27.445160 2026] [security2:error] [pid 751901:tid 752109] [client 38.190.144.4:49532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKbyrT982lovRn7gnHuQAAAE4"]
[Thu Jul 30 12:31:27.829521 2026] [core:notice] [pid 751901:tid 752063] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:27.837287 2026] [security2:error] [pid 751901:tid 752063] [client 103.215.74.26:3058] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKbyrT982lovRn7gnHxwAAACA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:28.123386 2026] [security2:error] [pid 751901:tid 752043] [client 40.77.167.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuKbyrT982lovRn7gnHwgAAAAw"]
[Thu Jul 30 12:31:28.175971 2026] [security2:error] [pid 751901:tid 752040] [client 24.57.181.146:42820] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.ttf"] [unique_id "amuKcCrT982lovRn7gnH0gAAAAk"]
[Thu Jul 30 12:31:28.435556 2026] [security2:error] [pid 751901:tid 752141] [client 20.215.191.139:42898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-includes/widgets/about.php"] [unique_id "amuKcCrT982lovRn7gnH4AAAAG4"]
[Thu Jul 30 12:31:28.555969 2026] [core:notice] [pid 751901:tid 752044] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:28.560027 2026] [security2:error] [pid 751901:tid 752044] [client 103.215.74.26:3068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "762"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKcCrT982lovRn7gnH4gAAAA0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:28.749095 2026] [security2:error] [pid 751901:tid 752042] [client 57.141.0.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuKcCrT982lovRn7gnH0QAAAAs"]
[Thu Jul 30 12:31:29.000188 2026] [core:notice] [pid 751901:tid 751912] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:29.297210 2026] [core:notice] [pid 751901:tid 752111] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:29.303809 2026] [security2:error] [pid 751901:tid 752111] [client 103.215.74.26:3078] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKcSrT982lovRn7gnICQAAAFA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:29.306323 2026] [security2:error] [pid 751901:tid 752102] [client 85.208.98.18:33752] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kendarikomputer.com"] [uri "/robots.txt"] [unique_id "amuKcSrT982lovRn7gnIDAAAAEc"]
[Thu Jul 30 12:31:29.306397 2026] [security2:error] [pid 751901:tid 752102] [client 85.208.98.18:33752] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.kendarikomputer.com"] [uri "/robots.txt"] [unique_id "amuKcSrT982lovRn7gnIDAAAAEc"]
[Thu Jul 30 12:31:29.600671 2026] [security2:error] [pid 751901:tid 752031] [client 57.141.0.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuKcSrT982lovRn7gnH9AAAAAA"]
[Thu Jul 30 12:31:29.604622 2026] [security2:error] [pid 751901:tid 752154] [client 119.73.97.132:29775] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuKcSrT982lovRn7gnICwAAewc"]
[Thu Jul 30 12:31:29.801355 2026] [security2:error] [pid 751901:tid 751935] [remote 40.77.167.2:30073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/agrijati/article/view/4847"] [unique_id "amuKcSrT982lovRn7gnIGgAASSE"]
[Thu Jul 30 12:31:29.888372 2026] [security2:error] [pid 751901:tid 752154] [client 119.73.97.132:29775] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuKcSrT982lovRn7gnIEwAAexw"]
[Thu Jul 30 12:31:30.054513 2026] [core:notice] [pid 751901:tid 751934] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:30.070687 2026] [core:notice] [pid 751901:tid 752115] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:30.074872 2026] [security2:error] [pid 751901:tid 752115] [client 103.215.74.26:3094] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "775"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKcirT982lovRn7gnILAAAAFQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:30.110124 2026] [security2:error] [pid 751901:tid 752151] [client 62.34.17.16:50392] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.eot"] [unique_id "amuKcirT982lovRn7gnILgAAAHg"]
[Thu Jul 30 12:31:30.360029 2026] [security2:error] [pid 751901:tid 752094] [client 62.34.88.147:18334] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.ttf"] [unique_id "amuKcirT982lovRn7gnINgAAAD8"]
[Thu Jul 30 12:31:30.417291 2026] [security2:error] [pid 751901:tid 752133] [client 57.141.0.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuKcSrT982lovRn7gnIIQAAAGY"]
[Thu Jul 30 12:31:30.432545 2026] [security2:error] [pid 751901:tid 752077] [client 119.73.97.132:29775] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuKcirT982lovRn7gnIMQAALhA"], referer: https://www.urwru.club/emm-elevate/?preview_id=685&preview_nonce=6cdd8f071f&preview=true&aaeid=1
[Thu Jul 30 12:31:30.800826 2026] [core:notice] [pid 751901:tid 752142] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:30.805517 2026] [security2:error] [pid 751901:tid 752142] [client 103.215.74.26:3106] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "745"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKcirT982lovRn7gnIQQAAAG8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:31.010915 2026] [security2:error] [pid 751901:tid 752129] [client 216.73.216.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.investigations.worldofwhiskers.com"] [uri "/index.php"] [unique_id "amuKcirT982lovRn7gnISAAAYik"]
[Thu Jul 30 12:31:31.177750 2026] [security2:error] [pid 751901:tid 752124] [client 78.197.69.176:33932] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.ttf"] [unique_id "amuKcyrT982lovRn7gnITAAAAF0"]
[Thu Jul 30 12:31:31.217060 2026] [security2:error] [pid 751901:tid 752075] [client 31.111.178.5:38782] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.eot"] [unique_id "amuKcyrT982lovRn7gnITgAAACw"]
[Thu Jul 30 12:31:31.541609 2026] [core:notice] [pid 751901:tid 752065] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:31.545562 2026] [security2:error] [pid 751901:tid 752065] [client 103.215.74.26:3114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKcyrT982lovRn7gnIWwAAACI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:31.648414 2026] [security2:error] [pid 751901:tid 752115] [client 139.28.219.70:59822] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nobleinternationals.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuKcyrT982lovRn7gnIXAAAAFQ"]
[Thu Jul 30 12:31:31.833264 2026] [security2:error] [pid 751901:tid 752155] [client 85.86.58.213:51149] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.woff"] [unique_id "amuKcyrT982lovRn7gnIXQAAAHw"]
[Thu Jul 30 12:31:31.912814 2026] [security2:error] [pid 751901:tid 752153] [client 170.246.191.69:16883] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.eot"] [unique_id "amuKcyrT982lovRn7gnIYgAAAHo"]
[Thu Jul 30 12:31:32.065462 2026] [security2:error] [pid 751901:tid 752092] [client 95.27.206.97:2651] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.eot"] [unique_id "amuKdCrT982lovRn7gnIbgAAAD0"]
[Thu Jul 30 12:31:32.149363 2026] [security2:error] [pid 751901:tid 752112] [client 89.29.175.168:40730] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.eot"] [unique_id "amuKdCrT982lovRn7gnIbwAAAFE"]
[Thu Jul 30 12:31:32.205219 2026] [security2:error] [pid 751901:tid 752077] [client 139.28.219.70:59832] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nobleinternationals.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuKdCrT982lovRn7gnIcQAAAC4"]
[Thu Jul 30 12:31:32.298998 2026] [core:notice] [pid 751901:tid 752156] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:32.303208 2026] [security2:error] [pid 751901:tid 752156] [client 103.215.74.26:3124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKdCrT982lovRn7gnIcgAAAH0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:32.521030 2026] [security2:error] [pid 751901:tid 752032] [client 139.28.219.70:59848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nobleinternationals.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuKdCrT982lovRn7gnIegAAAAE"]
[Thu Jul 30 12:31:32.554052 2026] [security2:error] [pid 751901:tid 752081] [client 2a03:2880:f800:2d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuKcyrT982lovRn7gnIZQAAMjA"]
[Thu Jul 30 12:31:32.854245 2026] [security2:error] [pid 751901:tid 752129] [client 139.28.219.70:59864] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nobleinternationals.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuKdCrT982lovRn7gnIfgAAAGI"]
[Thu Jul 30 12:31:32.951431 2026] [security2:error] [pid 751901:tid 752033] [client 20.215.191.139:7027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-includes/IXR/about.php"] [unique_id "amuKdCrT982lovRn7gnIgwAAAAI"]
[Thu Jul 30 12:31:33.127193 2026] [security2:error] [pid 751901:tid 752075] [client 139.28.219.70:59876] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nobleinternationals.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuKdSrT982lovRn7gnIhwAAACw"]
[Thu Jul 30 12:31:33.399699 2026] [security2:error] [pid 751901:tid 752135] [client 139.28.219.70:59884] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nobleinternationals.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuKdSrT982lovRn7gnIjwAAAGg"]
[Thu Jul 30 12:31:33.713916 2026] [security2:error] [pid 751901:tid 752157] [client 139.28.219.70:59890] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nobleinternationals.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuKdSrT982lovRn7gnImgAAAH4"]
[Thu Jul 30 12:31:33.989686 2026] [security2:error] [pid 751901:tid 752036] [client 139.28.219.70:59892] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nobleinternationals.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuKdSrT982lovRn7gnIoAAAAAU"]
[Thu Jul 30 12:31:34.060430 2026] [security2:error] [pid 751901:tid 752071] [client 69.51.242.122:59674] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.ttf"] [unique_id "amuKdirT982lovRn7gnIogAAACg"]
[Thu Jul 30 12:31:34.124344 2026] [security2:error] [pid 751901:tid 752057] [client 99.246.175.62:40882] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.eot"] [unique_id "amuKdirT982lovRn7gnIpgAAABo"]
[Thu Jul 30 12:31:34.254905 2026] [security2:error] [pid 751901:tid 752098] [client 139.28.219.70:59896] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nobleinternationals.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuKdirT982lovRn7gnIqgAAAEM"]
[Thu Jul 30 12:31:34.525774 2026] [security2:error] [pid 751901:tid 752114] [client 139.28.219.70:59904] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nobleinternationals.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuKdirT982lovRn7gnIsAAAAFM"]
[Thu Jul 30 12:31:34.706170 2026] [security2:error] [pid 751901:tid 752038] [client 20.215.191.139:7174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-admin/js/about.php"] [unique_id "amuKdirT982lovRn7gnIuAAAAAc"]
[Thu Jul 30 12:31:34.793055 2026] [security2:error] [pid 751901:tid 752033] [client 139.28.219.70:59918] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nobleinternationals.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuKdirT982lovRn7gnIuQAAAAI"]
[Thu Jul 30 12:31:35.138003 2026] [security2:error] [pid 751901:tid 752131] [client 139.28.219.70:59922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nobleinternationals.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuKdyrT982lovRn7gnIxgAAAGQ"]
[Thu Jul 30 12:31:35.407392 2026] [security2:error] [pid 751901:tid 752031] [client 139.28.219.70:59936] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nobleinternationals.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuKdyrT982lovRn7gnIzAAAAAA"]
[Thu Jul 30 12:31:35.680523 2026] [security2:error] [pid 751901:tid 752117] [client 139.28.219.70:59948] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nobleinternationals.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuKdyrT982lovRn7gnI0AAAAFY"]
[Thu Jul 30 12:31:35.839529 2026] [security2:error] [pid 751901:tid 752108] [client 20.215.191.139:10789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amuKdyrT982lovRn7gnI2gAAAE0"]
[Thu Jul 30 12:31:35.946511 2026] [security2:error] [pid 751901:tid 752119] [client 139.28.219.70:59954] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nobleinternationals.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuKdyrT982lovRn7gnI2wAAAFg"]
[Thu Jul 30 12:31:35.988547 2026] [security2:error] [pid 751901:tid 751989] [remote 74.7.241.59:32932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuKdyrT982lovRn7gnI3AAAHlc"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/forms/actions
[Thu Jul 30 12:31:36.212920 2026] [security2:error] [pid 751901:tid 752126] [client 139.28.219.70:59970] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nobleinternationals.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuKeCrT982lovRn7gnI4wAAAF8"]
[Thu Jul 30 12:31:36.485480 2026] [security2:error] [pid 751901:tid 752033] [client 139.28.219.70:59974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nobleinternationals.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuKeCrT982lovRn7gnI5wAAAAI"]
[Thu Jul 30 12:31:36.706673 2026] [security2:error] [pid 751901:tid 752146] [client 20.215.191.139:42940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-includes/pomo/about.php"] [unique_id "amuKeCrT982lovRn7gnI6wAAAHM"]
[Thu Jul 30 12:31:37.332278 2026] [security2:error] [pid 751901:tid 752095] [client 20.215.191.139:13105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-includes/block-patterns/about.php"] [unique_id "amuKeSrT982lovRn7gnI_AAAAEA"]
[Thu Jul 30 12:31:38.030663 2026] [core:notice] [pid 751901:tid 752112] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:38.036079 2026] [security2:error] [pid 751901:tid 752112] [client 103.215.74.26:57650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKeirT982lovRn7gnJCwAAAFE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:38.248913 2026] [security2:error] [pid 751901:tid 752106] [client 38.190.144.4:34883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKeirT982lovRn7gnJDwAAAEs"]
[Thu Jul 30 12:31:38.249048 2026] [security2:error] [pid 751901:tid 752106] [client 38.190.144.4:34883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKeirT982lovRn7gnJDwAAAEs"]
[Thu Jul 30 12:31:38.281271 2026] [security2:error] [pid 751901:tid 752061] [client 91.92.41.115:56202] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "mail.azureskyfilms.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuKeirT982lovRn7gnJEQAAAB4"]
[Thu Jul 30 12:31:38.758161 2026] [core:notice] [pid 751901:tid 752034] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:38.762203 2026] [security2:error] [pid 751901:tid 752034] [client 103.215.74.26:57658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKeirT982lovRn7gnJGgAAAAM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:38.903702 2026] [security2:error] [pid 751901:tid 752136] [client 20.215.191.139:42939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/updraft/about.php"] [unique_id "amuKeirT982lovRn7gnJIQAAAGk"]
[Thu Jul 30 12:31:39.497306 2026] [core:notice] [pid 751901:tid 752147] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:39.501327 2026] [security2:error] [pid 751901:tid 752147] [client 103.215.74.26:57666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKeyrT982lovRn7gnJLAAAAHQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:39.620602 2026] [security2:error] [pid 751901:tid 752004] [remote 69.57.172.212:54840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.172.57.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emmelevate.club"] [uri "/wp-login.php"] [unique_id "amuKeyrT982lovRn7gnJKAAAMWY"]
[Thu Jul 30 12:31:39.626431 2026] [core:notice] [pid 751901:tid 752065] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:40.017414 2026] [core:notice] [pid 751901:tid 752153] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:40.225864 2026] [core:notice] [pid 751901:tid 752088] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:40.230340 2026] [security2:error] [pid 751901:tid 752088] [client 103.215.74.26:57678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKfCrT982lovRn7gnJOQAAADk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:40.251148 2026] [core:notice] [pid 751901:tid 752129] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:40.399892 2026] [core:notice] [pid 751901:tid 752092] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:40.656860 2026] [core:notice] [pid 751901:tid 752122] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:40.941879 2026] [core:notice] [pid 751901:tid 752094] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:40.946198 2026] [security2:error] [pid 751901:tid 752094] [client 103.215.74.26:57682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKfCrT982lovRn7gnJTwAAAD8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:41.529476 2026] [security2:error] [pid 751901:tid 752091] [client 20.215.191.139:42891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "amuKfSrT982lovRn7gnJXQAAADw"]
[Thu Jul 30 12:31:41.686458 2026] [core:notice] [pid 751901:tid 752084] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:41.694694 2026] [security2:error] [pid 751901:tid 752084] [client 103.215.74.26:57694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKfSrT982lovRn7gnJXgAAADU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:42.081367 2026] [security2:error] [pid 751901:tid 752082] [client 20.215.191.139:12159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/themes/about.php"] [unique_id "amuKfirT982lovRn7gnJbAAAADM"]
[Thu Jul 30 12:31:42.766529 2026] [security2:error] [pid 751901:tid 752054] [client 51.77.211.229:32932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.211.77.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/board.php"] [unique_id "amuKfirT982lovRn7gnJeQAAABc"]
[Thu Jul 30 12:31:43.384857 2026] [security2:error] [pid 751901:tid 752062] [client 20.215.191.139:2839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-admin/includes/about.php"] [unique_id "amuKfyrT982lovRn7gnJiAAAAB8"]
[Thu Jul 30 12:31:43.653122 2026] [security2:error] [pid 751901:tid 752117] [client 141.95.54.132:51836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.54.95.141.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/board.php"] [unique_id "amuKfyrT982lovRn7gnJiQAAAFY"]
[Thu Jul 30 12:31:43.819093 2026] [security2:error] [pid 751901:tid 752061] [client 84.54.44.19:54554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.44.54.84.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/email-now.php"] [unique_id "amuKfyrT982lovRn7gnJlAAAAB4"], referer: http://arabiandubaisafari.com/contact.html
[Thu Jul 30 12:31:44.123599 2026] [security2:error] [pid 751901:tid 752144] [client 20.215.191.139:4022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/images/about.php"] [unique_id "amuKgCrT982lovRn7gnJnAAAAHE"]
[Thu Jul 30 12:31:44.756949 2026] [security2:error] [pid 751901:tid 752070] [client 20.215.191.139:6366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/blogs.dir/about.php"] [unique_id "amuKgCrT982lovRn7gnJqAAAACc"]
[Thu Jul 30 12:31:44.876173 2026] [security2:error] [pid 751901:tid 751928] [remote 74.7.241.60:49996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/js/article.php"] [unique_id "amuKgCrT982lovRn7gnJqQAAGRo"], referer: https://aded-rdc.org/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/js/bootstrap.bundle.min.js
[Thu Jul 30 12:31:45.115261 2026] [security2:error] [pid 751901:tid 752073] [client 151.80.133.238:58992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.133.80.151.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/board.php"] [unique_id "amuKgSrT982lovRn7gnJsAAAACo"]
[Thu Jul 30 12:31:45.528757 2026] [core:notice] [pid 751901:tid 752087] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:45.786334 2026] [security2:error] [pid 751901:tid 752054] [client 50.16.216.166:10945] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "sellvia.womenclothingbox.com"] [uri "/"] [unique_id "amuKgSrT982lovRn7gnJxAAAABc"]
[Thu Jul 30 12:31:45.856085 2026] [security2:error] [pid 751901:tid 752080] [client 51.75.24.242:57768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.24.75.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/board.php"] [unique_id "amuKgSrT982lovRn7gnJugAAADE"]
[Thu Jul 30 12:31:45.880205 2026] [security2:error] [pid 751901:tid 752050] [client 20.215.191.139:2851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-includes/images/about.php"] [unique_id "amuKgSrT982lovRn7gnJxQAAABM"]
[Thu Jul 30 12:31:46.242539 2026] [core:notice] [pid 751901:tid 752047] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:46.553458 2026] [security2:error] [pid 751901:tid 752158] [client 20.215.191.139:6352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-includes/about.php"] [unique_id "amuKgirT982lovRn7gnJ1wAAAH8"]
[Thu Jul 30 12:31:47.307940 2026] [security2:error] [pid 751901:tid 752093] [client 20.215.191.139:6775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/cgi-bin/about.php"] [unique_id "amuKgyrT982lovRn7gnJ6QAAAD4"]
[Thu Jul 30 12:31:47.315151 2026] [security2:error] [pid 751901:tid 752108] [client 185.191.171.12:57502] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2021/04/22/covid-brasil-registra-2-027-mortes-e-45-178-novos-casos-em-24-horas/"] [unique_id "amuKgyrT982lovRn7gnJ6gAAAE0"]
[Thu Jul 30 12:31:47.315289 2026] [security2:error] [pid 751901:tid 752108] [client 185.191.171.12:57502] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2021/04/22/covid-brasil-registra-2-027-mortes-e-45-178-novos-casos-em-24-horas/"] [unique_id "amuKgyrT982lovRn7gnJ6gAAAE0"]
[Thu Jul 30 12:31:47.418303 2026] [core:notice] [pid 751901:tid 752139] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:47.422721 2026] [security2:error] [pid 751901:tid 752139] [client 103.215.74.26:57550] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKgyrT982lovRn7gnJ7gAAAGw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:47.680600 2026] [security2:error] [pid 751901:tid 752032] [client 2a03:2880:f800:19:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuKgyrT982lovRn7gnJ4gAAATQ"]
[Thu Jul 30 12:31:48.131637 2026] [core:notice] [pid 751901:tid 752095] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:48.136357 2026] [security2:error] [pid 751901:tid 752095] [client 103.215.74.26:57564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKhCrT982lovRn7gnJ_gAAAEA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:48.435169 2026] [security2:error] [pid 751901:tid 752074] [client 20.215.191.139:11624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/gallery/about.php"] [unique_id "amuKhCrT982lovRn7gnKCAAAACs"]
[Thu Jul 30 12:31:48.886618 2026] [core:notice] [pid 751901:tid 752062] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:48.890801 2026] [security2:error] [pid 751901:tid 752062] [client 103.215.74.26:57588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKhCrT982lovRn7gnKEQAAAB8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:48.995837 2026] [security2:error] [pid 751901:tid 752068] [client 149.202.51.38:56682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.51.202.149.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/login.php"] [unique_id "amuKhCrT982lovRn7gnKDQAAACU"]
[Thu Jul 30 12:31:49.578352 2026] [security2:error] [pid 751901:tid 752117] [client 20.215.191.139:6379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuKhSrT982lovRn7gnKJQAAAFY"]
[Thu Jul 30 12:31:49.626780 2026] [core:notice] [pid 751901:tid 752052] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:49.631203 2026] [security2:error] [pid 751901:tid 752052] [client 103.215.74.26:57616] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKhSrT982lovRn7gnKJgAAABU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:49.741633 2026] [security2:error] [pid 751901:tid 752119] [client 57.141.0.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuKhSrT982lovRn7gnKFwAAAFg"]
[Thu Jul 30 12:31:49.954089 2026] [security2:error] [pid 751901:tid 752155] [client 38.190.144.4:50548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKhSrT982lovRn7gnKLQAAAHw"]
[Thu Jul 30 12:31:49.954205 2026] [security2:error] [pid 751901:tid 752155] [client 38.190.144.4:50548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKhSrT982lovRn7gnKLQAAAHw"]
[Thu Jul 30 12:31:50.159272 2026] [security2:error] [pid 751901:tid 752101] [client 2a03:2880:f800:31:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuKhSrT982lovRn7gnKJAAARjI"]
[Thu Jul 30 12:31:50.376416 2026] [core:notice] [pid 751901:tid 752044] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:50.384813 2026] [security2:error] [pid 751901:tid 752044] [client 103.215.74.26:57648] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKhirT982lovRn7gnKNgAAAA0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:50.940381 2026] [security2:error] [pid 751901:tid 752055] [client 185.191.171.12:53350] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2023/01/02/lula-assume-com-o-apoio-de-11-governadores-e-oposicao-de-14/"] [unique_id "amuKhirT982lovRn7gnKRgAAABg"]
[Thu Jul 30 12:31:50.940556 2026] [security2:error] [pid 751901:tid 752055] [client 185.191.171.12:53350] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2023/01/02/lula-assume-com-o-apoio-de-11-governadores-e-oposicao-de-14/"] [unique_id "amuKhirT982lovRn7gnKRgAAABg"]
[Thu Jul 30 12:31:51.004284 2026] [security2:error] [pid 751901:tid 751940] [remote 57.141.0.61:25428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/610298834/feed/rss2/"] [unique_id "amuKhyrT982lovRn7gnKRwAAYCY"]
[Thu Jul 30 12:31:51.131703 2026] [core:notice] [pid 751901:tid 752077] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:51.136120 2026] [security2:error] [pid 751901:tid 752077] [client 103.215.74.26:57672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKhyrT982lovRn7gnKSAAAAC4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:51.865877 2026] [core:notice] [pid 751901:tid 752106] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:51.870989 2026] [security2:error] [pid 751901:tid 752106] [client 103.215.74.26:57678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKhyrT982lovRn7gnKVQAAAEs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:52.579802 2026] [core:notice] [pid 751901:tid 752052] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:52.583775 2026] [security2:error] [pid 751901:tid 752052] [client 103.215.74.26:57690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "746"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKiCrT982lovRn7gnKYwAAABU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:52.920457 2026] [security2:error] [pid 751901:tid 752070] [client 20.215.191.139:4770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-admin/css/about.php"] [unique_id "amuKiCrT982lovRn7gnKZAAAACc"]
[Thu Jul 30 12:31:53.319926 2026] [core:notice] [pid 751901:tid 752131] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:53.326435 2026] [security2:error] [pid 751901:tid 752131] [client 103.215.74.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKiSrT982lovRn7gnKcQAAAGQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:53.745352 2026] [core:error] [pid 751901:tid 752080] [client 158.173.25.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://appliancerepairservice.one/
[Thu Jul 30 12:31:53.745375 2026] [core:error] [pid 751901:tid 752080] [client 158.173.25.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://appliancerepairservice.one/
[Thu Jul 30 12:31:53.841453 2026] [core:notice] [pid 751901:tid 752050] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:53.927298 2026] [security2:error] [pid 751901:tid 752095] [client 20.215.191.139:3265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-admin/images/about.php"] [unique_id "amuKiSrT982lovRn7gnKfQAAAEA"]
[Thu Jul 30 12:31:54.065337 2026] [core:notice] [pid 751901:tid 752151] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:54.070562 2026] [security2:error] [pid 751901:tid 752151] [client 103.215.74.26:38314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKiirT982lovRn7gnKhAAAAHg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:54.630413 2026] [security2:error] [pid 751901:tid 751994] [remote 57.141.0.49:32368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amuKiirT982lovRn7gnKlAAAVlw"]
[Thu Jul 30 12:31:54.745632 2026] [security2:error] [pid 751901:tid 751942] [remote 8.217.108.67:62888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ylw.gpl.temporary.site"] [uri "/wp-login.php"] [unique_id "amuKiirT982lovRn7gnKlQAAFCg"]
[Thu Jul 30 12:31:54.795673 2026] [core:notice] [pid 751901:tid 752089] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:54.803257 2026] [security2:error] [pid 751901:tid 752089] [client 103.215.74.26:38346] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKiirT982lovRn7gnKlgAAADo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:56.447737 2026] [security2:error] [pid 751901:tid 752060] [client 20.215.191.139:4328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/.well-known/pki-validation/cloud.php"] [unique_id "amuKjCrT982lovRn7gnKvAAAAB0"]
[Thu Jul 30 12:31:57.446926 2026] [security2:error] [pid 751901:tid 752064] [client 57.141.0.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuKjCrT982lovRn7gnK1AAAACE"]
[Thu Jul 30 12:31:57.864060 2026] [security2:error] [pid 751901:tid 752072] [client 20.215.191.139:4739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/.well-known/acme-challenge/cloud.php"] [unique_id "amuKjSrT982lovRn7gnK6gAAACk"]
[Thu Jul 30 12:31:59.577480 2026] [security2:error] [pid 751901:tid 752061] [client 172.237.109.114:34523] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKjirT982lovRn7gnK_wAAAB4"]
[Thu Jul 30 12:31:59.579494 2026] [security2:error] [pid 751901:tid 752156] [client 172.237.109.114:50976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKjirT982lovRn7gnK_gAAAH0"]
[Thu Jul 30 12:31:59.660608 2026] [security2:error] [pid 751901:tid 752118] [client 20.215.191.139:2551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-admin/network/cloud.php"] [unique_id "amuKjyrT982lovRn7gnLDgAAAFc"]
[Thu Jul 30 12:32:00.408654 2026] [security2:error] [pid 751901:tid 752076] [client 2a03:2880:f800:2a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuKjyrT982lovRn7gnLBQAALXw"]
[Thu Jul 30 12:32:00.534740 2026] [core:notice] [pid 751901:tid 752065] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:00.543086 2026] [security2:error] [pid 751901:tid 752065] [client 103.215.74.26:38364] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKkCrT982lovRn7gnLKgAAACI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:00.547187 2026] [security2:error] [pid 751901:tid 752047] [client 172.237.109.114:4640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKjyrT982lovRn7gnLGAAAABA"]
[Thu Jul 30 12:32:00.548044 2026] [security2:error] [pid 751901:tid 752086] [client 172.237.109.114:5397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKjyrT982lovRn7gnLFwAAADc"]
[Thu Jul 30 12:32:00.557942 2026] [security2:error] [pid 751901:tid 752093] [client 172.237.109.114:32149] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKjyrT982lovRn7gnLGwAAAD4"]
[Thu Jul 30 12:32:00.580254 2026] [security2:error] [pid 751901:tid 752145] [client 172.237.109.114:48753] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKjyrT982lovRn7gnLGQAAAHI"]
[Thu Jul 30 12:32:00.651013 2026] [security2:error] [pid 751901:tid 752155] [client 172.237.109.114:55284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKjyrT982lovRn7gnLHgAAAHw"]
[Thu Jul 30 12:32:00.662871 2026] [security2:error] [pid 751901:tid 752154] [client 172.237.109.114:41622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkCrT982lovRn7gnLIQAAAHs"]
[Thu Jul 30 12:32:00.664390 2026] [security2:error] [pid 751901:tid 752067] [client 172.237.109.114:40387] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkCrT982lovRn7gnLHwAAACQ"]
[Thu Jul 30 12:32:00.682009 2026] [security2:error] [pid 751901:tid 752038] [client 172.237.109.114:17730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkCrT982lovRn7gnLIAAAAAc"]
[Thu Jul 30 12:32:00.990429 2026] [security2:error] [pid 751901:tid 752045] [client 20.215.191.139:3288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/cloud.php"] [unique_id "amuKkCrT982lovRn7gnLNwAAAA4"]
[Thu Jul 30 12:32:01.285100 2026] [core:notice] [pid 751901:tid 752062] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:01.295514 2026] [security2:error] [pid 751901:tid 752062] [client 103.215.74.26:38376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKkSrT982lovRn7gnLTwAAAB8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:01.933835 2026] [security2:error] [pid 751901:tid 752098] [client 20.215.191.139:13379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/cgi-bin/cloud.php"] [unique_id "amuKkSrT982lovRn7gnLWgAAAEM"]
[Thu Jul 30 12:32:02.126248 2026] [core:error] [pid 751901:tid 752103] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:32:02.126270 2026] [core:error] [pid 751901:tid 752103] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:32:02.152387 2026] [core:error] [pid 751901:tid 752093] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:32:02.152406 2026] [core:error] [pid 751901:tid 752093] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:32:02.179461 2026] [core:error] [pid 751901:tid 752153] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:32:02.179487 2026] [core:error] [pid 751901:tid 752153] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:32:02.401372 2026] [security2:error] [pid 751901:tid 752074] [client 172.237.109.114:10633] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLPQAAACs"]
[Thu Jul 30 12:32:02.401502 2026] [security2:error] [pid 751901:tid 752111] [client 172.237.109.114:4743] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLQgAAAFA"]
[Thu Jul 30 12:32:02.443710 2026] [security2:error] [pid 751901:tid 752151] [client 172.237.109.114:64980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLPgAAAHg"]
[Thu Jul 30 12:32:02.490889 2026] [security2:error] [pid 751901:tid 752077] [client 172.237.109.114:33682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLQAAAAC4"]
[Thu Jul 30 12:32:02.510010 2026] [security2:error] [pid 751901:tid 752121] [client 172.237.109.114:22972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLPAAAAFo"]
[Thu Jul 30 12:32:02.533808 2026] [security2:error] [pid 751901:tid 752083] [client 172.237.109.114:1682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLQQAAADQ"]
[Thu Jul 30 12:32:02.546677 2026] [security2:error] [pid 751901:tid 752031] [client 172.237.109.114:3414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLQwAAAAA"]
[Thu Jul 30 12:32:02.572522 2026] [security2:error] [pid 751901:tid 752058] [client 172.237.109.114:35357] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLSAAAABs"]
[Thu Jul 30 12:32:02.589391 2026] [security2:error] [pid 751901:tid 752055] [client 172.237.109.114:47522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLOwAAABg"]
[Thu Jul 30 12:32:02.719937 2026] [security2:error] [pid 751901:tid 752140] [client 20.215.191.139:6912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/updates.php"] [unique_id "amuKkirT982lovRn7gnLewAAAG0"]
[Thu Jul 30 12:32:03.024344 2026] [security2:error] [pid 751901:tid 752087] [client 38.190.144.4:51051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKkyrT982lovRn7gnLfgAAADg"]
[Thu Jul 30 12:32:03.024474 2026] [security2:error] [pid 751901:tid 752087] [client 38.190.144.4:51051] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKkyrT982lovRn7gnLfgAAADg"]
[Thu Jul 30 12:32:03.216665 2026] [security2:error] [pid 751901:tid 752144] [client 172.237.109.114:2186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLSQAAAHE"]
[Thu Jul 30 12:32:03.218054 2026] [security2:error] [pid 751901:tid 752068] [client 172.237.109.114:23207] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLRgAAACU"]
[Thu Jul 30 12:32:03.231342 2026] [security2:error] [pid 751901:tid 752130] [client 172.237.109.114:15582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLRQAAAGM"]
[Thu Jul 30 12:32:03.234592 2026] [security2:error] [pid 751901:tid 752060] [client 172.237.109.114:9835] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLPwAAAB0"]
[Thu Jul 30 12:32:03.256882 2026] [security2:error] [pid 751901:tid 752059] [client 172.237.109.114:53673] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLSwAAABw"]
[Thu Jul 30 12:32:03.268364 2026] [security2:error] [pid 751901:tid 752137] [client 172.237.109.114:13190] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLTQAAAGo"]
[Thu Jul 30 12:32:03.269698 2026] [security2:error] [pid 751901:tid 752113] [client 172.237.109.114:65312] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLTgAAAFI"]
[Thu Jul 30 12:32:03.271827 2026] [security2:error] [pid 751901:tid 752071] [client 172.237.109.114:50525] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLRwAAACg"]
[Thu Jul 30 12:32:03.287238 2026] [security2:error] [pid 751901:tid 752158] [client 172.237.109.114:64426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLSgAAAH8"]
[Thu Jul 30 12:32:03.287931 2026] [security2:error] [pid 751901:tid 752112] [client 172.237.109.114:51700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLRAAAAFE"]
[Thu Jul 30 12:32:03.320049 2026] [security2:error] [pid 751901:tid 752134] [client 172.237.109.114:61440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLTAAAAGc"]
[Thu Jul 30 12:32:03.968005 2026] [security2:error] [pid 751901:tid 752105] [client 20.215.191.139:14604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/css/cloud.php"] [unique_id "amuKkyrT982lovRn7gnLlgAAAEo"]
[Thu Jul 30 12:32:04.089404 2026] [security2:error] [pid 751901:tid 751953] [remote 57.141.0.26:57170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuKlCrT982lovRn7gnLmgAALzM"]
[Thu Jul 30 12:32:05.518341 2026] [security2:error] [pid 751901:tid 752097] [client 74.7.244.45:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-2f97271e.ear.djb.temporary.site"] [uri "/index.php"] [unique_id "amuKlSrT982lovRn7gnLuQAAAEI"]
[Thu Jul 30 12:32:05.519194 2026] [security2:error] [pid 751901:tid 752087] [client 74.7.244.45:48134] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-2f97271e.ear.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amuKlSrT982lovRn7gnLtwAAOD4"]
[Thu Jul 30 12:32:06.972146 2026] [security2:error] [pid 751901:tid 752095] [client 20.215.191.139:3545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-admin/user/cloud.php"] [unique_id "amuKlirT982lovRn7gnL5QAAAEA"]
[Thu Jul 30 12:32:07.083845 2026] [core:notice] [pid 751901:tid 752118] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:07.090745 2026] [security2:error] [pid 751901:tid 752118] [client 103.215.74.26:34184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "762"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKlyrT982lovRn7gnL5gAAAFc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:07.197103 2026] [core:notice] [pid 751901:tid 752046] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:07.841241 2026] [core:notice] [pid 751901:tid 752037] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:07.847453 2026] [security2:error] [pid 751901:tid 752037] [client 103.215.74.26:34186] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKlyrT982lovRn7gnMCAAAAAY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:08.574531 2026] [core:notice] [pid 751901:tid 752138] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:08.578635 2026] [security2:error] [pid 751901:tid 752138] [client 103.215.74.26:34198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "775"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKmCrT982lovRn7gnMGQAAAGs"], referer: https://carnetdeshopping.com/
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Thu Jul 30 12:32:09.311905 2026] [core:notice] [pid 751901:tid 752144] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:09.315793 2026] [security2:error] [pid 751901:tid 752144] [client 103.215.74.26:34204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKmSrT982lovRn7gnMPAAAAHE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:10.068053 2026] [core:notice] [pid 751901:tid 752074] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:10.071897 2026] [security2:error] [pid 751901:tid 752074] [client 103.215.74.26:34212] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKmirT982lovRn7gnMXgAAACs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:10.441420 2026] [security2:error] [pid 751901:tid 752017] [remote 97.74.87.194:55278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/wp-login.php"] [unique_id "amuKmirT982lovRn7gnMYQAAeHM"]
[Thu Jul 30 12:32:10.479455 2026] [security2:error] [pid 751901:tid 752125] [client 20.215.191.139:2521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/img/cloud.php"] [unique_id "amuKmirT982lovRn7gnMZwAAAF4"]
[Thu Jul 30 12:32:10.786673 2026] [core:notice] [pid 751901:tid 752045] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:10.790725 2026] [security2:error] [pid 751901:tid 752045] [client 103.215.74.26:34224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKmirT982lovRn7gnMcQAAAA4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:11.670452 2026] [security2:error] [pid 751901:tid 752150] [client 20.215.191.139:2542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "amuKmyrT982lovRn7gnMlwAAAHc"]
[Thu Jul 30 12:32:12.137116 2026] [security2:error] [pid 751901:tid 752033] [client 34.143.178.95:57810] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "dhowcruisedinner.com"] [uri "/"] [unique_id "amuKnCrT982lovRn7gnMqQAAAAI"]
[Thu Jul 30 12:32:13.559557 2026] [security2:error] [pid 751901:tid 752146] [client 20.215.191.139:14650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-admin/images/cloud.php"] [unique_id "amuKnSrT982lovRn7gnMwAAAAHM"]
[Thu Jul 30 12:32:14.772635 2026] [security2:error] [pid 751901:tid 752150] [client 20.215.191.139:13393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/avaa.php"] [unique_id "amuKnirT982lovRn7gnM5AAAAHc"]
[Thu Jul 30 12:32:15.863957 2026] [security2:error] [pid 751901:tid 752072] [client 20.215.191.139:4321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/images/cloud.php"] [unique_id "amuKnyrT982lovRn7gnM-AAAACk"]
[Thu Jul 30 12:32:15.943110 2026] [security2:error] [pid 751901:tid 752046] [client 109.172.91.206:57096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.91.172.109.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supreme-hydraulics.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuKnyrT982lovRn7gnM_AAAAA8"], referer: https://supreme-hydraulics.com/contact/
[Thu Jul 30 12:32:16.517643 2026] [core:notice] [pid 751901:tid 752036] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:16.522211 2026] [security2:error] [pid 751901:tid 752036] [client 103.215.74.26:21624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKoCrT982lovRn7gnNKgAAAAU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:17.167434 2026] [security2:error] [pid 751901:tid 752091] [client 94.154.43.179:37516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "online-hope.com"] [uri "/.env"] [unique_id "amuKoSrT982lovRn7gnNOgAAADw"]
[Thu Jul 30 12:32:17.234715 2026] [core:notice] [pid 751901:tid 752142] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:17.238773 2026] [security2:error] [pid 751901:tid 752142] [client 103.215.74.26:21626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKoSrT982lovRn7gnNPAAAAG8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:17.597413 2026] [core:notice] [pid 751901:tid 752013] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:17.751309 2026] [core:notice] [pid 751901:tid 752016] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:17.870817 2026] [security2:error] [pid 751901:tid 752034] [client 20.215.191.139:8035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-admin/js/widgets/cloud.php"] [unique_id "amuKoSrT982lovRn7gnNUwAAAAM"]
[Thu Jul 30 12:32:17.982909 2026] [core:notice] [pid 751901:tid 752140] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:17.987035 2026] [security2:error] [pid 751901:tid 752140] [client 103.215.74.26:21656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKoSrT982lovRn7gnNWgAAAG0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:18.206377 2026] [proxy:error] [pid 751901:tid 752087] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:32:18.206463 2026] [proxy_http:error] [pid 751901:tid 752087] [client 143.244.57.82:52426] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:32:18.207035 2026] [proxy:error] [pid 751901:tid 752087] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:32:18.207079 2026] [proxy_http:error] [pid 751901:tid 752087] [client 143.244.57.82:52426] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:32:18.493650 2026] [proxy:error] [pid 751901:tid 752148] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:32:18.493729 2026] [proxy_http:error] [pid 751901:tid 752148] [client 143.244.57.82:52442] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:32:18.494316 2026] [proxy:error] [pid 751901:tid 752148] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:32:18.494360 2026] [proxy_http:error] [pid 751901:tid 752148] [client 143.244.57.82:52442] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:32:18.548777 2026] [security2:error] [pid 751901:tid 752101] [client 57.141.0.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuKoSrT982lovRn7gnNVgAAAEY"]
[Thu Jul 30 12:32:18.729965 2026] [core:notice] [pid 751901:tid 752077] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:18.737600 2026] [security2:error] [pid 751901:tid 752077] [client 103.215.74.26:21662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKoirT982lovRn7gnNbgAAAC4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:18.777800 2026] [security2:error] [pid 751901:tid 752128] [client 143.244.57.82:52450] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nuk.gzj.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuKoirT982lovRn7gnNbwAAAGE"]
[Thu Jul 30 12:32:19.051367 2026] [security2:error] [pid 751901:tid 752001] [remote 172.93.219.170:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.219.93.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "palmtreepools.ca"] [uri "/wp-login.php"] [unique_id "amuKoyrT982lovRn7gnNeAAAWWM"]
[Thu Jul 30 12:32:19.070854 2026] [security2:error] [pid 751901:tid 752094] [client 143.244.57.82:52452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.nuk.gzj.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuKoyrT982lovRn7gnNewAAAD8"]
[Thu Jul 30 12:32:19.357154 2026] [proxy:error] [pid 751901:tid 752045] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:32:19.357245 2026] [proxy_http:error] [pid 751901:tid 752045] [client 143.244.57.82:52468] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:32:19.357824 2026] [proxy:error] [pid 751901:tid 752045] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:32:19.357866 2026] [proxy_http:error] [pid 751901:tid 752045] [client 143.244.57.82:52468] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:32:19.450018 2026] [core:notice] [pid 751901:tid 752041] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:19.457399 2026] [security2:error] [pid 751901:tid 752041] [client 103.215.74.26:21674] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKoyrT982lovRn7gnNigAAAAo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:19.560468 2026] [security2:error] [pid 751901:tid 752115] [client 104.254.90.251:56348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.90.254.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuKoyrT982lovRn7gnNjwAAAFQ"]
[Thu Jul 30 12:32:19.560569 2026] [security2:error] [pid 751901:tid 752115] [client 104.254.90.251:56348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuKoyrT982lovRn7gnNjwAAAFQ"]
[Thu Jul 30 12:32:19.645400 2026] [security2:error] [pid 751901:tid 752153] [client 143.244.57.82:52482] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nuk.gzj.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuKoyrT982lovRn7gnNlAAAAHo"]
[Thu Jul 30 12:32:19.666989 2026] [security2:error] [pid 751901:tid 752034] [client 74.7.175.165:54172] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cpanel.ampere.us.cc"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amuKoyrT982lovRn7gnNlQAAAAM"]
[Thu Jul 30 12:32:19.883062 2026] [security2:error] [pid 751901:tid 752152] [client 20.215.191.139:33541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-includes/Requests/Text/admin.php"] [unique_id "amuKoyrT982lovRn7gnNmQAAAHk"]
[Thu Jul 30 12:32:19.935523 2026] [security2:error] [pid 751901:tid 752093] [client 143.244.57.82:52488] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nuk.gzj.temporary.site"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuKoyrT982lovRn7gnNmwAAAD4"]
[Thu Jul 30 12:32:20.180024 2026] [core:notice] [pid 751901:tid 752143] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:20.187507 2026] [security2:error] [pid 751901:tid 752143] [client 103.215.74.26:21684] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKpCrT982lovRn7gnNpAAAAHA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:20.217210 2026] [security2:error] [pid 751901:tid 752148] [client 143.244.57.82:52498] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nuk.gzj.temporary.site"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuKpCrT982lovRn7gnNpQAAAHU"]
[Thu Jul 30 12:32:20.498191 2026] [security2:error] [pid 751901:tid 752128] [client 143.244.57.82:52512] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nuk.gzj.temporary.site"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuKpCrT982lovRn7gnNrQAAAGE"]
[Thu Jul 30 12:32:20.774112 2026] [security2:error] [pid 751901:tid 752119] [client 143.244.57.82:52516] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nuk.gzj.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuKpCrT982lovRn7gnNswAAAFg"]
[Thu Jul 30 12:32:20.784987 2026] [security2:error] [pid 751901:tid 752050] [client 20.215.191.139:13553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "amuKpCrT982lovRn7gnNtAAAABM"]
[Thu Jul 30 12:32:20.940538 2026] [core:notice] [pid 751901:tid 752157] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:20.947473 2026] [security2:error] [pid 751901:tid 752157] [client 103.215.74.26:21688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKpCrT982lovRn7gnNugAAAH4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:21.058038 2026] [security2:error] [pid 751901:tid 752060] [client 143.244.57.82:52522] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nuk.gzj.temporary.site"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuKpSrT982lovRn7gnNvwAAAB0"]
[Thu Jul 30 12:32:21.340701 2026] [security2:error] [pid 751901:tid 752039] [client 143.244.57.82:52534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nuk.gzj.temporary.site"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuKpSrT982lovRn7gnNxQAAAAg"]
[Thu Jul 30 12:32:21.597236 2026] [security2:error] [pid 751901:tid 752113] [client 179.43.134.114:16478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.134.43.179.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-login.php"] [unique_id "amuKpSrT982lovRn7gnNxAAAAFI"]
[Thu Jul 30 12:32:21.616245 2026] [security2:error] [pid 751901:tid 752047] [client 143.244.57.82:52542] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nuk.gzj.temporary.site"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuKpSrT982lovRn7gnNzAAAABA"]
[Thu Jul 30 12:32:21.710161 2026] [core:notice] [pid 751901:tid 752122] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:21.714500 2026] [security2:error] [pid 751901:tid 752122] [client 103.215.74.26:21704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKpSrT982lovRn7gnN0AAAAFs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:21.895725 2026] [security2:error] [pid 751901:tid 752044] [client 143.244.57.82:52550] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nuk.gzj.temporary.site"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuKpSrT982lovRn7gnN0QAAAA0"]
[Thu Jul 30 12:32:22.108823 2026] [security2:error] [pid 751901:tid 752058] [client 20.215.191.139:9007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-admin/includes/cloud.php"] [unique_id "amuKpirT982lovRn7gnN2QAAABs"]
[Thu Jul 30 12:32:22.165801 2026] [security2:error] [pid 751901:tid 751914] [remote 216.73.216.152:41909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuKpirT982lovRn7gnN3wAAbAw"]
[Thu Jul 30 12:32:22.181481 2026] [security2:error] [pid 751901:tid 752101] [client 143.244.57.82:52552] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nuk.gzj.temporary.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuKpirT982lovRn7gnN4gAAAEY"]
[Thu Jul 30 12:32:22.449951 2026] [core:notice] [pid 751901:tid 752083] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:22.454421 2026] [security2:error] [pid 751901:tid 752083] [client 103.215.74.26:21710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKpirT982lovRn7gnN5wAAADQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:22.455949 2026] [security2:error] [pid 751901:tid 752067] [client 143.244.57.82:52554] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nuk.gzj.temporary.site"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuKpirT982lovRn7gnN6gAAACQ"]
[Thu Jul 30 12:32:22.644886 2026] [security2:error] [pid 751901:tid 752125] [client 179.43.134.114:16480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.134.43.179.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-login.php"] [unique_id "amuKpirT982lovRn7gnN8AAAAF4"], referer: https://saifalkhaleejest.com/wp-admin/
[Thu Jul 30 12:32:22.743521 2026] [security2:error] [pid 751901:tid 752069] [client 143.244.57.82:52570] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nuk.gzj.temporary.site"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuKpirT982lovRn7gnN9AAAACY"]
[Thu Jul 30 12:32:22.804642 2026] [security2:error] [pid 751901:tid 752050] [client 20.215.191.139:42611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-admin/css/colors/blue/cloud.php"] [unique_id "amuKpirT982lovRn7gnN9QAAABM"]
[Thu Jul 30 12:32:23.031523 2026] [security2:error] [pid 751901:tid 752136] [client 143.244.57.82:52580] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nuk.gzj.temporary.site"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuKpyrT982lovRn7gnN-wAAAGk"]
[Thu Jul 30 12:32:23.032840 2026] [security2:error] [pid 751901:tid 751931] [remote 57.141.0.70:36632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amuKpyrT982lovRn7gnN-gAAHB0"]
[Thu Jul 30 12:32:23.059124 2026] [security2:error] [pid 751901:tid 752070] [client 2a03:2880:f800:24:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuKpirT982lovRn7gnN6wAAJyU"]
[Thu Jul 30 12:32:23.195997 2026] [core:notice] [pid 751901:tid 752094] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:23.200366 2026] [security2:error] [pid 751901:tid 752094] [client 103.215.74.26:28232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKpyrT982lovRn7gnN_wAAAD8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:23.616167 2026] [security2:error] [pid 751901:tid 752037] [client 200.80.186.239:26718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuKoyrT982lovRn7gnNiwAAAAY"], referer: http://pkf.jo
[Thu Jul 30 12:32:23.865668 2026] [security2:error] [pid 751901:tid 752100] [client 24.115.81.177:35867] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuKoirT982lovRn7gnNbQAAAEU"], referer: http://pkf.jo
[Thu Jul 30 12:32:23.887763 2026] [security2:error] [pid 751901:tid 752127] [client 138.219.238.58:28941] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuKoyrT982lovRn7gnNggAAAGA"], referer: http://pkf.jo
[Thu Jul 30 12:32:23.933073 2026] [core:notice] [pid 751901:tid 752044] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:23.937680 2026] [security2:error] [pid 751901:tid 752044] [client 103.215.74.26:28248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKpyrT982lovRn7gnOEgAAAA0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:24.383244 2026] [security2:error] [pid 751901:tid 752057] [client 152.59.57.196:56264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuKpyrT982lovRn7gnOBwAAABo"], referer: http://pkf.jo
[Thu Jul 30 12:32:24.614738 2026] [core:notice] [pid 751901:tid 752138] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:24.667214 2026] [core:notice] [pid 751901:tid 752150] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:24.672287 2026] [security2:error] [pid 751901:tid 752150] [client 103.215.74.26:28260] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKqCrT982lovRn7gnOKQAAAHc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:24.712598 2026] [security2:error] [pid 751901:tid 752067] [client 118.194.233.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fnm.gzj.temporary.site"] [uri "/index.php"] [unique_id "amuKqCrT982lovRn7gnOHgAAACQ"]
[Thu Jul 30 12:32:24.900770 2026] [security2:error] [pid 751901:tid 752131] [client 20.215.191.139:48281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-admin/cloud.php"] [unique_id "amuKqCrT982lovRn7gnOPQAAAGQ"]
[Thu Jul 30 12:32:25.273850 2026] [security2:error] [pid 751901:tid 752081] [client 216.73.217.138:63115] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.upns.ca"] [uri "/index.php"] [unique_id "amuKqSrT982lovRn7gnOUAAAMlM"]
[Thu Jul 30 12:32:25.402241 2026] [core:notice] [pid 751901:tid 752073] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:25.406107 2026] [security2:error] [pid 751901:tid 752073] [client 103.215.74.26:28266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKqSrT982lovRn7gnOVgAAACo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:25.413203 2026] [security2:error] [pid 751901:tid 752069] [client 38.190.144.4:52060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKqSrT982lovRn7gnOVwAAACY"]
[Thu Jul 30 12:32:25.413301 2026] [security2:error] [pid 751901:tid 752069] [client 38.190.144.4:52060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKqSrT982lovRn7gnOVwAAACY"]
[Thu Jul 30 12:32:25.542937 2026] [security2:error] [pid 751901:tid 752110] [client 20.215.191.139:2562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/updates.php"] [unique_id "amuKqSrT982lovRn7gnOWAAAAE8"]
[Thu Jul 30 12:32:26.164012 2026] [core:notice] [pid 751901:tid 752087] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:26.168040 2026] [security2:error] [pid 751901:tid 752087] [client 103.215.74.26:28280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "745"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKqirT982lovRn7gnOagAAADg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:26.493141 2026] [security2:error] [pid 751901:tid 752079] [client 20.215.191.139:3542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/libraries/legacy/updates.php"] [unique_id "amuKqirT982lovRn7gnOdQAAADA"]
[Thu Jul 30 12:32:26.920263 2026] [core:notice] [pid 751901:tid 752128] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:26.925290 2026] [security2:error] [pid 751901:tid 752128] [client 103.215.74.26:28292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKqirT982lovRn7gnOhgAAAGE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:27.027357 2026] [security2:error] [pid 751901:tid 752097] [client 216.73.217.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.embassyofbelgiumislamabad.cc"] [uri "/index.php"] [unique_id "amuKqSrT982lovRn7gnOXAAAQkQ"]
[Thu Jul 30 12:32:29.020529 2026] [security2:error] [pid 751901:tid 752058] [client 20.215.191.139:11019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/libraries/phpmailer/updates.php"] [unique_id "amuKrSrT982lovRn7gnOtwAAABs"]
[Thu Jul 30 12:32:29.124562 2026] [autoindex:error] [pid 751901:tid 751908] [remote 45.33.110.19:53876] AH01276: Cannot serve directory /home1/tdunyxte/public_html/svcambodia/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:32:31.145219 2026] [security2:error] [pid 751901:tid 752086] [client 20.215.191.139:2191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/libraries/vendor/updates.php"] [unique_id "amuKryrT982lovRn7gnO9QAAADc"]
[Thu Jul 30 12:32:31.866338 2026] [security2:error] [pid 751901:tid 752126] [client 127.0.0.1:10468] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuKryrT982lovRn7gnPBAAAAF8"]
[Thu Jul 30 12:32:31.866363 2026] [security2:error] [pid 751901:tid 752054] [client 127.0.0.1:10458] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.lucky-strike-shop.com"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuKryrT982lovRn7gnPAwAAABc"]
[Thu Jul 30 12:32:31.866448 2026] [security2:error] [pid 751901:tid 752105] [client 74.7.244.28:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.lucky-strike-shop.com"] [uri "/robots.txt"] [unique_id "amuKryrT982lovRn7gnPAgAASiU"]
[Thu Jul 30 12:32:32.625965 2026] [security2:error] [pid 751901:tid 752128] [client 104.28.155.129:63883] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuKsCrT982lovRn7gnPFwAAAGE"], referer: http://pkf.jo
[Thu Jul 30 12:32:32.660153 2026] [core:notice] [pid 751901:tid 752059] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:32.667407 2026] [security2:error] [pid 751901:tid 752059] [client 103.215.74.26:28300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKsCrT982lovRn7gnPIgAAABw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:32.887663 2026] [security2:error] [pid 751901:tid 752120] [client 20.52.54.143:1606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.alshateealazraqtours.com"] [uri "/wp-login.php"] [unique_id "amuKsCrT982lovRn7gnPIQAAAFk"]
[Thu Jul 30 12:32:32.887809 2026] [security2:error] [pid 751901:tid 752120] [client 20.52.54.143:1606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.alshateealazraqtours.com"] [uri "/wp-login.php"] [unique_id "amuKsCrT982lovRn7gnPIQAAAFk"]
[Thu Jul 30 12:32:33.131089 2026] [security2:error] [pid 751901:tid 752074] [client 40.77.167.243:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.nafmedical.com"] [uri "/index.php"] [unique_id "amuKsCrT982lovRn7gnPJgAAKxQ"]
[Thu Jul 30 12:32:33.328226 2026] [core:error] [pid 751901:tid 752069] [client 66.249.68.33:40617] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:32:33.328250 2026] [core:error] [pid 751901:tid 752069] [client 66.249.68.33:40617] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:32:33.413880 2026] [core:notice] [pid 751901:tid 752122] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:33.420298 2026] [security2:error] [pid 751901:tid 752122] [client 103.215.74.26:18042] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKsSrT982lovRn7gnPMwAAAFs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:33.555280 2026] [core:notice] [pid 751901:tid 752143] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:33.647374 2026] [core:notice] [pid 751901:tid 752158] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:33.916538 2026] [security2:error] [pid 751901:tid 752087] [client 20.215.191.139:11354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/alfa-rex.php7"] [unique_id "amuKsSrT982lovRn7gnPTQAAADg"]
[Thu Jul 30 12:32:34.053095 2026] [core:notice] [pid 751901:tid 752056] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:34.187821 2026] [core:notice] [pid 751901:tid 752091] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:34.197528 2026] [security2:error] [pid 751901:tid 752091] [client 103.215.74.26:18052] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKsirT982lovRn7gnPWAAAADw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:34.507994 2026] [security2:error] [pid 751901:tid 752062] [client 57.141.0.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuKsSrT982lovRn7gnPTAAAAB8"]
[Thu Jul 30 12:32:34.917203 2026] [core:notice] [pid 751901:tid 752039] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:34.921228 2026] [security2:error] [pid 751901:tid 752039] [client 103.215.74.26:18064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKsirT982lovRn7gnPagAAAAg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:34.966299 2026] [security2:error] [pid 751901:tid 752046] [client 20.215.191.139:42573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/alfanew.php"] [unique_id "amuKsirT982lovRn7gnPawAAAA8"]
[Thu Jul 30 12:32:35.508183 2026] [security2:error] [pid 751901:tid 752143] [client 62.102.148.166:36886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuKsyrT982lovRn7gnPfAAAAHA"]
[Thu Jul 30 12:32:35.508317 2026] [security2:error] [pid 751901:tid 752143] [client 62.102.148.166:36886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuKsyrT982lovRn7gnPfAAAAHA"]
[Thu Jul 30 12:32:35.654282 2026] [core:notice] [pid 751901:tid 752058] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:35.658324 2026] [security2:error] [pid 751901:tid 752058] [client 103.215.74.26:18068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "761"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKsyrT982lovRn7gnPgwAAABs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:35.797018 2026] [security2:error] [pid 751901:tid 752048] [client 57.141.0.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuKsyrT982lovRn7gnPdQAAABE"]
[Thu Jul 30 12:32:36.159171 2026] [security2:error] [pid 751901:tid 752102] [client 20.215.191.139:61200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/plugins/Cache/Cache.php"] [unique_id "amuKtCrT982lovRn7gnPkAAAAEc"]
[Thu Jul 30 12:32:36.396206 2026] [core:notice] [pid 751901:tid 752112] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:36.404326 2026] [security2:error] [pid 751901:tid 752112] [client 103.215.74.26:18074] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKtCrT982lovRn7gnPlAAAAFE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:37.134910 2026] [core:notice] [pid 751901:tid 752043] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:37.138791 2026] [security2:error] [pid 751901:tid 752043] [client 103.215.74.26:18076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "774"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKtSrT982lovRn7gnPpgAAAAw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:37.476865 2026] [core:notice] [pid 751901:tid 752011] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:37.554522 2026] [security2:error] [pid 751901:tid 752156] [client 20.215.191.139:8058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-admin/js/widgets/about.php7"] [unique_id "amuKtSrT982lovRn7gnPrwAAAH0"]
[Thu Jul 30 12:32:37.722683 2026] [core:notice] [pid 751901:tid 752013] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:37.839590 2026] [security2:error] [pid 751901:tid 752019] [remote 40.77.167.2:30035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/euclid/article/download/9214/4037"] [unique_id "amuKtSrT982lovRn7gnPuQAAYHU"]
[Thu Jul 30 12:32:37.862261 2026] [core:notice] [pid 751901:tid 752051] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:37.866332 2026] [security2:error] [pid 751901:tid 752051] [client 103.215.74.26:18086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "746"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKtSrT982lovRn7gnPugAAABQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:38.599031 2026] [core:notice] [pid 751901:tid 752086] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:38.603136 2026] [security2:error] [pid 751901:tid 752086] [client 103.215.74.26:18100] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKtirT982lovRn7gnPygAAADc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:38.728911 2026] [security2:error] [pid 751901:tid 752146] [client 20.215.191.139:33090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-p.php7"] [unique_id "amuKtirT982lovRn7gnPzgAAAHM"]
[Thu Jul 30 12:32:39.191862 2026] [security2:error] [pid 751901:tid 752088] [client 54.87.112.51:46804] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuKtyrT982lovRn7gnP2AAAADk"], referer: https://globalmarks.pk/
[Thu Jul 30 12:32:39.331240 2026] [core:notice] [pid 751901:tid 752152] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:39.336682 2026] [security2:error] [pid 751901:tid 752152] [client 103.215.74.26:18112] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "756"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKtyrT982lovRn7gnP4AAAAHk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:40.009628 2026] [security2:error] [pid 751901:tid 752156] [client 20.215.191.139:11386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-admin/repeater.php"] [unique_id "amuKuCrT982lovRn7gnP6gAAAH0"]
[Thu Jul 30 12:32:40.054041 2026] [core:notice] [pid 751901:tid 752143] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:40.058475 2026] [security2:error] [pid 751901:tid 752143] [client 103.215.74.26:18116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKuCrT982lovRn7gnP6wAAAHA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:40.826743 2026] [core:notice] [pid 751901:tid 752096] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:40.830680 2026] [security2:error] [pid 751901:tid 752096] [client 103.215.74.26:18120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "745"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKuCrT982lovRn7gnP_AAAAEE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:41.037596 2026] [security2:error] [pid 751901:tid 752102] [client 20.215.191.139:42603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-includes/repeater.php"] [unique_id "amuKuSrT982lovRn7gnQAAAAAEc"]
[Thu Jul 30 12:32:41.386895 2026] [proxy:error] [pid 751901:tid 752071] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:32:41.386972 2026] [proxy_http:error] [pid 751901:tid 752071] [client 143.244.57.82:37676] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:32:41.387629 2026] [proxy:error] [pid 751901:tid 752071] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:32:41.387674 2026] [proxy_http:error] [pid 751901:tid 752071] [client 143.244.57.82:37676] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:32:41.568105 2026] [core:notice] [pid 751901:tid 752153] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:41.572115 2026] [security2:error] [pid 751901:tid 752153] [client 103.215.74.26:18132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "745"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKuSrT982lovRn7gnQDgAAAHo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:41.688942 2026] [proxy:error] [pid 751901:tid 752093] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:32:41.689028 2026] [proxy_http:error] [pid 751901:tid 752093] [client 143.244.57.82:37690] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:32:41.689593 2026] [proxy:error] [pid 751901:tid 752093] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:32:41.689634 2026] [proxy_http:error] [pid 751901:tid 752093] [client 143.244.57.82:37690] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:32:41.804766 2026] [core:notice] [pid 751901:tid 752076] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:42.009557 2026] [security2:error] [pid 751901:tid 752111] [client 143.244.57.82:37698] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xru.gzj.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuKuirT982lovRn7gnQGwAAAFA"]
[Thu Jul 30 12:32:42.026638 2026] [core:notice] [pid 751901:tid 752025] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:42.286407 2026] [proxy:error] [pid 751901:tid 752149] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:32:42.286477 2026] [proxy_http:error] [pid 751901:tid 752149] [client 143.244.57.82:37704] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:32:42.287074 2026] [proxy:error] [pid 751901:tid 752149] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:32:42.287126 2026] [proxy_http:error] [pid 751901:tid 752149] [client 143.244.57.82:37704] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:32:42.335759 2026] [core:notice] [pid 751901:tid 752051] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:42.340247 2026] [security2:error] [pid 751901:tid 752051] [client 103.215.74.26:18142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKuirT982lovRn7gnQKAAAABQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:42.576626 2026] [security2:error] [pid 751901:tid 752150] [client 143.244.57.82:37708] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xru.gzj.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuKuirT982lovRn7gnQLwAAAHc"]
[Thu Jul 30 12:32:42.855908 2026] [security2:error] [pid 751901:tid 752154] [client 143.244.57.82:9972] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xru.gzj.temporary.site"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuKuirT982lovRn7gnQMwAAAHs"]
[Thu Jul 30 12:32:43.081534 2026] [core:notice] [pid 751901:tid 752087] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:43.086557 2026] [security2:error] [pid 751901:tid 752087] [client 103.215.74.26:37394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKuyrT982lovRn7gnQQAAAADg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:43.144374 2026] [security2:error] [pid 751901:tid 752141] [client 143.244.57.82:37724] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xru.gzj.temporary.site"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuKuyrT982lovRn7gnQQQAAAG4"]
[Thu Jul 30 12:32:43.332001 2026] [security2:error] [pid 751901:tid 752097] [client 40.77.167.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nafmedical.com"] [uri "/index.php"] [unique_id "amuKuyrT982lovRn7gnQPAAAQhE"]
[Thu Jul 30 12:32:43.426508 2026] [security2:error] [pid 751901:tid 752042] [client 143.244.57.82:37726] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xru.gzj.temporary.site"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuKuyrT982lovRn7gnQRgAAAAs"]
[Thu Jul 30 12:32:43.433912 2026] [security2:error] [pid 751901:tid 752120] [client 20.203.221.142:23478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuKuyrT982lovRn7gnQRwAAAFk"]
[Thu Jul 30 12:32:43.434030 2026] [security2:error] [pid 751901:tid 752120] [client 20.203.221.142:23478] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "saifalkhaleejest.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuKuyrT982lovRn7gnQRwAAAFk"]
[Thu Jul 30 12:32:43.709076 2026] [security2:error] [pid 751901:tid 752046] [client 143.244.57.82:37736] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xru.gzj.temporary.site"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuKuyrT982lovRn7gnQUQAAAA8"]
[Thu Jul 30 12:32:43.813928 2026] [core:notice] [pid 751901:tid 752049] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:43.818306 2026] [security2:error] [pid 751901:tid 752049] [client 103.215.74.26:37402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKuyrT982lovRn7gnQVQAAABI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:43.841791 2026] [security2:error] [pid 751901:tid 752066] [client 20.215.191.139:13567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/repeater.php"] [unique_id "amuKuyrT982lovRn7gnQVgAAACM"]
[Thu Jul 30 12:32:43.993790 2026] [security2:error] [pid 751901:tid 752055] [client 143.244.57.82:37744] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xru.gzj.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuKuyrT982lovRn7gnQWgAAABg"]
[Thu Jul 30 12:32:44.282136 2026] [security2:error] [pid 751901:tid 752100] [client 143.244.57.82:37758] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xru.gzj.temporary.site"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuKvCrT982lovRn7gnQYQAAAEU"]
[Thu Jul 30 12:32:44.560204 2026] [core:notice] [pid 751901:tid 752031] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:44.564885 2026] [security2:error] [pid 751901:tid 752031] [client 103.215.74.26:37418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKvCrT982lovRn7gnQZgAAAAA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:44.564909 2026] [security2:error] [pid 751901:tid 752092] [client 143.244.57.82:37762] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xru.gzj.temporary.site"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuKvCrT982lovRn7gnQZwAAAD0"]
[Thu Jul 30 12:32:44.844164 2026] [security2:error] [pid 751901:tid 752123] [client 143.244.57.82:37768] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xru.gzj.temporary.site"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuKvCrT982lovRn7gnQbgAAAFw"]
[Thu Jul 30 12:32:45.151805 2026] [security2:error] [pid 751901:tid 752136] [client 143.244.57.82:37770] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xru.gzj.temporary.site"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuKvSrT982lovRn7gnQdAAAAGk"]
[Thu Jul 30 12:32:45.177864 2026] [security2:error] [pid 751901:tid 752105] [client 20.203.221.142:4384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuKvSrT982lovRn7gnQdgAAAEo"]
[Thu Jul 30 12:32:45.178003 2026] [security2:error] [pid 751901:tid 752105] [client 20.203.221.142:4384] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "saifalkhaleejest.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuKvSrT982lovRn7gnQdgAAAEo"]
[Thu Jul 30 12:32:45.426393 2026] [security2:error] [pid 751901:tid 752071] [client 143.244.57.82:37784] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xru.gzj.temporary.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuKvSrT982lovRn7gnQfAAAACg"]
[Thu Jul 30 12:32:45.608838 2026] [security2:error] [pid 751901:tid 752157] [client 2a03:2880:f800:25:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuKvCrT982lovRn7gnQcAAAfhw"]
[Thu Jul 30 12:32:45.714568 2026] [security2:error] [pid 751901:tid 752120] [client 143.244.57.82:37792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xru.gzj.temporary.site"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuKvSrT982lovRn7gnQhgAAAFk"]
[Thu Jul 30 12:32:45.999579 2026] [security2:error] [pid 751901:tid 752044] [client 143.244.57.82:37798] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xru.gzj.temporary.site"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuKvSrT982lovRn7gnQiwAAAA0"]
[Thu Jul 30 12:32:46.283382 2026] [security2:error] [pid 751901:tid 752069] [client 143.244.57.82:37812] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xru.gzj.temporary.site"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuKvirT982lovRn7gnQmAAAACY"]
[Thu Jul 30 12:32:46.563288 2026] [security2:error] [pid 751901:tid 752095] [client 143.244.57.82:37816] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xru.gzj.temporary.site"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuKvirT982lovRn7gnQnAAAAEA"]
[Thu Jul 30 12:32:47.077137 2026] [core:notice] [pid 751901:tid 752092] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:47.568753 2026] [core:notice] [pid 751901:tid 752114] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:47.594042 2026] [security2:error] [pid 751901:tid 752058] [client 38.190.144.4:53061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKvyrT982lovRn7gnQtwAAABs"]
[Thu Jul 30 12:32:47.595764 2026] [security2:error] [pid 751901:tid 752058] [client 38.190.144.4:53061] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKvyrT982lovRn7gnQtwAAABs"]
[Thu Jul 30 12:32:48.184776 2026] [security2:error] [pid 751901:tid 752122] [client 2a03:2880:f800:14:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuKvyrT982lovRn7gnQtgAAWxk"]
[Thu Jul 30 12:32:48.730232 2026] [security2:error] [pid 751901:tid 752139] [client 20.203.221.142:40589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-login.php"] [unique_id "amuKwCrT982lovRn7gnQzQAAAGw"]
[Thu Jul 30 12:32:48.730360 2026] [security2:error] [pid 751901:tid 752139] [client 20.203.221.142:40589] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "saifalkhaleejest.com"] [uri "/wp-login.php"] [unique_id "amuKwCrT982lovRn7gnQzQAAAGw"]
[Thu Jul 30 12:32:49.235117 2026] [security2:error] [pid 751901:tid 751969] [remote 74.7.241.60:43410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/article.php"] [unique_id "amuKwSrT982lovRn7gnQ3wAAZ0M"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/1784117929_IMG_3676.jpg
[Thu Jul 30 12:32:49.842458 2026] [security2:error] [pid 751901:tid 752105] [client 20.203.221.142:1435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/red.php"] [unique_id "amuKwSrT982lovRn7gnQ7QAAAEo"]
[Thu Jul 30 12:32:49.842606 2026] [security2:error] [pid 751901:tid 752105] [client 20.203.221.142:1435] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "saifalkhaleejest.com"] [uri "/red.php"] [unique_id "amuKwSrT982lovRn7gnQ7QAAAEo"]
[Thu Jul 30 12:32:50.304594 2026] [core:notice] [pid 751901:tid 752142] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:50.308880 2026] [security2:error] [pid 751901:tid 752142] [client 103.215.74.26:37430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKwirT982lovRn7gnQ9AAAAG8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:50.397123 2026] [security2:error] [pid 751901:tid 752054] [client 31.56.58.134:42504] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-e91d45c4.wrf.zzt.temporary.site"] [uri "/.env"] [unique_id "amuKwirT982lovRn7gnQ-AAAABc"]
[Thu Jul 30 12:32:50.496487 2026] [core:notice] [pid 751901:tid 751996] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:51.071753 2026] [core:notice] [pid 751901:tid 752042] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:51.075882 2026] [security2:error] [pid 751901:tid 752042] [client 103.215.74.26:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKwyrT982lovRn7gnRBwAAAAs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:51.815022 2026] [core:notice] [pid 751901:tid 752135] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:51.819368 2026] [security2:error] [pid 751901:tid 752135] [client 103.215.74.26:37448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKwyrT982lovRn7gnRFAAAAGg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:52.310859 2026] [core:notice] [pid 751901:tid 752008] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:52.567069 2026] [core:notice] [pid 751901:tid 752107] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:52.574148 2026] [security2:error] [pid 751901:tid 752107] [client 103.215.74.26:37462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKxCrT982lovRn7gnRJwAAAEw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:52.578191 2026] [core:notice] [pid 751901:tid 751970] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:53.306797 2026] [core:notice] [pid 751901:tid 752091] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:53.311146 2026] [security2:error] [pid 751901:tid 752091] [client 103.215.74.26:2152] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKxSrT982lovRn7gnROQAAADw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:54.056184 2026] [core:notice] [pid 751901:tid 752153] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:54.060170 2026] [security2:error] [pid 751901:tid 752153] [client 103.215.74.26:2164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "745"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKxirT982lovRn7gnRSQAAAHo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:54.288772 2026] [security2:error] [pid 751901:tid 752048] [client 31.56.58.134:42534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-e91d45c4.wrf.zzt.temporary.site"] [uri "/.env"] [unique_id "amuKxirT982lovRn7gnRYAAAABE"]
[Thu Jul 30 12:32:54.636198 2026] [security2:error] [pid 751901:tid 752145] [client 38.190.144.4:53560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKxirT982lovRn7gnRagAAAHI"]
[Thu Jul 30 12:32:54.636334 2026] [security2:error] [pid 751901:tid 752145] [client 38.190.144.4:53560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKxirT982lovRn7gnRagAAAHI"]
[Thu Jul 30 12:32:54.783330 2026] [core:notice] [pid 751901:tid 752092] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:54.787304 2026] [security2:error] [pid 751901:tid 752092] [client 103.215.74.26:2172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKxirT982lovRn7gnRawAAAD0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:55.225649 2026] [security2:error] [pid 751901:tid 752121] [client 85.208.96.197:64670] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/11/04/eua-anunciam-us-400-milhoes-em-novo-pacote-de-ajuda-militar-a-ucrania/"] [unique_id "amuKxyrT982lovRn7gnRfQAAAFo"]
[Thu Jul 30 12:32:55.225926 2026] [security2:error] [pid 751901:tid 752121] [client 85.208.96.197:64670] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/11/04/eua-anunciam-us-400-milhoes-em-novo-pacote-de-ajuda-militar-a-ucrania/"] [unique_id "amuKxyrT982lovRn7gnRfQAAAFo"]
[Thu Jul 30 12:32:55.544386 2026] [core:notice] [pid 751901:tid 752102] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:55.552222 2026] [security2:error] [pid 751901:tid 752102] [client 103.215.74.26:2178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKxyrT982lovRn7gnRggAAAEc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:55.565441 2026] [security2:error] [pid 751901:tid 752109] [client 172.237.109.114:29705] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRTAAAAE4"]
[Thu Jul 30 12:32:55.881915 2026] [security2:error] [pid 751901:tid 752096] [client 57.141.0.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuKxyrT982lovRn7gnRfAAAAEE"]
[Thu Jul 30 12:32:55.931405 2026] [security2:error] [pid 751901:tid 752157] [client 79.117.189.155:45144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuKxyrT982lovRn7gnRhQAAAH4"], referer: http://pkf.jo
[Thu Jul 30 12:32:56.225481 2026] [security2:error] [pid 751901:tid 752042] [client 67.206.207.234:46606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuKxyrT982lovRn7gnRiQAAAAs"], referer: http://pkf.jo
[Thu Jul 30 12:32:56.238202 2026] [security2:error] [pid 751901:tid 752049] [client 172.237.109.114:59281] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRVAAAABI"]
[Thu Jul 30 12:32:56.246358 2026] [security2:error] [pid 751901:tid 752046] [client 172.237.109.114:37106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRUgAAAA8"]
[Thu Jul 30 12:32:56.254948 2026] [security2:error] [pid 751901:tid 752035] [client 172.237.109.114:61161] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRTgAAAAQ"]
[Thu Jul 30 12:32:56.284610 2026] [security2:error] [pid 751901:tid 752111] [client 172.237.109.114:44724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRUwAAAFA"]
[Thu Jul 30 12:32:56.304147 2026] [core:notice] [pid 751901:tid 752095] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:56.308565 2026] [security2:error] [pid 751901:tid 752140] [client 172.237.109.114:18255] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRSwAAAG0"]
[Thu Jul 30 12:32:56.312165 2026] [security2:error] [pid 751901:tid 752095] [client 103.215.74.26:2188] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKyCrT982lovRn7gnRmAAAAEA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:56.340903 2026] [security2:error] [pid 751901:tid 752057] [client 172.237.109.114:52815] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRTwAAABo"]
[Thu Jul 30 12:32:56.341098 2026] [security2:error] [pid 751901:tid 752040] [client 172.237.109.114:16965] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRVQAAAAk"]
[Thu Jul 30 12:32:56.365235 2026] [security2:error] [pid 751901:tid 752124] [client 172.237.109.114:58684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRTQAAAF0"]
[Thu Jul 30 12:32:56.386132 2026] [security2:error] [pid 751901:tid 752099] [client 172.237.109.114:45904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRXgAAAEQ"]
[Thu Jul 30 12:32:56.390293 2026] [security2:error] [pid 751901:tid 752078] [client 172.237.109.114:9030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRWgAAAC8"]
[Thu Jul 30 12:32:56.401166 2026] [security2:error] [pid 751901:tid 752133] [client 172.237.109.114:46370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRSgAAAGY"]
[Thu Jul 30 12:32:56.413760 2026] [security2:error] [pid 751901:tid 752126] [client 172.237.109.114:36101] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRVwAAAF8"]
[Thu Jul 30 12:32:56.420204 2026] [security2:error] [pid 751901:tid 752080] [client 172.237.109.114:21830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRWQAAADE"]
[Thu Jul 30 12:32:56.427040 2026] [security2:error] [pid 751901:tid 752084] [client 172.237.109.114:42518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRWAAAADU"]
[Thu Jul 30 12:32:56.427050 2026] [security2:error] [pid 751901:tid 752066] [client 172.237.109.114:20129] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRXAAAACM"]
[Thu Jul 30 12:32:56.436224 2026] [security2:error] [pid 751901:tid 752079] [client 172.237.109.114:36354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRUAAAADA"]
[Thu Jul 30 12:32:56.477932 2026] [security2:error] [pid 751901:tid 752108] [client 172.237.109.114:34072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRUQAAAE0"]
[Thu Jul 30 12:32:56.484403 2026] [security2:error] [pid 751901:tid 752139] [client 172.237.109.114:22475] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRXQAAAGw"]
[Thu Jul 30 12:32:56.562856 2026] [security2:error] [pid 751901:tid 752069] [client 172.237.109.114:14912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRWwAAACY"]
[Thu Jul 30 12:32:56.594927 2026] [security2:error] [pid 751901:tid 752056] [client 172.237.109.114:19708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRXwAAABk"]
[Thu Jul 30 12:32:56.667551 2026] [security2:error] [pid 751901:tid 752089] [client 200.24.99.234:11613] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuKyCrT982lovRn7gnRmQAAADo"], referer: http://pkf.jo
[Thu Jul 30 12:32:56.681223 2026] [security2:error] [pid 751901:tid 752136] [client 172.237.109.114:24554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxyrT982lovRn7gnRdQAAAGk"]
[Thu Jul 30 12:32:56.752164 2026] [security2:error] [pid 751901:tid 752053] [client 172.237.109.114:60008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxyrT982lovRn7gnReQAAABY"]
[Thu Jul 30 12:32:56.753512 2026] [security2:error] [pid 751901:tid 752075] [client 172.237.109.114:11154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxyrT982lovRn7gnReAAAACw"]
[Thu Jul 30 12:32:56.779629 2026] [security2:error] [pid 751901:tid 752058] [client 172.237.109.114:19302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxyrT982lovRn7gnRdwAAABs"]
[Thu Jul 30 12:32:57.747365 2026] [security2:error] [pid 751901:tid 752133] [client 20.203.221.142:40166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/cc.php"] [unique_id "amuKySrT982lovRn7gnRvAAAAGY"]
[Thu Jul 30 12:32:57.747462 2026] [security2:error] [pid 751901:tid 752133] [client 20.203.221.142:40166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "saifalkhaleejest.com"] [uri "/cc.php"] [unique_id "amuKySrT982lovRn7gnRvAAAAGY"]
[Thu Jul 30 12:32:58.225298 2026] [security2:error] [pid 751901:tid 752047] [client 168.228.85.104:15888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuKySrT982lovRn7gnRugAAABA"], referer: http://pkf.jo
[Thu Jul 30 12:32:58.245808 2026] [security2:error] [pid 751901:tid 752040] [client 57.141.0.38:42010] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuKySrT982lovRn7gnRvQAACSE"], referer: https://igetvape-australia.com/product/iget-bar-pro-grape-ice/
[Thu Jul 30 12:32:59.017578 2026] [security2:error] [pid 751901:tid 752097] [client 114.119.144.64:21697] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "inmobiliariadia.com"] [uri "/hello-world/"] [unique_id "amuKyyrT982lovRn7gnR0QAAAEI"], referer: http://inmobiliariadia.com/beautiful-lighting-effects/
[Thu Jul 30 12:33:00.953718 2026] [security2:error] [pid 751901:tid 752128] [client 95.108.213.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuKzCrT982lovRn7gnR_wAAAGE"]
[Thu Jul 30 12:33:01.760824 2026] [security2:error] [pid 751901:tid 752085] [client 20.203.221.142:24802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/log.php"] [unique_id "amuKzSrT982lovRn7gnSHQAAADY"]
[Thu Jul 30 12:33:01.760944 2026] [security2:error] [pid 751901:tid 752085] [client 20.203.221.142:24802] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "saifalkhaleejest.com"] [uri "/log.php"] [unique_id "amuKzSrT982lovRn7gnSHQAAADY"]
[Thu Jul 30 12:33:02.056644 2026] [core:notice] [pid 751901:tid 752044] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:02.064524 2026] [security2:error] [pid 751901:tid 752044] [client 103.215.74.26:2204] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKzirT982lovRn7gnSJwAAAA0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:02.807087 2026] [core:notice] [pid 751901:tid 752111] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:02.813825 2026] [security2:error] [pid 751901:tid 752111] [client 103.215.74.26:2220] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKzirT982lovRn7gnSMgAAAFA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:03.562009 2026] [core:notice] [pid 751901:tid 752127] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:03.565915 2026] [security2:error] [pid 751901:tid 752127] [client 103.215.74.26:25430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "745"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKzyrT982lovRn7gnSRQAAAGA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:04.304089 2026] [core:notice] [pid 751901:tid 752131] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:04.308150 2026] [security2:error] [pid 751901:tid 752131] [client 103.215.74.26:25440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "763"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK0CrT982lovRn7gnSUQAAAGQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:04.816308 2026] [security2:error] [pid 751901:tid 752096] [client 20.203.221.142:59828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/edit.php"] [unique_id "amuK0CrT982lovRn7gnSYQAAAEE"]
[Thu Jul 30 12:33:04.816445 2026] [security2:error] [pid 751901:tid 752096] [client 20.203.221.142:59828] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "saifalkhaleejest.com"] [uri "/edit.php"] [unique_id "amuK0CrT982lovRn7gnSYQAAAEE"]
[Thu Jul 30 12:33:04.913302 2026] [security2:error] [pid 751901:tid 752144] [client 51.9.41.235:39270] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.eot"] [unique_id "amuK0CrT982lovRn7gnSYwAAAHE"]
[Thu Jul 30 12:33:04.914814 2026] [security2:error] [pid 751901:tid 752058] [client 49.230.121.51:8933] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuK0CrT982lovRn7gnSXgAAABs"], referer: http://pkf.jo
[Thu Jul 30 12:33:05.018839 2026] [core:notice] [pid 751901:tid 752118] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:05.025321 2026] [security2:error] [pid 751901:tid 752118] [client 103.215.74.26:25442] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK0SrT982lovRn7gnSaAAAAFc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:05.064791 2026] [core:notice] [pid 751901:tid 752071] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:05.270081 2026] [security2:error] [pid 751901:tid 752088] [client 88.169.23.86:43833] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.eot"] [unique_id "amuK0SrT982lovRn7gnScQAAADk"]
[Thu Jul 30 12:33:05.428412 2026] [security2:error] [pid 751901:tid 752122] [client 89.12.23.34:33738] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.ttf"] [unique_id "amuK0SrT982lovRn7gnScgAAAFs"]
[Thu Jul 30 12:33:05.442661 2026] [security2:error] [pid 751901:tid 752085] [client 46.44.223.63:64388] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.eot"] [unique_id "amuK0SrT982lovRn7gnScwAAADY"]
[Thu Jul 30 12:33:05.474277 2026] [security2:error] [pid 751901:tid 752109] [client 2a03:2880:f800:4:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuK0CrT982lovRn7gnSTwAATkc"]
[Thu Jul 30 12:33:05.480462 2026] [security2:error] [pid 751901:tid 752031] [client 90.103.129.45:37592] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.woff"] [unique_id "amuK0SrT982lovRn7gnSdAAAAAA"]
[Thu Jul 30 12:33:05.578343 2026] [security2:error] [pid 751901:tid 752100] [client 38.190.144.4:54069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuK0SrT982lovRn7gnSfgAAAEU"]
[Thu Jul 30 12:33:05.578638 2026] [security2:error] [pid 751901:tid 752100] [client 38.190.144.4:54069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuK0SrT982lovRn7gnSfgAAAEU"]
[Thu Jul 30 12:33:05.609298 2026] [security2:error] [pid 751901:tid 752119] [client 85.222.250.226:54230] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.ttf"] [unique_id "amuK0SrT982lovRn7gnSfwAAAFg"]
[Thu Jul 30 12:33:05.725717 2026] [security2:error] [pid 751901:tid 752123] [client 103.192.152.144:52438] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.eot"] [unique_id "amuK0SrT982lovRn7gnShQAAAFw"]
[Thu Jul 30 12:33:05.763702 2026] [security2:error] [pid 751901:tid 752064] [client 99.217.44.60:54760] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.ttf"] [unique_id "amuK0SrT982lovRn7gnShgAAACE"]
[Thu Jul 30 12:33:05.814248 2026] [security2:error] [pid 751901:tid 752038] [client 192.81.202.237:35408] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.eot"] [unique_id "amuK0SrT982lovRn7gnShwAAAAc"]
[Thu Jul 30 12:33:05.972704 2026] [security2:error] [pid 751901:tid 752137] [client 95.26.138.15:13168] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.woff"] [unique_id "amuK0SrT982lovRn7gnSigAAAGo"]
[Thu Jul 30 12:33:05.993170 2026] [security2:error] [pid 751901:tid 752034] [client 86.180.65.33:58226] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.woff"] [unique_id "amuK0SrT982lovRn7gnSjAAAAAM"]
[Thu Jul 30 12:33:06.026686 2026] [security2:error] [pid 751901:tid 752102] [client 82.20.152.180:49796] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.eot"] [unique_id "amuK0irT982lovRn7gnSjQAAAEc"]
[Thu Jul 30 12:33:06.110102 2026] [security2:error] [pid 751901:tid 752084] [client 57.141.0.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuK0SrT982lovRn7gnSegAAADU"]
[Thu Jul 30 12:33:06.124135 2026] [core:notice] [pid 751901:tid 752139] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:06.172152 2026] [security2:error] [pid 751901:tid 752054] [client 20.203.221.142:56212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/plugins.php"] [unique_id "amuK0irT982lovRn7gnSlgAAABc"]
[Thu Jul 30 12:33:06.172241 2026] [security2:error] [pid 751901:tid 752054] [client 20.203.221.142:56212] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "saifalkhaleejest.com"] [uri "/plugins.php"] [unique_id "amuK0irT982lovRn7gnSlgAAABc"]
[Thu Jul 30 12:33:06.503476 2026] [security2:error] [pid 751901:tid 752121] [client 2a03:2880:f800:d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuK0CrT982lovRn7gnSVwAAWkA"]
[Thu Jul 30 12:33:06.648121 2026] [security2:error] [pid 751901:tid 752135] [client 20.203.221.142:41417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/style.php"] [unique_id "amuK0irT982lovRn7gnSqQAAAGg"]
[Thu Jul 30 12:33:06.648217 2026] [security2:error] [pid 751901:tid 752135] [client 20.203.221.142:41417] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "saifalkhaleejest.com"] [uri "/style.php"] [unique_id "amuK0irT982lovRn7gnSqQAAAGg"]
[Thu Jul 30 12:33:06.839700 2026] [security2:error] [pid 751901:tid 752065] [client 45.236.103.184:51737] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.eot"] [unique_id "amuK0irT982lovRn7gnSqgAAACI"]
[Thu Jul 30 12:33:07.385694 2026] [security2:error] [pid 751901:tid 752104] [client 24.76.188.15:48592] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.woff2"] [unique_id "amuK0yrT982lovRn7gnSugAAAEk"]
[Thu Jul 30 12:33:07.832904 2026] [security2:error] [pid 751901:tid 752133] [client 2a03:2880:f800:6:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuK0yrT982lovRn7gnSsgAAZmQ"]
[Thu Jul 30 12:33:09.059695 2026] [security2:error] [pid 751901:tid 752093] [client 43.172.196.156:41108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.196.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2009/06/29/organisez-une-journee-shopping-a-londres/"] [unique_id "amuK1CrT982lovRn7gnS2wAAAD4"]
[Thu Jul 30 12:33:09.332987 2026] [security2:error] [pid 751901:tid 752114] [client 57.141.0.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuK1CrT982lovRn7gnS2gAAAFM"]
[Thu Jul 30 12:33:09.427489 2026] [security2:error] [pid 751901:tid 752070] [client 57.141.0.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuK1CrT982lovRn7gnS4QAAACc"]
[Thu Jul 30 12:33:09.705448 2026] [core:notice] [pid 751901:tid 752122] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:09.709780 2026] [security2:error] [pid 751901:tid 752122] [client 43.173.179.206:55852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2009/06/29/organisez-une-journee-shopping-a-londres/"] [unique_id "amuK1SrT982lovRn7gnS8wAAAFs"], referer: https://carnetdeshopping.com/index.php/2009/06/29/organisez-une-journee-shopping-a-londres/
[Thu Jul 30 12:33:10.162473 2026] [core:notice] [pid 751901:tid 752089] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:10.831174 2026] [security2:error] [pid 751901:tid 752084] [client 20.203.221.142:59777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/plugins.php"] [unique_id "amuK1irT982lovRn7gnTDQAAADU"]
[Thu Jul 30 12:33:10.831299 2026] [security2:error] [pid 751901:tid 752084] [client 20.203.221.142:59777] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "saifalkhaleejest.com"] [uri "/plugins.php"] [unique_id "amuK1irT982lovRn7gnTDQAAADU"]
[Thu Jul 30 12:33:10.838809 2026] [core:notice] [pid 751901:tid 752131] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:10.842718 2026] [security2:error] [pid 751901:tid 752131] [client 103.215.74.26:25452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "776"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK1irT982lovRn7gnTDgAAAGQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:11.325468 2026] [security2:error] [pid 751901:tid 752074] [client 170.106.180.139:60374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.180.106.170.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/book.php"] [unique_id "amuK1yrT982lovRn7gnTGgAAACs"]
[Thu Jul 30 12:33:11.345593 2026] [security2:error] [pid 751901:tid 751997] [remote 69.57.172.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.172.57.69.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannyplatoncuevas.com"] [uri "/wp-login.php"] [unique_id "amuK1yrT982lovRn7gnTEgAAQV8"]
[Thu Jul 30 12:33:11.533141 2026] [core:error] [pid 751901:tid 752063] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:11.533162 2026] [core:error] [pid 751901:tid 752063] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:11.566617 2026] [core:notice] [pid 751901:tid 752093] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:11.574233 2026] [security2:error] [pid 751901:tid 752093] [client 103.215.74.26:25462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "738"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK1yrT982lovRn7gnTMAAAAD4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:11.576002 2026] [core:error] [pid 751901:tid 752126] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:11.576024 2026] [core:error] [pid 751901:tid 752126] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:11.616240 2026] [core:error] [pid 751901:tid 752067] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:11.616260 2026] [core:error] [pid 751901:tid 752067] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:11.625025 2026] [core:error] [pid 751901:tid 752069] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:11.625043 2026] [core:error] [pid 751901:tid 752069] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:11.625091 2026] [core:error] [pid 751901:tid 752119] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:11.625107 2026] [core:error] [pid 751901:tid 752119] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:12.091424 2026] [security2:error] [pid 751901:tid 752032] [client 157.35.45.167:43635] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.eot"] [unique_id "amuK2CrT982lovRn7gnTRgAAAAE"]
[Thu Jul 30 12:33:12.331881 2026] [core:notice] [pid 751901:tid 752035] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:12.336012 2026] [security2:error] [pid 751901:tid 752035] [client 103.215.74.26:25472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK2CrT982lovRn7gnTTAAAAAQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:13.068045 2026] [core:notice] [pid 751901:tid 752046] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:13.072152 2026] [security2:error] [pid 751901:tid 752046] [client 103.215.74.26:34656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK2SrT982lovRn7gnTXQAAAA8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:13.799006 2026] [core:notice] [pid 751901:tid 752033] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:13.803353 2026] [security2:error] [pid 751901:tid 752033] [client 103.215.74.26:34660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK2SrT982lovRn7gnTcAAAAAI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:13.864915 2026] [security2:error] [pid 751901:tid 751914] [remote 57.141.0.45:55852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/589953950/feed/rss2/"] [unique_id "amuK2SrT982lovRn7gnTcQAATww"]
[Thu Jul 30 12:33:14.523847 2026] [core:notice] [pid 751901:tid 752097] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:14.528167 2026] [security2:error] [pid 751901:tid 752097] [client 103.215.74.26:34670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "737"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK2irT982lovRn7gnTgQAAAEI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:14.752646 2026] [core:notice] [pid 751901:tid 752112] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:14.763530 2026] [core:notice] [pid 751901:tid 752139] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:15.253298 2026] [core:notice] [pid 751901:tid 752130] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:15.257303 2026] [security2:error] [pid 751901:tid 752130] [client 103.215.74.26:34686] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "737"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK2yrT982lovRn7gnTnAAAAGM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:15.551166 2026] [security2:error] [pid 751901:tid 752147] [client 8.217.152.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuK2yrT982lovRn7gnTnwAAAHQ"]
[Thu Jul 30 12:33:16.478643 2026] [security2:error] [pid 751901:tid 752123] [client 38.190.144.4:54570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuK3CrT982lovRn7gnTvQAAAFw"]
[Thu Jul 30 12:33:16.478764 2026] [security2:error] [pid 751901:tid 752123] [client 38.190.144.4:54570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuK3CrT982lovRn7gnTvQAAAFw"]
[Thu Jul 30 12:33:17.874318 2026] [security2:error] [pid 751901:tid 752141] [client 74.7.230.16:35332] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-19437fac.xdi.djb.temporary.site"] [uri "/index.php"] [unique_id "amuK3CrT982lovRn7gnTtQAAbjY"]
[Thu Jul 30 12:33:19.676402 2026] [security2:error] [pid 751901:tid 752103] [client 102.204.4.28:30787] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.ttf"] [unique_id "amuK3yrT982lovRn7gnUEgAAAEg"]
[Thu Jul 30 12:33:20.400996 2026] [core:notice] [pid 751901:tid 752106] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:20.973015 2026] [core:notice] [pid 751901:tid 752118] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:20.977295 2026] [security2:error] [pid 751901:tid 752118] [client 103.215.74.26:34700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK4CrT982lovRn7gnUPwAAAFc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:21.729871 2026] [core:notice] [pid 751901:tid 752104] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:21.734275 2026] [security2:error] [pid 751901:tid 752104] [client 103.215.74.26:34712] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK4SrT982lovRn7gnUWQAAAEk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:22.477908 2026] [core:notice] [pid 751901:tid 752106] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:22.482162 2026] [security2:error] [pid 751901:tid 752106] [client 103.215.74.26:34726] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK4irT982lovRn7gnUdQAAAEs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:23.217461 2026] [core:notice] [pid 751901:tid 752044] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:23.221598 2026] [security2:error] [pid 751901:tid 752044] [client 103.215.74.26:46710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK4yrT982lovRn7gnUjwAAAA0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:23.507906 2026] [security2:error] [pid 751901:tid 752081] [client 43.173.179.40:36802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dlr.djb.temporary.site"] [uri "/index.php"] [unique_id "amuK4yrT982lovRn7gnUkwAAADI"]
[Thu Jul 30 12:33:23.954054 2026] [core:notice] [pid 751901:tid 752102] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:23.959061 2026] [security2:error] [pid 751901:tid 752102] [client 103.215.74.26:46760] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK4yrT982lovRn7gnUrAAAAEc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:24.698058 2026] [core:notice] [pid 751901:tid 752140] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:24.702532 2026] [security2:error] [pid 751901:tid 752140] [client 103.215.74.26:46772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK5CrT982lovRn7gnUwQAAAG0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:25.422494 2026] [core:notice] [pid 751901:tid 752040] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:25.426917 2026] [security2:error] [pid 751901:tid 752040] [client 103.215.74.26:46830] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK5SrT982lovRn7gnU0wAAAAk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:25.529280 2026] [autoindex:error] [pid 751901:tid 752106] [client 82.102.18.188:47270] AH01276: Cannot serve directory /home1/yqegzjte/hello-pal.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:33:25.685058 2026] [autoindex:error] [pid 751901:tid 752115] [client 82.102.18.188:47270] AH01276: Cannot serve directory /home1/yqegzjte/hello-pal.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:33:25.840361 2026] [security2:error] [pid 751901:tid 752158] [client 82.102.18.188:47270] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hello-pal.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuK5SrT982lovRn7gnU4gAAAH8"]
[Thu Jul 30 12:33:26.176222 2026] [security2:error] [pid 751901:tid 752093] [client 82.102.18.188:47274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.hello-pal.com"] [uri "/xmlrpc.php"] [unique_id "amuK5irT982lovRn7gnU7gAAAD4"]
[Thu Jul 30 12:33:26.199913 2026] [core:notice] [pid 751901:tid 752095] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:26.204148 2026] [security2:error] [pid 751901:tid 752095] [client 103.215.74.26:46850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK5irT982lovRn7gnU7wAAAEA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:26.529220 2026] [autoindex:error] [pid 751901:tid 752033] [client 82.102.18.188:47290] AH01276: Cannot serve directory /home1/yqegzjte/hello-pal.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:33:26.892808 2026] [security2:error] [pid 751901:tid 752125] [client 82.102.18.188:47290] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hello-pal.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuK5irT982lovRn7gnVAgAAAF4"]
[Thu Jul 30 12:33:26.927123 2026] [core:notice] [pid 751901:tid 752066] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:26.931536 2026] [security2:error] [pid 751901:tid 752066] [client 103.215.74.26:46858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK5irT982lovRn7gnVAwAAACM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:27.111382 2026] [security2:error] [pid 751901:tid 752112] [client 66.249.64.172:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.reliablehomeappliancerepair.store"] [uri "/index.php"] [unique_id "amuK5irT982lovRn7gnU9gAAAFE"]
[Thu Jul 30 12:33:27.204363 2026] [security2:error] [pid 751901:tid 752117] [client 82.102.18.188:47294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hello-pal.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuK5yrT982lovRn7gnVDQAAAFY"]
[Thu Jul 30 12:33:27.534003 2026] [security2:error] [pid 751901:tid 752120] [client 82.102.18.188:47306] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hello-pal.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuK5yrT982lovRn7gnVFwAAAFk"]
[Thu Jul 30 12:33:27.650495 2026] [core:notice] [pid 751901:tid 752058] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:27.654464 2026] [security2:error] [pid 751901:tid 752058] [client 103.215.74.26:46916] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "737"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK5yrT982lovRn7gnVHQAAABs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:27.806417 2026] [security2:error] [pid 751901:tid 752034] [client 155.35.46.151:55200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuK5yrT982lovRn7gnVFAAAAAM"], referer: http://pkf.jo
[Thu Jul 30 12:33:28.537132 2026] [security2:error] [pid 751901:tid 752128] [client 5.111.46.83:1495] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuK6CrT982lovRn7gnVMgAAAGE"], referer: http://pkf.jo
[Thu Jul 30 12:33:28.594739 2026] [security2:error] [pid 751901:tid 752070] [client 49.51.72.76:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amuK6CrT982lovRn7gnVJgAAACc"]
[Thu Jul 30 12:33:28.824492 2026] [security2:error] [pid 751901:tid 752105] [client 82.102.18.188:47310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hello-pal.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuK6CrT982lovRn7gnVRgAAAEo"]
[Thu Jul 30 12:33:29.124812 2026] [security2:error] [pid 751901:tid 752143] [client 82.102.18.188:47312] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hello-pal.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuK6SrT982lovRn7gnVTgAAAHA"]
[Thu Jul 30 12:33:29.133542 2026] [core:error] [pid 751901:tid 752145] [client 74.7.241.156:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:29.133567 2026] [core:error] [pid 751901:tid 752145] [client 74.7.241.156:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:29.133733 2026] [security2:error] [pid 751901:tid 752145] [client 74.7.241.156:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.glowspakarachi.site"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amuK6SrT982lovRn7gnVTwAAAHI"]
[Thu Jul 30 12:33:29.134282 2026] [security2:error] [pid 751901:tid 752115] [client 74.7.241.156:50290] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.glowspakarachi.site"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amuK6SrT982lovRn7gnVTAAAVAc"]
[Thu Jul 30 12:33:29.222335 2026] [proxy:error] [pid 751901:tid 752026] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:33:29.222389 2026] [proxy_http:error] [pid 751901:tid 752026] [remote 74.7.244.30:52156] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:33:29.222948 2026] [proxy:error] [pid 751901:tid 752026] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:33:29.223008 2026] [proxy_http:error] [pid 751901:tid 752026] [remote 74.7.244.30:52156] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:33:29.450782 2026] [security2:error] [pid 751901:tid 752093] [client 82.102.18.188:47326] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hello-pal.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuK6SrT982lovRn7gnVWgAAAD4"]
[Thu Jul 30 12:33:29.591048 2026] [security2:error] [pid 751901:tid 752059] [client 74.7.241.128:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-55f007f0.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuK6CrT982lovRn7gnVPQAAABw"]
[Thu Jul 30 12:33:29.591789 2026] [security2:error] [pid 751901:tid 752132] [client 74.7.241.128:39546] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-55f007f0.glb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuK6CrT982lovRn7gnVOwAAZXs"]
[Thu Jul 30 12:33:29.796112 2026] [security2:error] [pid 751901:tid 752039] [client 82.102.18.188:47336] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hello-pal.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuK6SrT982lovRn7gnVYQAAAAg"]
[Thu Jul 30 12:33:29.812055 2026] [security2:error] [pid 751901:tid 752073] [client 43.172.198.169:51646] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dlr.djb.temporary.site"] [uri "/index.php"] [unique_id "amuK6SrT982lovRn7gnVWwAAACo"]
[Thu Jul 30 12:33:30.153285 2026] [security2:error] [pid 751901:tid 752056] [client 82.102.18.188:47352] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hello-pal.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuK6irT982lovRn7gnVbAAAABk"]
[Thu Jul 30 12:33:30.410060 2026] [security2:error] [pid 751901:tid 752101] [client 82.102.18.188:47368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hello-pal.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuK6irT982lovRn7gnVdAAAAEY"]
[Thu Jul 30 12:33:30.552687 2026] [security2:error] [pid 751901:tid 752037] [client 113.168.236.221:55041] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuK6SrT982lovRn7gnVawAAAAY"], referer: http://pkf.jo
[Thu Jul 30 12:33:30.628608 2026] [security2:error] [pid 751901:tid 752130] [client 34.21.248.151:5657] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.carnetdeshopping.com"] [uri "/wp-content/uploads/2013/02/ile-petite-terre-guadeloupe_13-300x225.jpg"] [unique_id "amuK6irT982lovRn7gnVigAAAGM"]
[Thu Jul 30 12:33:30.719221 2026] [security2:error] [pid 751901:tid 752143] [client 82.102.18.188:47374] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hello-pal.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuK6irT982lovRn7gnVmQAAAHA"]
[Thu Jul 30 12:33:30.812091 2026] [security2:error] [pid 751901:tid 752058] [client 51.68.107.137:32075] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.radiojelli.com"] [uri "/robots.txt"] [unique_id "amuK6irT982lovRn7gnVnQAAABs"]
[Thu Jul 30 12:33:30.812209 2026] [security2:error] [pid 751901:tid 752058] [client 51.68.107.137:32075] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.radiojelli.com"] [uri "/robots.txt"] [unique_id "amuK6irT982lovRn7gnVnQAAABs"]
[Thu Jul 30 12:33:31.048329 2026] [security2:error] [pid 751901:tid 752050] [client 82.102.18.188:47376] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hello-pal.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuK6yrT982lovRn7gnVqAAAABM"]
[Thu Jul 30 12:33:31.389767 2026] [security2:error] [pid 751901:tid 752148] [client 82.102.18.188:47386] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hello-pal.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuK6yrT982lovRn7gnVsQAAAHU"]
[Thu Jul 30 12:33:31.449262 2026] [security2:error] [pid 751901:tid 752132] [client 102.23.36.49:55938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuK6yrT982lovRn7gnVqQAAAGU"], referer: http://pkf.jo
[Thu Jul 30 12:33:32.400184 2026] [security2:error] [pid 751901:tid 752040] [client 51.68.107.137:12603] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.radiojelli.com"] [uri "/robots.txt"] [unique_id "amuK7CrT982lovRn7gnVxwAAAAk"]
[Thu Jul 30 12:33:32.400320 2026] [security2:error] [pid 751901:tid 752040] [client 51.68.107.137:12603] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.radiojelli.com"] [uri "/robots.txt"] [unique_id "amuK7CrT982lovRn7gnVxwAAAAk"]
[Thu Jul 30 12:33:32.639007 2026] [core:notice] [pid 751901:tid 752119] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:33.224127 2026] [core:notice] [pid 751901:tid 752035] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:33.397054 2026] [core:notice] [pid 751901:tid 752109] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:33.401001 2026] [security2:error] [pid 751901:tid 752109] [client 103.215.74.26:3758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK7SrT982lovRn7gnV5gAAAE4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:33.482464 2026] [security2:error] [pid 751901:tid 752088] [client 114.119.150.9:49627] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "alseermarine.com"] [uri "/investor-relations-2/share-price-look-up/"] [unique_id "amuK7SrT982lovRn7gnV6gAAADk"], referer: https://alseermarine.com/investor-relations-2/share-graph
[Thu Jul 30 12:33:33.659323 2026] [core:notice] [pid 751901:tid 752032] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:34.108379 2026] [security2:error] [pid 751901:tid 752076] [client 57.141.0.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuK7SrT982lovRn7gnV6QAAAC0"]
[Thu Jul 30 12:33:34.134180 2026] [core:notice] [pid 751901:tid 752128] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:34.138334 2026] [security2:error] [pid 751901:tid 752128] [client 103.215.74.26:3770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "736"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK7irT982lovRn7gnV-QAAAGE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:34.348460 2026] [core:error] [pid 751901:tid 752143] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:34.348483 2026] [core:error] [pid 751901:tid 752143] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:34.354433 2026] [core:error] [pid 751901:tid 752085] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:34.354459 2026] [core:error] [pid 751901:tid 752085] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:34.381124 2026] [core:error] [pid 751901:tid 752051] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:34.381141 2026] [core:error] [pid 751901:tid 752051] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:34.427909 2026] [core:error] [pid 751901:tid 752118] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:34.427935 2026] [core:error] [pid 751901:tid 752118] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:34.434604 2026] [core:error] [pid 751901:tid 752035] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:34.434621 2026] [core:error] [pid 751901:tid 752035] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:34.645820 2026] [security2:error] [pid 751901:tid 752133] [client 85.208.96.210:59664] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/11/11/terremoto-de-magnitude-73-causa-alerta-de-tsunami-em-tonga-na-oceania/"] [unique_id "amuK7irT982lovRn7gnWHgAAAGY"]
[Thu Jul 30 12:33:34.645958 2026] [security2:error] [pid 751901:tid 752133] [client 85.208.96.210:59664] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/11/11/terremoto-de-magnitude-73-causa-alerta-de-tsunami-em-tonga-na-oceania/"] [unique_id "amuK7irT982lovRn7gnWHgAAAGY"]
[Thu Jul 30 12:33:34.858272 2026] [core:notice] [pid 751901:tid 752043] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:34.862672 2026] [security2:error] [pid 751901:tid 752043] [client 103.215.74.26:3784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK7irT982lovRn7gnWJQAAAAw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:35.755070 2026] [security2:error] [pid 751901:tid 752067] [client 114.119.134.206:34781] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2023/01/067.jpeg"] [unique_id "amuK7yrT982lovRn7gnWRgAAACQ"], referer: https://www.nordeste1.com/2023/01/17/joao-azevedo-anuncia-rafaela-camaraense-para-assumir-secretaria-de-meio-ambiente/
[Thu Jul 30 12:33:37.818181 2026] [core:notice] [pid 751901:tid 752145] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:38.347328 2026] [security2:error] [pid 751901:tid 752097] [client 2a03:2880:f800:1e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuK8SrT982lovRn7gnWZQAAQg0"]
[Thu Jul 30 12:33:38.420519 2026] [security2:error] [pid 751901:tid 752125] [client 38.190.144.4:55576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuK8irT982lovRn7gnWjQAAAF4"]
[Thu Jul 30 12:33:38.420627 2026] [security2:error] [pid 751901:tid 752125] [client 38.190.144.4:55576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuK8irT982lovRn7gnWjQAAAF4"]
[Thu Jul 30 12:33:38.561862 2026] [security2:error] [pid 751901:tid 752121] [client 114.119.130.237:29131] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sv.radiojelli.com"] [uri "/where-are-all-the-single-men"] [unique_id "amuK8irT982lovRn7gnWjgAAAFo"], referer: https://sv.radiojelli.com/sitemaps/sitemap1.xml
[Thu Jul 30 12:33:38.601967 2026] [security2:error] [pid 751901:tid 752113] [client 57.141.0.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuK8irT982lovRn7gnWfQAAAFI"]
[Thu Jul 30 12:33:40.586103 2026] [core:notice] [pid 751901:tid 752123] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:40.592564 2026] [security2:error] [pid 751901:tid 752123] [client 103.215.74.26:3788] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK9CrT982lovRn7gnWyQAAAFw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:41.322507 2026] [core:notice] [pid 751901:tid 752087] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:41.329125 2026] [security2:error] [pid 751901:tid 752087] [client 103.215.74.26:3800] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK9SrT982lovRn7gnW4AAAADg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:42.307511 2026] [security2:error] [pid 751901:tid 752078] [client 114.119.156.86:33935] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.carnetdeshopping.com"] [uri "/tendance-la-chemise-en-jean-must-have-printemps-ete-2013"] [unique_id "amuK9irT982lovRn7gnW-wAAAC8"], referer: https://www.carnetdeshopping.com/author/sabrina/page/66
[Thu Jul 30 12:33:43.219450 2026] [security2:error] [pid 751901:tid 752076] [client 34.139.111.28:49404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "stunningtouchcleaning.com"] [uri "/index.php"] [unique_id "amuK9CrT982lovRn7gnWwAAAAC0"]
[Thu Jul 30 12:33:44.654414 2026] [security2:error] [pid 751901:tid 752129] [client 37.120.155.179:44156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.155.120.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuK-CrT982lovRn7gnXNwAAAGI"]
[Thu Jul 30 12:33:44.654510 2026] [security2:error] [pid 751901:tid 752129] [client 37.120.155.179:44156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuK-CrT982lovRn7gnXNwAAAGI"]
[Thu Jul 30 12:33:44.967294 2026] [security2:error] [pid 751901:tid 752142] [client 104.254.90.251:42112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.90.254.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuK-CrT982lovRn7gnXOwAAAG8"]
[Thu Jul 30 12:33:44.967402 2026] [security2:error] [pid 751901:tid 752142] [client 104.254.90.251:42112] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuK-CrT982lovRn7gnXOwAAAG8"]
[Thu Jul 30 12:33:44.985986 2026] [security2:error] [pid 751901:tid 751970] [remote 57.141.0.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuK-CrT982lovRn7gnXPAAAakQ"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=carbon,linen,polyester,cotton,denim,aluminum,plastic,nylon,wood&orderby=menu_order&rating=5&status=sale&filter_brand=desigual&unfilter=1
[Thu Jul 30 12:33:45.762331 2026] [security2:error] [pid 751901:tid 752011] [remote 57.141.0.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuK-SrT982lovRn7gnXRgAASm0"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=carbon,linen,polyester,cotton,denim,aluminum,plastic,nylon,wood&orderby=menu_order&rating=5&status=sale&filter_brand=desigual&unfilter=1
[Thu Jul 30 12:33:47.062350 2026] [core:notice] [pid 751901:tid 752111] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:47.067752 2026] [security2:error] [pid 751901:tid 752111] [client 103.215.74.26:39026] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "737"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK-yrT982lovRn7gnXZgAAAFA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:47.584399 2026] [core:notice] [pid 751901:tid 752108] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:47.634824 2026] [security2:error] [pid 751901:tid 752034] [client 20.63.98.115:54756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/gmo.php"] [unique_id "amuK-yrT982lovRn7gnXhAAAAAM"]
[Thu Jul 30 12:33:47.812933 2026] [core:notice] [pid 751901:tid 752123] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:47.817076 2026] [security2:error] [pid 751901:tid 752123] [client 103.215.74.26:39032] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK-yrT982lovRn7gnXiwAAAFw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:48.454274 2026] [security2:error] [pid 751901:tid 752042] [client 20.63.98.115:55308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/nakrip.php"] [unique_id "amuK_CrT982lovRn7gnXlwAAAAs"]
[Thu Jul 30 12:33:48.550955 2026] [core:notice] [pid 751901:tid 752079] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:48.557421 2026] [security2:error] [pid 751901:tid 752079] [client 103.215.74.26:39036] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK_CrT982lovRn7gnXmQAAADA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:48.710047 2026] [security2:error] [pid 751901:tid 752087] [client 74.7.241.183:59906] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "hris.rgserve.ph"] [uri "/cgi-sys/404.html"] [unique_id "amuK_CrT982lovRn7gnXoAAAOAU"]
[Thu Jul 30 12:33:49.201244 2026] [security2:error] [pid 751901:tid 752116] [client 38.190.144.4:56068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuK_SrT982lovRn7gnXqwAAAFU"]
[Thu Jul 30 12:33:49.201375 2026] [security2:error] [pid 751901:tid 752116] [client 38.190.144.4:56068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuK_SrT982lovRn7gnXqwAAAFU"]
[Thu Jul 30 12:33:49.302110 2026] [core:notice] [pid 751901:tid 752155] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:49.306016 2026] [security2:error] [pid 751901:tid 752155] [client 103.215.74.26:39046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "768"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK_SrT982lovRn7gnXrwAAAHw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:49.316535 2026] [security2:error] [pid 751901:tid 752032] [client 20.63.98.115:64876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/radio.php"] [unique_id "amuK_SrT982lovRn7gnXsAAAAAE"]
[Thu Jul 30 12:33:49.361278 2026] [core:notice] [pid 751901:tid 752122] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:49.618326 2026] [autoindex:error] [pid 751901:tid 751909] [remote 74.7.242.5:56540] AH01276: Cannot serve directory /home2/qnjgzjte/hris.rgserve.ph/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:33:50.043819 2026] [core:notice] [pid 751901:tid 752034] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:50.047781 2026] [security2:error] [pid 751901:tid 752034] [client 103.215.74.26:39052] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK_irT982lovRn7gnXvwAAAAM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:50.194522 2026] [security2:error] [pid 751901:tid 752037] [client 20.63.98.115:55303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-singin.php"] [unique_id "amuK_irT982lovRn7gnXwwAAAAY"]
[Thu Jul 30 12:33:50.795340 2026] [core:notice] [pid 751901:tid 752153] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:50.799455 2026] [security2:error] [pid 751901:tid 752153] [client 103.215.74.26:39064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK_irT982lovRn7gnXzgAAAHo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:51.519050 2026] [core:notice] [pid 751901:tid 752063] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:51.522889 2026] [security2:error] [pid 751901:tid 752063] [client 103.215.74.26:39074] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK_yrT982lovRn7gnX4wAAACA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:51.904086 2026] [security2:error] [pid 751901:tid 752142] [client 114.119.144.17:42595] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kendarikomputer.com"] [uri "/search"] [unique_id "amuK_yrT982lovRn7gnX5wAAAG8"], referer: https://www.kendarikomputer.com/search?updated-max=2023-05-30T13%3A12%3A00%2B08%3A00&max-results=10&reverse-paginate=true&m=1
[Thu Jul 30 12:33:51.939195 2026] [security2:error] [pid 751901:tid 752051] [client 20.63.98.115:59036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/as.php"] [unique_id "amuK_yrT982lovRn7gnX6AAAABQ"]
[Thu Jul 30 12:33:52.285150 2026] [core:notice] [pid 751901:tid 752060] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:52.289059 2026] [security2:error] [pid 751901:tid 752060] [client 103.215.74.26:39088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLACrT982lovRn7gnX8gAAAB0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:52.471968 2026] [core:notice] [pid 751901:tid 752136] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:53.006260 2026] [core:notice] [pid 751901:tid 752085] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:53.010385 2026] [security2:error] [pid 751901:tid 752085] [client 103.215.74.26:42766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLASrT982lovRn7gnYAgAAADY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:53.113240 2026] [security2:error] [pid 751901:tid 752034] [client 20.63.98.115:20953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/x.php"] [unique_id "amuLASrT982lovRn7gnYBgAAAAM"]
[Thu Jul 30 12:33:53.762195 2026] [core:notice] [pid 751901:tid 752154] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:53.766254 2026] [security2:error] [pid 751901:tid 752154] [client 103.215.74.26:42782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLASrT982lovRn7gnYIAAAAHs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:54.163819 2026] [autoindex:error] [pid 751901:tid 752107] [client 52.4.19.39:23296] AH01276: Cannot serve directory /home1/vdbnyxte/public_html/website_19d94cc7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:33:54.224358 2026] [security2:error] [pid 751901:tid 751949] [remote 74.7.241.60:56114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/article.php"] [unique_id "amuLAirT982lovRn7gnYLAAAZS8"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/1784117929_IMG_3676.jpg
[Thu Jul 30 12:33:54.540594 2026] [core:notice] [pid 751901:tid 752063] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:54.544606 2026] [security2:error] [pid 751901:tid 752063] [client 103.215.74.26:42784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLAirT982lovRn7gnYMAAAACA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:55.072222 2026] [security2:error] [pid 751901:tid 752093] [client 20.63.98.115:54772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/item.php"] [unique_id "amuLAyrT982lovRn7gnYQQAAAD4"]
[Thu Jul 30 12:33:55.290841 2026] [core:notice] [pid 751901:tid 752092] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:55.294808 2026] [security2:error] [pid 751901:tid 752092] [client 103.215.74.26:42796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "765"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLAyrT982lovRn7gnYSQAAAD0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:55.623464 2026] [security2:error] [pid 751901:tid 752069] [client 114.119.158.118:20187] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "saifalkhaleejest.com"] [uri "/2026/03/"] [unique_id "amuLAyrT982lovRn7gnYUQAAACY"], referer: https://saifalkhaleejest.com/when-to-use-rotation-chain-hoists-over-standard-chain-hoists/
[Thu Jul 30 12:33:55.776605 2026] [security2:error] [pid 751901:tid 751955] [remote 114.119.156.134:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/citationstylelanguage/get/vancouver"] [unique_id "amuLAyrT982lovRn7gnYVgAAWTU"], referer: https://www.jipkl.com/index.php/JIPKL/article/view/6/version/6
[Thu Jul 30 12:33:55.860399 2026] [security2:error] [pid 751901:tid 752140] [client 57.141.0.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuLAyrT982lovRn7gnYSAAAAG0"]
[Thu Jul 30 12:33:56.047366 2026] [core:notice] [pid 751901:tid 752044] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:56.048808 2026] [security2:error] [pid 751901:tid 752042] [client 20.63.98.115:59010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/app.php"] [unique_id "amuLBCrT982lovRn7gnYXAAAAAs"]
[Thu Jul 30 12:33:56.052474 2026] [security2:error] [pid 751901:tid 752044] [client 103.215.74.26:42804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLBCrT982lovRn7gnYWwAAAA0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:56.102479 2026] [security2:error] [pid 751901:tid 751983] [remote 5.181.134.118:36868] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "serverkr.com"] [uri "/"] [unique_id "amuLBCrT982lovRn7gnYYQAAVFE"]
[Thu Jul 30 12:33:56.717152 2026] [security2:error] [pid 751901:tid 752047] [client 20.63.98.115:55351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/k.php"] [unique_id "amuLBCrT982lovRn7gnYcgAAABA"]
[Thu Jul 30 12:33:56.781013 2026] [core:notice] [pid 751901:tid 752135] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:56.785085 2026] [security2:error] [pid 751901:tid 752135] [client 103.215.74.26:42806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLBCrT982lovRn7gnYdgAAAGg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:57.531178 2026] [core:notice] [pid 751901:tid 752056] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:57.535165 2026] [security2:error] [pid 751901:tid 752056] [client 103.215.74.26:42812] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLBSrT982lovRn7gnYhQAAABk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:57.919170 2026] [security2:error] [pid 751901:tid 752123] [client 20.63.98.115:55313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-fmfile.php"] [unique_id "amuLBSrT982lovRn7gnYlQAAAFw"]
[Thu Jul 30 12:33:58.256569 2026] [core:notice] [pid 751901:tid 752065] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:58.260858 2026] [security2:error] [pid 751901:tid 752065] [client 103.215.74.26:42820] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLBirT982lovRn7gnYnAAAACI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:58.808873 2026] [core:notice] [pid 751901:tid 752033] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:58.977931 2026] [core:notice] [pid 751901:tid 752078] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:58.982404 2026] [security2:error] [pid 751901:tid 752078] [client 103.215.74.26:42836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLBirT982lovRn7gnYrAAAAC8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:59.556333 2026] [security2:error] [pid 751901:tid 752098] [client 114.119.137.64:21581] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.arabiantourz.com"] [uri "/soldes/homme-aigle-cytise-marine-manteaux/"] [unique_id "amuLByrT982lovRn7gnYvQAAAEM"], referer: http://www.arabiantourz.com/soldes/homme-pierre-cardin-danton-grisrougerose-chemises/
[Thu Jul 30 12:33:59.715340 2026] [core:notice] [pid 751901:tid 752149] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:59.719655 2026] [security2:error] [pid 751901:tid 752149] [client 103.215.74.26:42844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLByrT982lovRn7gnYwwAAAHY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:59.729476 2026] [security2:error] [pid 751901:tid 752088] [client 20.63.98.115:54783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wi.php"] [unique_id "amuLByrT982lovRn7gnYxAAAADk"]
[Thu Jul 30 12:34:00.863742 2026] [core:error] [pid 751901:tid 752095] [client 74.7.244.12:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:00.863764 2026] [core:error] [pid 751901:tid 752095] [client 74.7.244.12:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:00.863860 2026] [security2:error] [pid 751901:tid 752095] [client 74.7.244.12:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.jta.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "amuLCCrT982lovRn7gnY3wAAAEA"]
[Thu Jul 30 12:34:00.864584 2026] [security2:error] [pid 751901:tid 752140] [client 74.7.244.12:58354] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.jta.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "amuLCCrT982lovRn7gnY3QAAbXo"]
[Thu Jul 30 12:34:01.004703 2026] [security2:error] [pid 751901:tid 752065] [client 114.119.132.248:39343] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kingstarenterprises.com"] [uri "/product-category/gym-club-accessories/versa-grips"] [unique_id "amuLCSrT982lovRn7gnY4gAAACI"], referer: https://www.kingstarenterprises.com/product-category/gym-club-accessories/versa-grips?wc_view_mode=masonry_grid
[Thu Jul 30 12:34:01.285088 2026] [core:notice] [pid 751901:tid 752061] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:02.068592 2026] [security2:error] [pid 751901:tid 752062] [client 20.215.191.139:58721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/011i.php"] [unique_id "amuLCirT982lovRn7gnY_wAAAB8"]
[Thu Jul 30 12:34:02.312252 2026] [security2:error] [pid 751901:tid 752129] [client 2a03:2880:f800:1d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuLCSrT982lovRn7gnY9QAAYn8"]
[Thu Jul 30 12:34:02.437831 2026] [security2:error] [pid 751901:tid 752040] [client 114.119.136.138:46687] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabiandubaisafari.com"] [uri "/docs/5cfb7b-portsmouth-kit-20/5cfb7b-where-was-david-stirling-born"] [unique_id "amuLCirT982lovRn7gnZDAAAAAk"], referer: https://arabiandubaisafari.com/docs/5cfb7b-portsmouth-kit-20/5cfb7b-where-was-david-stirling-born
[Thu Jul 30 12:34:03.668131 2026] [security2:error] [pid 751901:tid 752130] [client 20.215.191.139:58939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/03a005685d.php"] [unique_id "amuLCyrT982lovRn7gnZLAAAAGM"]
[Thu Jul 30 12:34:03.804836 2026] [core:notice] [pid 751901:tid 752124] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:04.051291 2026] [core:error] [pid 751901:tid 752041] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:04.051318 2026] [core:error] [pid 751901:tid 752041] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:04.078649 2026] [core:error] [pid 751901:tid 752144] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:04.078675 2026] [core:error] [pid 751901:tid 752144] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:04.080370 2026] [core:error] [pid 751901:tid 752136] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:04.080390 2026] [core:error] [pid 751901:tid 752136] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:04.497669 2026] [security2:error] [pid 751901:tid 752075] [client 20.215.191.139:58936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/403.php"] [unique_id "amuLDCrT982lovRn7gnZVQAAACw"]
[Thu Jul 30 12:34:04.924302 2026] [security2:error] [pid 751901:tid 752126] [client 119.73.97.132:30603] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuLDCrT982lovRn7gnZXQAAXys"]
[Thu Jul 30 12:34:04.935744 2026] [security2:error] [pid 751901:tid 752126] [client 119.73.97.132:30603] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuLDCrT982lovRn7gnZXgAAXyM"]
[Thu Jul 30 12:34:05.573322 2026] [core:notice] [pid 751901:tid 752157] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:05.577342 2026] [security2:error] [pid 751901:tid 752157] [client 103.215.74.26:41284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLDSrT982lovRn7gnZdAAAAH4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:05.808629 2026] [mpm_event:notice] [pid 8929:tid 8929] AH00493: SIGUSR1 received. Doing graceful restart
[Thu Jul 30 12:34:06.093501 2026] [security2:error] [pid 751901:tid 752049] [client 20.63.98.115:59059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/php8.php"] [unique_id "amuLDirT982lovRn7gnZeQAAABI"]
[Thu Jul 30 12:34:06.893540 2026] [:notice] [pid 751894:tid 751894] [host root@sh00085.hostgator.com] mod_lsapi: Selfstarter 751894 stopped
[Thu Jul 30 12:34:09.254541 2026] [lsapi:notice] [pid 8929:tid 8929] mod_lsapi: version 1.1-92
[Thu Jul 30 12:34:09.257965 2026] [:notice] [pid 765150:tid 765150] [host root@sh00085.hostgator.com] mod_lsapi: Selfstarter 765150 started
[Thu Jul 30 12:34:09.639517 2026] [ssl:warn] [pid 8929:tid 8929] AH01909: localhost:8443:0 server certificate does NOT include an ID which matches the server name
[Thu Jul 30 12:34:09.646791 2026] [qos:notice] [pid 8929:tid 8929] mod_qos(007): calculated MaxClients/MaxRequestWorkers (max connections): 6144, applied limit: 2048 (QS_MaxClients)
[Thu Jul 30 12:34:09.817305 2026] [http2:info] [pid 8929:tid 8929] AH03090: mod_http2 (v2.0.42, feats=CHPRIO+SHA256+INVHD+DWINS, nghttp2 1.69.0), initializing...
[Thu Jul 30 12:34:09.820631 2026] [mpm_event:notice] [pid 8929:tid 8929] AH00489: Apache/2.4.68 (cPanel) OpenSSL/3.5.5 Apache mod_qos/11.76 mod_bwlimited/1.4 mod_fcgid/2.3.9 mod_rbld2.0 configured -- resuming normal operations
[Thu Jul 30 12:34:09.820658 2026] [core:notice] [pid 8929:tid 8929] AH00094: Command line: '/usr/sbin/httpd'
[Thu Jul 30 12:34:10.865952 2026] [http2:info] [pid 765155:tid 765155] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 12:34:11.115343 2026] [security2:error] [pid 765155:tid 765292] [client 114.119.150.252:63021] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabian-tours.com"] [uri "/site/mercedes-a-class-2020-56216b"] [unique_id "amuLE-T5hFAbD-LhWHh5hwAAAIw"], referer: https://arabian-tours.com/site/wli-waterfalls-56216b
[Thu Jul 30 12:34:11.130329 2026] [security2:error] [pid 765155:tid 765164] [remote 57.141.0.36:37218] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "thdinfinity.com"] [uri "/search/83915116186/feed/rss2/"] [unique_id "amuLE-T5hFAbD-LhWHh5jAAAlwg"]
[Thu Jul 30 12:34:11.133582 2026] [security2:error] [pid 765155:tid 765165] [remote 57.141.0.3:27846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/674008491/feed/rss2/"] [unique_id "amuLE-T5hFAbD-LhWHh5igAAmwk"]
[Thu Jul 30 12:34:11.133754 2026] [core:notice] [pid 765155:tid 765288] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:11.146363 2026] [security2:error] [pid 765155:tid 765288] [client 103.215.74.26:41300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLE-T5hFAbD-LhWHh5jwAAAIg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:11.342449 2026] [security2:error] [pid 765155:tid 765290] [client 20.215.191.139:56991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/404.php"] [unique_id "amuLE-T5hFAbD-LhWHh5ogAAAIo"]
[Thu Jul 30 12:34:11.501635 2026] [security2:error] [pid 765155:tid 765311] [client 38.190.144.4:57079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLE-T5hFAbD-LhWHh5qgAAAJ8"]
[Thu Jul 30 12:34:11.501848 2026] [security2:error] [pid 765155:tid 765311] [client 38.190.144.4:57079] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLE-T5hFAbD-LhWHh5qgAAAJ8"]
[Thu Jul 30 12:34:11.542289 2026] [security2:error] [pid 765155:tid 765296] [client 119.73.97.132:30657] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5ggAAkAI"], referer: https://www.urwru.club/emm-elevate/?preview_id=685&preview_nonce=6cdd8f071f&preview=true&aaeid=1
[Thu Jul 30 12:34:11.845028 2026] [log_config:warn] [pid 751901:tid 752055] (32)Broken pipe: [client 52.4.19.39:0] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --suffix=-bytes_log
[Thu Jul 30 12:34:11.845054 2026] [log_config:warn] [pid 751901:tid 752055] (32)Broken pipe: [client 52.4.19.39:0] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --mainout=/etc/apache2/logs/access_log
[Thu Jul 30 12:34:11.845675 2026] [log_config:warn] [pid 751901:tid 752093] (32)Broken pipe: [client 127.0.0.1:33678] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --suffix=-bytes_log
[Thu Jul 30 12:34:11.845697 2026] [log_config:warn] [pid 751901:tid 752093] (32)Broken pipe: [client 127.0.0.1:33678] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --mainout=/etc/apache2/logs/access_log
[Thu Jul 30 12:34:11.846024 2026] [log_config:warn] [pid 751901:tid 752137] (32)Broken pipe: [client 52.4.19.39:26859] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --suffix=-bytes_log
[Thu Jul 30 12:34:11.846043 2026] [log_config:warn] [pid 751901:tid 752137] (32)Broken pipe: [client 52.4.19.39:26859] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --mainout=/etc/apache2/logs/access_log
[Thu Jul 30 12:34:11.876331 2026] [core:notice] [pid 765155:tid 765391] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:11.884467 2026] [security2:error] [pid 765155:tid 765391] [client 103.215.74.26:41314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLE-T5hFAbD-LhWHh5vAAAAO8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:11.960364 2026] [security2:error] [pid 765155:tid 765357] [client 57.141.0.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5mgAAAM0"]
[Thu Jul 30 12:34:11.981146 2026] [log_config:warn] [pid 751901:tid 752149] (32)Broken pipe: [client 44.213.206.96:0] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --suffix=-bytes_log
[Thu Jul 30 12:34:11.981169 2026] [log_config:warn] [pid 751901:tid 752149] (32)Broken pipe: [client 44.213.206.96:0] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --mainout=/etc/apache2/logs/access_log
[Thu Jul 30 12:34:11.996205 2026] [security2:error] [pid 765155:tid 765404] [client 20.215.191.139:59509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/aa.php"] [unique_id "amuLE-T5hFAbD-LhWHh5vgAAAPw"]
[Thu Jul 30 12:34:12.013366 2026] [log_config:warn] [pid 751901:tid 752098] (32)Broken pipe: [client 127.0.0.1:33694] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --suffix=-bytes_log
[Thu Jul 30 12:34:12.013390 2026] [log_config:warn] [pid 751901:tid 752098] (32)Broken pipe: [client 127.0.0.1:33694] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --mainout=/etc/apache2/logs/access_log
[Thu Jul 30 12:34:12.048247 2026] [security2:error] [pid 765155:tid 765339] [client 114.119.156.165:63545] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/shop/page/4/"] [unique_id "amuLFOT5hFAbD-LhWHh5vwAAALs"], referer: https://kicksity.com/shop/?min_price=140&max_price=280&filtering=1&filter_product_cat=166%2C210%2C192%2C236%2C137%2C146
[Thu Jul 30 12:34:12.340263 2026] [log_config:warn] [pid 751901:tid 752058] (32)Broken pipe: [client 44.213.206.96:41876] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --suffix=-bytes_log
[Thu Jul 30 12:34:12.340293 2026] [log_config:warn] [pid 751901:tid 752058] (32)Broken pipe: [client 44.213.206.96:41876] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --mainout=/etc/apache2/logs/access_log
[Thu Jul 30 12:34:12.398538 2026] [security2:error] [pid 765155:tid 765298] [client 172.237.109.114:37443] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5cgAAAJI"]
[Thu Jul 30 12:34:12.416946 2026] [security2:error] [pid 765155:tid 765312] [client 172.237.109.114:17228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5dQAAAKA"]
[Thu Jul 30 12:34:12.448557 2026] [security2:error] [pid 765155:tid 765304] [client 172.237.109.114:42931] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLEuT5hFAbD-LhWHh5cAAAAJg"]
[Thu Jul 30 12:34:12.459939 2026] [security2:error] [pid 765155:tid 765322] [client 172.237.109.114:36859] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5egAAAKo"]
[Thu Jul 30 12:34:12.524113 2026] [security2:error] [pid 765155:tid 765308] [client 172.237.109.114:60661] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5cQAAAJw"]
[Thu Jul 30 12:34:12.602020 2026] [security2:error] [pid 765155:tid 765315] [client 172.237.109.114:2955] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5eQAAAKM"]
[Thu Jul 30 12:34:12.609175 2026] [core:notice] [pid 765155:tid 765294] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:12.612575 2026] [security2:error] [pid 765155:tid 765320] [client 172.237.109.114:59971] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5cwAAAKg"]
[Thu Jul 30 12:34:12.612812 2026] [security2:error] [pid 765155:tid 765323] [client 172.237.109.114:19417] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5ewAAAKs"]
[Thu Jul 30 12:34:12.618939 2026] [security2:error] [pid 765155:tid 765294] [client 103.215.74.26:41324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLFOT5hFAbD-LhWHh5zQAAAI4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:12.659090 2026] [security2:error] [pid 765155:tid 765306] [client 172.237.109.114:48409] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLEuT5hFAbD-LhWHh5bwAAAJo"]
[Thu Jul 30 12:34:12.673681 2026] [security2:error] [pid 765155:tid 765329] [client 172.237.109.114:58263] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5fgAAALE"]
[Thu Jul 30 12:34:12.682748 2026] [security2:error] [pid 765155:tid 765302] [client 172.237.109.114:58604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLEuT5hFAbD-LhWHh5bgAAAJY"]
[Thu Jul 30 12:34:12.683947 2026] [security2:error] [pid 765155:tid 765316] [client 172.237.109.114:56570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5eAAAAKQ"]
[Thu Jul 30 12:34:12.737102 2026] [security2:error] [pid 765155:tid 765351] [client 14.116.236.91:18907] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/static/favicon.ico"] [unique_id "amuLFOT5hFAbD-LhWHh51QAAAMc"]
[Thu Jul 30 12:34:12.796439 2026] [security2:error] [pid 765155:tid 765354] [client 20.215.191.139:59504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/aafewc0k.php"] [unique_id "amuLFOT5hFAbD-LhWHh52AAAAMo"]
[Thu Jul 30 12:34:13.088232 2026] [security2:error] [pid 765155:tid 765392] [client 14.116.236.91:35617] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/icon/favicon.ico"] [unique_id "amuLFeT5hFAbD-LhWHh53AAAAPA"]
[Thu Jul 30 12:34:13.091227 2026] [security2:error] [pid 765155:tid 765401] [client 14.116.236.91:58139] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/img/favicon.ico"] [unique_id "amuLFeT5hFAbD-LhWHh53QAAAPk"]
[Thu Jul 30 12:34:13.092963 2026] [security2:error] [pid 765155:tid 765406] [client 14.116.236.91:35615] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/favicon.ico"] [unique_id "amuLFeT5hFAbD-LhWHh53gAAAP4"]
[Thu Jul 30 12:34:13.093759 2026] [security2:error] [pid 765155:tid 765398] [client 14.116.236.91:58138] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/favicon.png"] [unique_id "amuLFeT5hFAbD-LhWHh53wAAAPY"]
[Thu Jul 30 12:34:13.117949 2026] [security2:error] [pid 765155:tid 765407] [client 14.116.236.91:13472] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/images/favicon.ico"] [unique_id "amuLFeT5hFAbD-LhWHh54AAAAP8"]
[Thu Jul 30 12:34:13.242439 2026] [security2:error] [pid 765155:tid 765321] [client 172.237.109.114:25290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5dgAAAKk"]
[Thu Jul 30 12:34:13.243055 2026] [security2:error] [pid 765155:tid 765314] [client 172.237.109.114:5514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5dwAAAKI"]
[Thu Jul 30 12:34:13.248286 2026] [security2:error] [pid 765155:tid 765336] [client 172.237.109.114:55148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5iAAAALg"]
[Thu Jul 30 12:34:13.250446 2026] [security2:error] [pid 765155:tid 765317] [client 172.237.109.114:40842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5fAAAAKU"]
[Thu Jul 30 12:34:13.281542 2026] [security2:error] [pid 765155:tid 765310] [client 172.237.109.114:22794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5dAAAAJ4"]
[Thu Jul 30 12:34:13.306629 2026] [security2:error] [pid 765155:tid 765333] [client 172.237.109.114:38839] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5gwAAALU"]
[Thu Jul 30 12:34:13.338230 2026] [core:notice] [pid 765155:tid 765408] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:13.340131 2026] [security2:error] [pid 765155:tid 765300] [client 2a03:2880:f800:3d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5mwAAlAs"]
[Thu Jul 30 12:34:13.346785 2026] [security2:error] [pid 765155:tid 765408] [client 103.215.74.26:18598] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLFeT5hFAbD-LhWHh56gAAAQA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:13.375490 2026] [security2:error] [pid 765155:tid 765332] [client 172.237.109.114:22079] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5gAAAALQ"]
[Thu Jul 30 12:34:13.384108 2026] [security2:error] [pid 765155:tid 765330] [client 172.237.109.114:1410] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5fwAAALI"]
[Thu Jul 30 12:34:13.500107 2026] [core:notice] [pid 765155:tid 765303] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:13.500953 2026] [security2:error] [pid 765155:tid 765353] [client 2a03:2880:f800:42:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5qwAAyQ4"]
[Thu Jul 30 12:34:13.736957 2026] [security2:error] [pid 765155:tid 765345] [client 20.215.191.139:57023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/abcd.php"] [unique_id "amuLFeT5hFAbD-LhWHh59QAAAME"]
[Thu Jul 30 12:34:13.778048 2026] [security2:error] [pid 765155:tid 765326] [client 77.54.86.207:42294] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.woff2"] [unique_id "amuLFeT5hFAbD-LhWHh5-QAAAK4"]
[Thu Jul 30 12:34:13.838842 2026] [security2:error] [pid 765155:tid 765325] [client 77.183.60.157:52966] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.woff"] [unique_id "amuLFeT5hFAbD-LhWHh5-gAAAK0"]
[Thu Jul 30 12:34:13.839815 2026] [security2:error] [pid 765155:tid 765331] [client 43.173.182.51:38660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.182.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/11/22/a-ne-pas-manquer-ce-week-end-le-salon-creations-savoir-faire-marie-claire-idees/"] [unique_id "amuLFeT5hFAbD-LhWHh57AAAALM"]
[Thu Jul 30 12:34:13.918319 2026] [security2:error] [pid 765155:tid 765295] [client 86.183.74.14:36748] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.ttf"] [unique_id "amuLFeT5hFAbD-LhWHh5-wAAAI8"]
[Thu Jul 30 12:34:13.953141 2026] [core:error] [pid 765155:tid 765379] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:13.953165 2026] [core:error] [pid 765155:tid 765379] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:13.955434 2026] [core:error] [pid 765155:tid 765297] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:13.955456 2026] [core:error] [pid 765155:tid 765297] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:14.029934 2026] [core:error] [pid 765155:tid 765389] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:14.029962 2026] [core:error] [pid 765155:tid 765389] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:14.056738 2026] [security2:error] [pid 765155:tid 765304] [client 49.230.178.14:5826] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.eot"] [unique_id "amuLFuT5hFAbD-LhWHh6DgAAAJg"]
[Thu Jul 30 12:34:14.060186 2026] [core:notice] [pid 765155:tid 765377] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:14.065324 2026] [security2:error] [pid 765155:tid 765377] [client 103.215.74.26:18608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLFuT5hFAbD-LhWHh6DwAAAOE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:14.148079 2026] [security2:error] [pid 765155:tid 765393] [client 14.116.236.91:35616] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/assets/favicon.ico"] [unique_id "amuLFuT5hFAbD-LhWHh6EQAAAPE"]
[Thu Jul 30 12:34:14.260141 2026] [security2:error] [pid 765155:tid 765344] [client 57.141.0.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuLFeT5hFAbD-LhWHh57wAAAMA"]
[Thu Jul 30 12:34:14.402783 2026] [security2:error] [pid 765155:tid 765359] [client 99.232.160.131:50866] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.eot"] [unique_id "amuLFuT5hFAbD-LhWHh6HAAAAM8"]
[Thu Jul 30 12:34:14.488380 2026] [security2:error] [pid 765155:tid 765299] [client 20.63.98.115:54766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/tes.php"] [unique_id "amuLFuT5hFAbD-LhWHh6IAAAAJM"]
[Thu Jul 30 12:34:14.527799 2026] [core:notice] [pid 765155:tid 765328] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:14.533668 2026] [security2:error] [pid 765155:tid 765328] [client 43.173.182.74:59750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/11/22/a-ne-pas-manquer-ce-week-end-le-salon-creations-savoir-faire-marie-claire-idees/"] [unique_id "amuLFuT5hFAbD-LhWHh6IQAAALA"], referer: https://carnetdeshopping.com/index.php/2012/11/22/a-ne-pas-manquer-ce-week-end-le-salon-creations-savoir-faire-marie-claire-idees/
[Thu Jul 30 12:34:14.636970 2026] [security2:error] [pid 765155:tid 765367] [client 93.45.55.61:33994] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.eot"] [unique_id "amuLFuT5hFAbD-LhWHh6JAAAANc"]
[Thu Jul 30 12:34:14.758410 2026] [security2:error] [pid 765155:tid 765383] [client 85.86.218.110:3038] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.ttf"] [unique_id "amuLFuT5hFAbD-LhWHh6KgAAAOc"]
[Thu Jul 30 12:34:14.804035 2026] [core:notice] [pid 765155:tid 765327] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:14.809177 2026] [security2:error] [pid 765155:tid 765327] [client 103.215.74.26:18620] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLFuT5hFAbD-LhWHh6LgAAAK8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:14.943780 2026] [security2:error] [pid 765155:tid 765293] [client 82.39.7.236:53208] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.eot"] [unique_id "amuLFuT5hFAbD-LhWHh6MgAAAI0"]
[Thu Jul 30 12:34:15.068347 2026] [security2:error] [pid 765155:tid 765330] [client 90.195.134.120:56748] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.woff"] [unique_id "amuLF-T5hFAbD-LhWHh6MwAAALI"]
[Thu Jul 30 12:34:15.153236 2026] [security2:error] [pid 765155:tid 765302] [client 114.119.128.5:39751] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pkf.jo"] [uri "/careers"] [unique_id "amuLF-T5hFAbD-LhWHh6NQAAAJY"], referer: https://pkf.jo/careers?id=6023<id=4
[Thu Jul 30 12:34:15.246814 2026] [proxy:error] [pid 765155:tid 765287] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:34:15.247032 2026] [proxy_http:error] [pid 765155:tid 765287] [client 52.4.19.39:57687] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:34:15.247601 2026] [proxy:error] [pid 765155:tid 765287] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:34:15.247644 2026] [proxy_http:error] [pid 765155:tid 765287] [client 52.4.19.39:57687] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:34:15.294719 2026] [proxy:error] [pid 765155:tid 765296] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:34:15.294792 2026] [proxy_http:error] [pid 765155:tid 765296] [client 3.225.222.228:55949] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:34:15.295558 2026] [proxy:error] [pid 765155:tid 765296] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:34:15.295610 2026] [proxy_http:error] [pid 765155:tid 765296] [client 3.225.222.228:55949] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:34:15.471304 2026] [security2:error] [pid 765155:tid 765325] [client 88.182.238.108:22763] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.eot"] [unique_id "amuLF-T5hFAbD-LhWHh6QQAAAK0"]
[Thu Jul 30 12:34:15.545338 2026] [core:notice] [pid 765155:tid 765384] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:15.553353 2026] [security2:error] [pid 765155:tid 765384] [client 103.215.74.26:18630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "756"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLF-T5hFAbD-LhWHh6RAAAAOg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:15.631965 2026] [security2:error] [pid 765155:tid 765373] [client 46.189.233.91:56768] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.woff"] [unique_id "amuLF-T5hFAbD-LhWHh6RQAAAN0"]
[Thu Jul 30 12:34:15.698266 2026] [security2:error] [pid 765155:tid 765311] [client 77.54.239.38:38500] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.eot"] [unique_id "amuLF-T5hFAbD-LhWHh6RgAAAJ8"]
[Thu Jul 30 12:34:15.871478 2026] [security2:error] [pid 765155:tid 765306] [client 71.17.135.58:37210] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.eot"] [unique_id "amuLF-T5hFAbD-LhWHh6TgAAAJo"]
[Thu Jul 30 12:34:16.077685 2026] [security2:error] [pid 765155:tid 765297] [client 86.52.147.166:29823] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.eot"] [unique_id "amuLGOT5hFAbD-LhWHh6VQAAAJE"]
[Thu Jul 30 12:34:16.161133 2026] [security2:error] [pid 765155:tid 765400] [client 178.121.27.193:5006] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.eot"] [unique_id "amuLGOT5hFAbD-LhWHh6WAAAAPg"]
[Thu Jul 30 12:34:16.285572 2026] [security2:error] [pid 765155:tid 765403] [client 159.0.44.24:36882] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.woff"] [unique_id "amuLGOT5hFAbD-LhWHh6XQAAAPs"]
[Thu Jul 30 12:34:16.289781 2026] [core:notice] [pid 765155:tid 765349] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:16.296393 2026] [security2:error] [pid 765155:tid 765349] [client 103.215.74.26:18634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLGOT5hFAbD-LhWHh6XgAAAMU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:16.513488 2026] [security2:error] [pid 765155:tid 765397] [client 156.206.158.45:46408] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.woff"] [unique_id "amuLGOT5hFAbD-LhWHh6bAAAAPU"]
[Thu Jul 30 12:34:16.644520 2026] [security2:error] [pid 765155:tid 765398] [client 105.165.10.218:41688] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.ttf"] [unique_id "amuLGOT5hFAbD-LhWHh6cAAAAPY"]
[Thu Jul 30 12:34:16.703616 2026] [security2:error] [pid 765155:tid 765328] [client 103.26.86.38:61414] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.eot"] [unique_id "amuLGOT5hFAbD-LhWHh6cgAAALA"]
[Thu Jul 30 12:34:16.873574 2026] [security2:error] [pid 765155:tid 765291] [client 203.145.36.214:54980] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.woff"] [unique_id "amuLGOT5hFAbD-LhWHh6eQAAAIs"]
[Thu Jul 30 12:34:16.987778 2026] [security2:error] [pid 765155:tid 765391] [client 177.162.106.40:42904] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.eot"] [unique_id "amuLGOT5hFAbD-LhWHh6gQAAAO8"]
[Thu Jul 30 12:34:17.028827 2026] [core:notice] [pid 765155:tid 765332] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:17.033774 2026] [security2:error] [pid 765155:tid 765332] [client 103.215.74.26:18648] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLGeT5hFAbD-LhWHh6gwAAALQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:17.064593 2026] [security2:error] [pid 765155:tid 765392] [client 169.224.1.197:15382] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.eot"] [unique_id "amuLGeT5hFAbD-LhWHh6hAAAAPA"]
[Thu Jul 30 12:34:17.158036 2026] [security2:error] [pid 765155:tid 765402] [client 213.230.87.113:10791] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.eot"] [unique_id "amuLGeT5hFAbD-LhWHh6hQAAAPo"]
[Thu Jul 30 12:34:17.173331 2026] [security2:error] [pid 765155:tid 765288] [client 200.141.34.83:35032] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.eot"] [unique_id "amuLGeT5hFAbD-LhWHh6hgAAAIg"]
[Thu Jul 30 12:34:17.346219 2026] [security2:error] [pid 765155:tid 765303] [client 193.47.62.167:41648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worldofwhiskers.com"] [uri "/index.php"] [unique_id "amuLGOT5hFAbD-LhWHh6VwAAAJc"]
[Thu Jul 30 12:34:17.419525 2026] [security2:error] [pid 765155:tid 765362] [client 138.121.3.240:35895] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.ttf"] [unique_id "amuLGeT5hFAbD-LhWHh6jwAAANI"]
[Thu Jul 30 12:34:17.464528 2026] [security2:error] [pid 765155:tid 765318] [client 88.241.178.129:37476] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.eot"] [unique_id "amuLGeT5hFAbD-LhWHh6kwAAAKY"]
[Thu Jul 30 12:34:17.724539 2026] [log_config:warn] [pid 751901:tid 752058] (32)Broken pipe: [client 119.73.97.132:30603] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --suffix=-bytes_log, referer: https://www.urwru.club/emm-elevate/?preview_id=685&preview_nonce=6cdd8f071f&preview=true&aaeid=1
[Thu Jul 30 12:34:17.724561 2026] [log_config:warn] [pid 751901:tid 752058] (32)Broken pipe: [client 119.73.97.132:30603] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --mainout=/etc/apache2/logs/access_log, referer: https://www.urwru.club/emm-elevate/?preview_id=685&preview_nonce=6cdd8f071f&preview=true&aaeid=1
[Thu Jul 30 12:34:17.786341 2026] [core:notice] [pid 765155:tid 765358] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:17.793556 2026] [security2:error] [pid 765155:tid 765358] [client 103.215.74.26:18652] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLGeT5hFAbD-LhWHh6lQAAAM4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:17.841931 2026] [core:error] [pid 765155:tid 765389] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:17.841952 2026] [core:error] [pid 765155:tid 765389] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:17.961384 2026] [security2:error] [pid 765155:tid 765360] [client 201.141.29.93:34442] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.ttf"] [unique_id "amuLGeT5hFAbD-LhWHh6nQAAANA"]
[Thu Jul 30 12:34:17.982282 2026] [security2:error] [pid 765155:tid 765229] [remote 40.77.167.4:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/jipkl/article/view/107/105"] [unique_id "amuLGeT5hFAbD-LhWHh6ogAAsUk"]
[Thu Jul 30 12:34:18.021194 2026] [security2:error] [pid 765155:tid 765336] [client 31.206.13.16:54368] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.ttf"] [unique_id "amuLGuT5hFAbD-LhWHh6pQAAALg"]
[Thu Jul 30 12:34:18.088581 2026] [security2:error] [pid 765155:tid 765405] [client 20.215.191.139:50199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/about.php"] [unique_id "amuLGuT5hFAbD-LhWHh6pwAAAP0"]
[Thu Jul 30 12:34:18.525274 2026] [core:notice] [pid 765155:tid 765410] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:18.533037 2026] [security2:error] [pid 765155:tid 765410] [client 103.215.74.26:18658] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLGuT5hFAbD-LhWHh6tQAAAQI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:18.895193 2026] [security2:error] [pid 765155:tid 765347] [client 216.234.209.67:40379] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.ttf"] [unique_id "amuLGuT5hFAbD-LhWHh6wAAAAMM"]
[Thu Jul 30 12:34:19.248118 2026] [core:notice] [pid 765155:tid 765366] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:19.252386 2026] [security2:error] [pid 765155:tid 765366] [client 103.215.74.26:18660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLG-T5hFAbD-LhWHh6ywAAANY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:19.890316 2026] [security2:error] [pid 765155:tid 765324] [client 188.253.218.64:15811] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.woff2"] [unique_id "amuLG-T5hFAbD-LhWHh66QAAAKw"]
[Thu Jul 30 12:34:20.146563 2026] [security2:error] [pid 765155:tid 765402] [client 20.215.191.139:59086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/admin.php"] [unique_id "amuLHOT5hFAbD-LhWHh69gAAAPo"]
[Thu Jul 30 12:34:20.412260 2026] [security2:error] [pid 765155:tid 765303] [client 130.193.252.121:34618] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.ttf"] [unique_id "amuLHOT5hFAbD-LhWHh6-QAAAJc"]
[Thu Jul 30 12:34:20.431834 2026] [security2:error] [pid 765155:tid 765405] [client 57.141.0.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuLG-T5hFAbD-LhWHh66AAAAP0"]
[Thu Jul 30 12:34:20.712099 2026] [security2:error] [pid 765155:tid 765401] [client 88.224.16.100:43458] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.woff"] [unique_id "amuLHOT5hFAbD-LhWHh7BAAAAPk"]
[Thu Jul 30 12:34:20.844689 2026] [security2:error] [pid 765155:tid 765407] [client 20.215.191.139:50179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/adminfuns.php"] [unique_id "amuLHOT5hFAbD-LhWHh7BgAAAP8"]
[Thu Jul 30 12:34:21.221007 2026] [security2:error] [pid 765155:tid 765378] [client 20.63.98.115:57239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/about.php"] [unique_id "amuLHeT5hFAbD-LhWHh7DgAAAOI"]
[Thu Jul 30 12:34:21.423704 2026] [security2:error] [pid 765155:tid 765290] [client 114.119.135.199:35539] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "online-hope.com"] [uri "/product-tag/marlboro%E8%90%AC%E5%AF%B6%E8%B7%AF%E9%A6%99%E7%85%99%E4%B8%AD%E7%B4%94%E7%B4%85%E8%90%AC%E6%97%A5%E6%9C%AC%E6%9C%AC%E5%9C%9F%E5%85%8D%E7%A8%85%E9%A6%99%E6%B8%AF%E7%8F%BE%E8%B2%A8/"] [unique_id "amuLHeT5hFAbD-LhWHh7GgAAAIo"], referer: https://online-hope.com/product-tag/marlboro%E8%90%AC%E5%AF%B6%E8%B7%AF%E9%A6%99%E7%85%99%E4%B8%AD%E7%B4%94%E7%B4%85%E8%90%AC%E6%97%A5%E6%9C%AC%E6%9C%AC%E5%9C%9F%E5%85%8D%E7%A8%85%E9%A6%99%E6%B8%AF%E7%8F%BE%E8%B2%A8/
[Thu Jul 30 12:34:21.624902 2026] [security2:error] [pid 765155:tid 765272] [remote 57.141.0.1:40806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuLHeT5hFAbD-LhWHh7EgAA53Q"]
[Thu Jul 30 12:34:21.805612 2026] [core:notice] [pid 765155:tid 765355] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:22.096371 2026] [security2:error] [pid 765155:tid 765320] [client 20.215.191.139:59076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/albin.php"] [unique_id "amuLHuT5hFAbD-LhWHh7JQAAAKg"]
[Thu Jul 30 12:34:22.156323 2026] [security2:error] [pid 765155:tid 765304] [client 20.63.98.115:63471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/headers.php"] [unique_id "amuLHuT5hFAbD-LhWHh7JgAAAJg"]
[Thu Jul 30 12:34:23.303666 2026] [security2:error] [pid 765155:tid 765359] [client 20.215.191.139:50184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/amfsqvgv.php"] [unique_id "amuLH-T5hFAbD-LhWHh7RQAAAM8"]
[Thu Jul 30 12:34:23.425241 2026] [security2:error] [pid 765155:tid 765354] [client 82.132.233.218:23292] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.woff"] [unique_id "amuLH-T5hFAbD-LhWHh7SAAAAMo"]
[Thu Jul 30 12:34:23.437745 2026] [security2:error] [pid 765155:tid 765410] [client 114.119.128.5:41775] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toscanamall.com"] [uri "/hz/reviews-render/report-review"] [unique_id "amuLH-T5hFAbD-LhWHh7SQAAAQI"], referer: http://www.bedandbreakfast-skye.com/
[Thu Jul 30 12:34:23.468167 2026] [core:error] [pid 765155:tid 765160] [remote 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:23.468188 2026] [core:error] [pid 765155:tid 765160] [remote 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:23.505545 2026] [core:error] [pid 765155:tid 765164] [remote 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:23.505563 2026] [core:error] [pid 765155:tid 765164] [remote 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:23.561867 2026] [core:error] [pid 765155:tid 765171] [remote 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:23.561887 2026] [core:error] [pid 765155:tid 765171] [remote 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:23.568090 2026] [core:error] [pid 765155:tid 765174] [remote 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:23.568110 2026] [core:error] [pid 765155:tid 765174] [remote 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:23.620655 2026] [core:error] [pid 765155:tid 765172] [remote 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:23.620681 2026] [core:error] [pid 765155:tid 765172] [remote 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:23.664293 2026] [core:error] [pid 765155:tid 765175] [remote 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:23.664326 2026] [core:error] [pid 765155:tid 765175] [remote 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:24.092960 2026] [security2:error] [pid 765155:tid 765340] [client 20.215.191.139:59089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/ant.php"] [unique_id "amuLIOT5hFAbD-LhWHh7XwAAALw"]
[Thu Jul 30 12:34:24.872726 2026] [security2:error] [pid 765155:tid 765373] [client 107.170.60.13:33548] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.vertexroofsolutions.com"] [uri "/.env"] [unique_id "amuLIOT5hFAbD-LhWHh7cQAAAN0"]
[Thu Jul 30 12:34:24.961293 2026] [core:notice] [pid 765155:tid 765344] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:24.965697 2026] [security2:error] [pid 765155:tid 765344] [client 103.215.74.26:7176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "772"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLIOT5hFAbD-LhWHh7dgAAAMA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:25.331802 2026] [security2:error] [pid 765155:tid 765301] [client 20.63.98.115:20923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/admin.php"] [unique_id "amuLIeT5hFAbD-LhWHh7fQAAAJU"]
[Thu Jul 30 12:34:25.685361 2026] [core:notice] [pid 765155:tid 765285] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:25.693065 2026] [security2:error] [pid 765155:tid 765285] [client 103.215.74.26:7180] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLIeT5hFAbD-LhWHh7gwAAAIU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:25.832239 2026] [security2:error] [pid 765155:tid 765377] [client 57.141.0.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuLIeT5hFAbD-LhWHh7fAAAAOE"]
[Thu Jul 30 12:34:26.265418 2026] [security2:error] [pid 765155:tid 765375] [client 20.215.191.139:59912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/appreciators.php"] [unique_id "amuLIuT5hFAbD-LhWHh7jQAAAN8"]
[Thu Jul 30 12:34:26.420476 2026] [core:notice] [pid 765155:tid 765323] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:26.425458 2026] [security2:error] [pid 765155:tid 765323] [client 103.215.74.26:7188] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "785"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLIuT5hFAbD-LhWHh7lAAAAKs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:26.960385 2026] [security2:error] [pid 765155:tid 765319] [client 20.215.191.139:50198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/archive.php"] [unique_id "amuLIuT5hFAbD-LhWHh7qAAAAKc"]
[Thu Jul 30 12:34:27.164018 2026] [core:notice] [pid 765155:tid 765336] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:27.168909 2026] [security2:error] [pid 765155:tid 765336] [client 103.215.74.26:7194] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLI-T5hFAbD-LhWHh7sAAAALg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:28.170707 2026] [security2:error] [pid 765155:tid 765402] [client 20.215.191.139:50208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/as.php"] [unique_id "amuLJOT5hFAbD-LhWHh7yAAAAPo"]
[Thu Jul 30 12:34:28.461454 2026] [security2:error] [pid 765155:tid 765353] [client 20.63.98.115:20881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/flower.php"] [unique_id "amuLJOT5hFAbD-LhWHh70QAAAMk"]
[Thu Jul 30 12:34:28.787773 2026] [security2:error] [pid 765155:tid 765352] [client 20.215.191.139:59116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/atomlib.php"] [unique_id "amuLJOT5hFAbD-LhWHh73AAAAMg"]
[Thu Jul 30 12:34:29.311732 2026] [security2:error] [pid 765155:tid 765336] [client 20.63.98.115:20904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "amuLJeT5hFAbD-LhWHh73gAAALg"]
[Thu Jul 30 12:34:30.025538 2026] [core:notice] [pid 765155:tid 765225] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:30.254032 2026] [security2:error] [pid 765155:tid 765223] [remote 14.116.236.91:55064] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/static/favicon.ico"] [unique_id "amuLJuT5hFAbD-LhWHh79gAAoUM"]
[Thu Jul 30 12:34:30.254128 2026] [security2:error] [pid 765155:tid 765228] [remote 14.116.236.91:55064] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/favicon.png"] [unique_id "amuLJuT5hFAbD-LhWHh79QAAoUg"]
[Thu Jul 30 12:34:30.682721 2026] [security2:error] [pid 765155:tid 765296] [client 20.63.98.115:20917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content.php"] [unique_id "amuLJuT5hFAbD-LhWHh8KgAAAJA"]
[Thu Jul 30 12:34:30.697560 2026] [security2:error] [pid 765155:tid 765277] [remote 114.119.147.137:53307] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dhowcruisedinner.com"] [uri "/JbcYdA/where-is-fox-sports-undisputed-filmed"] [unique_id "amuLJuT5hFAbD-LhWHh8KwAAmnk"]
[Thu Jul 30 12:34:30.729413 2026] [fcgid:warn] [pid 765155:tid 765400] (70014)End of file found: [client 152.32.142.138:33464] mod_fcgid: can't get data from http client
[Thu Jul 30 12:34:32.632627 2026] [security2:error] [pid 765155:tid 765371] [client 38.190.144.4:58275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLKOT5hFAbD-LhWHh8XAAAANs"]
[Thu Jul 30 12:34:32.633182 2026] [security2:error] [pid 765155:tid 765371] [client 38.190.144.4:58275] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLKOT5hFAbD-LhWHh8XAAAANs"]
[Thu Jul 30 12:34:32.939800 2026] [core:notice] [pid 765155:tid 765389] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:32.944834 2026] [security2:error] [pid 765155:tid 765389] [client 103.215.74.26:7204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLKOT5hFAbD-LhWHh8YwAAAO0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:32.955639 2026] [security2:error] [pid 765155:tid 765306] [client 114.119.149.65:58219] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "fireworkskenya.co.ke"] [uri "/our-products/consumer-fireworks/helicopters/"] [unique_id "amuLKOT5hFAbD-LhWHh8ZAAAAJo"], referer: https://fireworkskenya.co.ke/our-products/consumer-fireworks/helicopters/
[Thu Jul 30 12:34:33.167823 2026] [autoindex:error] [pid 765155:tid 765356] [client 49.51.180.2:34764] AH01276: Cannot serve directory /home1/vdbnyxte/public_html/website_19d94cc7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:34:33.676014 2026] [core:notice] [pid 765155:tid 765298] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:33.681147 2026] [security2:error] [pid 765155:tid 765298] [client 103.215.74.26:33898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "765"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLKeT5hFAbD-LhWHh8cwAAAJI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:34.180535 2026] [core:error] [pid 765155:tid 765382] [client 74.7.244.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:34.180557 2026] [core:error] [pid 765155:tid 765382] [client 74.7.244.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:34.180678 2026] [security2:error] [pid 765155:tid 765382] [client 74.7.244.62:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.brx.dtn.temporary.site"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "amuLKuT5hFAbD-LhWHh8fwAAAOY"]
[Thu Jul 30 12:34:34.181224 2026] [security2:error] [pid 765155:tid 765398] [client 74.7.244.62:51902] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.brx.dtn.temporary.site"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuLKuT5hFAbD-LhWHh8fQAA9gY"]
[Thu Jul 30 12:34:34.419711 2026] [core:notice] [pid 765155:tid 765331] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:34.424246 2026] [security2:error] [pid 765155:tid 765331] [client 103.215.74.26:33900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLKuT5hFAbD-LhWHh8hQAAALM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:34.939562 2026] [lsapi:error] [pid 751901:tid 751993] [remote 41.210.167.242:0] [host flixon.net] Error receiving response: ReceiveResponse: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1009; user ID 1009), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://flixon.net/video/the-killer-vj-junior/
[Thu Jul 30 12:34:34.941045 2026] [log_config:warn] [pid 751901:tid 752058] (32)Broken pipe: [client 41.210.167.242:0] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --suffix=-bytes_log, referer: https://flixon.net/video/the-killer-vj-junior/
[Thu Jul 30 12:34:34.941061 2026] [log_config:warn] [pid 751901:tid 752058] (32)Broken pipe: [client 41.210.167.242:0] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --mainout=/etc/apache2/logs/access_log, referer: https://flixon.net/video/the-killer-vj-junior/
[Thu Jul 30 12:34:35.144780 2026] [core:notice] [pid 765155:tid 765371] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:35.149877 2026] [security2:error] [pid 765155:tid 765371] [client 103.215.74.26:33916] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLK-T5hFAbD-LhWHh8mwAAANs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:35.271956 2026] [security2:error] [pid 765155:tid 765378] [client 74.7.228.15:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-26e591d8.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuLKuT5hFAbD-LhWHh8kwAAAOI"]
[Thu Jul 30 12:34:35.272653 2026] [security2:error] [pid 765155:tid 765367] [client 74.7.228.15:37978] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-26e591d8.glb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuLKuT5hFAbD-LhWHh8kQAA1wc"]
[Thu Jul 30 12:34:35.400995 2026] [security2:error] [pid 765155:tid 765390] [client 20.215.191.139:60321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/autoload_classmap.php"] [unique_id "amuLK-T5hFAbD-LhWHh8oAAAAO4"]
[Thu Jul 30 12:34:35.556759 2026] [log_config:warn] [pid 751901:tid 752155] (32)Broken pipe: [client 119.73.97.132:30603] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --suffix=-bytes_log, referer: https://www.urwru.club/emm-elevate/?preview_id=685&preview_nonce=6cdd8f071f&preview=true&aaeid=1
[Thu Jul 30 12:34:35.556782 2026] [log_config:warn] [pid 751901:tid 752155] (32)Broken pipe: [client 119.73.97.132:30603] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --mainout=/etc/apache2/logs/access_log, referer: https://www.urwru.club/emm-elevate/?preview_id=685&preview_nonce=6cdd8f071f&preview=true&aaeid=1
[Thu Jul 30 12:34:35.885520 2026] [core:notice] [pid 765155:tid 765364] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:35.890524 2026] [security2:error] [pid 765155:tid 765364] [client 103.215.74.26:33918] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLK-T5hFAbD-LhWHh8qAAAANQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:36.487471 2026] [security2:error] [pid 765155:tid 765403] [client 20.215.191.139:60287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/bb.php"] [unique_id "amuLLOT5hFAbD-LhWHh8uAAAAPs"]
[Thu Jul 30 12:34:36.556631 2026] [core:notice] [pid 765155:tid 765381] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:36.602721 2026] [core:notice] [pid 765155:tid 765286] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:36.608175 2026] [security2:error] [pid 765155:tid 765286] [client 103.215.74.26:33922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLLOT5hFAbD-LhWHh8vgAAAIY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:36.729834 2026] [core:notice] [pid 765155:tid 765195] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:37.031687 2026] [security2:error] [pid 765155:tid 765311] [client 114.119.145.102:41027] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.shorewooddaycare.com"] [uri "/leatherflower/darkmans1814402.html"] [unique_id "amuLLeT5hFAbD-LhWHh8yQAAAJ8"], referer: https://www.shorewooddaycare.com/leatherflower/darkmans1814402.html
[Thu Jul 30 12:34:37.192234 2026] [security2:error] [pid 765155:tid 765372] [client 20.215.191.139:49872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/bnm.php"] [unique_id "amuLLeT5hFAbD-LhWHh80AAAANw"]
[Thu Jul 30 12:34:37.208122 2026] [security2:error] [pid 765155:tid 765400] [client 114.119.150.65:52879] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lark-shop.com"] [uri "/wp-content/uploads/2025/04/%E4%B8%8B%E8%BD%BD_%E5%89%AF%E6%9C%AC.png"] [unique_id "amuLLeT5hFAbD-LhWHh80gAAAPg"], referer: https://lark-shop.com/product/peel/
[Thu Jul 30 12:34:37.333691 2026] [core:notice] [pid 765155:tid 765359] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:37.338358 2026] [security2:error] [pid 765155:tid 765359] [client 103.215.74.26:33938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLLeT5hFAbD-LhWHh80wAAAM8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:37.762611 2026] [security2:error] [pid 765155:tid 765294] [client 20.215.191.139:61770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/bootstrap.php"] [unique_id "amuLLeT5hFAbD-LhWHh83gAAAI4"]
[Thu Jul 30 12:34:38.051524 2026] [core:notice] [pid 765155:tid 765405] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:38.055984 2026] [security2:error] [pid 765155:tid 765405] [client 103.215.74.26:33954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLLuT5hFAbD-LhWHh84wAAAP0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:38.297586 2026] [security2:error] [pid 765155:tid 765355] [client 20.63.98.115:47485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/function.php"] [unique_id "amuLLuT5hFAbD-LhWHh86gAAAMs"]
[Thu Jul 30 12:34:38.434333 2026] [security2:error] [pid 765155:tid 765402] [client 20.215.191.139:61763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/buy.php"] [unique_id "amuLLuT5hFAbD-LhWHh89gAAAPo"]
[Thu Jul 30 12:34:38.794079 2026] [core:notice] [pid 765155:tid 765325] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:38.800014 2026] [security2:error] [pid 765155:tid 765325] [client 103.215.74.26:33956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLLuT5hFAbD-LhWHh9AgAAAK0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:39.518192 2026] [core:notice] [pid 765155:tid 765291] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:39.523299 2026] [security2:error] [pid 765155:tid 765291] [client 103.215.74.26:33964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLL-T5hFAbD-LhWHh9EgAAAIs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:39.689643 2026] [security2:error] [pid 765155:tid 765409] [client 20.63.98.115:49974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/chosen.php"] [unique_id "amuLL-T5hFAbD-LhWHh9FgAAAQE"]
[Thu Jul 30 12:34:40.115032 2026] [security2:error] [pid 765155:tid 765236] [remote 57.141.0.68:60988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuLMOT5hFAbD-LhWHh9IAAA3VA"]
[Thu Jul 30 12:34:40.242886 2026] [core:notice] [pid 765155:tid 765367] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:40.248062 2026] [security2:error] [pid 765155:tid 765367] [client 103.215.74.26:33980] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLMOT5hFAbD-LhWHh9JwAAANc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:40.606113 2026] [proxy:error] [pid 765155:tid 765404] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:34:40.606165 2026] [proxy_http:error] [pid 765155:tid 765404] [client 18.211.55.47:41427] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:34:40.606739 2026] [proxy:error] [pid 765155:tid 765404] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:34:40.606781 2026] [proxy_http:error] [pid 765155:tid 765404] [client 18.211.55.47:41427] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:34:41.140209 2026] [security2:error] [pid 765155:tid 765352] [client 114.119.132.68:34221] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cnpinyin.com"] [uri "/study/Chinese-grammar/%E5%8F%A5%2B"] [unique_id "amuLMeT5hFAbD-LhWHh9QQAAAMg"], referer: https://cnpinyin.com/wp-sitemap-posts-post-1.xml
[Thu Jul 30 12:34:42.185029 2026] [security2:error] [pid 765155:tid 765321] [client 20.63.98.115:60838] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "svcambodia.com"] [uri "/1.php"] [unique_id "amuLMuT5hFAbD-LhWHh9ZAAAAKk"]
[Thu Jul 30 12:34:42.185160 2026] [security2:error] [pid 765155:tid 765321] [client 20.63.98.115:60838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/1.php"] [unique_id "amuLMuT5hFAbD-LhWHh9ZAAAAKk"]
[Thu Jul 30 12:34:43.216795 2026] [security2:error] [pid 765155:tid 765401] [client 92.119.36.164:43213] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guethleentertainment.com"] [uri "/"] [unique_id "amuLM-T5hFAbD-LhWHh9gwAAAPk"]
[Thu Jul 30 12:34:43.385344 2026] [security2:error] [pid 765155:tid 765290] [client 20.215.191.139:62512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/chosen.php"] [unique_id "amuLM-T5hFAbD-LhWHh9igAAAIo"]
[Thu Jul 30 12:34:43.499435 2026] [security2:error] [pid 765155:tid 765277] [remote 5.56.58.49:38724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.56.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-login.php"] [unique_id "amuLM-T5hFAbD-LhWHh9iwAAqnk"]
[Thu Jul 30 12:34:43.581398 2026] [security2:error] [pid 765155:tid 765366] [client 20.63.98.115:47190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/lv.php"] [unique_id "amuLM-T5hFAbD-LhWHh9jwAAANY"]
[Thu Jul 30 12:34:43.983103 2026] [security2:error] [pid 765155:tid 765303] [client 38.190.144.4:58815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLM-T5hFAbD-LhWHh9pAAAAJc"]
[Thu Jul 30 12:34:43.983226 2026] [security2:error] [pid 765155:tid 765303] [client 38.190.144.4:58815] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLM-T5hFAbD-LhWHh9pAAAAJc"]
[Thu Jul 30 12:34:44.128459 2026] [security2:error] [pid 765155:tid 765374] [client 20.215.191.139:49896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/class-wp-image.php"] [unique_id "amuLNOT5hFAbD-LhWHh9qQAAAN4"]
[Thu Jul 30 12:34:44.571227 2026] [security2:error] [pid 765155:tid 765406] [client 20.63.98.115:47260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/css.php"] [unique_id "amuLNOT5hFAbD-LhWHh9tAAAAP4"]
[Thu Jul 30 12:34:45.182296 2026] [security2:error] [pid 765155:tid 765288] [client 20.215.191.139:57253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/classsmtps.php"] [unique_id "amuLNeT5hFAbD-LhWHh9xgAAAIg"]
[Thu Jul 30 12:34:45.568820 2026] [proxy:error] [pid 765155:tid 765315] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:34:45.568897 2026] [proxy_http:error] [pid 765155:tid 765315] [client 44.216.125.112:61636] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:34:45.569484 2026] [proxy:error] [pid 765155:tid 765315] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:34:45.569532 2026] [proxy_http:error] [pid 765155:tid 765315] [client 44.216.125.112:61636] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:34:45.571669 2026] [security2:error] [pid 765155:tid 765382] [client 92.119.36.162:65185] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guethleentertainment.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "amuLNeT5hFAbD-LhWHh90gAAAOY"]
[Thu Jul 30 12:34:45.579395 2026] [autoindex:error] [pid 765155:tid 765310] [client 34.233.129.35:16665] AH01276: Cannot serve directory /home1/vdbnyxte/public_html/website_19d94cc7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:34:45.723281 2026] [security2:error] [pid 765155:tid 765319] [client 114.119.146.98:24647] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.hmhs.ph"] [uri "/events/retreat-dates/eventsbyday/2026/5/15/-"] [unique_id "amuLNeT5hFAbD-LhWHh92gAAAKc"], referer: https://www.hmhs.ph/events/retreat-dates/monthcalendar/2026/5/-
[Thu Jul 30 12:34:45.970337 2026] [security2:error] [pid 765155:tid 765329] [client 104.254.90.251:56148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.90.254.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuLNeT5hFAbD-LhWHh95QAAALE"]
[Thu Jul 30 12:34:45.970431 2026] [security2:error] [pid 765155:tid 765329] [client 104.254.90.251:56148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuLNeT5hFAbD-LhWHh95QAAALE"]
[Thu Jul 30 12:34:45.985085 2026] [core:notice] [pid 765155:tid 765297] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:45.990356 2026] [security2:error] [pid 765155:tid 765297] [client 103.215.74.26:12730] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLNeT5hFAbD-LhWHh95gAAAJE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:46.366528 2026] [security2:error] [pid 765155:tid 765357] [client 20.63.98.115:61494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/gecko.php"] [unique_id "amuLNuT5hFAbD-LhWHh97AAAAM0"]
[Thu Jul 30 12:34:46.450365 2026] [security2:error] [pid 765155:tid 765373] [client 216.24.212.251:51351] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guethleentertainment.com"] [uri "/media/system/js/core.js"] [unique_id "amuLNuT5hFAbD-LhWHh98AAAAN0"]
[Thu Jul 30 12:34:46.554788 2026] [core:notice] [pid 765155:tid 765285] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:46.722612 2026] [core:notice] [pid 765155:tid 765367] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:46.727943 2026] [security2:error] [pid 765155:tid 765367] [client 103.215.74.26:12744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLNuT5hFAbD-LhWHh9_AAAANc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:47.075716 2026] [fcgid:warn] [pid 765155:tid 765375] (70014)End of file found: [client 156.232.100.95:60036] mod_fcgid: can't get data from http client
[Thu Jul 30 12:34:47.252631 2026] [security2:error] [pid 765155:tid 765401] [client 103.59.161.168:63884] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.afropakmedical.com"] [uri "/"] [unique_id "amuLN-T5hFAbD-LhWHh-CwAAAPk"]
[Thu Jul 30 12:34:47.473382 2026] [core:notice] [pid 765155:tid 765402] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:47.473999 2026] [security2:error] [pid 765155:tid 765335] [client 103.59.161.168:63912] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.afropakmedical.com"] [uri "/wp-json/batch/v1"] [unique_id "amuLN-T5hFAbD-LhWHh-DwAAALc"]
[Thu Jul 30 12:34:47.477868 2026] [security2:error] [pid 765155:tid 765402] [client 103.215.74.26:12752] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLN-T5hFAbD-LhWHh-EAAAAPo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:47.881049 2026] [security2:error] [pid 765155:tid 765352] [client 20.63.98.115:47198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/xmlrpc.php"] [unique_id "amuLN-T5hFAbD-LhWHh-JwAAAMg"]
[Thu Jul 30 12:34:48.091609 2026] [autoindex:error] [pid 765155:tid 765385] [client 32.194.121.99:52363] AH01276: Cannot serve directory /home1/vdbnyxte/public_html/website_19d94cc7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:34:48.137950 2026] [autoindex:error] [pid 765155:tid 765358] [client 34.224.175.62:37774] AH01276: Cannot serve directory /home1/vdbnyxte/public_html/website_19d94cc7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:34:48.216128 2026] [core:notice] [pid 765155:tid 765289] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:48.220435 2026] [security2:error] [pid 765155:tid 765289] [client 103.215.74.26:12768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLOOT5hFAbD-LhWHh-OAAAAIk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:48.465204 2026] [security2:error] [pid 765155:tid 765302] [client 57.141.0.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuLN-T5hFAbD-LhWHh-JgAAAJY"]
[Thu Jul 30 12:34:48.965900 2026] [core:notice] [pid 765155:tid 765333] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:48.970935 2026] [security2:error] [pid 765155:tid 765333] [client 103.215.74.26:12770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "756"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLOOT5hFAbD-LhWHh-ggAAALU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:49.039913 2026] [security2:error] [pid 765155:tid 765392] [client 20.215.191.139:55472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/classwithtostring.php"] [unique_id "amuLOeT5hFAbD-LhWHh-iQAAAPA"]
[Thu Jul 30 12:34:49.349695 2026] [core:notice] [pid 765155:tid 765388] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:49.422149 2026] [security2:error] [pid 765155:tid 765402] [client 152.32.142.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.kfo.lku.temporary.site"] [uri "/index.php"] [unique_id "amuLOeT5hFAbD-LhWHh-mAAAAPo"]
[Thu Jul 30 12:34:49.702442 2026] [core:notice] [pid 765155:tid 765319] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:49.706540 2026] [security2:error] [pid 765155:tid 765319] [client 103.215.74.26:12778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLOeT5hFAbD-LhWHh-pAAAAKc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:50.350408 2026] [security2:error] [pid 765155:tid 765303] [client 20.63.98.115:61426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/f35.php"] [unique_id "amuLOuT5hFAbD-LhWHh-swAAAJc"]
[Thu Jul 30 12:34:50.438539 2026] [core:notice] [pid 765155:tid 765308] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:50.444529 2026] [security2:error] [pid 765155:tid 765308] [client 103.215.74.26:12790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLOuT5hFAbD-LhWHh-tAAAAJw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:51.008954 2026] [security2:error] [pid 765155:tid 765396] [client 20.63.98.115:61932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/autoload_classmap.php"] [unique_id "amuLO-T5hFAbD-LhWHh-vwAAAPQ"]
[Thu Jul 30 12:34:51.172648 2026] [core:notice] [pid 765155:tid 765410] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:51.179068 2026] [security2:error] [pid 765155:tid 765410] [client 103.215.74.26:12792] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLO-T5hFAbD-LhWHh-xQAAAQI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:51.909122 2026] [core:notice] [pid 765155:tid 765405] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:51.915927 2026] [security2:error] [pid 765155:tid 765405] [client 103.215.74.26:12800] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLO-T5hFAbD-LhWHh-1QAAAP0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:51.940350 2026] [security2:error] [pid 765155:tid 765382] [client 20.215.191.139:61996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/config.php"] [unique_id "amuLO-T5hFAbD-LhWHh-2QAAAOY"]
[Thu Jul 30 12:34:52.618790 2026] [security2:error] [pid 765155:tid 765358] [client 20.215.191.139:61997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/core.php"] [unique_id "amuLPOT5hFAbD-LhWHh-5wAAAM4"]
[Thu Jul 30 12:34:53.490013 2026] [security2:error] [pid 765155:tid 765187] [remote 144.76.32.242:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.32.76.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/view/29"] [unique_id "amuLPeT5hFAbD-LhWHh-9wAA3B8"]
[Thu Jul 30 12:34:53.518341 2026] [security2:error] [pid 765155:tid 765296] [client 20.215.191.139:56720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/css.php"] [unique_id "amuLPeT5hFAbD-LhWHh_AwAAAJA"]
[Thu Jul 30 12:34:53.591794 2026] [security2:error] [pid 765155:tid 765373] [client 57.141.0.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuLPeT5hFAbD-LhWHh-9gAAAN0"]
[Thu Jul 30 12:34:54.133670 2026] [security2:error] [pid 765155:tid 765398] [client 20.63.98.115:47224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/NewFile.php"] [unique_id "amuLPuT5hFAbD-LhWHh_FQAAAPY"]
[Thu Jul 30 12:34:54.366190 2026] [security2:error] [pid 765155:tid 765348] [client 2a03:2880:f800:29:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuLPeT5hFAbD-LhWHh_CwAAxDA"]
[Thu Jul 30 12:34:55.829726 2026] [security2:error] [pid 765155:tid 765299] [client 94.3.73.66:60254] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.woff2"] [unique_id "amuLP-T5hFAbD-LhWHh_PwAAAJM"]
[Thu Jul 30 12:34:55.923606 2026] [security2:error] [pid 765155:tid 765266] [remote 74.7.241.60:47250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/js/article.php"] [unique_id "amuLP-T5hFAbD-LhWHh_RAAAyW4"], referer: https://aded-rdc.org/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/js/bootstrap.bundle.min.js
[Thu Jul 30 12:34:56.267141 2026] [security2:error] [pid 765155:tid 765285] [client 62.158.137.186:34088] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.eot"] [unique_id "amuLQOT5hFAbD-LhWHh_UAAAAIU"]
[Thu Jul 30 12:34:56.755880 2026] [proxy:error] [pid 765155:tid 765305] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:34:56.755937 2026] [proxy_http:error] [pid 765155:tid 765305] [client 143.244.57.82:46758] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:34:56.756837 2026] [proxy:error] [pid 765155:tid 765305] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:34:56.756890 2026] [proxy_http:error] [pid 765155:tid 765305] [client 143.244.57.82:46758] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:34:56.757570 2026] [security2:error] [pid 765155:tid 765368] [client 85.209.75.95:39024] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.eot"] [unique_id "amuLQOT5hFAbD-LhWHh_ZQAAANg"]
[Thu Jul 30 12:34:56.788506 2026] [security2:error] [pid 765155:tid 765296] [client 70.67.96.40:39508] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.eot"] [unique_id "amuLQOT5hFAbD-LhWHh_ZgAAAJA"]
[Thu Jul 30 12:34:57.047400 2026] [proxy:error] [pid 765155:tid 765360] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:34:57.047481 2026] [proxy_http:error] [pid 765155:tid 765360] [client 143.244.57.82:50259] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:34:57.048441 2026] [proxy:error] [pid 765155:tid 765360] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:34:57.048503 2026] [proxy_http:error] [pid 765155:tid 765360] [client 143.244.57.82:50259] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:34:57.328960 2026] [security2:error] [pid 765155:tid 765389] [client 143.244.57.82:50350] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.hck.nyx.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuLQeT5hFAbD-LhWHh_dgAAAO0"]
[Thu Jul 30 12:34:57.517065 2026] [proxy:error] [pid 765155:tid 765286] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:34:57.517123 2026] [proxy_http:error] [pid 765155:tid 765286] [client 44.213.206.96:46263] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:34:57.517694 2026] [proxy:error] [pid 765155:tid 765286] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:34:57.517738 2026] [proxy_http:error] [pid 765155:tid 765286] [client 44.213.206.96:46263] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:34:57.611359 2026] [security2:error] [pid 765155:tid 765399] [client 143.244.57.82:50356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.hck.nyx.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuLQeT5hFAbD-LhWHh_gwAAAPc"]
[Thu Jul 30 12:34:57.627153 2026] [security2:error] [pid 765155:tid 765322] [client 20.215.191.139:62006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/database.php"] [unique_id "amuLQeT5hFAbD-LhWHh_hwAAAKo"]
[Thu Jul 30 12:34:57.636205 2026] [core:notice] [pid 765155:tid 765383] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:57.637416 2026] [proxy:error] [pid 765155:tid 765359] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:34:57.637490 2026] [proxy_http:error] [pid 765155:tid 765359] [client 44.213.206.96:64786] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:34:57.638057 2026] [proxy:error] [pid 765155:tid 765359] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:34:57.638104 2026] [proxy_http:error] [pid 765155:tid 765359] [client 44.213.206.96:64786] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:34:57.642596 2026] [security2:error] [pid 765155:tid 765383] [client 103.215.74.26:23810] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLQeT5hFAbD-LhWHh_iAAAAOc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:57.647738 2026] [core:notice] [pid 765155:tid 765367] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:57.652746 2026] [security2:error] [pid 765155:tid 765341] [client 62.57.122.34:49100] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.woff"] [unique_id "amuLQeT5hFAbD-LhWHh_jQAAAL0"]
[Thu Jul 30 12:34:57.690719 2026] [security2:error] [pid 765155:tid 765395] [client 131.100.100.69:39894] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.woff"] [unique_id "amuLQeT5hFAbD-LhWHh_jwAAAPM"]
[Thu Jul 30 12:34:57.692246 2026] [security2:error] [pid 765155:tid 765402] [client 20.63.98.115:61393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/xx.php"] [unique_id "amuLQeT5hFAbD-LhWHh_kAAAAPo"]
[Thu Jul 30 12:34:57.896246 2026] [proxy:error] [pid 765155:tid 765364] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:34:57.896357 2026] [proxy_http:error] [pid 765155:tid 765364] [client 143.244.57.82:50372] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:34:57.897210 2026] [proxy:error] [pid 765155:tid 765364] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:34:57.897272 2026] [proxy_http:error] [pid 765155:tid 765364] [client 143.244.57.82:50372] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:34:57.916797 2026] [security2:error] [pid 765155:tid 765297] [client 88.15.18.73:45995] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.eot"] [unique_id "amuLQeT5hFAbD-LhWHh_kgAAAJE"]
[Thu Jul 30 12:34:58.061115 2026] [security2:error] [pid 765155:tid 765321] [client 38.190.144.4:59395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLQuT5hFAbD-LhWHh_lgAAAKk"]
[Thu Jul 30 12:34:58.061242 2026] [security2:error] [pid 765155:tid 765321] [client 38.190.144.4:59395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLQuT5hFAbD-LhWHh_lgAAAKk"]
[Thu Jul 30 12:34:58.174282 2026] [security2:error] [pid 765155:tid 765348] [client 143.244.57.82:50388] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.hck.nyx.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuLQuT5hFAbD-LhWHh_mgAAAMQ"]
[Thu Jul 30 12:34:58.370470 2026] [core:notice] [pid 765155:tid 765298] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:58.374927 2026] [security2:error] [pid 765155:tid 765298] [client 103.215.74.26:23822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "772"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLQuT5hFAbD-LhWHh_owAAAJI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:58.455788 2026] [security2:error] [pid 765155:tid 765325] [client 143.244.57.82:7097] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.hck.nyx.temporary.site"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuLQuT5hFAbD-LhWHh_qwAAAK0"]
[Thu Jul 30 12:34:58.572726 2026] [security2:error] [pid 765155:tid 765335] [client 87.212.154.26:51078] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.eot"] [unique_id "amuLQuT5hFAbD-LhWHh_sAAAALc"]
[Thu Jul 30 12:34:58.599951 2026] [security2:error] [pid 765155:tid 765318] [client 81.133.118.137:44392] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.ttf"] [unique_id "amuLQuT5hFAbD-LhWHh_sQAAAKY"]
[Thu Jul 30 12:34:58.728679 2026] [security2:error] [pid 765155:tid 765407] [client 143.244.57.82:50418] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.hck.nyx.temporary.site"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuLQuT5hFAbD-LhWHh_uAAAAP8"]
[Thu Jul 30 12:34:58.898372 2026] [security2:error] [pid 765155:tid 765291] [client 77.32.13.48:1676] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.eot"] [unique_id "amuLQuT5hFAbD-LhWHh_uQAAAIs"]
[Thu Jul 30 12:34:59.007288 2026] [security2:error] [pid 765155:tid 765286] [client 143.244.57.82:50426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.hck.nyx.temporary.site"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuLQ-T5hFAbD-LhWHh_uwAAAIY"]
[Thu Jul 30 12:34:59.095021 2026] [core:notice] [pid 765155:tid 765390] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:59.101604 2026] [security2:error] [pid 765155:tid 765390] [client 103.215.74.26:23836] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLQ-T5hFAbD-LhWHh_wAAAAO4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:59.115963 2026] [security2:error] [pid 765155:tid 765323] [client 20.215.191.139:49891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/db.php"] [unique_id "amuLQ-T5hFAbD-LhWHh_wwAAAKs"]
[Thu Jul 30 12:34:59.141153 2026] [security2:error] [pid 765155:tid 765339] [client 20.63.98.115:42957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/plugins.php"] [unique_id "amuLQ-T5hFAbD-LhWHh_xAAAALs"]
[Thu Jul 30 12:34:59.267130 2026] [security2:error] [pid 765155:tid 765374] [client 81.222.178.170:12362] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.ttf"] [unique_id "amuLQ-T5hFAbD-LhWHh_yAAAAN4"]
[Thu Jul 30 12:34:59.291960 2026] [security2:error] [pid 765155:tid 765313] [client 143.244.57.82:50434] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.hck.nyx.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuLQ-T5hFAbD-LhWHh_yQAAAKE"]
[Thu Jul 30 12:34:59.471341 2026] [security2:error] [pid 765155:tid 765377] [client 114.119.151.174:58259] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ejournalugj.com"] [uri "/index_php/jdui/index"] [unique_id "amuLQ-T5hFAbD-LhWHh_1QAAAOE"], referer: https://www.ejournalugj.com/index_php/jdui/issue/current
[Thu Jul 30 12:34:59.573197 2026] [security2:error] [pid 765155:tid 765348] [client 143.244.57.82:50438] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.hck.nyx.temporary.site"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuLQ-T5hFAbD-LhWHh_2AAAAMQ"]
[Thu Jul 30 12:34:59.815109 2026] [core:notice] [pid 765155:tid 765352] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:59.823348 2026] [security2:error] [pid 765155:tid 765352] [client 103.215.74.26:23842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "785"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLQ-T5hFAbD-LhWHh_5AAAAMg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:59.856533 2026] [security2:error] [pid 765155:tid 765312] [client 143.244.57.82:50454] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.hck.nyx.temporary.site"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuLQ-T5hFAbD-LhWHh_5QAAAKA"]
[Thu Jul 30 12:35:00.043560 2026] [security2:error] [pid 765155:tid 765337] [client 20.215.191.139:55466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/default.php"] [unique_id "amuLROT5hFAbD-LhWHh_5wAAALk"]
[Thu Jul 30 12:35:00.113844 2026] [security2:error] [pid 765155:tid 765327] [client 143.198.88.13:63575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.88.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ylw.gpl.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuLROT5hFAbD-LhWHh_8AAAAK8"], referer: www.yjb.slj.mybluehost.me/blog//wp-login.php
[Thu Jul 30 12:35:00.141391 2026] [security2:error] [pid 765155:tid 765370] [client 143.244.57.82:50468] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.hck.nyx.temporary.site"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuLROT5hFAbD-LhWHh_-QAAANo"]
[Thu Jul 30 12:35:00.415514 2026] [security2:error] [pid 765155:tid 765315] [client 143.244.57.82:50484] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.hck.nyx.temporary.site"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuLROT5hFAbD-LhWHiABQAAAKM"]
[Thu Jul 30 12:35:00.433442 2026] [security2:error] [pid 765155:tid 765400] [client 143.198.88.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ylw.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuLROT5hFAbD-LhWHiABAAAAPg"], referer: www.yjb.slj.mybluehost.me/blog//wp-login.php
[Thu Jul 30 12:35:00.562364 2026] [core:notice] [pid 765155:tid 765410] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:00.570501 2026] [security2:error] [pid 765155:tid 765410] [client 103.215.74.26:23858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLROT5hFAbD-LhWHiACgAAAQI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:00.705138 2026] [security2:error] [pid 765155:tid 765388] [client 143.198.88.13:53390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ylw.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuLROT5hFAbD-LhWHiACAAAAOw"], referer: www.yjb.slj.mybluehost.me/blog//wp-login.php
[Thu Jul 30 12:35:00.719188 2026] [security2:error] [pid 765155:tid 765387] [client 143.244.57.82:50486] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.hck.nyx.temporary.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuLROT5hFAbD-LhWHiAFAAAAOs"]
[Thu Jul 30 12:35:00.835208 2026] [core:error] [pid 765155:tid 765172] [remote 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:00.835232 2026] [core:error] [pid 765155:tid 765172] [remote 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:00.838600 2026] [security2:error] [pid 765155:tid 765297] [client 47.128.121.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuLROT5hFAbD-LhWHiAEAAAAJE"]
[Thu Jul 30 12:35:00.840023 2026] [core:error] [pid 765155:tid 765174] [remote 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:00.840039 2026] [core:error] [pid 765155:tid 765174] [remote 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:00.898794 2026] [security2:error] [pid 765155:tid 765305] [client 143.198.88.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ylw.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuLROT5hFAbD-LhWHiAGgAAAJk"], referer: www.yjb.slj.mybluehost.me/blog//wp-login.php
[Thu Jul 30 12:35:00.942886 2026] [core:error] [pid 765155:tid 765175] [remote 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:00.942907 2026] [core:error] [pid 765155:tid 765175] [remote 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:01.003028 2026] [security2:error] [pid 765155:tid 765335] [client 143.244.57.82:50492] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.hck.nyx.temporary.site"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuLReT5hFAbD-LhWHiAIgAAALc"]
[Thu Jul 30 12:35:01.076467 2026] [security2:error] [pid 765155:tid 765289] [client 143.198.88.13:53390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ylw.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuLROT5hFAbD-LhWHiAIAAAAIk"], referer: www.yjb.slj.mybluehost.me/blog//wp-login.php
[Thu Jul 30 12:35:01.139593 2026] [security2:error] [pid 765155:tid 765303] [client 143.198.88.13:53390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.88.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ylw.gpl.temporary.site"] [uri "/blog//xmlrpc.php"] [unique_id "amuLReT5hFAbD-LhWHiAKgAAAJc"]
[Thu Jul 30 12:35:01.139690 2026] [security2:error] [pid 765155:tid 765303] [client 143.198.88.13:53390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ylw.gpl.temporary.site"] [uri "/blog//xmlrpc.php"] [unique_id "amuLReT5hFAbD-LhWHiAKgAAAJc"]
[Thu Jul 30 12:35:01.170090 2026] [security2:error] [pid 765155:tid 765378] [client 92.172.161.248:48634] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.ttf"] [unique_id "amuLReT5hFAbD-LhWHiALQAAAOI"]
[Thu Jul 30 12:35:01.262040 2026] [security2:error] [pid 765155:tid 765299] [client 143.198.88.13:60165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.88.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ylw.gpl.temporary.site"] [uri "/blog//wp-login.php"] [unique_id "amuLReT5hFAbD-LhWHiALwAAAJM"], referer: http://ylw.gpl.temporary.site//blog//wp-login.php
[Thu Jul 30 12:35:01.271918 2026] [security2:error] [pid 765155:tid 765350] [client 20.215.191.139:61975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/dropdown.php"] [unique_id "amuLReT5hFAbD-LhWHiAMQAAAMY"]
[Thu Jul 30 12:35:01.308121 2026] [security2:error] [pid 765155:tid 765308] [client 143.244.57.82:50502] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.hck.nyx.temporary.site"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuLReT5hFAbD-LhWHiAMwAAAJw"]
[Thu Jul 30 12:35:01.346951 2026] [core:notice] [pid 765155:tid 765319] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:01.355552 2026] [security2:error] [pid 765155:tid 765319] [client 103.215.74.26:23862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLReT5hFAbD-LhWHiANgAAAKc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:01.439595 2026] [security2:error] [pid 765155:tid 765338] [client 172.237.109.114:30762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLROT5hFAbD-LhWHh_6QAAALo"]
[Thu Jul 30 12:35:01.453257 2026] [security2:error] [pid 765155:tid 765315] [client 50.6.43.217:18568] ModSecurity: Warning. Matched phrase "fq" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "alseermarine.com"] [uri "/wp-cron.php"] [unique_id "amuLReT5hFAbD-LhWHiAOgAAAKM"]
[Thu Jul 30 12:35:01.459301 2026] [security2:error] [pid 765155:tid 765358] [client 172.237.109.114:15907] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLROT5hFAbD-LhWHh_7AAAAM4"]
[Thu Jul 30 12:35:01.460849 2026] [security2:error] [pid 765155:tid 765393] [client 172.237.109.114:27334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLROT5hFAbD-LhWHh_6AAAAPE"]
[Thu Jul 30 12:35:01.469444 2026] [security2:error] [pid 765155:tid 765346] [client 172.237.109.114:25785] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLROT5hFAbD-LhWHh_7QAAAMI"]
[Thu Jul 30 12:35:01.480997 2026] [security2:error] [pid 765155:tid 765366] [client 172.237.109.114:63973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLROT5hFAbD-LhWHh_8gAAANY"]
[Thu Jul 30 12:35:01.481264 2026] [security2:error] [pid 765155:tid 765345] [client 172.237.109.114:24586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLROT5hFAbD-LhWHh_9QAAAME"]
[Thu Jul 30 12:35:01.489931 2026] [security2:error] [pid 765155:tid 765408] [client 172.237.109.114:21358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLROT5hFAbD-LhWHh_8wAAAQA"]
[Thu Jul 30 12:35:01.493182 2026] [security2:error] [pid 765155:tid 765293] [client 172.237.109.114:27442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLROT5hFAbD-LhWHh_-wAAAI0"]
[Thu Jul 30 12:35:01.496796 2026] [security2:error] [pid 765155:tid 765291] [client 172.237.109.114:38398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLROT5hFAbD-LhWHh_9gAAAIs"]
[Thu Jul 30 12:35:01.509296 2026] [security2:error] [pid 765155:tid 765407] [client 172.237.109.114:52916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLROT5hFAbD-LhWHh_8QAAAP8"]
[Thu Jul 30 12:35:01.518591 2026] [security2:error] [pid 765155:tid 765347] [client 172.237.109.114:41596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLROT5hFAbD-LhWHh_9wAAAMM"]
[Thu Jul 30 12:35:01.520422 2026] [security2:error] [pid 765155:tid 765389] [client 172.237.109.114:10836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLROT5hFAbD-LhWHh_7gAAAO0"]
[Thu Jul 30 12:35:01.522487 2026] [security2:error] [pid 765155:tid 765286] [client 172.237.109.114:1142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLROT5hFAbD-LhWHh__AAAAIY"]
[Thu Jul 30 12:35:01.537470 2026] [security2:error] [pid 765155:tid 765332] [client 172.237.109.114:20627] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLROT5hFAbD-LhWHh_9AAAALQ"]
[Thu Jul 30 12:35:01.613966 2026] [security2:error] [pid 765155:tid 765355] [client 143.244.57.82:50510] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.hck.nyx.temporary.site"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuLReT5hFAbD-LhWHiAPAAAAMs"]
[Thu Jul 30 12:35:01.710811 2026] [security2:error] [pid 765155:tid 765397] [client 90.76.35.109:54798] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.eot"] [unique_id "amuLReT5hFAbD-LhWHiAQAAAAPU"]
[Thu Jul 30 12:35:01.910577 2026] [security2:error] [pid 765155:tid 765411] [client 143.244.57.82:50526] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.hck.nyx.temporary.site"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuLReT5hFAbD-LhWHiASwAAAQM"]
[Thu Jul 30 12:35:02.040349 2026] [core:notice] [pid 765155:tid 765287] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:02.272673 2026] [security2:error] [pid 765155:tid 765392] [client 87.20.247.37:33244] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.ttf"] [unique_id "amuLRuT5hFAbD-LhWHiAUQAAAPA"]
[Thu Jul 30 12:35:02.275625 2026] [security2:error] [pid 765155:tid 765354] [client 83.196.0.255:33434] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.woff"] [unique_id "amuLRuT5hFAbD-LhWHiAUwAAAMo"]
[Thu Jul 30 12:35:02.476118 2026] [security2:error] [pid 765155:tid 765391] [client 172.237.109.114:34631] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLReT5hFAbD-LhWHiAIwAAAO8"]
[Thu Jul 30 12:35:02.486484 2026] [security2:error] [pid 765155:tid 765318] [client 172.237.109.114:18139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLReT5hFAbD-LhWHiAJwAAAKY"]
[Thu Jul 30 12:35:02.506781 2026] [security2:error] [pid 765155:tid 765371] [client 172.237.109.114:7804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLReT5hFAbD-LhWHiAKAAAANs"]
[Thu Jul 30 12:35:02.532839 2026] [security2:error] [pid 765155:tid 765336] [client 172.237.109.114:53529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLReT5hFAbD-LhWHiALAAAALg"]
[Thu Jul 30 12:35:02.539038 2026] [security2:error] [pid 765155:tid 765311] [client 172.237.109.114:52647] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLReT5hFAbD-LhWHiAKwAAAJ8"]
[Thu Jul 30 12:35:02.541522 2026] [security2:error] [pid 765155:tid 765324] [client 172.237.109.114:19413] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLReT5hFAbD-LhWHiAKQAAAKw"]
[Thu Jul 30 12:35:02.677916 2026] [security2:error] [pid 765155:tid 765186] [remote 57.141.0.27:57076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/706661964/feed/rss2/"] [unique_id "amuLRuT5hFAbD-LhWHiAXwAAox4"]
[Thu Jul 30 12:35:03.064663 2026] [security2:error] [pid 765155:tid 765386] [client 20.215.191.139:50799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/edit.php"] [unique_id "amuLR-T5hFAbD-LhWHiAbQAAAOo"]
[Thu Jul 30 12:35:03.117373 2026] [security2:error] [pid 765155:tid 765390] [client 152.59.185.22:48176] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.woff"] [unique_id "amuLR-T5hFAbD-LhWHiAbwAAAO4"]
[Thu Jul 30 12:35:05.842115 2026] [security2:error] [pid 765155:tid 765298] [client 38.190.144.4:59913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLSeT5hFAbD-LhWHiArQAAAJI"]
[Thu Jul 30 12:35:05.844584 2026] [security2:error] [pid 765155:tid 765298] [client 38.190.144.4:59913] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLSeT5hFAbD-LhWHiArQAAAJI"]
[Thu Jul 30 12:35:06.018351 2026] [security2:error] [pid 765155:tid 765360] [client 74.7.241.145:53332] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "prednisolonetablets.store.qsv.hfl.temporary.site"] [uri "/robots.txt"] [unique_id "amuLSuT5hFAbD-LhWHiAsgAAANA"]
[Thu Jul 30 12:35:06.242962 2026] [security2:error] [pid 765155:tid 765329] [client 20.63.98.115:54587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/xxx.php"] [unique_id "amuLSuT5hFAbD-LhWHiAtgAAALE"]
[Thu Jul 30 12:35:06.484794 2026] [security2:error] [pid 765155:tid 765380] [client 50.6.43.217:43950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuLSeT5hFAbD-LhWHiAqgAAAOQ"]
[Thu Jul 30 12:35:06.694004 2026] [security2:error] [pid 765155:tid 765350] [client 88.99.80.227:20622] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuLSuT5hFAbD-LhWHiAwQAAAMY"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:35:06.907783 2026] [security2:error] [pid 765155:tid 765382] [client 20.215.191.139:53696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/f35.php"] [unique_id "amuLSuT5hFAbD-LhWHiAxQAAAOY"]
[Thu Jul 30 12:35:07.060843 2026] [core:notice] [pid 765155:tid 765341] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:07.066385 2026] [security2:error] [pid 765155:tid 765341] [client 88.99.80.227:20630] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLS-T5hFAbD-LhWHiAxwAAAL0"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:35:07.084698 2026] [core:notice] [pid 765155:tid 765309] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:07.088790 2026] [security2:error] [pid 765155:tid 765309] [client 103.215.74.26:16278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "764"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLS-T5hFAbD-LhWHiAyAAAAJ0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:07.213799 2026] [security2:error] [pid 765155:tid 765392] [client 50.6.43.217:43964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuLSuT5hFAbD-LhWHiAugAAAPA"]
[Thu Jul 30 12:35:07.317576 2026] [security2:error] [pid 765155:tid 765336] [client 20.63.98.115:61420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/css.php"] [unique_id "amuLS-T5hFAbD-LhWHiAzwAAALg"]
[Thu Jul 30 12:35:07.439701 2026] [security2:error] [pid 765155:tid 765403] [client 88.99.80.227:20640] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuLS-T5hFAbD-LhWHiA0wAAAPs"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:35:07.767221 2026] [security2:error] [pid 765155:tid 765379] [client 51.15.232.53:39234] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.eot"] [unique_id "amuLS-T5hFAbD-LhWHiA3QAAAOM"]
[Thu Jul 30 12:35:07.832090 2026] [core:notice] [pid 765155:tid 765340] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:07.837787 2026] [security2:error] [pid 765155:tid 765340] [client 103.215.74.26:16290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLS-T5hFAbD-LhWHiA4AAAALw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:08.025216 2026] [security2:error] [pid 765155:tid 765320] [client 123.202.189.111:9503] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.carnetdeshopping.com"] [uri "/wp-content/uploads/2015/12/id%C3%A9es-cadeaux-homme_beaute-2-300x210.png"] [unique_id "amuLTOT5hFAbD-LhWHiA5wAAAKg"]
[Thu Jul 30 12:35:08.299935 2026] [security2:error] [pid 765155:tid 765289] [client 20.63.98.115:61388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "amuLTOT5hFAbD-LhWHiA6gAAAIk"]
[Thu Jul 30 12:35:08.560429 2026] [core:notice] [pid 765155:tid 765322] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:08.565460 2026] [security2:error] [pid 765155:tid 765322] [client 103.215.74.26:16294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLTOT5hFAbD-LhWHiA9gAAAKo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:08.593639 2026] [security2:error] [pid 765155:tid 765378] [client 57.141.0.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuLS-T5hFAbD-LhWHiA5gAAAOI"]
[Thu Jul 30 12:35:09.039942 2026] [security2:error] [pid 765155:tid 765168] [remote 190.92.174.131:42326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-login.php"] [unique_id "amuLTeT5hFAbD-LhWHiBAQAAjQw"]
[Thu Jul 30 12:35:09.260292 2026] [security2:error] [pid 765155:tid 765285] [client 20.215.191.139:58374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/f7.php"] [unique_id "amuLTeT5hFAbD-LhWHiBBQAAAIU"]
[Thu Jul 30 12:35:09.298525 2026] [core:notice] [pid 765155:tid 765286] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:09.302350 2026] [security2:error] [pid 765155:tid 765286] [client 103.215.74.26:16296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLTeT5hFAbD-LhWHiBCQAAAIY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:09.632038 2026] [security2:error] [pid 765155:tid 765366] [client 20.63.98.115:20556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuLTeT5hFAbD-LhWHiBDwAAANY"]
[Thu Jul 30 12:35:10.036757 2026] [core:notice] [pid 765155:tid 765390] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:10.042092 2026] [security2:error] [pid 765155:tid 765390] [client 103.215.74.26:16298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLTuT5hFAbD-LhWHiBGQAAAO4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:10.580692 2026] [security2:error] [pid 765155:tid 765405] [client 20.63.98.115:62071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/images/index.php"] [unique_id "amuLTuT5hFAbD-LhWHiBJgAAAP0"]
[Thu Jul 30 12:35:11.815068 2026] [security2:error] [pid 765155:tid 765269] [remote 47.128.27.84:45476] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/moose-knuckles-jacket-olive/"] [unique_id "amuLT-T5hFAbD-LhWHiBQwAA4HE"]
[Thu Jul 30 12:35:12.397054 2026] [security2:error] [pid 765155:tid 765366] [client 20.63.98.115:61395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/network/about.php"] [unique_id "amuLUOT5hFAbD-LhWHiBWAAAANY"]
[Thu Jul 30 12:35:12.983658 2026] [core:notice] [pid 765155:tid 765372] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:13.340341 2026] [autoindex:error] [pid 765155:tid 765362] [client 52.4.19.39:32641] AH01276: Cannot serve directory /home1/vdbnyxte/public_html/website_19d94cc7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:35:13.443610 2026] [autoindex:error] [pid 765155:tid 765352] [client 52.4.19.39:6221] AH01276: Cannot serve directory /home1/vdbnyxte/public_html/website_19d94cc7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:35:13.565862 2026] [security2:error] [pid 765155:tid 765356] [client 119.73.97.132:30947] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuLUeT5hFAbD-LhWHiBdQAAzHU"]
[Thu Jul 30 12:35:13.584152 2026] [security2:error] [pid 765155:tid 765356] [client 119.73.97.132:30947] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuLUeT5hFAbD-LhWHiBeAAAzBE"]
[Thu Jul 30 12:35:13.898508 2026] [security2:error] [pid 765155:tid 765378] [client 20.63.98.115:36822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/xpw.php"] [unique_id "amuLUeT5hFAbD-LhWHiBkwAAAOI"]
[Thu Jul 30 12:35:14.322329 2026] [security2:error] [pid 765155:tid 765366] [client 119.73.97.132:30947] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuLUuT5hFAbD-LhWHiBmgAA1hk"], referer: https://www.urwru.club/emm-elevate/?preview_id=685&preview_nonce=6cdd8f071f&preview=true&aaeid=1
[Thu Jul 30 12:35:15.411001 2026] [security2:error] [pid 765155:tid 765407] [client 45.221.5.168:47478] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/js/jquery-plugin-collection.js"] [unique_id "amuLU-T5hFAbD-LhWHiBtQAAAP8"]
[Thu Jul 30 12:35:15.613625 2026] [security2:error] [pid 765155:tid 765346] [client 74.7.230.33:54876] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "hhmoaf.org.wrl.gzj.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuLU-T5hFAbD-LhWHiBvQAAwh4"]
[Thu Jul 30 12:35:15.727036 2026] [autoindex:error] [pid 765155:tid 765188] [remote 74.7.242.27:55578] AH01276: Cannot serve directory /home1/wrlgzjte/hhmoaf.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:35:15.778947 2026] [core:notice] [pid 765155:tid 765354] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:15.784372 2026] [security2:error] [pid 765155:tid 765354] [client 103.215.74.26:31408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLU-T5hFAbD-LhWHiBwwAAAMo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:16.522552 2026] [core:notice] [pid 765155:tid 765309] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:16.526937 2026] [security2:error] [pid 765155:tid 765309] [client 103.215.74.26:31420] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLVOT5hFAbD-LhWHiB0gAAAJ0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:16.706277 2026] [security2:error] [pid 765155:tid 765343] [client 50.6.43.217:20098] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jesus.claims"] [uri "/index.php"] [unique_id "amuLVOT5hFAbD-LhWHiB1gAAAL8"]
[Thu Jul 30 12:35:16.827684 2026] [security2:error] [pid 765155:tid 765305] [client 50.6.43.217:20102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jesus.claims"] [uri "/index.php"] [unique_id "amuLVOT5hFAbD-LhWHiB2gAAAJk"]
[Thu Jul 30 12:35:17.088047 2026] [core:notice] [pid 765155:tid 765392] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:17.255347 2026] [core:notice] [pid 765155:tid 765409] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:17.260065 2026] [security2:error] [pid 765155:tid 765409] [client 103.215.74.26:31436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLVeT5hFAbD-LhWHiB6AAAAQE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:17.680536 2026] [core:notice] [pid 765155:tid 765393] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:17.864370 2026] [security2:error] [pid 765155:tid 765367] [client 38.190.144.4:60442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLVeT5hFAbD-LhWHiB9gAAANc"]
[Thu Jul 30 12:35:17.864515 2026] [security2:error] [pid 765155:tid 765367] [client 38.190.144.4:60442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLVeT5hFAbD-LhWHiB9gAAANc"]
[Thu Jul 30 12:35:18.009860 2026] [core:notice] [pid 765155:tid 765300] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:18.014436 2026] [security2:error] [pid 765155:tid 765300] [client 103.215.74.26:31452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLVuT5hFAbD-LhWHiB-gAAAJQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:18.405181 2026] [security2:error] [pid 765155:tid 765289] [client 66.249.74.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kamiliacademy.com"] [uri "/index.php"] [unique_id "amuLU-T5hFAbD-LhWHiBwgAAAIk"]
[Thu Jul 30 12:35:18.787504 2026] [core:notice] [pid 765155:tid 765377] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:18.791784 2026] [security2:error] [pid 765155:tid 765377] [client 103.215.74.26:31460] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLVuT5hFAbD-LhWHiCCwAAAOE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:18.900352 2026] [security2:error] [pid 765155:tid 765203] [remote 82.130.249.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.249.130.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ciunews.com"] [uri "/wp-login.php"] [unique_id "amuLVuT5hFAbD-LhWHiCDAAAwy8"]
[Thu Jul 30 12:35:19.206020 2026] [core:notice] [pid 765155:tid 765394] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:19.440381 2026] [core:notice] [pid 765155:tid 765327] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:19.508727 2026] [security2:error] [pid 765155:tid 765304] [client 20.63.98.115:20550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-cron.php"] [unique_id "amuLV-T5hFAbD-LhWHiCHAAAAJg"]
[Thu Jul 30 12:35:19.567246 2026] [core:notice] [pid 765155:tid 765386] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:19.572737 2026] [security2:error] [pid 765155:tid 765386] [client 103.215.74.26:31462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLV-T5hFAbD-LhWHiCIAAAAOo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:20.299227 2026] [core:notice] [pid 765155:tid 765352] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:20.304221 2026] [security2:error] [pid 765155:tid 765352] [client 103.215.74.26:31470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLWOT5hFAbD-LhWHiCOQAAAMg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:20.406042 2026] [security2:error] [pid 765155:tid 765346] [client 119.73.97.132:30947] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuLWOT5hFAbD-LhWHiCLgAAwkU"]
[Thu Jul 30 12:35:20.615024 2026] [security2:error] [pid 765155:tid 765346] [client 119.73.97.132:30947] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuLWOT5hFAbD-LhWHiCOgAAwkE"]
[Thu Jul 30 12:35:20.782756 2026] [security2:error] [pid 765155:tid 765346] [client 119.73.97.132:30947] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuLWOT5hFAbD-LhWHiCPAAAwk4"], referer: https://www.urwru.club/emm-elevate/?preview_id=685&preview_nonce=6cdd8f071f&preview=true&aaeid=1
[Thu Jul 30 12:35:20.997317 2026] [security2:error] [pid 765155:tid 765360] [client 20.63.98.115:21081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/cah.php"] [unique_id "amuLWOT5hFAbD-LhWHiCRwAAANA"]
[Thu Jul 30 12:35:21.023468 2026] [core:notice] [pid 765155:tid 765412] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:21.028001 2026] [security2:error] [pid 765155:tid 765412] [client 103.215.74.26:31484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLWeT5hFAbD-LhWHiCSAAAAQQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:21.766734 2026] [core:notice] [pid 765155:tid 765394] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:21.770731 2026] [security2:error] [pid 765155:tid 765394] [client 103.215.74.26:31492] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLWeT5hFAbD-LhWHiCYQAAAPI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:22.220942 2026] [security2:error] [pid 765155:tid 765334] [client 20.63.98.115:21088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/cong.php"] [unique_id "amuLWuT5hFAbD-LhWHiCZwAAALY"]
[Thu Jul 30 12:35:22.499945 2026] [core:notice] [pid 765155:tid 765301] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:22.507033 2026] [security2:error] [pid 765155:tid 765301] [client 103.215.74.26:31500] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLWuT5hFAbD-LhWHiCcQAAAJU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:22.701207 2026] [core:notice] [pid 765155:tid 765380] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:22.756415 2026] [core:notice] [pid 765155:tid 765341] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:22.911848 2026] [proxy:error] [pid 765155:tid 765408] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:35:22.911915 2026] [proxy_http:error] [pid 765155:tid 765408] [client 54.87.222.253:64667] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:35:22.912581 2026] [proxy:error] [pid 765155:tid 765408] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:35:22.912627 2026] [proxy_http:error] [pid 765155:tid 765408] [client 54.87.222.253:64667] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:35:23.035547 2026] [core:notice] [pid 765155:tid 765356] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:23.066383 2026] [proxy:error] [pid 765155:tid 765310] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:35:23.066457 2026] [proxy_http:error] [pid 765155:tid 765310] [client 3.228.112.215:9963] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:35:23.067021 2026] [proxy:error] [pid 765155:tid 765310] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:35:23.067070 2026] [proxy_http:error] [pid 765155:tid 765310] [client 3.228.112.215:9963] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:35:23.119552 2026] [security2:error] [pid 765155:tid 765398] [client 42.105.179.169:29964] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/js/jquery-plugin-collection.js"] [unique_id "amuLW-T5hFAbD-LhWHiCiQAAAPY"]
[Thu Jul 30 12:35:23.253813 2026] [core:notice] [pid 765155:tid 765294] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:23.260489 2026] [security2:error] [pid 765155:tid 765294] [client 103.215.74.26:12946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "752"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLW-T5hFAbD-LhWHiCkAAAAI4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:23.372281 2026] [security2:error] [pid 765155:tid 765345] [client 20.63.98.115:65462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/Sanskrit.php"] [unique_id "amuLW-T5hFAbD-LhWHiClQAAAME"]
[Thu Jul 30 12:35:23.597329 2026] [security2:error] [pid 765155:tid 765333] [client 208.98.222.15:44627] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuLW-T5hFAbD-LhWHiCmQAAtVs"], referer: https://www.northyorksheridanmall.com/mall-map/
[Thu Jul 30 12:35:23.990941 2026] [core:notice] [pid 765155:tid 765394] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:23.996421 2026] [security2:error] [pid 765155:tid 765394] [client 103.215.74.26:12956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLW-T5hFAbD-LhWHiCpgAAAPI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:24.303930 2026] [fcgid:warn] [pid 765155:tid 765306] (70014)End of file found: [client 118.194.233.182:35336] mod_fcgid: can't get data from http client
[Thu Jul 30 12:35:24.699323 2026] [security2:error] [pid 765155:tid 765405] [client 20.63.98.115:63420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/ms-edit.php"] [unique_id "amuLXOT5hFAbD-LhWHiCvQAAAP0"]
[Thu Jul 30 12:35:24.761126 2026] [core:notice] [pid 765155:tid 765401] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:24.767250 2026] [security2:error] [pid 765155:tid 765401] [client 103.215.74.26:12960] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLXOT5hFAbD-LhWHiCwQAAAPk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:24.947038 2026] [security2:error] [pid 765155:tid 765307] [client 57.141.0.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuLW-T5hFAbD-LhWHiCngAAAJs"]
[Thu Jul 30 12:35:25.214099 2026] [security2:error] [pid 765155:tid 765388] [client 89.181.223.51:49456] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.eot"] [unique_id "amuLXeT5hFAbD-LhWHiCyQAAAOw"]
[Thu Jul 30 12:35:25.295126 2026] [security2:error] [pid 765155:tid 765387] [client 80.30.87.122:45718] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.woff2"] [unique_id "amuLXeT5hFAbD-LhWHiCywAAAOs"]
[Thu Jul 30 12:35:25.375303 2026] [security2:error] [pid 765155:tid 765316] [client 83.42.52.45:56280] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.ttf"] [unique_id "amuLXeT5hFAbD-LhWHiC0gAAAKQ"]
[Thu Jul 30 12:35:25.488884 2026] [core:notice] [pid 765155:tid 765345] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:25.498867 2026] [security2:error] [pid 765155:tid 765345] [client 103.215.74.26:12970] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLXeT5hFAbD-LhWHiC1wAAAME"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:25.543447 2026] [security2:error] [pid 765155:tid 765289] [client 85.243.150.4:46170] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.woff"] [unique_id "amuLXeT5hFAbD-LhWHiC3QAAAIk"]
[Thu Jul 30 12:35:26.117923 2026] [security2:error] [pid 765155:tid 765368] [client 108.172.254.208:45938] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.eot"] [unique_id "amuLXuT5hFAbD-LhWHiC7QAAANg"]
[Thu Jul 30 12:35:26.196599 2026] [security2:error] [pid 765155:tid 765367] [client 128.2.204.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuLXuT5hFAbD-LhWHiC7AAAANc"]
[Thu Jul 30 12:35:26.224293 2026] [core:notice] [pid 765155:tid 765303] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:26.228267 2026] [security2:error] [pid 765155:tid 765303] [client 103.215.74.26:12982] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLXuT5hFAbD-LhWHiC7gAAAJc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:26.952359 2026] [core:notice] [pid 765155:tid 765309] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:26.956337 2026] [security2:error] [pid 765155:tid 765309] [client 103.215.74.26:12986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "771"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLXuT5hFAbD-LhWHiDAQAAAJ0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:27.670428 2026] [core:notice] [pid 765155:tid 765347] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:27.682941 2026] [security2:error] [pid 765155:tid 765347] [client 103.215.74.26:12996] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLX-T5hFAbD-LhWHiDGQAAAMM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:27.776936 2026] [security2:error] [pid 765155:tid 765387] [client 44.255.204.121:53320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLX-T5hFAbD-LhWHiDCwAA6xM"]
[Thu Jul 30 12:35:28.235025 2026] [security2:error] [pid 765155:tid 765370] [client 20.63.98.115:21101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/function.php"] [unique_id "amuLYOT5hFAbD-LhWHiDLAAAANo"]
[Thu Jul 30 12:35:28.298748 2026] [security2:error] [pid 765155:tid 765308] [client 216.73.216.176:1939] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mediaspawn.com"] [uri "/index.php"] [unique_id "amuLX-T5hFAbD-LhWHiDGgAAnBE"]
[Thu Jul 30 12:35:28.335831 2026] [security2:error] [pid 765155:tid 765379] [client 86.205.97.104:40934] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.ttf"] [unique_id "amuLYOT5hFAbD-LhWHiDLwAAAOM"]
[Thu Jul 30 12:35:28.403051 2026] [core:notice] [pid 765155:tid 765315] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:28.407290 2026] [security2:error] [pid 765155:tid 765315] [client 103.215.74.26:13010] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "784"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLYOT5hFAbD-LhWHiDMQAAAKM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:28.415276 2026] [security2:error] [pid 765155:tid 765314] [client 86.2.135.66:45668] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.eot"] [unique_id "amuLYOT5hFAbD-LhWHiDMgAAAKI"]
[Thu Jul 30 12:35:28.446995 2026] [security2:error] [pid 765155:tid 765358] [client 50.6.43.217:29206] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mediaspawn.com"] [uri "/index.php"] [unique_id "amuLYOT5hFAbD-LhWHiDMAAAAM4"]
[Thu Jul 30 12:35:28.501100 2026] [security2:error] [pid 765155:tid 765375] [client 2a03:2880:f800:f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuLX-T5hFAbD-LhWHiDFAAA3wU"]
[Thu Jul 30 12:35:28.548923 2026] [security2:error] [pid 765155:tid 765361] [client 94.161.14.62:35296] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.ttf"] [unique_id "amuLYOT5hFAbD-LhWHiDOAAAANE"]
[Thu Jul 30 12:35:28.548942 2026] [security2:error] [pid 765155:tid 765407] [client 50.6.43.217:29222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mediaspawn.com"] [uri "/index.php"] [unique_id "amuLYOT5hFAbD-LhWHiDNwAAAP8"]
[Thu Jul 30 12:35:28.610483 2026] [security2:error] [pid 765155:tid 765393] [client 57.141.0.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuLYOT5hFAbD-LhWHiDIQAAAPE"]
[Thu Jul 30 12:35:28.746962 2026] [security2:error] [pid 765155:tid 765302] [client 86.2.71.239:57996] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.eot"] [unique_id "amuLYOT5hFAbD-LhWHiDRAAAAJY"]
[Thu Jul 30 12:35:28.750810 2026] [security2:error] [pid 765155:tid 765394] [client 80.41.184.212:56516] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.eot"] [unique_id "amuLYOT5hFAbD-LhWHiDRQAAAPI"]
[Thu Jul 30 12:35:28.832816 2026] [security2:error] [pid 765155:tid 765285] [client 38.190.144.4:60976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLYOT5hFAbD-LhWHiDSAAAAIU"]
[Thu Jul 30 12:35:28.832925 2026] [security2:error] [pid 765155:tid 765285] [client 38.190.144.4:60976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLYOT5hFAbD-LhWHiDSAAAAIU"]
[Thu Jul 30 12:35:29.124068 2026] [security2:error] [pid 765155:tid 765313] [client 102.212.189.63:36275] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.woff"] [unique_id "amuLYeT5hFAbD-LhWHiDUQAAAKE"]
[Thu Jul 30 12:35:29.157113 2026] [core:notice] [pid 765155:tid 765343] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:29.161333 2026] [security2:error] [pid 765155:tid 765343] [client 103.215.74.26:13026] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "756"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLYeT5hFAbD-LhWHiDUgAAAL8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:29.161866 2026] [security2:error] [pid 765155:tid 765338] [client 57.141.0.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuLYOT5hFAbD-LhWHiDPAAAALo"]
[Thu Jul 30 12:35:29.530969 2026] [security2:error] [pid 765155:tid 765412] [client 83.52.236.69:33794] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.eot"] [unique_id "amuLYeT5hFAbD-LhWHiDXAAAAQQ"]
[Thu Jul 30 12:35:29.820514 2026] [security2:error] [pid 765155:tid 765399] [client 152.58.60.211:48266] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.ttf"] [unique_id "amuLYeT5hFAbD-LhWHiDYQAAAPc"]
[Thu Jul 30 12:35:29.877768 2026] [core:notice] [pid 765155:tid 765367] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:29.885150 2026] [security2:error] [pid 765155:tid 765367] [client 103.215.74.26:13030] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLYeT5hFAbD-LhWHiDZQAAANc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:29.888441 2026] [security2:error] [pid 765155:tid 765406] [client 20.63.98.115:20580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/ee.php"] [unique_id "amuLYeT5hFAbD-LhWHiDZgAAAP4"]
[Thu Jul 30 12:35:30.058649 2026] [security2:error] [pid 765155:tid 765288] [client 99.229.28.199:53196] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.woff"] [unique_id "amuLYuT5hFAbD-LhWHiDagAAAIg"]
[Thu Jul 30 12:35:30.063174 2026] [security2:error] [pid 765155:tid 765388] [client 104.11.180.142:46798] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.eot"] [unique_id "amuLYuT5hFAbD-LhWHiDawAAAOw"]
[Thu Jul 30 12:35:30.595676 2026] [core:notice] [pid 765155:tid 765403] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:30.599704 2026] [security2:error] [pid 765155:tid 765403] [client 103.215.74.26:13034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "766"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLYuT5hFAbD-LhWHiDdQAAAPs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:30.749921 2026] [core:error] [pid 765155:tid 765285] [client 74.7.241.136:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:30.749944 2026] [core:error] [pid 765155:tid 765285] [client 74.7.241.136:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:30.750076 2026] [security2:error] [pid 765155:tid 765285] [client 74.7.241.136:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.rry.nyx.temporary.site"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amuLYuT5hFAbD-LhWHiDeQAAAIU"]
[Thu Jul 30 12:35:30.750613 2026] [security2:error] [pid 765155:tid 765377] [client 74.7.241.136:35924] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.rry.nyx.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuLYuT5hFAbD-LhWHiDdwAA4TY"]
[Thu Jul 30 12:35:30.803583 2026] [security2:error] [pid 765155:tid 765339] [client 79.45.13.177:32948] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.woff"] [unique_id "amuLYuT5hFAbD-LhWHiDegAAALs"]
[Thu Jul 30 12:35:31.315388 2026] [security2:error] [pid 765155:tid 765309] [client 72.38.57.2:50106] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.eot"] [unique_id "amuLY-T5hFAbD-LhWHiDhAAAAJ0"]
[Thu Jul 30 12:35:31.329194 2026] [core:notice] [pid 765155:tid 765408] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:31.334462 2026] [security2:error] [pid 765155:tid 765408] [client 103.215.74.26:13040] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLY-T5hFAbD-LhWHiDhQAAAQA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:31.843495 2026] [security2:error] [pid 765155:tid 765394] [client 20.63.98.115:36857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/new.php"] [unique_id "amuLY-T5hFAbD-LhWHiDkwAAAPI"]
[Thu Jul 30 12:35:32.061719 2026] [core:notice] [pid 765155:tid 765400] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:32.065946 2026] [security2:error] [pid 765155:tid 765400] [client 103.215.74.26:13042] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLZOT5hFAbD-LhWHiDnQAAAPg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:32.210219 2026] [core:error] [pid 765155:tid 765382] [client 152.32.207.42:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:32.210252 2026] [core:error] [pid 765155:tid 765382] [client 152.32.207.42:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:32.421195 2026] [core:notice] [pid 765155:tid 765378] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:32.793098 2026] [core:notice] [pid 765155:tid 765383] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:32.797095 2026] [security2:error] [pid 765155:tid 765383] [client 103.215.74.26:13054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLZOT5hFAbD-LhWHiDtAAAAOc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:32.889179 2026] [core:notice] [pid 765155:tid 765377] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:35.519079 2026] [security2:error] [pid 765155:tid 765290] [client 74.7.230.32:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "qsq.nyx.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuLZ-T5hFAbD-LhWHiD7wAAAIo"]
[Thu Jul 30 12:35:35.519694 2026] [security2:error] [pid 765155:tid 765403] [client 74.7.230.32:57268] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "qsq.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuLZ-T5hFAbD-LhWHiD7QAA-0o"]
[Thu Jul 30 12:35:35.761209 2026] [core:error] [pid 765155:tid 765287] [client 152.32.207.42:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:35.761236 2026] [core:error] [pid 765155:tid 765287] [client 152.32.207.42:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:35.987802 2026] [security2:error] [pid 765155:tid 765338] [client 20.52.125.110:6866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.tmb/LA.php"] [unique_id "amuLZ-T5hFAbD-LhWHiD_QAAALo"]
[Thu Jul 30 12:35:36.051770 2026] [security2:error] [pid 765155:tid 765326] [client 20.63.98.115:63366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-config.php"] [unique_id "amuLaOT5hFAbD-LhWHiD_gAAAK4"]
[Thu Jul 30 12:35:36.579392 2026] [security2:error] [pid 765155:tid 765357] [client 20.52.125.110:6732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.tmb/admin.php"] [unique_id "amuLaOT5hFAbD-LhWHiECwAAAM0"]
[Thu Jul 30 12:35:36.606072 2026] [core:notice] [pid 765155:tid 765238] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:37.132638 2026] [core:notice] [pid 765155:tid 765168] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:37.137299 2026] [security2:error] [pid 765155:tid 765329] [client 20.52.125.110:6875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.tmb/class_api.php"] [unique_id "amuLaeT5hFAbD-LhWHiEGAAAALE"]
[Thu Jul 30 12:35:37.168173 2026] [core:notice] [pid 765155:tid 765361] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:37.648882 2026] [core:notice] [pid 765155:tid 765295] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:37.707554 2026] [security2:error] [pid 765155:tid 765395] [client 20.52.125.110:6886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.tmb/cpabpkyk.php"] [unique_id "amuLaeT5hFAbD-LhWHiEJgAAAPM"]
[Thu Jul 30 12:35:38.042607 2026] [security2:error] [pid 765155:tid 765403] [client 20.63.98.115:65433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-conflg.php"] [unique_id "amuLauT5hFAbD-LhWHiEMAAAAPs"]
[Thu Jul 30 12:35:38.632526 2026] [core:notice] [pid 765155:tid 765330] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:38.636837 2026] [security2:error] [pid 765155:tid 765330] [client 103.215.74.26:43724] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLauT5hFAbD-LhWHiERAAAALI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:38.705333 2026] [security2:error] [pid 765155:tid 765336] [client 20.52.125.110:6884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.tmb/wp-login.php"] [unique_id "amuLauT5hFAbD-LhWHiEPgAAALg"]
[Thu Jul 30 12:35:38.810741 2026] [core:error] [pid 765155:tid 765405] [client 152.32.207.42:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:38.810774 2026] [core:error] [pid 765155:tid 765405] [client 152.32.207.42:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:39.139626 2026] [core:error] [pid 765155:tid 765344] [client 20.63.98.115:58184] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:39.139656 2026] [core:error] [pid 765155:tid 765344] [client 20.63.98.115:58184] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:39.306597 2026] [security2:error] [pid 765155:tid 765373] [client 20.52.125.110:7379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known//.well-known/owlmailer.php"] [unique_id "amuLa-T5hFAbD-LhWHiEXwAAAN0"]
[Thu Jul 30 12:35:39.364423 2026] [core:notice] [pid 765155:tid 765410] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:39.369501 2026] [security2:error] [pid 765155:tid 765410] [client 103.215.74.26:43738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLa-T5hFAbD-LhWHiEYwAAAQI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:39.527627 2026] [security2:error] [pid 765155:tid 765364] [client 2a03:2880:f800:2:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuLauT5hFAbD-LhWHiETwAA1Ew"]
[Thu Jul 30 12:35:39.842954 2026] [security2:error] [pid 765155:tid 765320] [client 20.52.125.110:6721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/991176.php"] [unique_id "amuLa-T5hFAbD-LhWHiEcgAAAKg"]
[Thu Jul 30 12:35:40.096398 2026] [core:notice] [pid 765155:tid 765287] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:40.101109 2026] [security2:error] [pid 765155:tid 765287] [client 103.215.74.26:43752] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLbOT5hFAbD-LhWHiEegAAAIc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:40.379384 2026] [security2:error] [pid 765155:tid 765391] [client 20.52.125.110:6856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/acme-challenge/adminfuns.php"] [unique_id "amuLbOT5hFAbD-LhWHiEgAAAAO8"]
[Thu Jul 30 12:35:40.830925 2026] [core:notice] [pid 765155:tid 765397] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:40.835366 2026] [security2:error] [pid 765155:tid 765397] [client 103.215.74.26:43766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLbOT5hFAbD-LhWHiEmQAAAPU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:40.948191 2026] [security2:error] [pid 765155:tid 765358] [client 20.52.125.110:6907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "amuLbOT5hFAbD-LhWHiEngAAAM4"]
[Thu Jul 30 12:35:41.511574 2026] [security2:error] [pid 765155:tid 765311] [client 20.52.125.110:6889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/acme-challenge/classsmtps.php"] [unique_id "amuLbeT5hFAbD-LhWHiErgAAAJ8"]
[Thu Jul 30 12:35:41.585490 2026] [core:notice] [pid 765155:tid 765402] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:41.589889 2026] [security2:error] [pid 765155:tid 765402] [client 103.215.74.26:43776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLbeT5hFAbD-LhWHiEsgAAAPo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:41.737680 2026] [security2:error] [pid 765155:tid 765163] [remote 216.38.28.47:53262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.28.38.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-login.php"] [unique_id "amuLbeT5hFAbD-LhWHiEtQAA7gc"]
[Thu Jul 30 12:35:41.744849 2026] [core:error] [pid 765155:tid 765328] [client 152.32.207.42:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:41.744866 2026] [core:error] [pid 765155:tid 765328] [client 152.32.207.42:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:42.071768 2026] [security2:error] [pid 765155:tid 765403] [client 20.52.125.110:7372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "amuLbuT5hFAbD-LhWHiEwgAAAPs"]
[Thu Jul 30 12:35:42.317087 2026] [core:notice] [pid 765155:tid 765309] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:42.321283 2026] [security2:error] [pid 765155:tid 765309] [client 103.215.74.26:43778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLbuT5hFAbD-LhWHiExAAAAJ0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:42.352494 2026] [security2:error] [pid 765155:tid 765334] [client 20.63.98.115:65430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "amuLbuT5hFAbD-LhWHiExQAAALY"]
[Thu Jul 30 12:35:42.640553 2026] [security2:error] [pid 765155:tid 765301] [client 20.52.125.110:6877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/acme-challenge/doc.php"] [unique_id "amuLbuT5hFAbD-LhWHiE0QAAAJU"]
[Thu Jul 30 12:35:42.954736 2026] [core:notice] [pid 765155:tid 765298] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:43.067062 2026] [core:notice] [pid 765155:tid 765286] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:43.070094 2026] [security2:error] [pid 765155:tid 765293] [client 20.63.98.115:65429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/customize/chosen.php"] [unique_id "amuLb-T5hFAbD-LhWHiE3gAAAI0"]
[Thu Jul 30 12:35:43.071958 2026] [security2:error] [pid 765155:tid 765286] [client 103.215.74.26:12752] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLb-T5hFAbD-LhWHiE3AAAAIY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:43.205191 2026] [proxy:error] [pid 765155:tid 765371] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:35:43.205251 2026] [proxy_http:error] [pid 765155:tid 765371] [client 20.52.125.110:6892] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:35:43.205814 2026] [proxy:error] [pid 765155:tid 765371] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:35:43.205856 2026] [proxy_http:error] [pid 765155:tid 765371] [client 20.52.125.110:6892] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:35:43.261011 2026] [proxy:error] [pid 765155:tid 765400] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:35:43.261093 2026] [proxy_http:error] [pid 765155:tid 765400] [client 32.194.121.99:50553] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:35:43.261652 2026] [proxy:error] [pid 765155:tid 765400] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:35:43.261694 2026] [proxy_http:error] [pid 765155:tid 765400] [client 32.194.121.99:50553] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:35:43.695250 2026] [security2:error] [pid 765155:tid 765354] [client 20.52.125.110:6868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/acme-challenge/fond.php"] [unique_id "amuLb-T5hFAbD-LhWHiFCwAAAMo"]
[Thu Jul 30 12:35:43.792385 2026] [core:notice] [pid 765155:tid 765320] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:43.796760 2026] [security2:error] [pid 765155:tid 765320] [client 103.215.74.26:12766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLb-T5hFAbD-LhWHiFEgAAAKg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:44.220715 2026] [security2:error] [pid 765155:tid 765405] [client 20.52.125.110:6726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "amuLcOT5hFAbD-LhWHiFLwAAAP0"]
[Thu Jul 30 12:35:44.469383 2026] [core:error] [pid 765155:tid 765383] [client 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:44.469408 2026] [core:error] [pid 765155:tid 765383] [client 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:44.510131 2026] [core:error] [pid 765155:tid 765328] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:44.510158 2026] [core:error] [pid 765155:tid 765328] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:44.531347 2026] [core:error] [pid 765155:tid 765349] [client 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:44.531367 2026] [core:error] [pid 765155:tid 765349] [client 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:44.543484 2026] [core:error] [pid 765155:tid 765295] [client 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:44.543502 2026] [core:error] [pid 765155:tid 765295] [client 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:44.545950 2026] [core:error] [pid 765155:tid 765353] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:44.545989 2026] [core:error] [pid 765155:tid 765353] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:44.549859 2026] [core:notice] [pid 765155:tid 765340] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:44.554168 2026] [security2:error] [pid 765155:tid 765340] [client 103.215.74.26:12780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLcOT5hFAbD-LhWHiFWAAAALw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:44.792761 2026] [security2:error] [pid 765155:tid 765404] [client 20.52.125.110:6848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/acme-challenge/license.php"] [unique_id "amuLcOT5hFAbD-LhWHiFWwAAAPw"]
[Thu Jul 30 12:35:45.255514 2026] [security2:error] [pid 765155:tid 765329] [client 20.52.125.110:6735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/acme-challenge/mariju.php"] [unique_id "amuLceT5hFAbD-LhWHiFZQAAALE"]
[Thu Jul 30 12:35:45.288668 2026] [core:notice] [pid 765155:tid 765298] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:45.292706 2026] [security2:error] [pid 765155:tid 765298] [client 103.215.74.26:12792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLceT5hFAbD-LhWHiFZgAAAJI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:45.803954 2026] [security2:error] [pid 765155:tid 765345] [client 20.52.125.110:6727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/acme-challenge/moon.php"] [unique_id "amuLceT5hFAbD-LhWHiFdQAAAME"]
[Thu Jul 30 12:35:46.008787 2026] [core:notice] [pid 765155:tid 765328] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:46.012851 2026] [security2:error] [pid 765155:tid 765328] [client 103.215.74.26:12806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "757"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLcuT5hFAbD-LhWHiFeQAAALA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:46.062839 2026] [proxy:error] [pid 765155:tid 765371] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:35:46.062913 2026] [proxy_http:error] [pid 765155:tid 765371] [client 3.228.112.215:17611] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:35:46.063733 2026] [proxy:error] [pid 765155:tid 765371] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:35:46.063779 2026] [proxy_http:error] [pid 765155:tid 765371] [client 3.228.112.215:17611] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:35:46.124640 2026] [security2:error] [pid 765155:tid 765351] [client 20.63.98.115:20678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/js/autoload_classmap.php"] [unique_id "amuLcuT5hFAbD-LhWHiFhAAAAMc"]
[Thu Jul 30 12:35:46.370904 2026] [security2:error] [pid 765155:tid 765340] [client 20.52.125.110:6894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amuLcuT5hFAbD-LhWHiFhgAAALw"]
[Thu Jul 30 12:35:46.747263 2026] [core:notice] [pid 765155:tid 765365] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:46.751274 2026] [security2:error] [pid 765155:tid 765365] [client 103.215.74.26:12810] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLcuT5hFAbD-LhWHiFmAAAANU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:46.920766 2026] [security2:error] [pid 765155:tid 765292] [client 20.52.125.110:6733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "amuLcuT5hFAbD-LhWHiFmQAAAIw"]
[Thu Jul 30 12:35:47.129168 2026] [security2:error] [pid 765155:tid 765389] [client 20.63.98.115:58203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/Text/autoload_classmap.php"] [unique_id "amuLc-T5hFAbD-LhWHiFoQAAAO0"]
[Thu Jul 30 12:35:47.463916 2026] [core:notice] [pid 765155:tid 765406] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:47.468286 2026] [security2:error] [pid 765155:tid 765406] [client 103.215.74.26:12820] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLc-T5hFAbD-LhWHiFpwAAAP4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:47.487547 2026] [security2:error] [pid 765155:tid 765290] [client 20.52.125.110:6731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "amuLc-T5hFAbD-LhWHiFqgAAAIo"]
[Thu Jul 30 12:35:47.997322 2026] [security2:error] [pid 765155:tid 765374] [client 20.52.125.110:6869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/amaxx.php"] [unique_id "amuLc-T5hFAbD-LhWHiFtAAAAN4"]
[Thu Jul 30 12:35:48.189939 2026] [core:notice] [pid 765155:tid 765369] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:48.198988 2026] [security2:error] [pid 765155:tid 765369] [client 103.215.74.26:12822] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLdOT5hFAbD-LhWHiFvwAAANk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:48.348899 2026] [security2:error] [pid 765155:tid 765295] [client 20.63.98.115:20548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/manager.php"] [unique_id "amuLdOT5hFAbD-LhWHiFwwAAAI8"]
[Thu Jul 30 12:35:48.609894 2026] [security2:error] [pid 765155:tid 765395] [client 74.7.244.42:59884] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-c5bc3a80.qgb.djb.temporary.site"] [uri "/index.php"] [unique_id "amuLc-T5hFAbD-LhWHiFsQAA8yA"]
[Thu Jul 30 12:35:48.756932 2026] [security2:error] [pid 765155:tid 765412] [client 20.52.125.110:6872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/bek.php"] [unique_id "amuLdOT5hFAbD-LhWHiF0AAAAQQ"]
[Thu Jul 30 12:35:48.932855 2026] [core:notice] [pid 765155:tid 765315] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:48.939646 2026] [security2:error] [pid 765155:tid 765315] [client 103.215.74.26:12832] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLdOT5hFAbD-LhWHiF0gAAAKM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:48.943108 2026] [core:notice] [pid 765155:tid 765382] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:49.342929 2026] [security2:error] [pid 765155:tid 765365] [client 20.52.125.110:6878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/caches.php.suspected"] [unique_id "amuLdeT5hFAbD-LhWHiF3QAAANU"]
[Thu Jul 30 12:35:49.665298 2026] [core:notice] [pid 765155:tid 765339] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:49.669322 2026] [security2:error] [pid 765155:tid 765339] [client 103.215.74.26:12840] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLdeT5hFAbD-LhWHiF4QAAALs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:49.951906 2026] [security2:error] [pid 765155:tid 765290] [client 20.52.125.110:6778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/class.api.php"] [unique_id "amuLdeT5hFAbD-LhWHiF6AAAAIo"]
[Thu Jul 30 12:35:50.400533 2026] [core:notice] [pid 765155:tid 765398] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:50.404505 2026] [security2:error] [pid 765155:tid 765398] [client 103.215.74.26:12850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "773"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLduT5hFAbD-LhWHiF8gAAAPY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:50.412401 2026] [core:error] [pid 765155:tid 765200] [remote 74.7.244.29:59842] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:50.412429 2026] [core:error] [pid 765155:tid 765200] [remote 74.7.244.29:59842] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:50.412593 2026] [security2:error] [pid 765155:tid 765372] [client 74.7.244.29:59842] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "website-e5d39057.jst.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuLduT5hFAbD-LhWHiF8wAA3Cw"]
[Thu Jul 30 12:35:50.504163 2026] [security2:error] [pid 765155:tid 765411] [client 20.52.125.110:6728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/cong.php"] [unique_id "amuLduT5hFAbD-LhWHiF9AAAAQM"]
[Thu Jul 30 12:35:50.694357 2026] [core:notice] [pid 765155:tid 765371] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:50.870514 2026] [security2:error] [pid 765155:tid 765394] [client 20.63.98.115:65408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-links.php"] [unique_id "amuLduT5hFAbD-LhWHiF_wAAAPI"]
[Thu Jul 30 12:35:51.059222 2026] [security2:error] [pid 765155:tid 765362] [client 20.52.125.110:6860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/content.php"] [unique_id "amuLd-T5hFAbD-LhWHiGAAAAANI"]
[Thu Jul 30 12:35:51.144247 2026] [core:notice] [pid 765155:tid 765370] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:51.151174 2026] [security2:error] [pid 765155:tid 765370] [client 103.215.74.26:12862] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLd-T5hFAbD-LhWHiGAQAAANo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:51.341546 2026] [security2:error] [pid 765155:tid 765319] [client 185.191.171.15:64988] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kendarikomputer.com"] [uri "/robots.txt"] [unique_id "amuLd-T5hFAbD-LhWHiGCAAAAKc"]
[Thu Jul 30 12:35:51.341657 2026] [security2:error] [pid 765155:tid 765319] [client 185.191.171.15:64988] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.kendarikomputer.com"] [uri "/robots.txt"] [unique_id "amuLd-T5hFAbD-LhWHiGCAAAAKc"]
[Thu Jul 30 12:35:51.542904 2026] [security2:error] [pid 765155:tid 765315] [client 20.52.125.110:6897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/cwianpri.php"] [unique_id "amuLd-T5hFAbD-LhWHiGDQAAAKM"]
[Thu Jul 30 12:35:51.671537 2026] [core:notice] [pid 765155:tid 765317] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:51.864707 2026] [core:notice] [pid 765155:tid 765365] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:51.869480 2026] [security2:error] [pid 765155:tid 765365] [client 103.215.74.26:12866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "786"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLd-T5hFAbD-LhWHiGFQAAANU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:51.977283 2026] [security2:error] [pid 765155:tid 765307] [client 49.47.10.252:34278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuLd-T5hFAbD-LhWHiGDgAAAJs"], referer: http://pkf.jo
[Thu Jul 30 12:35:52.055658 2026] [security2:error] [pid 765155:tid 765311] [client 20.52.125.110:6725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/elp.php"] [unique_id "amuLeOT5hFAbD-LhWHiGGgAAAJ8"]
[Thu Jul 30 12:35:52.347183 2026] [security2:error] [pid 765155:tid 765401] [client 20.63.98.115:58219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/fi2.php"] [unique_id "amuLeOT5hFAbD-LhWHiGIgAAAPk"]
[Thu Jul 30 12:35:52.499547 2026] [security2:error] [pid 765155:tid 765372] [client 20.52.125.110:6870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/kwggvpup.php"] [unique_id "amuLeOT5hFAbD-LhWHiGIwAAANw"]
[Thu Jul 30 12:35:52.523321 2026] [security2:error] [pid 765155:tid 765355] [client 185.191.171.1:54944] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kendarikomputer.com"] [uri "/2023/09/cara-menghilangkan-internet-baik"] [unique_id "amuLeOT5hFAbD-LhWHiGJAAAAMs"]
[Thu Jul 30 12:35:52.523461 2026] [security2:error] [pid 765155:tid 765355] [client 185.191.171.1:54944] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.kendarikomputer.com"] [uri "/2023/09/cara-menghilangkan-internet-baik"] [unique_id "amuLeOT5hFAbD-LhWHiGJAAAAMs"]
[Thu Jul 30 12:35:52.585827 2026] [core:notice] [pid 765155:tid 765227] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:52.592736 2026] [security2:error] [pid 765155:tid 765384] [client 83.44.180.240:54216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuLeOT5hFAbD-LhWHiGHwAAAOg"], referer: http://pkf.jo
[Thu Jul 30 12:35:52.632263 2026] [core:notice] [pid 765155:tid 765354] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:52.636231 2026] [security2:error] [pid 765155:tid 765354] [client 103.215.74.26:12878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLeOT5hFAbD-LhWHiGJwAAAMo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:53.064206 2026] [security2:error] [pid 765155:tid 765328] [client 20.52.125.110:6730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/101d2ae2-f2f3-4977-b35d-b3a0ad74a469.php"] [unique_id "amuLeeT5hFAbD-LhWHiGNAAAALA"]
[Thu Jul 30 12:35:53.366701 2026] [core:notice] [pid 765155:tid 765404] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:53.370761 2026] [security2:error] [pid 765155:tid 765404] [client 103.215.74.26:12954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "752"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLeeT5hFAbD-LhWHiGPAAAAPw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:53.558200 2026] [security2:error] [pid 765155:tid 765368] [client 20.63.98.115:20735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/0x.php"] [unique_id "amuLeeT5hFAbD-LhWHiGQQAAANg"]
[Thu Jul 30 12:35:53.660814 2026] [security2:error] [pid 765155:tid 765367] [client 20.52.125.110:6906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/LA.php"] [unique_id "amuLeeT5hFAbD-LhWHiGQwAAANc"]
[Thu Jul 30 12:35:54.115633 2026] [core:notice] [pid 765155:tid 765373] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:54.120633 2026] [security2:error] [pid 765155:tid 765373] [client 103.215.74.26:12958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLeuT5hFAbD-LhWHiGTQAAAN0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:54.243372 2026] [core:notice] [pid 765155:tid 765347] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:54.326697 2026] [security2:error] [pid 765155:tid 765324] [client 20.52.125.110:6741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/Newsupway.php"] [unique_id "amuLeuT5hFAbD-LhWHiGUwAAAKw"]
[Thu Jul 30 12:35:54.541293 2026] [core:error] [pid 765155:tid 765231] [remote 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:54.541322 2026] [core:error] [pid 765155:tid 765231] [remote 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:54.544841 2026] [core:error] [pid 765155:tid 765235] [remote 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:54.544858 2026] [core:error] [pid 765155:tid 765235] [remote 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:54.615111 2026] [core:error] [pid 765155:tid 765253] [remote 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:54.615152 2026] [core:error] [pid 765155:tid 765253] [remote 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:54.631778 2026] [core:error] [pid 765155:tid 765168] [remote 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:54.631795 2026] [core:error] [pid 765155:tid 765168] [remote 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:54.646877 2026] [core:notice] [pid 765155:tid 765332] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:54.672860 2026] [core:error] [pid 765155:tid 765249] [remote 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:54.672884 2026] [core:error] [pid 765155:tid 765249] [remote 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:54.690536 2026] [core:error] [pid 765155:tid 765228] [remote 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:54.690559 2026] [core:error] [pid 765155:tid 765228] [remote 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:54.768903 2026] [security2:error] [pid 765155:tid 765296] [client 20.63.98.115:44099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/k.php"] [unique_id "amuLeuT5hFAbD-LhWHiGbgAAAJA"]
[Thu Jul 30 12:35:54.853935 2026] [security2:error] [pid 765155:tid 765340] [client 37.120.155.179:37948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.155.120.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuLeuT5hFAbD-LhWHiGcQAAALw"]
[Thu Jul 30 12:35:54.854048 2026] [security2:error] [pid 765155:tid 765340] [client 37.120.155.179:37948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuLeuT5hFAbD-LhWHiGcQAAALw"]
[Thu Jul 30 12:35:54.896027 2026] [core:notice] [pid 765155:tid 765295] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:54.900648 2026] [security2:error] [pid 765155:tid 765295] [client 103.215.74.26:12960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLeuT5hFAbD-LhWHiGcgAAAI8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:54.914241 2026] [security2:error] [pid 765155:tid 765387] [client 20.52.125.110:6909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/a.php"] [unique_id "amuLeuT5hFAbD-LhWHiGcwAAAOs"]
[Thu Jul 30 12:35:55.508722 2026] [security2:error] [pid 765155:tid 765382] [client 20.52.125.110:6867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "amuLe-T5hFAbD-LhWHiGgQAAAOY"]
[Thu Jul 30 12:35:55.615545 2026] [core:notice] [pid 765155:tid 765304] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:55.620147 2026] [security2:error] [pid 765155:tid 765304] [client 103.215.74.26:12962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLe-T5hFAbD-LhWHiGhgAAAJg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:55.669994 2026] [core:notice] [pid 765155:tid 765367] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:56.115120 2026] [security2:error] [pid 765155:tid 765324] [client 20.52.125.110:6768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/amaxx.php"] [unique_id "amuLfOT5hFAbD-LhWHiGmAAAAKw"]
[Thu Jul 30 12:35:56.121621 2026] [core:notice] [pid 765155:tid 765359] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:56.335992 2026] [security2:error] [pid 765155:tid 765241] [remote 74.7.241.60:42332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/js/article.php"] [unique_id "amuLfOT5hFAbD-LhWHiGnQAA21U"], referer: https://aded-rdc.org/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/js/bootstrap.bundle.min.js
[Thu Jul 30 12:35:56.359333 2026] [core:notice] [pid 765155:tid 765356] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:56.363410 2026] [security2:error] [pid 765155:tid 765356] [client 103.215.74.26:12976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLfOT5hFAbD-LhWHiGngAAAMw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:56.442494 2026] [security2:error] [pid 765155:tid 765357] [client 20.63.98.115:20718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/gecko-new.php"] [unique_id "amuLfOT5hFAbD-LhWHiGnwAAAM0"]
[Thu Jul 30 12:35:56.692841 2026] [security2:error] [pid 765155:tid 765376] [client 20.52.125.110:6853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/bb.php"] [unique_id "amuLfOT5hFAbD-LhWHiGrAAAAOA"]
[Thu Jul 30 12:35:56.819870 2026] [security2:error] [pid 765155:tid 765411] [client 196.191.176.201:14475] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuLfOT5hFAbD-LhWHiGpAAAAQM"], referer: http://pkf.jo
[Thu Jul 30 12:35:57.101574 2026] [core:notice] [pid 765155:tid 765314] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:57.106105 2026] [security2:error] [pid 765155:tid 765314] [client 103.215.74.26:12992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLfeT5hFAbD-LhWHiGtgAAAKI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:57.209602 2026] [security2:error] [pid 765155:tid 765327] [client 20.52.125.110:6874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/cifcxgxm.php"] [unique_id "amuLfeT5hFAbD-LhWHiGugAAAK8"]
[Thu Jul 30 12:35:57.786141 2026] [security2:error] [pid 765155:tid 765409] [client 20.52.125.110:7363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/ckyocyyp.php"] [unique_id "amuLfeT5hFAbD-LhWHiGygAAAQE"]
[Thu Jul 30 12:35:57.808724 2026] [security2:error] [pid 765155:tid 765361] [client 74.7.175.190:43974] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "moswey.com"] [uri "/robots.txt"] [unique_id "amuLfeT5hFAbD-LhWHiGywAA0X0"]
[Thu Jul 30 12:35:57.827382 2026] [core:notice] [pid 765155:tid 765346] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:57.831746 2026] [security2:error] [pid 765155:tid 765346] [client 103.215.74.26:12996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLfeT5hFAbD-LhWHiGzAAAAMI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:58.020383 2026] [security2:error] [pid 765155:tid 765408] [client 85.208.96.205:24796] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/09/20/parceria-entre-creci-pb-e-tj-facilitara-prestacao-jurisdicional/"] [unique_id "amuLfuT5hFAbD-LhWHiGzQAAAQA"]
[Thu Jul 30 12:35:58.020518 2026] [security2:error] [pid 765155:tid 765408] [client 85.208.96.205:24796] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/09/20/parceria-entre-creci-pb-e-tj-facilitara-prestacao-jurisdicional/"] [unique_id "amuLfuT5hFAbD-LhWHiGzQAAAQA"]
[Thu Jul 30 12:35:58.247418 2026] [security2:error] [pid 765155:tid 765345] [client 20.52.125.110:7380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/classwithtostring.php"] [unique_id "amuLfuT5hFAbD-LhWHiG1gAAAME"]
[Thu Jul 30 12:35:58.413388 2026] [core:notice] [pid 765155:tid 765164] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:58.569468 2026] [core:notice] [pid 765155:tid 765354] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:58.573682 2026] [security2:error] [pid 765155:tid 765354] [client 103.215.74.26:13006] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLfuT5hFAbD-LhWHiG3QAAAMo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:58.785702 2026] [security2:error] [pid 765155:tid 765360] [client 20.52.125.110:6739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/content.php"] [unique_id "amuLfuT5hFAbD-LhWHiG4QAAANA"]
[Thu Jul 30 12:35:59.311847 2026] [security2:error] [pid 765155:tid 765286] [client 20.52.125.110:7367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/content.php.suspected"] [unique_id "amuLf-T5hFAbD-LhWHiG6wAAAIY"]
[Thu Jul 30 12:35:59.315028 2026] [core:notice] [pid 765155:tid 765348] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:59.320408 2026] [security2:error] [pid 765155:tid 765348] [client 103.215.74.26:13020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLf-T5hFAbD-LhWHiG7AAAAMQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:59.357665 2026] [security2:error] [pid 765155:tid 765398] [client 20.63.98.115:44102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/alfanew.php"] [unique_id "amuLf-T5hFAbD-LhWHiG7wAAAPY"]
[Thu Jul 30 12:36:00.046243 2026] [core:notice] [pid 765155:tid 765368] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:00.050967 2026] [security2:error] [pid 765155:tid 765368] [client 103.215.74.26:13036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLgOT5hFAbD-LhWHiG_QAAANg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:00.070685 2026] [security2:error] [pid 765155:tid 765317] [client 20.52.125.110:6890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/doc.php"] [unique_id "amuLgOT5hFAbD-LhWHiG_gAAAKU"]
[Thu Jul 30 12:36:00.447016 2026] [security2:error] [pid 765155:tid 765405] [client 38.190.144.4:64472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLgOT5hFAbD-LhWHiHCQAAAP0"]
[Thu Jul 30 12:36:00.447148 2026] [security2:error] [pid 765155:tid 765405] [client 38.190.144.4:64472] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLgOT5hFAbD-LhWHiHCQAAAP0"]
[Thu Jul 30 12:36:00.638431 2026] [security2:error] [pid 765155:tid 765318] [client 20.52.125.110:6895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/fond.php"] [unique_id "amuLgOT5hFAbD-LhWHiHCgAAAKY"]
[Thu Jul 30 12:36:01.215690 2026] [core:error] [pid 765155:tid 765395] [client 74.7.228.15:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:01.215711 2026] [core:error] [pid 765155:tid 765395] [client 74.7.228.15:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:01.215839 2026] [security2:error] [pid 765155:tid 765395] [client 74.7.228.15:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.vvr.hfl.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/index.php"] [unique_id "amuLgeT5hFAbD-LhWHiHFgAAAPM"]
[Thu Jul 30 12:36:01.216381 2026] [security2:error] [pid 765155:tid 765376] [client 74.7.228.15:57074] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.vvr.hfl.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "amuLgeT5hFAbD-LhWHiHFAAA4Ak"]
[Thu Jul 30 12:36:01.227714 2026] [security2:error] [pid 765155:tid 765316] [client 20.63.98.115:58202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/text.php"] [unique_id "amuLgeT5hFAbD-LhWHiHFwAAAKQ"]
[Thu Jul 30 12:36:01.349869 2026] [security2:error] [pid 765155:tid 765364] [client 20.52.125.110:6861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/gkiliuew.php"] [unique_id "amuLgeT5hFAbD-LhWHiHHgAAANQ"]
[Thu Jul 30 12:36:02.014231 2026] [security2:error] [pid 765155:tid 765367] [client 20.52.125.110:6900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/iR7SzrsOUEP.php"] [unique_id "amuLguT5hFAbD-LhWHiHMAAAANc"]
[Thu Jul 30 12:36:02.338997 2026] [security2:error] [pid 765155:tid 765304] [client 2a03:2880:f800:30:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuLgeT5hFAbD-LhWHiHJQAAmAI"]
[Thu Jul 30 12:36:02.457965 2026] [security2:error] [pid 765155:tid 765410] [client 68.221.69.72:38391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuLguT5hFAbD-LhWHiHOgAAAQI"]
[Thu Jul 30 12:36:02.458109 2026] [security2:error] [pid 765155:tid 765410] [client 68.221.69.72:38391] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuLguT5hFAbD-LhWHiHOgAAAQI"]
[Thu Jul 30 12:36:03.044741 2026] [security2:error] [pid 765155:tid 765288] [client 20.52.125.110:6873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/ibkejxnu.php"] [unique_id "amuLg-T5hFAbD-LhWHiHRwAAAIg"]
[Thu Jul 30 12:36:03.329502 2026] [security2:error] [pid 765155:tid 765342] [client 68.221.69.72:64775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuLg-T5hFAbD-LhWHiHTwAAAL4"]
[Thu Jul 30 12:36:03.329610 2026] [security2:error] [pid 765155:tid 765342] [client 68.221.69.72:64775] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuLg-T5hFAbD-LhWHiHTwAAAL4"]
[Thu Jul 30 12:36:03.623925 2026] [security2:error] [pid 765155:tid 765382] [client 20.52.125.110:7470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/install.php"] [unique_id "amuLg-T5hFAbD-LhWHiHWwAAAOY"]
[Thu Jul 30 12:36:03.680537 2026] [security2:error] [pid 765155:tid 765321] [client 20.63.98.115:38928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/f.php"] [unique_id "amuLg-T5hFAbD-LhWHiHXAAAAKk"]
[Thu Jul 30 12:36:04.072283 2026] [security2:error] [pid 765155:tid 765327] [client 74.7.241.128:58928] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.mobileblooddrawservices-com.aws.gzj.temporary.site"] [uri "/index.php"] [unique_id "amuLg-T5hFAbD-LhWHiHWAAArxw"]
[Thu Jul 30 12:36:04.157670 2026] [security2:error] [pid 765155:tid 765361] [client 138.186.20.11:44572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuLg-T5hFAbD-LhWHiHYQAAANE"], referer: http://pkf.jo
[Thu Jul 30 12:36:04.398872 2026] [security2:error] [pid 765155:tid 765392] [client 20.52.125.110:6862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/lang-load-role.php"] [unique_id "amuLhOT5hFAbD-LhWHiHbgAAAPA"]
[Thu Jul 30 12:36:04.546926 2026] [security2:error] [pid 765155:tid 765410] [client 20.63.98.115:21203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amuLhOT5hFAbD-LhWHiHcwAAAQI"]
[Thu Jul 30 12:36:04.748667 2026] [security2:error] [pid 765155:tid 765362] [client 68.221.69.72:14604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuLhOT5hFAbD-LhWHiHdwAAANI"]
[Thu Jul 30 12:36:04.748777 2026] [security2:error] [pid 765155:tid 765362] [client 68.221.69.72:14604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuLhOT5hFAbD-LhWHiHdwAAANI"]
[Thu Jul 30 12:36:04.936992 2026] [security2:error] [pid 765155:tid 765387] [client 20.52.125.110:7463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/link.php"] [unique_id "amuLhOT5hFAbD-LhWHiHggAAAOs"]
[Thu Jul 30 12:36:05.467125 2026] [security2:error] [pid 765155:tid 765206] [remote 151.158.180.11:59620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.180.158.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp-login.php"] [unique_id "amuLheT5hFAbD-LhWHiHnQAAwjI"]
[Thu Jul 30 12:36:05.576428 2026] [security2:error] [pid 765155:tid 765302] [client 20.52.125.110:7456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/mar.php"] [unique_id "amuLheT5hFAbD-LhWHiHoQAAAJY"]
[Thu Jul 30 12:36:05.855546 2026] [core:notice] [pid 765155:tid 765326] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:05.861003 2026] [security2:error] [pid 765155:tid 765326] [client 103.215.74.26:29056] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLheT5hFAbD-LhWHiHrgAAAK4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:06.005643 2026] [security2:error] [pid 765155:tid 765321] [client 20.63.98.115:21495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/hehe.php"] [unique_id "amuLhuT5hFAbD-LhWHiHswAAAKk"]
[Thu Jul 30 12:36:06.234316 2026] [security2:error] [pid 765155:tid 765357] [client 20.52.125.110:7486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "amuLhuT5hFAbD-LhWHiHuwAAAM0"]
[Thu Jul 30 12:36:06.411670 2026] [security2:error] [pid 765155:tid 765319] [client 68.221.69.72:64796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/err.php"] [unique_id "amuLhuT5hFAbD-LhWHiHvgAAAKc"]
[Thu Jul 30 12:36:06.411764 2026] [security2:error] [pid 765155:tid 765319] [client 68.221.69.72:64796] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/err.php"] [unique_id "amuLhuT5hFAbD-LhWHiHvgAAAKc"]
[Thu Jul 30 12:36:06.587302 2026] [core:notice] [pid 765155:tid 765352] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:06.591666 2026] [security2:error] [pid 765155:tid 765352] [client 103.215.74.26:29066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLhuT5hFAbD-LhWHiHxwAAAMg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:06.744258 2026] [security2:error] [pid 765155:tid 765379] [client 20.63.98.115:21501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/options.php"] [unique_id "amuLhuT5hFAbD-LhWHiHywAAAOM"]
[Thu Jul 30 12:36:06.849607 2026] [security2:error] [pid 765155:tid 765356] [client 20.52.125.110:7458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "amuLhuT5hFAbD-LhWHiHzQAAAMw"]
[Thu Jul 30 12:36:07.314146 2026] [core:notice] [pid 765155:tid 765298] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:07.318599 2026] [security2:error] [pid 765155:tid 765298] [client 103.215.74.26:29082] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLh-T5hFAbD-LhWHiH2AAAAJI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:07.432019 2026] [security2:error] [pid 765155:tid 765350] [client 20.52.125.110:6855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/plugins.php"] [unique_id "amuLh-T5hFAbD-LhWHiH3AAAAMY"]
[Thu Jul 30 12:36:08.025007 2026] [security2:error] [pid 765155:tid 765318] [client 20.52.125.110:7465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/post.php"] [unique_id "amuLiOT5hFAbD-LhWHiH6QAAAKY"]
[Thu Jul 30 12:36:08.062247 2026] [core:notice] [pid 765155:tid 765369] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:08.066910 2026] [security2:error] [pid 765155:tid 765369] [client 103.215.74.26:29086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLiOT5hFAbD-LhWHiH6gAAANk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:08.089299 2026] [security2:error] [pid 765155:tid 765287] [client 50.6.43.217:21580] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/1.jpg"] [unique_id "amuLiOT5hFAbD-LhWHiH6wAAAIc"]
[Thu Jul 30 12:36:08.098957 2026] [security2:error] [pid 765155:tid 765340] [client 50.6.43.217:21590] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/2.jpg"] [unique_id "amuLiOT5hFAbD-LhWHiH7AAAALw"]
[Thu Jul 30 12:36:08.108294 2026] [security2:error] [pid 765155:tid 765311] [client 50.6.43.217:21598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/3.jpg"] [unique_id "amuLiOT5hFAbD-LhWHiH7QAAAJ8"]
[Thu Jul 30 12:36:08.467796 2026] [security2:error] [pid 765155:tid 765357] [client 216.73.216.110:17171] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ajakholding.net"] [uri "/index.php"] [unique_id "amuLiOT5hFAbD-LhWHiH-AAAzV4"]
[Thu Jul 30 12:36:08.685702 2026] [security2:error] [pid 765155:tid 765337] [client 20.52.125.110:7462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/shell.php"] [unique_id "amuLiOT5hFAbD-LhWHiIAQAAALk"]
[Thu Jul 30 12:36:08.792098 2026] [core:notice] [pid 765155:tid 765403] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:08.795998 2026] [security2:error] [pid 765155:tid 765403] [client 103.215.74.26:29094] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLiOT5hFAbD-LhWHiICQAAAPs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:08.807609 2026] [security2:error] [pid 765155:tid 765312] [client 68.221.69.72:38354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/img.php"] [unique_id "amuLiOT5hFAbD-LhWHiICgAAAKA"]
[Thu Jul 30 12:36:08.807750 2026] [security2:error] [pid 765155:tid 765312] [client 68.221.69.72:38354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/img.php"] [unique_id "amuLiOT5hFAbD-LhWHiICgAAAKA"]
[Thu Jul 30 12:36:09.098509 2026] [security2:error] [pid 765155:tid 765307] [client 80.79.150.22:7058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuLiOT5hFAbD-LhWHiIBwAAAJs"], referer: http://pkf.jo
[Thu Jul 30 12:36:09.286972 2026] [security2:error] [pid 765155:tid 765363] [client 20.52.125.110:7464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/ssl.php"] [unique_id "amuLieT5hFAbD-LhWHiIEwAAANM"]
[Thu Jul 30 12:36:09.520866 2026] [core:notice] [pid 765155:tid 765298] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:09.528562 2026] [security2:error] [pid 765155:tid 765298] [client 103.215.74.26:29110] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLieT5hFAbD-LhWHiIGAAAAJI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:09.720248 2026] [security2:error] [pid 765155:tid 765292] [client 172.237.109.114:16270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLieT5hFAbD-LhWHiICwAAAIw"]
[Thu Jul 30 12:36:09.730540 2026] [security2:error] [pid 765155:tid 765406] [client 172.237.109.114:45394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLieT5hFAbD-LhWHiIDgAAAP4"]
[Thu Jul 30 12:36:09.734687 2026] [security2:error] [pid 765155:tid 765373] [client 172.237.109.114:10341] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLieT5hFAbD-LhWHiIDQAAAN0"]
[Thu Jul 30 12:36:09.734793 2026] [security2:error] [pid 765155:tid 765325] [client 172.237.109.114:55013] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLieT5hFAbD-LhWHiIDAAAAK0"]
[Thu Jul 30 12:36:09.742804 2026] [security2:error] [pid 765155:tid 765382] [client 172.237.109.114:18747] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLieT5hFAbD-LhWHiIDwAAAOY"]
[Thu Jul 30 12:36:09.851569 2026] [security2:error] [pid 765155:tid 765401] [client 20.52.125.110:6865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/sx.php"] [unique_id "amuLieT5hFAbD-LhWHiIJQAAAPk"]
[Thu Jul 30 12:36:10.246605 2026] [security2:error] [pid 765155:tid 765385] [client 20.63.98.115:21215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amuLiuT5hFAbD-LhWHiIMAAAAOk"]
[Thu Jul 30 12:36:10.256318 2026] [core:notice] [pid 765155:tid 765377] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:10.260272 2026] [security2:error] [pid 765155:tid 765377] [client 103.215.74.26:29126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "746"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLiuT5hFAbD-LhWHiIMQAAAOE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:10.445028 2026] [security2:error] [pid 765155:tid 765347] [client 20.52.125.110:7439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/themes.php"] [unique_id "amuLiuT5hFAbD-LhWHiINQAAAMM"]
[Thu Jul 30 12:36:10.749389 2026] [security2:error] [pid 765155:tid 765397] [client 68.221.69.72:38394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/aa.php"] [unique_id "amuLiuT5hFAbD-LhWHiIPAAAAPU"]
[Thu Jul 30 12:36:10.749524 2026] [security2:error] [pid 765155:tid 765397] [client 68.221.69.72:38394] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/aa.php"] [unique_id "amuLiuT5hFAbD-LhWHiIPAAAAPU"]
[Thu Jul 30 12:36:11.003720 2026] [core:notice] [pid 765155:tid 765292] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:11.008428 2026] [security2:error] [pid 765155:tid 765292] [client 103.215.74.26:29138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLi-T5hFAbD-LhWHiIQAAAAIw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:11.045965 2026] [security2:error] [pid 765155:tid 765402] [client 20.52.125.110:7470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/worksec.php"] [unique_id "amuLi-T5hFAbD-LhWHiIQQAAAPo"]
[Thu Jul 30 12:36:11.099750 2026] [security2:error] [pid 765155:tid 765340] [client 20.63.98.115:62424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/images/index.php"] [unique_id "amuLi-T5hFAbD-LhWHiIQgAAALw"]
[Thu Jul 30 12:36:11.284777 2026] [security2:error] [pid 765155:tid 765345] [client 38.190.144.4:64975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLi-T5hFAbD-LhWHiITAAAAME"]
[Thu Jul 30 12:36:11.284884 2026] [security2:error] [pid 765155:tid 765345] [client 38.190.144.4:64975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLi-T5hFAbD-LhWHiITAAAAME"]
[Thu Jul 30 12:36:11.637735 2026] [security2:error] [pid 765155:tid 765289] [client 20.52.125.110:7484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/wp-admin/install.php"] [unique_id "amuLi-T5hFAbD-LhWHiIUQAAAIk"]
[Thu Jul 30 12:36:11.737639 2026] [core:error] [pid 765155:tid 765337] [client 199.45.154.158:50956] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:11.737659 2026] [core:error] [pid 765155:tid 765337] [client 199.45.154.158:50956] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:11.738074 2026] [core:notice] [pid 765155:tid 765286] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:11.744108 2026] [security2:error] [pid 765155:tid 765286] [client 103.215.74.26:29144] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLi-T5hFAbD-LhWHiIWQAAAIY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:11.845084 2026] [core:error] [pid 765155:tid 765411] [client 74.7.230.30:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:11.845111 2026] [core:error] [pid 765155:tid 765411] [client 74.7.230.30:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:11.845230 2026] [security2:error] [pid 765155:tid 765411] [client 74.7.230.30:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.rru.djb.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "amuLi-T5hFAbD-LhWHiIXAAAAQM"]
[Thu Jul 30 12:36:11.845831 2026] [security2:error] [pid 765155:tid 765403] [client 74.7.230.30:32984] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.rru.djb.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "amuLi-T5hFAbD-LhWHiIWgAA-3o"]
[Thu Jul 30 12:36:12.174789 2026] [security2:error] [pid 765155:tid 765407] [client 74.7.230.0:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-468361c2.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuLi-T5hFAbD-LhWHiIXwAAAP8"]
[Thu Jul 30 12:36:12.175744 2026] [security2:error] [pid 765155:tid 765390] [client 74.7.230.0:48470] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-468361c2.glb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuLi-T5hFAbD-LhWHiIXQAA7g8"]
[Thu Jul 30 12:36:12.279185 2026] [security2:error] [pid 765155:tid 765384] [client 68.221.69.72:38375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/av.php"] [unique_id "amuLjOT5hFAbD-LhWHiIawAAAOg"]
[Thu Jul 30 12:36:12.279302 2026] [security2:error] [pid 765155:tid 765384] [client 68.221.69.72:38375] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/av.php"] [unique_id "amuLjOT5hFAbD-LhWHiIawAAAOg"]
[Thu Jul 30 12:36:12.490737 2026] [core:notice] [pid 765155:tid 765361] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:12.497518 2026] [security2:error] [pid 765155:tid 765361] [client 103.215.74.26:29148] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLjOT5hFAbD-LhWHiIcwAAANE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:12.516059 2026] [security2:error] [pid 765155:tid 765391] [client 20.52.125.110:6898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "amuLjOT5hFAbD-LhWHiIdAAAAO8"]
[Thu Jul 30 12:36:12.770731 2026] [security2:error] [pid 765155:tid 765353] [client 20.63.98.115:43946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/uploads/index.php"] [unique_id "amuLjOT5hFAbD-LhWHiIewAAAMk"]
[Thu Jul 30 12:36:13.197999 2026] [security2:error] [pid 765155:tid 765401] [client 41.251.191.60:60624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuLjOT5hFAbD-LhWHiIfgAAAPk"], referer: http://pkf.jo
[Thu Jul 30 12:36:13.239458 2026] [core:notice] [pid 765155:tid 765316] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:13.243712 2026] [security2:error] [pid 765155:tid 765316] [client 103.215.74.26:58130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLjeT5hFAbD-LhWHiIhAAAAKQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:13.497241 2026] [security2:error] [pid 765155:tid 765295] [client 185.182.217.177:37154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuLjeT5hFAbD-LhWHiIgwAAAI8"], referer: http://pkf.jo
[Thu Jul 30 12:36:13.786670 2026] [security2:error] [pid 765155:tid 765329] [client 68.221.69.72:64768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/xa.php"] [unique_id "amuLjeT5hFAbD-LhWHiIlwAAALE"]
[Thu Jul 30 12:36:13.786777 2026] [security2:error] [pid 765155:tid 765329] [client 68.221.69.72:64768] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/xa.php"] [unique_id "amuLjeT5hFAbD-LhWHiIlwAAALE"]
[Thu Jul 30 12:36:13.789955 2026] [security2:error] [pid 765155:tid 765358] [client 20.63.98.115:62826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/13.php"] [unique_id "amuLjeT5hFAbD-LhWHiImAAAAM4"]
[Thu Jul 30 12:36:13.958072 2026] [core:notice] [pid 765155:tid 765293] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:13.963121 2026] [security2:error] [pid 765155:tid 765293] [client 103.215.74.26:58146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "765"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLjeT5hFAbD-LhWHiInAAAAI0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:14.479719 2026] [fcgid:warn] [pid 765155:tid 765309] (70014)End of file found: [client 165.154.138.79:35748] mod_fcgid: can't get data from http client
[Thu Jul 30 12:36:14.696097 2026] [core:notice] [pid 765155:tid 765351] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:14.703463 2026] [security2:error] [pid 765155:tid 765351] [client 103.215.74.26:58160] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLjuT5hFAbD-LhWHiIqwAAAMc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:14.789046 2026] [security2:error] [pid 765155:tid 765363] [client 72.255.16.111:17799] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuLjuT5hFAbD-LhWHiIpwAAANM"], referer: http://pkf.jo
[Thu Jul 30 12:36:15.257487 2026] [security2:error] [pid 765155:tid 765392] [client 43.172.194.170:46664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.194.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2010/08/09/mon-sac-de-plage-ideal-le-beach-shoulder-bag-folli-follie/"] [unique_id "amuLj-T5hFAbD-LhWHiIsgAAAPA"]
[Thu Jul 30 12:36:15.437295 2026] [core:notice] [pid 765155:tid 765361] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:15.441201 2026] [security2:error] [pid 765155:tid 765361] [client 103.215.74.26:58174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "778"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLj-T5hFAbD-LhWHiIvgAAANE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:15.484484 2026] [security2:error] [pid 765155:tid 765349] [client 68.221.69.72:14603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/media.php"] [unique_id "amuLj-T5hFAbD-LhWHiIvwAAAMU"]
[Thu Jul 30 12:36:15.484598 2026] [security2:error] [pid 765155:tid 765349] [client 68.221.69.72:14603] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/media.php"] [unique_id "amuLj-T5hFAbD-LhWHiIvwAAAMU"]
[Thu Jul 30 12:36:15.565077 2026] [security2:error] [pid 765155:tid 765340] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuLj-T5hFAbD-LhWHiIxgAAALw"]
[Thu Jul 30 12:36:15.565184 2026] [security2:error] [pid 765155:tid 765340] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuLj-T5hFAbD-LhWHiIxgAAALw"]
[Thu Jul 30 12:36:15.755005 2026] [security2:error] [pid 765155:tid 765341] [client 193.47.62.167:35356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ssa.djb.temporary.site"] [uri "/index.php"] [unique_id "amuLj-T5hFAbD-LhWHiIxwAAAL0"]
[Thu Jul 30 12:36:15.921268 2026] [core:error] [pid 765155:tid 765384] [client 20.63.98.115:20827] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:15.921288 2026] [core:error] [pid 765155:tid 765384] [client 20.63.98.115:20827] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:16.026417 2026] [core:notice] [pid 765155:tid 765314] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:16.031073 2026] [security2:error] [pid 765155:tid 765314] [client 43.173.173.8:56220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2010/08/09/mon-sac-de-plage-ideal-le-beach-shoulder-bag-folli-follie/"] [unique_id "amuLkOT5hFAbD-LhWHiIzwAAAKI"], referer: https://carnetdeshopping.com/index.php/2010/08/09/mon-sac-de-plage-ideal-le-beach-shoulder-bag-folli-follie/
[Thu Jul 30 12:36:16.068322 2026] [security2:error] [pid 765155:tid 765337] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuLkOT5hFAbD-LhWHiI0gAAALk"]
[Thu Jul 30 12:36:16.068426 2026] [security2:error] [pid 765155:tid 765337] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuLkOT5hFAbD-LhWHiI0gAAALk"]
[Thu Jul 30 12:36:16.171572 2026] [core:notice] [pid 765155:tid 765378] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:16.175614 2026] [security2:error] [pid 765155:tid 765378] [client 103.215.74.26:58190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLkOT5hFAbD-LhWHiI1QAAAOI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:16.272807 2026] [security2:error] [pid 765155:tid 765356] [client 68.221.69.72:38363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/images.php"] [unique_id "amuLkOT5hFAbD-LhWHiI1gAAAMw"]
[Thu Jul 30 12:36:16.272912 2026] [security2:error] [pid 765155:tid 765356] [client 68.221.69.72:38363] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/images.php"] [unique_id "amuLkOT5hFAbD-LhWHiI1gAAAMw"]
[Thu Jul 30 12:36:16.604798 2026] [security2:error] [pid 765155:tid 765407] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/inputs.php"] [unique_id "amuLkOT5hFAbD-LhWHiI4AAAAP8"]
[Thu Jul 30 12:36:16.604924 2026] [security2:error] [pid 765155:tid 765407] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/inputs.php"] [unique_id "amuLkOT5hFAbD-LhWHiI4AAAAP8"]
[Thu Jul 30 12:36:16.753001 2026] [security2:error] [pid 765155:tid 765301] [client 20.63.98.115:62786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/inputs.php"] [unique_id "amuLkOT5hFAbD-LhWHiI6QAAAJU"]
[Thu Jul 30 12:36:16.887567 2026] [core:notice] [pid 765155:tid 765298] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:16.891338 2026] [security2:error] [pid 765155:tid 765298] [client 103.215.74.26:58200] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLkOT5hFAbD-LhWHiI7QAAAJI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:17.035765 2026] [security2:error] [pid 765155:tid 765400] [client 68.221.69.72:14616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/gecko.php"] [unique_id "amuLkeT5hFAbD-LhWHiI8gAAAPg"]
[Thu Jul 30 12:36:17.035890 2026] [security2:error] [pid 765155:tid 765400] [client 68.221.69.72:14616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/gecko.php"] [unique_id "amuLkeT5hFAbD-LhWHiI8gAAAPg"]
[Thu Jul 30 12:36:17.132145 2026] [security2:error] [pid 765155:tid 765327] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/admin.php"] [unique_id "amuLkeT5hFAbD-LhWHiI-AAAAK8"]
[Thu Jul 30 12:36:17.132253 2026] [security2:error] [pid 765155:tid 765327] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/admin.php"] [unique_id "amuLkeT5hFAbD-LhWHiI-AAAAK8"]
[Thu Jul 30 12:36:17.325100 2026] [security2:error] [pid 765155:tid 765325] [client 156.194.169.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuLkeT5hFAbD-LhWHiI-wAAAK0"], referer: https://cnpinyin.com
[Thu Jul 30 12:36:17.577515 2026] [security2:error] [pid 765155:tid 765345] [client 68.221.69.72:65466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/82.php"] [unique_id "amuLkeT5hFAbD-LhWHiJCgAAAME"]
[Thu Jul 30 12:36:17.577627 2026] [security2:error] [pid 765155:tid 765345] [client 68.221.69.72:65466] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/82.php"] [unique_id "amuLkeT5hFAbD-LhWHiJCgAAAME"]
[Thu Jul 30 12:36:17.650973 2026] [core:notice] [pid 765155:tid 765316] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:17.655072 2026] [security2:error] [pid 765155:tid 765316] [client 103.215.74.26:58216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "738"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLkeT5hFAbD-LhWHiJCwAAAKQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:17.663580 2026] [security2:error] [pid 765155:tid 765338] [client 20.63.98.115:62816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/jquery.php"] [unique_id "amuLkeT5hFAbD-LhWHiJDAAAALo"]
[Thu Jul 30 12:36:17.911999 2026] [security2:error] [pid 765155:tid 765344] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/goods.php"] [unique_id "amuLkeT5hFAbD-LhWHiJEwAAAMA"]
[Thu Jul 30 12:36:17.912085 2026] [security2:error] [pid 765155:tid 765344] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/goods.php"] [unique_id "amuLkeT5hFAbD-LhWHiJEwAAAMA"]
[Thu Jul 30 12:36:18.007108 2026] [security2:error] [pid 765155:tid 765402] [client 57.141.0.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuLkeT5hFAbD-LhWHiJAgAAAPo"]
[Thu Jul 30 12:36:18.393813 2026] [core:notice] [pid 765155:tid 765322] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:18.397794 2026] [security2:error] [pid 765155:tid 765322] [client 103.215.74.26:58230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "740"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLkuT5hFAbD-LhWHiJHwAAAKo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:18.416841 2026] [security2:error] [pid 765155:tid 765380] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/file.php"] [unique_id "amuLkuT5hFAbD-LhWHiJIgAAAOQ"]
[Thu Jul 30 12:36:18.416924 2026] [security2:error] [pid 765155:tid 765380] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/file.php"] [unique_id "amuLkuT5hFAbD-LhWHiJIgAAAOQ"]
[Thu Jul 30 12:36:18.606643 2026] [security2:error] [pid 765155:tid 765399] [client 20.63.98.115:62846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/doc.php"] [unique_id "amuLkuT5hFAbD-LhWHiJJQAAAPc"]
[Thu Jul 30 12:36:18.609807 2026] [security2:error] [pid 765155:tid 765362] [client 68.221.69.72:64776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/xstelth.php"] [unique_id "amuLkuT5hFAbD-LhWHiJJgAAANI"]
[Thu Jul 30 12:36:18.609888 2026] [security2:error] [pid 765155:tid 765362] [client 68.221.69.72:64776] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/xstelth.php"] [unique_id "amuLkuT5hFAbD-LhWHiJJgAAANI"]
[Thu Jul 30 12:36:18.895611 2026] [security2:error] [pid 765155:tid 765359] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/adminfuns.php"] [unique_id "amuLkuT5hFAbD-LhWHiJLgAAAM8"]
[Thu Jul 30 12:36:18.895708 2026] [security2:error] [pid 765155:tid 765359] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/adminfuns.php"] [unique_id "amuLkuT5hFAbD-LhWHiJLgAAAM8"]
[Thu Jul 30 12:36:19.114137 2026] [core:notice] [pid 765155:tid 765320] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:19.118076 2026] [security2:error] [pid 765155:tid 765320] [client 103.215.74.26:58238] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "732"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLk-T5hFAbD-LhWHiJMgAAAKg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:19.389412 2026] [security2:error] [pid 765155:tid 765311] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/404.php"] [unique_id "amuLk-T5hFAbD-LhWHiJOgAAAJ8"]
[Thu Jul 30 12:36:19.389558 2026] [security2:error] [pid 765155:tid 765311] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/404.php"] [unique_id "amuLk-T5hFAbD-LhWHiJOgAAAJ8"]
[Thu Jul 30 12:36:19.831510 2026] [security2:error] [pid 765155:tid 765292] [client 105.165.75.222:38094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuLk-T5hFAbD-LhWHiJPgAAAIw"], referer: http://pkf.jo
[Thu Jul 30 12:36:19.850758 2026] [security2:error] [pid 765155:tid 765371] [client 68.221.69.72:38365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/xp.php"] [unique_id "amuLk-T5hFAbD-LhWHiJRAAAANs"]
[Thu Jul 30 12:36:19.850922 2026] [security2:error] [pid 765155:tid 765371] [client 68.221.69.72:38365] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/xp.php"] [unique_id "amuLk-T5hFAbD-LhWHiJRAAAANs"]
[Thu Jul 30 12:36:19.975134 2026] [security2:error] [pid 765155:tid 765395] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wk/index.php"] [unique_id "amuLk-T5hFAbD-LhWHiJTgAAAPM"]
[Thu Jul 30 12:36:19.975221 2026] [security2:error] [pid 765155:tid 765395] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wk/index.php"] [unique_id "amuLk-T5hFAbD-LhWHiJTgAAAPM"]
[Thu Jul 30 12:36:20.358599 2026] [fcgid:warn] [pid 765155:tid 765402] (70014)End of file found: [client 156.229.16.165:38084] mod_fcgid: can't get data from http client
[Thu Jul 30 12:36:20.367336 2026] [security2:error] [pid 765155:tid 765348] [client 119.73.97.132:31239] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuLk-T5hFAbD-LhWHiJSAAAxEI"], referer: https://www.urwru.club/emm-elevate/?preview_id=685&preview_nonce=6cdd8f071f&preview=true&aaeid=1
[Thu Jul 30 12:36:20.367466 2026] [security2:error] [pid 765155:tid 765348] [client 119.73.97.132:31239] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuLk-T5hFAbD-LhWHiJQQAAxE8"]
[Thu Jul 30 12:36:20.367550 2026] [security2:error] [pid 765155:tid 765348] [client 119.73.97.132:31239] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuLk-T5hFAbD-LhWHiJQgAAxGE"]
[Thu Jul 30 12:36:20.534848 2026] [security2:error] [pid 765155:tid 765389] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/about.php"] [unique_id "amuLlOT5hFAbD-LhWHiJXwAAAO0"]
[Thu Jul 30 12:36:20.534987 2026] [security2:error] [pid 765155:tid 765389] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/about.php"] [unique_id "amuLlOT5hFAbD-LhWHiJXwAAAO0"]
[Thu Jul 30 12:36:20.646562 2026] [security2:error] [pid 765155:tid 765306] [client 20.63.98.115:65429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/02.php"] [unique_id "amuLlOT5hFAbD-LhWHiJYgAAAJo"]
[Thu Jul 30 12:36:21.071039 2026] [security2:error] [pid 765155:tid 765408] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/term.php"] [unique_id "amuLleT5hFAbD-LhWHiJcAAAAQA"]
[Thu Jul 30 12:36:21.071145 2026] [security2:error] [pid 765155:tid 765408] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/term.php"] [unique_id "amuLleT5hFAbD-LhWHiJcAAAAQA"]
[Thu Jul 30 12:36:21.282150 2026] [proxy:error] [pid 765155:tid 765410] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:36:21.282234 2026] [proxy_http:error] [pid 765155:tid 765410] [client 156.229.16.165:38094] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:36:21.282815 2026] [proxy:error] [pid 765155:tid 765410] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:36:21.282858 2026] [proxy_http:error] [pid 765155:tid 765410] [client 156.229.16.165:38094] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:36:21.457704 2026] [security2:error] [pid 765155:tid 765327] [client 82.194.28.254:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuLleT5hFAbD-LhWHiJeAAAAK8"], referer: https://cnpinyin.com
[Thu Jul 30 12:36:21.601820 2026] [security2:error] [pid 765155:tid 765375] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/ioxi-o.php"] [unique_id "amuLleT5hFAbD-LhWHiJgwAAAN8"]
[Thu Jul 30 12:36:21.601992 2026] [security2:error] [pid 765155:tid 765375] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/ioxi-o.php"] [unique_id "amuLleT5hFAbD-LhWHiJgwAAAN8"]
[Thu Jul 30 12:36:21.766372 2026] [security2:error] [pid 765155:tid 765311] [client 20.63.98.115:58065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/well-known/admin.php"] [unique_id "amuLleT5hFAbD-LhWHiJjQAAAJ8"]
[Thu Jul 30 12:36:21.768871 2026] [core:notice] [pid 765155:tid 765363] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:21.989682 2026] [security2:error] [pid 765155:tid 765304] [client 172.236.9.101:54281] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLleT5hFAbD-LhWHiJegAAAJg"]
[Thu Jul 30 12:36:22.025677 2026] [security2:error] [pid 765155:tid 765315] [client 172.236.9.101:57868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLleT5hFAbD-LhWHiJewAAAKM"]
[Thu Jul 30 12:36:22.115739 2026] [security2:error] [pid 765155:tid 765355] [client 20.104.22.47:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/1.php"] [unique_id "amuLluT5hFAbD-LhWHiJxAAAAMs"]
[Thu Jul 30 12:36:22.115851 2026] [security2:error] [pid 765155:tid 765355] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/1.php"] [unique_id "amuLluT5hFAbD-LhWHiJxAAAAMs"]
[Thu Jul 30 12:36:22.115947 2026] [security2:error] [pid 765155:tid 765355] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/1.php"] [unique_id "amuLluT5hFAbD-LhWHiJxAAAAMs"]
[Thu Jul 30 12:36:22.210892 2026] [security2:error] [pid 765155:tid 765290] [client 39.63.38.93:48410] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuLleT5hFAbD-LhWHiJvQAAAIo"], referer: http://pkf.jo
[Thu Jul 30 12:36:22.229114 2026] [security2:error] [pid 765155:tid 765292] [client 38.190.144.4:65480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLluT5hFAbD-LhWHiJywAAAIw"]
[Thu Jul 30 12:36:22.229215 2026] [security2:error] [pid 765155:tid 765292] [client 38.190.144.4:65480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLluT5hFAbD-LhWHiJywAAAIw"]
[Thu Jul 30 12:36:22.393329 2026] [security2:error] [pid 765155:tid 765319] [client 178.20.45.159:53466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.45.20.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/register"] [unique_id "amuLluT5hFAbD-LhWHiJxQAAAKc"], referer: https://cnpinyin.com/register
[Thu Jul 30 12:36:22.496733 2026] [security2:error] [pid 765155:tid 765343] [client 68.221.69.72:38381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/admin.php"] [unique_id "amuLluT5hFAbD-LhWHiJ9gAAAL8"]
[Thu Jul 30 12:36:22.496895 2026] [security2:error] [pid 765155:tid 765343] [client 68.221.69.72:38381] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/admin.php"] [unique_id "amuLluT5hFAbD-LhWHiJ9gAAAL8"]
[Thu Jul 30 12:36:22.595529 2026] [security2:error] [pid 765155:tid 765360] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/alfa.php"] [unique_id "amuLluT5hFAbD-LhWHiJ-wAAANA"]
[Thu Jul 30 12:36:22.595706 2026] [security2:error] [pid 765155:tid 765360] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/alfa.php"] [unique_id "amuLluT5hFAbD-LhWHiJ-wAAANA"]
[Thu Jul 30 12:36:22.854253 2026] [core:error] [pid 765155:tid 765333] [client 20.63.98.115:49759] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:22.854279 2026] [core:error] [pid 765155:tid 765333] [client 20.63.98.115:49759] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:22.921638 2026] [proxy:error] [pid 765155:tid 765411] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:36:22.921738 2026] [proxy_http:error] [pid 765155:tid 765411] [client 156.229.16.165:38108] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:36:22.922837 2026] [proxy:error] [pid 765155:tid 765411] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:36:22.922899 2026] [proxy_http:error] [pid 765155:tid 765411] [client 156.229.16.165:38108] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:36:23.033511 2026] [security2:error] [pid 765155:tid 765215] [remote 157.55.39.58:6634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.39.55.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/offres-demploi/article.php"] [unique_id "amuLl-T5hFAbD-LhWHiKBAAAvTs"]
[Thu Jul 30 12:36:23.097276 2026] [security2:error] [pid 765155:tid 765357] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/edit.php"] [unique_id "amuLl-T5hFAbD-LhWHiKCwAAAM0"]
[Thu Jul 30 12:36:23.097400 2026] [security2:error] [pid 765155:tid 765357] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/edit.php"] [unique_id "amuLl-T5hFAbD-LhWHiKCwAAAM0"]
[Thu Jul 30 12:36:23.216224 2026] [security2:error] [pid 765155:tid 765384] [client 178.20.45.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuLl-T5hFAbD-LhWHiKCgAAAOg"], referer: https://cnpinyin.com/register
[Thu Jul 30 12:36:23.490407 2026] [security2:error] [pid 765155:tid 765381] [client 172.236.9.101:5601] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLluT5hFAbD-LhWHiJ2gAAAOU"]
[Thu Jul 30 12:36:23.605710 2026] [security2:error] [pid 765155:tid 765302] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/elp.php"] [unique_id "amuLl-T5hFAbD-LhWHiKGgAAAJY"]
[Thu Jul 30 12:36:23.605884 2026] [security2:error] [pid 765155:tid 765302] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/elp.php"] [unique_id "amuLl-T5hFAbD-LhWHiKGgAAAJY"]
[Thu Jul 30 12:36:23.654072 2026] [security2:error] [pid 765155:tid 765368] [client 172.236.9.101:45037] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLluT5hFAbD-LhWHiJ5AAAANg"]
[Thu Jul 30 12:36:23.671488 2026] [security2:error] [pid 765155:tid 765365] [client 172.236.9.101:65290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLluT5hFAbD-LhWHiJ2QAAANU"]
[Thu Jul 30 12:36:23.801094 2026] [security2:error] [pid 765155:tid 765391] [client 68.221.69.72:14629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/adminner.php"] [unique_id "amuLl-T5hFAbD-LhWHiKHAAAAO8"]
[Thu Jul 30 12:36:23.801243 2026] [security2:error] [pid 765155:tid 765391] [client 68.221.69.72:14629] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/adminner.php"] [unique_id "amuLl-T5hFAbD-LhWHiKHAAAAO8"]
[Thu Jul 30 12:36:24.244704 2026] [security2:error] [pid 765155:tid 765285] [client 172.236.9.101:46315] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLluT5hFAbD-LhWHiJ8QAAAIU"]
[Thu Jul 30 12:36:24.247801 2026] [security2:error] [pid 765155:tid 765306] [client 172.236.9.101:53822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLluT5hFAbD-LhWHiJ2wAAAJo"]
[Thu Jul 30 12:36:24.253325 2026] [security2:error] [pid 765155:tid 765383] [client 172.236.9.101:42578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLluT5hFAbD-LhWHiJ3QAAAOc"]
[Thu Jul 30 12:36:24.267795 2026] [security2:error] [pid 765155:tid 765296] [client 172.236.9.101:11546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLluT5hFAbD-LhWHiJ5QAAAJA"]
[Thu Jul 30 12:36:24.272318 2026] [security2:error] [pid 765155:tid 765291] [client 172.236.9.101:36710] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLluT5hFAbD-LhWHiJ4gAAAIs"]
[Thu Jul 30 12:36:24.282380 2026] [security2:error] [pid 765155:tid 765309] [client 172.236.9.101:9475] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLluT5hFAbD-LhWHiJ5wAAAJ0"]
[Thu Jul 30 12:36:24.305143 2026] [security2:error] [pid 765155:tid 765407] [client 172.236.9.101:28791] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLluT5hFAbD-LhWHiJ6AAAAP8"]
[Thu Jul 30 12:36:24.328230 2026] [security2:error] [pid 765155:tid 765367] [client 172.236.9.101:65228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLluT5hFAbD-LhWHiJ4AAAANc"]
[Thu Jul 30 12:36:24.338412 2026] [security2:error] [pid 765155:tid 765347] [client 172.236.9.101:11871] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLluT5hFAbD-LhWHiJ3AAAAMM"]
[Thu Jul 30 12:36:24.349469 2026] [security2:error] [pid 765155:tid 765409] [client 172.236.9.101:48412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLluT5hFAbD-LhWHiJ4wAAAQE"]
[Thu Jul 30 12:36:24.376465 2026] [security2:error] [pid 765155:tid 765393] [client 172.236.9.101:22725] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLluT5hFAbD-LhWHiJ5gAAAPE"]
[Thu Jul 30 12:36:24.405047 2026] [security2:error] [pid 765155:tid 765351] [client 172.236.9.101:63530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLluT5hFAbD-LhWHiJ7wAAAMc"]
[Thu Jul 30 12:36:24.408487 2026] [security2:error] [pid 765155:tid 765362] [client 172.236.9.101:1498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLluT5hFAbD-LhWHiJ4QAAANI"]
[Thu Jul 30 12:36:24.423545 2026] [security2:error] [pid 765155:tid 765301] [client 172.236.9.101:4290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLluT5hFAbD-LhWHiJ8AAAAJU"]
[Thu Jul 30 12:36:24.486087 2026] [proxy:error] [pid 765155:tid 765396] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:36:24.486160 2026] [proxy_http:error] [pid 765155:tid 765396] [client 156.229.16.165:38112] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:36:24.486732 2026] [proxy:error] [pid 765155:tid 765396] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:36:24.486782 2026] [proxy_http:error] [pid 765155:tid 765396] [client 156.229.16.165:38112] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:36:24.543858 2026] [security2:error] [pid 765155:tid 765324] [client 172.236.9.101:34912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLluT5hFAbD-LhWHiJ7gAAAKw"]
[Thu Jul 30 12:36:24.854926 2026] [core:notice] [pid 765155:tid 765404] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:24.859237 2026] [security2:error] [pid 765155:tid 765404] [client 103.215.74.26:8782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "740"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLmOT5hFAbD-LhWHiKMwAAAPw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:24.894534 2026] [security2:error] [pid 765155:tid 765377] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/classwithtostring.php"] [unique_id "amuLmOT5hFAbD-LhWHiKNAAAAOE"]
[Thu Jul 30 12:36:24.894640 2026] [security2:error] [pid 765155:tid 765377] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/classwithtostring.php"] [unique_id "amuLmOT5hFAbD-LhWHiKNAAAAOE"]
[Thu Jul 30 12:36:24.997826 2026] [security2:error] [pid 765155:tid 765378] [client 68.221.69.72:64769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/a.php"] [unique_id "amuLmOT5hFAbD-LhWHiKOAAAAOI"]
[Thu Jul 30 12:36:24.997951 2026] [security2:error] [pid 765155:tid 765378] [client 68.221.69.72:64769] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/a.php"] [unique_id "amuLmOT5hFAbD-LhWHiKOAAAAOI"]
[Thu Jul 30 12:36:25.045128 2026] [security2:error] [pid 765155:tid 765307] [client 20.63.98.115:58061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/v.php"] [unique_id "amuLmeT5hFAbD-LhWHiKOgAAAJs"]
[Thu Jul 30 12:36:25.417030 2026] [security2:error] [pid 765155:tid 765352] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/666.php"] [unique_id "amuLmeT5hFAbD-LhWHiKQwAAAMg"]
[Thu Jul 30 12:36:25.417158 2026] [security2:error] [pid 765155:tid 765352] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/666.php"] [unique_id "amuLmeT5hFAbD-LhWHiKQwAAAMg"]
[Thu Jul 30 12:36:25.479844 2026] [proxy:error] [pid 765155:tid 765391] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:36:25.479941 2026] [proxy_http:error] [pid 765155:tid 765391] [client 156.229.16.165:60460] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:36:25.480569 2026] [proxy:error] [pid 765155:tid 765391] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:36:25.480617 2026] [proxy_http:error] [pid 765155:tid 765391] [client 156.229.16.165:60460] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:36:25.598241 2026] [security2:error] [pid 765155:tid 765361] [client 194.187.251.163:48910] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuLmeT5hFAbD-LhWHiKSAAAANE"]
[Thu Jul 30 12:36:25.598353 2026] [security2:error] [pid 765155:tid 765361] [client 194.187.251.163:48910] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuLmeT5hFAbD-LhWHiKSAAAANE"]
[Thu Jul 30 12:36:25.754126 2026] [security2:error] [pid 765155:tid 765294] [client 68.221.69.72:64792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/k.php"] [unique_id "amuLmeT5hFAbD-LhWHiKTwAAAI4"]
[Thu Jul 30 12:36:25.754236 2026] [security2:error] [pid 765155:tid 765294] [client 68.221.69.72:64792] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/k.php"] [unique_id "amuLmeT5hFAbD-LhWHiKTwAAAI4"]
[Thu Jul 30 12:36:25.850337 2026] [security2:error] [pid 765155:tid 765287] [client 20.63.98.115:57180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/main.php"] [unique_id "amuLmeT5hFAbD-LhWHiKUQAAAIc"]
[Thu Jul 30 12:36:25.933841 2026] [security2:error] [pid 765155:tid 765375] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_webdisk/wp-admin/"] [unique_id "amuLmeT5hFAbD-LhWHiKUgAAAN8"]
[Thu Jul 30 12:36:26.173163 2026] [security2:error] [pid 765155:tid 765347] [client 68.221.69.72:14644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/222.php"] [unique_id "amuLmuT5hFAbD-LhWHiKVgAAAMM"]
[Thu Jul 30 12:36:26.173316 2026] [security2:error] [pid 765155:tid 765347] [client 68.221.69.72:14644] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/222.php"] [unique_id "amuLmuT5hFAbD-LhWHiKVgAAAMM"]
[Thu Jul 30 12:36:26.179520 2026] [security2:error] [pid 765155:tid 765363] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/ws54.php"] [unique_id "amuLmuT5hFAbD-LhWHiKWAAAANM"]
[Thu Jul 30 12:36:26.179607 2026] [security2:error] [pid 765155:tid 765363] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/ws54.php"] [unique_id "amuLmuT5hFAbD-LhWHiKWAAAANM"]
[Thu Jul 30 12:36:26.689368 2026] [security2:error] [pid 765155:tid 765316] [client 68.221.69.72:38344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/mac.php"] [unique_id "amuLmuT5hFAbD-LhWHiKaAAAAKQ"]
[Thu Jul 30 12:36:26.689470 2026] [security2:error] [pid 765155:tid 765316] [client 68.221.69.72:38344] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/mac.php"] [unique_id "amuLmuT5hFAbD-LhWHiKaAAAAKQ"]
[Thu Jul 30 12:36:26.700965 2026] [security2:error] [pid 765155:tid 765337] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/deepseek_d.php"] [unique_id "amuLmuT5hFAbD-LhWHiKaQAAALk"]
[Thu Jul 30 12:36:26.701057 2026] [security2:error] [pid 765155:tid 765337] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/deepseek_d.php"] [unique_id "amuLmuT5hFAbD-LhWHiKaQAAALk"]
[Thu Jul 30 12:36:27.121088 2026] [security2:error] [pid 765155:tid 765305] [client 172.237.109.114:28491] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "alseermarine.com"] [uri "/WEB_VMS/LEVEL15/"] [unique_id "amuLm-T5hFAbD-LhWHiKeAAAAJk"]
[Thu Jul 30 12:36:27.238940 2026] [security2:error] [pid 765155:tid 765288] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/function/function.php"] [unique_id "amuLm-T5hFAbD-LhWHiKewAAAIg"]
[Thu Jul 30 12:36:27.239083 2026] [security2:error] [pid 765155:tid 765288] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/function/function.php"] [unique_id "amuLm-T5hFAbD-LhWHiKewAAAIg"]
[Thu Jul 30 12:36:27.289361 2026] [core:notice] [pid 765155:tid 765360] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:27.290789 2026] [security2:error] [pid 765155:tid 765360] [client 68.221.69.72:14610] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "radiojelli.com"] [uri "/wp-content/uploads.html"] [unique_id "amuLm-T5hFAbD-LhWHiKfgAAANA"]
[Thu Jul 30 12:36:27.399528 2026] [core:notice] [pid 765155:tid 765254] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:27.426873 2026] [security2:error] [pid 765155:tid 765257] [remote 216.73.216.152:3161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuLm-T5hFAbD-LhWHiKhgAA4GU"]
[Thu Jul 30 12:36:27.754760 2026] [security2:error] [pid 765155:tid 765362] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/nw.php"] [unique_id "amuLm-T5hFAbD-LhWHiKjAAAANI"]
[Thu Jul 30 12:36:27.754873 2026] [security2:error] [pid 765155:tid 765362] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/nw.php"] [unique_id "amuLm-T5hFAbD-LhWHiKjAAAANI"]
[Thu Jul 30 12:36:27.967397 2026] [core:notice] [pid 765155:tid 765370] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:28.263255 2026] [security2:error] [pid 765155:tid 765312] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/xleet.php"] [unique_id "amuLnOT5hFAbD-LhWHiKngAAAKA"]
[Thu Jul 30 12:36:28.263381 2026] [security2:error] [pid 765155:tid 765312] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/xleet.php"] [unique_id "amuLnOT5hFAbD-LhWHiKngAAAKA"]
[Thu Jul 30 12:36:28.356097 2026] [security2:error] [pid 765155:tid 765370] [client 68.221.69.72:14614] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/money.html"] [unique_id "amuLm-T5hFAbD-LhWHiKkwAAANo"]
[Thu Jul 30 12:36:28.761331 2026] [security2:error] [pid 765155:tid 765397] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp.php"] [unique_id "amuLnOT5hFAbD-LhWHiKwgAAAPU"]
[Thu Jul 30 12:36:28.761526 2026] [security2:error] [pid 765155:tid 765397] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp.php"] [unique_id "amuLnOT5hFAbD-LhWHiKwgAAAPU"]
[Thu Jul 30 12:36:28.780762 2026] [core:notice] [pid 765155:tid 765369] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:28.785290 2026] [security2:error] [pid 765155:tid 765369] [client 68.221.69.72:14610] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "radiojelli.com"] [uri "/wp-includes/Text.html"] [unique_id "amuLnOT5hFAbD-LhWHiKxAAAANk"]
[Thu Jul 30 12:36:28.915501 2026] [core:notice] [pid 765155:tid 765353] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:28.919045 2026] [security2:error] [pid 765155:tid 765353] [client 68.221.69.72:14614] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/money.html"] [unique_id "amuLnOT5hFAbD-LhWHiKyAAAAMk"]
[Thu Jul 30 12:36:28.926517 2026] [security2:error] [pid 765155:tid 765345] [client 57.141.0.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKoAAAAME"]
[Thu Jul 30 12:36:29.271448 2026] [security2:error] [pid 765155:tid 765396] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/155.php"] [unique_id "amuLneT5hFAbD-LhWHiKzgAAAPQ"]
[Thu Jul 30 12:36:29.271640 2026] [security2:error] [pid 765155:tid 765396] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/155.php"] [unique_id "amuLneT5hFAbD-LhWHiKzgAAAPQ"]
[Thu Jul 30 12:36:29.283169 2026] [security2:error] [pid 765155:tid 765315] [client 20.63.98.115:49761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/.well-known/file.php"] [unique_id "amuLneT5hFAbD-LhWHiKzwAAAKM"]
[Thu Jul 30 12:36:29.314941 2026] [security2:error] [pid 765155:tid 765314] [client 68.221.69.72:14610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/ops.php"] [unique_id "amuLneT5hFAbD-LhWHiK0AAAAKI"]
[Thu Jul 30 12:36:29.315137 2026] [security2:error] [pid 765155:tid 765314] [client 68.221.69.72:14610] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/ops.php"] [unique_id "amuLneT5hFAbD-LhWHiK0AAAAKI"]
[Thu Jul 30 12:36:29.331515 2026] [security2:error] [pid 765155:tid 765382] [client 37.236.210.189:41543] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKyQAAAOY"], referer: http://pkf.jo
[Thu Jul 30 12:36:29.601812 2026] [security2:error] [pid 765155:tid 765316] [client 172.236.9.101:21885] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKpwAAAKQ"]
[Thu Jul 30 12:36:29.679788 2026] [security2:error] [pid 765155:tid 765385] [client 57.141.0.43:36538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuLneT5hFAbD-LhWHiKygAA6Ws"], referer: https://igetvape-australia.com/product-category/iget-moon/?add-to-cart=177
[Thu Jul 30 12:36:29.893661 2026] [security2:error] [pid 765155:tid 765397] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/96i.php"] [unique_id "amuLneT5hFAbD-LhWHiK7gAAAPU"]
[Thu Jul 30 12:36:29.893744 2026] [security2:error] [pid 765155:tid 765397] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/96i.php"] [unique_id "amuLneT5hFAbD-LhWHiK7gAAAPU"]
[Thu Jul 30 12:36:30.351942 2026] [security2:error] [pid 765155:tid 765355] [client 172.236.9.101:15694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKqgAAAMs"]
[Thu Jul 30 12:36:30.359325 2026] [security2:error] [pid 765155:tid 765329] [client 172.236.9.101:24102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKpQAAALE"]
[Thu Jul 30 12:36:30.362760 2026] [security2:error] [pid 765155:tid 765340] [client 172.236.9.101:1617] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKpAAAALw"]
[Thu Jul 30 12:36:30.396251 2026] [security2:error] [pid 765155:tid 765391] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/as.php"] [unique_id "amuLnuT5hFAbD-LhWHiLAwAAAO8"]
[Thu Jul 30 12:36:30.396438 2026] [security2:error] [pid 765155:tid 765391] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/as.php"] [unique_id "amuLnuT5hFAbD-LhWHiLAwAAAO8"]
[Thu Jul 30 12:36:30.478654 2026] [security2:error] [pid 765155:tid 765304] [client 172.236.9.101:14176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKswAAAJg"]
[Thu Jul 30 12:36:30.524273 2026] [security2:error] [pid 765155:tid 765321] [client 68.221.69.72:38350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/8.php"] [unique_id "amuLnuT5hFAbD-LhWHiLBwAAAKk"]
[Thu Jul 30 12:36:30.524450 2026] [security2:error] [pid 765155:tid 765321] [client 68.221.69.72:38350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/8.php"] [unique_id "amuLnuT5hFAbD-LhWHiLBwAAAKk"]
[Thu Jul 30 12:36:30.531490 2026] [security2:error] [pid 765155:tid 765399] [client 172.236.9.101:27793] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKrAAAAPc"]
[Thu Jul 30 12:36:30.532347 2026] [security2:error] [pid 765155:tid 765388] [client 172.236.9.101:22274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKpgAAAOw"]
[Thu Jul 30 12:36:30.536591 2026] [security2:error] [pid 765155:tid 765404] [client 172.236.9.101:2729] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKsQAAAPw"]
[Thu Jul 30 12:36:30.538337 2026] [security2:error] [pid 765155:tid 765386] [client 172.236.9.101:33007] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKrQAAAOo"]
[Thu Jul 30 12:36:30.540876 2026] [security2:error] [pid 765155:tid 765334] [client 172.236.9.101:11947] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKsAAAALY"]
[Thu Jul 30 12:36:30.663056 2026] [core:notice] [pid 765155:tid 765371] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:30.667922 2026] [security2:error] [pid 765155:tid 765371] [client 103.215.74.26:8852] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLnuT5hFAbD-LhWHiLCgAAANs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:30.835365 2026] [security2:error] [pid 765155:tid 765305] [client 145.239.10.137:57698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/le.php"] [unique_id "amuLnuT5hFAbD-LhWHiLEgAAAJk"], referer: http://deltaedu.net/le.php
[Thu Jul 30 12:36:30.867536 2026] [security2:error] [pid 765155:tid 765382] [client 150.107.232.194:27283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuLnuT5hFAbD-LhWHiLCQAAAOY"]
[Thu Jul 30 12:36:30.867697 2026] [security2:error] [pid 765155:tid 765382] [client 150.107.232.194:27283] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuLnuT5hFAbD-LhWHiLCQAAAOY"]
[Thu Jul 30 12:36:30.885094 2026] [security2:error] [pid 765155:tid 765293] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/min.php"] [unique_id "amuLnuT5hFAbD-LhWHiLEwAAAI0"]
[Thu Jul 30 12:36:30.885178 2026] [security2:error] [pid 765155:tid 765293] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/min.php"] [unique_id "amuLnuT5hFAbD-LhWHiLEwAAAI0"]
[Thu Jul 30 12:36:31.145064 2026] [security2:error] [pid 765155:tid 765369] [client 204.8.98.25:35104] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuLn-T5hFAbD-LhWHiLGAAAANk"]
[Thu Jul 30 12:36:31.145173 2026] [security2:error] [pid 765155:tid 765369] [client 204.8.98.25:35104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuLn-T5hFAbD-LhWHiLGAAAANk"]
[Thu Jul 30 12:36:31.218673 2026] [security2:error] [pid 765155:tid 765377] [client 172.236.9.101:31090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKtwAAAOE"]
[Thu Jul 30 12:36:31.231638 2026] [security2:error] [pid 765155:tid 765379] [client 20.63.98.115:58070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "amuLn-T5hFAbD-LhWHiLGwAAAOM"]
[Thu Jul 30 12:36:31.233823 2026] [security2:error] [pid 765155:tid 765300] [client 172.236.9.101:16317] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKrgAAAJQ"]
[Thu Jul 30 12:36:31.236224 2026] [security2:error] [pid 765155:tid 765412] [client 172.236.9.101:17389] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKtAAAAQQ"]
[Thu Jul 30 12:36:31.237927 2026] [security2:error] [pid 765155:tid 765335] [client 172.236.9.101:2492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKrwAAALc"]
[Thu Jul 30 12:36:31.269174 2026] [security2:error] [pid 765155:tid 765339] [client 172.236.9.101:10264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKqAAAALs"]
[Thu Jul 30 12:36:31.287693 2026] [security2:error] [pid 765155:tid 765406] [client 172.236.9.101:45015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKqwAAAP4"]
[Thu Jul 30 12:36:31.370745 2026] [security2:error] [pid 765155:tid 765387] [client 172.236.9.101:64637] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKtgAAAOs"]
[Thu Jul 30 12:36:31.374921 2026] [security2:error] [pid 765155:tid 765380] [client 172.236.9.101:41551] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKsgAAAOQ"]
[Thu Jul 30 12:36:31.402360 2026] [security2:error] [pid 765155:tid 765285] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_webdisk/.well-known/"] [unique_id "amuLn-T5hFAbD-LhWHiLIgAAAIU"]
[Thu Jul 30 12:36:31.421454 2026] [core:notice] [pid 765155:tid 765327] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:31.430778 2026] [security2:error] [pid 765155:tid 765327] [client 103.215.74.26:8876] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLn-T5hFAbD-LhWHiLJAAAAK8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:31.514106 2026] [security2:error] [pid 765155:tid 765378] [client 172.236.9.101:33638] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKtQAAAOI"]
[Thu Jul 30 12:36:31.624489 2026] [security2:error] [pid 765155:tid 765367] [client 172.236.9.101:35531] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLneT5hFAbD-LhWHiK1gAAANc"]
[Thu Jul 30 12:36:31.649019 2026] [security2:error] [pid 765155:tid 765399] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/php8.php"] [unique_id "amuLn-T5hFAbD-LhWHiLKQAAAPc"]
[Thu Jul 30 12:36:31.649191 2026] [security2:error] [pid 765155:tid 765399] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/php8.php"] [unique_id "amuLn-T5hFAbD-LhWHiLKQAAAPc"]
[Thu Jul 30 12:36:31.920232 2026] [security2:error] [pid 765155:tid 765408] [client 50.6.43.217:18876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuLn-T5hFAbD-LhWHiLFwAAAQA"]
[Thu Jul 30 12:36:31.982124 2026] [security2:error] [pid 765155:tid 765342] [client 51.68.111.208:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "totalwebsite.biz"] [uri "/robots.txt"] [unique_id "amuLn-T5hFAbD-LhWHiLNQAAAL4"]
[Thu Jul 30 12:36:31.982237 2026] [security2:error] [pid 765155:tid 765342] [client 51.68.111.208:0] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "totalwebsite.biz"] [uri "/robots.txt"] [unique_id "amuLn-T5hFAbD-LhWHiLNQAAAL4"]
[Thu Jul 30 12:36:32.128973 2026] [security2:error] [pid 765155:tid 765352] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-content/admin.php"] [unique_id "amuLoOT5hFAbD-LhWHiLNgAAAMg"]
[Thu Jul 30 12:36:32.129076 2026] [security2:error] [pid 765155:tid 765352] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-content/admin.php"] [unique_id "amuLoOT5hFAbD-LhWHiLNgAAAMg"]
[Thu Jul 30 12:36:32.166053 2026] [core:notice] [pid 765155:tid 765312] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:32.170695 2026] [security2:error] [pid 765155:tid 765312] [client 103.215.74.26:8886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLoOT5hFAbD-LhWHiLNwAAAKA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:32.170858 2026] [security2:error] [pid 765155:tid 765297] [client 216.73.216.104:25913] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuLn-T5hFAbD-LhWHiLMAAAkQQ"]
[Thu Jul 30 12:36:32.270144 2026] [security2:error] [pid 765155:tid 765351] [client 172.236.9.101:4522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLneT5hFAbD-LhWHiK0wAAAMc"]
[Thu Jul 30 12:36:32.270845 2026] [security2:error] [pid 765155:tid 765313] [client 172.236.9.101:26648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLneT5hFAbD-LhWHiK0gAAAKE"]
[Thu Jul 30 12:36:32.296252 2026] [security2:error] [pid 765155:tid 765337] [client 20.63.98.115:47310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "amuLoOT5hFAbD-LhWHiLOAAAALk"]
[Thu Jul 30 12:36:32.316482 2026] [security2:error] [pid 765155:tid 765363] [client 172.236.9.101:15532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLneT5hFAbD-LhWHiK1AAAANM"]
[Thu Jul 30 12:36:32.365278 2026] [security2:error] [pid 765155:tid 765402] [client 172.236.9.101:59825] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKqQAAAPo"]
[Thu Jul 30 12:36:32.371777 2026] [security2:error] [pid 765155:tid 765362] [client 172.236.9.101:62946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLneT5hFAbD-LhWHiK2AAAANI"]
[Thu Jul 30 12:36:32.397069 2026] [security2:error] [pid 765155:tid 765309] [client 172.236.9.101:3307] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLneT5hFAbD-LhWHiK2QAAAJ0"]
[Thu Jul 30 12:36:32.440885 2026] [security2:error] [pid 765155:tid 765300] [client 68.221.69.72:64780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/FWAZ.php"] [unique_id "amuLoOT5hFAbD-LhWHiLPwAAAJQ"]
[Thu Jul 30 12:36:32.441287 2026] [security2:error] [pid 765155:tid 765300] [client 68.221.69.72:64780] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/FWAZ.php"] [unique_id "amuLoOT5hFAbD-LhWHiLPwAAAJQ"]
[Thu Jul 30 12:36:32.480962 2026] [security2:error] [pid 765155:tid 765400] [client 172.236.9.101:29640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLneT5hFAbD-LhWHiK3QAAAPg"]
[Thu Jul 30 12:36:32.488240 2026] [security2:error] [pid 765155:tid 765409] [client 172.236.9.101:19914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLneT5hFAbD-LhWHiK2wAAAQE"]
[Thu Jul 30 12:36:32.514742 2026] [security2:error] [pid 765155:tid 765393] [client 172.236.9.101:57044] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLneT5hFAbD-LhWHiK4gAAAPE"]
[Thu Jul 30 12:36:32.529817 2026] [security2:error] [pid 765155:tid 765288] [client 2a03:2880:f800:36:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuLn-T5hFAbD-LhWHiLGgAAiHs"]
[Thu Jul 30 12:36:32.534460 2026] [security2:error] [pid 765155:tid 765311] [client 172.236.9.101:32077] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLneT5hFAbD-LhWHiK1wAAAJ8"]
[Thu Jul 30 12:36:32.650219 2026] [security2:error] [pid 765155:tid 765301] [client 172.236.9.101:30706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLneT5hFAbD-LhWHiK3gAAAJU"]
[Thu Jul 30 12:36:32.657547 2026] [security2:error] [pid 765155:tid 765341] [client 172.236.9.101:43526] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLneT5hFAbD-LhWHiK4QAAAL0"]
[Thu Jul 30 12:36:32.661113 2026] [security2:error] [pid 765155:tid 765407] [client 172.236.9.101:61983] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLneT5hFAbD-LhWHiK4wAAAP8"]
[Thu Jul 30 12:36:32.668052 2026] [security2:error] [pid 765155:tid 765345] [client 172.236.9.101:52209] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnuT5hFAbD-LhWHiLBAAAAME"]
[Thu Jul 30 12:36:32.694854 2026] [security2:error] [pid 765155:tid 765306] [client 172.236.9.101:25400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLneT5hFAbD-LhWHiK4AAAAJo"]
[Thu Jul 30 12:36:32.705966 2026] [security2:error] [pid 765155:tid 765401] [client 172.236.9.101:27123] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLneT5hFAbD-LhWHiK3wAAAPk"]
[Thu Jul 30 12:36:32.714861 2026] [security2:error] [pid 765155:tid 765353] [client 172.236.9.101:19971] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnuT5hFAbD-LhWHiLBQAAAMk"]
[Thu Jul 30 12:36:32.723106 2026] [security2:error] [pid 765155:tid 765336] [client 172.236.9.101:24981] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLneT5hFAbD-LhWHiK5AAAALg"]
[Thu Jul 30 12:36:32.736836 2026] [security2:error] [pid 765155:tid 765394] [client 172.236.9.101:41073] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLneT5hFAbD-LhWHiK3AAAAPI"]
[Thu Jul 30 12:36:32.751038 2026] [security2:error] [pid 765155:tid 765381] [client 172.236.9.101:22512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnuT5hFAbD-LhWHiLAgAAAOU"]
[Thu Jul 30 12:36:32.817039 2026] [security2:error] [pid 765155:tid 765405] [client 174.138.89.209:60442] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.58"] [uri "/"] [unique_id "amuLoOT5hFAbD-LhWHiLSwAAAP0"]
[Thu Jul 30 12:36:32.872373 2026] [security2:error] [pid 765155:tid 765395] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/222.php"] [unique_id "amuLoOT5hFAbD-LhWHiLTgAAAPM"]
[Thu Jul 30 12:36:32.872520 2026] [security2:error] [pid 765155:tid 765395] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/222.php"] [unique_id "amuLoOT5hFAbD-LhWHiLTgAAAPM"]
[Thu Jul 30 12:36:32.891700 2026] [security2:error] [pid 765155:tid 765290] [client 50.6.43.217:18882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuLn-T5hFAbD-LhWHiLMQAAAIo"]
[Thu Jul 30 12:36:32.895904 2026] [core:notice] [pid 765155:tid 765396] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:32.899971 2026] [security2:error] [pid 765155:tid 765396] [client 103.215.74.26:8898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLoOT5hFAbD-LhWHiLUAAAAPQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:33.064434 2026] [security2:error] [pid 765155:tid 765398] [client 174.138.89.209:45516] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.58"] [uri "/"] [unique_id "amuLoeT5hFAbD-LhWHiLVwAAAPY"]
[Thu Jul 30 12:36:33.290602 2026] [security2:error] [pid 765155:tid 765367] [client 38.190.144.4:11339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLoeT5hFAbD-LhWHiLXAAAANc"]
[Thu Jul 30 12:36:33.290723 2026] [security2:error] [pid 765155:tid 765367] [client 38.190.144.4:11339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLoeT5hFAbD-LhWHiLXAAAANc"]
[Thu Jul 30 12:36:33.366594 2026] [security2:error] [pid 765155:tid 765311] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "amuLoeT5hFAbD-LhWHiLXQAAAJ8"]
[Thu Jul 30 12:36:33.366706 2026] [security2:error] [pid 765155:tid 765311] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "amuLoeT5hFAbD-LhWHiLXQAAAJ8"]
[Thu Jul 30 12:36:33.547256 2026] [security2:error] [pid 765155:tid 765391] [client 68.221.69.72:14638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/biufile.php"] [unique_id "amuLoeT5hFAbD-LhWHiLZwAAAO8"]
[Thu Jul 30 12:36:33.547354 2026] [security2:error] [pid 765155:tid 765391] [client 68.221.69.72:14638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/biufile.php"] [unique_id "amuLoeT5hFAbD-LhWHiLZwAAAO8"]
[Thu Jul 30 12:36:33.553352 2026] [core:notice] [pid 765155:tid 765175] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:33.631491 2026] [core:notice] [pid 765155:tid 765376] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:33.635409 2026] [security2:error] [pid 765155:tid 765376] [client 103.215.74.26:1450] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLoeT5hFAbD-LhWHiLaQAAAOA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:33.906713 2026] [security2:error] [pid 765155:tid 765314] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/info.php"] [unique_id "amuLoeT5hFAbD-LhWHiLbQAAAKI"]
[Thu Jul 30 12:36:33.906820 2026] [security2:error] [pid 765155:tid 765314] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/info.php"] [unique_id "amuLoeT5hFAbD-LhWHiLbQAAAKI"]
[Thu Jul 30 12:36:34.364065 2026] [core:notice] [pid 765155:tid 765338] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:34.368402 2026] [security2:error] [pid 765155:tid 765338] [client 103.215.74.26:1460] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLouT5hFAbD-LhWHiLeAAAALo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:34.446866 2026] [security2:error] [pid 765155:tid 765342] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/a.php"] [unique_id "amuLouT5hFAbD-LhWHiLfAAAAL4"]
[Thu Jul 30 12:36:34.446958 2026] [security2:error] [pid 765155:tid 765342] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/a.php"] [unique_id "amuLouT5hFAbD-LhWHiLfAAAAL4"]
[Thu Jul 30 12:36:34.469903 2026] [security2:error] [pid 765155:tid 765357] [client 68.221.69.72:38339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/coffexium.php"] [unique_id "amuLouT5hFAbD-LhWHiLfwAAAM0"]
[Thu Jul 30 12:36:34.470019 2026] [security2:error] [pid 765155:tid 765357] [client 68.221.69.72:38339] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/coffexium.php"] [unique_id "amuLouT5hFAbD-LhWHiLfwAAAM0"]
[Thu Jul 30 12:36:34.657074 2026] [security2:error] [pid 765155:tid 765316] [client 20.63.98.115:47322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/file.php"] [unique_id "amuLouT5hFAbD-LhWHiLhAAAAKQ"]
[Thu Jul 30 12:36:34.989692 2026] [security2:error] [pid 765155:tid 765363] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/chosen.php"] [unique_id "amuLouT5hFAbD-LhWHiLjAAAANM"]
[Thu Jul 30 12:36:34.989788 2026] [security2:error] [pid 765155:tid 765363] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/chosen.php"] [unique_id "amuLouT5hFAbD-LhWHiLjAAAANM"]
[Thu Jul 30 12:36:35.212964 2026] [security2:error] [pid 765155:tid 765335] [client 68.221.69.72:38371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/simple.php"] [unique_id "amuLo-T5hFAbD-LhWHiLkgAAALc"]
[Thu Jul 30 12:36:35.213112 2026] [security2:error] [pid 765155:tid 765335] [client 68.221.69.72:38371] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/simple.php"] [unique_id "amuLo-T5hFAbD-LhWHiLkgAAALc"]
[Thu Jul 30 12:36:35.756796 2026] [security2:error] [pid 765155:tid 765387] [client 20.63.98.115:47318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-signup.php"] [unique_id "amuLo-T5hFAbD-LhWHiLnwAAAOs"]
[Thu Jul 30 12:36:36.306879 2026] [security2:error] [pid 765155:tid 765290] [client 68.221.69.72:14593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/fpwch.php"] [unique_id "amuLpOT5hFAbD-LhWHiLrAAAAIo"]
[Thu Jul 30 12:36:36.307085 2026] [security2:error] [pid 765155:tid 765290] [client 68.221.69.72:14593] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/fpwch.php"] [unique_id "amuLpOT5hFAbD-LhWHiLrAAAAIo"]
[Thu Jul 30 12:36:36.589346 2026] [security2:error] [pid 765155:tid 765389] [client 204.8.98.25:35114] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuLpOT5hFAbD-LhWHiLtwAAAO0"]
[Thu Jul 30 12:36:36.589445 2026] [security2:error] [pid 765155:tid 765389] [client 204.8.98.25:35114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuLpOT5hFAbD-LhWHiLtwAAAO0"]
[Thu Jul 30 12:36:37.209706 2026] [security2:error] [pid 765155:tid 765403] [client 172.213.232.128:62106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/011i.php"] [unique_id "amuLpeT5hFAbD-LhWHiLxwAAAPs"]
[Thu Jul 30 12:36:37.263921 2026] [security2:error] [pid 765155:tid 765298] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-content/index.php"] [unique_id "amuLpeT5hFAbD-LhWHiLyAAAAJI"]
[Thu Jul 30 12:36:37.264032 2026] [security2:error] [pid 765155:tid 765298] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-content/index.php"] [unique_id "amuLpeT5hFAbD-LhWHiLyAAAAJI"]
[Thu Jul 30 12:36:37.321970 2026] [security2:error] [pid 765155:tid 765288] [client 68.221.69.72:64815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/dex.php"] [unique_id "amuLpeT5hFAbD-LhWHiLyQAAAIg"]
[Thu Jul 30 12:36:37.322100 2026] [security2:error] [pid 765155:tid 765288] [client 68.221.69.72:64815] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/dex.php"] [unique_id "amuLpeT5hFAbD-LhWHiLyQAAAIg"]
[Thu Jul 30 12:36:37.795169 2026] [security2:error] [pid 765155:tid 765407] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/vx.php"] [unique_id "amuLpeT5hFAbD-LhWHiL1wAAAP8"]
[Thu Jul 30 12:36:37.795267 2026] [security2:error] [pid 765155:tid 765407] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/vx.php"] [unique_id "amuLpeT5hFAbD-LhWHiL1wAAAP8"]
[Thu Jul 30 12:36:37.932289 2026] [security2:error] [pid 765155:tid 765304] [client 68.221.69.72:38373] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "radiojelli.com"] [uri "/1.php"] [unique_id "amuLpeT5hFAbD-LhWHiL2wAAAJg"]
[Thu Jul 30 12:36:37.932460 2026] [security2:error] [pid 765155:tid 765304] [client 68.221.69.72:38373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/1.php"] [unique_id "amuLpeT5hFAbD-LhWHiL2wAAAJg"]
[Thu Jul 30 12:36:37.932594 2026] [security2:error] [pid 765155:tid 765304] [client 68.221.69.72:38373] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/1.php"] [unique_id "amuLpeT5hFAbD-LhWHiL2wAAAJg"]
[Thu Jul 30 12:36:38.087343 2026] [security2:error] [pid 765155:tid 765386] [client 150.107.232.194:27290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuLpuT5hFAbD-LhWHiL5AAAAOo"]
[Thu Jul 30 12:36:38.087485 2026] [security2:error] [pid 765155:tid 765386] [client 150.107.232.194:27290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuLpuT5hFAbD-LhWHiL5AAAAOo"]
[Thu Jul 30 12:36:38.140641 2026] [core:notice] [pid 765155:tid 765378] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:38.349905 2026] [security2:error] [pid 765155:tid 765290] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_webdisk/admin/controller/extension/"] [unique_id "amuLpuT5hFAbD-LhWHiL6QAAAIo"]
[Thu Jul 30 12:36:38.647074 2026] [security2:error] [pid 765155:tid 765297] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wap.php"] [unique_id "amuLpuT5hFAbD-LhWHiL8AAAAJE"]
[Thu Jul 30 12:36:38.647209 2026] [security2:error] [pid 765155:tid 765297] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wap.php"] [unique_id "amuLpuT5hFAbD-LhWHiL8AAAAJE"]
[Thu Jul 30 12:36:38.772646 2026] [security2:error] [pid 765155:tid 765348] [client 172.213.232.128:53651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/03a005685d.php"] [unique_id "amuLpuT5hFAbD-LhWHiL8QAAAMQ"]
[Thu Jul 30 12:36:39.197445 2026] [security2:error] [pid 765155:tid 765398] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-admin/wp.php"] [unique_id "amuLp-T5hFAbD-LhWHiL_AAAAPY"]
[Thu Jul 30 12:36:39.197551 2026] [security2:error] [pid 765155:tid 765398] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-admin/wp.php"] [unique_id "amuLp-T5hFAbD-LhWHiL_AAAAPY"]
[Thu Jul 30 12:36:39.439925 2026] [security2:error] [pid 765155:tid 765377] [client 172.213.232.128:60019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/403.php"] [unique_id "amuLp-T5hFAbD-LhWHiMBgAAAOE"]
[Thu Jul 30 12:36:39.506520 2026] [security2:error] [pid 765155:tid 765319] [client 20.63.98.115:58056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/css/index.php"] [unique_id "amuLp-T5hFAbD-LhWHiMCAAAAKc"]
[Thu Jul 30 12:36:39.703304 2026] [security2:error] [pid 765155:tid 765406] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/bgymj.php"] [unique_id "amuLp-T5hFAbD-LhWHiMDAAAAP4"]
[Thu Jul 30 12:36:39.703428 2026] [security2:error] [pid 765155:tid 765406] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/bgymj.php"] [unique_id "amuLp-T5hFAbD-LhWHiMDAAAAP4"]
[Thu Jul 30 12:36:40.130918 2026] [core:notice] [pid 765155:tid 765340] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:40.135285 2026] [security2:error] [pid 765155:tid 765340] [client 103.215.74.26:1470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLqOT5hFAbD-LhWHiMFgAAALw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:40.199207 2026] [security2:error] [pid 765155:tid 765334] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/aa.php"] [unique_id "amuLqOT5hFAbD-LhWHiMFwAAALY"]
[Thu Jul 30 12:36:40.199326 2026] [security2:error] [pid 765155:tid 765334] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/aa.php"] [unique_id "amuLqOT5hFAbD-LhWHiMFwAAALY"]
[Thu Jul 30 12:36:40.296202 2026] [core:notice] [pid 765155:tid 765338] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:40.300364 2026] [security2:error] [pid 765155:tid 765338] [client 68.221.69.72:14605] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "radiojelli.com"] [uri "/wp-admin/css/colors/modern.html"] [unique_id "amuLqOT5hFAbD-LhWHiMGAAAALo"]
[Thu Jul 30 12:36:40.680050 2026] [security2:error] [pid 765155:tid 765312] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-mail.php"] [unique_id "amuLqOT5hFAbD-LhWHiMNAAAAKA"]
[Thu Jul 30 12:36:40.680198 2026] [security2:error] [pid 765155:tid 765312] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-mail.php"] [unique_id "amuLqOT5hFAbD-LhWHiMNAAAAKA"]
[Thu Jul 30 12:36:40.844078 2026] [core:notice] [pid 765155:tid 765297] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:40.848451 2026] [security2:error] [pid 765155:tid 765297] [client 103.215.74.26:1484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLqOT5hFAbD-LhWHiMNQAAAJE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:41.182361 2026] [security2:error] [pid 765155:tid 765397] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/bolt.php"] [unique_id "amuLqeT5hFAbD-LhWHiMPAAAAPU"]
[Thu Jul 30 12:36:41.182474 2026] [security2:error] [pid 765155:tid 765397] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/bolt.php"] [unique_id "amuLqeT5hFAbD-LhWHiMPAAAAPU"]
[Thu Jul 30 12:36:41.403656 2026] [security2:error] [pid 765155:tid 765360] [client 172.213.232.128:59984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/404.php"] [unique_id "amuLqeT5hFAbD-LhWHiMRAAAANA"]
[Thu Jul 30 12:36:41.571018 2026] [security2:error] [pid 765155:tid 765303] [client 172.236.9.101:65368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqOT5hFAbD-LhWHiMGgAAAJc"]
[Thu Jul 30 12:36:41.585650 2026] [core:notice] [pid 765155:tid 765339] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:41.586533 2026] [security2:error] [pid 765155:tid 765330] [client 172.236.9.101:45252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqOT5hFAbD-LhWHiMGQAAALI"]
[Thu Jul 30 12:36:41.598223 2026] [security2:error] [pid 765155:tid 765339] [client 103.215.74.26:1488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLqeT5hFAbD-LhWHiMTgAAALs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:41.608487 2026] [security2:error] [pid 765155:tid 765394] [client 172.236.9.101:7636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqOT5hFAbD-LhWHiMHgAAAPI"]
[Thu Jul 30 12:36:41.614467 2026] [security2:error] [pid 765155:tid 765404] [client 172.236.9.101:35653] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqOT5hFAbD-LhWHiMHAAAAPw"]
[Thu Jul 30 12:36:41.697260 2026] [security2:error] [pid 765155:tid 765331] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/bthil.php"] [unique_id "amuLqeT5hFAbD-LhWHiMTwAAALM"]
[Thu Jul 30 12:36:41.697374 2026] [security2:error] [pid 765155:tid 765331] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/bthil.php"] [unique_id "amuLqeT5hFAbD-LhWHiMTwAAALM"]
[Thu Jul 30 12:36:42.132504 2026] [security2:error] [pid 765155:tid 765243] [remote 57.141.0.40:37820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/post-sitemap.xml"] [unique_id "amuLquT5hFAbD-LhWHiMVwAA61c"]
[Thu Jul 30 12:36:42.150468 2026] [security2:error] [pid 765155:tid 765323] [client 20.63.98.115:60269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/ge.php"] [unique_id "amuLquT5hFAbD-LhWHiMWQAAAKs"]
[Thu Jul 30 12:36:42.193056 2026] [security2:error] [pid 765155:tid 765408] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_webdisk/cgi-bin/"] [unique_id "amuLquT5hFAbD-LhWHiMWgAAAQA"]
[Thu Jul 30 12:36:42.233264 2026] [security2:error] [pid 765155:tid 765347] [client 172.236.9.101:4374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqOT5hFAbD-LhWHiMIQAAAMM"]
[Thu Jul 30 12:36:42.234260 2026] [security2:error] [pid 765155:tid 765358] [client 172.236.9.101:47798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqOT5hFAbD-LhWHiMIwAAAM4"]
[Thu Jul 30 12:36:42.237693 2026] [security2:error] [pid 765155:tid 765405] [client 172.236.9.101:9703] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqOT5hFAbD-LhWHiMHwAAAP0"]
[Thu Jul 30 12:36:42.238105 2026] [security2:error] [pid 765155:tid 765289] [client 172.236.9.101:28171] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqOT5hFAbD-LhWHiMJgAAAIk"]
[Thu Jul 30 12:36:42.249571 2026] [security2:error] [pid 765155:tid 765378] [client 172.236.9.101:62838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqOT5hFAbD-LhWHiMJAAAAOI"]
[Thu Jul 30 12:36:42.252221 2026] [core:notice] [pid 765155:tid 765296] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:42.260756 2026] [security2:error] [pid 765155:tid 765344] [client 172.236.9.101:40521] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqOT5hFAbD-LhWHiMIgAAAMA"]
[Thu Jul 30 12:36:42.267819 2026] [security2:error] [pid 765155:tid 765354] [client 172.236.9.101:45709] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqOT5hFAbD-LhWHiMJwAAAMo"]
[Thu Jul 30 12:36:42.273091 2026] [security2:error] [pid 765155:tid 765384] [client 172.236.9.101:17196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqOT5hFAbD-LhWHiMKwAAAOg"]
[Thu Jul 30 12:36:42.273356 2026] [security2:error] [pid 765155:tid 765396] [client 172.236.9.101:5023] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqOT5hFAbD-LhWHiMKAAAAPQ"]
[Thu Jul 30 12:36:42.273447 2026] [security2:error] [pid 765155:tid 765306] [client 172.236.9.101:33544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqOT5hFAbD-LhWHiMKQAAAJo"]
[Thu Jul 30 12:36:42.286561 2026] [security2:error] [pid 765155:tid 765388] [client 172.236.9.101:48910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqOT5hFAbD-LhWHiMJQAAAOw"]
[Thu Jul 30 12:36:42.332824 2026] [core:notice] [pid 765155:tid 765304] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:42.337179 2026] [security2:error] [pid 765155:tid 765304] [client 103.215.74.26:1494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLquT5hFAbD-LhWHiMYwAAAJg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:42.366380 2026] [security2:error] [pid 765155:tid 765391] [client 172.236.9.101:8666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqOT5hFAbD-LhWHiMKgAAAO8"]
[Thu Jul 30 12:36:42.385881 2026] [security2:error] [pid 765155:tid 765395] [client 101.201.173.226:56454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "adviseassociates.com"] [uri "/index.php"] [unique_id "amuLquT5hFAbD-LhWHiMXQAAAPM"]
[Thu Jul 30 12:36:42.448906 2026] [security2:error] [pid 765155:tid 765390] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/x.php"] [unique_id "amuLquT5hFAbD-LhWHiMagAAAO4"]
[Thu Jul 30 12:36:42.449064 2026] [security2:error] [pid 765155:tid 765390] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/x.php"] [unique_id "amuLquT5hFAbD-LhWHiMagAAAO4"]
[Thu Jul 30 12:36:42.640617 2026] [security2:error] [pid 765155:tid 765296] [client 68.221.69.72:64800] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/money.html"] [unique_id "amuLquT5hFAbD-LhWHiMXwAAAJA"]
[Thu Jul 30 12:36:42.712232 2026] [security2:error] [pid 765155:tid 765412] [client 172.236.9.101:57945] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqeT5hFAbD-LhWHiMQgAAAQQ"]
[Thu Jul 30 12:36:42.743943 2026] [security2:error] [pid 765155:tid 765336] [client 172.236.9.101:34690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqeT5hFAbD-LhWHiMRQAAALg"]
[Thu Jul 30 12:36:42.745493 2026] [security2:error] [pid 765155:tid 765409] [client 172.236.9.101:30435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqeT5hFAbD-LhWHiMRgAAAQE"]
[Thu Jul 30 12:36:42.750277 2026] [security2:error] [pid 765155:tid 765300] [client 172.236.9.101:46902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqeT5hFAbD-LhWHiMQwAAAJQ"]
[Thu Jul 30 12:36:42.798048 2026] [security2:error] [pid 765155:tid 765328] [client 204.8.98.25:56092] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuLquT5hFAbD-LhWHiMbwAAALA"]
[Thu Jul 30 12:36:42.798146 2026] [security2:error] [pid 765155:tid 765328] [client 204.8.98.25:56092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuLquT5hFAbD-LhWHiMbwAAALA"]
[Thu Jul 30 12:36:42.952082 2026] [security2:error] [pid 765155:tid 765331] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/index/function.php"] [unique_id "amuLquT5hFAbD-LhWHiMdAAAALM"]
[Thu Jul 30 12:36:42.952196 2026] [security2:error] [pid 765155:tid 765331] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/index/function.php"] [unique_id "amuLquT5hFAbD-LhWHiMdAAAALM"]
[Thu Jul 30 12:36:43.059393 2026] [core:notice] [pid 765155:tid 765325] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:43.064886 2026] [security2:error] [pid 765155:tid 765325] [client 103.215.74.26:58206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLq-T5hFAbD-LhWHiMeAAAAK0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:43.128856 2026] [security2:error] [pid 765155:tid 765330] [client 118.194.233.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fnm.gzj.temporary.site"] [uri "/index.php"] [unique_id "amuLquT5hFAbD-LhWHiMcgAAALI"]
[Thu Jul 30 12:36:43.187910 2026] [security2:error] [pid 765155:tid 765340] [client 172.213.232.128:53793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/aa.php"] [unique_id "amuLq-T5hFAbD-LhWHiMfwAAALw"]
[Thu Jul 30 12:36:43.469684 2026] [security2:error] [pid 765155:tid 765289] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/aaa.php"] [unique_id "amuLq-T5hFAbD-LhWHiMhQAAAIk"]
[Thu Jul 30 12:36:43.469796 2026] [security2:error] [pid 765155:tid 765289] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/aaa.php"] [unique_id "amuLq-T5hFAbD-LhWHiMhQAAAIk"]
[Thu Jul 30 12:36:43.817630 2026] [core:notice] [pid 765155:tid 765306] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:43.822177 2026] [security2:error] [pid 765155:tid 765306] [client 103.215.74.26:58216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLq-T5hFAbD-LhWHiMjgAAAJo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:43.957800 2026] [security2:error] [pid 765155:tid 765312] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/abcd.php"] [unique_id "amuLq-T5hFAbD-LhWHiMkgAAAKA"]
[Thu Jul 30 12:36:43.957916 2026] [security2:error] [pid 765155:tid 765312] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/abcd.php"] [unique_id "amuLq-T5hFAbD-LhWHiMkgAAAKA"]
[Thu Jul 30 12:36:44.047901 2026] [security2:error] [pid 765155:tid 765395] [client 68.221.69.72:14605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/config.json.php"] [unique_id "amuLrOT5hFAbD-LhWHiMmAAAAPM"]
[Thu Jul 30 12:36:44.048010 2026] [security2:error] [pid 765155:tid 765395] [client 68.221.69.72:14605] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/config.json.php"] [unique_id "amuLrOT5hFAbD-LhWHiMmAAAAPM"]
[Thu Jul 30 12:36:44.298645 2026] [security2:error] [pid 765155:tid 765332] [client 38.190.144.4:50112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLrOT5hFAbD-LhWHiMmwAAALQ"]
[Thu Jul 30 12:36:44.298769 2026] [security2:error] [pid 765155:tid 765332] [client 38.190.144.4:50112] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLrOT5hFAbD-LhWHiMmwAAALQ"]
[Thu Jul 30 12:36:44.465831 2026] [security2:error] [pid 765155:tid 765301] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-good.php"] [unique_id "amuLrOT5hFAbD-LhWHiMnwAAAJU"]
[Thu Jul 30 12:36:44.465972 2026] [security2:error] [pid 765155:tid 765301] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-good.php"] [unique_id "amuLrOT5hFAbD-LhWHiMnwAAAJU"]
[Thu Jul 30 12:36:44.559339 2026] [core:notice] [pid 765155:tid 765308] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:44.560483 2026] [security2:error] [pid 765155:tid 765241] [remote 111.225.149.236:23446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "nfi.nyx.temporary.site"] [uri "/website_14d99ba9/wp-content/uploads/2025/08/fireworks23-1-1536x805.webp"] [unique_id "amuLrOT5hFAbD-LhWHiMpwABAVU"], referer: https://fireworkskenya.co.ke/
[Thu Jul 30 12:36:44.563985 2026] [security2:error] [pid 765155:tid 765308] [client 103.215.74.26:58228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLrOT5hFAbD-LhWHiMpgAAAJw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:44.682644 2026] [security2:error] [pid 765155:tid 765362] [client 172.213.232.128:60501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/aafewc0k.php"] [unique_id "amuLrOT5hFAbD-LhWHiMrQAAANI"]
[Thu Jul 30 12:36:44.924699 2026] [security2:error] [pid 765155:tid 765370] [client 2a03:2880:f800:8:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuLrOT5hFAbD-LhWHiMmgAA2mg"]
[Thu Jul 30 12:36:44.952956 2026] [security2:error] [pid 765155:tid 765363] [client 20.63.98.115:60276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/goods.php"] [unique_id "amuLrOT5hFAbD-LhWHiMtwAAANM"]
[Thu Jul 30 12:36:44.991454 2026] [security2:error] [pid 765155:tid 765314] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/simple.php"] [unique_id "amuLrOT5hFAbD-LhWHiMuAAAAKI"]
[Thu Jul 30 12:36:44.991551 2026] [security2:error] [pid 765155:tid 765314] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/simple.php"] [unique_id "amuLrOT5hFAbD-LhWHiMuAAAAKI"]
[Thu Jul 30 12:36:45.066386 2026] [security2:error] [pid 765155:tid 765287] [client 101.201.173.226:56454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adviseassociates.com"] [uri "/index.php"] [unique_id "amuLrOT5hFAbD-LhWHiMtgAAAIc"]
[Thu Jul 30 12:36:45.286044 2026] [core:notice] [pid 765155:tid 765330] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:45.290579 2026] [security2:error] [pid 765155:tid 765330] [client 103.215.74.26:58234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLreT5hFAbD-LhWHiMvwAAALI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:45.370099 2026] [core:error] [pid 765155:tid 765338] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:45.370122 2026] [core:error] [pid 765155:tid 765338] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:45.457908 2026] [security2:error] [pid 765155:tid 765341] [client 101.201.173.226:56454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adviseassociates.com"] [uri "/index.php"] [unique_id "amuLreT5hFAbD-LhWHiMwgAAAL0"]
[Thu Jul 30 12:36:45.532057 2026] [security2:error] [pid 765155:tid 765290] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/edit-tags.php"] [unique_id "amuLreT5hFAbD-LhWHiM2AAAAIo"]
[Thu Jul 30 12:36:45.532185 2026] [security2:error] [pid 765155:tid 765290] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/edit-tags.php"] [unique_id "amuLreT5hFAbD-LhWHiM2AAAAIo"]
[Thu Jul 30 12:36:45.589236 2026] [security2:error] [pid 765155:tid 765381] [client 101.201.173.226:56930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adviseassociates.com"] [uri "/index.php"] [unique_id "amuLreT5hFAbD-LhWHiMygAAAOU"]
[Thu Jul 30 12:36:45.598283 2026] [security2:error] [pid 765155:tid 765396] [client 101.201.173.226:56928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adviseassociates.com"] [uri "/index.php"] [unique_id "amuLreT5hFAbD-LhWHiMyQAAAPQ"]
[Thu Jul 30 12:36:45.606328 2026] [security2:error] [pid 765155:tid 765384] [client 101.201.173.226:56919] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adviseassociates.com"] [uri "/index.php"] [unique_id "amuLreT5hFAbD-LhWHiMxwAAAOg"]
[Thu Jul 30 12:36:45.606414 2026] [security2:error] [pid 765155:tid 765358] [client 101.201.173.226:56918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adviseassociates.com"] [uri "/index.php"] [unique_id "amuLreT5hFAbD-LhWHiMyAAAAM4"]
[Thu Jul 30 12:36:45.621333 2026] [security2:error] [pid 765155:tid 765315] [client 101.201.173.226:56926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adviseassociates.com"] [uri "/index.php"] [unique_id "amuLreT5hFAbD-LhWHiMywAAAKM"]
[Thu Jul 30 12:36:45.626737 2026] [security2:error] [pid 765155:tid 765359] [client 101.201.173.226:56924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adviseassociates.com"] [uri "/index.php"] [unique_id "amuLreT5hFAbD-LhWHiM1QAAAM8"]
[Thu Jul 30 12:36:45.645852 2026] [security2:error] [pid 765155:tid 765351] [client 101.201.173.226:56862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adviseassociates.com"] [uri "/index.php"] [unique_id "amuLreT5hFAbD-LhWHiMwQAAAMc"], referer: http://adviseassociates.com/statics/images/ext/dir.gif
[Thu Jul 30 12:36:45.766092 2026] [security2:error] [pid 765155:tid 765334] [client 172.213.232.128:60532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/abcd.php"] [unique_id "amuLreT5hFAbD-LhWHiM3AAAALY"]
[Thu Jul 30 12:36:46.034415 2026] [core:notice] [pid 765155:tid 765352] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:46.038268 2026] [security2:error] [pid 765155:tid 765352] [client 103.215.74.26:58246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLruT5hFAbD-LhWHiM5gAAAMg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:46.076014 2026] [security2:error] [pid 765155:tid 765377] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/u.php"] [unique_id "amuLruT5hFAbD-LhWHiM5wAAAOE"]
[Thu Jul 30 12:36:46.076103 2026] [security2:error] [pid 765155:tid 765377] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/u.php"] [unique_id "amuLruT5hFAbD-LhWHiM5wAAAOE"]
[Thu Jul 30 12:36:46.204180 2026] [security2:error] [pid 765155:tid 765344] [client 20.63.98.115:60242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/403.php"] [unique_id "amuLruT5hFAbD-LhWHiM6gAAAMA"]
[Thu Jul 30 12:36:46.288565 2026] [security2:error] [pid 765155:tid 765398] [client 101.201.173.226:56454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adviseassociates.com"] [uri "/index.php"] [unique_id "amuLruT5hFAbD-LhWHiM6QAAAPY"]
[Thu Jul 30 12:36:46.563686 2026] [security2:error] [pid 765155:tid 765406] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-content/themes/admin.php"] [unique_id "amuLruT5hFAbD-LhWHiM9AAAAP4"]
[Thu Jul 30 12:36:46.563827 2026] [security2:error] [pid 765155:tid 765406] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-content/themes/admin.php"] [unique_id "amuLruT5hFAbD-LhWHiM9AAAAP4"]
[Thu Jul 30 12:36:46.708135 2026] [security2:error] [pid 765155:tid 765322] [client 68.221.69.72:38370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/k2.php"] [unique_id "amuLruT5hFAbD-LhWHiNAgAAAKo"]
[Thu Jul 30 12:36:46.708298 2026] [security2:error] [pid 765155:tid 765322] [client 68.221.69.72:38370] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/k2.php"] [unique_id "amuLruT5hFAbD-LhWHiNAgAAAKo"]
[Thu Jul 30 12:36:46.786215 2026] [core:notice] [pid 765155:tid 765299] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:46.793034 2026] [security2:error] [pid 765155:tid 765299] [client 103.215.74.26:58262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "741"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLruT5hFAbD-LhWHiNAwAAAJM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:46.899961 2026] [security2:error] [pid 765155:tid 765285] [client 101.201.173.226:57052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adviseassociates.com"] [uri "/index.php"] [unique_id "amuLruT5hFAbD-LhWHiM-AAAAIU"], referer: http://adviseassociates.com/e/data/images/arrow.gif
[Thu Jul 30 12:36:46.917351 2026] [security2:error] [pid 765155:tid 765349] [client 101.201.173.226:57056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adviseassociates.com"] [uri "/index.php"] [unique_id "amuLruT5hFAbD-LhWHiM-gAAAMU"], referer: http://adviseassociates.com/plus/img/df_dedetitle.gif
[Thu Jul 30 12:36:46.922291 2026] [security2:error] [pid 765155:tid 765374] [client 101.201.173.226:57054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adviseassociates.com"] [uri "/index.php"] [unique_id "amuLruT5hFAbD-LhWHiM-wAAAN4"], referer: http://adviseassociates.com/public/plugins/ckeditor/images/spacer.gif
[Thu Jul 30 12:36:46.958880 2026] [security2:error] [pid 765155:tid 765399] [client 172.213.232.128:61230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/about.php"] [unique_id "amuLruT5hFAbD-LhWHiNCQAAAPc"]
[Thu Jul 30 12:36:47.080693 2026] [security2:error] [pid 765155:tid 765392] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/h.php"] [unique_id "amuLr-T5hFAbD-LhWHiNDgAAAPA"]
[Thu Jul 30 12:36:47.080798 2026] [security2:error] [pid 765155:tid 765392] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/h.php"] [unique_id "amuLr-T5hFAbD-LhWHiNDgAAAPA"]
[Thu Jul 30 12:36:47.219909 2026] [security2:error] [pid 765155:tid 765325] [client 101.201.173.226:57050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adviseassociates.com"] [uri "/index.php"] [unique_id "amuLruT5hFAbD-LhWHiM_QAAAK0"], referer: http://adviseassociates.com/public/plugins/Ueditor/dialogs/attachment/images/alignicon.gif
[Thu Jul 30 12:36:47.222250 2026] [security2:error] [pid 765155:tid 765373] [client 101.201.173.226:57048] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adviseassociates.com"] [uri "/index.php"] [unique_id "amuLruT5hFAbD-LhWHiM_wAAAN0"], referer: http://adviseassociates.com/include/ckeditor/plugins/smiley/images/angel_smile.gif
[Thu Jul 30 12:36:47.240896 2026] [security2:error] [pid 765155:tid 765287] [client 101.201.173.226:57060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adviseassociates.com"] [uri "/index.php"] [unique_id "amuLruT5hFAbD-LhWHiNAQAAAIc"], referer: http://adviseassociates.com/README.md
[Thu Jul 30 12:36:47.270555 2026] [security2:error] [pid 765155:tid 765314] [client 101.201.173.226:57058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adviseassociates.com"] [uri "/index.php"] [unique_id "amuLruT5hFAbD-LhWHiNAAAAAKI"], referer: http://adviseassociates.com/apps/admin/view/default/layui/images/face/11.gif
[Thu Jul 30 12:36:47.521400 2026] [core:notice] [pid 765155:tid 765388] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:47.527892 2026] [security2:error] [pid 765155:tid 765388] [client 103.215.74.26:58272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "738"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLr-T5hFAbD-LhWHiNIgAAAOw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:47.551840 2026] [security2:error] [pid 765155:tid 765334] [client 101.201.173.226:56454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adviseassociates.com"] [uri "/index.php"] [unique_id "amuLr-T5hFAbD-LhWHiNFgAAALY"]
[Thu Jul 30 12:36:47.600410 2026] [security2:error] [pid 765155:tid 765403] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/ms-edit.php"] [unique_id "amuLr-T5hFAbD-LhWHiNJgAAAPs"]
[Thu Jul 30 12:36:47.600554 2026] [security2:error] [pid 765155:tid 765403] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/ms-edit.php"] [unique_id "amuLr-T5hFAbD-LhWHiNJgAAAPs"]
[Thu Jul 30 12:36:47.687030 2026] [security2:error] [pid 765155:tid 765302] [client 20.63.98.115:21157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/public/makeasmtp.php"] [unique_id "amuLr-T5hFAbD-LhWHiNKQAAAJY"]
[Thu Jul 30 12:36:47.953343 2026] [security2:error] [pid 765155:tid 765396] [client 172.236.9.101:14440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLr-T5hFAbD-LhWHiNEgAAAPQ"]
[Thu Jul 30 12:36:47.971821 2026] [security2:error] [pid 765155:tid 765384] [client 172.236.9.101:57829] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLr-T5hFAbD-LhWHiNEwAAAOg"]
[Thu Jul 30 12:36:48.071090 2026] [security2:error] [pid 765155:tid 765348] [client 172.236.9.101:56301] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLr-T5hFAbD-LhWHiNFQAAAMQ"]
[Thu Jul 30 12:36:48.075112 2026] [security2:error] [pid 765155:tid 765295] [client 172.236.9.101:16816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLr-T5hFAbD-LhWHiNFwAAAI8"]
[Thu Jul 30 12:36:48.077156 2026] [security2:error] [pid 765155:tid 765315] [client 172.236.9.101:27378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLr-T5hFAbD-LhWHiNGQAAAKM"]
[Thu Jul 30 12:36:48.092074 2026] [security2:error] [pid 765155:tid 765358] [client 172.236.9.101:23386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLr-T5hFAbD-LhWHiNFAAAAM4"]
[Thu Jul 30 12:36:48.106433 2026] [security2:error] [pid 765155:tid 765389] [client 172.236.9.101:63622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLr-T5hFAbD-LhWHiNGAAAAO0"]
[Thu Jul 30 12:36:48.133096 2026] [security2:error] [pid 765155:tid 765361] [client 172.236.9.101:45073] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLr-T5hFAbD-LhWHiNGgAAANE"]
[Thu Jul 30 12:36:48.165029 2026] [security2:error] [pid 765155:tid 765394] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/a7.php"] [unique_id "amuLsOT5hFAbD-LhWHiNMQAAAPI"]
[Thu Jul 30 12:36:48.165137 2026] [security2:error] [pid 765155:tid 765394] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/a7.php"] [unique_id "amuLsOT5hFAbD-LhWHiNMQAAAPI"]
[Thu Jul 30 12:36:48.283462 2026] [core:notice] [pid 765155:tid 765412] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:48.287933 2026] [security2:error] [pid 765155:tid 765412] [client 103.215.74.26:58282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLsOT5hFAbD-LhWHiNNQAAAQQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:48.670638 2026] [security2:error] [pid 765155:tid 765304] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/manager.php"] [unique_id "amuLsOT5hFAbD-LhWHiNSwAAAJg"]
[Thu Jul 30 12:36:48.670824 2026] [security2:error] [pid 765155:tid 765304] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/manager.php"] [unique_id "amuLsOT5hFAbD-LhWHiNSwAAAJg"]
[Thu Jul 30 12:36:49.015260 2026] [core:notice] [pid 765155:tid 765314] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:49.022743 2026] [security2:error] [pid 765155:tid 765314] [client 103.215.74.26:58302] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLseT5hFAbD-LhWHiNUwAAAKI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:49.053865 2026] [security2:error] [pid 765155:tid 765402] [client 150.107.232.194:27304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuLseT5hFAbD-LhWHiNVAAAAPo"]
[Thu Jul 30 12:36:49.053967 2026] [security2:error] [pid 765155:tid 765402] [client 150.107.232.194:27304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuLseT5hFAbD-LhWHiNVAAAAPo"]
[Thu Jul 30 12:36:49.076043 2026] [security2:error] [pid 765155:tid 765330] [client 116.62.147.43:52568] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 43.147.62.116.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "themushroom.online"] [uri "/wp-comments-post.php"] [unique_id "amuLsOT5hFAbD-LhWHiNTwAAALI"]
[Thu Jul 30 12:36:49.076257 2026] [security2:error] [pid 765155:tid 765330] [client 116.62.147.43:52568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "themushroom.online"] [uri "/wp-comments-post.php"] [unique_id "amuLsOT5hFAbD-LhWHiNTwAAALI"]
[Thu Jul 30 12:36:49.142439 2026] [security2:error] [pid 765155:tid 765369] [client 20.63.98.115:49114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/mar.php"] [unique_id "amuLseT5hFAbD-LhWHiNVwAAANk"]
[Thu Jul 30 12:36:49.168681 2026] [security2:error] [pid 765155:tid 765297] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/w1.php"] [unique_id "amuLseT5hFAbD-LhWHiNWQAAAJE"]
[Thu Jul 30 12:36:49.168790 2026] [security2:error] [pid 765155:tid 765297] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/w1.php"] [unique_id "amuLseT5hFAbD-LhWHiNWQAAAJE"]
[Thu Jul 30 12:36:49.283917 2026] [security2:error] [pid 765155:tid 765298] [client 172.236.9.101:17408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLsOT5hFAbD-LhWHiNOgAAAJI"]
[Thu Jul 30 12:36:49.286015 2026] [security2:error] [pid 765155:tid 765327] [client 172.236.9.101:59676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLsOT5hFAbD-LhWHiNOwAAAK8"]
[Thu Jul 30 12:36:49.292355 2026] [security2:error] [pid 765155:tid 765336] [client 172.236.9.101:56383] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLsOT5hFAbD-LhWHiNPAAAALg"]
[Thu Jul 30 12:36:49.298557 2026] [security2:error] [pid 765155:tid 765329] [client 172.236.9.101:17398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLsOT5hFAbD-LhWHiNOQAAALE"]
[Thu Jul 30 12:36:49.307596 2026] [security2:error] [pid 765155:tid 765286] [client 172.236.9.101:64584] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLsOT5hFAbD-LhWHiNPgAAAIY"]
[Thu Jul 30 12:36:49.313027 2026] [security2:error] [pid 765155:tid 765411] [client 172.236.9.101:55669] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLsOT5hFAbD-LhWHiNPQAAAQM"]
[Thu Jul 30 12:36:49.313569 2026] [security2:error] [pid 765155:tid 765326] [client 172.236.9.101:58479] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLsOT5hFAbD-LhWHiNPwAAAK4"]
[Thu Jul 30 12:36:49.332675 2026] [security2:error] [pid 765155:tid 765317] [client 172.236.9.101:14204] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLsOT5hFAbD-LhWHiNQAAAAKU"]
[Thu Jul 30 12:36:49.346761 2026] [security2:error] [pid 765155:tid 765322] [client 172.236.9.101:19301] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLsOT5hFAbD-LhWHiNRgAAAKo"]
[Thu Jul 30 12:36:49.402088 2026] [security2:error] [pid 765155:tid 765363] [client 172.236.9.101:3490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLsOT5hFAbD-LhWHiNQQAAANM"]
[Thu Jul 30 12:36:49.415509 2026] [security2:error] [pid 765155:tid 765340] [client 172.236.9.101:54716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLsOT5hFAbD-LhWHiNQgAAALw"]
[Thu Jul 30 12:36:49.419888 2026] [core:notice] [pid 765155:tid 765367] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:49.494379 2026] [security2:error] [pid 765155:tid 765299] [client 172.236.9.101:12598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLsOT5hFAbD-LhWHiNRwAAAJM"]
[Thu Jul 30 12:36:49.667585 2026] [security2:error] [pid 765155:tid 765328] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_webdisk/wp-includes/fonts/"] [unique_id "amuLseT5hFAbD-LhWHiNdgAAALA"]
[Thu Jul 30 12:36:49.761674 2026] [core:notice] [pid 765155:tid 765360] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:49.768827 2026] [security2:error] [pid 765155:tid 765360] [client 103.215.74.26:58316] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLseT5hFAbD-LhWHiNgAAAANA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:50.056476 2026] [core:notice] [pid 765155:tid 765387] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:50.174553 2026] [security2:error] [pid 765155:tid 765294] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-login.php"] [unique_id "amuLseT5hFAbD-LhWHiNggAAAI4"]
[Thu Jul 30 12:36:50.174681 2026] [security2:error] [pid 765155:tid 765294] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-login.php"] [unique_id "amuLseT5hFAbD-LhWHiNggAAAI4"]
[Thu Jul 30 12:36:50.191762 2026] [security2:error] [pid 765155:tid 765366] [client 20.63.98.115:60249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/system.php"] [unique_id "amuLsuT5hFAbD-LhWHiNiQAAANY"]
[Thu Jul 30 12:36:50.545547 2026] [core:notice] [pid 765155:tid 765325] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:50.554528 2026] [security2:error] [pid 765155:tid 765325] [client 103.215.74.26:58330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLsuT5hFAbD-LhWHiNkAAAAK0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:50.665287 2026] [security2:error] [pid 765155:tid 765333] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/default.php"] [unique_id "amuLsuT5hFAbD-LhWHiNlAAAALU"]
[Thu Jul 30 12:36:50.665384 2026] [security2:error] [pid 765155:tid 765333] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/default.php"] [unique_id "amuLsuT5hFAbD-LhWHiNlAAAALU"]
[Thu Jul 30 12:36:50.768447 2026] [security2:error] [pid 765155:tid 765336] [client 68.221.69.72:64788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/raw.php"] [unique_id "amuLsuT5hFAbD-LhWHiNmAAAALg"]
[Thu Jul 30 12:36:50.768535 2026] [security2:error] [pid 765155:tid 765336] [client 68.221.69.72:64788] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/raw.php"] [unique_id "amuLsuT5hFAbD-LhWHiNmAAAALg"]
[Thu Jul 30 12:36:51.167097 2026] [security2:error] [pid 765155:tid 765342] [client 68.67.112.235:29072] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "kicksity.com"] [uri "/robots.txt"] [unique_id "amuLs-T5hFAbD-LhWHiNoAAAAL4"]
[Thu Jul 30 12:36:51.192860 2026] [security2:error] [pid 765155:tid 765362] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/i.php"] [unique_id "amuLs-T5hFAbD-LhWHiNogAAANI"]
[Thu Jul 30 12:36:51.192973 2026] [security2:error] [pid 765155:tid 765362] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/i.php"] [unique_id "amuLs-T5hFAbD-LhWHiNogAAANI"]
[Thu Jul 30 12:36:51.281631 2026] [core:notice] [pid 765155:tid 765299] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:51.291594 2026] [security2:error] [pid 765155:tid 765299] [client 103.215.74.26:58342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "757"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLs-T5hFAbD-LhWHiNpgAAAJM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:51.301120 2026] [security2:error] [pid 765155:tid 765302] [client 172.236.9.101:15271] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNZQAAAJY"]
[Thu Jul 30 12:36:51.318089 2026] [security2:error] [pid 765155:tid 765365] [client 172.236.9.101:19736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNXgAAANU"]
[Thu Jul 30 12:36:51.322811 2026] [security2:error] [pid 765155:tid 765397] [client 172.236.9.101:59795] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNYQAAAPU"]
[Thu Jul 30 12:36:51.339834 2026] [security2:error] [pid 765155:tid 765301] [client 172.236.9.101:45129] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNYAAAAJU"]
[Thu Jul 30 12:36:51.357671 2026] [security2:error] [pid 765155:tid 765337] [client 172.236.9.101:60874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNXwAAALk"]
[Thu Jul 30 12:36:51.360752 2026] [security2:error] [pid 765155:tid 765383] [client 172.236.9.101:43111] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNawAAAOc"]
[Thu Jul 30 12:36:51.387860 2026] [security2:error] [pid 765155:tid 765296] [client 172.236.9.101:58834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNYwAAAJA"]
[Thu Jul 30 12:36:51.390609 2026] [security2:error] [pid 765155:tid 765400] [client 172.236.9.101:53164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNZAAAAPg"]
[Thu Jul 30 12:36:51.399721 2026] [security2:error] [pid 765155:tid 765368] [client 172.236.9.101:56769] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNXQAAANg"]
[Thu Jul 30 12:36:51.409385 2026] [security2:error] [pid 765155:tid 765403] [client 172.236.9.101:48132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNYgAAAPs"]
[Thu Jul 30 12:36:51.429991 2026] [security2:error] [pid 765155:tid 765352] [client 172.236.9.101:63055] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNZgAAAMg"]
[Thu Jul 30 12:36:51.448848 2026] [security2:error] [pid 765155:tid 765364] [client 172.236.9.101:34400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNbQAAANQ"]
[Thu Jul 30 12:36:51.451427 2026] [security2:error] [pid 765155:tid 765332] [client 172.236.9.101:20466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNcQAAALQ"]
[Thu Jul 30 12:36:51.453580 2026] [security2:error] [pid 765155:tid 765396] [client 172.236.9.101:60668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNaQAAAPQ"]
[Thu Jul 30 12:36:51.465947 2026] [security2:error] [pid 765155:tid 765384] [client 172.236.9.101:25715] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNbAAAAOg"]
[Thu Jul 30 12:36:51.467938 2026] [security2:error] [pid 765155:tid 765305] [client 172.236.9.101:42027] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNaAAAAJk"]
[Thu Jul 30 12:36:51.484633 2026] [security2:error] [pid 765155:tid 765377] [client 172.236.9.101:63672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNagAAAOE"]
[Thu Jul 30 12:36:51.535218 2026] [security2:error] [pid 765155:tid 765348] [client 172.236.9.101:28856] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNcAAAAMQ"]
[Thu Jul 30 12:36:51.542313 2026] [security2:error] [pid 765155:tid 765393] [client 172.236.9.101:1052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNZwAAAPE"]
[Thu Jul 30 12:36:51.610103 2026] [security2:error] [pid 765155:tid 765295] [client 172.236.9.101:34752] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNcgAAAI8"]
[Thu Jul 30 12:36:51.628973 2026] [security2:error] [pid 765155:tid 765389] [client 20.63.98.115:60287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/lock360.php"] [unique_id "amuLs-T5hFAbD-LhWHiNqgAAAO0"]
[Thu Jul 30 12:36:51.707929 2026] [security2:error] [pid 765155:tid 765294] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_webdisk/wp-content/uploads/"] [unique_id "amuLs-T5hFAbD-LhWHiNqwAAAI4"]
[Thu Jul 30 12:36:51.964317 2026] [security2:error] [pid 765155:tid 765324] [client 152.32.142.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.kfo.lku.temporary.site"] [uri "/index.php"] [unique_id "amuLs-T5hFAbD-LhWHiNrgAAAKw"]
[Thu Jul 30 12:36:51.983666 2026] [security2:error] [pid 765155:tid 765410] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "amuLs-T5hFAbD-LhWHiNuAAAAQI"]
[Thu Jul 30 12:36:51.983766 2026] [security2:error] [pid 765155:tid 765410] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "amuLs-T5hFAbD-LhWHiNuAAAAQI"]
[Thu Jul 30 12:36:51.984762 2026] [security2:error] [pid 765155:tid 765388] [client 204.8.98.25:50994] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuLs-T5hFAbD-LhWHiNuQAAAOw"]
[Thu Jul 30 12:36:51.984840 2026] [security2:error] [pid 765155:tid 765388] [client 204.8.98.25:50994] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuLs-T5hFAbD-LhWHiNuQAAAOw"]
[Thu Jul 30 12:36:52.024171 2026] [core:notice] [pid 765155:tid 765351] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:52.030782 2026] [security2:error] [pid 765155:tid 765351] [client 103.215.74.26:58352] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLtOT5hFAbD-LhWHiNugAAAMc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:52.458142 2026] [security2:error] [pid 765155:tid 765407] [client 172.213.232.128:57888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/admin.php"] [unique_id "amuLtOT5hFAbD-LhWHiNxwAAAP8"]
[Thu Jul 30 12:36:52.472295 2026] [security2:error] [pid 765155:tid 765394] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-content/themes/index.php"] [unique_id "amuLtOT5hFAbD-LhWHiNyAAAAPI"]
[Thu Jul 30 12:36:52.472411 2026] [security2:error] [pid 765155:tid 765394] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-content/themes/index.php"] [unique_id "amuLtOT5hFAbD-LhWHiNyAAAAPI"]
[Thu Jul 30 12:36:52.699861 2026] [security2:error] [pid 765155:tid 765372] [client 68.221.69.72:65433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/wp.php"] [unique_id "amuLtOT5hFAbD-LhWHiNyQAAANw"]
[Thu Jul 30 12:36:52.700039 2026] [security2:error] [pid 765155:tid 765372] [client 68.221.69.72:65433] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/wp.php"] [unique_id "amuLtOT5hFAbD-LhWHiNyQAAANw"]
[Thu Jul 30 12:36:52.749894 2026] [core:notice] [pid 765155:tid 765385] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:52.755244 2026] [security2:error] [pid 765155:tid 765385] [client 103.215.74.26:58362] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "770"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLtOT5hFAbD-LhWHiNygAAAOk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:52.939668 2026] [autoindex:error] [pid 765155:tid 765305] [client 49.235.136.28:38308] AH01276: Cannot serve directory /home2/dovdtnte/public_html/rodneyleesmith/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:36:52.985343 2026] [security2:error] [pid 765155:tid 765311] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/gecko-new.php"] [unique_id "amuLtOT5hFAbD-LhWHiN1gAAAJ8"]
[Thu Jul 30 12:36:52.985485 2026] [security2:error] [pid 765155:tid 765311] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/gecko-new.php"] [unique_id "amuLtOT5hFAbD-LhWHiN1gAAAJ8"]
[Thu Jul 30 12:36:53.074920 2026] [security2:error] [pid 765155:tid 765390] [client 20.63.98.115:54199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "amuLteT5hFAbD-LhWHiN2gAAAO4"]
[Thu Jul 30 12:36:53.207246 2026] [security2:error] [pid 765155:tid 765376] [client 172.213.232.128:52946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/adminfuns.php"] [unique_id "amuLteT5hFAbD-LhWHiN3AAAAOA"]
[Thu Jul 30 12:36:53.435009 2026] [security2:error] [pid 765155:tid 765303] [client 57.141.0.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuLtOT5hFAbD-LhWHiNzgAAAJc"]
[Thu Jul 30 12:36:53.476097 2026] [core:notice] [pid 765155:tid 765370] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:53.483157 2026] [security2:error] [pid 765155:tid 765370] [client 103.215.74.26:33640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "740"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLteT5hFAbD-LhWHiN5gAAANo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:53.520322 2026] [security2:error] [pid 765155:tid 765307] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/NewFile.php"] [unique_id "amuLteT5hFAbD-LhWHiN5wAAAJs"]
[Thu Jul 30 12:36:53.520413 2026] [security2:error] [pid 765155:tid 765307] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/NewFile.php"] [unique_id "amuLteT5hFAbD-LhWHiN5wAAAJs"]
[Thu Jul 30 12:36:53.811418 2026] [security2:error] [pid 765155:tid 765318] [client 172.213.232.128:57650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/albin.php"] [unique_id "amuLteT5hFAbD-LhWHiN6wAAAKY"]
[Thu Jul 30 12:36:53.929131 2026] [security2:error] [pid 765155:tid 765373] [client 20.63.98.115:21169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/mah.php"] [unique_id "amuLteT5hFAbD-LhWHiN7QAAAN0"]
[Thu Jul 30 12:36:54.063528 2026] [security2:error] [pid 765155:tid 765408] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-Blogs.php"] [unique_id "amuLtuT5hFAbD-LhWHiN9AAAAQA"]
[Thu Jul 30 12:36:54.063616 2026] [security2:error] [pid 765155:tid 765408] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-Blogs.php"] [unique_id "amuLtuT5hFAbD-LhWHiN9AAAAQA"]
[Thu Jul 30 12:36:54.209578 2026] [core:notice] [pid 765155:tid 765314] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:54.213533 2026] [security2:error] [pid 765155:tid 765314] [client 103.215.74.26:33656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLtuT5hFAbD-LhWHiN-AAAAKI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:54.289606 2026] [core:notice] [pid 765155:tid 765297] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:54.595482 2026] [security2:error] [pid 765155:tid 765296] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-includes/fonts/index.php"] [unique_id "amuLtuT5hFAbD-LhWHiOBQAAAJA"]
[Thu Jul 30 12:36:54.595580 2026] [security2:error] [pid 765155:tid 765296] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-includes/fonts/index.php"] [unique_id "amuLtuT5hFAbD-LhWHiOBQAAAJA"]
[Thu Jul 30 12:36:54.712729 2026] [security2:error] [pid 765155:tid 765305] [client 68.221.69.72:38392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/fffm.php"] [unique_id "amuLtuT5hFAbD-LhWHiOBwAAAJk"]
[Thu Jul 30 12:36:54.712834 2026] [security2:error] [pid 765155:tid 765305] [client 68.221.69.72:38392] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/fffm.php"] [unique_id "amuLtuT5hFAbD-LhWHiOBwAAAJk"]
[Thu Jul 30 12:36:54.784202 2026] [core:error] [pid 765155:tid 765368] [client 20.63.98.115:54159] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:54.784231 2026] [core:error] [pid 765155:tid 765368] [client 20.63.98.115:54159] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:54.943760 2026] [core:notice] [pid 765155:tid 765377] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:54.947737 2026] [security2:error] [pid 765155:tid 765377] [client 103.215.74.26:33658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLtuT5hFAbD-LhWHiOCQAAAOE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:55.102039 2026] [security2:error] [pid 765155:tid 765374] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/themes.php"] [unique_id "amuLt-T5hFAbD-LhWHiOEQAAAN4"]
[Thu Jul 30 12:36:55.102146 2026] [security2:error] [pid 765155:tid 765374] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/themes.php"] [unique_id "amuLt-T5hFAbD-LhWHiOEQAAAN4"]
[Thu Jul 30 12:36:55.677264 2026] [security2:error] [pid 765155:tid 765381] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/cv.php"] [unique_id "amuLt-T5hFAbD-LhWHiOHgAAAOU"]
[Thu Jul 30 12:36:55.677369 2026] [security2:error] [pid 765155:tid 765381] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/cv.php"] [unique_id "amuLt-T5hFAbD-LhWHiOHgAAAOU"]
[Thu Jul 30 12:36:55.683895 2026] [core:notice] [pid 765155:tid 765386] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:55.689551 2026] [security2:error] [pid 765155:tid 765386] [client 103.215.74.26:33662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLt-T5hFAbD-LhWHiOIAAAAOo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:56.058849 2026] [security2:error] [pid 765155:tid 765318] [client 68.221.69.72:38389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/111.php"] [unique_id "amuLuOT5hFAbD-LhWHiOJAAAAKY"]
[Thu Jul 30 12:36:56.058991 2026] [security2:error] [pid 765155:tid 765318] [client 68.221.69.72:38389] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/111.php"] [unique_id "amuLuOT5hFAbD-LhWHiOJAAAAKY"]
[Thu Jul 30 12:36:56.212196 2026] [security2:error] [pid 765155:tid 765351] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_webdisk/wp-admin/js/"] [unique_id "amuLuOT5hFAbD-LhWHiOMAAAAMc"]
[Thu Jul 30 12:36:56.431586 2026] [core:notice] [pid 765155:tid 765391] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:56.436509 2026] [security2:error] [pid 765155:tid 765391] [client 103.215.74.26:33670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLuOT5hFAbD-LhWHiOMQAAAO8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:56.476233 2026] [security2:error] [pid 765155:tid 765315] [client 57.141.0.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuLt-T5hFAbD-LhWHiOIwAAAKM"]
[Thu Jul 30 12:36:56.480123 2026] [security2:error] [pid 765155:tid 765314] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-content/uploads/index.php"] [unique_id "amuLuOT5hFAbD-LhWHiOMgAAAKI"]
[Thu Jul 30 12:36:56.480210 2026] [security2:error] [pid 765155:tid 765314] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-content/uploads/index.php"] [unique_id "amuLuOT5hFAbD-LhWHiOMgAAAKI"]
[Thu Jul 30 12:36:56.598816 2026] [security2:error] [pid 765155:tid 765290] [client 172.237.109.114:49948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLuOT5hFAbD-LhWHiOJQAAAIo"]
[Thu Jul 30 12:36:56.608999 2026] [security2:error] [pid 765155:tid 765340] [client 20.63.98.115:49111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-class.php"] [unique_id "amuLuOT5hFAbD-LhWHiOOQAAALw"]
[Thu Jul 30 12:36:56.652631 2026] [security2:error] [pid 765155:tid 765320] [client 172.237.109.114:12838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLuOT5hFAbD-LhWHiOKQAAAKg"]
[Thu Jul 30 12:36:56.741278 2026] [security2:error] [pid 765155:tid 765359] [client 172.237.109.114:46634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLuOT5hFAbD-LhWHiOKgAAAM8"]
[Thu Jul 30 12:36:56.744194 2026] [security2:error] [pid 765155:tid 765350] [client 172.237.109.114:1638] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLuOT5hFAbD-LhWHiOLgAAAMY"]
[Thu Jul 30 12:36:56.755511 2026] [security2:error] [pid 765155:tid 765287] [client 172.237.109.114:23062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLuOT5hFAbD-LhWHiOLwAAAIc"]
[Thu Jul 30 12:36:56.970797 2026] [security2:error] [pid 765155:tid 765396] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/ws83.php"] [unique_id "amuLuOT5hFAbD-LhWHiOPQAAAPQ"]
[Thu Jul 30 12:36:56.970919 2026] [security2:error] [pid 765155:tid 765396] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/ws83.php"] [unique_id "amuLuOT5hFAbD-LhWHiOPQAAAPQ"]
[Thu Jul 30 12:36:57.093847 2026] [security2:error] [pid 765155:tid 765317] [client 172.213.232.128:59665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/amfsqvgv.php"] [unique_id "amuLueT5hFAbD-LhWHiORQAAAKU"]
[Thu Jul 30 12:36:57.142510 2026] [core:error] [pid 765155:tid 765211] [remote 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:57.142532 2026] [core:error] [pid 765155:tid 765211] [remote 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:57.159369 2026] [core:notice] [pid 765155:tid 765403] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:57.163204 2026] [security2:error] [pid 765155:tid 765403] [client 103.215.74.26:33686] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLueT5hFAbD-LhWHiORwAAAPs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:57.185075 2026] [core:error] [pid 765155:tid 765226] [remote 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:57.185092 2026] [core:error] [pid 765155:tid 765226] [remote 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:57.230078 2026] [core:error] [pid 765155:tid 765206] [remote 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:57.230097 2026] [core:error] [pid 765155:tid 765206] [remote 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:57.504717 2026] [security2:error] [pid 765155:tid 765356] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/atex1.php"] [unique_id "amuLueT5hFAbD-LhWHiOUQAAAMw"]
[Thu Jul 30 12:36:57.504820 2026] [security2:error] [pid 765155:tid 765356] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/atex1.php"] [unique_id "amuLueT5hFAbD-LhWHiOUQAAAMw"]
[Thu Jul 30 12:36:57.532098 2026] [security2:error] [pid 765155:tid 765285] [client 20.63.98.115:58085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/backup.php"] [unique_id "amuLueT5hFAbD-LhWHiOUwAAAIU"]
[Thu Jul 30 12:36:57.887539 2026] [core:notice] [pid 765155:tid 765293] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:57.892138 2026] [security2:error] [pid 765155:tid 765293] [client 103.215.74.26:33690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLueT5hFAbD-LhWHiOXQAAAI0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:58.034410 2026] [security2:error] [pid 765155:tid 765334] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/class-t.api.php"] [unique_id "amuLuuT5hFAbD-LhWHiOXgAAALY"]
[Thu Jul 30 12:36:58.034524 2026] [security2:error] [pid 765155:tid 765334] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/class-t.api.php"] [unique_id "amuLuuT5hFAbD-LhWHiOXgAAALY"]
[Thu Jul 30 12:36:58.198303 2026] [security2:error] [pid 765155:tid 765321] [client 172.213.232.128:59950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/ant.php"] [unique_id "amuLuuT5hFAbD-LhWHiOYQAAAKk"]
[Thu Jul 30 12:36:58.300069 2026] [security2:error] [pid 765155:tid 765298] [client 85.208.96.195:60450] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/07/26/5g-entenda-o-que-muda-com-a-chegada-do-sinal-em-joao-pessoa-nesta-sexta-feira-29/"] [unique_id "amuLuuT5hFAbD-LhWHiOaQAAAJI"]
[Thu Jul 30 12:36:58.300190 2026] [security2:error] [pid 765155:tid 765298] [client 85.208.96.195:60450] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/07/26/5g-entenda-o-que-muda-com-a-chegada-do-sinal-em-joao-pessoa-nesta-sexta-feira-29/"] [unique_id "amuLuuT5hFAbD-LhWHiOaQAAAJI"]
[Thu Jul 30 12:36:58.575849 2026] [security2:error] [pid 765155:tid 765288] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/w.php"] [unique_id "amuLuuT5hFAbD-LhWHiObwAAAIg"]
[Thu Jul 30 12:36:58.575957 2026] [security2:error] [pid 765155:tid 765288] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/w.php"] [unique_id "amuLuuT5hFAbD-LhWHiObwAAAIg"]
[Thu Jul 30 12:36:58.635635 2026] [core:notice] [pid 765155:tid 765329] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:58.640187 2026] [security2:error] [pid 765155:tid 765329] [client 103.215.74.26:33698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLuuT5hFAbD-LhWHiOcAAAALE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:58.661018 2026] [security2:error] [pid 765155:tid 765398] [client 20.63.98.115:58051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/default.php"] [unique_id "amuLuuT5hFAbD-LhWHiOcQAAAPY"]
[Thu Jul 30 12:36:58.794609 2026] [security2:error] [pid 765155:tid 765399] [client 57.141.0.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuLuuT5hFAbD-LhWHiOZQAAAPc"]
[Thu Jul 30 12:36:58.999063 2026] [security2:error] [pid 765155:tid 765324] [client 2a03:2880:f800:f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuLuuT5hFAbD-LhWHiObQAArEs"]
[Thu Jul 30 12:36:59.052934 2026] [security2:error] [pid 765155:tid 765355] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/archive.php"] [unique_id "amuLu-T5hFAbD-LhWHiOfwAAAMs"]
[Thu Jul 30 12:36:59.053076 2026] [security2:error] [pid 765155:tid 765355] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/archive.php"] [unique_id "amuLu-T5hFAbD-LhWHiOfwAAAMs"]
[Thu Jul 30 12:36:59.268412 2026] [core:notice] [pid 765155:tid 765237] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:59.284924 2026] [security2:error] [pid 765155:tid 765403] [client 150.107.232.194:27104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuLu-T5hFAbD-LhWHiOggAAAPs"]
[Thu Jul 30 12:36:59.285039 2026] [security2:error] [pid 765155:tid 765403] [client 150.107.232.194:27104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuLu-T5hFAbD-LhWHiOggAAAPs"]
[Thu Jul 30 12:36:59.376956 2026] [core:notice] [pid 765155:tid 765374] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:59.382505 2026] [security2:error] [pid 765155:tid 765374] [client 103.215.74.26:33712] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLu-T5hFAbD-LhWHiOhgAAAN4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:59.558742 2026] [security2:error] [pid 765155:tid 765303] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/bless.php"] [unique_id "amuLu-T5hFAbD-LhWHiOjQAAAJc"]
[Thu Jul 30 12:36:59.558860 2026] [security2:error] [pid 765155:tid 765303] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/bless.php"] [unique_id "amuLu-T5hFAbD-LhWHiOjQAAAJc"]
[Thu Jul 30 12:36:59.974281 2026] [core:notice] [pid 765155:tid 765168] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:00.058599 2026] [security2:error] [pid 765155:tid 765346] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/sagax1.php"] [unique_id "amuLvOT5hFAbD-LhWHiOmAAAAMI"]
[Thu Jul 30 12:37:00.058748 2026] [security2:error] [pid 765155:tid 765346] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/sagax1.php"] [unique_id "amuLvOT5hFAbD-LhWHiOmAAAAMI"]
[Thu Jul 30 12:37:00.124300 2026] [security2:error] [pid 765155:tid 765345] [client 20.63.98.115:47325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/maint/about.php"] [unique_id "amuLvOT5hFAbD-LhWHiOmQAAAME"]
[Thu Jul 30 12:37:00.130619 2026] [core:notice] [pid 765155:tid 765325] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:00.135947 2026] [security2:error] [pid 765155:tid 765325] [client 103.215.74.26:33726] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLvOT5hFAbD-LhWHiOmgAAAK0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:00.181262 2026] [security2:error] [pid 765155:tid 765307] [client 20.151.221.234:20969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wk/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOmwAAAJs"]
[Thu Jul 30 12:37:00.551655 2026] [security2:error] [pid 765155:tid 765350] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wpc.php"] [unique_id "amuLvOT5hFAbD-LhWHiOvAAAAMY"]
[Thu Jul 30 12:37:00.551862 2026] [security2:error] [pid 765155:tid 765350] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wpc.php"] [unique_id "amuLvOT5hFAbD-LhWHiOvAAAAMY"]
[Thu Jul 30 12:37:00.562105 2026] [security2:error] [pid 765155:tid 765320] [client 172.213.232.128:58231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/appreciators.php"] [unique_id "amuLvOT5hFAbD-LhWHiOvQAAAKg"]
[Thu Jul 30 12:37:00.879753 2026] [core:notice] [pid 765155:tid 765357] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:00.884940 2026] [security2:error] [pid 765155:tid 765357] [client 103.215.74.26:33736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLvOT5hFAbD-LhWHiOvgAAAM0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:01.066171 2026] [security2:error] [pid 765155:tid 765339] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/fone1.php"] [unique_id "amuLveT5hFAbD-LhWHiOxwAAALs"]
[Thu Jul 30 12:37:01.066281 2026] [security2:error] [pid 765155:tid 765339] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/fone1.php"] [unique_id "amuLveT5hFAbD-LhWHiOxwAAALs"]
[Thu Jul 30 12:37:01.157454 2026] [security2:error] [pid 765155:tid 765352] [client 20.63.98.115:49133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/uploads/2022/10/upload.php"] [unique_id "amuLveT5hFAbD-LhWHiOyQAAAMg"]
[Thu Jul 30 12:37:01.178710 2026] [security2:error] [pid 765155:tid 765384] [client 20.151.221.234:54039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/av.php"] [unique_id "amuLveT5hFAbD-LhWHiOygAAAOg"]
[Thu Jul 30 12:37:01.234441 2026] [core:notice] [pid 765155:tid 765409] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:01.237826 2026] [security2:error] [pid 765155:tid 765409] [client 68.221.69.72:14595] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "radiojelli.com"] [uri "/wp-includes/Requests.html"] [unique_id "amuLveT5hFAbD-LhWHiOywAAAQE"]
[Thu Jul 30 12:37:01.489459 2026] [core:notice] [pid 765155:tid 765240] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:01.571349 2026] [security2:error] [pid 765155:tid 765389] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/ncx.php"] [unique_id "amuLveT5hFAbD-LhWHiO1QAAAO0"]
[Thu Jul 30 12:37:01.571514 2026] [security2:error] [pid 765155:tid 765389] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/ncx.php"] [unique_id "amuLveT5hFAbD-LhWHiO1QAAAO0"]
[Thu Jul 30 12:37:01.615622 2026] [core:notice] [pid 765155:tid 765300] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:01.620946 2026] [security2:error] [pid 765155:tid 765300] [client 103.215.74.26:33738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLveT5hFAbD-LhWHiO2AAAAJQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:01.676325 2026] [security2:error] [pid 765155:tid 765355] [client 172.213.232.128:53891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/archive.php"] [unique_id "amuLveT5hFAbD-LhWHiO2QAAAMs"]
[Thu Jul 30 12:37:02.084616 2026] [security2:error] [pid 765155:tid 765316] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-admin/js/index.php"] [unique_id "amuLvuT5hFAbD-LhWHiO4gAAAKQ"]
[Thu Jul 30 12:37:02.084712 2026] [security2:error] [pid 765155:tid 765316] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-admin/js/index.php"] [unique_id "amuLvuT5hFAbD-LhWHiO4gAAAKQ"]
[Thu Jul 30 12:37:02.136873 2026] [security2:error] [pid 765155:tid 765245] [remote 74.7.241.60:43382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/article.php"] [unique_id "amuLvuT5hFAbD-LhWHiO5AAA5Vk"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/1784117929_IMG_3676.jpg
[Thu Jul 30 12:37:02.251503 2026] [security2:error] [pid 765155:tid 765292] [client 172.236.9.101:30072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOnAAAAIw"]
[Thu Jul 30 12:37:02.278679 2026] [security2:error] [pid 765155:tid 765400] [client 172.236.9.101:36033] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOnQAAAPg"]
[Thu Jul 30 12:37:02.343431 2026] [security2:error] [pid 765155:tid 765343] [client 172.236.9.101:50341] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOpAAAAL8"]
[Thu Jul 30 12:37:02.343431 2026] [security2:error] [pid 765155:tid 765286] [client 172.236.9.101:8314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOqAAAAIY"]
[Thu Jul 30 12:37:02.344628 2026] [security2:error] [pid 765155:tid 765321] [client 172.236.9.101:57894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOogAAAKk"]
[Thu Jul 30 12:37:02.350996 2026] [core:notice] [pid 765155:tid 765370] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:02.359164 2026] [security2:error] [pid 765155:tid 765370] [client 103.215.74.26:33754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLvuT5hFAbD-LhWHiO5QAAANo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:02.377172 2026] [security2:error] [pid 765155:tid 765298] [client 172.236.9.101:33143] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOpgAAAJI"]
[Thu Jul 30 12:37:02.383852 2026] [security2:error] [pid 765155:tid 765306] [client 172.236.9.101:12833] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOoQAAAJo"]
[Thu Jul 30 12:37:02.398754 2026] [security2:error] [pid 765155:tid 765367] [client 172.236.9.101:42389] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOsgAAANc"]
[Thu Jul 30 12:37:02.398754 2026] [security2:error] [pid 765155:tid 765411] [client 172.236.9.101:12919] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOsAAAAQM"]
[Thu Jul 30 12:37:02.398754 2026] [security2:error] [pid 765155:tid 765330] [client 172.236.9.101:10978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOpwAAALI"]
[Thu Jul 30 12:37:02.401875 2026] [security2:error] [pid 765155:tid 765336] [client 172.236.9.101:4828] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOrwAAALg"]
[Thu Jul 30 12:37:02.417549 2026] [security2:error] [pid 765155:tid 765340] [client 172.236.9.101:40714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOrgAAALw"]
[Thu Jul 30 12:37:02.428125 2026] [security2:error] [pid 765155:tid 765315] [client 172.236.9.101:60136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOrQAAAKM"]
[Thu Jul 30 12:37:02.428125 2026] [security2:error] [pid 765155:tid 765408] [client 172.236.9.101:26760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOnwAAAQA"]
[Thu Jul 30 12:37:02.431715 2026] [security2:error] [pid 765155:tid 765363] [client 172.236.9.101:30720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOqQAAANM"]
[Thu Jul 30 12:37:02.439511 2026] [security2:error] [pid 765155:tid 765258] [remote 216.73.216.152:7696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuLvuT5hFAbD-LhWHiO5gAAyWY"]
[Thu Jul 30 12:37:02.444850 2026] [security2:error] [pid 765155:tid 765391] [client 172.236.9.101:59176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOrAAAAO8"]
[Thu Jul 30 12:37:02.444948 2026] [security2:error] [pid 765155:tid 765297] [client 172.236.9.101:48947] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOqgAAAJE"]
[Thu Jul 30 12:37:02.450071 2026] [security2:error] [pid 765155:tid 765327] [client 172.236.9.101:12610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOngAAAK8"]
[Thu Jul 30 12:37:02.453134 2026] [security2:error] [pid 765155:tid 765290] [client 172.236.9.101:46667] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOqwAAAIo"]
[Thu Jul 30 12:37:02.484339 2026] [security2:error] [pid 765155:tid 765326] [client 172.236.9.101:14017] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOsQAAAK4"]
[Thu Jul 30 12:37:02.572884 2026] [security2:error] [pid 765155:tid 765299] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wso.php"] [unique_id "amuLvuT5hFAbD-LhWHiO6gAAAJM"]
[Thu Jul 30 12:37:02.573008 2026] [security2:error] [pid 765155:tid 765299] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wso.php"] [unique_id "amuLvuT5hFAbD-LhWHiO6gAAAJM"]
[Thu Jul 30 12:37:02.855071 2026] [security2:error] [pid 765155:tid 765317] [client 20.151.221.234:20929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/mini.php"] [unique_id "amuLvuT5hFAbD-LhWHiO9AAAAKU"]
[Thu Jul 30 12:37:03.002247 2026] [core:notice] [pid 765155:tid 765233] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:03.096416 2026] [security2:error] [pid 765155:tid 765293] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/zup.php73"] [unique_id "amuLv-T5hFAbD-LhWHiO_QAAAI0"]
[Thu Jul 30 12:37:03.096548 2026] [security2:error] [pid 765155:tid 765293] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/zup.php73"] [unique_id "amuLv-T5hFAbD-LhWHiO_QAAAI0"]
[Thu Jul 30 12:37:03.653914 2026] [security2:error] [pid 765155:tid 765342] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/k.php"] [unique_id "amuLv-T5hFAbD-LhWHiPBgAAAL4"]
[Thu Jul 30 12:37:03.654073 2026] [security2:error] [pid 765155:tid 765342] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/k.php"] [unique_id "amuLv-T5hFAbD-LhWHiPBgAAAL4"]
[Thu Jul 30 12:37:04.115387 2026] [security2:error] [pid 765155:tid 765322] [client 20.151.221.234:20965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/aa.php"] [unique_id "amuLwOT5hFAbD-LhWHiPDQAAAKo"]
[Thu Jul 30 12:37:04.210148 2026] [security2:error] [pid 765155:tid 765327] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-blink.php"] [unique_id "amuLwOT5hFAbD-LhWHiPEgAAAK8"]
[Thu Jul 30 12:37:04.210251 2026] [security2:error] [pid 765155:tid 765327] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-blink.php"] [unique_id "amuLwOT5hFAbD-LhWHiPEgAAAK8"]
[Thu Jul 30 12:37:04.520072 2026] [core:notice] [pid 765155:tid 765283] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:04.766220 2026] [security2:error] [pid 765155:tid 765331] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_webdisk/randkeyword.PhP7"] [unique_id "amuLwOT5hFAbD-LhWHiPIQAAALM"]
[Thu Jul 30 12:37:04.922741 2026] [security2:error] [pid 765155:tid 765309] [client 20.63.98.115:60265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/ty.php"] [unique_id "amuLwOT5hFAbD-LhWHiPIgAAAJ0"]
[Thu Jul 30 12:37:05.029599 2026] [security2:error] [pid 765155:tid 765324] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/colors/ectoplasm/"] [unique_id "amuLweT5hFAbD-LhWHiPIwAAAKw"]
[Thu Jul 30 12:37:05.181249 2026] [core:error] [pid 765155:tid 765278] [remote 66.249.73.224:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:37:05.181271 2026] [core:error] [pid 765155:tid 765278] [remote 66.249.73.224:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:37:05.328905 2026] [security2:error] [pid 765155:tid 765296] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_webdisk/wp-content/"] [unique_id "amuLweT5hFAbD-LhWHiPLgAAAJA"]
[Thu Jul 30 12:37:05.588684 2026] [security2:error] [pid 765155:tid 765347] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/ww5.php"] [unique_id "amuLweT5hFAbD-LhWHiPLwAAAMM"]
[Thu Jul 30 12:37:05.588811 2026] [security2:error] [pid 765155:tid 765347] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/ww5.php"] [unique_id "amuLweT5hFAbD-LhWHiPLwAAAMM"]
[Thu Jul 30 12:37:05.938060 2026] [security2:error] [pid 765155:tid 765338] [client 38.190.144.4:51117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLweT5hFAbD-LhWHiPOwAAALo"]
[Thu Jul 30 12:37:05.938175 2026] [security2:error] [pid 765155:tid 765338] [client 38.190.144.4:51117] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLweT5hFAbD-LhWHiPOwAAALo"]
[Thu Jul 30 12:37:06.033675 2026] [core:notice] [pid 765155:tid 765177] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:06.087740 2026] [security2:error] [pid 765155:tid 765285] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/2.php"] [unique_id "amuLwuT5hFAbD-LhWHiPPgAAAIU"]
[Thu Jul 30 12:37:06.087864 2026] [security2:error] [pid 765155:tid 765285] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/2.php"] [unique_id "amuLwuT5hFAbD-LhWHiPPgAAAIU"]
[Thu Jul 30 12:37:06.202076 2026] [security2:error] [pid 765155:tid 765369] [client 20.151.221.234:20974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/w.php"] [unique_id "amuLwuT5hFAbD-LhWHiPRQAAANk"]
[Thu Jul 30 12:37:06.285005 2026] [security2:error] [pid 765155:tid 765354] [client 201.209.116.37:59912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuLweT5hFAbD-LhWHiPPAAAAMo"], referer: http://pkf.jo
[Thu Jul 30 12:37:06.503261 2026] [core:notice] [pid 765155:tid 765395] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:06.577586 2026] [security2:error] [pid 765155:tid 765355] [client 198.163.194.127:7867] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuLwuT5hFAbD-LhWHiPSgAAAMs"], referer: http://pkf.jo
[Thu Jul 30 12:37:06.590435 2026] [security2:error] [pid 765155:tid 765315] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-admin/classwithtostring.php"] [unique_id "amuLwuT5hFAbD-LhWHiPVgAAAKM"]
[Thu Jul 30 12:37:06.590546 2026] [security2:error] [pid 765155:tid 765315] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-admin/classwithtostring.php"] [unique_id "amuLwuT5hFAbD-LhWHiPVgAAAKM"]
[Thu Jul 30 12:37:06.753545 2026] [security2:error] [pid 765155:tid 765320] [client 195.63.20.72:54094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "deltaedu.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuLwuT5hFAbD-LhWHiPVwAAqBs"], referer: https://deltaedu.net/wp-admin/admin-ajax.php?action=tnp&na=s
[Thu Jul 30 12:37:06.886652 2026] [security2:error] [pid 765155:tid 765400] [client 172.236.9.101:6801] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLwuT5hFAbD-LhWHiPTgAAAPg"]
[Thu Jul 30 12:37:06.887401 2026] [security2:error] [pid 765155:tid 765286] [client 172.236.9.101:4614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLwuT5hFAbD-LhWHiPSwAAAIY"]
[Thu Jul 30 12:37:06.973546 2026] [security2:error] [pid 765155:tid 765313] [client 20.151.221.234:54031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/admin.php"] [unique_id "amuLwuT5hFAbD-LhWHiPXwAAAKE"]
[Thu Jul 30 12:37:06.980499 2026] [security2:error] [pid 765155:tid 765306] [client 172.236.9.101:17670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLwuT5hFAbD-LhWHiPUAAAAJo"]
[Thu Jul 30 12:37:07.019499 2026] [security2:error] [pid 765155:tid 765330] [client 172.236.9.101:40437] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLwuT5hFAbD-LhWHiPUQAAALI"]
[Thu Jul 30 12:37:07.115048 2026] [security2:error] [pid 765155:tid 765404] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/atomlib.php"] [unique_id "amuLw-T5hFAbD-LhWHiPZAAAAPw"]
[Thu Jul 30 12:37:07.115127 2026] [security2:error] [pid 765155:tid 765404] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/atomlib.php"] [unique_id "amuLw-T5hFAbD-LhWHiPZAAAAPw"]
[Thu Jul 30 12:37:07.160563 2026] [core:notice] [pid 765155:tid 765297] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:07.211472 2026] [security2:error] [pid 765155:tid 765398] [client 146.103.115.7:54211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.103.146.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/my-account/"] [unique_id "amuLwuT5hFAbD-LhWHiPXgAAAPY"], referer: http://smoke-tfhk.com/
[Thu Jul 30 12:37:07.550304 2026] [core:notice] [pid 765155:tid 765189] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:07.582401 2026] [security2:error] [pid 765155:tid 765297] [client 68.221.69.72:14619] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/money.html"] [unique_id "amuLw-T5hFAbD-LhWHiPaQAAAJE"]
[Thu Jul 30 12:37:07.650200 2026] [security2:error] [pid 765155:tid 765345] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/rip.php"] [unique_id "amuLw-T5hFAbD-LhWHiPiQAAAME"]
[Thu Jul 30 12:37:07.650390 2026] [security2:error] [pid 765155:tid 765345] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/rip.php"] [unique_id "amuLw-T5hFAbD-LhWHiPiQAAAME"]
[Thu Jul 30 12:37:07.935639 2026] [security2:error] [pid 765155:tid 765369] [client 20.151.221.234:20980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuLw-T5hFAbD-LhWHiPkgAAANk"]
[Thu Jul 30 12:37:08.124698 2026] [core:notice] [pid 765155:tid 765322] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:08.129102 2026] [security2:error] [pid 765155:tid 765322] [client 103.215.74.26:23214] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLxOT5hFAbD-LhWHiPmQAAAKo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:08.151202 2026] [security2:error] [pid 765155:tid 765371] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/p.php"] [unique_id "amuLxOT5hFAbD-LhWHiPmgAAANs"]
[Thu Jul 30 12:37:08.151349 2026] [security2:error] [pid 765155:tid 765371] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/p.php"] [unique_id "amuLxOT5hFAbD-LhWHiPmgAAANs"]
[Thu Jul 30 12:37:08.290206 2026] [security2:error] [pid 765155:tid 765316] [client 57.141.0.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuLw-T5hFAbD-LhWHiPgwAAAKQ"]
[Thu Jul 30 12:37:08.291560 2026] [security2:error] [pid 765155:tid 765406] [client 172.213.232.128:61323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/as.php"] [unique_id "amuLxOT5hFAbD-LhWHiPqAAAAP4"]
[Thu Jul 30 12:37:08.492808 2026] [security2:error] [pid 765155:tid 765335] [client 172.236.9.101:2768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLw-T5hFAbD-LhWHiPbgAAALc"]
[Thu Jul 30 12:37:08.499281 2026] [security2:error] [pid 765155:tid 765352] [client 172.236.9.101:43872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLw-T5hFAbD-LhWHiPcAAAAMg"]
[Thu Jul 30 12:37:08.501230 2026] [security2:error] [pid 765155:tid 765384] [client 172.236.9.101:15474] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLw-T5hFAbD-LhWHiPbQAAAOg"]
[Thu Jul 30 12:37:08.518885 2026] [security2:error] [pid 765155:tid 765291] [client 172.236.9.101:1314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLw-T5hFAbD-LhWHiPbwAAAIs"]
[Thu Jul 30 12:37:08.586527 2026] [security2:error] [pid 765155:tid 765295] [client 172.236.9.101:30089] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLw-T5hFAbD-LhWHiPcgAAAI8"]
[Thu Jul 30 12:37:08.588784 2026] [security2:error] [pid 765155:tid 765323] [client 172.236.9.101:9845] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLw-T5hFAbD-LhWHiPdQAAAKs"]
[Thu Jul 30 12:37:08.602967 2026] [security2:error] [pid 765155:tid 765362] [client 172.236.9.101:54875] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLw-T5hFAbD-LhWHiPdAAAANI"]
[Thu Jul 30 12:37:08.638003 2026] [security2:error] [pid 765155:tid 765368] [client 172.236.9.101:24564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLw-T5hFAbD-LhWHiPcQAAANg"]
[Thu Jul 30 12:37:08.640110 2026] [security2:error] [pid 765155:tid 765379] [client 172.236.9.101:13558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLw-T5hFAbD-LhWHiPcwAAAOM"]
[Thu Jul 30 12:37:08.653828 2026] [security2:error] [pid 765155:tid 765289] [client 172.236.9.101:29658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLw-T5hFAbD-LhWHiPdwAAAIk"]
[Thu Jul 30 12:37:08.656094 2026] [security2:error] [pid 765155:tid 765287] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/php.php"] [unique_id "amuLxOT5hFAbD-LhWHiPrQAAAIc"]
[Thu Jul 30 12:37:08.656284 2026] [security2:error] [pid 765155:tid 765287] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/php.php"] [unique_id "amuLxOT5hFAbD-LhWHiPrQAAAIc"]
[Thu Jul 30 12:37:08.660742 2026] [security2:error] [pid 765155:tid 765389] [client 172.236.9.101:55216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLw-T5hFAbD-LhWHiPewAAAO0"]
[Thu Jul 30 12:37:08.665683 2026] [security2:error] [pid 765155:tid 765350] [client 172.236.9.101:17991] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLw-T5hFAbD-LhWHiPfAAAAMY"]
[Thu Jul 30 12:37:08.669016 2026] [security2:error] [pid 765155:tid 765296] [client 172.236.9.101:1385] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLw-T5hFAbD-LhWHiPeAAAAJA"]
[Thu Jul 30 12:37:08.669016 2026] [security2:error] [pid 765155:tid 765370] [client 172.236.9.101:1509] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLw-T5hFAbD-LhWHiPeQAAANo"]
[Thu Jul 30 12:37:08.674617 2026] [security2:error] [pid 765155:tid 765305] [client 172.236.9.101:53158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLw-T5hFAbD-LhWHiPdgAAAJk"]
[Thu Jul 30 12:37:08.684053 2026] [security2:error] [pid 765155:tid 765405] [client 172.236.9.101:59557] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLw-T5hFAbD-LhWHiPegAAAP0"]
[Thu Jul 30 12:37:08.854008 2026] [core:notice] [pid 765155:tid 765308] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:08.858593 2026] [security2:error] [pid 765155:tid 765308] [client 103.215.74.26:23230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLxOT5hFAbD-LhWHiPtQAAAJw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:09.067791 2026] [core:notice] [pid 765155:tid 765210] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:09.594437 2026] [core:notice] [pid 765155:tid 765397] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:09.598397 2026] [security2:error] [pid 765155:tid 765397] [client 103.215.74.26:23232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLxeT5hFAbD-LhWHiP0QAAAPU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:09.817717 2026] [security2:error] [pid 765155:tid 765380] [client 172.213.232.128:62827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/atomlib.php"] [unique_id "amuLxeT5hFAbD-LhWHiP1gAAAOQ"]
[Thu Jul 30 12:37:10.060051 2026] [security2:error] [pid 765155:tid 765309] [client 150.107.232.194:26957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuLxuT5hFAbD-LhWHiP3gAAAJ0"]
[Thu Jul 30 12:37:10.060162 2026] [security2:error] [pid 765155:tid 765309] [client 150.107.232.194:26957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuLxuT5hFAbD-LhWHiP3gAAAJ0"]
[Thu Jul 30 12:37:10.580548 2026] [core:notice] [pid 765155:tid 765214] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:10.902582 2026] [security2:error] [pid 765155:tid 765285] [client 20.151.221.234:20989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/m.php"] [unique_id "amuLxuT5hFAbD-LhWHiP9QAAAIU"]
[Thu Jul 30 12:37:11.420629 2026] [security2:error] [pid 765155:tid 765411] [client 185.191.171.19:61512] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/06/04/mega-sena-concurso-deste-sabado-4-tem-premio-estimado-em-r-4-milhoes/"] [unique_id "amuLx-T5hFAbD-LhWHiP_gAAAQM"]
[Thu Jul 30 12:37:11.420761 2026] [security2:error] [pid 765155:tid 765411] [client 185.191.171.19:61512] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/06/04/mega-sena-concurso-deste-sabado-4-tem-premio-estimado-em-r-4-milhoes/"] [unique_id "amuLx-T5hFAbD-LhWHiP_gAAAQM"]
[Thu Jul 30 12:37:11.602241 2026] [security2:error] [pid 765155:tid 765315] [client 47.128.48.166:54176] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ecre.ae"] [uri "/robots.txt"] [unique_id "amuLx-T5hFAbD-LhWHiQAwAAAKM"]
[Thu Jul 30 12:37:12.064660 2026] [security2:error] [pid 765155:tid 765326] [client 20.151.221.234:20876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuLx-T5hFAbD-LhWHiQBwAAAK4"]
[Thu Jul 30 12:37:12.092324 2026] [core:notice] [pid 765155:tid 765221] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:12.381375 2026] [security2:error] [pid 765155:tid 765322] [client 20.63.98.115:21133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/readme.php"] [unique_id "amuLyOT5hFAbD-LhWHiQFQAAAKo"]
[Thu Jul 30 12:37:12.441884 2026] [security2:error] [pid 765155:tid 765238] [remote 216.73.216.152:6815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuLyOT5hFAbD-LhWHiQGgAAq1I"]
[Thu Jul 30 12:37:13.315139 2026] [security2:error] [pid 765155:tid 765390] [client 20.63.98.115:49099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/options.php"] [unique_id "amuLyeT5hFAbD-LhWHiQKQAAAO4"]
[Thu Jul 30 12:37:13.611907 2026] [core:notice] [pid 765155:tid 765249] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:14.188766 2026] [security2:error] [pid 765155:tid 765246] [remote 47.128.24.74:63974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "shop-mevius.com"] [uri "/product/terea-13/"] [unique_id "amuLyuT5hFAbD-LhWHiQQAAAilo"]
[Thu Jul 30 12:37:14.198875 2026] [security2:error] [pid 765155:tid 765356] [client 20.63.98.115:21017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/admin.php7"] [unique_id "amuLyuT5hFAbD-LhWHiQQQAAAMw"]
[Thu Jul 30 12:37:14.229670 2026] [security2:error] [pid 765155:tid 765358] [client 172.213.232.128:58157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/autoload_classmap.php"] [unique_id "amuLyuT5hFAbD-LhWHiQQgAAAM4"]
[Thu Jul 30 12:37:15.124519 2026] [core:notice] [pid 765155:tid 765240] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:15.338296 2026] [core:notice] [pid 765155:tid 765291] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:15.342011 2026] [security2:error] [pid 765155:tid 765291] [client 103.215.74.26:41332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "741"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLy-T5hFAbD-LhWHiQYQAAAIs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:15.376705 2026] [security2:error] [pid 765155:tid 765379] [client 185.244.152.228:18263] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuLy-T5hFAbD-LhWHiQVQAAAOM"], referer: http://pkf.jo
[Thu Jul 30 12:37:16.075623 2026] [core:notice] [pid 765155:tid 765342] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:16.079707 2026] [security2:error] [pid 765155:tid 765342] [client 103.215.74.26:41346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "738"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLzOT5hFAbD-LhWHiQcAAAAL4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:16.162683 2026] [security2:error] [pid 765155:tid 765393] [client 216.73.216.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.embassyofbelgiumislamabad.cc"] [uri "/index.php"] [unique_id "amuLzOT5hFAbD-LhWHiQbQAA8Vs"]
[Thu Jul 30 12:37:16.359456 2026] [security2:error] [pid 765155:tid 765323] [client 20.63.98.115:49146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/.well-known/wp-login.php"] [unique_id "amuLzOT5hFAbD-LhWHiQegAAAKs"]
[Thu Jul 30 12:37:16.637935 2026] [core:notice] [pid 765155:tid 765274] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:16.844120 2026] [core:notice] [pid 765155:tid 765383] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:16.849149 2026] [security2:error] [pid 765155:tid 765411] [client 38.190.144.4:51620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLzOT5hFAbD-LhWHiQjQAAAQM"]
[Thu Jul 30 12:37:16.849279 2026] [security2:error] [pid 765155:tid 765411] [client 38.190.144.4:51620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLzOT5hFAbD-LhWHiQjQAAAQM"]
[Thu Jul 30 12:37:16.851615 2026] [security2:error] [pid 765155:tid 765383] [client 103.215.74.26:41348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLzOT5hFAbD-LhWHiQjgAAAOc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:17.100624 2026] [security2:error] [pid 765155:tid 765375] [client 68.221.69.72:64782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/ws.php"] [unique_id "amuLzeT5hFAbD-LhWHiQkAAAAN8"]
[Thu Jul 30 12:37:17.100738 2026] [security2:error] [pid 765155:tid 765375] [client 68.221.69.72:64782] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/ws.php"] [unique_id "amuLzeT5hFAbD-LhWHiQkAAAAN8"]
[Thu Jul 30 12:37:17.103481 2026] [security2:error] [pid 765155:tid 765311] [client 172.213.232.128:58960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/bb.php"] [unique_id "amuLzeT5hFAbD-LhWHiQkgAAAJ8"]
[Thu Jul 30 12:37:17.424181 2026] [security2:error] [pid 765155:tid 765373] [client 216.73.216.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guardian-heir.com"] [uri "/index.php"] [unique_id "amuLzeT5hFAbD-LhWHiQlwAA3Wc"]
[Thu Jul 30 12:37:17.587271 2026] [core:notice] [pid 765155:tid 765324] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:17.599626 2026] [security2:error] [pid 765155:tid 765324] [client 103.215.74.26:41352] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLzeT5hFAbD-LhWHiQngAAAKw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:17.759090 2026] [security2:error] [pid 765155:tid 765363] [client 20.63.98.115:47320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amuLzeT5hFAbD-LhWHiQpgAAANM"]
[Thu Jul 30 12:37:17.827118 2026] [security2:error] [pid 765155:tid 765379] [client 20.104.18.253:26164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/011i.php"] [unique_id "amuLzeT5hFAbD-LhWHiQqwAAAOM"]
[Thu Jul 30 12:37:18.158234 2026] [core:notice] [pid 765155:tid 765242] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:18.298539 2026] [security2:error] [pid 765155:tid 765399] [client 195.200.28.67:53884] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "195.200.28.67" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "deltaedu.net"] [uri "/wp-comments-post.php"] [unique_id "amuLzuT5hFAbD-LhWHiQvgAAAPc"], referer: http://deltaedu.net/2016/11/04/university-scholarship-2017/
[Thu Jul 30 12:37:18.325965 2026] [core:notice] [pid 765155:tid 765392] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:18.337262 2026] [security2:error] [pid 765155:tid 765392] [client 103.215.74.26:41356] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLzuT5hFAbD-LhWHiQvwAAAPA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:18.456970 2026] [security2:error] [pid 765155:tid 765321] [client 57.141.0.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuLzeT5hFAbD-LhWHiQrQAAAKk"]
[Thu Jul 30 12:37:18.465521 2026] [security2:error] [pid 765155:tid 765399] [client 195.200.28.67:53884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "deltaedu.net"] [uri "/wp-comments-post.php"] [unique_id "amuLzuT5hFAbD-LhWHiQvgAAAPc"], referer: http://deltaedu.net/2016/11/04/university-scholarship-2017/
[Thu Jul 30 12:37:18.628130 2026] [security2:error] [pid 765155:tid 765278] [remote 52.167.144.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/jipkl/article/download/138/131"] [unique_id "amuLzuT5hFAbD-LhWHiQxAAAm3o"]
[Thu Jul 30 12:37:18.679517 2026] [security2:error] [pid 765155:tid 765371] [client 57.141.0.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuLzuT5hFAbD-LhWHiQwgAAANs"]
[Thu Jul 30 12:37:18.783127 2026] [security2:error] [pid 765155:tid 765320] [client 20.104.18.253:25922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/03a005685d.php"] [unique_id "amuLzuT5hFAbD-LhWHiQywAAAKg"]
[Thu Jul 30 12:37:18.798032 2026] [security2:error] [pid 765155:tid 765389] [client 195.200.28.67:53910] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "195.200.28.67" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "deltaedu.net"] [uri "/wp-comments-post.php"] [unique_id "amuLzuT5hFAbD-LhWHiQzgAAAO0"], referer: http://deltaedu.net/2016/11/04/university-scholarship-2017/
[Thu Jul 30 12:37:18.963519 2026] [security2:error] [pid 765155:tid 765389] [client 195.200.28.67:53910] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "deltaedu.net"] [uri "/wp-comments-post.php"] [unique_id "amuLzuT5hFAbD-LhWHiQzgAAAO0"], referer: http://deltaedu.net/2016/11/04/university-scholarship-2017/
[Thu Jul 30 12:37:19.671610 2026] [core:notice] [pid 765155:tid 765172] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:20.037102 2026] [security2:error] [pid 765155:tid 765360] [client 153.117.11.4:10144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuLz-T5hFAbD-LhWHiQ5gAAANA"], referer: http://pkf.jo
[Thu Jul 30 12:37:20.290243 2026] [security2:error] [pid 765155:tid 765298] [client 150.107.232.194:27073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuL0OT5hFAbD-LhWHiQ8wAAAJI"]
[Thu Jul 30 12:37:20.290354 2026] [security2:error] [pid 765155:tid 765298] [client 150.107.232.194:27073] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuL0OT5hFAbD-LhWHiQ8wAAAJI"]
[Thu Jul 30 12:37:20.574509 2026] [security2:error] [pid 765155:tid 765393] [client 20.104.18.253:43297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/403.php"] [unique_id "amuL0OT5hFAbD-LhWHiQ_QAAAPE"]
[Thu Jul 30 12:37:20.801874 2026] [security2:error] [pid 765155:tid 765342] [client 20.63.98.115:49108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/file.php"] [unique_id "amuL0OT5hFAbD-LhWHiRAwAAAL4"]
[Thu Jul 30 12:37:20.844629 2026] [security2:error] [pid 765155:tid 765377] [client 146.103.115.7:55757] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuLz-T5hFAbD-LhWHiQ2wAAAOE"], referer: http://smoke-tfhk.com/xmlrpc.php
[Thu Jul 30 12:37:20.870150 2026] [core:notice] [pid 765155:tid 765156] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:21.028680 2026] [security2:error] [pid 765155:tid 765313] [client 172.213.232.128:59001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/bnm.php"] [unique_id "amuL0eT5hFAbD-LhWHiRDAAAAKE"]
[Thu Jul 30 12:37:21.443998 2026] [security2:error] [pid 765155:tid 765337] [client 102.211.145.195:42338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuL0eT5hFAbD-LhWHiRDgAAALk"], referer: http://pkf.jo
[Thu Jul 30 12:37:21.497929 2026] [security2:error] [pid 765155:tid 765349] [client 20.104.18.253:47751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/404.php"] [unique_id "amuL0eT5hFAbD-LhWHiRGgAAAMU"]
[Thu Jul 30 12:37:21.588040 2026] [security2:error] [pid 765155:tid 765396] [client 94.20.26.237:56440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuL0eT5hFAbD-LhWHiRDwAAAPQ"], referer: http://pkf.jo
[Thu Jul 30 12:37:21.991566 2026] [core:notice] [pid 765155:tid 765161] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:22.133083 2026] [security2:error] [pid 765155:tid 765341] [client 20.63.98.115:60255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/bak.php"] [unique_id "amuL0uT5hFAbD-LhWHiRJgAAAL0"]
[Thu Jul 30 12:37:22.516474 2026] [security2:error] [pid 765155:tid 765344] [client 20.104.18.253:53757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/aa.php"] [unique_id "amuL0uT5hFAbD-LhWHiRRwAAAMA"]
[Thu Jul 30 12:37:22.742161 2026] [security2:error] [pid 765155:tid 765368] [client 146.103.115.7:55994] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuL0eT5hFAbD-LhWHiRDQAAANg"], referer: http://smoke-tfhk.com/xmlrpc.php
[Thu Jul 30 12:37:23.232921 2026] [security2:error] [pid 765155:tid 765320] [client 20.63.98.115:60262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/config.php"] [unique_id "amuL0-T5hFAbD-LhWHiRVQAAAKg"]
[Thu Jul 30 12:37:23.646575 2026] [core:notice] [pid 765155:tid 765384] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:24.057423 2026] [core:notice] [pid 765155:tid 765347] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:24.061336 2026] [security2:error] [pid 765155:tid 765347] [client 103.215.74.26:63946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL1OT5hFAbD-LhWHiRaAAAAMM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:24.282627 2026] [security2:error] [pid 765155:tid 765331] [client 172.236.9.101:19924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiRLQAAALM"]
[Thu Jul 30 12:37:24.284053 2026] [security2:error] [pid 765155:tid 765304] [client 172.236.9.101:34203] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiRLAAAAJg"]
[Thu Jul 30 12:37:24.310590 2026] [security2:error] [pid 765155:tid 765401] [client 172.236.9.101:5534] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiRMAAAAPk"]
[Thu Jul 30 12:37:24.350030 2026] [security2:error] [pid 765155:tid 765364] [client 172.236.9.101:32227] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiRLgAAANQ"]
[Thu Jul 30 12:37:24.353910 2026] [security2:error] [pid 765155:tid 765357] [client 172.236.9.101:21792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiRMwAAAM0"]
[Thu Jul 30 12:37:24.356405 2026] [security2:error] [pid 765155:tid 765352] [client 172.236.9.101:25625] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiRMgAAAMg"]
[Thu Jul 30 12:37:24.364129 2026] [security2:error] [pid 765155:tid 765367] [client 172.236.9.101:20001] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiROgAAANc"]
[Thu Jul 30 12:37:24.364490 2026] [security2:error] [pid 765155:tid 765369] [client 172.236.9.101:45788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiRNgAAANk"]
[Thu Jul 30 12:37:24.371891 2026] [security2:error] [pid 765155:tid 765334] [client 172.236.9.101:59019] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiROAAAALY"]
[Thu Jul 30 12:37:24.376076 2026] [security2:error] [pid 765155:tid 765327] [client 172.236.9.101:18277] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiRPgAAAK8"]
[Thu Jul 30 12:37:24.376882 2026] [security2:error] [pid 765155:tid 765366] [client 172.236.9.101:22227] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiRKwAAANY"]
[Thu Jul 30 12:37:24.407607 2026] [security2:error] [pid 765155:tid 765290] [client 172.236.9.101:5733] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiROwAAAIo"]
[Thu Jul 30 12:37:24.429868 2026] [security2:error] [pid 765155:tid 765288] [client 172.236.9.101:30082] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiRPAAAAIg"]
[Thu Jul 30 12:37:24.437229 2026] [security2:error] [pid 765155:tid 765339] [client 172.236.9.101:27034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiRLwAAALs"]
[Thu Jul 30 12:37:24.440022 2026] [security2:error] [pid 765155:tid 765387] [client 172.213.232.128:53581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/bootstrap.php"] [unique_id "amuL1OT5hFAbD-LhWHiRcQAAAOs"]
[Thu Jul 30 12:37:24.443637 2026] [security2:error] [pid 765155:tid 765298] [client 172.236.9.101:30494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiRQAAAAJI"]
[Thu Jul 30 12:37:24.452277 2026] [security2:error] [pid 765155:tid 765310] [client 172.236.9.101:60060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiRKgAAAJ4"]
[Thu Jul 30 12:37:24.472955 2026] [security2:error] [pid 765155:tid 765388] [client 172.236.9.101:26753] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiRPwAAAOw"]
[Thu Jul 30 12:37:24.500829 2026] [security2:error] [pid 765155:tid 765294] [client 172.236.9.101:14127] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiRNwAAAI4"]
[Thu Jul 30 12:37:24.504854 2026] [security2:error] [pid 765155:tid 765396] [client 20.63.98.115:21127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/uploads/2025/03/themes.php"] [unique_id "amuL1OT5hFAbD-LhWHiRdQAAAPQ"]
[Thu Jul 30 12:37:24.583567 2026] [security2:error] [pid 765155:tid 765360] [client 172.236.9.101:39444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiRMQAAANA"]
[Thu Jul 30 12:37:24.634014 2026] [security2:error] [pid 765155:tid 765350] [client 172.236.9.101:28917] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiRPQAAAMY"]
[Thu Jul 30 12:37:24.811096 2026] [core:notice] [pid 765155:tid 765383] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:24.815125 2026] [security2:error] [pid 765155:tid 765383] [client 103.215.74.26:63960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "757"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL1OT5hFAbD-LhWHiRfgAAAOc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:25.285862 2026] [security2:error] [pid 765155:tid 765351] [client 172.213.232.128:58884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/buy.php"] [unique_id "amuL1eT5hFAbD-LhWHiRiwAAAMc"]
[Thu Jul 30 12:37:25.529691 2026] [security2:error] [pid 765155:tid 765365] [client 57.141.0.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuL1eT5hFAbD-LhWHiRjwAAANU"]
[Thu Jul 30 12:37:25.543855 2026] [security2:error] [pid 765155:tid 765361] [client 20.63.98.115:49128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-activate.php"] [unique_id "amuL1eT5hFAbD-LhWHiRlAAAANE"]
[Thu Jul 30 12:37:25.574193 2026] [core:notice] [pid 765155:tid 765325] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:25.580344 2026] [security2:error] [pid 765155:tid 765325] [client 103.215.74.26:63968] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL1eT5hFAbD-LhWHiRlwAAAK0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:25.785819 2026] [security2:error] [pid 765155:tid 765408] [client 20.104.18.253:57239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/aafewc0k.php"] [unique_id "amuL1eT5hFAbD-LhWHiRnQAAAQA"]
[Thu Jul 30 12:37:25.932087 2026] [core:notice] [pid 765155:tid 765328] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:26.189861 2026] [security2:error] [pid 765155:tid 765411] [client 172.213.232.128:59200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/chosen.php"] [unique_id "amuL1uT5hFAbD-LhWHiRrAAAAQM"]
[Thu Jul 30 12:37:26.300643 2026] [security2:error] [pid 765155:tid 765352] [client 50.6.43.217:40460] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "smoke-tfhk.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuL1eT5hFAbD-LhWHiRkwAAAMg"]
[Thu Jul 30 12:37:26.311743 2026] [core:notice] [pid 765155:tid 765355] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:26.316862 2026] [security2:error] [pid 765155:tid 765320] [client 146.103.115.7:56470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "smoke-tfhk.com"] [uri "/wp-admin/post-new.php"] [unique_id "amuL1OT5hFAbD-LhWHiRfAAAAKg"], referer: http://smoke-tfhk.com/my-account/?action=register&xoo_el_reg_email=gb_roxanneculbert9581%40falderewonek.site&xoo_el_reg_fname=Ada&xoo_el_reg_lname=Goodson&xoo_el_reg_pass=rRyQ1bxn2mm0uk-&xoo_el_reg_pass_again=rRyQ1bxn2mm0uk-&xoo_el_reg_terms=yes&_xoo_el_form=register&xoo_el_redirect=%2Fmy-account%2F%3Faction%3Dregister
[Thu Jul 30 12:37:26.317719 2026] [security2:error] [pid 765155:tid 765355] [client 103.215.74.26:63972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "770"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL1uT5hFAbD-LhWHiRtQAAAMs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:26.646469 2026] [security2:error] [pid 765155:tid 765402] [client 20.104.18.253:25979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/abcd.php"] [unique_id "amuL1uT5hFAbD-LhWHiRwAAAAPo"]
[Thu Jul 30 12:37:26.771393 2026] [security2:error] [pid 765155:tid 765291] [client 20.63.98.115:47356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-file.php"] [unique_id "amuL1uT5hFAbD-LhWHiRxQAAAIs"]
[Thu Jul 30 12:37:26.818541 2026] [core:notice] [pid 765155:tid 765379] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:27.444276 2026] [security2:error] [pid 765155:tid 765401] [client 20.104.18.253:47763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/about.php"] [unique_id "amuL1-T5hFAbD-LhWHiR1gAAAPk"]
[Thu Jul 30 12:37:27.450001 2026] [security2:error] [pid 765155:tid 765254] [remote 216.73.216.152:36902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuL1-T5hFAbD-LhWHiR1wAAzGI"]
[Thu Jul 30 12:37:28.022021 2026] [security2:error] [pid 765155:tid 765387] [client 38.190.144.4:52124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuL2OT5hFAbD-LhWHiR5AAAAOs"]
[Thu Jul 30 12:37:28.022263 2026] [security2:error] [pid 765155:tid 765387] [client 38.190.144.4:52124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuL2OT5hFAbD-LhWHiR5AAAAOs"]
[Thu Jul 30 12:37:28.392820 2026] [security2:error] [pid 765155:tid 765352] [client 57.141.0.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuL2OT5hFAbD-LhWHiR8gAAAMg"]
[Thu Jul 30 12:37:28.747227 2026] [security2:error] [pid 765155:tid 765373] [client 20.63.98.115:21038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/12.php"] [unique_id "amuL2OT5hFAbD-LhWHiSAAAAAN0"]
[Thu Jul 30 12:37:28.848286 2026] [security2:error] [pid 765155:tid 765368] [client 20.104.18.253:26254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/admin.php"] [unique_id "amuL2OT5hFAbD-LhWHiSBAAAANg"]
[Thu Jul 30 12:37:28.980050 2026] [core:notice] [pid 765155:tid 765383] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:29.348921 2026] [security2:error] [pid 765155:tid 765351] [client 172.213.232.128:62145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/class-wp-image.php"] [unique_id "amuL2eT5hFAbD-LhWHiSHwAAAMc"]
[Thu Jul 30 12:37:29.675185 2026] [security2:error] [pid 765155:tid 765339] [client 20.104.18.253:25960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/adminfuns.php"] [unique_id "amuL2eT5hFAbD-LhWHiSJwAAALs"]
[Thu Jul 30 12:37:30.063173 2026] [security2:error] [pid 765155:tid 765386] [client 20.63.98.115:20797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/epinyins.php"] [unique_id "amuL2uT5hFAbD-LhWHiSMgAAAOo"]
[Thu Jul 30 12:37:30.452183 2026] [security2:error] [pid 765155:tid 765330] [client 172.213.232.128:62168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/classsmtps.php"] [unique_id "amuL2uT5hFAbD-LhWHiSRgAAALI"]
[Thu Jul 30 12:37:30.512900 2026] [security2:error] [pid 765155:tid 765337] [client 150.107.232.194:27049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuL2uT5hFAbD-LhWHiSRwAAALk"]
[Thu Jul 30 12:37:30.513093 2026] [security2:error] [pid 765155:tid 765337] [client 150.107.232.194:27049] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuL2uT5hFAbD-LhWHiSRwAAALk"]
[Thu Jul 30 12:37:30.915175 2026] [security2:error] [pid 765155:tid 765287] [client 41.100.124.239:40364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuL2uT5hFAbD-LhWHiSSQAAAIc"], referer: http://pkf.jo
[Thu Jul 30 12:37:31.271110 2026] [security2:error] [pid 765155:tid 765382] [client 20.63.98.115:20737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "amuL2-T5hFAbD-LhWHiSWgAAAOY"]
[Thu Jul 30 12:37:31.603270 2026] [security2:error] [pid 765155:tid 765325] [client 95.95.51.42:33338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuL2-T5hFAbD-LhWHiSXgAAAK0"], referer: http://pkf.jo
[Thu Jul 30 12:37:32.075529 2026] [core:notice] [pid 765155:tid 765374] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:32.079503 2026] [security2:error] [pid 765155:tid 765374] [client 103.215.74.26:63988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL3OT5hFAbD-LhWHiSgQAAAN4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:32.356429 2026] [security2:error] [pid 765155:tid 765360] [client 172.213.232.128:62185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/classwithtostring.php"] [unique_id "amuL3OT5hFAbD-LhWHiSiwAAANA"]
[Thu Jul 30 12:37:32.458269 2026] [core:notice] [pid 765155:tid 765215] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:32.790348 2026] [security2:error] [pid 765155:tid 765391] [client 57.141.0.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuL3OT5hFAbD-LhWHiShAAAAO8"]
[Thu Jul 30 12:37:32.808623 2026] [core:notice] [pid 765155:tid 765223] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:32.828957 2026] [core:notice] [pid 765155:tid 765402] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:32.832971 2026] [security2:error] [pid 765155:tid 765402] [client 103.215.74.26:63998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL3OT5hFAbD-LhWHiSmQAAAPo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:32.849622 2026] [security2:error] [pid 765155:tid 765399] [client 20.104.18.253:37448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/albin.php"] [unique_id "amuL3OT5hFAbD-LhWHiSmgAAAPc"]
[Thu Jul 30 12:37:33.070929 2026] [security2:error] [pid 765155:tid 765292] [client 188.245.61.191:36032] ModSecurity: Access denied with code 406 (phase 1). Match of "rx (^/administrator/)" against "REQUEST_URI" required. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "63"] [id "331216"] [rev "2"] [msg "Atomicorp.com WAF Rules: Wordpress DOS Attack Dropped"] [severity "CRITICAL"] [hostname "jesus.claims"] [uri "/wp-load.php"] [unique_id "amuL3eT5hFAbD-LhWHiSngAAAIw"]
[Thu Jul 30 12:37:33.461019 2026] [security2:error] [pid 765155:tid 765357] [client 20.63.98.115:21269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/system_log.php"] [unique_id "amuL3eT5hFAbD-LhWHiSqwAAAM0"]
[Thu Jul 30 12:37:33.565732 2026] [core:notice] [pid 765155:tid 765293] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:33.569767 2026] [security2:error] [pid 765155:tid 765293] [client 103.215.74.26:50212] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL3eT5hFAbD-LhWHiSrAAAAI0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:34.334851 2026] [core:notice] [pid 765155:tid 765307] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:34.337190 2026] [security2:error] [pid 765155:tid 765409] [client 20.104.18.253:29059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/amfsqvgv.php"] [unique_id "amuL3uT5hFAbD-LhWHiSvQAAAQE"]
[Thu Jul 30 12:37:34.339339 2026] [security2:error] [pid 765155:tid 765307] [client 103.215.74.26:50224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL3uT5hFAbD-LhWHiSvAAAAJs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:35.010498 2026] [core:notice] [pid 765155:tid 765372] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:35.092599 2026] [core:notice] [pid 765155:tid 765324] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:35.096432 2026] [security2:error] [pid 765155:tid 765324] [client 103.215.74.26:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "738"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL3-T5hFAbD-LhWHiS0gAAAKw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:35.230905 2026] [security2:error] [pid 765155:tid 765304] [client 135.119.63.61:45824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/011i.php"] [unique_id "amuL3-T5hFAbD-LhWHiS1gAAAJg"]
[Thu Jul 30 12:37:35.273850 2026] [core:notice] [pid 765155:tid 765341] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:35.393924 2026] [core:notice] [pid 765155:tid 765398] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:35.540021 2026] [security2:error] [pid 765155:tid 765362] [client 20.104.18.253:46819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/ant.php"] [unique_id "amuL3-T5hFAbD-LhWHiS4QAAANI"]
[Thu Jul 30 12:37:35.704442 2026] [security2:error] [pid 765155:tid 765318] [client 20.63.98.115:49256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuL3-T5hFAbD-LhWHiS5gAAAKY"]
[Thu Jul 30 12:37:35.824805 2026] [core:notice] [pid 765155:tid 765397] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:35.828790 2026] [security2:error] [pid 765155:tid 765397] [client 103.215.74.26:50238] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "738"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL3-T5hFAbD-LhWHiS5wAAAPU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:35.910818 2026] [security2:error] [pid 765155:tid 765388] [client 172.236.9.101:9392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL3-T5hFAbD-LhWHiS2gAAAOw"]
[Thu Jul 30 12:37:36.151271 2026] [security2:error] [pid 765155:tid 765291] [client 172.213.232.128:53626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/config.php"] [unique_id "amuL4OT5hFAbD-LhWHiS8wAAAIs"]
[Thu Jul 30 12:37:36.302759 2026] [security2:error] [pid 765155:tid 765300] [client 135.119.63.61:46187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/03a005685d.php"] [unique_id "amuL4OT5hFAbD-LhWHiS-wAAAJQ"]
[Thu Jul 30 12:37:36.368210 2026] [security2:error] [pid 765155:tid 765337] [client 172.236.9.101:8153] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.ssh/id_rsa"] [unique_id "amuL4OT5hFAbD-LhWHiS_gAAALk"]
[Thu Jul 30 12:37:36.374359 2026] [security2:error] [pid 765155:tid 765289] [client 172.236.9.101:22365] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/id_dsa"] [unique_id "amuL4OT5hFAbD-LhWHiS_wAAAIk"]
[Thu Jul 30 12:37:36.381491 2026] [security2:error] [pid 765155:tid 765409] [client 172.236.9.101:47921] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/id_rsa"] [unique_id "amuL4OT5hFAbD-LhWHiTAQAAAQE"]
[Thu Jul 30 12:37:36.402513 2026] [security2:error] [pid 765155:tid 765336] [client 172.236.9.101:62274] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/key.pem"] [unique_id "amuL4OT5hFAbD-LhWHiTBgAAALg"]
[Thu Jul 30 12:37:36.430213 2026] [security2:error] [pid 765155:tid 765373] [client 172.236.9.101:55459] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/privatekey.key"] [unique_id "amuL4OT5hFAbD-LhWHiTCgAAAN0"]
[Thu Jul 30 12:37:36.430618 2026] [security2:error] [pid 765155:tid 765345] [client 172.236.9.101:25304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.ssh/id_dsa"] [unique_id "amuL4OT5hFAbD-LhWHiTDgAAAME"]
[Thu Jul 30 12:37:36.900371 2026] [core:notice] [pid 765155:tid 765342] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:36.966574 2026] [security2:error] [pid 765155:tid 765365] [client 20.63.98.115:21143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/ini.php"] [unique_id "amuL4OT5hFAbD-LhWHiTIwAAANU"]
[Thu Jul 30 12:37:37.357388 2026] [security2:error] [pid 765155:tid 765395] [client 172.236.9.101:24103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL4OT5hFAbD-LhWHiS_AAAAPM"]
[Thu Jul 30 12:37:37.435690 2026] [security2:error] [pid 765155:tid 765307] [client 172.236.9.101:46174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL4OT5hFAbD-LhWHiTAAAAAJs"]
[Thu Jul 30 12:37:37.437075 2026] [security2:error] [pid 765155:tid 765370] [client 172.236.9.101:26404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL4OT5hFAbD-LhWHiS_QAAANo"]
[Thu Jul 30 12:37:37.450138 2026] [security2:error] [pid 765155:tid 765400] [client 172.236.9.101:30139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL4OT5hFAbD-LhWHiTAgAAAPg"]
[Thu Jul 30 12:37:37.451075 2026] [security2:error] [pid 765155:tid 765385] [client 172.236.9.101:37071] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL4OT5hFAbD-LhWHiTAwAAAOk"]
[Thu Jul 30 12:37:37.474161 2026] [security2:error] [pid 765155:tid 765338] [client 172.236.9.101:61949] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL4OT5hFAbD-LhWHiTCAAAALo"]
[Thu Jul 30 12:37:37.475744 2026] [security2:error] [pid 765155:tid 765349] [client 172.236.9.101:2043] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL4OT5hFAbD-LhWHiTBAAAAMU"]
[Thu Jul 30 12:37:37.488780 2026] [security2:error] [pid 765155:tid 765323] [client 172.236.9.101:41458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL4OT5hFAbD-LhWHiTBQAAAKs"]
[Thu Jul 30 12:37:37.505209 2026] [security2:error] [pid 765155:tid 765403] [client 172.236.9.101:50684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL4OT5hFAbD-LhWHiTDQAAAPs"]
[Thu Jul 30 12:37:37.508572 2026] [security2:error] [pid 765155:tid 765346] [client 172.236.9.101:34476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL4OT5hFAbD-LhWHiTCQAAAMI"]
[Thu Jul 30 12:37:37.520901 2026] [security2:error] [pid 765155:tid 765392] [client 172.236.9.101:59718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL4OT5hFAbD-LhWHiTDAAAAPA"]
[Thu Jul 30 12:37:37.521485 2026] [security2:error] [pid 765155:tid 765312] [client 172.236.9.101:1720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL4OT5hFAbD-LhWHiTBwAAAKA"]
[Thu Jul 30 12:37:37.525604 2026] [security2:error] [pid 765155:tid 765313] [client 172.236.9.101:4831] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL4OT5hFAbD-LhWHiTCwAAAKE"]
[Thu Jul 30 12:37:37.530580 2026] [security2:error] [pid 765155:tid 765298] [client 57.141.0.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuL4OT5hFAbD-LhWHiTIgAAAJI"]
[Thu Jul 30 12:37:37.579792 2026] [security2:error] [pid 765155:tid 765290] [client 135.119.63.61:46100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/403.php"] [unique_id "amuL4eT5hFAbD-LhWHiTNAAAAIo"]
[Thu Jul 30 12:37:37.731289 2026] [security2:error] [pid 765155:tid 765288] [client 185.24.61.123:29108] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuL4eT5hFAbD-LhWHiTLQAAAIg"], referer: http://pkf.jo
[Thu Jul 30 12:37:37.869324 2026] [security2:error] [pid 765155:tid 765410] [client 172.213.232.128:58466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/core.php"] [unique_id "amuL4eT5hFAbD-LhWHiTPwAAAQI"]
[Thu Jul 30 12:37:38.317342 2026] [security2:error] [pid 765155:tid 765319] [client 57.141.0.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuL4eT5hFAbD-LhWHiTPgAAAKc"]
[Thu Jul 30 12:37:38.667204 2026] [security2:error] [pid 765155:tid 765353] [client 20.63.98.115:21034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/ok.php"] [unique_id "amuL4uT5hFAbD-LhWHiTUwAAAMk"]
[Thu Jul 30 12:37:38.741292 2026] [core:error] [pid 765155:tid 765321] [client 74.7.230.55:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:37:38.741336 2026] [core:error] [pid 765155:tid 765321] [client 74.7.230.55:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:37:38.741486 2026] [security2:error] [pid 765155:tid 765321] [client 74.7.230.55:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.ldk.nyx.temporary.site"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amuL4uT5hFAbD-LhWHiTVgAAAKk"]
[Thu Jul 30 12:37:38.742137 2026] [security2:error] [pid 765155:tid 765292] [client 74.7.230.55:46720] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.ldk.nyx.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuL4uT5hFAbD-LhWHiTVAAAjGs"]
[Thu Jul 30 12:37:38.753503 2026] [security2:error] [pid 765155:tid 765381] [client 135.119.63.61:46172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/404.php"] [unique_id "amuL4uT5hFAbD-LhWHiTVwAAAOU"]
[Thu Jul 30 12:37:39.038837 2026] [security2:error] [pid 765155:tid 765272] [remote 57.141.0.68:41954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuL4-T5hFAbD-LhWHiTYgAA83Q"]
[Thu Jul 30 12:37:39.254326 2026] [core:notice] [pid 765155:tid 765311] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:39.585370 2026] [security2:error] [pid 765155:tid 765380] [client 20.63.98.115:49229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/includes/about.php"] [unique_id "amuL4-T5hFAbD-LhWHiTdwAAAOQ"]
[Thu Jul 30 12:37:39.725875 2026] [core:notice] [pid 765155:tid 765377] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:39.726480 2026] [security2:error] [pid 765155:tid 765322] [client 135.119.63.61:46121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/aa.php"] [unique_id "amuL4-T5hFAbD-LhWHiTfgAAAKo"]
[Thu Jul 30 12:37:39.950832 2026] [core:notice] [pid 765155:tid 765360] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:40.063461 2026] [core:notice] [pid 765155:tid 765162] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:40.434881 2026] [security2:error] [pid 765155:tid 765400] [client 172.213.232.128:58717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/css.php"] [unique_id "amuL5OT5hFAbD-LhWHiTkwAAAPg"]
[Thu Jul 30 12:37:40.988783 2026] [security2:error] [pid 765155:tid 765362] [client 150.107.232.194:27385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuL5OT5hFAbD-LhWHiToAAAANI"]
[Thu Jul 30 12:37:40.988896 2026] [security2:error] [pid 765155:tid 765362] [client 150.107.232.194:27385] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuL5OT5hFAbD-LhWHiToAAAANI"]
[Thu Jul 30 12:37:41.335573 2026] [security2:error] [pid 765155:tid 765319] [client 135.119.63.61:45844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/aafewc0k.php"] [unique_id "amuL5eT5hFAbD-LhWHiTrAAAAKc"]
[Thu Jul 30 12:37:41.360746 2026] [security2:error] [pid 765155:tid 765287] [client 20.104.18.253:30643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/appreciators.php"] [unique_id "amuL5eT5hFAbD-LhWHiTrQAAAIc"]
[Thu Jul 30 12:37:41.551714 2026] [security2:error] [pid 765155:tid 765408] [client 172.213.232.128:53578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/database.php"] [unique_id "amuL5eT5hFAbD-LhWHiTsQAAAQA"]
[Thu Jul 30 12:37:41.574561 2026] [core:notice] [pid 765155:tid 765313] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:41.579912 2026] [security2:error] [pid 765155:tid 765313] [client 103.215.74.26:50260] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL5eT5hFAbD-LhWHiTsgAAAKE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:42.127001 2026] [security2:error] [pid 765155:tid 765405] [client 135.119.63.61:45851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/abcd.php"] [unique_id "amuL5uT5hFAbD-LhWHiTvAAAAP0"]
[Thu Jul 30 12:37:42.300515 2026] [core:notice] [pid 765155:tid 765393] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:42.304541 2026] [security2:error] [pid 765155:tid 765393] [client 103.215.74.26:50284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL5uT5hFAbD-LhWHiTwAAAAPE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:42.625287 2026] [core:error] [pid 765155:tid 765363] [client 20.63.98.115:49097] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:37:42.625313 2026] [core:error] [pid 765155:tid 765363] [client 20.63.98.115:49097] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:37:42.752077 2026] [security2:error] [pid 765155:tid 765303] [client 20.104.18.253:53341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/archive.php"] [unique_id "amuL5uT5hFAbD-LhWHiTywAAAJc"]
[Thu Jul 30 12:37:43.100698 2026] [security2:error] [pid 765155:tid 765411] [client 135.119.63.61:46133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/about.php"] [unique_id "amuL5-T5hFAbD-LhWHiT2gAAAQM"]
[Thu Jul 30 12:37:43.550320 2026] [security2:error] [pid 765155:tid 765400] [client 185.191.171.13:19926] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/03/21/nova-sala-de-reuniao-da-camara-de-pirpirituba-tera-o-nome-do-ex-vereador-argemiro-moura/"] [unique_id "amuL5-T5hFAbD-LhWHiT4wAAAPg"]
[Thu Jul 30 12:37:43.550442 2026] [security2:error] [pid 765155:tid 765400] [client 185.191.171.13:19926] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/03/21/nova-sala-de-reuniao-da-camara-de-pirpirituba-tera-o-nome-do-ex-vereador-argemiro-moura/"] [unique_id "amuL5-T5hFAbD-LhWHiT4wAAAPg"]
[Thu Jul 30 12:37:43.716704 2026] [security2:error] [pid 765155:tid 765348] [client 172.213.232.128:53697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/db.php"] [unique_id "amuL5-T5hFAbD-LhWHiT5QAAAMQ"]
[Thu Jul 30 12:37:43.777885 2026] [security2:error] [pid 765155:tid 765339] [client 20.104.18.253:34692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/as.php"] [unique_id "amuL5-T5hFAbD-LhWHiT5gAAALs"]
[Thu Jul 30 12:37:43.973421 2026] [security2:error] [pid 765155:tid 765305] [client 135.119.63.61:45830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/admin.php"] [unique_id "amuL5-T5hFAbD-LhWHiT7QAAAJk"]
[Thu Jul 30 12:37:45.297412 2026] [security2:error] [pid 765155:tid 765398] [client 20.63.98.115:62686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-configs.php"] [unique_id "amuL6eT5hFAbD-LhWHiUBwAAAPY"]
[Thu Jul 30 12:37:45.496252 2026] [security2:error] [pid 765155:tid 765368] [client 20.104.18.253:46843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/atomlib.php"] [unique_id "amuL6eT5hFAbD-LhWHiUCwAAANg"]
[Thu Jul 30 12:37:45.947691 2026] [security2:error] [pid 765155:tid 765323] [client 172.213.232.128:62342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/default.php"] [unique_id "amuL6eT5hFAbD-LhWHiUEwAAAKs"]
[Thu Jul 30 12:37:45.961833 2026] [security2:error] [pid 765155:tid 765291] [client 3.149.57.90:56214] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuL6OT5hFAbD-LhWHiT-wAAAIs"], referer: https://globalmarks.pk/
[Thu Jul 30 12:37:45.994604 2026] [security2:error] [pid 765155:tid 765324] [client 216.73.216.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.thesounddepot.com"] [uri "/index.php"] [unique_id "amuL5-T5hFAbD-LhWHiT1wAAAKw"]
[Thu Jul 30 12:37:46.019852 2026] [security2:error] [pid 765155:tid 765356] [client 135.119.63.61:46130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/adminfuns.php"] [unique_id "amuL6uT5hFAbD-LhWHiUFwAAAMw"]
[Thu Jul 30 12:37:46.649568 2026] [security2:error] [pid 765155:tid 765349] [client 20.104.18.253:34710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/autoload_classmap.php"] [unique_id "amuL6uT5hFAbD-LhWHiUJgAAAMU"]
[Thu Jul 30 12:37:48.030954 2026] [core:notice] [pid 765155:tid 765398] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:48.037963 2026] [security2:error] [pid 765155:tid 765398] [client 103.215.74.26:6532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL7OT5hFAbD-LhWHiUQgAAAPY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:48.124739 2026] [security2:error] [pid 765155:tid 765383] [client 172.213.232.128:53860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/dropdown.php"] [unique_id "amuL7OT5hFAbD-LhWHiURgAAAOc"]
[Thu Jul 30 12:37:48.138961 2026] [security2:error] [pid 765155:tid 765405] [client 20.104.18.253:39448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/bb.php"] [unique_id "amuL7OT5hFAbD-LhWHiUSAAAAP0"]
[Thu Jul 30 12:37:48.759918 2026] [core:notice] [pid 765155:tid 765324] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:48.764431 2026] [security2:error] [pid 765155:tid 765324] [client 103.215.74.26:6546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL7OT5hFAbD-LhWHiUVwAAAKw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:49.206874 2026] [core:notice] [pid 765155:tid 765312] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:49.282094 2026] [core:notice] [pid 765155:tid 765318] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:49.344665 2026] [security2:error] [pid 765155:tid 765319] [client 135.119.63.61:46082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/albin.php"] [unique_id "amuL7eT5hFAbD-LhWHiUbwAAAKc"]
[Thu Jul 30 12:37:49.384421 2026] [security2:error] [pid 765155:tid 765329] [client 20.63.98.115:65339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/01.php"] [unique_id "amuL7eT5hFAbD-LhWHiUcAAAALE"]
[Thu Jul 30 12:37:49.527091 2026] [core:notice] [pid 765155:tid 765386] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:49.531568 2026] [security2:error] [pid 765155:tid 765386] [client 103.215.74.26:6562] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL7eT5hFAbD-LhWHiUcQAAAOo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:49.660131 2026] [proxy:error] [pid 765155:tid 765375] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:37:49.660182 2026] [proxy_http:error] [pid 765155:tid 765375] [client 3.225.222.228:30352] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:37:49.660739 2026] [proxy:error] [pid 765155:tid 765375] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:37:49.660784 2026] [proxy_http:error] [pid 765155:tid 765375] [client 3.225.222.228:30352] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:37:49.671694 2026] [proxy:error] [pid 765155:tid 765358] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:37:49.671765 2026] [proxy_http:error] [pid 765155:tid 765358] [client 44.213.206.96:52745] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:37:49.672627 2026] [proxy:error] [pid 765155:tid 765358] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:37:49.672687 2026] [proxy_http:error] [pid 765155:tid 765358] [client 44.213.206.96:52745] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:37:50.171673 2026] [security2:error] [pid 765155:tid 765395] [client 20.104.18.253:43330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/bnm.php"] [unique_id "amuL7uT5hFAbD-LhWHiUiwAAAPM"]
[Thu Jul 30 12:37:50.279137 2026] [core:notice] [pid 765155:tid 765316] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:50.283509 2026] [security2:error] [pid 765155:tid 765316] [client 103.215.74.26:6572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL7uT5hFAbD-LhWHiUkQAAAKQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:50.773697 2026] [security2:error] [pid 765155:tid 765390] [client 135.119.63.61:46178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/amfsqvgv.php"] [unique_id "amuL7uT5hFAbD-LhWHiUmAAAAO4"]
[Thu Jul 30 12:37:50.879636 2026] [security2:error] [pid 765155:tid 765343] [client 172.213.232.128:53625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/edit.php"] [unique_id "amuL7uT5hFAbD-LhWHiUnAAAAL8"]
[Thu Jul 30 12:37:51.048763 2026] [core:notice] [pid 765155:tid 765321] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:51.053485 2026] [security2:error] [pid 765155:tid 765321] [client 103.215.74.26:6578] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL7-T5hFAbD-LhWHiUoQAAAKk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:51.268636 2026] [security2:error] [pid 765155:tid 765346] [client 74.7.230.57:37776] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.tgr.fiyan.co"] [uri "/cgi-sys/404.html"] [unique_id "amuL7-T5hFAbD-LhWHiUqAAAwms"]
[Thu Jul 30 12:37:51.288659 2026] [security2:error] [pid 765155:tid 765370] [client 20.104.18.253:39484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/bootstrap.php"] [unique_id "amuL7-T5hFAbD-LhWHiUrAAAANo"]
[Thu Jul 30 12:37:51.460172 2026] [security2:error] [pid 765155:tid 765314] [client 119.73.97.132:29563] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuL7-T5hFAbD-LhWHiUogAAomk"]
[Thu Jul 30 12:37:51.514278 2026] [security2:error] [pid 765155:tid 765302] [client 150.107.232.194:26621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuL7-T5hFAbD-LhWHiUuAAAAJY"]
[Thu Jul 30 12:37:51.514438 2026] [security2:error] [pid 765155:tid 765302] [client 150.107.232.194:26621] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuL7-T5hFAbD-LhWHiUuAAAAJY"]
[Thu Jul 30 12:37:51.547192 2026] [security2:error] [pid 765155:tid 765314] [client 119.73.97.132:29563] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuL7-T5hFAbD-LhWHiUpAAAogo"]
[Thu Jul 30 12:37:51.734025 2026] [security2:error] [pid 765155:tid 765300] [client 20.63.98.115:38872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "amuL7-T5hFAbD-LhWHiUuQAAAJQ"]
[Thu Jul 30 12:37:51.758042 2026] [security2:error] [pid 765155:tid 765306] [client 135.119.63.61:46153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/ant.php"] [unique_id "amuL7-T5hFAbD-LhWHiUugAAAJo"]
[Thu Jul 30 12:37:51.809671 2026] [core:notice] [pid 765155:tid 765288] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:51.817165 2026] [security2:error] [pid 765155:tid 765288] [client 103.215.74.26:6584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL7-T5hFAbD-LhWHiUvgAAAIg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:51.902713 2026] [security2:error] [pid 765155:tid 765318] [client 57.141.0.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuL7-T5hFAbD-LhWHiUqwAAAKY"]
[Thu Jul 30 12:37:52.214960 2026] [security2:error] [pid 765155:tid 765336] [client 20.104.18.253:29764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/buy.php"] [unique_id "amuL8OT5hFAbD-LhWHiUyQAAALg"]
[Thu Jul 30 12:37:52.542143 2026] [core:notice] [pid 765155:tid 765323] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:52.546624 2026] [security2:error] [pid 765155:tid 765323] [client 103.215.74.26:6596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL8OT5hFAbD-LhWHiU1gAAAKs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:52.614104 2026] [security2:error] [pid 765155:tid 765291] [client 135.119.63.61:46203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/appreciators.php"] [unique_id "amuL8OT5hFAbD-LhWHiU1wAAAIs"]
[Thu Jul 30 12:37:53.064907 2026] [security2:error] [pid 765155:tid 765330] [client 119.73.97.132:29563] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuL8OT5hFAbD-LhWHiU0QAAsng"], referer: https://www.urwru.club/emm-elevate/?preview_id=685&preview_nonce=6cdd8f071f&preview=true&aaeid=1
[Thu Jul 30 12:37:53.113629 2026] [security2:error] [pid 765155:tid 765315] [client 20.63.98.115:62708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/css/colors/midnight/colors.php"] [unique_id "amuL8eT5hFAbD-LhWHiU4wAAAKM"]
[Thu Jul 30 12:37:53.276744 2026] [core:notice] [pid 765155:tid 765312] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:53.283896 2026] [security2:error] [pid 765155:tid 765312] [client 103.215.74.26:56954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "738"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL8eT5hFAbD-LhWHiU5QAAAKA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:53.815921 2026] [security2:error] [pid 765155:tid 765344] [client 20.104.18.253:53874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/chosen.php"] [unique_id "amuL8eT5hFAbD-LhWHiU9AAAAMA"]
[Thu Jul 30 12:37:54.023526 2026] [core:notice] [pid 765155:tid 765288] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:54.028046 2026] [security2:error] [pid 765155:tid 765288] [client 103.215.74.26:56956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "740"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL8uT5hFAbD-LhWHiU-wAAAIg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:54.330849 2026] [security2:error] [pid 765155:tid 765306] [client 20.63.98.115:65321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "amuL8uT5hFAbD-LhWHiVAQAAAJo"]
[Thu Jul 30 12:37:54.688698 2026] [security2:error] [pid 765155:tid 765342] [client 172.213.232.128:53705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/f35.php"] [unique_id "amuL8uT5hFAbD-LhWHiVDAAAAL4"]
[Thu Jul 30 12:37:54.748678 2026] [core:notice] [pid 765155:tid 765309] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:54.752471 2026] [security2:error] [pid 765155:tid 765309] [client 103.215.74.26:56972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "737"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL8uT5hFAbD-LhWHiVDwAAAJ0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:54.824129 2026] [security2:error] [pid 765155:tid 765364] [client 20.104.18.253:25736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/class-wp-image.php"] [unique_id "amuL8uT5hFAbD-LhWHiVEQAAANQ"]
[Thu Jul 30 12:37:55.160255 2026] [security2:error] [pid 765155:tid 765325] [client 135.119.63.61:46186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/archive.php"] [unique_id "amuL8-T5hFAbD-LhWHiVGwAAAK0"]
[Thu Jul 30 12:37:55.340655 2026] [security2:error] [pid 765155:tid 765299] [client 57.141.0.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuL8uT5hFAbD-LhWHiVEAAAAJM"]
[Thu Jul 30 12:37:55.489249 2026] [core:notice] [pid 765155:tid 765301] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:55.493381 2026] [security2:error] [pid 765155:tid 765301] [client 103.215.74.26:56980] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL8-T5hFAbD-LhWHiVIAAAAJU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:55.641892 2026] [proxy:error] [pid 765155:tid 765346] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:37:55.641958 2026] [proxy_http:error] [pid 765155:tid 765346] [client 3.228.112.215:55466] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:37:55.642526 2026] [proxy:error] [pid 765155:tid 765346] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:37:55.642569 2026] [proxy_http:error] [pid 765155:tid 765346] [client 3.228.112.215:55466] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:37:55.676110 2026] [proxy:error] [pid 765155:tid 765406] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:37:55.676191 2026] [proxy_http:error] [pid 765155:tid 765406] [client 3.228.112.215:42151] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:37:55.677021 2026] [proxy:error] [pid 765155:tid 765406] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:37:55.677075 2026] [proxy_http:error] [pid 765155:tid 765406] [client 3.228.112.215:42151] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:37:55.954815 2026] [security2:error] [pid 765155:tid 765302] [client 135.119.63.61:45843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/as.php"] [unique_id "amuL8-T5hFAbD-LhWHiVMAAAAJY"]
[Thu Jul 30 12:37:55.989372 2026] [security2:error] [pid 765155:tid 765358] [client 20.104.18.253:39469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/classsmtps.php"] [unique_id "amuL8-T5hFAbD-LhWHiVNAAAAM4"]
[Thu Jul 30 12:37:56.053052 2026] [security2:error] [pid 765155:tid 765400] [client 172.213.232.128:58459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/f7.php"] [unique_id "amuL9OT5hFAbD-LhWHiVOAAAAPg"]
[Thu Jul 30 12:37:56.228286 2026] [core:notice] [pid 765155:tid 765359] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:56.235224 2026] [security2:error] [pid 765155:tid 765359] [client 103.215.74.26:56994] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL9OT5hFAbD-LhWHiVPAAAAM8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:56.293918 2026] [security2:error] [pid 765155:tid 765303] [client 20.63.98.115:43992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/db.php"] [unique_id "amuL9OT5hFAbD-LhWHiVPQAAAJc"]
[Thu Jul 30 12:37:56.955024 2026] [security2:error] [pid 765155:tid 765352] [client 38.190.144.4:53154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuL9OT5hFAbD-LhWHiVTwAAAMg"]
[Thu Jul 30 12:37:56.955157 2026] [security2:error] [pid 765155:tid 765352] [client 38.190.144.4:53154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuL9OT5hFAbD-LhWHiVTwAAAMg"]
[Thu Jul 30 12:37:56.962150 2026] [core:notice] [pid 765155:tid 765317] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:56.968897 2026] [security2:error] [pid 765155:tid 765317] [client 103.215.74.26:57002] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL9OT5hFAbD-LhWHiVUAAAAKU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:56.977869 2026] [security2:error] [pid 765155:tid 765348] [client 57.141.0.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuL9OT5hFAbD-LhWHiVQQAAAMQ"]
[Thu Jul 30 12:37:57.019638 2026] [security2:error] [pid 765155:tid 765351] [client 135.119.63.61:46107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/atomlib.php"] [unique_id "amuL9eT5hFAbD-LhWHiVUgAAAMc"]
[Thu Jul 30 12:37:57.172733 2026] [security2:error] [pid 765155:tid 765394] [client 20.104.18.253:53836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/classwithtostring.php"] [unique_id "amuL9eT5hFAbD-LhWHiVWgAAAPI"]
[Thu Jul 30 12:37:57.708517 2026] [core:notice] [pid 765155:tid 765386] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:57.712498 2026] [security2:error] [pid 765155:tid 765386] [client 103.215.74.26:57008] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "738"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL9eT5hFAbD-LhWHiVZwAAAOo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:58.013073 2026] [security2:error] [pid 765155:tid 765398] [client 62.102.148.158:55040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuL9uT5hFAbD-LhWHiVcQAAAPY"]
[Thu Jul 30 12:37:58.013168 2026] [security2:error] [pid 765155:tid 765398] [client 62.102.148.158:55040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuL9uT5hFAbD-LhWHiVcQAAAPY"]
[Thu Jul 30 12:37:58.095782 2026] [core:notice] [pid 765155:tid 765212] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:58.175434 2026] [security2:error] [pid 765155:tid 765406] [client 20.104.18.253:53331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/config.php"] [unique_id "amuL9uT5hFAbD-LhWHiVdwAAAP4"]
[Thu Jul 30 12:37:58.425427 2026] [core:notice] [pid 765155:tid 765379] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:58.429360 2026] [security2:error] [pid 765155:tid 765379] [client 103.215.74.26:57012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "756"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL9uT5hFAbD-LhWHiVfwAAAOM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:58.634894 2026] [security2:error] [pid 765155:tid 765334] [client 195.63.22.178:33340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "deltaedu.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuL9uT5hFAbD-LhWHiVgwAAtkc"], referer: https://deltaedu.net/wp-admin/admin-ajax.php?action=tnp&na=s
[Thu Jul 30 12:37:58.727940 2026] [core:notice] [pid 765155:tid 765208] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:58.768150 2026] [security2:error] [pid 765155:tid 765404] [client 2a03:2880:f800:27:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuL9uT5hFAbD-LhWHiVdgAA_Ds"]
[Thu Jul 30 12:37:59.175545 2026] [core:notice] [pid 765155:tid 765331] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:59.186125 2026] [security2:error] [pid 765155:tid 765331] [client 103.215.74.26:57014] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL9-T5hFAbD-LhWHiVmQAAALM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:59.443365 2026] [security2:error] [pid 765155:tid 765362] [client 20.104.18.253:45219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/core.php"] [unique_id "amuL9-T5hFAbD-LhWHiVnQAAANI"]
[Thu Jul 30 12:37:59.560676 2026] [security2:error] [pid 765155:tid 765324] [client 20.63.98.115:39197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/pages.php"] [unique_id "amuL9-T5hFAbD-LhWHiVoQAAAKw"]
[Thu Jul 30 12:37:59.604400 2026] [core:notice] [pid 765155:tid 765312] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:59.933890 2026] [core:notice] [pid 765155:tid 765388] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:59.937847 2026] [security2:error] [pid 765155:tid 765388] [client 103.215.74.26:57024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "769"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL9-T5hFAbD-LhWHiVrAAAAOw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:00.180494 2026] [core:notice] [pid 765155:tid 765384] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:00.620239 2026] [security2:error] [pid 765155:tid 765339] [client 20.104.18.253:25698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/css.php"] [unique_id "amuL-OT5hFAbD-LhWHiVxwAAALs"]
[Thu Jul 30 12:38:00.725987 2026] [fcgid:warn] [pid 765155:tid 765316] (70014)End of file found: [client 156.229.16.165:46654] mod_fcgid: can't get data from http client
[Thu Jul 30 12:38:01.107585 2026] [security2:error] [pid 765155:tid 765372] [client 194.187.251.163:46446] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuL-eT5hFAbD-LhWHiV0QAAANw"]
[Thu Jul 30 12:38:01.107694 2026] [security2:error] [pid 765155:tid 765372] [client 194.187.251.163:46446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuL-eT5hFAbD-LhWHiV0QAAANw"]
[Thu Jul 30 12:38:01.125956 2026] [security2:error] [pid 765155:tid 765404] [client 20.63.98.115:38867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/admin.php"] [unique_id "amuL-eT5hFAbD-LhWHiV1AAAAPw"]
[Thu Jul 30 12:38:01.362113 2026] [security2:error] [pid 765155:tid 765363] [client 2a03:2880:f800:1e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuL-OT5hFAbD-LhWHiVzAAA0ww"]
[Thu Jul 30 12:38:01.716160 2026] [security2:error] [pid 765155:tid 765343] [client 66.249.73.98:51485] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuL-eT5hFAbD-LhWHiV4gAAAL8"]
[Thu Jul 30 12:38:01.905955 2026] [security2:error] [pid 765155:tid 765292] [client 194.187.251.163:46458] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuL-eT5hFAbD-LhWHiV9wAAAIw"]
[Thu Jul 30 12:38:01.906072 2026] [security2:error] [pid 765155:tid 765292] [client 194.187.251.163:46458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuL-eT5hFAbD-LhWHiV9wAAAIw"]
[Thu Jul 30 12:38:01.965660 2026] [security2:error] [pid 765155:tid 765360] [client 150.107.232.194:26745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuL-eT5hFAbD-LhWHiV-gAAANA"]
[Thu Jul 30 12:38:01.965823 2026] [security2:error] [pid 765155:tid 765360] [client 150.107.232.194:26745] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuL-eT5hFAbD-LhWHiV-gAAANA"]
[Thu Jul 30 12:38:02.007127 2026] [security2:error] [pid 765155:tid 765327] [client 20.63.98.115:53830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-load.php"] [unique_id "amuL-uT5hFAbD-LhWHiV_QAAAK8"]
[Thu Jul 30 12:38:02.105721 2026] [security2:error] [pid 765155:tid 765401] [client 20.104.18.253:33638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/database.php"] [unique_id "amuL-uT5hFAbD-LhWHiV_gAAAPk"]
[Thu Jul 30 12:38:02.354402 2026] [security2:error] [pid 765155:tid 765336] [client 85.208.96.193:31656] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kendarikomputer.com"] [uri "/2022/02/download-bios-lenovo-thinkpad-t430"] [unique_id "amuL-uT5hFAbD-LhWHiWCwAAALg"]
[Thu Jul 30 12:38:02.354544 2026] [security2:error] [pid 765155:tid 765336] [client 85.208.96.193:31656] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.kendarikomputer.com"] [uri "/2022/02/download-bios-lenovo-thinkpad-t430"] [unique_id "amuL-uT5hFAbD-LhWHiWCwAAALg"]
[Thu Jul 30 12:38:02.473338 2026] [autoindex:error] [pid 765155:tid 765320] [client 64.69.216.78:50864] AH01276: Cannot serve directory /home2/lgggplte/brianhpark.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:38:02.568145 2026] [security2:error] [pid 765155:tid 765295] [client 20.215.191.139:11385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/geju.php"] [unique_id "amuL-uT5hFAbD-LhWHiWEQAAAI8"]
[Thu Jul 30 12:38:02.952836 2026] [security2:error] [pid 765155:tid 765316] [client 57.141.0.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuL-uT5hFAbD-LhWHiWDAAAAKQ"]
[Thu Jul 30 12:38:03.298657 2026] [security2:error] [pid 765155:tid 765369] [client 2a03:2880:f800:26:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuL-uT5hFAbD-LhWHiWEwAA2XA"]
[Thu Jul 30 12:38:03.301909 2026] [fcgid:warn] [pid 765155:tid 765393] (70014)End of file found: [client 104.28.219.195:40327] mod_fcgid: can't get data from http client
[Thu Jul 30 12:38:03.310460 2026] [fcgid:warn] [pid 765155:tid 765292] (70014)End of file found: [client 104.28.219.195:40328] mod_fcgid: can't get data from http client
[Thu Jul 30 12:38:03.376257 2026] [security2:error] [pid 765155:tid 765291] [client 20.63.98.115:38878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/as/function.php"] [unique_id "amuL--T5hFAbD-LhWHiWMAAAAIs"]
[Thu Jul 30 12:38:03.434665 2026] [security2:error] [pid 765155:tid 765357] [client 20.215.191.139:2354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/plugins/about.php"] [unique_id "amuL--T5hFAbD-LhWHiWNAAAAM0"]
[Thu Jul 30 12:38:03.458113 2026] [security2:error] [pid 765155:tid 765349] [client 20.104.18.253:33652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/db.php"] [unique_id "amuL--T5hFAbD-LhWHiWNQAAAMU"]
[Thu Jul 30 12:38:03.555116 2026] [security2:error] [pid 765155:tid 765329] [client 104.28.219.195:40336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.219.28.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abs-sa.net"] [uri "/index.php"] [unique_id "amuL--T5hFAbD-LhWHiWKgAAALE"]
[Thu Jul 30 12:38:03.555264 2026] [security2:error] [pid 765155:tid 765329] [client 104.28.219.195:40336] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "mail.abs-sa.net"] [uri "/index.php"] [unique_id "amuL--T5hFAbD-LhWHiWKgAAALE"]
[Thu Jul 30 12:38:04.128148 2026] [autoindex:error] [pid 765155:tid 765320] [client 64.69.216.78:50972] AH01276: Cannot serve directory /home2/lgggplte/brianhpark.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:38:04.130442 2026] [security2:error] [pid 765155:tid 765336] [client 20.215.191.139:6981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp.php"] [unique_id "amuL_OT5hFAbD-LhWHiWRwAAALg"]
[Thu Jul 30 12:38:04.312135 2026] [security2:error] [pid 765155:tid 765321] [client 20.63.98.115:43279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/filter.php"] [unique_id "amuL_OT5hFAbD-LhWHiWSwAAAKk"]
[Thu Jul 30 12:38:04.502423 2026] [fcgid:warn] [pid 765155:tid 765384] (70014)End of file found: [client 104.28.219.195:40339] mod_fcgid: can't get data from http client
[Thu Jul 30 12:38:04.791211 2026] [security2:error] [pid 765155:tid 765333] [client 135.119.63.61:45831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/autoload_classmap.php"] [unique_id "amuL_OT5hFAbD-LhWHiWVwAAALU"]
[Thu Jul 30 12:38:04.813720 2026] [security2:error] [pid 765155:tid 765317] [client 20.104.18.253:50505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/default.php"] [unique_id "amuL_OT5hFAbD-LhWHiWWAAAAKU"]
[Thu Jul 30 12:38:05.154844 2026] [security2:error] [pid 765155:tid 765311] [client 20.215.191.139:2341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/aaa.php"] [unique_id "amuL_eT5hFAbD-LhWHiWYgAAAJ8"]
[Thu Jul 30 12:38:05.169475 2026] [core:notice] [pid 765155:tid 765281] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:05.548832 2026] [security2:error] [pid 765155:tid 765164] [remote 74.7.241.60:58830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/article.php"] [unique_id "amuL_eT5hFAbD-LhWHiWdAAAxgg"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/1784117929_IMG_3676.jpg
[Thu Jul 30 12:38:05.664403 2026] [core:notice] [pid 765155:tid 765323] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:05.668515 2026] [security2:error] [pid 765155:tid 765323] [client 103.215.74.26:17734] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "741"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL_eT5hFAbD-LhWHiWdQAAAKs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:05.870109 2026] [security2:error] [pid 765155:tid 765357] [client 2a03:2880:f800:22:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuL_eT5hFAbD-LhWHiWZwAAzW8"]
[Thu Jul 30 12:38:06.009335 2026] [security2:error] [pid 765155:tid 765406] [client 62.102.148.158:55822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuL_uT5hFAbD-LhWHiWfQAAAP4"]
[Thu Jul 30 12:38:06.009481 2026] [security2:error] [pid 765155:tid 765406] [client 62.102.148.158:55822] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuL_uT5hFAbD-LhWHiWfQAAAP4"]
[Thu Jul 30 12:38:06.239092 2026] [security2:error] [pid 765155:tid 765302] [client 135.119.63.61:45835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/bb.php"] [unique_id "amuL_uT5hFAbD-LhWHiWggAAAJY"]
[Thu Jul 30 12:38:06.387943 2026] [core:notice] [pid 765155:tid 765412] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:06.392230 2026] [security2:error] [pid 765155:tid 765412] [client 103.215.74.26:17738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "745"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL_uT5hFAbD-LhWHiWhgAAAQQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:06.408388 2026] [proxy:error] [pid 765155:tid 765169] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:38:06.408444 2026] [proxy_http:error] [pid 765155:tid 765169] [remote 143.244.47.86:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:38:06.409053 2026] [proxy:error] [pid 765155:tid 765169] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:38:06.409102 2026] [proxy_http:error] [pid 765155:tid 765169] [remote 143.244.47.86:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:38:06.713714 2026] [security2:error] [pid 765155:tid 765343] [client 20.63.98.115:43305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/he.php"] [unique_id "amuL_uT5hFAbD-LhWHiWkAAAAL8"]
[Thu Jul 30 12:38:07.166425 2026] [security2:error] [pid 765155:tid 765324] [client 135.119.63.61:46087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/bnm.php"] [unique_id "amuL_-T5hFAbD-LhWHiWmgAAAKw"]
[Thu Jul 30 12:38:07.188377 2026] [core:notice] [pid 765155:tid 765394] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:07.192384 2026] [security2:error] [pid 765155:tid 765394] [client 103.215.74.26:17744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL_-T5hFAbD-LhWHiWmwAAAPI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:07.336923 2026] [core:notice] [pid 765155:tid 765291] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:07.588924 2026] [proxy:error] [pid 765155:tid 765162] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:38:07.589009 2026] [proxy_http:error] [pid 765155:tid 765162] [remote 143.244.47.86:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:38:07.589597 2026] [proxy:error] [pid 765155:tid 765162] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:38:07.589639 2026] [proxy_http:error] [pid 765155:tid 765162] [remote 143.244.47.86:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:38:07.857286 2026] [core:notice] [pid 765155:tid 765382] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:07.926032 2026] [core:notice] [pid 765155:tid 765364] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:07.930397 2026] [security2:error] [pid 765155:tid 765364] [client 103.215.74.26:17754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL_-T5hFAbD-LhWHiWqwAAANQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:07.964148 2026] [core:notice] [pid 765155:tid 765201] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:07.991255 2026] [security2:error] [pid 765155:tid 765346] [client 38.190.144.4:53657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuL_-T5hFAbD-LhWHiWrQAAAMI"]
[Thu Jul 30 12:38:07.991558 2026] [security2:error] [pid 765155:tid 765346] [client 38.190.144.4:53657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuL_-T5hFAbD-LhWHiWrQAAAMI"]
[Thu Jul 30 12:38:08.124386 2026] [core:notice] [pid 765155:tid 765158] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:08.672864 2026] [core:notice] [pid 765155:tid 765348] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:08.676608 2026] [security2:error] [pid 765155:tid 765348] [client 103.215.74.26:17760] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "740"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMAOT5hFAbD-LhWHiWvwAAAMQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:08.972810 2026] [security2:error] [pid 765155:tid 765354] [client 20.104.18.253:52258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/dropdown.php"] [unique_id "amuMAOT5hFAbD-LhWHiWxAAAAMo"]
[Thu Jul 30 12:38:09.409918 2026] [core:notice] [pid 765155:tid 765365] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:09.415958 2026] [security2:error] [pid 765155:tid 765365] [client 103.215.74.26:17764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "740"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMAeT5hFAbD-LhWHiW0QAAANU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:09.473971 2026] [core:notice] [pid 765155:tid 765327] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:09.513008 2026] [security2:error] [pid 765155:tid 765405] [client 135.119.63.61:46182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/bootstrap.php"] [unique_id "amuMAeT5hFAbD-LhWHiW0wAAAP0"]
[Thu Jul 30 12:38:10.008928 2026] [security2:error] [pid 765155:tid 765332] [client 49.0.84.125:59688] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.248"] [uri "/"] [unique_id "amuMAuT5hFAbD-LhWHiW3wAAALQ"]
[Thu Jul 30 12:38:10.172320 2026] [core:notice] [pid 765155:tid 765356] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:10.177666 2026] [security2:error] [pid 765155:tid 765356] [client 103.215.74.26:17772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMAuT5hFAbD-LhWHiW4wAAAMw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:10.245298 2026] [security2:error] [pid 765155:tid 765323] [client 49.0.84.125:45498] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.248"] [uri "/"] [unique_id "amuMAuT5hFAbD-LhWHiW5wAAAKs"]
[Thu Jul 30 12:38:10.301444 2026] [security2:error] [pid 765155:tid 765386] [client 20.104.18.253:26431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/edit.php"] [unique_id "amuMAuT5hFAbD-LhWHiW6wAAAOo"]
[Thu Jul 30 12:38:10.359429 2026] [security2:error] [pid 765155:tid 765311] [client 20.215.191.139:2339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/hoot.php"] [unique_id "amuMAuT5hFAbD-LhWHiW7AAAAJ8"]
[Thu Jul 30 12:38:10.579889 2026] [security2:error] [pid 765155:tid 765361] [client 44.209.187.99:13134] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "radiojelli.com"] [uri "/img/articles/68/famous-men-classified-by-myers-briggs-type-4.jpg"] [unique_id "amuMAuT5hFAbD-LhWHiW7QAAANE"]
[Thu Jul 30 12:38:10.694385 2026] [security2:error] [pid 765155:tid 765364] [client 135.119.63.61:46166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/buy.php"] [unique_id "amuMAuT5hFAbD-LhWHiW7gAAANQ"]
[Thu Jul 30 12:38:10.833382 2026] [security2:error] [pid 765155:tid 765212] [remote 57.141.0.58:44002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amuMAuT5hFAbD-LhWHiW-AAAljg"]
[Thu Jul 30 12:38:10.897272 2026] [core:notice] [pid 765155:tid 765352] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:10.901581 2026] [security2:error] [pid 765155:tid 765352] [client 103.215.74.26:17786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMAuT5hFAbD-LhWHiW-QAAAMg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:11.018476 2026] [security2:error] [pid 765155:tid 765408] [client 20.215.191.139:2589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/about.php"] [unique_id "amuMA-T5hFAbD-LhWHiW-gAAAQA"]
[Thu Jul 30 12:38:11.195737 2026] [security2:error] [pid 765155:tid 765390] [client 20.104.18.253:26425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/f35.php"] [unique_id "amuMA-T5hFAbD-LhWHiW-wAAAO4"]
[Thu Jul 30 12:38:11.361710 2026] [core:notice] [pid 765155:tid 765388] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:11.942908 2026] [security2:error] [pid 765155:tid 765163] [remote 97.74.87.194:43744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gkc.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuMA-T5hFAbD-LhWHiXFAAA1Qc"]
[Thu Jul 30 12:38:12.103996 2026] [security2:error] [pid 765155:tid 765289] [client 20.104.18.253:52254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/f7.php"] [unique_id "amuMBOT5hFAbD-LhWHiXFQAAAIk"]
[Thu Jul 30 12:38:12.113816 2026] [security2:error] [pid 765155:tid 765292] [client 20.63.98.115:53832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/setup-config.php"] [unique_id "amuMBOT5hFAbD-LhWHiXFgAAAIw"]
[Thu Jul 30 12:38:12.380540 2026] [security2:error] [pid 765155:tid 765294] [client 20.215.191.139:2338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/admin.php"] [unique_id "amuMBOT5hFAbD-LhWHiXHQAAAI4"]
[Thu Jul 30 12:38:12.443878 2026] [security2:error] [pid 765155:tid 765399] [client 150.107.232.194:27448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMBOT5hFAbD-LhWHiXIQAAAPc"]
[Thu Jul 30 12:38:12.443995 2026] [security2:error] [pid 765155:tid 765399] [client 150.107.232.194:27448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMBOT5hFAbD-LhWHiXIQAAAPc"]
[Thu Jul 30 12:38:12.500801 2026] [core:notice] [pid 765155:tid 765346] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:13.215719 2026] [security2:error] [pid 765155:tid 765354] [client 20.215.191.139:7005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "amuMBeT5hFAbD-LhWHiXNwAAAMo"]
[Thu Jul 30 12:38:13.227925 2026] [security2:error] [pid 765155:tid 765340] [client 20.63.98.115:53873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/languages/wp-login.php"] [unique_id "amuMBeT5hFAbD-LhWHiXOAAAALw"]
[Thu Jul 30 12:38:13.653806 2026] [core:notice] [pid 765155:tid 765219] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:13.925611 2026] [security2:error] [pid 765155:tid 765369] [client 172.236.9.101:1063] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMBeT5hFAbD-LhWHiXQgAAANk"]
[Thu Jul 30 12:38:14.004131 2026] [security2:error] [pid 765155:tid 765319] [client 172.236.9.101:8727] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMBeT5hFAbD-LhWHiXQQAAAKc"]
[Thu Jul 30 12:38:14.904812 2026] [core:notice] [pid 765155:tid 765374] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:14.919021 2026] [security2:error] [pid 765155:tid 765301] [client 172.236.9.101:52948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMBuT5hFAbD-LhWHiXSwAAAJU"]
[Thu Jul 30 12:38:14.943598 2026] [fcgid:warn] [pid 765155:tid 765308] (70014)End of file found: [client 118.193.58.125:54906] mod_fcgid: can't get data from http client
[Thu Jul 30 12:38:15.585710 2026] [security2:error] [pid 765155:tid 765358] [client 20.63.98.115:43322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/autoload_classmap.php"] [unique_id "amuMB-T5hFAbD-LhWHiXaAAAAM4"]
[Thu Jul 30 12:38:15.916052 2026] [security2:error] [pid 765155:tid 765349] [client 172.236.9.101:28740] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMB-T5hFAbD-LhWHiXYQAAAMU"]
[Thu Jul 30 12:38:15.941127 2026] [security2:error] [pid 765155:tid 765403] [client 172.236.9.101:7296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMB-T5hFAbD-LhWHiXZAAAAPs"]
[Thu Jul 30 12:38:15.983593 2026] [core:notice] [pid 765155:tid 765387] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:16.040258 2026] [security2:error] [pid 765155:tid 765331] [client 172.236.9.101:64687] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMB-T5hFAbD-LhWHiXZQAAALM"]
[Thu Jul 30 12:38:16.054658 2026] [security2:error] [pid 765155:tid 765384] [client 172.236.9.101:43380] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMB-T5hFAbD-LhWHiXYwAAAOg"]
[Thu Jul 30 12:38:16.061516 2026] [security2:error] [pid 765155:tid 765393] [client 172.236.9.101:4544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMB-T5hFAbD-LhWHiXZgAAAPE"]
[Thu Jul 30 12:38:16.218728 2026] [security2:error] [pid 765155:tid 765293] [client 135.119.63.61:46189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/chosen.php"] [unique_id "amuMCOT5hFAbD-LhWHiXewAAAI0"]
[Thu Jul 30 12:38:16.242146 2026] [security2:error] [pid 765155:tid 765369] [client 20.215.191.139:8218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/db-cache.php"] [unique_id "amuMCOT5hFAbD-LhWHiXfAAAANk"]
[Thu Jul 30 12:38:16.664251 2026] [core:notice] [pid 765155:tid 765303] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:16.670542 2026] [security2:error] [pid 765155:tid 765303] [client 103.215.74.26:23710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMCOT5hFAbD-LhWHiXjwAAAJc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:16.896327 2026] [security2:error] [pid 765155:tid 765379] [client 20.215.191.139:2586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/themes/twentyeleven/functions.php"] [unique_id "amuMCOT5hFAbD-LhWHiXlAAAAOM"]
[Thu Jul 30 12:38:16.951588 2026] [security2:error] [pid 765155:tid 765356] [client 20.63.98.115:53833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/plugins/WordPressCore/include.php"] [unique_id "amuMCOT5hFAbD-LhWHiXlQAAAMw"]
[Thu Jul 30 12:38:17.225997 2026] [security2:error] [pid 765155:tid 765344] [client 172.236.9.101:52434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMCOT5hFAbD-LhWHiXfwAAAMA"]
[Thu Jul 30 12:38:17.293075 2026] [security2:error] [pid 765155:tid 765371] [client 172.236.9.101:64113] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMCOT5hFAbD-LhWHiXfgAAANs"]
[Thu Jul 30 12:38:17.307325 2026] [security2:error] [pid 765155:tid 765370] [client 172.236.9.101:3463] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMCOT5hFAbD-LhWHiXgAAAANo"]
[Thu Jul 30 12:38:17.307951 2026] [security2:error] [pid 765155:tid 765385] [client 172.236.9.101:28896] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMCOT5hFAbD-LhWHiXfQAAAOk"]
[Thu Jul 30 12:38:17.313282 2026] [security2:error] [pid 765155:tid 765342] [client 172.236.9.101:65386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMCOT5hFAbD-LhWHiXgQAAAL4"]
[Thu Jul 30 12:38:17.328907 2026] [security2:error] [pid 765155:tid 765306] [client 43.172.195.68:55566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.195.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/09/14/trouver-sa-tenue-de-sport/"] [unique_id "amuMCeT5hFAbD-LhWHiXmQAAAJo"]
[Thu Jul 30 12:38:17.402153 2026] [security2:error] [pid 765155:tid 765307] [client 172.236.9.101:1234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMCOT5hFAbD-LhWHiXgwAAAJs"]
[Thu Jul 30 12:38:17.411429 2026] [security2:error] [pid 765155:tid 765329] [client 172.236.9.101:58118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMCOT5hFAbD-LhWHiXggAAALE"]
[Thu Jul 30 12:38:17.413216 2026] [core:notice] [pid 765155:tid 765366] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:17.420415 2026] [security2:error] [pid 765155:tid 765366] [client 103.215.74.26:23722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMCeT5hFAbD-LhWHiXpgAAANY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:17.422110 2026] [security2:error] [pid 765155:tid 765391] [client 172.236.9.101:7996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMCOT5hFAbD-LhWHiXhAAAAO8"]
[Thu Jul 30 12:38:17.425960 2026] [security2:error] [pid 765155:tid 765337] [client 172.236.9.101:55263] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMCOT5hFAbD-LhWHiXhQAAALk"]
[Thu Jul 30 12:38:17.447721 2026] [security2:error] [pid 765155:tid 765397] [client 172.236.9.101:30818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMCOT5hFAbD-LhWHiXiQAAAPU"]
[Thu Jul 30 12:38:17.459404 2026] [security2:error] [pid 765155:tid 765322] [client 172.236.9.101:14307] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMCOT5hFAbD-LhWHiXiwAAAKo"]
[Thu Jul 30 12:38:17.465830 2026] [security2:error] [pid 765155:tid 765286] [client 172.236.9.101:62488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMCOT5hFAbD-LhWHiXigAAAIY"]
[Thu Jul 30 12:38:17.593766 2026] [security2:error] [pid 765155:tid 765350] [client 43.172.198.150:36984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.198.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/05/26/les-10-indispensables-de-la-semaine-9/"] [unique_id "amuMCeT5hFAbD-LhWHiXoAAAAMY"]
[Thu Jul 30 12:38:17.594696 2026] [security2:error] [pid 765155:tid 765305] [client 135.119.63.61:46145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/class-wp-image.php"] [unique_id "amuMCeT5hFAbD-LhWHiXqAAAAJk"]
[Thu Jul 30 12:38:17.756729 2026] [security2:error] [pid 765155:tid 765317] [client 20.215.191.139:10843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/themes/oceanwp/functions.php"] [unique_id "amuMCeT5hFAbD-LhWHiXrAAAAKU"]
[Thu Jul 30 12:38:17.966516 2026] [core:notice] [pid 765155:tid 765365] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:17.970949 2026] [security2:error] [pid 765155:tid 765365] [client 43.173.180.29:47270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/09/14/trouver-sa-tenue-de-sport/"] [unique_id "amuMCeT5hFAbD-LhWHiXtgAAANU"], referer: https://carnetdeshopping.com/index.php/2014/09/14/trouver-sa-tenue-de-sport/
[Thu Jul 30 12:38:18.137966 2026] [core:notice] [pid 765155:tid 765288] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:18.142359 2026] [security2:error] [pid 765155:tid 765288] [client 103.215.74.26:23726] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMCuT5hFAbD-LhWHiXuwAAAIg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:18.216732 2026] [core:notice] [pid 765155:tid 765303] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:18.220915 2026] [security2:error] [pid 765155:tid 765303] [client 43.173.178.89:47920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/05/26/les-10-indispensables-de-la-semaine-9/"] [unique_id "amuMCuT5hFAbD-LhWHiXvAAAAJc"], referer: https://carnetdeshopping.com/index.php/2013/05/26/les-10-indispensables-de-la-semaine-9/
[Thu Jul 30 12:38:18.612337 2026] [security2:error] [pid 765155:tid 765345] [client 135.119.63.61:46124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/classsmtps.php"] [unique_id "amuMCuT5hFAbD-LhWHiXxwAAAME"]
[Thu Jul 30 12:38:18.645811 2026] [security2:error] [pid 765155:tid 765383] [client 57.141.0.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMCuT5hFAbD-LhWHiXuQAAAOc"]
[Thu Jul 30 12:38:18.786406 2026] [core:notice] [pid 765155:tid 765304] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:18.859045 2026] [core:notice] [pid 765155:tid 765311] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:18.863505 2026] [security2:error] [pid 765155:tid 765311] [client 103.215.74.26:23742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMCuT5hFAbD-LhWHiXzgAAAJ8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:18.940077 2026] [security2:error] [pid 765155:tid 765356] [client 20.215.191.139:2597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/themes/twentythirteen/functions.php"] [unique_id "amuMCuT5hFAbD-LhWHiX0AAAAMw"]
[Thu Jul 30 12:38:19.248270 2026] [core:notice] [pid 765155:tid 765408] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:19.351316 2026] [core:notice] [pid 765155:tid 765381] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:19.516180 2026] [security2:error] [pid 765155:tid 765354] [client 20.215.191.139:2307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/themes/kadence/functions.php"] [unique_id "amuMC-T5hFAbD-LhWHiX3QAAAMo"]
[Thu Jul 30 12:38:19.600693 2026] [core:notice] [pid 765155:tid 765339] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:19.605666 2026] [security2:error] [pid 765155:tid 765339] [client 103.215.74.26:23750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMC-T5hFAbD-LhWHiX5AAAALs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:19.686805 2026] [core:notice] [pid 765155:tid 765252] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:19.747957 2026] [security2:error] [pid 765155:tid 765350] [client 135.119.63.61:46101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/classwithtostring.php"] [unique_id "amuMC-T5hFAbD-LhWHiX5wAAAMY"]
[Thu Jul 30 12:38:19.820883 2026] [core:notice] [pid 765155:tid 765393] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:19.926718 2026] [security2:error] [pid 765155:tid 765360] [client 74.7.241.181:46592] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amuMC-T5hFAbD-LhWHiX8gAA0G0"], referer: https://www.bedandbreakfast-skye.com/
[Thu Jul 30 12:38:19.995373 2026] [security2:error] [pid 765155:tid 765394] [client 20.63.98.115:57334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/atomlib.php"] [unique_id "amuMC-T5hFAbD-LhWHiX8wAAAPI"]
[Thu Jul 30 12:38:20.339086 2026] [core:notice] [pid 765155:tid 765336] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:20.343452 2026] [security2:error] [pid 765155:tid 765336] [client 103.215.74.26:23764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMDOT5hFAbD-LhWHiX_wAAALg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:20.498883 2026] [security2:error] [pid 765155:tid 765368] [client 57.141.0.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMC-T5hFAbD-LhWHiX8QAAANg"]
[Thu Jul 30 12:38:20.591619 2026] [security2:error] [pid 765155:tid 765345] [client 135.119.63.61:46175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/config.php"] [unique_id "amuMDOT5hFAbD-LhWHiYBAAAAME"]
[Thu Jul 30 12:38:20.674024 2026] [proxy:error] [pid 765155:tid 765311] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:38:20.674101 2026] [proxy_http:error] [pid 765155:tid 765311] [client 100.58.154.137:39366] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:38:20.674666 2026] [proxy:error] [pid 765155:tid 765311] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:38:20.674709 2026] [proxy_http:error] [pid 765155:tid 765311] [client 100.58.154.137:39366] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:38:20.702108 2026] [security2:error] [pid 765155:tid 765367] [client 2a03:2880:f800:1b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMDOT5hFAbD-LhWHiX9wAA12s"]
[Thu Jul 30 12:38:20.803184 2026] [security2:error] [pid 765155:tid 765404] [client 20.63.98.115:39163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "amuMDOT5hFAbD-LhWHiYCgAAAPw"]
[Thu Jul 30 12:38:21.065119 2026] [security2:error] [pid 765155:tid 765372] [client 74.7.241.181:46592] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amuMDeT5hFAbD-LhWHiYDgAA3Gk"], referer: https://www.bedandbreakfast-skye.com/
[Thu Jul 30 12:38:21.080932 2026] [core:notice] [pid 765155:tid 765366] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:21.085117 2026] [security2:error] [pid 765155:tid 765366] [client 103.215.74.26:23772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMDeT5hFAbD-LhWHiYDwAAANY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:21.102736 2026] [core:notice] [pid 765155:tid 765259] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:21.455476 2026] [core:notice] [pid 765155:tid 765309] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:21.524748 2026] [security2:error] [pid 765155:tid 765378] [client 20.215.191.139:11047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/themes/twentytwenty/functions.php"] [unique_id "amuMDeT5hFAbD-LhWHiYIAAAAOI"]
[Thu Jul 30 12:38:21.611068 2026] [security2:error] [pid 765155:tid 765349] [client 135.119.63.61:46151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/core.php"] [unique_id "amuMDeT5hFAbD-LhWHiYIQAAAMU"]
[Thu Jul 30 12:38:21.644945 2026] [security2:error] [pid 765155:tid 765331] [client 20.63.98.115:20953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/gebase.php"] [unique_id "amuMDeT5hFAbD-LhWHiYIgAAALM"]
[Thu Jul 30 12:38:21.812343 2026] [core:notice] [pid 765155:tid 765408] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:21.816521 2026] [security2:error] [pid 765155:tid 765408] [client 103.215.74.26:23776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "740"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMDeT5hFAbD-LhWHiYJgAAAQA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:21.896173 2026] [security2:error] [pid 765155:tid 765377] [client 2a03:2880:f800:28:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMDeT5hFAbD-LhWHiYFwAA4RY"]
[Thu Jul 30 12:38:21.926666 2026] [security2:error] [pid 765155:tid 765403] [client 172.236.9.101:11118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMDeT5hFAbD-LhWHiYHgAAAPs"]
[Thu Jul 30 12:38:21.936302 2026] [security2:error] [pid 765155:tid 765330] [client 172.236.9.101:56590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMDeT5hFAbD-LhWHiYGwAAALI"]
[Thu Jul 30 12:38:22.010289 2026] [security2:error] [pid 765155:tid 765339] [client 172.236.9.101:18838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMDeT5hFAbD-LhWHiYHQAAALs"]
[Thu Jul 30 12:38:22.034271 2026] [security2:error] [pid 765155:tid 765305] [client 172.236.9.101:44623] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMDeT5hFAbD-LhWHiYHAAAAJk"]
[Thu Jul 30 12:38:22.095268 2026] [security2:error] [pid 765155:tid 765271] [remote 47.128.96.185:58214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.96.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/Konstruksi/article/view/3842"] [unique_id "amuMDeT5hFAbD-LhWHiYJwAAoHM"]
[Thu Jul 30 12:38:22.165968 2026] [core:notice] [pid 765155:tid 765282] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:22.172070 2026] [security2:error] [pid 765155:tid 765364] [client 47.128.96.185:58214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Konstruksi/article/view/3842"] [unique_id "amuMDuT5hFAbD-LhWHiYNAAA1H4"], referer: https://www.ejournalugj.com/index.php/Konstruksi/article/view/3842?articlesBySameAuthorPage=1
[Thu Jul 30 12:38:22.250046 2026] [security2:error] [pid 765155:tid 765402] [client 74.7.244.23:60972] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amuMDuT5hFAbD-LhWHiYNQAA-m8"], referer: https://www.bedandbreakfast-skye.com/robots.txt
[Thu Jul 30 12:38:22.346648 2026] [security2:error] [pid 765155:tid 765406] [client 20.215.191.139:11388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/content.php"] [unique_id "amuMDuT5hFAbD-LhWHiYNgAAAP4"]
[Thu Jul 30 12:38:22.407682 2026] [core:notice] [pid 765155:tid 765172] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:22.514102 2026] [core:notice] [pid 765155:tid 765276] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:22.514258 2026] [core:notice] [pid 765155:tid 765165] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:22.547890 2026] [core:notice] [pid 765155:tid 765385] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:22.555437 2026] [security2:error] [pid 765155:tid 765385] [client 103.215.74.26:23780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMDuT5hFAbD-LhWHiYTgAAAOk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:22.688213 2026] [security2:error] [pid 765155:tid 765181] [remote 57.141.0.24:39342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amuMDuT5hFAbD-LhWHiYQwAAhRk"]
[Thu Jul 30 12:38:22.768241 2026] [core:notice] [pid 765155:tid 765159] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:22.773618 2026] [security2:error] [pid 765155:tid 765386] [client 135.119.63.61:46174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/css.php"] [unique_id "amuMDuT5hFAbD-LhWHiYUwAAAOo"]
[Thu Jul 30 12:38:22.963841 2026] [security2:error] [pid 765155:tid 765336] [client 172.236.9.101:12429] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMDuT5hFAbD-LhWHiYOAAAALg"]
[Thu Jul 30 12:38:22.983572 2026] [security2:error] [pid 765155:tid 765361] [client 172.236.9.101:65290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMDuT5hFAbD-LhWHiYNwAAANE"]
[Thu Jul 30 12:38:22.994393 2026] [security2:error] [pid 765155:tid 765294] [client 172.236.9.101:46285] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMDuT5hFAbD-LhWHiYOQAAAI4"]
[Thu Jul 30 12:38:23.003442 2026] [security2:error] [pid 765155:tid 765412] [client 172.236.9.101:37924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMDuT5hFAbD-LhWHiYOgAAAQQ"]
[Thu Jul 30 12:38:23.006690 2026] [autoindex:error] [pid 765155:tid 765286] [client 3.225.222.228:38543] AH01276: Cannot serve directory /home2/meggzjte/01.serverkr.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:38:23.025373 2026] [security2:error] [pid 765155:tid 765359] [client 172.236.9.101:3574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMDuT5hFAbD-LhWHiYOwAAAM8"]
[Thu Jul 30 12:38:23.098614 2026] [security2:error] [pid 765155:tid 765329] [client 57.141.0.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMDuT5hFAbD-LhWHiYSgAAALE"]
[Thu Jul 30 12:38:23.099844 2026] [security2:error] [pid 765155:tid 765362] [client 20.100.187.246:61703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/json.php"] [unique_id "amuMD-T5hFAbD-LhWHiYYgAAANI"]
[Thu Jul 30 12:38:23.281396 2026] [core:notice] [pid 765155:tid 765350] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:23.286194 2026] [security2:error] [pid 765155:tid 765350] [client 103.215.74.26:61964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMD-T5hFAbD-LhWHiYZgAAAMY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:23.293554 2026] [security2:error] [pid 765155:tid 765345] [client 172.236.9.101:63019] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMDuT5hFAbD-LhWHiYRAAAAME"]
[Thu Jul 30 12:38:23.294136 2026] [security2:error] [pid 765155:tid 765342] [client 172.236.9.101:58760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMDuT5hFAbD-LhWHiYPwAAAL4"]
[Thu Jul 30 12:38:23.296002 2026] [security2:error] [pid 765155:tid 765384] [client 172.236.9.101:26444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMDuT5hFAbD-LhWHiYPAAAAOg"]
[Thu Jul 30 12:38:23.296103 2026] [security2:error] [pid 765155:tid 765347] [client 150.107.232.194:27039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMD-T5hFAbD-LhWHiYZwAAAMM"]
[Thu Jul 30 12:38:23.296202 2026] [security2:error] [pid 765155:tid 765347] [client 150.107.232.194:27039] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMD-T5hFAbD-LhWHiYZwAAAMM"]
[Thu Jul 30 12:38:23.299126 2026] [security2:error] [pid 765155:tid 765370] [client 172.236.9.101:19810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMDuT5hFAbD-LhWHiYPQAAANo"]
[Thu Jul 30 12:38:23.312512 2026] [security2:error] [pid 765155:tid 765371] [client 172.236.9.101:11830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMDuT5hFAbD-LhWHiYRQAAANs"]
[Thu Jul 30 12:38:23.885440 2026] [security2:error] [pid 765155:tid 765346] [client 20.63.98.115:43319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/xl.php"] [unique_id "amuMD-T5hFAbD-LhWHiYdwAAAMI"]
[Thu Jul 30 12:38:23.965607 2026] [security2:error] [pid 765155:tid 765394] [client 172.236.9.101:63002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMD-T5hFAbD-LhWHiYaQAAAPI"]
[Thu Jul 30 12:38:23.966986 2026] [security2:error] [pid 765155:tid 765339] [client 172.236.9.101:14752] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMD-T5hFAbD-LhWHiYbQAAALs"]
[Thu Jul 30 12:38:23.967057 2026] [security2:error] [pid 765155:tid 765303] [client 172.236.9.101:1691] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMD-T5hFAbD-LhWHiYbAAAAJc"]
[Thu Jul 30 12:38:23.969954 2026] [security2:error] [pid 765155:tid 765315] [client 172.236.9.101:30226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMD-T5hFAbD-LhWHiYawAAAKM"]
[Thu Jul 30 12:38:23.975487 2026] [security2:error] [pid 765155:tid 765357] [client 172.236.9.101:54847] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMD-T5hFAbD-LhWHiYaAAAAM0"]
[Thu Jul 30 12:38:23.978412 2026] [security2:error] [pid 765155:tid 765288] [client 172.236.9.101:31882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMD-T5hFAbD-LhWHiYagAAAIg"]
[Thu Jul 30 12:38:24.009962 2026] [core:notice] [pid 765155:tid 765328] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:24.014852 2026] [security2:error] [pid 765155:tid 765328] [client 103.215.74.26:61968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMEOT5hFAbD-LhWHiYfwAAALA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:24.138456 2026] [security2:error] [pid 765155:tid 765374] [client 20.100.187.246:61173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/mini.php"] [unique_id "amuMEOT5hFAbD-LhWHiYgwAAAN4"]
[Thu Jul 30 12:38:24.622764 2026] [security2:error] [pid 765155:tid 765306] [client 20.215.191.139:11032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/plugins/not/includes/about.php"] [unique_id "amuMEOT5hFAbD-LhWHiYmwAAAJo"]
[Thu Jul 30 12:38:24.749019 2026] [security2:error] [pid 765155:tid 765404] [client 135.119.63.61:46149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/database.php"] [unique_id "amuMEOT5hFAbD-LhWHiYowAAAPw"]
[Thu Jul 30 12:38:24.749055 2026] [core:notice] [pid 765155:tid 765362] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:24.761062 2026] [security2:error] [pid 765155:tid 765362] [client 103.215.74.26:61974] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMEOT5hFAbD-LhWHiYogAAANI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:24.779573 2026] [security2:error] [pid 765155:tid 765377] [client 20.100.187.246:64369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/chosen.php"] [unique_id "amuMEOT5hFAbD-LhWHiYpAAAAOE"]
[Thu Jul 30 12:38:25.259694 2026] [security2:error] [pid 765155:tid 765332] [client 20.63.98.115:57341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/2.php"] [unique_id "amuMEeT5hFAbD-LhWHiYrAAAALQ"]
[Thu Jul 30 12:38:25.397148 2026] [security2:error] [pid 765155:tid 765389] [client 172.236.9.101:13946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEOT5hFAbD-LhWHiYjAAAAO0"]
[Thu Jul 30 12:38:25.397352 2026] [security2:error] [pid 765155:tid 765286] [client 172.236.9.101:20636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEOT5hFAbD-LhWHiYkQAAAIY"]
[Thu Jul 30 12:38:25.403667 2026] [security2:error] [pid 765155:tid 765291] [client 172.236.9.101:9912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEOT5hFAbD-LhWHiYiwAAAIs"]
[Thu Jul 30 12:38:25.403667 2026] [security2:error] [pid 765155:tid 765349] [client 172.236.9.101:26581] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEOT5hFAbD-LhWHiYigAAAMU"]
[Thu Jul 30 12:38:25.404476 2026] [security2:error] [pid 765155:tid 765387] [client 172.236.9.101:5247] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEOT5hFAbD-LhWHiYjgAAAOs"]
[Thu Jul 30 12:38:25.419747 2026] [security2:error] [pid 765155:tid 765294] [client 172.236.9.101:33376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEOT5hFAbD-LhWHiYjwAAAI4"]
[Thu Jul 30 12:38:25.428339 2026] [security2:error] [pid 765155:tid 765361] [client 172.236.9.101:46252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEOT5hFAbD-LhWHiYjQAAANE"]
[Thu Jul 30 12:38:25.450489 2026] [security2:error] [pid 765155:tid 765412] [client 172.236.9.101:14019] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEOT5hFAbD-LhWHiYkAAAAQQ"]
[Thu Jul 30 12:38:25.469472 2026] [security2:error] [pid 765155:tid 765359] [client 172.236.9.101:10462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEOT5hFAbD-LhWHiYkgAAAM8"]
[Thu Jul 30 12:38:25.472468 2026] [security2:error] [pid 765155:tid 765319] [client 172.236.9.101:3696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEOT5hFAbD-LhWHiYkwAAAKc"]
[Thu Jul 30 12:38:25.500168 2026] [core:notice] [pid 765155:tid 765406] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:25.511103 2026] [security2:error] [pid 765155:tid 765406] [client 103.215.74.26:61978] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMEeT5hFAbD-LhWHiYtwAAAP4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:25.535645 2026] [security2:error] [pid 765155:tid 765321] [client 172.236.9.101:40203] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEOT5hFAbD-LhWHiYlAAAAKk"]
[Thu Jul 30 12:38:25.556702 2026] [security2:error] [pid 765155:tid 765393] [client 172.236.9.101:29177] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEOT5hFAbD-LhWHiYlgAAAPE"]
[Thu Jul 30 12:38:25.558072 2026] [security2:error] [pid 765155:tid 765400] [client 172.236.9.101:5895] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEOT5hFAbD-LhWHiYlQAAAPg"]
[Thu Jul 30 12:38:25.579656 2026] [security2:error] [pid 765155:tid 765354] [client 172.236.9.101:9296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEOT5hFAbD-LhWHiYlwAAAMo"]
[Thu Jul 30 12:38:25.617150 2026] [security2:error] [pid 765155:tid 765394] [client 135.119.63.61:46152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/db.php"] [unique_id "amuMEeT5hFAbD-LhWHiYvAAAAPI"]
[Thu Jul 30 12:38:26.019213 2026] [security2:error] [pid 765155:tid 765310] [client 20.215.191.139:61242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/plugins/simple/simple.php"] [unique_id "amuMEuT5hFAbD-LhWHiYwwAAAJ4"]
[Thu Jul 30 12:38:26.266844 2026] [core:notice] [pid 765155:tid 765390] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:26.273791 2026] [security2:error] [pid 765155:tid 765390] [client 103.215.74.26:61994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "740"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMEuT5hFAbD-LhWHiYxwAAAO4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:26.285670 2026] [security2:error] [pid 765155:tid 765180] [remote 198.38.94.87:55236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.94.38.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp-login.php"] [unique_id "amuMEuT5hFAbD-LhWHiYyAAAkhg"]
[Thu Jul 30 12:38:26.341002 2026] [security2:error] [pid 765155:tid 765368] [client 172.236.9.101:2620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEeT5hFAbD-LhWHiYsgAAANg"]
[Thu Jul 30 12:38:26.350231 2026] [security2:error] [pid 765155:tid 765346] [client 172.236.9.101:20334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEeT5hFAbD-LhWHiYtgAAAMI"]
[Thu Jul 30 12:38:26.383360 2026] [security2:error] [pid 765155:tid 765383] [client 172.236.9.101:6946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEeT5hFAbD-LhWHiYsQAAAOc"]
[Thu Jul 30 12:38:26.385069 2026] [security2:error] [pid 765155:tid 765353] [client 172.236.9.101:44836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEeT5hFAbD-LhWHiYtQAAAMk"]
[Thu Jul 30 12:38:26.405029 2026] [security2:error] [pid 765155:tid 765398] [client 172.236.9.101:40397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEeT5hFAbD-LhWHiYswAAAPY"]
[Thu Jul 30 12:38:26.405659 2026] [security2:error] [pid 765155:tid 765295] [client 172.236.9.101:47776] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEeT5hFAbD-LhWHiYtAAAAI8"]
[Thu Jul 30 12:38:26.552323 2026] [security2:error] [pid 765155:tid 765362] [client 20.63.98.115:20983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/baxa1.php"] [unique_id "amuMEuT5hFAbD-LhWHiYzwAAANI"]
[Thu Jul 30 12:38:27.007223 2026] [core:notice] [pid 765155:tid 765349] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:27.011211 2026] [security2:error] [pid 765155:tid 765349] [client 103.215.74.26:62002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuME-T5hFAbD-LhWHiY4AAAAMU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:27.193511 2026] [security2:error] [pid 765155:tid 765208] [remote 37.59.204.153:45726] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "aded-rdc.org"] [uri "/no-sidebar-full-width/"] [unique_id "amuME-T5hFAbD-LhWHiY5AAAhTQ"]
[Thu Jul 30 12:38:27.193675 2026] [security2:error] [pid 765155:tid 765285] [client 37.59.204.153:45726] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "aded-rdc.org"] [uri "/no-sidebar-full-width/"] [unique_id "amuME-T5hFAbD-LhWHiY5AAAhTQ"]
[Thu Jul 30 12:38:27.431436 2026] [security2:error] [pid 765155:tid 765365] [client 135.119.63.61:46134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/default.php"] [unique_id "amuME-T5hFAbD-LhWHiY6wAAANU"]
[Thu Jul 30 12:38:27.743026 2026] [core:notice] [pid 765155:tid 765336] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:27.750358 2026] [security2:error] [pid 765155:tid 765336] [client 103.215.74.26:62014] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuME-T5hFAbD-LhWHiY7wAAALg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:27.784610 2026] [security2:error] [pid 765155:tid 765348] [client 20.63.98.115:57281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/settings.php"] [unique_id "amuME-T5hFAbD-LhWHiY8AAAAMQ"]
[Thu Jul 30 12:38:28.349943 2026] [security2:error] [pid 765155:tid 765371] [client 135.119.63.61:46167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/dropdown.php"] [unique_id "amuMFOT5hFAbD-LhWHiZEgAAANs"]
[Thu Jul 30 12:38:28.482524 2026] [core:notice] [pid 765155:tid 765407] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:28.486460 2026] [security2:error] [pid 765155:tid 765407] [client 103.215.74.26:62028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "771"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMFOT5hFAbD-LhWHiZGwAAAP8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:28.623249 2026] [security2:error] [pid 765155:tid 765236] [remote 57.141.0.58:40878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/post-sitemap.xml"] [unique_id "amuMFOT5hFAbD-LhWHiZHQAAhlA"]
[Thu Jul 30 12:38:28.894668 2026] [security2:error] [pid 765155:tid 765375] [client 38.190.144.4:54657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMFOT5hFAbD-LhWHiZLgAAAN8"]
[Thu Jul 30 12:38:28.894803 2026] [security2:error] [pid 765155:tid 765375] [client 38.190.144.4:54657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMFOT5hFAbD-LhWHiZLgAAAN8"]
[Thu Jul 30 12:38:28.896196 2026] [security2:error] [pid 765155:tid 765191] [remote 57.141.0.35:57402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/4804188137/feed/rss2/"] [unique_id "amuMFOT5hFAbD-LhWHiZLwAA6yM"]
[Thu Jul 30 12:38:29.168510 2026] [security2:error] [pid 765155:tid 765384] [client 20.215.191.139:10852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/plugins/wp-theme-editor/include.php"] [unique_id "amuMFeT5hFAbD-LhWHiZNQAAAOg"]
[Thu Jul 30 12:38:29.201578 2026] [security2:error] [pid 765155:tid 765405] [client 69.158.246.168:53748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuMFeT5hFAbD-LhWHiZNAAA_VU"], referer: https://www.northyorksheridanmall.com/store/
[Thu Jul 30 12:38:29.217387 2026] [core:notice] [pid 765155:tid 765366] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:29.221331 2026] [security2:error] [pid 765155:tid 765366] [client 103.215.74.26:62034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "733"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMFeT5hFAbD-LhWHiZNgAAANY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:29.268810 2026] [security2:error] [pid 765155:tid 765386] [client 20.63.98.115:20959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/dropdown.php"] [unique_id "amuMFeT5hFAbD-LhWHiZOgAAAOo"]
[Thu Jul 30 12:38:29.842723 2026] [security2:error] [pid 765155:tid 765302] [client 57.141.0.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMFeT5hFAbD-LhWHiZOQAAAJY"]
[Thu Jul 30 12:38:29.905902 2026] [core:notice] [pid 765155:tid 765256] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:29.954536 2026] [core:notice] [pid 765155:tid 765403] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:29.958351 2026] [security2:error] [pid 765155:tid 765403] [client 103.215.74.26:62042] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "737"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMFeT5hFAbD-LhWHiZUAAAAPs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:30.104254 2026] [core:error] [pid 765155:tid 765390] [client 20.63.98.115:64881] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:38:30.104275 2026] [core:error] [pid 765155:tid 765390] [client 20.63.98.115:64881] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:38:30.150348 2026] [security2:error] [pid 765155:tid 765392] [client 20.215.191.139:11798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/themes/aahana/json.php"] [unique_id "amuMFuT5hFAbD-LhWHiZVQAAAPA"]
[Thu Jul 30 12:38:30.717513 2026] [security2:error] [pid 765155:tid 765369] [client 2a03:2880:f800:2b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMFuT5hFAbD-LhWHiZVAAA2Vg"]
[Thu Jul 30 12:38:30.725774 2026] [security2:error] [pid 765155:tid 765374] [client 20.100.187.246:64338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/kj.php"] [unique_id "amuMFuT5hFAbD-LhWHiZYQAAAN4"]
[Thu Jul 30 12:38:30.730763 2026] [core:notice] [pid 765155:tid 765357] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:30.734772 2026] [security2:error] [pid 765155:tid 765357] [client 103.215.74.26:62044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMFuT5hFAbD-LhWHiZYgAAAM0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:30.735175 2026] [core:notice] [pid 765155:tid 765268] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:31.096674 2026] [core:notice] [pid 765155:tid 765278] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:31.207097 2026] [security2:error] [pid 765155:tid 765328] [client 20.215.191.139:11030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/plugins/awesome-coming-soon/come.php"] [unique_id "amuMF-T5hFAbD-LhWHiZbgAAALA"]
[Thu Jul 30 12:38:31.387265 2026] [core:notice] [pid 765155:tid 765409] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:31.425353 2026] [security2:error] [pid 765155:tid 765375] [client 20.63.98.115:21313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin.php"] [unique_id "amuMF-T5hFAbD-LhWHiZdgAAAN8"]
[Thu Jul 30 12:38:31.456790 2026] [core:notice] [pid 765155:tid 765410] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:31.460859 2026] [security2:error] [pid 765155:tid 765410] [client 103.215.74.26:62048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMF-T5hFAbD-LhWHiZfgAAAQI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:31.564682 2026] [security2:error] [pid 765155:tid 765341] [client 20.100.187.246:61704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/wp-files.php"] [unique_id "amuMF-T5hFAbD-LhWHiZgwAAAL0"]
[Thu Jul 30 12:38:31.769071 2026] [security2:error] [pid 765155:tid 765402] [client 135.119.63.61:46136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/edit.php"] [unique_id "amuMF-T5hFAbD-LhWHiZiAAAAPo"]
[Thu Jul 30 12:38:31.815737 2026] [core:notice] [pid 765155:tid 765379] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:31.896443 2026] [core:notice] [pid 765155:tid 765275] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:31.947363 2026] [security2:error] [pid 765155:tid 765403] [client 20.215.191.139:6977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/plugins/wp-conflg.php"] [unique_id "amuMF-T5hFAbD-LhWHiZjgAAAPs"]
[Thu Jul 30 12:38:32.012955 2026] [core:notice] [pid 765155:tid 765259] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:32.420995 2026] [security2:error] [pid 765155:tid 765377] [client 49.37.44.76:43084] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.eot"] [unique_id "amuMGOT5hFAbD-LhWHiZnQAAAOE"]
[Thu Jul 30 12:38:32.557337 2026] [security2:error] [pid 765155:tid 765311] [client 20.100.187.246:61722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/wp-setup.php"] [unique_id "amuMGOT5hFAbD-LhWHiZnwAAAJ8"]
[Thu Jul 30 12:38:32.843568 2026] [security2:error] [pid 765155:tid 765372] [client 20.215.191.139:3069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "amuMGOT5hFAbD-LhWHiZqwAAANw"]
[Thu Jul 30 12:38:32.923079 2026] [security2:error] [pid 765155:tid 765389] [client 172.236.9.101:45983] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGOT5hFAbD-LhWHiZmwAAAO0"]
[Thu Jul 30 12:38:32.928831 2026] [security2:error] [pid 765155:tid 765303] [client 172.236.9.101:41058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGOT5hFAbD-LhWHiZmgAAAJc"]
[Thu Jul 30 12:38:32.974449 2026] [security2:error] [pid 765155:tid 765338] [client 172.236.9.101:15313] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGOT5hFAbD-LhWHiZnAAAALo"]
[Thu Jul 30 12:38:32.991364 2026] [security2:error] [pid 765155:tid 765292] [client 172.236.9.101:37273] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGOT5hFAbD-LhWHiZngAAAIw"]
[Thu Jul 30 12:38:33.288828 2026] [security2:error] [pid 765155:tid 765391] [client 90.241.132.197:38808] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/js/revolution-slider/fonts/revicons/revicons.ttf"] [unique_id "amuMGeT5hFAbD-LhWHiZtgAAAO8"]
[Thu Jul 30 12:38:33.321753 2026] [security2:error] [pid 765155:tid 765324] [client 88.189.115.138:12130] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.eot"] [unique_id "amuMGeT5hFAbD-LhWHiZtwAAAKw"]
[Thu Jul 30 12:38:33.382023 2026] [core:notice] [pid 765155:tid 765267] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:33.382023 2026] [core:notice] [pid 765155:tid 765282] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:33.457994 2026] [security2:error] [pid 765155:tid 765371] [client 150.107.232.194:27512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMGeT5hFAbD-LhWHiZzQAAANs"]
[Thu Jul 30 12:38:33.458140 2026] [security2:error] [pid 765155:tid 765371] [client 150.107.232.194:27512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMGeT5hFAbD-LhWHiZzQAAANs"]
[Thu Jul 30 12:38:33.458530 2026] [security2:error] [pid 765155:tid 765287] [client 84.67.10.213:52926] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/js/revolution-slider/fonts/revicons/revicons.eot"] [unique_id "amuMGeT5hFAbD-LhWHiZzAAAAIc"]
[Thu Jul 30 12:38:33.489320 2026] [security2:error] [pid 765155:tid 765356] [client 136.158.42.51:57398] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.eot"] [unique_id "amuMGeT5hFAbD-LhWHiZzgAAAMw"]
[Thu Jul 30 12:38:33.512181 2026] [core:notice] [pid 765155:tid 765183] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:33.523265 2026] [core:notice] [pid 765155:tid 765276] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:33.536754 2026] [security2:error] [pid 765155:tid 765328] [client 87.90.83.146:65506] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.eot"] [unique_id "amuMGeT5hFAbD-LhWHiZ0QAAALA"]
[Thu Jul 30 12:38:33.598363 2026] [security2:error] [pid 765155:tid 765309] [client 62.166.248.70:43196] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.eot"] [unique_id "amuMGeT5hFAbD-LhWHiZ1QAAAJ0"]
[Thu Jul 30 12:38:33.707044 2026] [security2:error] [pid 765155:tid 765294] [client 51.68.111.202:34937] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pkf.jo"] [uri "/robots.txt"] [unique_id "amuMGeT5hFAbD-LhWHiZ2QAAAI4"]
[Thu Jul 30 12:38:33.895676 2026] [security2:error] [pid 765155:tid 765317] [client 85.189.9.119:52066] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.ttf"] [unique_id "amuMGeT5hFAbD-LhWHiZ3gAAAKU"]
[Thu Jul 30 12:38:33.955291 2026] [core:notice] [pid 765155:tid 765159] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:33.959269 2026] [security2:error] [pid 765155:tid 765409] [client 86.195.222.85:39770] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.eot"] [unique_id "amuMGeT5hFAbD-LhWHiZ4wAAAQE"]
[Thu Jul 30 12:38:34.022595 2026] [security2:error] [pid 765155:tid 765375] [client 76.131.96.102:58097] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.woff2"] [unique_id "amuMGuT5hFAbD-LhWHiZ5QAAAN8"]
[Thu Jul 30 12:38:34.053061 2026] [security2:error] [pid 765155:tid 765367] [client 135.119.63.61:46180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/f35.php"] [unique_id "amuMGuT5hFAbD-LhWHiZ5gAAANc"]
[Thu Jul 30 12:38:34.089067 2026] [security2:error] [pid 765155:tid 765406] [client 136.239.180.67:59516] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.eot"] [unique_id "amuMGuT5hFAbD-LhWHiZ5wAAAP4"]
[Thu Jul 30 12:38:34.097132 2026] [proxy:error] [pid 765155:tid 765277] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:38:34.097179 2026] [proxy_http:error] [pid 765155:tid 765277] [remote 74.7.230.11:39038] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:38:34.097755 2026] [proxy:error] [pid 765155:tid 765277] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:38:34.097796 2026] [proxy_http:error] [pid 765155:tid 765277] [remote 74.7.230.11:39038] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:38:34.120879 2026] [security2:error] [pid 765155:tid 765157] [remote 143.244.47.86:57901] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "website-167e4a7a.vdb.nyx.temporary.site"] [uri "/cdn-cgi/rum"] [unique_id "amuMGuT5hFAbD-LhWHiZ6QAA3AE"], referer: https://website-167e4a7a.vdb.nyx.temporary.site/
[Thu Jul 30 12:38:34.191335 2026] [security2:error] [pid 765155:tid 765296] [client 57.141.0.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMGeT5hFAbD-LhWHiZ1AAAAJA"]
[Thu Jul 30 12:38:34.213194 2026] [security2:error] [pid 765155:tid 765340] [client 79.30.133.179:42231] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.woff"] [unique_id "amuMGuT5hFAbD-LhWHiZ7QAAALw"]
[Thu Jul 30 12:38:34.263337 2026] [core:notice] [pid 765155:tid 765173] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:34.265926 2026] [security2:error] [pid 765155:tid 765360] [client 172.236.9.101:60729] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGeT5hFAbD-LhWHiZuAAAANA"]
[Thu Jul 30 12:38:34.281219 2026] [security2:error] [pid 765155:tid 765293] [client 172.236.9.101:11002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGeT5hFAbD-LhWHiZuQAAAI0"]
[Thu Jul 30 12:38:34.285272 2026] [security2:error] [pid 765155:tid 765342] [client 172.236.9.101:43155] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGeT5hFAbD-LhWHiZuwAAAL4"]
[Thu Jul 30 12:38:34.300423 2026] [security2:error] [pid 765155:tid 765352] [client 172.236.9.101:27950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGeT5hFAbD-LhWHiZvAAAAMg"]
[Thu Jul 30 12:38:34.386051 2026] [security2:error] [pid 765155:tid 765302] [client 172.236.9.101:52673] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGeT5hFAbD-LhWHiZugAAAJY"]
[Thu Jul 30 12:38:34.407845 2026] [security2:error] [pid 765155:tid 765301] [client 172.236.9.101:1381] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGeT5hFAbD-LhWHiZywAAAJU"]
[Thu Jul 30 12:38:34.408469 2026] [security2:error] [pid 765155:tid 765398] [client 172.236.9.101:45040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGeT5hFAbD-LhWHiZwgAAAPY"]
[Thu Jul 30 12:38:34.414116 2026] [security2:error] [pid 765155:tid 765368] [client 172.236.9.101:19634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGeT5hFAbD-LhWHiZxAAAANg"]
[Thu Jul 30 12:38:34.426681 2026] [security2:error] [pid 765155:tid 765346] [client 172.236.9.101:19581] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGeT5hFAbD-LhWHiZwQAAAMI"]
[Thu Jul 30 12:38:34.433370 2026] [security2:error] [pid 765155:tid 765320] [client 172.236.9.101:1784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGeT5hFAbD-LhWHiZyAAAAKg"]
[Thu Jul 30 12:38:34.433645 2026] [security2:error] [pid 765155:tid 765347] [client 172.236.9.101:59531] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGeT5hFAbD-LhWHiZyQAAAMM"]
[Thu Jul 30 12:38:34.447666 2026] [security2:error] [pid 765155:tid 765362] [client 20.100.187.246:61144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/defaults.php"] [unique_id "amuMGuT5hFAbD-LhWHiZ-QAAANI"]
[Thu Jul 30 12:38:34.468918 2026] [security2:error] [pid 765155:tid 765396] [client 172.236.9.101:20653] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGeT5hFAbD-LhWHiZygAAAPQ"]
[Thu Jul 30 12:38:34.582918 2026] [security2:error] [pid 765155:tid 765358] [client 78.51.163.187:61534] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.woff"] [unique_id "amuMGuT5hFAbD-LhWHiZ-gAAAM4"]
[Thu Jul 30 12:38:34.869072 2026] [security2:error] [pid 765155:tid 765378] [client 172.236.9.101:1452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGuT5hFAbD-LhWHiZ8gAAAOI"]
[Thu Jul 30 12:38:34.869638 2026] [security2:error] [pid 765155:tid 765338] [client 172.236.9.101:11984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGuT5hFAbD-LhWHiZ8wAAALo"]
[Thu Jul 30 12:38:34.871327 2026] [security2:error] [pid 765155:tid 765408] [client 172.236.9.101:27483] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGuT5hFAbD-LhWHiZ9AAAAQA"]
[Thu Jul 30 12:38:34.916495 2026] [security2:error] [pid 765155:tid 765327] [client 172.236.9.101:2564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGuT5hFAbD-LhWHiZ-AAAAK8"]
[Thu Jul 30 12:38:34.922737 2026] [security2:error] [pid 765155:tid 765389] [client 152.58.47.243:54942] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/js/revolution-slider/fonts/revicons/revicons.eot"] [unique_id "amuMGuT5hFAbD-LhWHiaBQAAAO0"]
[Thu Jul 30 12:38:35.012943 2026] [security2:error] [pid 765155:tid 765324] [client 135.119.63.61:46109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/f7.php"] [unique_id "amuMG-T5hFAbD-LhWHiaCgAAAKw"]
[Thu Jul 30 12:38:35.094934 2026] [security2:error] [pid 765155:tid 765307] [client 70.64.20.57:52958] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.ttf"] [unique_id "amuMG-T5hFAbD-LhWHiaCwAAAJs"]
[Thu Jul 30 12:38:35.109581 2026] [security2:error] [pid 765155:tid 765366] [client 99.237.236.213:47690] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.woff"] [unique_id "amuMG-T5hFAbD-LhWHiaDAAAANY"]
[Thu Jul 30 12:38:35.147936 2026] [security2:error] [pid 765155:tid 765310] [client 51.223.65.234:58730] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.eot"] [unique_id "amuMG-T5hFAbD-LhWHiaDQAAAJ4"]
[Thu Jul 30 12:38:35.213969 2026] [security2:error] [pid 765155:tid 765397] [client 93.47.41.144:40665] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.ttf"] [unique_id "amuMG-T5hFAbD-LhWHiaDgAAAPU"]
[Thu Jul 30 12:38:35.315102 2026] [core:notice] [pid 765155:tid 765158] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:35.574343 2026] [security2:error] [pid 765155:tid 765184] [remote 143.244.47.86:57901] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "website-167e4a7a.vdb.nyx.temporary.site"] [uri "/cdn-cgi/rum"] [unique_id "amuMG-T5hFAbD-LhWHiaGwAAphw"], referer: https://website-167e4a7a.vdb.nyx.temporary.site/
[Thu Jul 30 12:38:35.584294 2026] [security2:error] [pid 765155:tid 765354] [client 20.100.187.246:60172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/gtc.php"] [unique_id "amuMG-T5hFAbD-LhWHiaHAAAAMo"]
[Thu Jul 30 12:38:35.659657 2026] [core:notice] [pid 765155:tid 765187] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:35.659657 2026] [core:notice] [pid 765155:tid 765195] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:35.659670 2026] [core:notice] [pid 765155:tid 765182] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:35.662155 2026] [core:notice] [pid 765155:tid 765176] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:35.662162 2026] [core:notice] [pid 765155:tid 765188] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:35.662519 2026] [core:notice] [pid 765155:tid 765199] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:35.691198 2026] [security2:error] [pid 765155:tid 765197] [remote 5.161.62.209:10994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lxw.gpl.temporary.site"] [uri "/.env"] [unique_id "amuMG-T5hFAbD-LhWHiaIwAA-Sk"]
[Thu Jul 30 12:38:35.963660 2026] [security2:error] [pid 765155:tid 765374] [client 95.20.4.203:42626] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.ttf"] [unique_id "amuMG-T5hFAbD-LhWHiaKgAAAN4"]
[Thu Jul 30 12:38:36.280781 2026] [security2:error] [pid 765155:tid 765299] [client 20.215.191.139:6719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-includes/style-engine/about.php"] [unique_id "amuMHOT5hFAbD-LhWHiaLwAAAJM"]
[Thu Jul 30 12:38:36.314732 2026] [security2:error] [pid 765155:tid 765291] [client 20.63.98.115:39110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/buy.php"] [unique_id "amuMHOT5hFAbD-LhWHiaNQAAAIs"]
[Thu Jul 30 12:38:36.408886 2026] [security2:error] [pid 765155:tid 765370] [client 20.100.187.246:61142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/import.php"] [unique_id "amuMHOT5hFAbD-LhWHiaOgAAANo"]
[Thu Jul 30 12:38:37.192192 2026] [core:notice] [pid 765155:tid 765400] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:37.195956 2026] [security2:error] [pid 765155:tid 765400] [client 103.215.74.26:27374] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "732"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMHeT5hFAbD-LhWHiaRwAAAPg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:37.931762 2026] [core:notice] [pid 765155:tid 765388] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:37.935663 2026] [security2:error] [pid 765155:tid 765388] [client 103.215.74.26:27384] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "732"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMHeT5hFAbD-LhWHiaWQAAAOw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:38.464047 2026] [security2:error] [pid 765155:tid 765303] [client 20.215.191.139:2488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "amuMHuT5hFAbD-LhWHiaZwAAAJc"]
[Thu Jul 30 12:38:38.675093 2026] [security2:error] [pid 765155:tid 765372] [client 20.100.187.246:61075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/lufix.php"] [unique_id "amuMHuT5hFAbD-LhWHiabAAAANw"]
[Thu Jul 30 12:38:38.676333 2026] [core:notice] [pid 765155:tid 765351] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:38.680686 2026] [security2:error] [pid 765155:tid 765351] [client 103.215.74.26:27400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMHuT5hFAbD-LhWHiaawAAAMc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:38.843006 2026] [security2:error] [pid 765155:tid 765312] [client 20.63.98.115:64875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/mini.php"] [unique_id "amuMHuT5hFAbD-LhWHiacAAAAKA"]
[Thu Jul 30 12:38:38.886263 2026] [security2:error] [pid 765155:tid 765325] [client 172.236.9.101:35805] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMHuT5hFAbD-LhWHiaYwAAAK0"]
[Thu Jul 30 12:38:39.409238 2026] [core:notice] [pid 765155:tid 765344] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:39.416292 2026] [security2:error] [pid 765155:tid 765344] [client 103.215.74.26:27408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMH-T5hFAbD-LhWHiahgAAAMA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:39.914392 2026] [security2:error] [pid 765155:tid 765357] [client 172.236.9.101:36913] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMH-T5hFAbD-LhWHiagQAAAM0"]
[Thu Jul 30 12:38:39.941962 2026] [security2:error] [pid 765155:tid 765317] [client 172.236.9.101:61882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMH-T5hFAbD-LhWHiaggAAAKU"]
[Thu Jul 30 12:38:40.050520 2026] [security2:error] [pid 765155:tid 765324] [client 172.236.9.101:2872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMH-T5hFAbD-LhWHiahQAAAKw"]
[Thu Jul 30 12:38:40.050806 2026] [security2:error] [pid 765155:tid 765410] [client 172.236.9.101:4589] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMH-T5hFAbD-LhWHiahAAAAQI"]
[Thu Jul 30 12:38:40.051859 2026] [security2:error] [pid 765155:tid 765389] [client 172.236.9.101:11333] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMH-T5hFAbD-LhWHiagwAAAO0"]
[Thu Jul 30 12:38:40.060055 2026] [security2:error] [pid 765155:tid 765367] [client 172.236.9.101:38492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMH-T5hFAbD-LhWHiahwAAANc"]
[Thu Jul 30 12:38:40.071563 2026] [security2:error] [pid 765155:tid 765406] [client 172.236.9.101:2276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMH-T5hFAbD-LhWHiaiAAAAP4"]
[Thu Jul 30 12:38:40.165304 2026] [core:notice] [pid 765155:tid 765320] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:40.169689 2026] [security2:error] [pid 765155:tid 765320] [client 103.215.74.26:27418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMIOT5hFAbD-LhWHiapgAAAKg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:40.188169 2026] [security2:error] [pid 765155:tid 765375] [client 66.249.65.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMH-T5hFAbD-LhWHiakQAAAN8"]
[Thu Jul 30 12:38:40.359925 2026] [autoindex:error] [pid 765155:tid 765399] [client 81.215.199.165:52264] AH01276: Cannot serve directory /home1/yqegzjte/fintn.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.google.com/
[Thu Jul 30 12:38:40.721941 2026] [autoindex:error] [pid 765155:tid 765326] [client 81.215.199.165:52278] AH01276: Cannot serve directory /home1/yqegzjte/fintn.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.google.com/
[Thu Jul 30 12:38:40.920886 2026] [core:notice] [pid 765155:tid 765337] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:40.927781 2026] [security2:error] [pid 765155:tid 765337] [client 103.215.74.26:27432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMIOT5hFAbD-LhWHiawQAAALk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:40.929896 2026] [security2:error] [pid 765155:tid 765356] [client 172.236.9.101:14985] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMIOT5hFAbD-LhWHiasAAAAMw"]
[Thu Jul 30 12:38:40.929966 2026] [security2:error] [pid 765155:tid 765308] [client 172.236.9.101:53858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMIOT5hFAbD-LhWHiargAAAJw"]
[Thu Jul 30 12:38:40.948343 2026] [security2:error] [pid 765155:tid 765309] [client 172.236.9.101:52303] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMIOT5hFAbD-LhWHiarwAAAJ0"]
[Thu Jul 30 12:38:40.958794 2026] [security2:error] [pid 765155:tid 765319] [client 172.236.9.101:36767] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMIOT5hFAbD-LhWHiasQAAAKc"]
[Thu Jul 30 12:38:40.971960 2026] [security2:error] [pid 765155:tid 765363] [client 172.236.9.101:17596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMIOT5hFAbD-LhWHiasgAAANM"]
[Thu Jul 30 12:38:40.997794 2026] [security2:error] [pid 765155:tid 765312] [client 172.236.9.101:44755] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMIOT5hFAbD-LhWHiatAAAAKA"]
[Thu Jul 30 12:38:41.005047 2026] [security2:error] [pid 765155:tid 765328] [client 172.236.9.101:1460] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMIOT5hFAbD-LhWHiaswAAALA"]
[Thu Jul 30 12:38:41.051560 2026] [security2:error] [pid 765155:tid 765377] [client 172.236.9.101:1352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMIOT5hFAbD-LhWHiatgAAAOE"]
[Thu Jul 30 12:38:41.051829 2026] [security2:error] [pid 765155:tid 765325] [client 172.236.9.101:21716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMIOT5hFAbD-LhWHiatQAAAK0"]
[Thu Jul 30 12:38:41.291064 2026] [security2:error] [pid 765155:tid 765395] [client 20.215.191.139:11793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuMIeT5hFAbD-LhWHiayAAAAPM"]
[Thu Jul 30 12:38:41.399025 2026] [autoindex:error] [pid 765155:tid 765364] [client 81.215.199.165:52288] AH01276: Cannot serve directory /home1/yqegzjte/fintn.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.google.com/
[Thu Jul 30 12:38:41.533426 2026] [security2:error] [pid 765155:tid 765409] [client 20.100.187.246:64969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/Geforce.php"] [unique_id "amuMIeT5hFAbD-LhWHia0AAAAQE"]
[Thu Jul 30 12:38:41.647456 2026] [core:notice] [pid 765155:tid 765410] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:41.654935 2026] [security2:error] [pid 765155:tid 765410] [client 103.215.74.26:27436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMIeT5hFAbD-LhWHia1AAAAQI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:41.751962 2026] [autoindex:error] [pid 765155:tid 765403] [client 81.215.199.165:52302] AH01276: Cannot serve directory /home1/yqegzjte/fintn.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.google.com/
[Thu Jul 30 12:38:41.843581 2026] [security2:error] [pid 765155:tid 765398] [client 172.236.9.101:32595] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMIeT5hFAbD-LhWHiaywAAAPY"]
[Thu Jul 30 12:38:41.862493 2026] [security2:error] [pid 765155:tid 765346] [client 172.236.9.101:18719] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMIeT5hFAbD-LhWHiazQAAAMI"]
[Thu Jul 30 12:38:41.912443 2026] [security2:error] [pid 765155:tid 765362] [client 172.236.9.101:49524] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMIeT5hFAbD-LhWHiazwAAANI"]
[Thu Jul 30 12:38:42.295748 2026] [security2:error] [pid 765155:tid 765384] [client 20.215.191.139:11836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/banners/about.php"] [unique_id "amuMIuT5hFAbD-LhWHia4gAAAOg"]
[Thu Jul 30 12:38:42.403792 2026] [core:notice] [pid 765155:tid 765383] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:42.408608 2026] [security2:error] [pid 765155:tid 765383] [client 103.215.74.26:27450] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMIuT5hFAbD-LhWHia5gAAAOc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:42.601376 2026] [security2:error] [pid 765155:tid 765341] [client 20.63.98.115:32387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/cd.php"] [unique_id "amuMIuT5hFAbD-LhWHia7wAAAL0"]
[Thu Jul 30 12:38:43.128355 2026] [security2:error] [pid 765155:tid 765326] [client 74.7.230.57:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.ncg.udi.temporary.site"] [uri "/index.php"] [unique_id "amuMIuT5hFAbD-LhWHia6QAAAK4"]
[Thu Jul 30 12:38:43.129259 2026] [security2:error] [pid 765155:tid 765349] [client 74.7.230.57:33228] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.ncg.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amuMIuT5hFAbD-LhWHia5wAAxWg"]
[Thu Jul 30 12:38:43.161600 2026] [core:notice] [pid 765155:tid 765333] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:43.166260 2026] [security2:error] [pid 765155:tid 765333] [client 103.215.74.26:40642] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMI-T5hFAbD-LhWHibAgAAALU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:43.709488 2026] [security2:error] [pid 765155:tid 765322] [client 20.215.191.139:8217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/about.php"] [unique_id "amuMI-T5hFAbD-LhWHibIAAAAKo"]
[Thu Jul 30 12:38:43.787929 2026] [security2:error] [pid 765155:tid 765291] [client 62.102.148.158:52376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuMI-T5hFAbD-LhWHibJAAAAIs"]
[Thu Jul 30 12:38:43.788069 2026] [security2:error] [pid 765155:tid 765291] [client 62.102.148.158:52376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuMI-T5hFAbD-LhWHibJAAAAIs"]
[Thu Jul 30 12:38:43.908144 2026] [core:notice] [pid 765155:tid 765299] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:43.912609 2026] [security2:error] [pid 765155:tid 765299] [client 103.215.74.26:40652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMI-T5hFAbD-LhWHibKAAAAJM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:43.919914 2026] [security2:error] [pid 765155:tid 765361] [client 150.107.232.194:27218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMI-T5hFAbD-LhWHibKQAAANE"]
[Thu Jul 30 12:38:43.920016 2026] [security2:error] [pid 765155:tid 765361] [client 150.107.232.194:27218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMI-T5hFAbD-LhWHibKQAAANE"]
[Thu Jul 30 12:38:44.173713 2026] [security2:error] [pid 765155:tid 765375] [client 20.63.98.115:21343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amuMJOT5hFAbD-LhWHibMAAAAN8"]
[Thu Jul 30 12:38:44.438734 2026] [core:notice] [pid 765155:tid 765316] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:44.446735 2026] [security2:error] [pid 765155:tid 765316] [client 195.23.32.200:60500] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.carnetdeshopping.com"] [uri "/feed/atom/"] [unique_id "amuMJOT5hFAbD-LhWHibOQAAAKQ"]
[Thu Jul 30 12:38:44.522000 2026] [core:notice] [pid 765155:tid 765240] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:44.664054 2026] [core:notice] [pid 765155:tid 765387] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:44.668429 2026] [security2:error] [pid 765155:tid 765387] [client 103.215.74.26:40666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMJOT5hFAbD-LhWHibPQAAAOs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:45.224361 2026] [security2:error] [pid 765155:tid 765313] [client 172.236.9.101:57260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibBgAAAKE"]
[Thu Jul 30 12:38:45.232447 2026] [security2:error] [pid 765155:tid 765365] [client 172.236.9.101:38185] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibCAAAANU"]
[Thu Jul 30 12:38:45.235061 2026] [security2:error] [pid 765155:tid 765324] [client 172.236.9.101:9254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibCQAAAKw"]
[Thu Jul 30 12:38:45.299617 2026] [security2:error] [pid 765155:tid 765396] [client 172.236.9.101:1693] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibBwAAAPQ"]
[Thu Jul 30 12:38:45.301899 2026] [security2:error] [pid 765155:tid 765347] [client 172.236.9.101:48363] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibCgAAAMM"]
[Thu Jul 30 12:38:45.345544 2026] [security2:error] [pid 765155:tid 765389] [client 172.236.9.101:61886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibDQAAAO0"]
[Thu Jul 30 12:38:45.346430 2026] [security2:error] [pid 765155:tid 765367] [client 172.236.9.101:8984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibDAAAANc"]
[Thu Jul 30 12:38:45.366676 2026] [security2:error] [pid 765155:tid 765364] [client 172.236.9.101:64744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibCwAAANQ"]
[Thu Jul 30 12:38:45.366732 2026] [security2:error] [pid 765155:tid 765305] [client 172.236.9.101:11561] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibEgAAAJk"]
[Thu Jul 30 12:38:45.371295 2026] [security2:error] [pid 765155:tid 765303] [client 172.236.9.101:12378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibFQAAAJc"]
[Thu Jul 30 12:38:45.378761 2026] [security2:error] [pid 765155:tid 765343] [client 172.236.9.101:38605] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibEAAAAL8"]
[Thu Jul 30 12:38:45.383270 2026] [security2:error] [pid 765155:tid 765306] [client 172.236.9.101:26976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibEwAAAJo"]
[Thu Jul 30 12:38:45.391898 2026] [security2:error] [pid 765155:tid 765329] [client 172.236.9.101:58714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibEQAAALE"]
[Thu Jul 30 12:38:45.392866 2026] [security2:error] [pid 765155:tid 765409] [client 172.236.9.101:26477] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibDgAAAQE"]
[Thu Jul 30 12:38:45.396620 2026] [core:notice] [pid 765155:tid 765380] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:45.398846 2026] [security2:error] [pid 765155:tid 765402] [client 172.236.9.101:39762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibFgAAAPo"]
[Thu Jul 30 12:38:45.400773 2026] [security2:error] [pid 765155:tid 765380] [client 103.215.74.26:40674] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "732"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMJeT5hFAbD-LhWHibTgAAAOQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:45.403806 2026] [security2:error] [pid 765155:tid 765391] [client 172.236.9.101:7315] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibGAAAAO8"]
[Thu Jul 30 12:38:45.403807 2026] [security2:error] [pid 765155:tid 765406] [client 172.236.9.101:23172] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibDwAAAP4"]
[Thu Jul 30 12:38:45.422752 2026] [security2:error] [pid 765155:tid 765410] [client 172.236.9.101:46388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibFAAAAQI"]
[Thu Jul 30 12:38:45.459719 2026] [security2:error] [pid 765155:tid 765411] [client 172.236.9.101:54509] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibFwAAAQM"]
[Thu Jul 30 12:38:45.471988 2026] [security2:error] [pid 765155:tid 765392] [client 172.236.9.101:33623] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibGQAAAPA"]
[Thu Jul 30 12:38:45.550528 2026] [security2:error] [pid 765155:tid 765339] [client 20.215.191.139:7984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/about.php"] [unique_id "amuMJeT5hFAbD-LhWHibUgAAALs"]
[Thu Jul 30 12:38:45.701033 2026] [core:notice] [pid 765155:tid 765287] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:45.704592 2026] [security2:error] [pid 765155:tid 765287] [client 195.23.32.200:60592] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/feed/atom/"] [unique_id "amuMJeT5hFAbD-LhWHibWwAAAIc"]
[Thu Jul 30 12:38:46.136914 2026] [core:notice] [pid 765155:tid 765394] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:46.140821 2026] [security2:error] [pid 765155:tid 765394] [client 103.215.74.26:40676] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "734"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMJuT5hFAbD-LhWHibaAAAAPI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:46.637909 2026] [security2:error] [pid 765155:tid 765340] [client 20.215.191.139:12366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuMJuT5hFAbD-LhWHibcgAAALw"]
[Thu Jul 30 12:38:46.869596 2026] [core:notice] [pid 765155:tid 765409] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:46.873849 2026] [security2:error] [pid 765155:tid 765409] [client 103.215.74.26:40692] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "731"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMJuT5hFAbD-LhWHibdwAAAQE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:46.977855 2026] [security2:error] [pid 765155:tid 765392] [client 194.187.251.163:34364] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuMJuT5hFAbD-LhWHibfAAAAPA"]
[Thu Jul 30 12:38:46.977993 2026] [security2:error] [pid 765155:tid 765392] [client 194.187.251.163:34364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuMJuT5hFAbD-LhWHibfAAAAPA"]
[Thu Jul 30 12:38:47.314729 2026] [security2:error] [pid 765155:tid 765364] [client 195.23.32.200:60676] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuMJuT5hFAbD-LhWHibeAAAANQ"]
[Thu Jul 30 12:38:47.357427 2026] [security2:error] [pid 765155:tid 765391] [client 2a03:2880:f800:44:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMJuT5hFAbD-LhWHibcwAA71Y"]
[Thu Jul 30 12:38:47.401438 2026] [security2:error] [pid 765155:tid 765370] [client 20.215.191.139:2910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuMJ-T5hFAbD-LhWHibgwAAANo"]
[Thu Jul 30 12:38:47.627245 2026] [core:notice] [pid 765155:tid 765378] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:47.631839 2026] [security2:error] [pid 765155:tid 765378] [client 103.215.74.26:40702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMJ-T5hFAbD-LhWHibjQAAAOI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:48.003882 2026] [security2:error] [pid 765155:tid 765310] [client 20.100.187.246:61716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/a4.php"] [unique_id "amuMKOT5hFAbD-LhWHibmQAAAJ4"]
[Thu Jul 30 12:38:48.123330 2026] [security2:error] [pid 765155:tid 765293] [client 20.215.191.139:12389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/img/about.php"] [unique_id "amuMKOT5hFAbD-LhWHibnQAAAI0"]
[Thu Jul 30 12:38:48.247004 2026] [security2:error] [pid 765155:tid 765342] [client 20.63.98.115:64865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/batm.php"] [unique_id "amuMKOT5hFAbD-LhWHiboQAAAL4"]
[Thu Jul 30 12:38:48.349886 2026] [core:notice] [pid 765155:tid 765404] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:48.356436 2026] [security2:error] [pid 765155:tid 765404] [client 103.215.74.26:40712] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMKOT5hFAbD-LhWHibogAAAPw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:48.542914 2026] [security2:error] [pid 765155:tid 765339] [client 2a03:2880:f800:3e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMJ-T5hFAbD-LhWHiblQAAu28"]
[Thu Jul 30 12:38:48.568040 2026] [security2:error] [pid 765155:tid 765173] [remote 57.141.0.53:64344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/63798190810/feed/rss2/"] [unique_id "amuMKOT5hFAbD-LhWHibrgAA1hE"]
[Thu Jul 30 12:38:48.832778 2026] [security2:error] [pid 765155:tid 765349] [client 57.141.0.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMKOT5hFAbD-LhWHiboAAAAMU"]
[Thu Jul 30 12:38:49.095506 2026] [security2:error] [pid 765155:tid 765333] [client 20.100.187.246:61092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/accueil.php"] [unique_id "amuMKeT5hFAbD-LhWHibwwAAALU"]
[Thu Jul 30 12:38:49.102890 2026] [core:notice] [pid 765155:tid 765412] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:49.109493 2026] [security2:error] [pid 765155:tid 765412] [client 103.215.74.26:40722] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMKeT5hFAbD-LhWHibxAAAAQQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:49.578099 2026] [security2:error] [pid 765155:tid 765304] [client 20.215.191.139:13475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/languages/about.php"] [unique_id "amuMKeT5hFAbD-LhWHib0AAAAJg"]
[Thu Jul 30 12:38:49.692020 2026] [security2:error] [pid 765155:tid 765408] [client 57.141.0.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMKeT5hFAbD-LhWHibwgAAAQA"]
[Thu Jul 30 12:38:49.837731 2026] [core:notice] [pid 765155:tid 765356] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:49.841782 2026] [security2:error] [pid 765155:tid 765356] [client 103.215.74.26:40724] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "732"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMKeT5hFAbD-LhWHib2gAAAMw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:50.073715 2026] [security2:error] [pid 765155:tid 765363] [client 20.100.187.246:64356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/dashboard.php"] [unique_id "amuMKuT5hFAbD-LhWHib4wAAANM"]
[Thu Jul 30 12:38:50.314268 2026] [core:notice] [pid 765155:tid 765292] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:50.418275 2026] [security2:error] [pid 765155:tid 765397] [client 20.63.98.115:59049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/hehehehe.php"] [unique_id "amuMKuT5hFAbD-LhWHib6QAAAPU"]
[Thu Jul 30 12:38:50.565003 2026] [core:notice] [pid 765155:tid 765339] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:50.569917 2026] [security2:error] [pid 765155:tid 765339] [client 103.215.74.26:40740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMKuT5hFAbD-LhWHib6wAAALs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:51.237287 2026] [security2:error] [pid 765155:tid 765374] [client 20.100.187.246:61151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/radio.php"] [unique_id "amuMK-T5hFAbD-LhWHib_gAAAN4"]
[Thu Jul 30 12:38:51.317116 2026] [core:notice] [pid 765155:tid 765333] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:51.323787 2026] [security2:error] [pid 765155:tid 765333] [client 103.215.74.26:40744] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMK-T5hFAbD-LhWHicAgAAALU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:51.623224 2026] [security2:error] [pid 765155:tid 765315] [client 20.215.191.139:5105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-includes/customize/about.php"] [unique_id "amuMK-T5hFAbD-LhWHicCAAAAKM"]
[Thu Jul 30 12:38:52.062117 2026] [core:notice] [pid 765155:tid 765294] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:52.066176 2026] [security2:error] [pid 765155:tid 765294] [client 103.215.74.26:40750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "763"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMLOT5hFAbD-LhWHicFAAAAI4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:52.144013 2026] [core:notice] [pid 765155:tid 765359] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:52.314526 2026] [security2:error] [pid 765155:tid 765376] [client 85.204.70.98:48138] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jto.nyx.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuMLOT5hFAbD-LhWHicIAAAAOA"]
[Thu Jul 30 12:38:52.389852 2026] [security2:error] [pid 765155:tid 765400] [client 38.190.144.4:55677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMLOT5hFAbD-LhWHicIgAAAPg"]
[Thu Jul 30 12:38:52.389954 2026] [security2:error] [pid 765155:tid 765400] [client 38.190.144.4:55677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMLOT5hFAbD-LhWHicIgAAAPg"]
[Thu Jul 30 12:38:52.584583 2026] [security2:error] [pid 765155:tid 765292] [client 85.204.70.98:48146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jto.nyx.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuMLOT5hFAbD-LhWHicIwAAAIw"]
[Thu Jul 30 12:38:52.786586 2026] [core:notice] [pid 765155:tid 765317] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:52.790595 2026] [security2:error] [pid 765155:tid 765317] [client 103.215.74.26:40760] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMLOT5hFAbD-LhWHicLQAAAKU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:53.059382 2026] [security2:error] [pid 765155:tid 765412] [client 74.7.244.5:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.jto.nyx.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuMLeT5hFAbD-LhWHicOwAAAQQ"]
[Thu Jul 30 12:38:53.060114 2026] [security2:error] [pid 765155:tid 765346] [client 74.7.244.5:37680] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.jto.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuMLeT5hFAbD-LhWHicOQAAwkk"]
[Thu Jul 30 12:38:53.125329 2026] [security2:error] [pid 765155:tid 765411] [client 74.7.175.182:58566] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "pkfye.ye"] [uri "/cgi-sys/404.html"] [unique_id "amuMLeT5hFAbD-LhWHicPAABA10"]
[Thu Jul 30 12:38:53.390350 2026] [security2:error] [pid 765155:tid 765348] [client 2a03:2880:f800:36:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMLOT5hFAbD-LhWHicLAAAxDw"]
[Thu Jul 30 12:38:53.526739 2026] [core:notice] [pid 765155:tid 765373] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:53.530876 2026] [security2:error] [pid 765155:tid 765373] [client 103.215.74.26:18300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMLeT5hFAbD-LhWHicUAAAAN0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:53.795315 2026] [proxy:error] [pid 765155:tid 765294] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:38:53.795368 2026] [proxy_http:error] [pid 765155:tid 765294] [client 74.7.241.191:57114] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:38:53.795926 2026] [proxy:error] [pid 765155:tid 765294] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:38:53.795967 2026] [proxy_http:error] [pid 765155:tid 765294] [client 74.7.241.191:57114] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:38:53.796099 2026] [security2:error] [pid 765155:tid 765294] [client 74.7.241.191:57114] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "cpcontacts.zbj.udi.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuMLeT5hFAbD-LhWHicXAAAAI4"]
[Thu Jul 30 12:38:53.853377 2026] [security2:error] [pid 765155:tid 765289] [client 85.204.70.98:48158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jto.nyx.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuMLeT5hFAbD-LhWHicXgAAAIk"]
[Thu Jul 30 12:38:53.853495 2026] [security2:error] [pid 765155:tid 765289] [client 85.204.70.98:48158] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jto.nyx.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuMLeT5hFAbD-LhWHicXgAAAIk"]
[Thu Jul 30 12:38:53.884654 2026] [core:notice] [pid 765155:tid 765356] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:54.011722 2026] [security2:error] [pid 765155:tid 765403] [client 2a03:2880:f800:28:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMLeT5hFAbD-LhWHicTAAA-0U"]
[Thu Jul 30 12:38:54.110215 2026] [security2:error] [pid 765155:tid 765260] [remote 57.141.0.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuMLuT5hFAbD-LhWHicZAAA-Wg"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=wood,aluminum,steel,plastic,lycra,nylon,polyester&filter_size=extra-extra-large,extra-large,small,extra-small&orderby=price&unfilter=1
[Thu Jul 30 12:38:54.116904 2026] [security2:error] [pid 765155:tid 765191] [remote 57.141.0.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuMLuT5hFAbD-LhWHicZQAAsiM"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=wood,aluminum,steel,plastic,lycra,nylon,polyester&filter_size=extra-extra-large,extra-large,small,extra-small&orderby=price&unfilter=1
[Thu Jul 30 12:38:54.189729 2026] [core:notice] [pid 765155:tid 765168] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:54.294410 2026] [core:notice] [pid 765155:tid 765306] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:54.298424 2026] [security2:error] [pid 765155:tid 765306] [client 103.215.74.26:18304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMLuT5hFAbD-LhWHicbwAAAJo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:54.406556 2026] [security2:error] [pid 765155:tid 765382] [client 150.107.232.194:27325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMLuT5hFAbD-LhWHicdgAAAOY"]
[Thu Jul 30 12:38:54.406663 2026] [security2:error] [pid 765155:tid 765382] [client 150.107.232.194:27325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMLuT5hFAbD-LhWHicdgAAAOY"]
[Thu Jul 30 12:38:54.961754 2026] [security2:error] [pid 765155:tid 765350] [client 172.237.109.114:62601] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/id_rsa"] [unique_id "amuMLuT5hFAbD-LhWHichgAAAMY"]
[Thu Jul 30 12:38:54.972941 2026] [security2:error] [pid 765155:tid 765359] [client 172.237.109.114:9758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.ssh/id_dsa"] [unique_id "amuMLuT5hFAbD-LhWHicigAAAM8"]
[Thu Jul 30 12:38:54.977906 2026] [security2:error] [pid 765155:tid 765286] [client 172.237.109.114:59003] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/key.pem"] [unique_id "amuMLuT5hFAbD-LhWHicjAAAAIY"]
[Thu Jul 30 12:38:54.992789 2026] [security2:error] [pid 765155:tid 765300] [client 172.237.109.114:15601] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/id_dsa"] [unique_id "amuMLuT5hFAbD-LhWHicjQAAAJQ"]
[Thu Jul 30 12:38:55.009897 2026] [security2:error] [pid 765155:tid 765404] [client 172.237.109.114:47679] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.ssh/id_rsa"] [unique_id "amuML-T5hFAbD-LhWHickwAAAPw"]
[Thu Jul 30 12:38:55.010045 2026] [security2:error] [pid 765155:tid 765326] [client 172.237.109.114:56101] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/privatekey.key"] [unique_id "amuML-T5hFAbD-LhWHiclwAAAK4"]
[Thu Jul 30 12:38:55.034875 2026] [core:notice] [pid 765155:tid 765361] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:55.042097 2026] [security2:error] [pid 765155:tid 765361] [client 103.215.74.26:18314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuML-T5hFAbD-LhWHicmgAAANE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:55.365812 2026] [core:notice] [pid 765155:tid 765329] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:55.560771 2026] [core:notice] [pid 765155:tid 765332] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:55.740827 2026] [security2:error] [pid 765155:tid 765305] [client 20.215.191.139:5099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-includes.bak/html-api/about.php"] [unique_id "amuML-T5hFAbD-LhWHicrgAAAJk"]
[Thu Jul 30 12:38:55.788080 2026] [core:notice] [pid 765155:tid 765351] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:55.791992 2026] [security2:error] [pid 765155:tid 765351] [client 103.215.74.26:18316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "752"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuML-T5hFAbD-LhWHicsgAAAMc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:56.281865 2026] [security2:error] [pid 765155:tid 765325] [client 172.237.109.114:34834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMLuT5hFAbD-LhWHichwAAAK0"]
[Thu Jul 30 12:38:56.370529 2026] [security2:error] [pid 765155:tid 765353] [client 172.237.109.114:36418] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMLuT5hFAbD-LhWHicjwAAAMk"]
[Thu Jul 30 12:38:56.378198 2026] [security2:error] [pid 765155:tid 765327] [client 172.237.109.114:48270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMLuT5hFAbD-LhWHiciQAAAK8"]
[Thu Jul 30 12:38:56.401144 2026] [security2:error] [pid 765155:tid 765376] [client 172.237.109.114:55322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuML-T5hFAbD-LhWHiclQAAAOA"]
[Thu Jul 30 12:38:56.413458 2026] [security2:error] [pid 765155:tid 765328] [client 20.215.191.139:15330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-includes/widgets/about.php"] [unique_id "amuMMOT5hFAbD-LhWHicyQAAALA"]
[Thu Jul 30 12:38:56.424963 2026] [security2:error] [pid 765155:tid 765386] [client 172.237.109.114:65462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMLuT5hFAbD-LhWHickAAAAOo"]
[Thu Jul 30 12:38:56.425390 2026] [security2:error] [pid 765155:tid 765381] [client 172.237.109.114:33281] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuML-T5hFAbD-LhWHiclAAAAOU"]
[Thu Jul 30 12:38:56.434926 2026] [security2:error] [pid 765155:tid 765294] [client 172.237.109.114:3703] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuML-T5hFAbD-LhWHicmAAAAI4"]
[Thu Jul 30 12:38:56.444426 2026] [security2:error] [pid 765155:tid 765387] [client 172.237.109.114:49426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMLuT5hFAbD-LhWHickQAAAOs"]
[Thu Jul 30 12:38:56.447722 2026] [security2:error] [pid 765155:tid 765342] [client 172.237.109.114:19989] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuML-T5hFAbD-LhWHiclgAAAL4"]
[Thu Jul 30 12:38:56.449800 2026] [security2:error] [pid 765155:tid 765290] [client 172.237.109.114:41752] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMLuT5hFAbD-LhWHicjgAAAIo"]
[Thu Jul 30 12:38:56.455411 2026] [security2:error] [pid 765155:tid 765310] [client 172.237.109.114:3988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMLuT5hFAbD-LhWHickgAAAJ4"]
[Thu Jul 30 12:38:56.489028 2026] [core:notice] [pid 765155:tid 765373] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:56.498539 2026] [security2:error] [pid 765155:tid 765318] [client 172.237.109.114:47639] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMLuT5hFAbD-LhWHiciwAAAKY"]
[Thu Jul 30 12:38:56.503372 2026] [security2:error] [pid 765155:tid 765301] [client 172.237.109.114:22513] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuML-T5hFAbD-LhWHicmQAAAJU"]
[Thu Jul 30 12:38:56.557160 2026] [security2:error] [pid 765155:tid 765408] [client 172.237.109.114:37591] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMLuT5hFAbD-LhWHiciAAAAQA"]
[Thu Jul 30 12:38:56.561012 2026] [core:notice] [pid 765155:tid 765359] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:56.567036 2026] [security2:error] [pid 765155:tid 765359] [client 103.215.74.26:18332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMMOT5hFAbD-LhWHic1AAAAM8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:56.685252 2026] [security2:error] [pid 765155:tid 765374] [client 2a03:2880:f800:38:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuML-T5hFAbD-LhWHictgAA3mA"]
[Thu Jul 30 12:38:57.155860 2026] [security2:error] [pid 765155:tid 765305] [client 20.215.191.139:2919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-includes/IXR/about.php"] [unique_id "amuMMeT5hFAbD-LhWHic3wAAAJk"]
[Thu Jul 30 12:38:57.175697 2026] [security2:error] [pid 765155:tid 765334] [client 20.100.187.246:61089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/wpsml-sys.php"] [unique_id "amuMMeT5hFAbD-LhWHic4AAAALY"]
[Thu Jul 30 12:38:57.288500 2026] [core:notice] [pid 765155:tid 765346] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:57.297363 2026] [security2:error] [pid 765155:tid 765346] [client 103.215.74.26:18336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "764"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMMeT5hFAbD-LhWHic5QAAAMI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:57.467135 2026] [core:notice] [pid 765155:tid 765285] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:57.517194 2026] [security2:error] [pid 765155:tid 765324] [client 172.236.9.101:60061] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuML-T5hFAbD-LhWHicoAAAAKw"]
[Thu Jul 30 12:38:57.552860 2026] [security2:error] [pid 765155:tid 765339] [client 172.236.9.101:32877] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuML-T5hFAbD-LhWHicpAAAALs"]
[Thu Jul 30 12:38:57.573642 2026] [security2:error] [pid 765155:tid 765357] [client 172.236.9.101:9880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuML-T5hFAbD-LhWHicoQAAAM0"]
[Thu Jul 30 12:38:57.720028 2026] [fcgid:warn] [pid 765155:tid 765325] (70014)End of file found: [client 45.43.62.77:59364] mod_fcgid: can't get data from http client
[Thu Jul 30 12:38:58.030266 2026] [core:notice] [pid 765155:tid 765328] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:58.034438 2026] [security2:error] [pid 765155:tid 765328] [client 103.215.74.26:18346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "770"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMMuT5hFAbD-LhWHic-wAAALA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:58.145768 2026] [security2:error] [pid 765155:tid 765323] [client 20.215.191.139:2902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-admin/js/about.php"] [unique_id "amuMMuT5hFAbD-LhWHic_wAAAKs"]
[Thu Jul 30 12:38:58.235742 2026] [security2:error] [pid 765155:tid 765397] [client 172.236.9.101:10394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuML-T5hFAbD-LhWHicpQAAAPU"]
[Thu Jul 30 12:38:58.244526 2026] [security2:error] [pid 765155:tid 765298] [client 20.100.187.246:61723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/02.php"] [unique_id "amuMMuT5hFAbD-LhWHidAQAAAJI"]
[Thu Jul 30 12:38:58.246464 2026] [security2:error] [pid 765155:tid 765401] [client 172.236.9.101:41795] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuML-T5hFAbD-LhWHicqQAAAPk"]
[Thu Jul 30 12:38:58.357330 2026] [security2:error] [pid 765155:tid 765317] [client 172.236.9.101:45742] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuML-T5hFAbD-LhWHicpwAAAKU"]
[Thu Jul 30 12:38:58.399410 2026] [security2:error] [pid 765155:tid 765316] [client 172.236.9.101:40867] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMMOT5hFAbD-LhWHicwwAAAKQ"]
[Thu Jul 30 12:38:58.403680 2026] [security2:error] [pid 765155:tid 765362] [client 172.236.9.101:38510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuML-T5hFAbD-LhWHicqAAAANI"]
[Thu Jul 30 12:38:58.407337 2026] [security2:error] [pid 765155:tid 765307] [client 172.236.9.101:14228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMMOT5hFAbD-LhWHicxQAAAJs"]
[Thu Jul 30 12:38:58.427821 2026] [security2:error] [pid 765155:tid 765391] [client 172.236.9.101:1182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMMOT5hFAbD-LhWHicwAAAAO8"]
[Thu Jul 30 12:38:58.430257 2026] [security2:error] [pid 765155:tid 765378] [client 172.236.9.101:54676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMMOT5hFAbD-LhWHicwgAAAOI"]
[Thu Jul 30 12:38:58.446125 2026] [security2:error] [pid 765155:tid 765377] [client 172.236.9.101:57470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMMOT5hFAbD-LhWHicyAAAAOE"]
[Thu Jul 30 12:38:58.485542 2026] [security2:error] [pid 765155:tid 765344] [client 172.236.9.101:33431] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMMOT5hFAbD-LhWHiczQAAAMA"]
[Thu Jul 30 12:38:58.497056 2026] [security2:error] [pid 765155:tid 765352] [client 172.236.9.101:15732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMMOT5hFAbD-LhWHiczgAAAMg"]
[Thu Jul 30 12:38:58.501395 2026] [security2:error] [pid 765155:tid 765347] [client 172.236.9.101:37698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMMOT5hFAbD-LhWHicwQAAAMM"]
[Thu Jul 30 12:38:58.501411 2026] [security2:error] [pid 765155:tid 765295] [client 172.236.9.101:64583] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMMOT5hFAbD-LhWHicvwAAAI8"]
[Thu Jul 30 12:38:58.527887 2026] [security2:error] [pid 765155:tid 765341] [client 172.236.9.101:36942] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMMOT5hFAbD-LhWHicvgAAAL0"]
[Thu Jul 30 12:38:58.530109 2026] [security2:error] [pid 765155:tid 765303] [client 172.236.9.101:47515] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMMOT5hFAbD-LhWHicxwAAAJc"]
[Thu Jul 30 12:38:58.543609 2026] [security2:error] [pid 765155:tid 765321] [client 172.236.9.101:33851] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMMOT5hFAbD-LhWHicxAAAAKk"]
[Thu Jul 30 12:38:58.581087 2026] [security2:error] [pid 765155:tid 765348] [client 172.236.9.101:40979] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMMOT5hFAbD-LhWHiczAAAAMQ"]
[Thu Jul 30 12:38:58.775304 2026] [core:notice] [pid 765155:tid 765409] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:58.779798 2026] [security2:error] [pid 765155:tid 765409] [client 103.215.74.26:18354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMMuT5hFAbD-LhWHidDgAAAQE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:59.508840 2026] [core:notice] [pid 765155:tid 765289] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:59.512839 2026] [security2:error] [pid 765155:tid 765289] [client 103.215.74.26:18366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMM-T5hFAbD-LhWHidIgAAAIk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:59.740512 2026] [security2:error] [pid 765155:tid 765376] [client 20.215.191.139:12387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amuMM-T5hFAbD-LhWHidKgAAAOA"]
[Thu Jul 30 12:38:59.879493 2026] [security2:error] [pid 765155:tid 765359] [client 172.236.9.101:24073] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMM-T5hFAbD-LhWHidHAAAAM8"]
[Thu Jul 30 12:38:59.893792 2026] [security2:error] [pid 765155:tid 765319] [client 172.236.9.101:4631] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMM-T5hFAbD-LhWHidHQAAAKc"]
[Thu Jul 30 12:38:59.917276 2026] [security2:error] [pid 765155:tid 765356] [client 172.236.9.101:55810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMM-T5hFAbD-LhWHidIQAAAMw"]
[Thu Jul 30 12:38:59.921154 2026] [security2:error] [pid 765155:tid 765408] [client 172.236.9.101:7708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMM-T5hFAbD-LhWHidIAAAAQA"]
[Thu Jul 30 12:39:00.131158 2026] [security2:error] [pid 765155:tid 765173] [remote 195.178.110.211:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.choiceroofingservices.click"] [uri "/app/config/local.php"] [unique_id "amuMM-T5hFAbD-LhWHidKwAAyBE"]
[Thu Jul 30 12:39:00.245650 2026] [core:notice] [pid 765155:tid 765303] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:00.249612 2026] [security2:error] [pid 765155:tid 765303] [client 103.215.74.26:18380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMNOT5hFAbD-LhWHidNQAAAJc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:00.344334 2026] [security2:error] [pid 765155:tid 765189] [remote 195.178.110.211:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.choiceroofingservices.click"] [uri "/app/config/local.php.bak"] [unique_id "amuMNOT5hFAbD-LhWHidNgAArCE"]
[Thu Jul 30 12:39:00.567915 2026] [security2:error] [pid 765155:tid 765201] [remote 195.178.110.211:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.choiceroofingservices.click"] [uri "/mautic/app/config/local.php"] [unique_id "amuMNOT5hFAbD-LhWHidQgABAS0"]
[Thu Jul 30 12:39:00.749175 2026] [security2:error] [pid 765155:tid 765360] [client 20.63.98.115:20670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/sim.php/wp-includes/certificates/plugins.php"] [unique_id "amuMNOT5hFAbD-LhWHidSQAAANA"]
[Thu Jul 30 12:39:00.752095 2026] [security2:error] [pid 765155:tid 765184] [remote 195.178.110.211:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.choiceroofingservices.click"] [uri "/config/mail.php"] [unique_id "amuMNOT5hFAbD-LhWHidSgAAphw"]
[Thu Jul 30 12:39:00.907750 2026] [security2:error] [pid 765155:tid 765296] [client 172.236.9.101:30904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMNOT5hFAbD-LhWHidOAAAAJA"]
[Thu Jul 30 12:39:00.929443 2026] [security2:error] [pid 765155:tid 765345] [client 172.236.9.101:8990] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMNOT5hFAbD-LhWHidOQAAAME"]
[Thu Jul 30 12:39:00.935963 2026] [security2:error] [pid 765155:tid 765188] [remote 195.178.110.211:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.choiceroofingservices.click"] [uri "/config/services.php"] [unique_id "amuMNOT5hFAbD-LhWHidVAAAhiA"]
[Thu Jul 30 12:39:00.937827 2026] [security2:error] [pid 765155:tid 765375] [client 172.236.9.101:13732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMNOT5hFAbD-LhWHidNwAAAN8"]
[Thu Jul 30 12:39:00.961009 2026] [security2:error] [pid 765155:tid 765285] [client 172.236.9.101:21547] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMNOT5hFAbD-LhWHidOwAAAIU"]
[Thu Jul 30 12:39:00.961648 2026] [core:notice] [pid 765155:tid 765311] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:00.962869 2026] [security2:error] [pid 765155:tid 765368] [client 172.236.9.101:60497] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMNOT5hFAbD-LhWHidPgAAANg"]
[Thu Jul 30 12:39:00.966002 2026] [security2:error] [pid 765155:tid 765311] [client 103.215.74.26:18382] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMNOT5hFAbD-LhWHidVQAAAJ8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:00.969003 2026] [security2:error] [pid 765155:tid 765365] [client 172.236.9.101:31522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMNOT5hFAbD-LhWHidOgAAANU"]
[Thu Jul 30 12:39:00.973790 2026] [security2:error] [pid 765155:tid 765369] [client 172.236.9.101:55598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMNOT5hFAbD-LhWHidPQAAANk"]
[Thu Jul 30 12:39:01.120418 2026] [security2:error] [pid 765155:tid 765372] [client 20.215.191.139:7255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-includes/pomo/about.php"] [unique_id "amuMNeT5hFAbD-LhWHidVgAAANw"]
[Thu Jul 30 12:39:01.243284 2026] [core:notice] [pid 765155:tid 765322] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:01.431526 2026] [security2:error] [pid 765155:tid 765356] [client 47.128.121.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuMNeT5hFAbD-LhWHidYQAAAMw"]
[Thu Jul 30 12:39:01.718356 2026] [core:notice] [pid 765155:tid 765351] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:01.726566 2026] [security2:error] [pid 765155:tid 765351] [client 103.215.74.26:18396] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMNeT5hFAbD-LhWHiddwAAAMc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:01.966605 2026] [security2:error] [pid 765155:tid 765332] [client 20.63.98.115:61458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-seo.php"] [unique_id "amuMNeT5hFAbD-LhWHidegAAALQ"]
[Thu Jul 30 12:39:01.992870 2026] [security2:error] [pid 765155:tid 765377] [client 172.236.9.101:52591] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMNeT5hFAbD-LhWHidYgAAAOE"]
[Thu Jul 30 12:39:02.002948 2026] [security2:error] [pid 765155:tid 765392] [client 172.236.9.101:19346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMNeT5hFAbD-LhWHidYwAAAPA"]
[Thu Jul 30 12:39:02.020587 2026] [security2:error] [pid 765155:tid 765394] [client 172.236.9.101:37015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMNeT5hFAbD-LhWHidZwAAAPI"]
[Thu Jul 30 12:39:02.024799 2026] [security2:error] [pid 765155:tid 765336] [client 172.236.9.101:1791] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMNeT5hFAbD-LhWHidZAAAALg"]
[Thu Jul 30 12:39:02.061126 2026] [security2:error] [pid 765155:tid 765347] [client 172.236.9.101:14016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMNeT5hFAbD-LhWHidbQAAAMM"]
[Thu Jul 30 12:39:02.061129 2026] [security2:error] [pid 765155:tid 765408] [client 172.236.9.101:4560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMNeT5hFAbD-LhWHidZQAAAQA"]
[Thu Jul 30 12:39:02.061131 2026] [security2:error] [pid 765155:tid 765358] [client 172.236.9.101:8923] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMNeT5hFAbD-LhWHidZgAAAM4"]
[Thu Jul 30 12:39:02.061874 2026] [security2:error] [pid 765155:tid 765295] [client 172.236.9.101:53606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMNeT5hFAbD-LhWHidawAAAI8"]
[Thu Jul 30 12:39:02.068519 2026] [security2:error] [pid 765155:tid 765340] [client 172.236.9.101:50100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMNeT5hFAbD-LhWHidbAAAALw"]
[Thu Jul 30 12:39:02.355866 2026] [security2:error] [pid 765155:tid 765291] [client 57.141.0.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMNeT5hFAbD-LhWHiddQAAAIs"]
[Thu Jul 30 12:39:02.458764 2026] [core:notice] [pid 765155:tid 765345] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:02.466195 2026] [security2:error] [pid 765155:tid 765345] [client 103.215.74.26:18408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMNuT5hFAbD-LhWHidhwAAAME"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:02.803563 2026] [security2:error] [pid 765155:tid 765288] [client 20.63.98.115:63475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/zwso.php"] [unique_id "amuMNuT5hFAbD-LhWHidjwAAAIg"]
[Thu Jul 30 12:39:02.901527 2026] [security2:error] [pid 765155:tid 765334] [client 20.215.191.139:9291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-includes/block-patterns/about.php"] [unique_id "amuMNuT5hFAbD-LhWHidkwAAALY"]
[Thu Jul 30 12:39:03.203003 2026] [core:notice] [pid 765155:tid 765322] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:03.207331 2026] [security2:error] [pid 765155:tid 765322] [client 103.215.74.26:21904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMN-T5hFAbD-LhWHidlwAAAKo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:03.223556 2026] [core:notice] [pid 765155:tid 765289] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:03.309993 2026] [security2:error] [pid 765155:tid 765357] [client 38.190.144.4:56180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMN-T5hFAbD-LhWHidnwAAAM0"]
[Thu Jul 30 12:39:03.310091 2026] [security2:error] [pid 765155:tid 765357] [client 38.190.144.4:56180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMN-T5hFAbD-LhWHidnwAAAM0"]
[Thu Jul 30 12:39:03.960908 2026] [core:notice] [pid 765155:tid 765315] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:03.965263 2026] [security2:error] [pid 765155:tid 765315] [client 103.215.74.26:21920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMN-T5hFAbD-LhWHidqQAAAKM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:04.234178 2026] [security2:error] [pid 765155:tid 765359] [client 20.215.191.139:4081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/updraft/about.php"] [unique_id "amuMOOT5hFAbD-LhWHidrQAAAM8"]
[Thu Jul 30 12:39:04.339732 2026] [security2:error] [pid 765155:tid 765358] [client 20.63.98.115:49945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/user.php"] [unique_id "amuMOOT5hFAbD-LhWHidsQAAAM4"]
[Thu Jul 30 12:39:04.725159 2026] [core:notice] [pid 765155:tid 765390] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:04.729467 2026] [security2:error] [pid 765155:tid 765390] [client 103.215.74.26:21936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMOOT5hFAbD-LhWHiduAAAAO4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:04.896881 2026] [security2:error] [pid 765155:tid 765290] [client 150.107.232.194:26670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMOOT5hFAbD-LhWHiduwAAAIo"]
[Thu Jul 30 12:39:04.897001 2026] [security2:error] [pid 765155:tid 765290] [client 150.107.232.194:26670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMOOT5hFAbD-LhWHiduwAAAIo"]
[Thu Jul 30 12:39:05.081896 2026] [security2:error] [pid 765155:tid 765323] [client 20.215.191.139:7237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "amuMOeT5hFAbD-LhWHidxgAAAKs"]
[Thu Jul 30 12:39:05.135768 2026] [core:notice] [pid 765155:tid 765196] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:05.367551 2026] [security2:error] [pid 765155:tid 765287] [client 20.63.98.115:61476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/assets/index.php"] [unique_id "amuMOeT5hFAbD-LhWHidzAAAAIc"]
[Thu Jul 30 12:39:05.471693 2026] [core:notice] [pid 765155:tid 765397] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:05.476126 2026] [security2:error] [pid 765155:tid 765397] [client 103.215.74.26:21952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMOeT5hFAbD-LhWHid0QAAAPU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:05.757673 2026] [security2:error] [pid 765155:tid 765289] [client 20.100.187.246:61108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/infos.php"] [unique_id "amuMOeT5hFAbD-LhWHid1wAAAIk"]
[Thu Jul 30 12:39:06.222441 2026] [core:notice] [pid 765155:tid 765402] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:06.226848 2026] [security2:error] [pid 765155:tid 765402] [client 103.215.74.26:21956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMOuT5hFAbD-LhWHid4gAAAPo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:06.532748 2026] [security2:error] [pid 765155:tid 765294] [client 20.215.191.139:11300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/themes/about.php"] [unique_id "amuMOuT5hFAbD-LhWHid6gAAAI4"]
[Thu Jul 30 12:39:06.959257 2026] [core:notice] [pid 765155:tid 765395] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:06.963540 2026] [security2:error] [pid 765155:tid 765395] [client 103.215.74.26:21960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMOuT5hFAbD-LhWHid8gAAAPM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:07.706904 2026] [core:notice] [pid 765155:tid 765349] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:07.713626 2026] [security2:error] [pid 765155:tid 765349] [client 103.215.74.26:21968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMO-T5hFAbD-LhWHieBAAAAMU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:08.436283 2026] [core:notice] [pid 765155:tid 765407] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:08.440230 2026] [security2:error] [pid 765155:tid 765407] [client 103.215.74.26:21974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "761"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMPOT5hFAbD-LhWHieFQAAAP8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:08.658581 2026] [security2:error] [pid 765155:tid 765191] [remote 57.141.0.62:29102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/7514146397/feed/rss2/"] [unique_id "amuMPOT5hFAbD-LhWHieHAAAoCM"]
[Thu Jul 30 12:39:08.733829 2026] [security2:error] [pid 765155:tid 765408] [client 20.215.191.139:11311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-admin/includes/about.php"] [unique_id "amuMPOT5hFAbD-LhWHieHQAAAQA"]
[Thu Jul 30 12:39:09.163021 2026] [core:notice] [pid 765155:tid 765361] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:09.167048 2026] [security2:error] [pid 765155:tid 765361] [client 103.215.74.26:21976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMPeT5hFAbD-LhWHieKQAAANE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:09.267485 2026] [core:error] [pid 765155:tid 765245] [remote 74.7.230.46:33162] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:09.267505 2026] [core:error] [pid 765155:tid 765245] [remote 74.7.230.46:33162] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:09.267673 2026] [security2:error] [pid 765155:tid 765406] [client 74.7.230.46:33162] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuMPeT5hFAbD-LhWHieLwAA_lk"]
[Thu Jul 30 12:39:09.559796 2026] [security2:error] [pid 765155:tid 765372] [client 20.215.191.139:9305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/images/about.php"] [unique_id "amuMPeT5hFAbD-LhWHiePAAAANw"]
[Thu Jul 30 12:39:09.583497 2026] [security2:error] [pid 765155:tid 765386] [client 20.100.187.246:61057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/updates.php"] [unique_id "amuMPeT5hFAbD-LhWHieQAAAAOo"]
[Thu Jul 30 12:39:09.894314 2026] [core:notice] [pid 765155:tid 765341] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:09.898556 2026] [security2:error] [pid 765155:tid 765341] [client 103.215.74.26:21984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMPeT5hFAbD-LhWHieSQAAAL0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:10.352840 2026] [security2:error] [pid 765155:tid 765351] [client 20.215.191.139:15317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/blogs.dir/about.php"] [unique_id "amuMPuT5hFAbD-LhWHieUgAAAMc"]
[Thu Jul 30 12:39:10.638961 2026] [security2:error] [pid 765155:tid 765232] [remote 74.7.241.60:41034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/js/article.php"] [unique_id "amuMPuT5hFAbD-LhWHieVwAAw0w"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/js/bootstrap.bundle.min.js
[Thu Jul 30 12:39:10.683846 2026] [core:notice] [pid 765155:tid 765332] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:10.690491 2026] [security2:error] [pid 765155:tid 765332] [client 103.215.74.26:21986] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMPuT5hFAbD-LhWHieWAAAALQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:10.741195 2026] [autoindex:error] [pid 765155:tid 765307] [client 85.204.70.114:33040] AH01276: Cannot serve directory /home2/nxtudite/public_html/riisesolution.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:39:11.045739 2026] [autoindex:error] [pid 765155:tid 765285] [client 85.204.70.114:33040] AH01276: Cannot serve directory /home2/nxtudite/public_html/riisesolution.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:39:11.074951 2026] [security2:error] [pid 765155:tid 765326] [client 20.215.191.139:9334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-includes/images/about.php"] [unique_id "amuMP-T5hFAbD-LhWHieZwAAAK4"]
[Thu Jul 30 12:39:11.312101 2026] [security2:error] [pid 765155:tid 765399] [client 20.100.187.246:61155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/user.php"] [unique_id "amuMP-T5hFAbD-LhWHiebgAAAPc"]
[Thu Jul 30 12:39:11.330553 2026] [security2:error] [pid 765155:tid 765366] [client 85.204.70.114:33040] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riisesolution.com.nxt.udi.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuMP-T5hFAbD-LhWHiebwAAANY"]
[Thu Jul 30 12:39:11.432059 2026] [core:notice] [pid 765155:tid 765386] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:11.439018 2026] [security2:error] [pid 765155:tid 765386] [client 103.215.74.26:21998] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMP-T5hFAbD-LhWHiedQAAAOo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:11.849824 2026] [security2:error] [pid 765155:tid 765398] [client 20.215.191.139:12385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-includes/about.php"] [unique_id "amuMP-T5hFAbD-LhWHieiQAAAPY"]
[Thu Jul 30 12:39:11.856747 2026] [security2:error] [pid 765155:tid 765348] [client 85.204.70.114:33056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "riisesolution.com.nxt.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuMP-T5hFAbD-LhWHieigAAAMQ"]
[Thu Jul 30 12:39:11.871238 2026] [security2:error] [pid 765155:tid 765361] [client 2a03:2880:f800:3a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMP-T5hFAbD-LhWHiebQAA0X0"]
[Thu Jul 30 12:39:11.891128 2026] [security2:error] [pid 765155:tid 765290] [client 20.63.98.115:49954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/byp.php"] [unique_id "amuMP-T5hFAbD-LhWHieiwAAAIo"]
[Thu Jul 30 12:39:12.169749 2026] [core:notice] [pid 765155:tid 765360] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:12.175862 2026] [security2:error] [pid 765155:tid 765360] [client 103.215.74.26:22012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMQOT5hFAbD-LhWHiejQAAANA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:12.434516 2026] [security2:error] [pid 765155:tid 765404] [client 20.215.191.139:13350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/cgi-bin/about.php"] [unique_id "amuMQOT5hFAbD-LhWHielQAAAPw"]
[Thu Jul 30 12:39:12.473680 2026] [autoindex:error] [pid 765155:tid 765411] [client 85.204.70.114:33064] AH01276: Cannot serve directory /home2/nxtudite/public_html/riisesolution.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:39:12.829576 2026] [security2:error] [pid 765155:tid 765162] [remote 47.128.27.96:13134] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/dior-jacket-brown-and-black/"] [unique_id "amuMQOT5hFAbD-LhWHiemgAA3AY"]
[Thu Jul 30 12:39:12.926524 2026] [security2:error] [pid 765155:tid 765314] [client 20.63.98.115:63435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/bs1.php"] [unique_id "amuMQOT5hFAbD-LhWHienwAAAKI"]
[Thu Jul 30 12:39:12.927050 2026] [core:notice] [pid 765155:tid 765310] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:12.931151 2026] [security2:error] [pid 765155:tid 765310] [client 103.215.74.26:22028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "777"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMQOT5hFAbD-LhWHiengAAAJ4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:13.241766 2026] [security2:error] [pid 765155:tid 765364] [client 85.204.70.114:33064] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riisesolution.com.nxt.udi.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuMQeT5hFAbD-LhWHiepQAAANQ"]
[Thu Jul 30 12:39:13.710106 2026] [core:notice] [pid 765155:tid 765351] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:13.716846 2026] [security2:error] [pid 765155:tid 765351] [client 103.215.74.26:38506] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMQeT5hFAbD-LhWHieuAAAAMc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:13.806832 2026] [security2:error] [pid 765155:tid 765306] [client 20.63.98.115:60857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/IXR/allez.php"] [unique_id "amuMQeT5hFAbD-LhWHieuwAAAJo"]
[Thu Jul 30 12:39:13.895592 2026] [security2:error] [pid 765155:tid 765371] [client 2a03:2880:f800:28:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMQeT5hFAbD-LhWHiepgAA2y0"]
[Thu Jul 30 12:39:13.924798 2026] [security2:error] [pid 765155:tid 765290] [client 20.215.191.139:15324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/gallery/about.php"] [unique_id "amuMQeT5hFAbD-LhWHiewgAAAIo"]
[Thu Jul 30 12:39:14.266372 2026] [security2:error] [pid 765155:tid 765373] [client 38.190.144.4:56677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMQuT5hFAbD-LhWHieygAAAN0"]
[Thu Jul 30 12:39:14.266651 2026] [security2:error] [pid 765155:tid 765373] [client 38.190.144.4:56677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMQuT5hFAbD-LhWHieygAAAN0"]
[Thu Jul 30 12:39:14.305495 2026] [security2:error] [pid 765155:tid 765385] [client 85.204.70.114:33080] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riisesolution.com.nxt.udi.temporary.site"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuMQuT5hFAbD-LhWHieywAAAOk"]
[Thu Jul 30 12:39:14.438852 2026] [core:notice] [pid 765155:tid 765318] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:14.444411 2026] [security2:error] [pid 765155:tid 765318] [client 103.215.74.26:38520] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "790"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMQuT5hFAbD-LhWHie3QAAAKY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:14.665749 2026] [security2:error] [pid 765155:tid 765380] [client 204.8.98.25:39030] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuMQuT5hFAbD-LhWHie3wAAAOQ"]
[Thu Jul 30 12:39:14.666171 2026] [security2:error] [pid 765155:tid 765380] [client 204.8.98.25:39030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuMQuT5hFAbD-LhWHie3wAAAOQ"]
[Thu Jul 30 12:39:14.758831 2026] [security2:error] [pid 765155:tid 765375] [client 57.141.0.63:48800] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuMQuT5hFAbD-LhWHie2AAA3xg"], referer: https://igetvape-australia.com/product/iget-moon-pomegranate-kiwi-ice/?add-to-cart=175
[Thu Jul 30 12:39:14.799409 2026] [security2:error] [pid 765155:tid 765362] [client 85.204.70.114:33096] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riisesolution.com.nxt.udi.temporary.site"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuMQuT5hFAbD-LhWHie5gAAANI"]
[Thu Jul 30 12:39:15.151448 2026] [security2:error] [pid 765155:tid 765328] [client 85.204.70.114:33102] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riisesolution.com.nxt.udi.temporary.site"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuMQ-T5hFAbD-LhWHie7gAAALA"]
[Thu Jul 30 12:39:15.170954 2026] [core:notice] [pid 765155:tid 765389] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:15.174884 2026] [security2:error] [pid 765155:tid 765389] [client 103.215.74.26:38530] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMQ-T5hFAbD-LhWHie7wAAAO0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:15.278972 2026] [security2:error] [pid 765155:tid 765391] [client 20.63.98.115:47188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/load.php"] [unique_id "amuMQ-T5hFAbD-LhWHie8wAAAO8"]
[Thu Jul 30 12:39:15.316972 2026] [security2:error] [pid 765155:tid 765309] [client 172.236.9.101:25567] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQuT5hFAbD-LhWHie1QAAAJ0"]
[Thu Jul 30 12:39:15.333117 2026] [security2:error] [pid 765155:tid 765285] [client 172.236.9.101:43873] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQuT5hFAbD-LhWHie1AAAAIU"]
[Thu Jul 30 12:39:15.345359 2026] [security2:error] [pid 765155:tid 765381] [client 172.236.9.101:4920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQuT5hFAbD-LhWHie1wAAAOU"]
[Thu Jul 30 12:39:15.346036 2026] [security2:error] [pid 765155:tid 765390] [client 172.236.9.101:22928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQuT5hFAbD-LhWHie0wAAAO4"]
[Thu Jul 30 12:39:15.346444 2026] [security2:error] [pid 765155:tid 765393] [client 172.236.9.101:60349] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQuT5hFAbD-LhWHie0gAAAPE"]
[Thu Jul 30 12:39:15.347911 2026] [security2:error] [pid 765155:tid 765317] [client 172.236.9.101:38808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQuT5hFAbD-LhWHie1gAAAKU"]
[Thu Jul 30 12:39:15.353148 2026] [security2:error] [pid 765155:tid 765331] [client 172.236.9.101:49043] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQuT5hFAbD-LhWHie2QAAALM"]
[Thu Jul 30 12:39:15.374452 2026] [security2:error] [pid 765155:tid 765311] [client 172.236.9.101:43128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQuT5hFAbD-LhWHie2gAAAJ8"]
[Thu Jul 30 12:39:15.375335 2026] [security2:error] [pid 765155:tid 765329] [client 172.236.9.101:32523] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQuT5hFAbD-LhWHie3gAAALE"]
[Thu Jul 30 12:39:15.379627 2026] [security2:error] [pid 765155:tid 765343] [client 172.236.9.101:42554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQuT5hFAbD-LhWHie3AAAAL8"]
[Thu Jul 30 12:39:15.383043 2026] [security2:error] [pid 765155:tid 765292] [client 172.236.9.101:9267] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQuT5hFAbD-LhWHie2wAAAIw"]
[Thu Jul 30 12:39:15.386034 2026] [security2:error] [pid 765155:tid 765371] [client 150.107.232.194:26602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMQ-T5hFAbD-LhWHie_AAAANs"]
[Thu Jul 30 12:39:15.386168 2026] [security2:error] [pid 765155:tid 765371] [client 150.107.232.194:26602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMQ-T5hFAbD-LhWHie_AAAANs"]
[Thu Jul 30 12:39:15.714593 2026] [security2:error] [pid 765155:tid 765401] [client 85.204.70.114:33112] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riisesolution.com.nxt.udi.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuMQ-T5hFAbD-LhWHifDAAAAPk"]
[Thu Jul 30 12:39:15.887467 2026] [security2:error] [pid 765155:tid 765315] [client 172.236.9.101:46226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQ-T5hFAbD-LhWHie-gAAAKM"]
[Thu Jul 30 12:39:15.919726 2026] [core:notice] [pid 765155:tid 765322] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:15.925186 2026] [security2:error] [pid 765155:tid 765322] [client 103.215.74.26:38536] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "764"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMQ-T5hFAbD-LhWHifFAAAAKo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:16.230826 2026] [security2:error] [pid 765155:tid 765299] [client 172.236.9.101:60367] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQ-T5hFAbD-LhWHie-wAAAJM"]
[Thu Jul 30 12:39:16.233949 2026] [security2:error] [pid 765155:tid 765361] [client 172.236.9.101:42043] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQ-T5hFAbD-LhWHie_gAAANE"]
[Thu Jul 30 12:39:16.240552 2026] [security2:error] [pid 765155:tid 765408] [client 172.236.9.101:17508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQ-T5hFAbD-LhWHie_QAAAQA"]
[Thu Jul 30 12:39:16.242856 2026] [security2:error] [pid 765155:tid 765387] [client 172.236.9.101:36683] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQ-T5hFAbD-LhWHifAwAAAOs"]
[Thu Jul 30 12:39:16.245381 2026] [security2:error] [pid 765155:tid 765351] [client 172.236.9.101:44287] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQ-T5hFAbD-LhWHifBAAAAMc"]
[Thu Jul 30 12:39:16.247941 2026] [security2:error] [pid 765155:tid 765295] [client 172.236.9.101:61967] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQ-T5hFAbD-LhWHie_wAAAI8"]
[Thu Jul 30 12:39:16.261368 2026] [security2:error] [pid 765155:tid 765359] [client 172.236.9.101:20494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQ-T5hFAbD-LhWHifBgAAAM8"]
[Thu Jul 30 12:39:16.274242 2026] [security2:error] [pid 765155:tid 765338] [client 172.236.9.101:48054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQ-T5hFAbD-LhWHifBQAAALo"]
[Thu Jul 30 12:39:16.275600 2026] [security2:error] [pid 765155:tid 765339] [client 43.173.180.222:45792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.180.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/09/09/au-hasard-de-la-toile-3/"] [unique_id "amuMROT5hFAbD-LhWHifFQAAALs"]
[Thu Jul 30 12:39:16.301553 2026] [security2:error] [pid 765155:tid 765332] [client 85.204.70.114:33124] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riisesolution.com.nxt.udi.temporary.site"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuMROT5hFAbD-LhWHifHgAAALQ"]
[Thu Jul 30 12:39:16.399581 2026] [security2:error] [pid 765155:tid 765312] [client 43.173.182.142:41202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.182.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/12/01/noel-2013-20-idees-cadeaux-a-moins-de-5-euros/"] [unique_id "amuMROT5hFAbD-LhWHifGgAAAKA"]
[Thu Jul 30 12:39:16.758615 2026] [core:notice] [pid 765155:tid 765319] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:16.763282 2026] [security2:error] [pid 765155:tid 765319] [client 43.173.174.173:60294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/09/09/au-hasard-de-la-toile-3/"] [unique_id "amuMROT5hFAbD-LhWHifKQAAAKc"], referer: https://carnetdeshopping.com/index.php/2013/09/09/au-hasard-de-la-toile-3/
[Thu Jul 30 12:39:16.809707 2026] [core:error] [pid 765155:tid 765366] [client 74.7.228.4:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:16.809726 2026] [core:error] [pid 765155:tid 765366] [client 74.7.228.4:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:16.809846 2026] [security2:error] [pid 765155:tid 765366] [client 74.7.228.4:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.embassyofspaininpakistan.info"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amuMROT5hFAbD-LhWHifLwAAANY"]
[Thu Jul 30 12:39:16.810629 2026] [security2:error] [pid 765155:tid 765404] [client 74.7.228.4:50330] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.embassyofspaininpakistan.info"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amuMROT5hFAbD-LhWHifLQAA_EM"]
[Thu Jul 30 12:39:16.896047 2026] [security2:error] [pid 765155:tid 765345] [client 85.204.70.114:32868] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riisesolution.com.nxt.udi.temporary.site"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuMROT5hFAbD-LhWHifNgAAAME"]
[Thu Jul 30 12:39:16.933614 2026] [core:notice] [pid 765155:tid 765329] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:17.170354 2026] [core:notice] [pid 765155:tid 765397] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:17.175154 2026] [security2:error] [pid 765155:tid 765397] [client 43.172.197.93:53532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/12/01/noel-2013-20-idees-cadeaux-a-moins-de-5-euros/"] [unique_id "amuMReT5hFAbD-LhWHifPAAAAPU"], referer: https://carnetdeshopping.com/index.php/2013/12/01/noel-2013-20-idees-cadeaux-a-moins-de-5-euros/
[Thu Jul 30 12:39:17.451353 2026] [security2:error] [pid 765155:tid 765338] [client 85.204.70.114:32878] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riisesolution.com.nxt.udi.temporary.site"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuMReT5hFAbD-LhWHifSAAAALo"]
[Thu Jul 30 12:39:17.980598 2026] [security2:error] [pid 765155:tid 765353] [client 85.204.70.114:32894] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riisesolution.com.nxt.udi.temporary.site"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuMReT5hFAbD-LhWHifVgAAAMk"]
[Thu Jul 30 12:39:18.047835 2026] [security2:error] [pid 765155:tid 765376] [client 193.37.252.99:44096] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMReT5hFAbD-LhWHifTAAAAOA"]
[Thu Jul 30 12:39:18.047963 2026] [security2:error] [pid 765155:tid 765376] [client 193.37.252.99:44096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMReT5hFAbD-LhWHifTAAAAOA"]
[Thu Jul 30 12:39:18.082609 2026] [security2:error] [pid 765155:tid 765367] [client 20.63.98.115:60837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/privacy.php"] [unique_id "amuMRuT5hFAbD-LhWHifVwAAANc"]
[Thu Jul 30 12:39:18.390527 2026] [security2:error] [pid 765155:tid 765347] [client 20.215.191.139:7282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuMRuT5hFAbD-LhWHifZQAAAMM"]
[Thu Jul 30 12:39:18.465670 2026] [security2:error] [pid 765155:tid 765337] [client 85.204.70.114:32898] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riisesolution.com.nxt.udi.temporary.site"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuMRuT5hFAbD-LhWHifaQAAALk"]
[Thu Jul 30 12:39:18.898006 2026] [security2:error] [pid 765155:tid 765360] [client 20.100.187.246:64986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/admin-ajax.php"] [unique_id "amuMRuT5hFAbD-LhWHifcwAAANA"]
[Thu Jul 30 12:39:19.054795 2026] [security2:error] [pid 765155:tid 765329] [client 20.215.191.139:42484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-admin/css/about.php"] [unique_id "amuMR-T5hFAbD-LhWHifegAAALE"]
[Thu Jul 30 12:39:19.332573 2026] [security2:error] [pid 765155:tid 765290] [client 2a03:2880:f800:35:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMRuT5hFAbD-LhWHifYgAAilE"]
[Thu Jul 30 12:39:19.521854 2026] [security2:error] [pid 765155:tid 765355] [client 2a03:2880:f800:6:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMRuT5hFAbD-LhWHifagAAy0g"]
[Thu Jul 30 12:39:19.581580 2026] [security2:error] [pid 765155:tid 765168] [remote 57.141.0.19:35840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuMR-T5hFAbD-LhWHifjQAAzww"]
[Thu Jul 30 12:39:19.628635 2026] [security2:error] [pid 765155:tid 765304] [client 20.63.98.115:61471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-cli.php"] [unique_id "amuMR-T5hFAbD-LhWHifjgAAAJg"]
[Thu Jul 30 12:39:20.133362 2026] [security2:error] [pid 765155:tid 765337] [client 85.204.70.114:32912] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riisesolution.com.nxt.udi.temporary.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuMSOT5hFAbD-LhWHifowAAALk"]
[Thu Jul 30 12:39:20.230791 2026] [security2:error] [pid 765155:tid 765410] [client 43.157.53.115:35398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.53.157.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/jibm/issue/current"] [unique_id "amuMR-T5hFAbD-LhWHifngAAAQI"], referer: https://ejournalugj.com/index_php/jibm/issue/current
[Thu Jul 30 12:39:20.337478 2026] [security2:error] [pid 765155:tid 765252] [remote 57.141.0.63:32306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/674008491/feed/rss2/"] [unique_id "amuMSOT5hFAbD-LhWHifsAAAzWA"]
[Thu Jul 30 12:39:20.683474 2026] [security2:error] [pid 765155:tid 765316] [client 2a03:2880:f800:2c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMSOT5hFAbD-LhWHifogAApGo"]
[Thu Jul 30 12:39:20.685840 2026] [security2:error] [pid 765155:tid 765315] [client 85.204.70.114:32918] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riisesolution.com.nxt.udi.temporary.site"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuMSOT5hFAbD-LhWHifuwAAAKM"]
[Thu Jul 30 12:39:20.707606 2026] [core:notice] [pid 765155:tid 765234] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:21.107315 2026] [security2:error] [pid 765155:tid 765399] [client 20.215.191.139:15351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-admin/images/about.php"] [unique_id "amuMSeT5hFAbD-LhWHifywAAAPc"]
[Thu Jul 30 12:39:21.361448 2026] [security2:error] [pid 765155:tid 765359] [client 85.204.70.114:32920] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riisesolution.com.nxt.udi.temporary.site"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuMSeT5hFAbD-LhWHif0AAAAM8"]
[Thu Jul 30 12:39:21.506743 2026] [core:notice] [pid 765155:tid 765309] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:21.542839 2026] [security2:error] [pid 765155:tid 765298] [client 20.100.187.246:61124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/alfa.php"] [unique_id "amuMSeT5hFAbD-LhWHif1AAAAJI"]
[Thu Jul 30 12:39:21.671494 2026] [core:notice] [pid 765155:tid 765345] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:21.675416 2026] [security2:error] [pid 765155:tid 765345] [client 103.215.74.26:38538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "770"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMSeT5hFAbD-LhWHif3AAAAME"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:22.068163 2026] [security2:error] [pid 765155:tid 765353] [client 20.215.191.139:42534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/cloud.php"] [unique_id "amuMSuT5hFAbD-LhWHif5gAAAMk"]
[Thu Jul 30 12:39:22.700110 2026] [core:notice] [pid 765155:tid 765336] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:22.806911 2026] [security2:error] [pid 765155:tid 765382] [client 85.204.70.114:32922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riisesolution.com.nxt.udi.temporary.site"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuMSuT5hFAbD-LhWHigAAAAAOY"]
[Thu Jul 30 12:39:23.013518 2026] [security2:error] [pid 765155:tid 765403] [client 20.215.191.139:42535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/acme-challenge/cloud.php"] [unique_id "amuMS-T5hFAbD-LhWHigBwAAAPs"]
[Thu Jul 30 12:39:23.476421 2026] [security2:error] [pid 765155:tid 765355] [client 85.204.70.114:32936] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riisesolution.com.nxt.udi.temporary.site"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuMS-T5hFAbD-LhWHigHAAAAMs"]
[Thu Jul 30 12:39:23.929258 2026] [security2:error] [pid 765155:tid 765307] [client 172.236.9.101:27997] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMS-T5hFAbD-LhWHigDwAAAJs"]
[Thu Jul 30 12:39:24.003151 2026] [security2:error] [pid 765155:tid 765399] [client 172.236.9.101:17730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMS-T5hFAbD-LhWHigEgAAAPc"]
[Thu Jul 30 12:39:24.003936 2026] [security2:error] [pid 765155:tid 765311] [client 172.236.9.101:55263] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMS-T5hFAbD-LhWHigFwAAAJ8"]
[Thu Jul 30 12:39:24.026426 2026] [security2:error] [pid 765155:tid 765390] [client 172.236.9.101:20318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMS-T5hFAbD-LhWHigGQAAAO4"]
[Thu Jul 30 12:39:24.034271 2026] [security2:error] [pid 765155:tid 765343] [client 172.236.9.101:24512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMS-T5hFAbD-LhWHigGAAAAL8"]
[Thu Jul 30 12:39:24.042722 2026] [security2:error] [pid 765155:tid 765392] [client 172.236.9.101:20834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMS-T5hFAbD-LhWHigFgAAAPA"]
[Thu Jul 30 12:39:24.052070 2026] [core:error] [pid 765155:tid 765294] [client 20.100.187.246:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:24.052098 2026] [core:error] [pid 765155:tid 765294] [client 20.100.187.246:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:24.080675 2026] [security2:error] [pid 765155:tid 765359] [client 172.236.9.101:29514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMS-T5hFAbD-LhWHigGwAAAM8"]
[Thu Jul 30 12:39:24.231186 2026] [security2:error] [pid 765155:tid 765350] [client 38.190.144.4:57197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMTOT5hFAbD-LhWHigMAAAAMY"]
[Thu Jul 30 12:39:24.231314 2026] [security2:error] [pid 765155:tid 765350] [client 38.190.144.4:57197] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMTOT5hFAbD-LhWHigMAAAAMY"]
[Thu Jul 30 12:39:24.949473 2026] [security2:error] [pid 765155:tid 765316] [client 119.73.97.132:29860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuMTOT5hFAbD-LhWHigSwAApDM"], referer: https://www.urwru.club/emm-elevate/?preview_id=685&preview_nonce=6cdd8f071f&preview=true&aaeid=1
[Thu Jul 30 12:39:25.245509 2026] [security2:error] [pid 765155:tid 765337] [client 172.236.9.101:9498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMTOT5hFAbD-LhWHigNQAAALk"]
[Thu Jul 30 12:39:25.264224 2026] [security2:error] [pid 765155:tid 765291] [client 172.236.9.101:19021] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMTOT5hFAbD-LhWHigNAAAAIs"]
[Thu Jul 30 12:39:25.285390 2026] [security2:error] [pid 765155:tid 765356] [client 172.236.9.101:44838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMTOT5hFAbD-LhWHigOQAAAMw"]
[Thu Jul 30 12:39:25.293874 2026] [security2:error] [pid 765155:tid 765327] [client 172.236.9.101:22622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMTOT5hFAbD-LhWHigOAAAAK8"]
[Thu Jul 30 12:39:25.306068 2026] [security2:error] [pid 765155:tid 765388] [client 72.62.248.216:46548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuMTOT5hFAbD-LhWHigUgAA7Bg"]
[Thu Jul 30 12:39:25.313274 2026] [security2:error] [pid 765155:tid 765373] [client 172.236.9.101:13719] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMTOT5hFAbD-LhWHigOwAAAN0"]
[Thu Jul 30 12:39:25.334061 2026] [security2:error] [pid 765155:tid 765364] [client 172.236.9.101:56359] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMTOT5hFAbD-LhWHigPAAAANQ"]
[Thu Jul 30 12:39:25.344699 2026] [security2:error] [pid 765155:tid 765318] [client 172.236.9.101:23221] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMTOT5hFAbD-LhWHigPQAAAKY"]
[Thu Jul 30 12:39:25.370230 2026] [security2:error] [pid 765155:tid 765308] [client 20.63.98.115:47179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/cc.php"] [unique_id "amuMTeT5hFAbD-LhWHigYAAAAJw"]
[Thu Jul 30 12:39:25.404657 2026] [security2:error] [pid 765155:tid 765383] [client 172.236.9.101:53988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/ssl/private/alseermarine.com_key.pem"] [unique_id "amuMTeT5hFAbD-LhWHigYwAAAOc"]
[Thu Jul 30 12:39:25.434159 2026] [security2:error] [pid 765155:tid 765400] [client 172.236.9.101:18486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMTOT5hFAbD-LhWHigQQAAAPg"]
[Thu Jul 30 12:39:25.436781 2026] [security2:error] [pid 765155:tid 765374] [client 172.236.9.101:35411] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMTOT5hFAbD-LhWHigPgAAAN4"]
[Thu Jul 30 12:39:25.437561 2026] [security2:error] [pid 765155:tid 765334] [client 172.236.9.101:5323] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMTOT5hFAbD-LhWHigPwAAALY"]
[Thu Jul 30 12:39:25.440104 2026] [security2:error] [pid 765155:tid 765386] [client 172.236.9.101:25414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMTOT5hFAbD-LhWHigQAAAAOo"]
[Thu Jul 30 12:39:25.442560 2026] [security2:error] [pid 765155:tid 765384] [client 172.236.9.101:13345] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMTOT5hFAbD-LhWHigQgAAAOg"]
[Thu Jul 30 12:39:25.539098 2026] [security2:error] [pid 765155:tid 765345] [client 194.187.251.163:45144] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuMTeT5hFAbD-LhWHigXAAAAME"]
[Thu Jul 30 12:39:25.539220 2026] [security2:error] [pid 765155:tid 765345] [client 194.187.251.163:45144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuMTeT5hFAbD-LhWHigXAAAAME"]
[Thu Jul 30 12:39:25.629230 2026] [security2:error] [pid 765155:tid 765324] [client 119.73.97.132:29860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuMTeT5hFAbD-LhWHigXQAArB8"]
[Thu Jul 30 12:39:25.650036 2026] [security2:error] [pid 765155:tid 765324] [client 119.73.97.132:29860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuMTeT5hFAbD-LhWHigXgAArCs"]
[Thu Jul 30 12:39:25.797775 2026] [security2:error] [pid 765155:tid 765390] [client 72.62.248.216:46548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuMTeT5hFAbD-LhWHigZAAA7jg"]
[Thu Jul 30 12:39:25.932661 2026] [security2:error] [pid 765155:tid 765325] [client 150.107.232.194:27436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMTeT5hFAbD-LhWHigewAAAK0"]
[Thu Jul 30 12:39:25.932774 2026] [security2:error] [pid 765155:tid 765325] [client 150.107.232.194:27436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMTeT5hFAbD-LhWHigewAAAK0"]
[Thu Jul 30 12:39:26.042449 2026] [security2:error] [pid 765155:tid 765204] [remote 74.7.241.59:56376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuMTuT5hFAbD-LhWHigfwAAkzA"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/backup_1784717747
[Thu Jul 30 12:39:26.666582 2026] [security2:error] [pid 765155:tid 765309] [client 20.215.191.139:30374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-admin/network/cloud.php"] [unique_id "amuMTuT5hFAbD-LhWHigkQAAAJ0"]
[Thu Jul 30 12:39:27.023642 2026] [security2:error] [pid 765155:tid 765317] [client 20.63.98.115:47223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/media-new.php"] [unique_id "amuMT-T5hFAbD-LhWHignwAAAKU"]
[Thu Jul 30 12:39:27.025595 2026] [security2:error] [pid 765155:tid 765361] [client 20.100.187.246:60169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/hehe.php"] [unique_id "amuMT-T5hFAbD-LhWHigoAAAANE"]
[Thu Jul 30 12:39:27.334257 2026] [security2:error] [pid 765155:tid 765385] [client 20.104.16.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laduchessecollections.com"] [uri "/index.php"] [unique_id "amuMTeT5hFAbD-LhWHigaAAA6Sw"]
[Thu Jul 30 12:39:27.397651 2026] [core:notice] [pid 765155:tid 765412] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:27.403288 2026] [security2:error] [pid 765155:tid 765412] [client 103.215.74.26:5674] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMT-T5hFAbD-LhWHigrAAAAQQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:28.159558 2026] [core:notice] [pid 765155:tid 765333] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:28.163323 2026] [security2:error] [pid 765155:tid 765333] [client 103.215.74.26:5680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMUOT5hFAbD-LhWHigxQAAALU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:28.454809 2026] [security2:error] [pid 765155:tid 765303] [client 20.63.98.115:61931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-blog.php"] [unique_id "amuMUOT5hFAbD-LhWHig0gAAAJc"]
[Thu Jul 30 12:39:28.483411 2026] [security2:error] [pid 765155:tid 765334] [client 20.100.187.246:62390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/rk2.php"] [unique_id "amuMUOT5hFAbD-LhWHig1AAAALY"]
[Thu Jul 30 12:39:28.617834 2026] [core:notice] [pid 765155:tid 765287] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:29.457357 2026] [security2:error] [pid 765155:tid 765295] [client 20.100.187.246:62354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/setup-config.php"] [unique_id "amuMUeT5hFAbD-LhWHig8wAAAI8"]
[Thu Jul 30 12:39:30.247584 2026] [security2:error] [pid 765155:tid 765369] [client 20.215.191.139:12668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/cloud.php"] [unique_id "amuMUuT5hFAbD-LhWHihDwAAANk"]
[Thu Jul 30 12:39:31.332190 2026] [security2:error] [pid 765155:tid 765409] [client 20.100.187.246:61154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/a7.php"] [unique_id "amuMU-T5hFAbD-LhWHihOwAAAQE"]
[Thu Jul 30 12:39:31.667926 2026] [security2:error] [pid 765155:tid 765300] [client 20.215.191.139:14963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/cgi-bin/cloud.php"] [unique_id "amuMU-T5hFAbD-LhWHihSAAAAJQ"]
[Thu Jul 30 12:39:31.784133 2026] [security2:error] [pid 765155:tid 765338] [client 185.206.81.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMUuT5hFAbD-LhWHihNAAAulg"], referer: https://allmontecristi.com
[Thu Jul 30 12:39:32.184485 2026] [security2:error] [pid 765155:tid 765368] [client 20.63.98.115:57261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-2019.php"] [unique_id "amuMVOT5hFAbD-LhWHihUwAAANg"]
[Thu Jul 30 12:39:32.452405 2026] [security2:error] [pid 765155:tid 765322] [client 20.215.191.139:42507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/updates.php"] [unique_id "amuMVOT5hFAbD-LhWHihXQAAAKo"]
[Thu Jul 30 12:39:33.110291 2026] [security2:error] [pid 765155:tid 765398] [client 20.215.191.139:14947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/css/cloud.php"] [unique_id "amuMVeT5hFAbD-LhWHihcQAAAPY"]
[Thu Jul 30 12:39:33.915542 2026] [security2:error] [pid 765155:tid 765291] [client 20.63.98.115:20913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/menu.php"] [unique_id "amuMVeT5hFAbD-LhWHihiAAAAIs"]
[Thu Jul 30 12:39:33.917345 2026] [security2:error] [pid 765155:tid 765385] [client 20.215.191.139:14724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-admin/user/cloud.php"] [unique_id "amuMVeT5hFAbD-LhWHihiQAAAOk"]
[Thu Jul 30 12:39:33.930012 2026] [core:notice] [pid 765155:tid 765365] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:33.933881 2026] [security2:error] [pid 765155:tid 765365] [client 103.215.74.26:61704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMVeT5hFAbD-LhWHihigAAANU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:34.292944 2026] [security2:error] [pid 765155:tid 765172] [remote 72.167.132.114:50964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jgp.fxh.temporary.site"] [uri "/wp-login.php"] [unique_id "amuMVuT5hFAbD-LhWHihkgAArxA"]
[Thu Jul 30 12:39:34.295581 2026] [security2:error] [pid 765155:tid 765411] [client 20.100.187.246:64350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/f7.php"] [unique_id "amuMVuT5hFAbD-LhWHihkwAAAQM"]
[Thu Jul 30 12:39:34.649942 2026] [core:notice] [pid 765155:tid 765342] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:34.654389 2026] [security2:error] [pid 765155:tid 765342] [client 103.215.74.26:61708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMVuT5hFAbD-LhWHihnQAAAL4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:34.935854 2026] [security2:error] [pid 765155:tid 765328] [client 20.100.187.246:61174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/nw.php"] [unique_id "amuMVuT5hFAbD-LhWHihpwAAALA"]
[Thu Jul 30 12:39:35.023183 2026] [security2:error] [pid 765155:tid 765312] [client 20.215.191.139:42526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/img/cloud.php"] [unique_id "amuMV-T5hFAbD-LhWHihqAAAAKA"]
[Thu Jul 30 12:39:35.386617 2026] [core:notice] [pid 765155:tid 765367] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:35.390986 2026] [security2:error] [pid 765155:tid 765367] [client 103.215.74.26:61712] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMV-T5hFAbD-LhWHihtAAAANc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:35.807825 2026] [security2:error] [pid 765155:tid 765383] [client 20.63.98.115:57219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-crons.php"] [unique_id "amuMV-T5hFAbD-LhWHihvQAAAOc"]
[Thu Jul 30 12:39:36.116617 2026] [core:notice] [pid 765155:tid 765407] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:36.120833 2026] [security2:error] [pid 765155:tid 765407] [client 103.215.74.26:61726] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMWOT5hFAbD-LhWHihzgAAAP8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:36.464819 2026] [security2:error] [pid 765155:tid 765356] [client 150.107.232.194:26772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMWOT5hFAbD-LhWHih3QAAAMw"]
[Thu Jul 30 12:39:36.464914 2026] [security2:error] [pid 765155:tid 765356] [client 150.107.232.194:26772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMWOT5hFAbD-LhWHih3QAAAMw"]
[Thu Jul 30 12:39:36.616850 2026] [core:error] [pid 765155:tid 765364] [client 156.229.16.165:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:36.616877 2026] [core:error] [pid 765155:tid 765364] [client 156.229.16.165:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:36.845194 2026] [core:notice] [pid 765155:tid 765318] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:36.849545 2026] [security2:error] [pid 765155:tid 765318] [client 103.215.74.26:61730] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMWOT5hFAbD-LhWHih7QAAAKY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:36.950120 2026] [security2:error] [pid 765155:tid 765305] [client 20.215.191.139:15003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "amuMWOT5hFAbD-LhWHih9QAAAJk"]
[Thu Jul 30 12:39:37.918085 2026] [security2:error] [pid 765155:tid 765380] [client 20.100.187.246:62364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/ova.php"] [unique_id "amuMWeT5hFAbD-LhWHiiHwAAAOQ"]
[Thu Jul 30 12:39:38.129682 2026] [security2:error] [pid 765155:tid 765356] [client 74.7.228.39:34126] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cmv.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amuMWuT5hFAbD-LhWHiiJwAAAMw"]
[Thu Jul 30 12:39:38.315753 2026] [security2:error] [pid 765155:tid 765293] [client 20.63.98.115:61951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/class.php"] [unique_id "amuMWuT5hFAbD-LhWHiiYwAAAI0"]
[Thu Jul 30 12:39:38.349337 2026] [security2:error] [pid 765155:tid 765288] [client 20.215.191.139:4750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-admin/images/cloud.php"] [unique_id "amuMWuT5hFAbD-LhWHiiZAAAAIg"]
[Thu Jul 30 12:39:39.174957 2026] [security2:error] [pid 765155:tid 765357] [client 20.63.98.115:21430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/login.php"] [unique_id "amuMW-T5hFAbD-LhWHiilQAAAM0"]
[Thu Jul 30 12:39:39.448134 2026] [security2:error] [pid 765155:tid 765405] [client 20.215.191.139:14740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/avaa.php"] [unique_id "amuMW-T5hFAbD-LhWHiingAAAP0"]
[Thu Jul 30 12:39:39.917598 2026] [core:error] [pid 765155:tid 765367] [client 20.63.98.115:61892] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:39.917618 2026] [core:error] [pid 765155:tid 765367] [client 20.63.98.115:61892] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:41.325145 2026] [core:notice] [pid 765155:tid 765203] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:41.384361 2026] [security2:error] [pid 765155:tid 765368] [client 20.100.187.246:64429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/robots.php"] [unique_id "amuMXeT5hFAbD-LhWHii4AAAANg"]
[Thu Jul 30 12:39:41.629412 2026] [core:notice] [pid 765155:tid 765187] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:41.788295 2026] [security2:error] [pid 765155:tid 765292] [client 103.98.129.76:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMXOT5hFAbD-LhWHii0wAAjCY"], referer: https://allmontecristi.com
[Thu Jul 30 12:39:42.031637 2026] [security2:error] [pid 765155:tid 765312] [client 20.63.98.115:54585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/aged.php"] [unique_id "amuMXuT5hFAbD-LhWHii8wAAAKA"]
[Thu Jul 30 12:39:42.210142 2026] [core:error] [pid 765155:tid 765379] [client 156.229.16.165:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:42.210165 2026] [core:error] [pid 765155:tid 765379] [client 156.229.16.165:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:42.467633 2026] [security2:error] [pid 765155:tid 765402] [client 20.215.191.139:14967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/images/cloud.php"] [unique_id "amuMXuT5hFAbD-LhWHijAAAAAPo"]
[Thu Jul 30 12:39:42.586082 2026] [core:notice] [pid 765155:tid 765397] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:42.590537 2026] [security2:error] [pid 765155:tid 765397] [client 103.215.74.26:61736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMXuT5hFAbD-LhWHijAQAAAPU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:42.886545 2026] [security2:error] [pid 765155:tid 765304] [client 20.63.98.115:61901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/vv.php"] [unique_id "amuMXuT5hFAbD-LhWHijCwAAAJg"]
[Thu Jul 30 12:39:43.327177 2026] [core:notice] [pid 765155:tid 765350] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:43.331784 2026] [security2:error] [pid 765155:tid 765350] [client 103.215.74.26:64442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMX-T5hFAbD-LhWHijHQAAAMY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:43.580323 2026] [security2:error] [pid 765155:tid 765357] [client 20.215.191.139:7756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-admin/js/widgets/cloud.php"] [unique_id "amuMX-T5hFAbD-LhWHijJAAAAM0"]
[Thu Jul 30 12:39:44.100700 2026] [core:notice] [pid 765155:tid 765286] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:44.105200 2026] [security2:error] [pid 765155:tid 765286] [client 103.215.74.26:64444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMYOT5hFAbD-LhWHijMwAAAIY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:44.147214 2026] [security2:error] [pid 765155:tid 765411] [client 20.63.98.115:62019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/user-edit.php"] [unique_id "amuMYOT5hFAbD-LhWHijNwAAAQM"]
[Thu Jul 30 12:39:44.870383 2026] [core:notice] [pid 765155:tid 765338] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:44.874790 2026] [security2:error] [pid 765155:tid 765338] [client 103.215.74.26:64450] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMYOT5hFAbD-LhWHijSgAAALo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:45.125524 2026] [core:notice] [pid 765155:tid 765358] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:45.214413 2026] [security2:error] [pid 765155:tid 765388] [client 20.63.98.115:42956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "amuMYeT5hFAbD-LhWHijVwAAAOw"]
[Thu Jul 30 12:39:45.372719 2026] [security2:error] [pid 765155:tid 765342] [client 20.215.191.139:7782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-includes/Requests/Text/admin.php"] [unique_id "amuMYeT5hFAbD-LhWHijXAAAAL4"]
[Thu Jul 30 12:39:45.616482 2026] [core:notice] [pid 765155:tid 765336] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:45.624840 2026] [security2:error] [pid 765155:tid 765336] [client 103.215.74.26:64466] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMYeT5hFAbD-LhWHijYwAAALg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:45.630610 2026] [security2:error] [pid 765155:tid 765317] [client 20.100.187.246:59525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/alf.php"] [unique_id "amuMYeT5hFAbD-LhWHijZAAAAKU"]
[Thu Jul 30 12:39:45.782864 2026] [security2:error] [pid 765155:tid 765372] [client 38.190.144.4:58352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMYeT5hFAbD-LhWHijawAAANw"]
[Thu Jul 30 12:39:45.782986 2026] [security2:error] [pid 765155:tid 765372] [client 38.190.144.4:58352] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMYeT5hFAbD-LhWHijawAAANw"]
[Thu Jul 30 12:39:46.190828 2026] [security2:error] [pid 765155:tid 765390] [client 20.215.191.139:60860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "amuMYuT5hFAbD-LhWHijeQAAAO4"]
[Thu Jul 30 12:39:46.385211 2026] [core:notice] [pid 765155:tid 765375] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:46.389513 2026] [security2:error] [pid 765155:tid 765375] [client 103.215.74.26:64480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMYuT5hFAbD-LhWHijggAAAN8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:46.453999 2026] [security2:error] [pid 765155:tid 765288] [client 57.141.0.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMYeT5hFAbD-LhWHijbgAAAIg"]
[Thu Jul 30 12:39:46.930805 2026] [security2:error] [pid 765155:tid 765293] [client 150.107.232.194:26917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMYuT5hFAbD-LhWHijlQAAAI0"]
[Thu Jul 30 12:39:46.930935 2026] [security2:error] [pid 765155:tid 765293] [client 150.107.232.194:26917] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMYuT5hFAbD-LhWHijlQAAAI0"]
[Thu Jul 30 12:39:47.005313 2026] [security2:error] [pid 765155:tid 765315] [client 172.236.9.101:47661] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMYuT5hFAbD-LhWHijgQAAAKM"]
[Thu Jul 30 12:39:47.005370 2026] [security2:error] [pid 765155:tid 765330] [client 172.236.9.101:42590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMYuT5hFAbD-LhWHijgAAAALI"]
[Thu Jul 30 12:39:47.010033 2026] [security2:error] [pid 765155:tid 765320] [client 172.236.9.101:37891] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMYuT5hFAbD-LhWHijgwAAAKg"]
[Thu Jul 30 12:39:47.130169 2026] [security2:error] [pid 765155:tid 765324] [client 20.63.98.115:38867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/engine.php"] [unique_id "amuMY-T5hFAbD-LhWHijnwAAAKw"]
[Thu Jul 30 12:39:47.331842 2026] [security2:error] [pid 765155:tid 765298] [client 20.215.191.139:2696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-admin/includes/cloud.php"] [unique_id "amuMY-T5hFAbD-LhWHijpwAAAJI"]
[Thu Jul 30 12:39:47.335083 2026] [security2:error] [pid 765155:tid 765310] [client 74.7.241.144:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "webdisk.koinjp189.com"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuMY-T5hFAbD-LhWHijpgAAAJ4"]
[Thu Jul 30 12:39:47.600170 2026] [security2:error] [pid 765155:tid 765390] [client 20.100.187.246:60412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/feedback.php"] [unique_id "amuMY-T5hFAbD-LhWHijuQAAAO4"]
[Thu Jul 30 12:39:47.678128 2026] [lsapi:error] [pid 765155:tid 765170] [remote 41.210.167.242:0] [host flixon.net] Error receiving response: ReceiveResponse: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1009; user ID 1009), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://flixon.net/video/the-killer-vj-junior/
[Thu Jul 30 12:39:47.705770 2026] [security2:error] [pid 765155:tid 765387] [client 2a03:2880:f800:2c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMY-T5hFAbD-LhWHijngAA63E"]
[Thu Jul 30 12:39:47.897931 2026] [security2:error] [pid 765155:tid 765409] [client 172.236.9.101:2318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMY-T5hFAbD-LhWHijqwAAAQE"]
[Thu Jul 30 12:39:47.898750 2026] [security2:error] [pid 765155:tid 765308] [client 172.236.9.101:18861] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMY-T5hFAbD-LhWHijrAAAAJw"]
[Thu Jul 30 12:39:48.002323 2026] [security2:error] [pid 765155:tid 765338] [client 74.7.228.6:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-ed9bceb3.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuMY-T5hFAbD-LhWHijuAAAALo"]
[Thu Jul 30 12:39:48.003021 2026] [security2:error] [pid 765155:tid 765309] [client 74.7.228.6:38796] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-ed9bceb3.glb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuMY-T5hFAbD-LhWHijtgAAnU4"]
[Thu Jul 30 12:39:48.296418 2026] [security2:error] [pid 765155:tid 765381] [client 20.215.191.139:60845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-admin/css/colors/blue/cloud.php"] [unique_id "amuMZOT5hFAbD-LhWHijzAAAAOU"]
[Thu Jul 30 12:39:48.928916 2026] [core:error] [pid 765155:tid 765298] [client 156.229.16.165:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:48.928942 2026] [core:error] [pid 765155:tid 765298] [client 156.229.16.165:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:48.952013 2026] [security2:error] [pid 765155:tid 765360] [client 57.141.0.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMZOT5hFAbD-LhWHijzwAAANA"]
[Thu Jul 30 12:39:49.229470 2026] [security2:error] [pid 765155:tid 765344] [client 20.100.187.246:33844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/gettest.php"] [unique_id "amuMZeT5hFAbD-LhWHikAwAAAMA"]
[Thu Jul 30 12:39:49.258381 2026] [security2:error] [pid 765155:tid 765348] [client 20.215.191.139:3776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-admin/cloud.php"] [unique_id "amuMZeT5hFAbD-LhWHikBAAAAMQ"]
[Thu Jul 30 12:39:49.350572 2026] [security2:error] [pid 765155:tid 765347] [client 57.141.0.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMZOT5hFAbD-LhWHij4AAAAMM"]
[Thu Jul 30 12:39:49.447513 2026] [security2:error] [pid 765155:tid 765342] [client 20.63.98.115:61420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/edit-comments.php"] [unique_id "amuMZeT5hFAbD-LhWHikEwAAAL4"]
[Thu Jul 30 12:39:49.603864 2026] [core:notice] [pid 765155:tid 765209] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:49.848638 2026] [proxy:error] [pid 765155:tid 765350] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:39:49.848733 2026] [proxy_http:error] [pid 765155:tid 765350] [client 34.233.129.35:1577] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:39:49.849469 2026] [proxy:error] [pid 765155:tid 765350] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:39:49.849521 2026] [proxy_http:error] [pid 765155:tid 765350] [client 34.233.129.35:1577] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:39:49.861518 2026] [proxy:error] [pid 765155:tid 765355] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:39:49.861629 2026] [proxy_http:error] [pid 765155:tid 765355] [client 34.224.175.62:18202] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:39:49.862504 2026] [proxy:error] [pid 765155:tid 765355] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:39:49.862571 2026] [proxy_http:error] [pid 765155:tid 765355] [client 34.224.175.62:18202] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:39:49.883412 2026] [security2:error] [pid 765155:tid 765322] [client 172.236.9.101:51672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMZeT5hFAbD-LhWHikCQAAAKo"]
[Thu Jul 30 12:39:49.883807 2026] [security2:error] [pid 765155:tid 765363] [client 172.236.9.101:30488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMZeT5hFAbD-LhWHikCAAAANM"]
[Thu Jul 30 12:39:49.904083 2026] [security2:error] [pid 765155:tid 765323] [client 172.236.9.101:48071] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMZeT5hFAbD-LhWHikDgAAAKs"]
[Thu Jul 30 12:39:49.919398 2026] [security2:error] [pid 765155:tid 765403] [client 172.236.9.101:24433] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMZeT5hFAbD-LhWHikEAAAAPs"]
[Thu Jul 30 12:39:49.991523 2026] [security2:error] [pid 765155:tid 765385] [client 20.100.187.246:60589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/maint.php"] [unique_id "amuMZeT5hFAbD-LhWHikKwAAAOk"]
[Thu Jul 30 12:39:50.607097 2026] [security2:error] [pid 765155:tid 765313] [client 74.7.228.42:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.frontierphoenix.site"] [uri "/index.php"] [unique_id "amuMZeT5hFAbD-LhWHikKgAAoTM"]
[Thu Jul 30 12:39:50.607129 2026] [security2:error] [pid 765155:tid 765313] [client 74.7.228.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.frontierphoenix.site"] [uri "/index.php"] [unique_id "amuMZeT5hFAbD-LhWHikKgAAoTM"]
[Thu Jul 30 12:39:50.758087 2026] [security2:error] [pid 765155:tid 765290] [client 20.63.98.115:61914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-blog-header.php"] [unique_id "amuMZuT5hFAbD-LhWHikSgAAAIo"]
[Thu Jul 30 12:39:50.776217 2026] [security2:error] [pid 765155:tid 765330] [client 20.215.191.139:30292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/updates.php"] [unique_id "amuMZuT5hFAbD-LhWHikSwAAALI"]
[Thu Jul 30 12:39:50.857897 2026] [security2:error] [pid 765155:tid 765411] [client 172.236.9.101:63456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMZuT5hFAbD-LhWHikMwAAAQM"]
[Thu Jul 30 12:39:50.915198 2026] [security2:error] [pid 765155:tid 765300] [client 172.236.9.101:44096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMZuT5hFAbD-LhWHikNAAAAJQ"]
[Thu Jul 30 12:39:51.624632 2026] [security2:error] [pid 765155:tid 765382] [client 74.7.228.42:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "frontierphoenix.site"] [uri "/index.php"] [unique_id "amuMZ-T5hFAbD-LhWHikZAAA5kY"], referer: https://www.frontierphoenix.site/robots.txt
[Thu Jul 30 12:39:51.671437 2026] [security2:error] [pid 765155:tid 765316] [client 20.63.98.115:42973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/alfa-rex.php7"] [unique_id "amuMZ-T5hFAbD-LhWHikcAAAAKQ"]
[Thu Jul 30 12:39:51.867157 2026] [security2:error] [pid 765155:tid 765307] [client 172.236.9.101:45098] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMZ-T5hFAbD-LhWHikWgAAAJs"]
[Thu Jul 30 12:39:51.894512 2026] [security2:error] [pid 765155:tid 765350] [client 172.236.9.101:12116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMZ-T5hFAbD-LhWHikXwAAAMY"]
[Thu Jul 30 12:39:51.930925 2026] [security2:error] [pid 765155:tid 765322] [client 172.236.9.101:53508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMZ-T5hFAbD-LhWHikYAAAAKo"]
[Thu Jul 30 12:39:51.981230 2026] [security2:error] [pid 765155:tid 765374] [client 20.215.191.139:3751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/libraries/legacy/updates.php"] [unique_id "amuMZ-T5hFAbD-LhWHikewAAAN4"]
[Thu Jul 30 12:39:52.112665 2026] [core:notice] [pid 765155:tid 765298] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:52.116570 2026] [security2:error] [pid 765155:tid 765298] [client 103.215.74.26:64488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "761"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMaOT5hFAbD-LhWHikfwAAAJI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:52.431756 2026] [core:notice] [pid 765155:tid 765304] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:52.437937 2026] [security2:error] [pid 765155:tid 765314] [client 2a03:2880:f800:17:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMZ-T5hFAbD-LhWHikdwAAol4"]
[Thu Jul 30 12:39:52.570276 2026] [core:error] [pid 765155:tid 765377] [client 20.63.98.115:21114] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:52.570312 2026] [core:error] [pid 765155:tid 765377] [client 20.63.98.115:21114] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:52.724845 2026] [security2:error] [pid 765155:tid 765342] [client 69.158.246.168:53753] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuMaOT5hFAbD-LhWHikkgAAvlA"]
[Thu Jul 30 12:39:52.808034 2026] [core:notice] [pid 765155:tid 765330] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:52.843662 2026] [security2:error] [pid 765155:tid 765319] [client 172.236.9.101:19620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMaOT5hFAbD-LhWHikhwAAAKc"]
[Thu Jul 30 12:39:52.859321 2026] [core:notice] [pid 765155:tid 765308] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:52.863300 2026] [security2:error] [pid 765155:tid 765308] [client 103.215.74.26:64492] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMaOT5hFAbD-LhWHikmwAAAJw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:53.115783 2026] [core:notice] [pid 765155:tid 765337] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:53.346562 2026] [core:notice] [pid 765155:tid 765370] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:53.470926 2026] [core:error] [pid 765155:tid 765288] [client 20.63.98.115:32938] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:53.470948 2026] [core:error] [pid 765155:tid 765288] [client 20.63.98.115:32938] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:53.605812 2026] [core:notice] [pid 765155:tid 765404] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:53.609951 2026] [security2:error] [pid 765155:tid 765404] [client 103.215.74.26:45702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMaeT5hFAbD-LhWHikrwAAAPw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:53.674495 2026] [core:notice] [pid 765155:tid 765245] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:53.814022 2026] [security2:error] [pid 765155:tid 765411] [client 20.215.191.139:2974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/libraries/phpmailer/updates.php"] [unique_id "amuMaeT5hFAbD-LhWHiktwAAAQM"]
[Thu Jul 30 12:39:53.925172 2026] [security2:error] [pid 765155:tid 765313] [client 69.158.246.168:53753] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuMaeT5hFAbD-LhWHikuwAAoV0"]
[Thu Jul 30 12:39:54.096861 2026] [core:error] [pid 765155:tid 765333] [client 156.229.16.165:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:54.096885 2026] [core:error] [pid 765155:tid 765333] [client 156.229.16.165:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:54.337836 2026] [core:notice] [pid 765155:tid 765365] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:54.348667 2026] [security2:error] [pid 765155:tid 765365] [client 103.215.74.26:45718] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMauT5hFAbD-LhWHik0AAAANU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:54.588497 2026] [security2:error] [pid 765155:tid 765330] [client 69.158.246.168:53753] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuMauT5hFAbD-LhWHik1wAAsmg"]
[Thu Jul 30 12:39:54.679785 2026] [security2:error] [pid 765155:tid 765306] [client 57.141.0.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMauT5hFAbD-LhWHikwwAAAJo"]
[Thu Jul 30 12:39:54.795417 2026] [security2:error] [pid 765155:tid 765390] [client 57.141.0.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMauT5hFAbD-LhWHikyQAAAO4"]
[Thu Jul 30 12:39:55.099756 2026] [core:notice] [pid 765155:tid 765381] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:55.106506 2026] [security2:error] [pid 765155:tid 765381] [client 103.215.74.26:45732] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMa-T5hFAbD-LhWHik6QAAAOU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:55.231143 2026] [security2:error] [pid 765155:tid 765287] [client 69.158.246.168:53753] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuMa-T5hFAbD-LhWHik6gAAhz8"]
[Thu Jul 30 12:39:55.251285 2026] [security2:error] [pid 765155:tid 765334] [client 20.215.191.139:13179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/libraries/vendor/updates.php"] [unique_id "amuMa-T5hFAbD-LhWHik6wAAALY"]
[Thu Jul 30 12:39:55.706169 2026] [security2:error] [pid 765155:tid 765261] [remote 57.141.0.69:46530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/55276018792/feed/rss2/"] [unique_id "amuMa-T5hFAbD-LhWHilAQAAyGk"]
[Thu Jul 30 12:39:55.746301 2026] [security2:error] [pid 765155:tid 765402] [client 69.158.246.168:53753] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuMa-T5hFAbD-LhWHilAAAA-hU"]
[Thu Jul 30 12:39:55.839326 2026] [core:notice] [pid 765155:tid 765407] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:55.843329 2026] [security2:error] [pid 765155:tid 765407] [client 103.215.74.26:45738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMa-T5hFAbD-LhWHilCAAAAP8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:55.866113 2026] [security2:error] [pid 765155:tid 765349] [client 20.215.191.139:31292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/alfa-rex.php7"] [unique_id "amuMa-T5hFAbD-LhWHilCQAAAMU"]
[Thu Jul 30 12:39:55.943385 2026] [security2:error] [pid 765155:tid 765359] [client 20.63.98.115:21091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/pomo/fgertreyersd.php"] [unique_id "amuMa-T5hFAbD-LhWHilDgAAAM8"]
[Thu Jul 30 12:39:56.542652 2026] [security2:error] [pid 765155:tid 765330] [client 38.190.144.4:58850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMbOT5hFAbD-LhWHilKQAAALI"]
[Thu Jul 30 12:39:56.542861 2026] [security2:error] [pid 765155:tid 765330] [client 38.190.144.4:58850] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMbOT5hFAbD-LhWHilKQAAALI"]
[Thu Jul 30 12:39:56.594186 2026] [core:notice] [pid 765155:tid 765337] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:56.601244 2026] [security2:error] [pid 765155:tid 765337] [client 103.215.74.26:45754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "777"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMbOT5hFAbD-LhWHilKgAAALk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:56.896605 2026] [security2:error] [pid 765155:tid 765363] [client 172.236.9.101:39355] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMbOT5hFAbD-LhWHilGwAAANM"]
[Thu Jul 30 12:39:56.896605 2026] [security2:error] [pid 765155:tid 765403] [client 172.236.9.101:31578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMbOT5hFAbD-LhWHilGAAAAPs"]
[Thu Jul 30 12:39:57.008785 2026] [security2:error] [pid 765155:tid 765390] [client 172.236.9.101:58060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMbOT5hFAbD-LhWHilHQAAAO4"]
[Thu Jul 30 12:39:57.018388 2026] [security2:error] [pid 765155:tid 765299] [client 172.236.9.101:27392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMbOT5hFAbD-LhWHilHwAAAJM"]
[Thu Jul 30 12:39:57.022802 2026] [security2:error] [pid 765155:tid 765369] [client 172.236.9.101:64491] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMbOT5hFAbD-LhWHilHgAAANk"]
[Thu Jul 30 12:39:57.069183 2026] [security2:error] [pid 765155:tid 765339] [client 20.63.98.115:32912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/css/xmrlpc.php"] [unique_id "amuMbeT5hFAbD-LhWHilOAAAALs"]
[Thu Jul 30 12:39:57.331680 2026] [core:notice] [pid 765155:tid 765291] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:57.338643 2026] [security2:error] [pid 765155:tid 765291] [client 103.215.74.26:45762] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMbeT5hFAbD-LhWHilOQAAAIs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:57.516714 2026] [security2:error] [pid 765155:tid 765400] [client 20.100.187.246:61558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/files.php"] [unique_id "amuMbeT5hFAbD-LhWHilRwAAAPg"]
[Thu Jul 30 12:39:57.523877 2026] [autoindex:error] [pid 765155:tid 765296] [client 43.134.163.229:0] AH01276: Cannot serve directory /home2/mbmudite/ok.otbola.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://ok.otbola.click
[Thu Jul 30 12:39:57.967242 2026] [security2:error] [pid 765155:tid 765319] [client 20.215.191.139:2399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/alfanew.php"] [unique_id "amuMbeT5hFAbD-LhWHilUgAAAKc"]
[Thu Jul 30 12:39:58.062742 2026] [core:notice] [pid 765155:tid 765379] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:58.066648 2026] [security2:error] [pid 765155:tid 765379] [client 103.215.74.26:45764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "790"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMbuT5hFAbD-LhWHilVgAAAOM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:58.376911 2026] [security2:error] [pid 765155:tid 765308] [client 20.63.98.115:21077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/classsmtps.php"] [unique_id "amuMbuT5hFAbD-LhWHilWQAAAJw"]
[Thu Jul 30 12:39:58.410867 2026] [security2:error] [pid 765155:tid 765381] [client 150.107.232.194:27215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMbuT5hFAbD-LhWHilWwAAAOU"]
[Thu Jul 30 12:39:58.411032 2026] [security2:error] [pid 765155:tid 765381] [client 150.107.232.194:27215] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMbuT5hFAbD-LhWHilWwAAAOU"]
[Thu Jul 30 12:39:58.786655 2026] [core:notice] [pid 765155:tid 765350] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:58.790401 2026] [security2:error] [pid 765155:tid 765350] [client 103.215.74.26:45770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMbuT5hFAbD-LhWHilZwAAAMY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:59.303011 2026] [security2:error] [pid 765155:tid 765286] [client 47.128.27.194:27720] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.carnetdeshopping.com"] [uri "/robots.txt"] [unique_id "amuMb-T5hFAbD-LhWHilewAAAIY"]
[Thu Jul 30 12:39:59.521586 2026] [core:notice] [pid 765155:tid 765300] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:59.525519 2026] [security2:error] [pid 765155:tid 765300] [client 103.215.74.26:45776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "763"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMb-T5hFAbD-LhWHilhwAAAJQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:59.739169 2026] [security2:error] [pid 765155:tid 765362] [client 139.28.219.70:41490] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "google-search.org"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuMb-T5hFAbD-LhWHiljgAAANI"]
[Thu Jul 30 12:39:59.814179 2026] [security2:error] [pid 765155:tid 765407] [client 57.141.0.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMb-T5hFAbD-LhWHilegAAAP8"]
[Thu Jul 30 12:39:59.824674 2026] [security2:error] [pid 765155:tid 765299] [client 2a03:2880:f800:3a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMb-T5hFAbD-LhWHildgAAkwU"]
[Thu Jul 30 12:39:59.885330 2026] [security2:error] [pid 765155:tid 765378] [client 172.236.9.101:12256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMb-T5hFAbD-LhWHilfgAAAOI"]
[Thu Jul 30 12:40:00.017374 2026] [security2:error] [pid 765155:tid 765356] [client 20.100.187.246:63961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/gecko.php"] [unique_id "amuMcOT5hFAbD-LhWHillQAAAMw"]
[Thu Jul 30 12:40:00.076588 2026] [security2:error] [pid 765155:tid 765369] [client 20.63.98.115:39100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/themes/zMousse/otuz1.php"] [unique_id "amuMcOT5hFAbD-LhWHilmQAAANk"]
[Thu Jul 30 12:40:00.139125 2026] [security2:error] [pid 765155:tid 765408] [client 139.28.219.70:41506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "google-search.org"] [uri "/xmlrpc.php"] [unique_id "amuMcOT5hFAbD-LhWHilmgAAAQA"]
[Thu Jul 30 12:40:00.262142 2026] [core:notice] [pid 765155:tid 765385] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:00.266058 2026] [security2:error] [pid 765155:tid 765385] [client 103.215.74.26:45792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "769"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMcOT5hFAbD-LhWHilogAAAOk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:00.872969 2026] [security2:error] [pid 765155:tid 765316] [client 172.236.9.101:12877] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMcOT5hFAbD-LhWHilowAAAKQ"]
[Thu Jul 30 12:40:00.898553 2026] [security2:error] [pid 765155:tid 765337] [client 172.236.9.101:25932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMcOT5hFAbD-LhWHilpQAAALk"]
[Thu Jul 30 12:40:00.962854 2026] [security2:error] [pid 765155:tid 765292] [client 172.236.9.101:58391] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMcOT5hFAbD-LhWHilpAAAAIw"]
[Thu Jul 30 12:40:00.986247 2026] [core:notice] [pid 765155:tid 765305] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:00.993665 2026] [security2:error] [pid 765155:tid 765305] [client 103.215.74.26:45798] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMcOT5hFAbD-LhWHilugAAAJk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:01.015661 2026] [security2:error] [pid 765155:tid 765374] [client 172.236.9.101:51758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMcOT5hFAbD-LhWHilpgAAAN4"]
[Thu Jul 30 12:40:01.086191 2026] [security2:error] [pid 765155:tid 765302] [client 139.28.219.70:41518] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "google-search.org"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuMceT5hFAbD-LhWHilwQAAAJY"]
[Thu Jul 30 12:40:01.288336 2026] [core:error] [pid 765155:tid 765163] [remote 195.178.110.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://massageandspaislamabad.rest/
[Thu Jul 30 12:40:01.288361 2026] [core:error] [pid 765155:tid 765163] [remote 195.178.110.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://massageandspaislamabad.rest/
[Thu Jul 30 12:40:01.396038 2026] [security2:error] [pid 765155:tid 765383] [client 139.28.219.70:45732] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "google-search.org"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuMceT5hFAbD-LhWHilzgAAAOc"]
[Thu Jul 30 12:40:01.679470 2026] [security2:error] [pid 765155:tid 765381] [client 139.28.219.70:45744] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "google-search.org"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuMceT5hFAbD-LhWHil2wAAAOU"]
[Thu Jul 30 12:40:01.716958 2026] [core:notice] [pid 765155:tid 765314] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:01.721035 2026] [security2:error] [pid 765155:tid 765314] [client 103.215.74.26:45804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMceT5hFAbD-LhWHil3AAAAKI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:01.780787 2026] [core:error] [pid 765155:tid 765336] [client 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:01.780810 2026] [core:error] [pid 765155:tid 765336] [client 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:01.814916 2026] [core:error] [pid 765155:tid 765391] [client 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:01.814939 2026] [core:error] [pid 765155:tid 765391] [client 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:01.838432 2026] [core:error] [pid 765155:tid 765404] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:01.838455 2026] [core:error] [pid 765155:tid 765404] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:01.941738 2026] [security2:error] [pid 765155:tid 765350] [client 139.28.219.70:45748] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "google-search.org"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuMceT5hFAbD-LhWHil8wAAAMY"]
[Thu Jul 30 12:40:01.944498 2026] [core:error] [pid 765155:tid 765373] [client 158.69.117.45:20957] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:01.944516 2026] [core:error] [pid 765155:tid 765373] [client 158.69.117.45:20957] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:02.070507 2026] [security2:error] [pid 765155:tid 765403] [client 156.59.105.1:65163] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "911"] [severity "CRITICAL"] [tag "SQLi"] [hostname "jesus.claims"] [uri "/wp-json/batch/v1"] [unique_id "amuMcuT5hFAbD-LhWHil9wAAAPs"]
[Thu Jul 30 12:40:02.302746 2026] [security2:error] [pid 765155:tid 765358] [client 139.28.219.70:45754] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "google-search.org"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuMcuT5hFAbD-LhWHimAgAAAM4"]
[Thu Jul 30 12:40:02.364241 2026] [security2:error] [pid 765155:tid 765347] [client 20.100.187.246:33127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/zwso.php"] [unique_id "amuMcuT5hFAbD-LhWHimAwAAAMM"]
[Thu Jul 30 12:40:02.469419 2026] [core:notice] [pid 765155:tid 765302] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:02.473392 2026] [security2:error] [pid 765155:tid 765302] [client 103.215.74.26:45816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMcuT5hFAbD-LhWHimBQAAAJY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:02.614268 2026] [security2:error] [pid 765155:tid 765354] [client 139.28.219.70:45762] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "google-search.org"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuMcuT5hFAbD-LhWHimCAAAAMo"]
[Thu Jul 30 12:40:02.766411 2026] [core:error] [pid 765155:tid 765296] [client 158.69.117.45:20164] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:02.766444 2026] [core:error] [pid 765155:tid 765296] [client 158.69.117.45:20164] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:02.901359 2026] [core:error] [pid 765155:tid 765330] [client 158.69.117.45:23083] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:02.901387 2026] [core:error] [pid 765155:tid 765330] [client 158.69.117.45:23083] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:02.906623 2026] [security2:error] [pid 765155:tid 765393] [client 139.28.219.70:45774] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "google-search.org"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuMcuT5hFAbD-LhWHimFQAAAPE"]
[Thu Jul 30 12:40:03.185177 2026] [core:notice] [pid 765155:tid 765410] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:03.192104 2026] [security2:error] [pid 765155:tid 765410] [client 103.215.74.26:2126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMc-T5hFAbD-LhWHimIwAAAQI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:03.196463 2026] [proxy:error] [pid 765155:tid 765372] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:40:03.196523 2026] [proxy_http:error] [pid 765155:tid 765372] [client 3.225.222.228:29297] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:40:03.197345 2026] [proxy:error] [pid 765155:tid 765372] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:40:03.197402 2026] [proxy_http:error] [pid 765155:tid 765372] [client 3.225.222.228:29297] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:40:03.219022 2026] [security2:error] [pid 765155:tid 765373] [client 139.28.219.70:45776] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "google-search.org"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuMc-T5hFAbD-LhWHimKAAAAN0"]
[Thu Jul 30 12:40:03.252585 2026] [proxy:error] [pid 765155:tid 765334] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:40:03.252680 2026] [proxy_http:error] [pid 765155:tid 765334] [client 3.225.222.228:15037] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:40:03.253265 2026] [proxy:error] [pid 765155:tid 765334] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:40:03.253319 2026] [proxy_http:error] [pid 765155:tid 765334] [client 3.225.222.228:15037] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:40:03.303865 2026] [security2:error] [pid 765155:tid 765362] [client 20.63.98.115:61424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/123.php"] [unique_id "amuMc-T5hFAbD-LhWHimMQAAANI"]
[Thu Jul 30 12:40:03.545440 2026] [security2:error] [pid 765155:tid 765412] [client 139.28.219.70:45788] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "google-search.org"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuMc-T5hFAbD-LhWHimNQAAAQQ"]
[Thu Jul 30 12:40:03.634042 2026] [core:error] [pid 765155:tid 765298] [client 158.69.117.45:40399] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:03.634073 2026] [core:error] [pid 765155:tid 765298] [client 158.69.117.45:40399] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:03.873992 2026] [security2:error] [pid 765155:tid 765291] [client 20.100.187.246:33473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/13.php"] [unique_id "amuMc-T5hFAbD-LhWHimSQAAAIs"]
[Thu Jul 30 12:40:03.889859 2026] [security2:error] [pid 765155:tid 765401] [client 139.28.219.70:45792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "google-search.org"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuMc-T5hFAbD-LhWHimSgAAAPk"]
[Thu Jul 30 12:40:04.233629 2026] [security2:error] [pid 765155:tid 765379] [client 139.28.219.70:45808] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "google-search.org"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuMdOT5hFAbD-LhWHimVAAAAOM"]
[Thu Jul 30 12:40:04.556676 2026] [security2:error] [pid 765155:tid 765340] [client 139.28.219.70:45810] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "google-search.org"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuMdOT5hFAbD-LhWHimWwAAALw"]
[Thu Jul 30 12:40:04.782501 2026] [security2:error] [pid 765155:tid 765388] [client 20.215.191.139:31229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/plugins/Cache/Cache.php"] [unique_id "amuMdOT5hFAbD-LhWHimXwAAAOw"]
[Thu Jul 30 12:40:04.855516 2026] [security2:error] [pid 765155:tid 765314] [client 20.100.187.246:59101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/ava.php"] [unique_id "amuMdOT5hFAbD-LhWHimYAAAAKI"]
[Thu Jul 30 12:40:04.883562 2026] [security2:error] [pid 765155:tid 765350] [client 139.28.219.70:45826] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "google-search.org"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuMdOT5hFAbD-LhWHimYQAAAMY"]
[Thu Jul 30 12:40:04.910706 2026] [core:notice] [pid 765155:tid 765384] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:05.191957 2026] [security2:error] [pid 765155:tid 765356] [client 139.28.219.70:45840] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "google-search.org"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuMdeT5hFAbD-LhWHimbAAAAMw"]
[Thu Jul 30 12:40:05.442264 2026] [security2:error] [pid 765155:tid 765403] [client 20.215.191.139:33601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-admin/js/widgets/about.php7"] [unique_id "amuMdeT5hFAbD-LhWHimeAAAAPs"]
[Thu Jul 30 12:40:05.450897 2026] [core:notice] [pid 765155:tid 765243] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:05.792495 2026] [security2:error] [pid 765155:tid 765248] [remote 57.141.0.37:42446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuMdeT5hFAbD-LhWHimigAAkFw"]
[Thu Jul 30 12:40:05.913684 2026] [security2:error] [pid 765155:tid 765339] [client 172.236.9.101:44283] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMdeT5hFAbD-LhWHimcAAAALs"]
[Thu Jul 30 12:40:05.931147 2026] [security2:error] [pid 765155:tid 765313] [client 20.63.98.115:61421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "amuMdeT5hFAbD-LhWHimiwAAAKE"]
[Thu Jul 30 12:40:05.945847 2026] [security2:error] [pid 765155:tid 765310] [client 172.236.9.101:45146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMdeT5hFAbD-LhWHimcQAAAJ4"]
[Thu Jul 30 12:40:05.980287 2026] [security2:error] [pid 765155:tid 765322] [client 172.236.9.101:23233] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMdeT5hFAbD-LhWHimdgAAAKo"]
[Thu Jul 30 12:40:06.002218 2026] [security2:error] [pid 765155:tid 765337] [client 172.236.9.101:54666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMdeT5hFAbD-LhWHimdQAAALk"]
[Thu Jul 30 12:40:06.034388 2026] [security2:error] [pid 765155:tid 765397] [client 172.236.9.101:23726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMdeT5hFAbD-LhWHimdwAAAPU"]
[Thu Jul 30 12:40:06.217838 2026] [security2:error] [pid 765155:tid 765392] [client 57.141.0.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMdeT5hFAbD-LhWHimhQAAAPA"]
[Thu Jul 30 12:40:06.282893 2026] [security2:error] [pid 765155:tid 765319] [client 20.215.191.139:4073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-p.php7"] [unique_id "amuMduT5hFAbD-LhWHimlQAAAKc"]
[Thu Jul 30 12:40:06.426144 2026] [security2:error] [pid 765155:tid 765318] [client 20.100.187.246:61468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/main.php"] [unique_id "amuMduT5hFAbD-LhWHimmgAAAKY"]
[Thu Jul 30 12:40:06.577935 2026] [core:notice] [pid 765155:tid 765378] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:06.581911 2026] [security2:error] [pid 765155:tid 765378] [client 23.95.131.140:39307] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Perspective/citationstylelanguage/download/bibtex"] [unique_id "amuMduT5hFAbD-LhWHimmQAAAOI"]
[Thu Jul 30 12:40:06.669908 2026] [autoindex:error] [pid 765155:tid 765316] [client 23.94.133.71:49542] AH01276: Cannot serve directory /home2/lgggplte/brianhpark.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:40:06.806767 2026] [core:notice] [pid 765155:tid 765362] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:07.328028 2026] [security2:error] [pid 765155:tid 765406] [client 38.190.144.4:59403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMd-T5hFAbD-LhWHimtwAAAP4"]
[Thu Jul 30 12:40:07.330180 2026] [security2:error] [pid 765155:tid 765406] [client 38.190.144.4:59403] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMd-T5hFAbD-LhWHimtwAAAP4"]
[Thu Jul 30 12:40:07.368858 2026] [security2:error] [pid 765155:tid 765344] [client 20.215.191.139:11847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-admin/repeater.php"] [unique_id "amuMd-T5hFAbD-LhWHimugAAAMA"]
[Thu Jul 30 12:40:07.945706 2026] [security2:error] [pid 765155:tid 765327] [client 150.107.232.194:27043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMd-T5hFAbD-LhWHimzAAAAK8"]
[Thu Jul 30 12:40:07.945865 2026] [security2:error] [pid 765155:tid 765327] [client 150.107.232.194:27043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMd-T5hFAbD-LhWHimzAAAAK8"]
[Thu Jul 30 12:40:07.952615 2026] [security2:error] [pid 765155:tid 765259] [remote 97.74.87.194:44804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/wp-login.php"] [unique_id "amuMd-T5hFAbD-LhWHimzQAAvWc"]
[Thu Jul 30 12:40:08.177602 2026] [security2:error] [pid 765155:tid 765375] [client 150.109.119.38:48554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.119.109.150.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/theme/darm_theme_basic01/page_html/company_vision.php"] [unique_id "amuMeOT5hFAbD-LhWHim1wAAAN8"]
[Thu Jul 30 12:40:08.899122 2026] [security2:error] [pid 765155:tid 765384] [client 20.215.191.139:6329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-includes/repeater.php"] [unique_id "amuMeOT5hFAbD-LhWHim6QAAAOg"]
[Thu Jul 30 12:40:08.966581 2026] [core:notice] [pid 765155:tid 765334] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:08.970946 2026] [security2:error] [pid 765155:tid 765334] [client 103.215.74.26:2132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMeOT5hFAbD-LhWHim7gAAALY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:09.045234 2026] [security2:error] [pid 765155:tid 765353] [client 20.100.187.246:33120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/wp-file.php"] [unique_id "amuMeeT5hFAbD-LhWHim8gAAAMk"]
[Thu Jul 30 12:40:09.703726 2026] [core:notice] [pid 765155:tid 765303] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:09.707869 2026] [security2:error] [pid 765155:tid 765303] [client 103.215.74.26:2134] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMeeT5hFAbD-LhWHinBgAAAJc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:09.736849 2026] [security2:error] [pid 765155:tid 765365] [client 20.215.191.139:12125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/repeater.php"] [unique_id "amuMeeT5hFAbD-LhWHinCAAAANU"]
[Thu Jul 30 12:40:09.929872 2026] [core:error] [pid 765155:tid 765389] [client 20.63.98.115:54561] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:09.929897 2026] [core:error] [pid 765155:tid 765389] [client 20.63.98.115:54561] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:10.446470 2026] [core:notice] [pid 765155:tid 765294] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:10.450863 2026] [security2:error] [pid 765155:tid 765294] [client 103.215.74.26:2148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMeuT5hFAbD-LhWHinGwAAAI4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:11.177986 2026] [core:notice] [pid 765155:tid 765348] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:11.183923 2026] [security2:error] [pid 765155:tid 765348] [client 103.215.74.26:2160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMe-T5hFAbD-LhWHinMgAAAMQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:11.311512 2026] [core:notice] [pid 765155:tid 765368] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:11.766387 2026] [security2:error] [pid 765155:tid 765367] [client 20.63.98.115:61430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/filebrowser.php"] [unique_id "amuMe-T5hFAbD-LhWHinQAAAANc"]
[Thu Jul 30 12:40:11.911133 2026] [core:notice] [pid 765155:tid 765306] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:11.915374 2026] [security2:error] [pid 765155:tid 765306] [client 103.215.74.26:2162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMe-T5hFAbD-LhWHinSAAAAJo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:12.377499 2026] [security2:error] [pid 765155:tid 765370] [client 74.7.175.130:55144] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.voyagegetaways.com.met.nyx.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuMfOT5hFAbD-LhWHinWQAA2hg"]
[Thu Jul 30 12:40:12.400959 2026] [security2:error] [pid 765155:tid 765212] [remote 74.7.241.60:37080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/js/article.php"] [unique_id "amuMfOT5hFAbD-LhWHinWgAA8zg"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/js/bootstrap.bundle.min.js
[Thu Jul 30 12:40:12.642806 2026] [core:notice] [pid 765155:tid 765311] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:12.647437 2026] [security2:error] [pid 765155:tid 765311] [client 103.215.74.26:2166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMfOT5hFAbD-LhWHinYgAAAJ8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:12.705061 2026] [security2:error] [pid 765155:tid 765364] [client 2a03:2880:f800:1a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMfOT5hFAbD-LhWHinTwAA1C8"]
[Thu Jul 30 12:40:12.897972 2026] [security2:error] [pid 765155:tid 765382] [client 49.13.164.148:38666] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuMfOT5hFAbD-LhWHinbAAAAOY"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:40:12.912316 2026] [security2:error] [pid 765155:tid 765328] [client 20.100.187.246:44091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/wp-signin.php"] [unique_id "amuMfOT5hFAbD-LhWHinbQAAALA"]
[Thu Jul 30 12:40:13.163446 2026] [autoindex:error] [pid 765155:tid 765204] [remote 74.7.227.25:49252] AH01276: Cannot serve directory /home1/metnyxte/voyagegetaways.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:40:13.292680 2026] [core:notice] [pid 765155:tid 765406] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:13.297056 2026] [security2:error] [pid 765155:tid 765406] [client 49.13.164.148:38682] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMfeT5hFAbD-LhWHineAAAAP4"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:40:13.387905 2026] [core:notice] [pid 765155:tid 765332] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:13.392093 2026] [security2:error] [pid 765155:tid 765332] [client 103.215.74.26:48364] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMfeT5hFAbD-LhWHinfgAAALQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:13.733629 2026] [security2:error] [pid 765155:tid 765391] [client 49.13.164.148:38696] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuMfeT5hFAbD-LhWHinlAAAAO8"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:40:13.765731 2026] [security2:error] [pid 765155:tid 765349] [client 20.63.98.115:39069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/makeasmtp.php"] [unique_id "amuMfeT5hFAbD-LhWHinlQAAAMU"]
[Thu Jul 30 12:40:13.902791 2026] [security2:error] [pid 765155:tid 765299] [client 65.20.159.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMfeT5hFAbD-LhWHincgAAkzQ"], referer: https://allmontecristi.com
[Thu Jul 30 12:40:14.128537 2026] [core:notice] [pid 765155:tid 765383] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:14.136152 2026] [security2:error] [pid 765155:tid 765383] [client 103.215.74.26:48368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMfuT5hFAbD-LhWHinoAAAAOc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:14.542047 2026] [core:notice] [pid 765155:tid 765172] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:14.634963 2026] [core:error] [pid 765155:tid 765380] [client 74.7.241.169:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:14.635020 2026] [core:error] [pid 765155:tid 765380] [client 74.7.241.169:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:14.635176 2026] [security2:error] [pid 765155:tid 765380] [client 74.7.241.169:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.yne.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/index.php"] [unique_id "amuMfuT5hFAbD-LhWHin8QAAAOQ"]
[Thu Jul 30 12:40:14.635831 2026] [security2:error] [pid 765155:tid 765342] [client 74.7.241.169:43314] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.yne.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "amuMfuT5hFAbD-LhWHin7wAAvnk"]
[Thu Jul 30 12:40:14.854533 2026] [core:notice] [pid 765155:tid 765354] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:14.858697 2026] [security2:error] [pid 765155:tid 765354] [client 103.215.74.26:48370] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMfuT5hFAbD-LhWHioBAAAAMo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:14.868526 2026] [security2:error] [pid 765155:tid 765357] [client 172.236.9.101:29878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMfuT5hFAbD-LhWHinrwAAAM0"]
[Thu Jul 30 12:40:15.567458 2026] [security2:error] [pid 765155:tid 765314] [client 20.63.98.115:36857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/bypass.php"] [unique_id "amuMf-T5hFAbD-LhWHioJAAAAKI"]
[Thu Jul 30 12:40:15.582732 2026] [core:notice] [pid 765155:tid 765309] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:15.586757 2026] [security2:error] [pid 765155:tid 765309] [client 103.215.74.26:48382] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMf-T5hFAbD-LhWHioJQAAAJ0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:15.921698 2026] [security2:error] [pid 765155:tid 765355] [client 172.236.9.101:50453] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMf-T5hFAbD-LhWHioGgAAAMs"]
[Thu Jul 30 12:40:15.965812 2026] [security2:error] [pid 765155:tid 765287] [client 172.236.9.101:18575] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMf-T5hFAbD-LhWHioGwAAAIc"]
[Thu Jul 30 12:40:16.004269 2026] [security2:error] [pid 765155:tid 765405] [client 172.236.9.101:48400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMf-T5hFAbD-LhWHioHgAAAP0"]
[Thu Jul 30 12:40:16.022786 2026] [security2:error] [pid 765155:tid 765315] [client 172.236.9.101:9811] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMf-T5hFAbD-LhWHioHQAAAKM"]
[Thu Jul 30 12:40:16.088808 2026] [core:notice] [pid 765155:tid 765348] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:16.485412 2026] [security2:error] [pid 765155:tid 765286] [client 185.191.171.8:63426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/02/12/mari-apos-pressao-e-ameaca-de-greve-prefeitura-anuncia-reajuste-para-os-professores-e-retroativo-de-janeiro/"] [unique_id "amuMgOT5hFAbD-LhWHioQQAAAIY"]
[Thu Jul 30 12:40:16.485600 2026] [security2:error] [pid 765155:tid 765286] [client 185.191.171.8:63426] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/02/12/mari-apos-pressao-e-ameaca-de-greve-prefeitura-anuncia-reajuste-para-os-professores-e-retroativo-de-janeiro/"] [unique_id "amuMgOT5hFAbD-LhWHioQQAAAIY"]
[Thu Jul 30 12:40:16.630568 2026] [core:notice] [pid 765155:tid 765285] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:17.065883 2026] [security2:error] [pid 765155:tid 765317] [client 20.100.187.246:33909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/simi.php"] [unique_id "amuMgeT5hFAbD-LhWHioUwAAAKU"]
[Thu Jul 30 12:40:17.485168 2026] [core:error] [pid 765155:tid 765346] [client 40.77.167.219:22156] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug'